Privacy Policy
Privacy Policy
Effective from: 1 December 2025
1. Data Controller
The controller of personal data within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as "GDPR") and Act No. 18/2018 Coll. on the protection of personal data, as amended, is:
yknot s. r. o. Ďurgalova 2860/2 Bratislava — mestská časť Nové Mesto, 831 01 Company ID (IČO): 56569653 Tax ID (DIČ): 2122352012 Email: info@wovenrag.com
The company is registered in the Commercial Register of the Municipal Court Bratislava III, Section: Sro, File No.: 189593/B.
2. What Personal Data Do We Process?
2.1 Order Data
When you purchase from our online store, we process:
- First name and surname
- Delivery address
- Email address
- Phone number (if provided)
- Billing data (Company ID, Tax ID, VAT number — if provided)
- Order and purchase history data
2.2 Contact Form Data
When you use the contact form, we process:
- Your name
- Email address
- Message content
2.3 Newsletter Subscription Data
When you subscribe to our newsletter, we process:
- Email address
- Name (if provided)
- Subscription date and consent
2.4 Cookies and Analytics Data
For detailed information about cookies, please see our Cookie Policy.
3. Purposes and Legal Bases for Processing
3.1 Processing Orders and Performing
the Purchase Contract
- Legal basis: Art. 6(1)(b) GDPR (performance of a contract)
- Data processed: first name, surname, delivery address, email, phone number
- Retention period: for the duration of the contractual relationship and 10 years after its termination (accounting and tax obligations)
3.2 Accounting and Tax Records
- Legal basis: Art. 6(1)(c) GDPR (compliance with a legal obligation)
- Data processed: billing data, Company ID, Tax ID, VAT number (if available)
- Retention period: 10 years
3.3 Protection of Rights and Legal Claims
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the trader)
- Data processed: all data from the order and communication
- Retention period: for the duration of the limitation period (5 years)
3.4 Responding to Inquiries
(Contact Form)
- Legal basis: Art. 6(1)(a) GDPR (consent) or Art. 6(1)(b) GDPR (performance of a contract)
- Data processed: name, email, message content
- Retention period: for the time necessary to handle the inquiry; if no contractual relationship arises, the data will be deleted
3.5 Sending Commercial Communications
(With Consent Only)
- Legal basis: Art. 6(1)(a) GDPR (consent)
- Data processed: email, name
- Retention period: until consent is withdrawn
- You may withdraw your consent at any time
3.6 Analytics and Marketing Purposes
- Legal basis: Art. 6(1)(a) GDPR (consent)
- Data processed: anonymised data about website usage
- For details, see our Cookie Policy
4. Recipients of Personal Data
We do not sell your personal data. Data may be shared with the following categories of recipients:
- Delivery companies (Slovenská pošta, a.s., courier services)
- Payment service providers (banks)
- IT service providers (hosting, website maintenance)
- Accounting services
- Analytics service providers (Google Analytics)
- Marketing service providers (Meta / Facebook Pixel)
- State authorities (tax office, courts) in the case of a legal obligation
All processors have concluded a personal data processing agreement in accordance with Art. 28 GDPR.
5. Transfer of Personal Data
to Third Countries
In connection with the use of analytics and marketing tools, some data may be transferred to the USA:
- Google LLC (Google Analytics) — based on EU-approved standard contractual clauses
- Meta Platforms Inc. (Facebook Pixel) — based on the EU adequacy decision
Transfers occur only on the basis of your consent to analytics or marketing cookies.
Data from orders and contact forms is not transferred outside the European Economic Area.
6. Your Rights
Under the GDPR, you have the following rights:
6.1 Right of Access (Art. 15 GDPR)
You have the right to information about the processing of your personal data and to a copy of the processed data.
6.2 Right to Rectification
(Art. 16 GDPR)
You have the right to request correction of inaccurate or supplementation of incomplete personal data.
6.3 Right to Erasure (Art. 17 GDPR)
You have the right to request the deletion of your personal data. This right is subject to statutory exceptions (accounting obligations, legal claims).
6.4 Right to Restriction of Processing
(Art. 18 GDPR)
You have the right to request restriction of the processing of your data, for example in the case of disputed accuracy of data or unlawful processing.
6.5 Right to Data Portability
(Art. 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transfer the data to another controller.
6.6 Right to Object (Art. 21 GDPR)
You have the right to object to the processing of your personal data on grounds relating to your particular situation. For direct marketing, you have an absolute right to object and the controller must immediately cease processing.
6.7 Right to Withdraw Consent
If processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing before its withdrawal.
You can withdraw cookie consent by clicking the "Cookie Settings" icon at the bottom of the page.
You can withdraw newsletter consent via the "Unsubscribe" link in every email, or contact us at info@wovenrag.com.
6.8 Right to Lodge a Complaint
(Art. 77 GDPR)
You have the right to lodge a complaint with the supervisory authority:
Úrad na ochranu osobných údajov Slovenskej republiky Hraničná 12 820 07 Bratislava 27 Slovak Republic Phone: +421 2 3231 3214 Email: statny.dozor@pdp.gov.sk Website: https://dataprotection.gov.sk/
How to Exercise Your Rights
To exercise your rights, contact us at info@wovenrag.com or in writing at the company's registered office. We will respond to your request without undue delay, within a maximum of 1 month from receipt.
7. Data Security
We have implemented appropriate technical and organisational measures to protect your personal data in accordance with Art. 32 GDPR, including:
- Encryption of personal data during transfer (HTTPS/SSL)
- Access control for personal data
- Regular data backup
- Security of IT systems
8. Children's Privacy
Our website is not directed at persons under the age of 16. We do not knowingly process personal data of persons under the age of 16.
9. Voluntary Provision of Data
The provision of personal data when placing an order is a contractual requirement. Without the provision of personal data, it is not possible to conclude and perform the purchase contract (the order cannot be fulfilled, the goods cannot be delivered).
The provision of personal data via the contact form and newsletter subscription is voluntary.
10. Changes to This Privacy Policy
We reserve the right to update this privacy policy. We will inform you of any significant changes through a notice on our website. The current version is always available on this page.
Last updated: 1 December 2025
11. Related Documents
- Terms & Conditions — Art. IX contains provisions on the protection of personal data in relation to the purchase contract
- Cookie Policy — detailed information about cookies and analytics tools
12. Contact
If you have any questions about the protection of your personal data, contact us:
Email: info@wovenrag.com Postal address: yknot s. r. o. Ďurgalova 2860/2 831 01 Bratislava — Nové Mesto Slovak Republic
This policy was created in accordance with EU Regulation 2016/679 (GDPR) and Act No. 18/2018 Coll. on the Protection of Personal Data.