Privacy and Personal Data Protection Policy

As the operator of the website bolha.com, the company Styria digital marketplaces d.o.o., Verovškova ulica 55, Ljubljana is extremely concerned with the protection of your personal data. We treat your personal data with the greatest possible care and safety, pursuant to the applicable legislation in the Republic of Slovenia in the field of personal data protection and, above all, pursuant to the Personal Data Protection Act (Official Gazette of the Republic of Slovenia, No. 94/07, as amended) and the General Data Protection Regulation of the EU (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC). Data processing is only performed by those authorised to do so as well as by our carefully selected contractual processors. This Privacy and Personal Data Protection Policy regulates the collection and processing of personal data obtained by Styria digital marketplaces d.o.o. when you access the website bolha.com or when you use the services of the website bolha.com. Data processing is always based on one of the legal bases set out in Article 6 of the General Data Protection Regulation.

In the framework of this Privacy and Personal Data Protection Policy, we would like to inform you of the following:

1. Data protection officer

If you have any questions related to our Privacy and Personal Data Protection Policy or to the processing of your personal data, you can always contact our data protection officer at dpo_styria-slo@styria.com.

2. Acquisition of personal data and the purposes for their processing

Personal data means any information relating to an identified or identifiable natural person, such as first and last name, address, e-mail address, etc. Since personal data protection is conferred on natural persons, this Privacy and Personal Data Protection Policy is not related to the protection of personal data of natural persons pursuing their activities on the market who are acting as registered users according to the Rules and Conditions of Use of bolha.com in this capacity, nor to the data of legal persons.

We acquire and further process your personal data in order to provide the services on these websites, improve your user experience and our services, provide communication and information through the use of various means of communication (e-mail, phone number, mobile phone number or an online service provider of “remote assistance” or “live chats”) and comply with our legal obligations.

I. We acquire these data when you complete your registration at bolha.com. Upon registration, you accept the Rules and Conditions of Use of bolha.com, thus acquiring the status of a registered user. The personal data needed for registration (in order to provide the basic identification of the user) are:

  1. first and last name,
  2. address (street name, street number, town, postcode),
  3. contact information (e-mail address and phone number which is needed in order to verify the identity of a registered user. After registration, the user (generally only in the role of a vendor) will receive an SMS message with a confirmation code which must be entered into the registration form in order to conclude the registration process).

When you are using the website bolha.com, we may also ask you to provide other data necessary for the provision of our services; however, they will only be entered as you begin to use said services (e.g. entering data as you purchase services/goods, reserve tourist accommodation and fill in other forms related to the provision of services.)

This information is processed based on Article 6, point (b) of the General Data Protection Regulation (processing necessary for the performance of a contract).

If you wish, you can also add the following elements during your use of the website bolha.com:

  1. your photograph in the user profile Moja bolha.com,
  2. other information which is voluntarily entered into these websites (such as data that you enter voluntarily as you publish an ad).

We collect and further process your personal data also in the context of various forms on the bolha.com website, when this is necessary to perform the ordered services:

  1. IBAN number, tax number or place of birth, date of birth, valid identity document and tax residency certificate, if you perform financial transactions when using the bolha.com website,
  2. within the scope of other forms that are available from time to time on the bolha.com website.

When you use services that do not require user registration (for example, services in the Tourism category), we obtain your personal data when booking accommodation and catering services, when you accept the Terms and Conditions of Use of bolha.com. The personal data required to provide the above services are:

  1. username,
  2. first and last name,
  3. address (street, house number, postal code, post office, country),
  4. contact information (e-mail address, telephone number),
  5. data on the reservation of accommodation and catering services,
  6. in case of possible refunds of paid-in funds, also your account information (IBAN, swift code and name of the bank where the account is opened).

This information is processed based on Article 6, point (a) of the General Data Protection Regulation (your consent).

II. The data that you have provided us upon registration will also be processed if you order paid services from our website bolha.com in order to process payments and refunds of paid funds, provide support when it comes to accessing contents and services of bolha.com, the requirements of system and technical information about any changes and the functioning of bolha.com, and communicating with other users of these websites. All of the aforementioned instances are examples of personal data processing related to the provision of services of the bolha.com website (the legal basis set out in Article 6, point (b) of the General Data Protection Regulation - processing necessary for the performance of a contract).

III. We will also use your e-mail address to inform you of any new developments and related services of bolha.com (through the bolha.com newsletter), if you have not revoked your consent to receive said content at the time of your registration based on the instructions received in the confirmation message, or at any time after said registration. Since we only send our newsletter to registered users, we will also process the information that you are a registered user of bolha.com in this instance. Data processing for the purpose of sending the bolha.com newsletter is based on Article 6, point (f) of the General Data Protection Regulation - legitimate interest of the controller - or the second paragraph of Article 158 of the Electronic Communications Act.

IV. If you consent to receiving e-mail notifications for which we do not have any other legal basis, we will use your e-mail address and the fact that you are a registered user of bolha.com who is the intended recipient of said e-mail notifications. The processing of your personal data for the purpose of receiving said e-mail notifications is based on Article 6, point (a) of the General Data Protection Regulation (your consent).

V. During your use of services at bolha.com, other data or information which are automatically processed for the purpose of internal analysis, in order to improve our services, to provide statistical processing and for safety reasons, can also be systemically recorded. The data that are being processed for the aforementioned purposes are:

  • geolocation data and cookies (based on the provided consent),
  • information on the use of services (web browser, current IP address of the device, time and duration of access to these websites),
  • information on phone conversations and online chats (username (optionally), time and duration).

In this event, the processing of personal data is based on Article 6, point (f) of the General Data Protection Regulation (the legitimate interest of the processor to provide user-friendly services tailored, as much as possible, to the individual needs of the user, reduce the risk of misuse, assist in the detection of said misuses and guarantee the safety of its network and information).

Whenever we can achieve the intended purpose, anonymised data is used for statistical processing. Anonymised data can no longer be connected to the user who provided said personal data, which is why the processing of anonymised data is not subject to this Privacy and Personal Data Protection Policy.

VI. We can also obtain your data from third parties, namely:

  1. other users of the website bolha.com (e.g. when they report abuses or breaches),
  2. our contractual partners who individually process your personal data, but only in the scope necessary for the realisation of their services on these websites (e.g. your phone number when you pay through the Premium SMS channel),
  3. social networks, if you connect your bolha.com profile with your profile on said social network (e.g. your username, contact information and any other information with which you provide us in this way).

In the case referred to in point 1, we acquire your personal data and continue processing them based on Article 6, point (f) of the General Data Protection Regulation (the legitimate interest of the processor in order to reduce the risk of misuse and assist in the detection of said misuse).

In the case referred to in point 2, we acquire your personal data and continue processing them based on Article 6, point (b) of the General Data Protection Regulation (processing necessary for the performance of a contract).

In the case referred to in point 3, we acquire your personal data and continue processing them based on Article 6, point (a) of the General Data Protection Regulation (your consent).

VI. We must also use the personal data obtained through the provision of services of bolha.com or in relation to the provision of said services for the purpose of performing our legal obligations (e.g. identifying a user based on the Prevention of Undeclared Work and Employment Act, and for accounting purposes based on tax legislation etc.). In these cases, the processing of your personal data is based on Article 6, point (c) of the General Data Protection Regulation (compliance with a legal obligation).

2.1 Age limit related to the information society services

The intended users of the services provided at bolha.com are persons over the age of 16 since the registration on the portal means entering into a contractual relationship for which the aforementioned capacity to contract must be guaranteed at a minimum. The age information is not a condition for the registration on the website bolha.com, and we are not authorised to verify which data are related to persons under the age of 16. We recommend that parents and legal guardians of persons under the age of 16 talk to their children under the age of 16 about the safe use of the Internet and the provision of one's personal data. Any risks related to the inability of minors to assume a valid commitment lie with their parents and guardians.

3. Transfer of personal data to third parties

We would like to inform you that your personal data may also be available to:

  • other users of the website bolha.com, to the extent specified by yourself, or if you voluntarily provide your data to other users (based on Article 6, point (a) of the General Data Protection Regulation - your consent),
  • to providers of accommodation and hospitality services in the Tourism category, when you order the specified services (on the basis of point b 6/I of Article 6 of the General Regulation on Data Protection - Implementation of the Contract),
  • other companies of Styria Media Group of which the controller is also a part (based on Article 6, point (f) of the General Data Protection Regulation - legitimate interest of the companies within the Group for the internal administrative purpose related to analytics, statistics, etc.),- other companies of Styria Media Group of which the controller is also a part (based on Article 6, point (f) of the General Data Protection Regulation - legitimate interest of the companies within the Group for the internal administrative purpose related to analytics, statistics, etc.), to the company Njuškalo d.o.o., Miroslava Miholića 2, Zagreb, Croatia (administrator of the website www.njuskalo.hr), which together with the company Styria digital marketplaces, d.o.o. (the operator of the website www.bolha.com) processes your personal data when you use the services of the Tourism category, and in this case the two companies act as joint managers of your personal data with the aim of ensuring the reservation of accommodation and catering services and support in using the services of the Tourism category (based on concluded service contracts and agreements pursuant to Article 26 of the General Data Protection Regulation),
  • our verified contractual processors who make it possible for us to develop and maintain these websites, provide payment services and electronic notification services, conduct lotteries, reserve accommodation and catering services through these websites, etc.; whenever possible, these services are provided to us by companies within the Styria Media Group (on the basis of the concluded service contract and agreement according to Article 28 of the General Data Protection Regulation),
  • authorised persons and competent national authorities, the legal provisions of which contain a suitable legal basis for obtaining and processing said data (based on Article 6, point (c) of the General Data Protection Regulation - compliance with a legal obligation).

Every time we transfer your personal data, we perform suitable technical and organisational actions in order to guarantee the safety of your personal data; all recipients of your data are bound to perform these same actions.

3.1 Transfer of personal data to third countries

We only transfer data to third countries (outside of the EU and the EEA) if we have your explicit consent to do so and if this is strictly necessary for us to comply with our contractual and legal obligations. In the event of any export of your personal data, this will be carried out to the minimum extent necessary for the provision of services on these websites.

Your data may be transferred:

  • to the US, if you have provided your consent to receive personalised ads on these websites (e.g. to Google, Inc.), if you are using the Stripe payment application (to Stripe, Inc.) and during communication with social networks (to find out more, read Chapter 4 of this Privacy and Personal Data Protection Policy of bolha.com);
  • to Switzerland, if you are using the Premium SMS payment channel (to the company NTH AG), and
  • standard contractual clauses adopted by the European Commission and the Information Commissioner of the Republic of Slovenia and approved by the European Commission (e.g. transfer of data to the US).

When we are transferring your personal data to third countries, in addition to a suitable legal basis for such a transfer, we also provide additional measures with the purpose of maintaining a suitable level of security of your data during transfer; in doing so, we are leaning on the principles of Chapter V of the General Data Protection Regulation. We are performing the transfer of your data to third countries based on:

  • the issued decision on the provision of a suitable level of personal data protection by the European Commission or the Information Commissioner of the Republic of Slovenia (e.g. transfer of data to Switzerland and the United Kingdom);
  • standard contractual clauses adopted by the European Commission and the Information Commissioner of the Republic of Slovenia and approved by the European Commission (e.g. transfer of data to the US).

4. Social networks

In order to communicate and provide interesting content to the users of the website bolha.com, we also use our business profiles on the following social networks:

  • Meta Platforms, Inc., the company managing Facebook and Instagram;
  • Google, Inc., the company managing YouTube, and
  • Twitter, Inc., the company managing the eponymous Twitter.

In the aforementioned cases, we can obtain and process your data but we do not transfer them to our internal databases of the website bolha.com. When using the aforementioned personal profiles, the authorised persons of the controller have access to your personal messages and publications. Social networks provide us with statistical reports on the visits to our profiles, general interests of our visitors and demographic data. These reports do not contain any personal data but merely help us in providing the users of our services with interesting content.

In the event of use of these social networks and their interaction with these websites, data is being transferred to the US, whereby the companies managing each individual network also individually manage the personal data received, which means that they define the types of personal data that they are processing as well as the purposes and legal bases used to process personal data; furthermore, they also individually manage cookies on their websites and define the purposes of their use.

If you are interacting with social networks as set out in the first paragraph of this point, we invite you to familiarise yourselves with their privacy policies available at:

5. Cookies

The website bolha.com uses various cookies. Cookies are alphanumerical identifiers loaded on the users' hard drive which can recognise the user upon their next visit. That way, you do not have to enter the same data when you log in and use the services of these websites. Cookie management is performed through the Didomi application which enables users to receive information on the cookies that have been loaded on their hard drive and manage consent for the loading of individual cookies on the device of the user. Find out more about the cookies used by the website bolha.com at Cookies used by bolha.com.

Personal data are processed using cookies based on the provisions of the Electronic Communications Act (Official Gazette of the Republic of Slovenia, No. 109/12, as amended). With the exception of personal data processing using cookies, which are necessary for the functioning of the web pages, other cookies are only installed upon the prior consent of each individual.

6. Zaštita

Styria digital marketplaces d.o.o. is extremely concerned with the protection of your data, which is why we use the so-called SSL (Secure Socket Layer) technology when entering data into some of the subsites. This technology represents a global de facto standard and prevents the possibility of unauthorised persons accessing the data that you have entered into your device. Your data is protected from loss, destruction, forgery, manipulation and unprotected access by third parties. In addition, our employees are committed to protecting your personal data and complying with the applicable regulations and internal rules of Styria digital marketplaces d.o.o. We regularly examine and complete the adopted protective measures. We choose our contractual business partners carefully and responsibly. Furthermore, we also achieve a high level of protection through data pseudonymisation and anonymisation if such data still allows for a suitable provision of our services.

To find out more about safety precautions that you can provide by yourself, go to Safety tips

7. Retention period

We will retain your personal data pursuant to the prescribed retention periods or until the fulfilment of the purpose for which they have been acquired, i.e.:

  • Personal data acquired on the basis of a concluded contract will be processed until the end of the period of limitation, according to the general rules of civil law. This also applies if you delete your user profile on the website bolha.com or in the event of a cancellation of a user profile pursuant to the Rules and Conditions of Use of bolha.com, unless the applicable legislation provides for a longer retention period (e.g. a retention period of 10 years for data connected to invoices and other financial documents).
  • Personal data acquired for the purpose of sending bolha.com newsletters will be retained until we receive a notification that you no longer wish to be subscribed to receiving said newsletters.
  • Personal data acquired on the basis of your consent will be retained until revocation unless your consent provides for a different retention period. In case of any new functionalities and whenever this is necessary for a smooth, legal provision of services, the website bolha.com may prepare new consent forms or stop acquiring said data. Such a change does not affect the validity of any prior consents. Any registered user may manage (provide or withdraw) their consent through their user profile at Moja bolha.com or through a written request addressed to the controller.
  • Personal data acquired in order to protect the network and prevent any misuse will be retained for 2 years after the date of their generation. Deleted ads of registered users will also be retained in the framework of the aforementioned data, i.e. for 2 more years after they have been deleted or after the user profile of the registered user who published said ad is deleted (whichever comes first).
  • Personal data acquired in order to enforce, execute and defend legal claims will be retained for 5 years after the finality of the judgment, settlement or agreement on an out-of-court settlement of a dispute.

8. Rights of users

Individuals or users of the website bolha.com enter and provide their own personal data and decide on their processing in the framework of their rights.

We are hereby informing you that you have the right to access your personal data, complete your personal data, correct your personal data, delete your personal data (right to be forgotten) and restrict the processing of your personal data as well as the right to data portability and objection to the processing based on Article 6, paragraph 1, point (f) of the EU General Data Protection Regulation, or for the purpose of direct marketing - in the scope and under the conditions set out by the General Data Protection Regulation.

Registered bolha.com users can also enforce their right to access your personal data by accessing your data independently and at any time within the Moja bolha.com user profile. In order to provide accuracy and currency of your personal data, you can also change your data, thus avoiding the need to file a special request for correcting your personal data. If you have any further questions or if you cannot enter any changes and rectify errors in the personal data that have been provided, or when using services that do not require registration on bolha.com (for example, when using services in the Tourism category), you can notify us immediately and send notifications and requests to exercise your rights to the email address podpora@bolha.com or dpo_styria-slo@styria.com or to Styria digital marketplaces, d.o.o., Verovškova 55, SI-1000 Ljubljana.

We would like to notify you that:

  • you can limit the use of your e-mail address for receiving the bolha.com newsletter at any time,
  • you can also cancel any other consent that you have provided at any time,

based on a written request forwarded to the controller or through the intended functionality in the Moja bolha.com profile.

Due to the specific nature of this process, you can also unsubscribe from receiving the bolha.com newsletter and revoke your consent for the processing of your personal data for the purpose of receiving other e-mail notifications through an online link which is available in every e-mail message that you receive.

The lawfulness of processing performed with your consent before the revocation of your consent or erasure of your data shall remain unaffected by said revocation of your consent and erasure

We would like to inform you that the erasure process may be stopped within 24 hours or no later than the next day after submitting your request for deletion by 24:00; after that, it is no longer possible to stop it. Data erasure is an irreversible process, which is why it is no longer possible to subsequently acquire your data.

As data holders, individuals have the right to request that your data be transferred to another processor. For technical reasons, you cannot independently transfer your data through the Moja bolha.com profile. In the aforementioned cases, the controller of the website bolha.com will receive a written request for the transfer of your data.

All requests must be provided in writing. When it is not possible to submit a claim through your Moja bolha.com profile (in the case of the inability to use the Moja bolha.com profile or when you use bolha.com services, user registration is not required for cattery), and sent to Styria digital marketplaces d.o.o., Verovškova 55, SI-1000 Ljubljana, or by e-mail at dpo_styria-slo@styria.com. We will also provide our answer to your request in writing, within the deadline set out in the General Data Protection Regulation.

We would like to inform you that the aforementioned rights are not absolute and must only be complied with by us in certain cases. When you decide to enforce your rights, we will first check your identity since the aforementioned rights may only be enforced by the data subject.

If you suspect that your data is not being processed pursuant to the applicable regulations in the field of personal data protection, and if we do not accept your request to enforce your rights, you are entitled to lodge a complaint with the Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, SI-1000 Ljubljana.

9. Links to other websites

This Privacy Policy relates to the website bolha.com. Our websites may also contain links to other websites or services (such as prize games) for which other privacy policies apply. When you click on a link to another website and provide your personal data in the framework of the services not subject to this Privacy Policy, you must familiarise yourself with their privacy policies. Unless explicitly agreed otherwise, the company Styria digital marketplaces d.o.o. is not responsible for the privacy and cookie policy, nor for the content of linked websites and other services.

10. Validity and amendments

This Privacy Policy shall enter into force on the day that it is published. The controller is entitled to change this Privacy Policy without prior notice; a notification on the amended Privacy and Personal Data Protection Policy will be published on the homepage of the website bolha.com for 7 days from the day of publication of the revised policy. All changes will be published on these websites and shall enter into force on the day of publication on this website.

Your data is being processed by:
Styria digital marketplaces, d.o.o.
Verovškova 55
SI - 1000 Ljubljana
e-mail address: dpo_styria-slo@styria.com

Ljubljana, 12 May 2023