Privacy Policy
Last updated: 1. 6. 2026
1. Data Controller
ROTO Nautica d.o.o.
Gorička ulica 150, Černelavci
9000 Murska Sobota, Slovenia
Email: [email protected]
(“Controller”, “we”, “us”)
2. Scope and Purpose
This Privacy Policy explains how we collect, use, and protect personal data when you visit our website or contact us. Processing is carried out in accordance with EU GDPR Regulation and applicable Slovenian data protection law.
3. Legal Bases for Processing
We process personal data on the following legal bases:
- Consent: for cookies, analytics, newsletter, and marketing
- Pre-contractual measures: when you contact us regarding products or services
- Legal obligations
- Legitimate interests: ensuring website security, preventing misuse, and improving services
4. Categories of Personal Data
We may process the following data:
- Contact data: name, email address, phone number (if provided)
- Communication data: content of inquiries
- Technical data: IP address, browser type, device information
- Usage data: pages visited, interactions, timestamps
- Marketing data: consent preferences, interaction with campaigns
5. Cookies and Consent Management
We use cookies and similar technologies in accordance with GDPR and ePrivacy rules.
Types of cookies:
- Strictly necessary: required for website operation
- Functional: enable enhanced features
- Analytics and marketing: used only with your prior consent
We use a consent management platform (CMP) that allows you to:
- Give, refuse, or withdraw consent
- Manage preferences at any time
Consent is logged and can be withdrawn without affecting the lawfulness of prior processing.
6. Analytics
We use Google Analytics 4 to analyze website usage and improve performance.
Data processed may include:
- Truncated IP address
- Device and browser information
- User behavior (pages visited, interactions)
Processing is based on your consent.
We use privacy-enhancing settings, including IP anonymization and consent mode. Data retention is configured to the minimum necessary period.
7. Marketing and Remarketing
We use Meta Pixel to measure the effectiveness of advertising and provide relevant content.
This may involve:
- Tracking interactions with our website
- Linking behavior to Meta platforms (e.g., Facebook, Instagram)
Processing occurs only with your consent.
8. Newsletter and Direct Marketing
If you subscribe to our newsletter, we process your email address to send marketing communications.
- Legal basis: consent
- You can withdraw consent at any time via the unsubscribe link or by contacting us
We may analyze newsletter engagement (e.g., open rates, clicks) to improve content.
9. Contact Forms and Communication
When you contact us via forms or email, we process your data to respond to your inquiry.
- Legal basis: pre-contractual measures or legitimate interest
- Data is not shared with third parties unless necessary to handle your request
10. Server Log Files
We automatically collect the following data:
- IP address
- Date and time of access
- Requested content
- Referrer URL
- Browser and operating system
This processing is necessary for security, system stability, and abuse prevention.
11. Data Retention
We retain personal data only as long as necessary:
- Contact inquiries: up to 12 months after resolution
- Newsletter data: until withdrawal of consent
- Analytics data: according to configured retention settings (typically 2–14 months)
- Server logs: up to 90 days
Longer retention may apply where required by law.
12. Data Sharing and Processors
We use external service providers (processors), including:
- Website hosting providers
- Analytics providers (Google)
- Marketing platforms (Meta)
All processors are bound by GDPR-compliant data processing agreements.
We do not sell personal data.
13. International Data Transfers
Some providers (e.g., Google, Meta) may process data outside the European Economic Area.
Where this occurs, transfers are protected by appropriate safeguards, including:
- European Commission Standard Contractual Clauses
- Additional technical and organizational measures where required
14. Data Security
We implement appropriate technical and organizational measures in accordance with GDPR, including:
- HTTPS encryption
- Access controls
- System monitoring and protection measures
Email communication may not be fully secure unless additional encryption is used.
15. Rights of Data Subjects
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase data
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent at any time
Requests can be sent to: [email protected]
We respond within one month, extendable where legally permitted.
16. Right to Lodge a Complaint
You have the right to lodge a complaint with:
Information Commissioner of the Republic of Slovenia
Zaloška cesta 59, 1000 Ljubljana
17. Updates to This Policy
We may update this Privacy Policy to reflect legal or operational changes. The current version is always available on this website.