This draft explains the intended handling of customer data. The controller identity, processors, exact retention periods and international-transfer safeguards must be completed before launch.
Controller and contact
The controller will be [FULL LEGAL COMPANY NAME], [FULL REGISTERED ADDRESS], registration number [NUMBER], VAT number [SI NUMBER]. Privacy questions and rights requests can be sent to info@example.com. Add the data-protection officer contact here if one is appointed or legally required.
Data we collect
Depending on the service, we may process name, contact details, delivery and billing address, company and VAT details, account information, order and payment status, project requirements, uploaded documents, support communications, cookie choices and limited technical security logs. Payment card data should be handled directly by the selected payment provider rather than stored by Solarco.
Purposes and legal bases
Data is used to respond to requests, take pre-contract steps, conclude and perform sales, deliver products, provide support and warranties, meet tax and accounting duties, prevent abuse and defend legal claims. The legal basis is contract, legal obligation or legitimate interests as appropriate. Optional analytics and marketing use consent and remain off until consent is given.
Frontend preview and accounts
The current cart, profile, consent choice and demo order history are stored only in this browser. The preview password is never stored. When backend accounts launch, this notice must identify the hosting, authentication, email and support providers, security approach, server locations and actual account retention rules.
Recipients and transfers
Necessary data may be shared with contracted hosting, payment, delivery, accounting, communications and technical-support providers, and with authorities where legally required. Processors may act only under appropriate agreements. Any transfer outside the EEA requires a valid transfer mechanism and, where needed, supplementary safeguards.
Retention
Enquiries should be kept only as long as needed for follow-up; account data until deletion or a defined inactivity period; order, invoice and warranty records for the applicable contractual, tax and limitation periods; consent evidence while needed to demonstrate compliance; and security logs for a short documented period. Replace these categories with exact operational periods before launch.
Analytics and cookies
Google Analytics is optional and remains blocked until analytics cookies are allowed in Cookie preferences. Withdrawing consent stops future analytics loading. Essential browser storage used for the cart, language, account preview and consent choices does not depend on analytics consent.
Your rights
Subject to applicable conditions, individuals may request access, correction, deletion, restriction and portability, object to processing based on legitimate interests, and withdraw consent without affecting earlier lawful processing. Complaints may be submitted to the Slovenian Information Commissioner or the competent supervisory authority.
Security and updates
Solarco will use access controls, encryption in transit, backups, vendor reviews and incident procedures proportionate to the risk. No internet service is completely risk-free. Material notice changes will be dated and communicated where the law requires it.