privacy policy

Notice to individuals under Article 13 of the General Data Protection Regulation (GDPR) concerning the processing of personal data, v 1.0.

The controller of personal data in connection with the website https://kokoroclub.co/ and your other interactions with Vizualna umetnost, Urška Trkov, s.p. is:

Vizualna umetnost, Urška Trkov, s.p.

Sostrska cesta 43

1261 Ljubljana - Dobrunje

Registration number: 7504721000

VAT number: SI 33844186

email: hello@kokoroclub.co

(hereinafter: the “organisation” or the “company”)

A data protection officer has not yet been appointed in our organisation. All questions, requests, enquiries and other communications relating to the area of personal data protection in our organisation may be addressed to: hello@kokoroclub.co.

Introduction

Basic information about the organisation and its mission

Our organisation collects, stores and otherwise processes certain information and data, including personal data, as provided for by the Personal Data Protection Act (ZVOP-2) and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the General Data Protection Regulation or the GDPR).

Purpose and use of this notice

This notice describes how our organisation processes the personal data of individuals who have entrusted their personal data directly to it as the controller of personal data in connection with the website https://kokoroclub.co/ (e.g. when cookies are loaded upon a visit to the website, when completing and submitting the contact form, etc.).

Use of terms and changes to this notice

Unless otherwise stated, the terms appearing in this notice (e.g. personal data, processing, controller, processor, etc.) have the same meaning as in the GDPR.

The phrase website or web page means https://kokoroclub.co/ and also covers all associated subpages and connected servers and systems.

The emphasised or defined terms in this notice (e.g. individual), although written in the singular, are deemed to include the plural and vice versa; and terms written in one gender include all genders.

We may update or change the information and statements in this notice from time to time, whereby news of major changes will be published on our website.

In the event of material changes (e.g. regarding the legal bases and purposes of processing of data already collected), we will inform individuals of the proposed changes by email or in another appropriate manner.

1. Overview of the collections and types of personal data, the categories of data subjects to whom the personal data relate, the anticipated time limits for the erasure of personal data, and the legal bases for processing and the purposes and types of processing

1.1. Table of processing

NAME OF THE CONTROLLER’S PERSONAL DATA COLLECTION

TYPES OF PERSONAL DATA IN THE COLLECTION

CATEGORIES OF DATA SUBJECTS TO WHOM THE PERSONAL DATA RELATE

ANTICIPATED TIME LIMITS FOR ERASURE OF PERSONAL DATA *

LEGAL BASIS FOR PROCESSING, PURPOSES OF PROCESSING AND TYPES OF PROCESSING OF PERSONAL DATA **

Data related to an open user account (registration on the website)

Username, email address and password (which is stored exclusively in encrypted or hashed form and to which our organisation has no access), as well as any other data that the user voluntarily enters into their user account (e.g. first and last name, address, telephone number, order history, saved products).

The individual (website visitor) who registers on the website and concludes a user account agreement with our organisation, or accepts the website’s terms of business.

Until the deletion of the user account (i.e. until the user cancels the registration or until the termination of the contractual relationship regarding the use of the user account), whereby our organisation may also delete the user account itself if it has been inactive for a longer period, as described in more detail under points 1.3 and 2 of this document. Individual data from the user account that are at the same time part of another collection (e.g. data on issued invoices) are retained in accordance with the time limits applicable to that collection.

The processing is based on point (b) of Article 6(1) of the GDPR (processing is necessary for the performance of a contract on the use of a user account to which the individual is a party, or in order to take steps at the request of the individual prior to entering into a contract). For the purposes of opening and managing a user account, enabling user log-in and authentication, providing the functionalities of the user account (e.g. review of order history, faster checkout) and communicating with the user in connection with the user account (e.g. registration confirmation, password reset), we may store the data and process it in ways that are logically connected with the management of the user account (i.e. storage in the back end of the online store and in the email-sending system, access, editing and correction, transmission, erasure, back-up copying).

Data related to a concluded contract (distance purchase)

The buyer’s name and any other data collected at the final step of the purchase (i.e. contact data, telephone, email address, delivery address, gender, etc.).

The buyer who concludes a distance-selling contract with our organisation (i.e. a purchase via the website), or in connection with which our organisation issues an invoice for its services.

Until the expiry of the retention period or the fulfilment of the purpose of processing of individual personal data, whereby our organisation as a rule retains the data for a further 6 years after the completion of the purchase, or even longer (e.g. in connection with data on the invoice, which is as a rule retained for at least 10 years on the basis of the law), as described in more detail under points 1.3 and 2 of this document.

For the purposes of performing the concluded contract (e.g. delivery of the product, issuance of the invoice), we may store the data and process it in ways that are logically connected with the performance of the contract or the issuance of invoices (i.e. storage in the email-sending system and in the back end of the online store, physical storage (invoice), access, transmission, erasure, back-up copying).

Data on an individual who has already been a customer of our online store

Email address of the individual who has already been a customer of our online store.

Individuals who have already purchased products from our online store.

Until unsubscribing from receiving electronic communications, whereby the unsubscribe link is contained in every electronic message.

*The individual may at any time also request unsubscribing or the erasure of data by sending their request to the organisation’s official email address, which is stated at the beginning of this document.

On the basis of the express statutory exception that permits this type of sending of electronic messages, we may, until the receipt of the individual’s unsubscription, store the data and process it in ways that are logically connected with sending commercial electronic messages (i.e. retaining and using it in connection with the email-sending system) exclusively for the purposes of providing information, advice and other useful data regarding the organisation’s services.

Data on an individual who communicates with the organisation via email addresses and other communication channels available on the website

First and/or last name of the individual who communicates with our organisation. Any email address of the individual who communicates with our organisation. Any telephone number of the individual who communicates with our organisation. Any personal data contained in the communication with the individual.

Individuals who, of their own will, communicate with the organisation (e.g. enquiring about the organisation’s services, arranging a visit to the business premises via the published email address or contact form, etc.).

Until the expiry of the purposes of processing of individual personal data for which the data was collected (e.g. until the end of the communication), or until the expiry of 4 years from the last communication with the individual.

On the basis of negotiations for the conclusion of a contract (i.e. obtaining information about, or ordering, a service, or other voluntary communication of the individual with the organisation in connection with this), the organisation may process the data in ways that are logically connected with the negotiations regarding the performance of the subject of the service or the preparation of a response (e.g. storage in the email-sending system for the purposes of responding and any further communication, storage of data in the organisation’s archive, etc.).

Data on individuals who have subscribed to receiving informational electronic messages of the organisation

Email address of the individual.

Individuals who have consented to the organisation occasionally sending information, advice and other useful data regarding the organisation’s products/services to their email address.

Until unsubscribing from receiving electronic communications, whereby the unsubscribe link is contained in every electronic message.

*The individual may at any time also request unsubscribing or the erasure of data by sending their request to the organisation’s official email address, which is stated at the beginning of this document.

On the basis of the consent obtained, the organisation may process the data (i.e. retain and use it in connection with the email-sending system) exclusively for the purposes of providing information, advice and other useful data regarding the organisation’s services.

Data on individuals who register to participate in a prize game

First and last name of the prize-game participant, email address, and any other data that the individual may disclose during participation in the prize game (e.g. delivery address for the prize, tax number for the calculation of withholding, etc.).

Individuals who participate in the prize game.

Until the expiry of the period of the prize game and a further 6 years from that day for the purposes of proof (complaints / inspection supervision).

On the basis of negotiations for the conclusion of a contract (i.e. the promise of a prize pursuant to the provisions of the Obligations Code and the rules of the relevant prize game), the company may collect and retain the data for the duration of the prize game and a further 6 years after the expiry of the prize game, structure it and otherwise use it in a meaningful manner exclusively for the purposes of carrying out the prize game (e.g. publication of the winner’s first and last name on the company’s website, review of the received entry, drawing/carrying out the selection, contacting the individual in the event of selection, delivery of the product, payment of the withholding, etc.).

Data on individuals who apply for a vacant position in the organisation

First and last name of the candidate, email address of the candidate, CV, cover letter, data on past work experience or other data relevant to the selection procedure and stated as such at the time of publication of the vacancy, as well as any personal data that may be contained in the email correspondence with such an individual.

The individual who applies for a vacant position in the organisation.

Until the completion of the recruitment procedure, if the organisation has not obtained the individual’s express consent for longer retention of the data.

On the basis of negotiations for the conclusion of an employment contract, the organisation may process the data (i.e. collect, retain for the duration of the selection procedure, review, structure) and otherwise use it in a meaningful manner exclusively for the purposes of the recruitment procedure (e.g. evaluation of the individual’s references and communicating with them about the course of the recruitment procedure, use of the data to view other publicly available data on the individual, etc.).

Data obtained with the help of cookie-technology providers from website visitors

The data described in the case of the individual type of essential or non-essential cookies (such as IP address, session time, browser data, etc.) (see our dedicated cookie policy).

The individual who visits our website and installs essential or non-essential cookies (see our dedicated cookie policy).

(See our dedicated cookie policy)

(See our dedicated cookie policy)

* In certain cases based on its legitimate interests, the organisation reserves the right to retain certain data longer than the above periods (e.g. in the case of inspection proceedings in connection with a service/prize game/form), whereby in all such cases the organisation will limit the retention of data to that data which is necessary to pursue such a legitimate interest. The individual may at any time request the erasure of data by sending their request to the official email address stated at the beginning of this document.

** In connection with the above purposes (e.g. data storage), the data may be provided for processing to the organisation’s contractual partners (sub-processors) listed in chapter 3.3 of this notice. Sub-processors may process the data only in connection with the performance of the tasks assigned to them and directly connected with the pursued purposes.

1.2 The legal basis for the processing of personal data may lie in the performance of a concluded contract or in negotiations for the conclusion of a contract

We may process the personal data of individuals on the basis of a concluded contract (e.g. the performance of a service at our business premises) or negotiations for the conclusion of a contract (e.g. when an individual contacts us via our official communication channels and wishes to obtain more information about our services).

In the described cases, you provide us with your personal data as part of a contractual obligation or as part of negotiations for the conclusion of a contract, and consequently we do not require your express consent for the aforementioned processing of your personal data.

In principle, you will not suffer any serious negative consequences in situations where we would otherwise need your personal data to perform our services and you do not provide us with this data. However, such situations may significantly hinder or even prevent the performance of the ordered services or our cooperation, and in such cases you will be informed of this beforehand or afterwards.

1.3. The legal basis for the processing of your data may also be the law

In the organisation we also process personal data for the purposes of fulfilling statutory and other regulations, in particular those governing taxes and accounting (e.g. records of issued and received invoices, etc.), for example:

- when an inspector or other holder of public authority instructs the organisation to entrust it, in accordance with the law, with the personal data of a particular customer/visitor (e.g. in the context of carrying out inspection supervision under the provisions of the Inspection Act (ZIN)),

- when the organisation processes the personal data of a customer to whom it has issued an invoice, the organisation processes that invoice and the data on the customer (e.g. personal name, contact data, etc.) on the basis of the Value Added Tax Act (ZDDV-1) (see chapter 3.2.), etc.

1.4. On the basis of the legitimate interests of the organisation

We may also process certain personal data for the purposes of protecting our own legitimate interests. This is the case, for example, where the processing of your data would be necessary from the perspective of administrative, criminal or civil proceedings (e.g. where the organisation would have to submit a database as evidence in proceedings, otherwise the organisation would suffer a penalty or the occurrence of more serious and irreparable damage), whereby in such cases we will always process only that data which is strictly necessary to pursue such legitimate objectives.

The organisation may also process the personal data of an individual in cases where the processing is necessary to protect the vital interests of the individual (e.g. access to the address of an individual facing an immediate and serious threat to life).

1.5. On the basis of consent obtained

As a rule, we do not make cooperation with us and the use of the organisation’s services conditional upon your consent to the processing of personal data.

Nevertheless, the organisation may also process your personal data on the basis of your express consent. The express consent of an individual is deemed to be their voluntary declaration of will by which they consent to the processing of certain personal data for a specific purpose (e.g. your consent to receiving our informational messages), whereby in such cases we process the data listed in the section of the table under point 1 where it is indicated that the processing is based on consent.

This type of communication may be cancelled at any time by following the link contained in each such electronic message, or by contacting us in this regard at the address stated at the beginning of this document.

Our online advertising may also be carried out on the basis of your consent, if, upon visiting our website, you have consented to the installation of the non-mandatory (advertising) cookies and tracking pixels of our advertising partners (e.g. the installation of the Google Analytics cookie, which enables us to advertise our services more easily on other websites as well, etc.). A precise inventory of the non-mandatory cookies of our advertising partners, the data we process with them and the retention periods of that data is set out on the “Cookies” subpage.

The organisation guarantees the individual the right to withdraw their express consent at any time in a simple manner, i.e. by contacting us in this regard at any time at the email address stated at the beginning of this document.

The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of consent up to the moment of withdrawal.

If you do not give consent for the processing of personal data, give consent in part, or (partially) withdraw consent, we will, insofar as this is possible, cooperate with you only to the extent of the consent given, or in ways permitted by applicable legislation.

Consent is voluntary, and if you decide that you do not wish to give it, or you subsequently withdraw it, this in no case diminishes your other rights, nor does it represent additional costs or aggravating circumstances for you.

2. How long do we retain or process your personal data?

The retention period of personal data depends on the basis and purpose of processing of the individual category of personal data. Personal data is as a rule retained for as long as is necessary to fulfil the purpose for which the data was collected, or for as long as a regulation requires us to retain it, after which it is erased.

Insofar as the retention period of individual data is not defined in more detail in the table of chapter 1, the following applies:

- Data related to a concluded contract or the provision of our services and the issuance of invoices: until the expiry of the retention period or the fulfilment of the purpose of processing of the individual personal data, whereby the organisation may as a rule retain the data for a further 6 years after the completion of the cooperation, or even longer (e.g. data on the invoice), whereby the personal data of customers on invoices is retained for a further 10 years, as this obligation is imposed on the organisation by the Value Added Tax Act (ZDDV-1);

- Data on an individual who communicates with the organisation via email addresses and other communication channels available on the website is retained until the expiry of the purposes of processing of the individual personal data for which the data was collected (e.g. until the end of the communication), or until the expiry of 4 years from the last communication with the individual;

- On the basis of your express consent to marketing communications or our legitimate interest in advertising to persons who are already our customers, we retain the data for as long as the person does not withdraw their consent.

The organisation may retain the data for a further 15 days after the expiry of the aforementioned retention period, in order to be able, during this period, to destroy the stored data from all data carriers and servers.

The individual may at any time request the erasure of data by sending their request to the organisation’s official email address, at the address stated at the beginning of this document.

3. Who processes your personal data within and outside the organisation (users of personal data)?

3.1. Certain employees in the organisation

Your personal data is processed by those employees in the organisation who need the data in order to be able to perform their work tasks. All employees are bound by confidentiality and by respect for the protection of personal data.

3.2. State authorities

In certain cases prescribed by applicable legislation, the organisation must also provide your personal data to, or report on it to, the competent state authorities, as well as authorities that are, for example, competent for financial, tax or other supervision (e.g. the Information Commissioner of the Republic of Slovenia, etc.). In certain cases, the organisation is also obliged to provide the data to third parties, if such an obligation to provide or disclose the data is imposed on the organisation by law or by the legal entitlement of a third party.

3.3. Contractual processing of personal data

In addition to the employees in the organisation, users of personal data may also be the employed persons of the organisation’s contractual processors, who may process the personal data as confidential exclusively on behalf of the organisation and within the limits of the external personal data processing contract that the organisation has concluded with each such processor. Contractual processors may process personal data only within the framework of the organisation’s instructions (i.e. the contract), whereby they may not use the data to pursue any interests of their own.

The contractual processors with whom the organisation cooperates are:

  • persons who cooperate with us on the basis of contracts for services or copyright contracts (IT system maintainers, software code developers, etc.),

  • payment service providers,

  • accountants or accounting services or accounting tools,

  • the website hosting service provider - Squarespace, Inc (see chapter 3.4.).

The organisation will not provide your personal data to unauthorised third parties.

To obtain a precise list of all the organisation’s contractual sub-processors, you may write to us at the email address stated at the beginning of this document.

3.4 Website hosting service provider

Our website is hosted on servers belonging to Squarespace, Inc.

3.5. Transfer of personal data to third countries and international organisations, and measures to protect transferred data

Our organisation as a rule does not transfer personal data to third countries (i.e. outside the area of the European Union, Iceland, Norway and Liechtenstein, i.e. the EEA) or to international organisations.

An exception to the above is represented by occasional transfers of certain technical and personal data to the servers of the above-mentioned processors whose registered offices or servers are located in the USA (i.e. the automatic transfer of certain data collected by the cookies of American companies– more in our cookie policy,  or website related data transfers to Squarespace, Inc.), whereby the relevant contractual processors are former members of the “Privacy Shield” programme (https://www.privacyshield.gov/) and, after 12 July 2020, respect and have adopted security measures in connection with the receipt or transfer of data (e.g. standard contractual clauses), or have duly carried out and achieved full self-certification in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on an adequate level of protection of personal data under the EU–US Data Privacy Framework (i.e. within the meaning of the new framework for the transfer of data between the EU and the USA in accordance with the aforementioned adequacy decision of 10 July 2023).

You may obtain a list of all such sub-processors by sending a request in this regard to the email address stated at the beginning of this document.

4. Processing and protection of special categories of personal data

In connection with our website or services, we do not direct individuals to provide special categories of personal data (i.e. data revealing racial or ethnic origin, political opinion, religious or philosophical belief or trade union membership, genetic data or biometric data, data concerning health or data concerning an individual’s sex life or sexual orientation).

Should the organisation become aware of the occurrence of a situation in which such data would be disclosed to it, protection or other appropriate handling will be ensured with regard to the data received.

5. What are your rights regarding your personal data and how can you exercise them?

In connection with this notice on the processing of personal data, or regarding the processing of your personal data by our organisation and our contractual processors, you may contact us at any time and without reservation via the email address stated at the beginning of these General Terms.

You may likewise use the stated address to send your requests and to exercise other rights connected with personal data and the GDPR.

As a data subject to whom the personal data relate, the GDPR offers you the option to exercise the following rights with our organisation:

Right to be informed: Individuals have the right to be informed about the collection and processing of their personal data.

Right of access: Individuals have the right to access their personal data and to obtain information about how the data is processed, as well as a copy of the data itself.

Right to erasure (right to be forgotten): Individuals have the right to request the erasure of their personal data in certain circumstances.

Right to withdraw consent: If the processing of personal data is based on consent, individuals have the right to withdraw their consent at any time without suffering any negative consequence.

Right to rectification: Individuals have the right to request the rectification of inaccurate or incomplete personal data. If the data has been provided to third parties, we will, insofar as this is possible, inform those third parties of the rectification carried out.

Right to restriction of processing: Individuals have the right to request the restriction of the processing of their personal data. This right applies in certain cases, for example when the accuracy of the data is contested or the individual has objected to its processing.

Right to data portability: In certain cases, individuals have the right to receive their personal data in a structured, commonly used and machine-readable format. They may also request that their data be transmitted to another controller, if the processing is based on consent or a contract and if the processing is carried out by automated means.

Right to object: Individuals have the right to object to the processing of their personal data on the basis of legitimate interests or public interest/the exercise of public authority. In such cases we will cease such processing, unless we can demonstrate compelling legitimate grounds which override the interests, rights and freedoms of the individual.

Rights in relation to automated decision-making and profiling: Individuals have the right not to be subject to solely automated decisions, including profiling, that significantly affect them. They also have the right to human intervention, to express their point of view and to contest such decisions.

Right to lodge a complaint with a supervisory authority: If you consider that the processing of personal data carried out by our organisation in relation to you infringes the personal data protection regulations, you may, without prejudice to any other (administrative or other) legal remedy, lodge a complaint with a supervisory authority, in particular in the state in which you have your habitual residence, in which your place of work is located, or in which the alleged infringement took place (in Slovenia this is the Information Commissioner):

- Information Commissioner, Dunajska 22, 1000 Ljubljana, email: gp.ip@ip-rs.si, telephone: 01 230 97 30, website: www.ip-rs.si.

A list of other EU supervisory authorities and their contact details is available here: https://www.edpb.europa.eu/about-edpb/about-edpb/members_sl.

6. Existence of automated decision-making and profiling

The processing carried out by our organisation does not involve automated decision-making and profiling based on your personal data.

7. Processing of personal data of persons under 15 years of age

Our organisation has directed the development and offering of its services towards the collection of personal data of persons who are older than 15 years. In cases where a younger person would use the organisation’s service, the organisation will, insofar as it becomes aware of such a case, obtain the consent of the parent or guardian of such a person.

Insofar as the organisation itself subsequently establishes that, in connection with the service, the personal data of a person under 15 years of age is being processed, but their parent or guardian has not consented to this, it will do everything necessary to erase all the captured personal data.

The above-mentioned persons or their parents or guardians may at any time send their requests for the erasure of the relevant data to the email address stated at the beginning of this document.

8. Whom can you contact regarding additional explanations concerning the processing of personal data and your rights?

Regarding the processing of your personal data, you may contact us at any time at the email address stated at the beginning of this document.

9. Protection of your personal data

In the organisation we carefully store and protect personal data with organisational, technical and logical-technical procedures and measures, by which we protect the data against accidental or intentional unauthorised access, destruction, alteration or loss, and against unauthorised disclosure or another form of processing to which you have not expressly consented.

To this end, the organisation has also adopted appropriate internal processes and established various measures (e.g. the assignment, use and modification of passwords, the locking of premises, offices and locations of servers and workstations, the regular updating of supporting software and the upgrading of security-deficient components, the physical safeguarding of material containing personal data at specially designated places, the training of employees, etc.). The organisation also requires the same security requirements from its contractual processors.

10. Version and date of the last update of this notice

The text of this notice represents version 1.0 of this document. This notice was last updated on 31st of July 2026.

Vizualna umetnost, Urška Trkov, s.p.