Privacy policy
Last updated: December 24, 2025
PRIVACY POLICY (GDPR)
1. Who we are (controller)
The controller of your personal data under Regulation (EU) 2016/679 of the European Parliament and of the Council ("GDPR") and related legal regulations is:
Penev, spol, s.r.o
Zahradna 35, 080 01 Presov, Slovak Republic
E-mail: obchod@printhia.sk
Company ID: 31677622
Tax ID: 2020497985
VAT ID: SK2020497985
In this Privacy Policy ("Policy") we explain how we process your personal data when you visit our online store, use our services ("Services"), make a purchase, communicate with us, or otherwise interact with us.
By using our Services, you confirm that you have read this Policy and understand how we process your personal data as described herein.
In the event of a conflict between our general terms and conditions and this Policy, this Policy shall prevail on matters of personal data protection.
--------------------------------------------------
2. What personal data we process
"Personal data" means any information relating to an identified or identifiable natural person.
Depending on how you interact with the Services, where you reside, and what applicable legislation allows or requires (in particular the GDPR and Act No. 18/2018 Coll. on the Protection of Personal Data), we may process the following categories of personal data:
- Contact details
First name, last name, billing address, delivery address, phone number, email address.
- Billing and financial data
Data required to process payment and invoicing (e.g. payment account information, transaction data, payment method and confirmation). Full payment card details are typically processed by your payment gateway provider; Printhia does not have full access to this data unless necessary and permitted by law.
- Account data
Username, password (hash stored in the system), security settings, preferences and account settings.
- Order and transaction data
Products purchased, products in the cart or wishlist, purchase history, returns, exchanges, order cancellations and related information.
- Communication with us
Information you provide when communicating with us (email, contact form, phone, social media), including the content of your questions, complaints or feedback.
- Device and connection data
IP address, browser type and version, device type, operating system, language settings, cookie identifiers and similar technical data.
- Data on the use of the Services
Information about your interaction with the website and online store (pages visited, clicks, time spent, referral source, etc.). This data may be collected through cookies and similar technologies.
--------------------------------------------------
3. Sources of personal data
We obtain personal data mainly from the following sources:
- Directly from you: creating an account, placing an order, filling in forms, communicating with us, submitting a review, entering data during payment, etc.
- Automatically when using the Services: through cookies and similar technologies, as well as server logs and technical tools used by Shopify.
- From service providers: e.g. payment gateways, logistics partners, IT administrators, analytics tools, who process data on our behalf as processors.
- From partners and third parties: e.g. marketing and advertising partners, if you have allowed them to share data or as required by applicable legislation.
--------------------------------------------------
4. Purposes of processing and legal bases (GDPR)
We process your personal data only when we have a valid legal basis under Article 6 of the GDPR. Depending on the specific situation, this mainly concerns the following purposes and legal bases:
4.1 Providing, operating and improving the Services
Purpose: processing orders, delivering goods, account management, payment management, handling complaints, technical operation of the website, content personalization (e.g. displaying items in the cart, recommended products).
Legal bases:
- performance of a contract (Art. 6(1)(b) GDPR),
- compliance with legal obligations (Art. 6(1)(c) GDPR),
- legitimate interest (Art. 6(1)(f) GDPR): basic technical logging, improving the functionality and security of the Services.
4.2 Marketing and advertising
Purpose: sending marketing information (e.g. newsletter), personalized offers, displaying advertising on our website or other websites (remarketing), analyzing campaign effectiveness.
Legal bases:
- consent (Art. 6(1)(a) GDPR),
- legitimate interest (Art. 6(1)(f) GDPR) to the extent permitted by law, always with the option to easily object / unsubscribe.
4.3 Security and fraud prevention
Purpose: account verification, detecting and investigating fraud, ensuring a safe shopping environment, protecting our rights and the rights of third parties, securing our network and IT systems.
Legal bases:
- legitimate interest (Art. 6(1)(f) GDPR),
- compliance with legal obligations (Art. 6(1)(c) GDPR), where such an obligation is imposed by law.
4.4 Communication with you and customer support
Purpose: answering questions, processing requests, handling complaints, informing you about order status, technical support.
Legal bases:
- performance of a contract (Art. 6(1)(b) GDPR),
- legitimate interest (Art. 6(1)(f) GDPR) for general communication and service improvement.
4.5 Compliance with legal obligations
Purpose: bookkeeping, retaining tax documents, complying with obligations under Slovak/EU law, cooperating with public authorities, handling judicial and administrative proceedings.
Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR).
--------------------------------------------------
5. Who we disclose personal data to
Your personal data may, under certain circumstances, be disclosed to the following categories of recipients:
- Shopify: the provider of our online store and hosting platform, which processes personal data to provide technical infrastructure, hosting, payment and logistics integrations, and analytics and security features.
- Our processors: entities that process data on our behalf under a data processing agreement, e.g. IT and hosting service providers, payment gateways, logistics and courier partners, cloud storage providers, marketing and analytics tools (to the extent permitted by law).
- Business and marketing partners: entities that help us with marketing, advertising and offer personalization. These partners process personal data under their own privacy policies and their own responsibility, where they act as controllers themselves.
- Public authorities and other third parties: where necessary to comply with legal obligations, to protect our rights and the rights of third parties (e.g. courts, police, supervisory authorities).
- Within our group / a potential legal successor: in the event of a merger, sale of the business or other corporate transaction, your data may be transferred to the legal successor in accordance with the law.
We do not sell personal data in the sense of directly providing data to third parties for financial compensation in a manner contrary to the GDPR.
--------------------------------------------------
6. Relationship with Shopify
Our Services are hosted and technically supported by Shopify, which processes personal data in the position of:
- a processor: when it processes data on our behalf and on our instructions (e.g. storing orders, technical hosting, managing the e-commerce platform),
- an independent controller: for certain activities where Shopify itself determines the purpose and means of processing (e.g. certain security or analytics features at the level of the entire platform).
Information you submit through our online store is transmitted to and processed in Shopify's systems and may also be transferred to other countries outside the EEA/UK (see the "International transfers of personal data" section).
Details on how Shopify processes personal data and what rights you can exercise directly against Shopify can be found in the following documents:
https://www.shopify.com/legal/privacy/app-users
https://privacy.shopify.com/en
--------------------------------------------------
7. Third-party websites
Our Services may contain links to third-party websites or services (e.g. social media, payment gateways, partner sites). These entities have their own privacy and security policies, for which we bear no responsibility.
We recommend that you always read the relevant privacy policy and terms of use on these sites.
Information you publish in public or semi-public places (e.g. public reviews, social media) may also be visible to other users beyond our control.
--------------------------------------------------
8. Children's personal data
Our Services are not intended for persons under the age of majority in your jurisdiction (typically 18 years). We do not knowingly collect data on children.
If you are a parent or legal guardian and believe that your child has provided us with their personal data, please contact us so that we can delete this data.
As of the effective date of this Policy, we are not aware of "selling" or "sharing" the personal data of persons under 16 years of age within the meaning of personal data protection legislation.
--------------------------------------------------
9. Security and retention period of personal data
We use appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, misuse or damage, in accordance with Article 32 of the GDPR.
However, no security measure is absolute. We recommend that you protect your login credentials, do not use the same password across multiple services, and do not transmit sensitive information through unsecured channels.
Retention period:
- order and invoicing data: generally 10 years in accordance with tax and accounting regulations,
- account data: for the duration of the account; upon account cancellation we delete or anonymize it, unless we are required to retain it longer,
- marketing data: until consent is withdrawn or an objection to processing for direct marketing purposes is raised, or until the internal retention period expires,
- logs and technical data: for the period necessary to ensure operation, protection against attacks and incident resolution (typically months to a few years, depending on the nature of the data and legal obligations).
Where a fixed period is not possible, we apply criteria such as the length of the contractual relationship, warranty periods, limitation periods, and statutory archiving obligations.
--------------------------------------------------
10. Your rights under the GDPR
As a data subject, you have (subject to the conditions laid down by law) in particular the following rights:
- Right of access: request confirmation as to whether we process your personal data, obtain a copy of your data and information about the processing.
- Right to rectification: request the correction of inaccurate or incomplete personal data.
- Right to erasure ("right to be forgotten"): request the deletion of your personal data if the conditions are met (e.g. the data is no longer needed, you have withdrawn your consent, you have successfully objected to processing, or the processing is unlawful).
- Right to restriction of processing: request the restriction of processing (e.g. while an objection or the accuracy of the data is being verified).
- Right to data portability: in certain circumstances, request that your personal data be provided in a structured, commonly used and machine-readable format and transferred to another controller.
- Right to object: object to processing based on legitimate interest (including profiling) for reasons relating to your particular situation; in particular, you have the right to object at any time to processing for direct marketing purposes, in which case we will stop processing your data for this purpose.
- Right to withdraw consent: where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
- Right to lodge a complaint: if you believe that the processing of your personal data violates the GDPR or other legal regulations, you have the right to lodge a complaint with a supervisory authority.
How to exercise your rights:
You can exercise your rights by email at obchod@printhia.sk or in writing at Printhia, Zahradna 35, 080 01 Presov, Slovak Republic. Before processing your request, we may ask you for reasonable information to verify your identity.
--------------------------------------------------
11. Supervisory authority (complaints)
The supervisory authority for the protection of personal data in the Slovak Republic is:
Office for Personal Data Protection of the Slovak Republic
Hranicna 12, 820 07 Bratislava 27
Web: https://dataprotection.gov.sk
You have the right to contact this authority if you believe that your rights in the field of personal data protection have been violated.
--------------------------------------------------
12. International transfers of personal data
Because we use Shopify's services and those of other providers, your personal data may be transferred to countries outside the European Economic Area (EEA) or the United Kingdom, for example to Canada or the USA.
Where such a transfer takes place, we ensure that an adequate level of protection of personal data is maintained, in particular through:
- transfer to countries for which the European Commission has adopted an adequacy decision, or
- the use of the European Commission's standard contractual clauses (SCC) or equivalent mechanisms under applicable law.
Information on how Shopify ensures international transfers can be found in its privacy policy.
--------------------------------------------------
13. Changes to this Privacy Policy
We may update this Policy from time to time, for example due to changes in legislation, our processes or services.
We will always publish the updated version on this page, update the "Last updated" date, and, in the event of material changes, provide reasonable notice (e.g. by email or a prominent notice on the website) where required by law.
--------------------------------------------------
14. Contact
If you have questions about this Policy, about how we process your personal data, or if you wish to exercise any of your rights, please contact us:
Penev, spol, s.r.o
Zahradna 35, 080 01 Presov, Slovak Republic
E-mail: obchod@printhia.sk
Company ID: 31677622
Tax ID: 2020497985
VAT ID: SK2020497985
For the purposes of the GDPR and related legal regulations, Printhia acts as the controller of your personal data in connection with this online store and the Services provided.