PRIVACY POLICY OF RURALL

(“Privacy Policy”)

 
WELCOME TO RURALL'S PRIVACY POLICY.
WE AS A COMPANY RESPECT YOUR  PRIVACY AND ARE COMMITTED TO PROTECTING YOUR PERSONAL DATA. THIS PRIVACY  POLICY WILL INFORM YOU AS TO HOW WE LOOK AFTER YOUR PERSONAL DATA WHEN YOU  VISIT OUR WEBSITE (REGARDLESS OF WHERE YOU VISIT IT FROM) AND TELL YOU ABOUT YOUR  PRIVACY RIGHTS AND HOW THE LAW PROTECTS YOU.
PLEASE READ THIS PRIVACY  POLICY CAREFULLY BEFORE BROWSING OUR WEBSITE AND LET US KNOW IF YOU HAVE ANY QUESTIONS OR  OTHER FEEDBACK REGARDING IT.
PLEASE ALSO USE THE  DEFINITIONS TO UNDERSTAND THE MEANING OF SOME OF THE TERMS USED IN THIS  PRIVACY POLICY. 
 
Important information and who we are:
Rojac Wine, narovano dobra vina, d.o.o
Gažon 63a
SI-6274 Šmarje
Slovenia, EU 
experience@rurall.com
https://rurall.com/

1.                DEFINITIONS
1.1             The terms in this Privacy  Policy have the following meaning:
“Personal Data (or Data)”:
Any information    that directly, indirectly, or in connection with other information —    including a personal identification number, such as user ID number, provided    by some services — allows for the identification or identifiability of a    natural person.
“Usage Data”:
Information    collected automatically through this Website (or third-party services    employed in this Website), which can include: the IP addresses or domain    names of the computers utilized by the You who use this Website, the URI    addresses (Uniform Resource Identifier), the time of the request, the method    utilized to submit the request to the server, the size of the file received    in response, the numerical code indicating the status of the server's answer    (successful outcome, error, etc.), the country of origin, the features of    the browser and the operating system utilized by the You, the various time    details per visit (e.g., the time spent on each page on the Website) and the    details about the path followed on the Website with special reference to the    sequence of pages visited, and other parameters about the device operating    system and/or the Your IT environment.
“You”:
The    individual using visiting this Website who, unless otherwise specified,    coincides with the Data Subject.
“Data Processor”:
The natural    or legal person, public authority, agency or other body which processes    Personal Data on behalf of the Controller, as described in this Privacy Policy.
“Data Controller”:
The natural    or legal person, public authority, agency or other body which, alone or    jointly with others, determines the purposes and means of the processing of    Personal Data, including the security measures concerning the operation and    use of this Application. The Data Controller, unless otherwise specified, is    the Owner of this Website.
“Website”:
The means by    which the Personal Data is collected and processed, located at https://rurall.com/.
“Service”:
The service    provided by this Website as described in the relative terms.
“EU”:
Unless    otherwise specified, all references made within this document to the    European Union include all current member states to the European Union and    the European Economic Area.
“Tracker”:
Tracker    indicates any technology - e.g Cookies, unique identifiers, web beacons,    embedded scripts, e-tags and fingerprinting - that enables the tracking of Website    visitors, for example by accessing or storing information on the Your    device.
“Cookie”:
Cookies are    Trackers consisting of small sets of data stored in Your browser.

1.                OWNER AND DATA CONTROLLER
1.2             Rojac Wine, naravno dobra vina,  d.o.o is the Owner and Data Controller and responsible for Your Data ("We",  "Us" or "Our").
1.3             We are the controller and  responsible for this Website.

2.               TYPES OF DATA COLLECTED 
2.1             Among the types of Data that  this Website collects, by itself or through third parties, there are: 
(a)         Identity Data includes: first name, last name, username, or similar identifier.
(b)         Contact Data includes: physical address, email address and telephone numbers.
(c)         Transaction Data includes: details about payments to and from You and other details  of products You have purchased from Us.
(d)         Usage Data includes: information about how You use Our Website.
2.2             Where We need to collect Personal  Data by law, or under the terms of a contract We have with You, and You fail  to provide that Data when requested, We may not be able to perform the  contract we have or are trying to enter into with You (for example, to provide  You with goods or services). In this case, We may have to cancel a product or  service You have with Us, but We will notify You if this is the case at the  time.

3.               MODE OF COLLECTING DATA
3.1             We use different methods to  collect Data from and about You including through:
(a)         Direct interactions. You may give Us Your Identity,  Contact and Financial Data by filling in forms or by corresponding with Us by  post, phone, email or otherwise. This includes Personal Data You provide when You: 
(i)          apply for Our products or  services;
(ii)         subscribe to Our service or  publications;
(iii)        request marketing to be sent  to You;
(iv)        enter a competition,  promotion, or survey; or
(v)         give Us feedback or contact Us.
(b)         Automated technologies  or interactions. As You interact with Our Website,  We will automatically collect Technical Data about Your equipment, browsing  actions and patterns. We collect this Personal Data by using Cookies and other similar technologies. 
(c)         Third parties or  publicly available sources. We will receive Personal Data about You from various third parties  as set out below: 
(i)          analytics providers: Google and Squarespace (based  outside the EU),
(ii)         Contact, Financial and  Transaction Data from providers of technical, payment and delivery services: Squarespace, Pay Pal and Stripe (based outside the EU),
(iii)        delivery services: GLS, DPD,  UPS, SŽ Express,
3.2             Legal basis of  processing. We may process Personal Data  relating to You if one of the following applies:
(a)         You have given Your consent  for one or more specific purposes. Note: Under some legislations We may be  allowed to process Personal Data until You object to such processing  (“opt-out”), without having to rely on consent or any other of the following  legal bases. This, however, does not apply, whenever the processing of  Personal Data is subject to European data protection law;
(b)         provision of Data is necessary  for the performance of an agreement with the You and/or for any  pre-contractual obligations thereof;
(c)         processing is necessary for  compliance with a legal obligation to which We are subject;
(d)         processing is related to a  task that is carried out in the public interest or in the exercise of official  authority vested in Us;
(e)         processing is necessary for  the purposes of the legitimate interests pursued by Us or by a third party.
In any case, We will gladly help to  clarify the specific legal basis that applies to the processing, and in  particular whether the provision of Personal Data is a statutory or  contractual requirement, or a requirement necessary to enter into a contract.
3.3             Place. The Data is processed at the Our  operating offices and in any other places where the parties involved in the  processing are located. Depending on Your location, data transfers may involve  transferring Your Data to a country other than Your own. To find out more  about the place of processing of such transferred Data, You can check the  section containing details about the processing of Personal Data. You are also  entitled to learn about the legal basis of Data transfers to a country outside  the European Union or to any international organization governed by public  international law or set up by two or more countries, such as the UN, and  about the security measures taken by Us to safeguard their Data. If any such  transfer takes place, You can find out more by checking the relevant sections  of this Privacy Policy or inquire with Us using the information provided in  the contact section.

4.               THE PURPOSE OF PROCESSING
4.1             The Data concerning You is  collected to allow Us to provide Our Service, comply with Our legal  obligations, respond to enforcement requests, protect Our rights and interests  (or those of Our users or third parties), detect any malicious or fraudulent  activity, as well as the following: Analytics and Mobile Identifiers,  Advertising.
4.2             We have set out below, in a  table format, a description of all the ways we plan to use Your Personal Data,  and which of the legal bases We rely on to do so. We have also identified what  Our legitimate interests are where appropriate.
Purpose/Activity Type of Data Lawful Basis for Processing
To register You as a new customer (a) First name, last name
(b) E-mail address
(c) Phone number
Performance of a contract with You
To process and deliver Your order including:
(a) Manage payments, fees, and charges
(b) Collect and recover money owed to us
(a) First name, last name
(b) E-mail address
(c) Phone number
(d) Financial
(a) Performance of a contract with You
(b) Necessary for Our legitimate interests (to recover debts due to Us)
To manage Our relationship with You which will include:
(a) Notifying You about changes to Our terms or Privacy Policy
(b) Asking You to leave a review or take a survey
(a) First name, last name
(b) E-mail address
(c) Phone number
(d) Marketing and Communications
(a) Performance of a contract with You
(b) Necessary to comply with a legal obligation
(c) Necessary for Our legitimate interests (to keep Our records updated and to study how customers use Our products/services)
To enable You to partake in a prize draw, competition or complete a survey (a) First name, last name
(b) E-mail address
(c) Phone number
(d) Marketing and Communications
(a) Performance of a contract with You
(b) Necessary for Our legitimate interests (to study how customers use Our products/services, to develop them and grow Our business)
To administer and protect Our business and this Website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) (a) First name, last name
(b) E-mail address
(c) Phone number
(a) Necessary for Our legitimate interests (for running Our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)
(b) Necessary to comply with a legal obligation
To use data analytics to improve Our Website, Application, products/services, marketing, customer relationships and experiences (a) Technical
(b) Usage
Necessary for Our legitimate interests (to define types of customers for Our products and services, to keep Our Website/Application updated and relevant, to develop Our business and to inform Our marketing strategy)
To make suggestions and recommendations to You about goods or services that may be of interest to You (a) First name, last name
(b) E-mail address
(c) Phone number
(d) Marketing and Communications
Necessary for Our legitimate interests (to develop Our products/services and grow Our business)
5.               CHANGE OF PURPOSE 
5.1             We will only use Your Personal  Data for the purposes for which We collected it, unless We reasonably consider  that We need to use it for another reason and that reason is compatible with  the original purpose. If You wish to get an explanation as to how the  processing for the new purpose is compatible with the original purpose, please  contact Us. 
5.2             If We need to use Your Personal  Data for an unrelated purpose, We will notify You and We will explain the  legal basis which allows Us to do so.
5.3             Please note that We may  process Your Personal Data without Your knowledge or consent, in compliance  with the above rules, where this is required or permitted by law.

6.               RETENTION TIME
6.1             Personal Data shall be  processed and stored for as long as required by the purpose they have been  collected for. Therefore:
(a)         Personal Data collected for  purposes related to the performance of a contract between Us and You shall be  retained until such contract has been fully performed.
(b)         Personal Data collected for  the purposes of Our legitimate interests shall be retained as long as needed  to fulfil such purposes. You may find specific information regarding the  legitimate interests pursued by Us within the relevant sections of this Privacy  Policy or by contacting Us.
(c)         We may be allowed to retain  Personal Data for a longer period whenever You have given consent to such  processing, as long as such consent is not withdrawn. Furthermore, We may be  obliged to retain Personal Data for a longer period whenever required to do so  for the performance of a legal obligation or upon order of an authority.
(d)         Once the retention period  expires, Personal Data shall be deleted. Therefore, the right to access, the  right to erasure, the right to rectification and the right to data portability  cannot be enforced after expiration of the retention period.

7.               DEVICE PERMISSIONS FOR  PERSONAL DATA ACCESS
7.1             Depending on the Your specific  device, this Website may request certain permissions that allow it to access  the Your device Data as described below. By default, these permissions must be  granted by You before the respective information can be accessed. Once the  permission has been given, it can be revoked by You at any time. In order to  revoke these permissions, You may refer to the device settings or contact Us  for support at the contact details provided in this Privacy Policy. The exact  procedure for controlling permissions may be dependent on Your device and  software. Please note that the revoking of such permissions might impact the  proper functioning of this Website.

8.               YOUR RIGHTS
8.1             You may exercise certain  rights regarding your Data processed by Us. In particular, You have the right  to do the following:
(a)         Withdraw Your consent at  any time. You  have the right to withdraw consent where You have previously given Your  consent to the processing of your Personal Data.
(b)         Object to processing of Your  Data. You have  the right to object to the processing of Your Data if the processing is  carried out on a legal basis other than consent. Further details are provided  in the dedicated section below.
(c)         Access Your Data. You have the right to learn if Data  is being processed by Us, obtain disclosure regarding certain aspects of the processing,  and obtain a copy of the Data undergoing processing.
(d)         Verify and seek  rectification. You  have the right to verify the accuracy of Your Data and ask for it to be  updated or corrected.
(e)         Restrict the processing  of Your Data. You  have the right, under certain circumstances, to restrict the processing of Your  Data. In this case, We will not process Your Data for any purpose other than  storing it.
(f)          Have Your Personal Data  deleted or otherwise removed. You have the right, under certain circumstances, to obtain the  erasure of Your Data from Us.
(g)         Receive Your Data and  have it transferred to another controller. You have the right to receive Your Data in a structured, commonly  used and machine-readable format and, if technically feasible, to have it  transmitted to another controller without any hindrance. This provision is  applicable provided that the Data is processed by automated means and that the  processing is based on Your consent, on a contract which You are part of or on  pre-contractual obligations thereof.
(h)         Lodge a complaint. You have the right to bring a claim  before their competent data protection authority.
8.2             Details about the right  to object to processing. Where Personal Data is processed for a public interest, in the  exercise of an official authority vested in Us or for the purposes of the  legitimate interests pursued by Us, You may object to such processing by  providing a ground related to their particular situation to justify the  objection. You must know that, however, should Your Personal Data be processed  for direct marketing purposes, You can object to that processing at any time  without providing any justification. To learn, whether We are processing Personal  Data for direct marketing purposes, You may refer to the relevant sections of  this Privacy Policy.
8.3             How to exercise these rights. Any requests to exercise Your rights  can be directed to Us through the contact details provided in this Privacy  Policy (stated in the beginning of this Privacy Policy). These requests can be  exercised free of charge and will be addressed by Us as early as possible and  always within one month. 

9.               ADDITIONAL INFORMATION ABOUT  DATA COLLECTION AND PROCESSING
9.1             Reliability. You are responsible for backing up,  to Your own computer or other device, any important data stored or accessed  via this Website. We do not guarantee or warrant that any content You may  store or access through the Website will not be subject to inadvertent damage,  corruption, or loss.
9.2             Security. We will use commercially reasonable  efforts to safeguard the confidentiality of Your Data. However, We cannot be  held liable for any loss of or disclosure of Data or any losses or damages  incurred due to errors in transmission or unauthorized or unlawful acts of  third parties or Your decision to disclose Your Personal Data. No system can  be 100% secure, and despite Our efforts, there is always a risk of  unauthorized access to Your Data. By using this Website, You assume this risk.
9.3             Legal action. Your Personal Data may be used for  legal purposes by Us in Court or in the stages leading to possible legal  action arising from improper use of this Website or the related Services. You  declare to be aware that We may be required to reveal personal data upon  request of public authorities.
9.4             Additional information  about Your Personal Data. In addition to the information contained in this Privacy Policy,  this Website may provide You with additional and contextual information  concerning particular Services or the collection and processing of Personal  Data upon request.
9.5             System logs and  maintenance. For  operation and maintenance purposes, this Website, and any third-party services  may collect files that record interaction with this Website (System logs) use  other Personal Data (such as the IP Address) for this purpose.
9.6             Information not  contained in this Privacy Policy. More details concerning the collection or processing of Personal  Data may be requested from Us at any time. Please see the contact information  at the beginning of this Privacy Policy.
9.7             Changes to this Privacy Policy. We reserve the right to make changes  to this Privacy Policy at any time by notifying You on this page and possibly  within this Application and/or - as far as technically and legally feasible -  sending a notice to You via any contact information available to Us. It is  strongly recommended to check this page often, referring to the date of the  last modification listed at the bottom. Should the changes affect processing  activities performed on the basis of the Your consent, We shall collect new  consent from You, where required.
9.8             Legal information. This Privacy Policy has been prepared  based on provisions of multiple legislations, including Art. 13/14 of  Regulation (EU) 2016/679 (General Data Protection Regulation). This Privacy Policy  relates solely to this Website, if not stated otherwise within this Privacy  Policy.
Latest update: 22. 2. 2024.