Privacy Policy

Last updated: 1. 6. 2026

1. Data Controller

ROTO Nautica d.o.o.
Gorička ulica 150, Černelavci
9000 Murska Sobota, Slovenia
Email: [email protected]

(“Controller”, “we”, “us”)

2. Scope and Purpose

This Privacy Policy explains how we collect, use, and protect personal data when you visit our website or contact us. Processing is carried out in accordance with EU GDPR Regulation and applicable Slovenian data protection law.

3. Legal Bases for Processing

We process personal data on the following legal bases:

  • Consent: for cookies, analytics, newsletter, and marketing
  • Pre-contractual measures: when you contact us regarding products or services
  • Legal obligations
  • Legitimate interests: ensuring website security, preventing misuse, and improving services

4. Categories of Personal Data

We may process the following data:

  • Contact data: name, email address, phone number (if provided)
  • Communication data: content of inquiries
  • Technical data: IP address, browser type, device information
  • Usage data: pages visited, interactions, timestamps
  • Marketing data: consent preferences, interaction with campaigns

5. Cookies and Consent Management

We use cookies and similar technologies in accordance with GDPR and ePrivacy rules.

Types of cookies:

  • Strictly necessary: required for website operation
  • Functional: enable enhanced features
  • Analytics and marketing: used only with your prior consent

We use a consent management platform (CMP) that allows you to:

  • Give, refuse, or withdraw consent
  • Manage preferences at any time

Consent is logged and can be withdrawn without affecting the lawfulness of prior processing.

6. Analytics

We use Google Analytics 4 to analyze website usage and improve performance.

Data processed may include:

  • Truncated IP address
  • Device and browser information
  • User behavior (pages visited, interactions)

Processing is based on your consent.

We use privacy-enhancing settings, including IP anonymization and consent mode. Data retention is configured to the minimum necessary period.

7. Marketing and Remarketing

We use Meta Pixel to measure the effectiveness of advertising and provide relevant content.

This may involve:

  • Tracking interactions with our website
  • Linking behavior to Meta platforms (e.g., Facebook, Instagram)

Processing occurs only with your consent.

8. Newsletter and Direct Marketing

If you subscribe to our newsletter, we process your email address to send marketing communications.

  • Legal basis: consent
  • You can withdraw consent at any time via the unsubscribe link or by contacting us

We may analyze newsletter engagement (e.g., open rates, clicks) to improve content.

9. Contact Forms and Communication

When you contact us via forms or email, we process your data to respond to your inquiry.

  • Legal basis: pre-contractual measures or legitimate interest
  • Data is not shared with third parties unless necessary to handle your request

10. Server Log Files

We automatically collect the following data:

  • IP address
  • Date and time of access
  • Requested content
  • Referrer URL
  • Browser and operating system

This processing is necessary for security, system stability, and abuse prevention.

11. Data Retention

We retain personal data only as long as necessary:

  • Contact inquiries: up to 12 months after resolution
  • Newsletter data: until withdrawal of consent
  • Analytics data: according to configured retention settings (typically 2–14 months)
  • Server logs: up to 90 days

Longer retention may apply where required by law.

12. Data Sharing and Processors

We use external service providers (processors), including:

  • Website hosting providers
  • Analytics providers (Google)
  • Marketing platforms (Meta)

All processors are bound by GDPR-compliant data processing agreements.

We do not sell personal data.

13. International Data Transfers

Some providers (e.g., Google, Meta) may process data outside the European Economic Area.

Where this occurs, transfers are protected by appropriate safeguards, including:

  • European Commission Standard Contractual Clauses
  • Additional technical and organizational measures where required

14. Data Security

We implement appropriate technical and organizational measures in accordance with GDPR, including:

  • HTTPS encryption
  • Access controls
  • System monitoring and protection measures

Email communication may not be fully secure unless additional encryption is used.

15. Rights of Data Subjects

You have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase data
  • Restrict processing
  • Data portability
  • Object to processing
  • Withdraw consent at any time

Requests can be sent to: [email protected]

We respond within one month, extendable where legally permitted.

16. Right to Lodge a Complaint

You have the right to lodge a complaint with:

Information Commissioner of the Republic of Slovenia
Zaloška cesta 59, 1000 Ljubljana

www.ip-rs.si

17. Updates to This Policy

We may update this Privacy Policy to reflect legal or operational changes. The current version is always available on this website.

Don't Fall Behind!

Enter your email for new arrivals, events, promotions and more!

We promise to not use your email as spam!