1. Data Controller
The controller of your personal data is AXA Servis Koles, Partizanska cesta 11, 4260 Bled, Slovenia.
For any questions regarding your personal data, you can contact us at david.kosovel@axa-servis.si.
2. What Data We Collect
We collect personal data that you voluntarily provide when submitting a service order or inquiry through our website:
- ●Name
- ●Email address
- ●Phone number
- ●Message (optional)
Depending on the type of service, we may also collect service-specific details such as:
- ●Number of bikes and bike types
- ●Fleet size and service frequency
- ●Trip dates, route descriptions, and group size
- ●Skill level and preferred contact method
We do not collect data through cookies, analytics tools, or advertising trackers.
3. Legal Basis for Processing
We process your personal data on the basis of Article 6(1)(b) of the General Data Protection Regulation (GDPR) — the processing is necessary for the performance of a contract or to take steps at your request prior to entering into a contract.
When you submit a service order or inquiry, we process your data to receive, confirm, and fulfil your service request.
4. How We Use Your Data
We use your personal data for the following purposes:
- ●Process and confirm your service order or inquiry
- ●Send you order confirmation and service-related communications via email
- ●Respond to your questions or requests
5. Third-Party Services
To provide our services, we use the following third-party service providers:
- ●Firebase / Firestore (Google Cloud) — We store your order data in Google Cloud Firestore. Google processes this data in accordance with its data processing terms and applicable EU data protection regulations.
- ●Postmark (ActiveCampaign, Inc.) — We use Postmark to send order confirmation and notification emails. Your name, email address, and order details are transmitted to Postmark for this purpose.
- ●Google Places API — We use the Google Places API to display public business reviews on our website. No personal user data is sent to this service.
- ●Vercel Inc. — Our website is hosted on Vercel. As part of standard web hosting, Vercel may process technical data such as your IP address and request metadata.
6. Data Retention
We retain your order data for as long as necessary to fulfil the service and to comply with legal obligations (such as bookkeeping and tax requirements).
You may request the deletion of your personal data at any time by contacting us at the email address listed above.
7. Your Rights Under GDPR
Under the General Data Protection Regulation, you have the following rights:
- ●Right of access to your personal data
- ●Right to rectification of inaccurate data
- ●Right to erasure ('right to be forgotten')
- ●Right to restriction of processing
- ●Right to data portability
- ●Right to object to processing
To exercise any of these rights, please contact us at david.kosovel@axa-servis.si.
You also have the right to lodge a complaint with the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec) at www.ip-rs.si.
8. Data Security
We take appropriate measures to protect your personal data:
- ●All data transmitted through our website is encrypted using HTTPS
- ●Data stored in Firebase / Firestore is encrypted at rest
- ●Access to order data is restricted to authorised personnel only
9. Children's Privacy
Our services are not directed at children under the age of 16. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a child, please contact us so we can delete it promptly.
10. Changes to This Policy
We may update this privacy policy from time to time. Any changes will be posted on this page with an updated date. We encourage you to review this policy periodically.