In accordance with Regulation (EU) 2016/679 (GDPR) and the Slovenian Personal Data Protection Act (ZVOP-2), we inform you about the processing of your personal data on the website https://kcstv.si.
Effective from: 18 March 2025
Last updated: 28 September 2026
1. Data controller
Zavod KC STV
Tehnološki park 18, 1000 Ljubljana
Slovenia
Registration number: 7024134000
VAT number: SI86260537
E-mail: info@kcstv.si
Phone: 041 328 964
Website: https://kcstv.si
For any questions regarding the processing of personal data, please contact us using the details above.
2. Data Protection Officer (DPO)
For data protection matters, contact us at info@kcstv.si; we respond to individuals’ requests within the statutory deadline.
3. Purposes and legal bases of processing
We process your personal data for the following purposes:
Contact form
Legal basis: Consent (Art. 6(1)(a)). Purpose: Responding to enquiries and further communication. Data: name, e-mail, message content, optionally company.
Newsletter subscription
Legal basis: Consent (Art. 6(1)(a)). Purpose: Sending marketing messages. Data: e-mail, name (optional).
User accounts
Legal basis: Contract (Art. 6(1)(b)). Purpose: Managing the user account. Data: e-mail, password (hashed), login data.
Cookies (non-essential)
Legal basis: Consent (Art. 6(1)(a)). Purpose: Analytics, personalisation, marketing. Details in the Cookie Policy.
Direct marketing
Legal basis: Consent / Legitimate interest (Art. 6(1)(a)/(f)). Purpose: Direct marketing communication with existing clients.
4. Categories of data
In line with the processing above, we collect:
- Identification data (first name, last name)
- Contact data (e-mail, phone, address)
- Technical data – website access (IP address, browser, device)
- Behavioural data on the website (via cookies, if you allow them)
5. Recipients of data
We share your data with the following processors:
| Service | Purpose | Location |
|---|---|---|
| Bitrix24 (e-mail marketing) | Service | Amazon cloud, Frankfurt, Germany |
We have signed Data Processing Agreements (DPA) with all processors in accordance with Art. 28 GDPR.
6. Transfers to third countries
We do not transfer personal data to countries outside the European Economic Area.
7. Retention periods
| Type of data | Retention period |
|---|---|
| Newsletter subscription | Until unsubscribed |
| Contact form | 2 years |
| Server logs | 6 months |
| Cookies | 14 months or as set by you |
8. Your rights
Under the GDPR you have the following rights:
- Access (Art. 15) – you may receive a copy of your data upon request
- Rectification (Art. 16) – we correct inaccurate or incomplete data
- Erasure (Art. 17) – we delete your data (“right to be forgotten”), except data we are required to keep by law (e.g. invoices)
- Restriction (Art. 18) – we temporarily suspend processing
- Portability (Art. 20) – we export your data in a machine-readable format
- Objection (Art. 21) – against processing based on legitimate interest, and at any time against direct marketing
- Withdrawal of consent – at any time where processing is based on consent; withdrawal does not affect the lawfulness of processing before the withdrawal
To exercise your rights, send your request to info@kcstv.si. We respond without undue delay and within one month at the latest; in complex cases we may extend the deadline by up to two further months and will inform you accordingly (Art. 12(3) GDPR).
Providing personal data is not a legal obligation. However, without the data marked as required in the form, we cannot answer your enquiry or process your order.
9. Right to lodge a complaint
If you believe that the processing of your data infringes the GDPR, you may lodge a complaint with:
Information Commissioner of the Republic of Slovenia
Dunajska cesta 22, 1000 Ljubljana
E-mail: gp.ip@ip-rs.si
Phone: 01 230 97 30
www.ip-rs.si
10. Automated decision-making
We do not use automated decision-making without human involvement for decisions that produce legal effects concerning an individual.
11. Security measures
To protect your data we use:
- HTTPS / SSL encryption
- Database encryption
- Strong passwords and 2FA for administrators
- Regular backups
- Restricted access on a “need to know” basis
In the event of a security incident, we will notify you within 72 hours.
12. Changes to this policy
We may update this policy in line with changes in legislation or in our operations. The date of the last update is stated at the top of this document. We will communicate significant changes through our communication channels and publications on our website.
Ljubljana, September 2026
Rudi Panjtar, Director
