Personal Data Protection Policy
Website and Personal Data Operator
This policy applies to the processing of all personal data carried out by SHtudio.eu (hereinafter: the Operator) or on its behalf.
Operator Information:
Photo studio:
SHtudio.eu
Ulica heroja Šaranoviča 23
SI-2000 Maribor
Slovenia
Parent company:
Plastikfantastik, Saša Huzjak s.p.
Sernčeva ulica 10
SI-2000 Maribor
Slovenia
phone: +386 41 897 899
e-mail: info@shtudio.eu
Personal Data
Personal data means any information relating to an identified or identifiable individual (hereinafter: the User) who visits our Website. Personal data may include, in particular: name, surname, email address, telephone number, IP address, location data, or other information that allows the identification of an individual.
Purposes and Legal Basis for Data Processing
The Operator collects and processes the User’s personal data based on the following legal grounds:
- Consent of the individual (e.g., subscribing to newsletters, using a contact form),
- Performance of a contract or steps prior to entering into a contract (e.g., service inquiries, ordering services),
- Legal obligation (e.g., storing invoices in accordance with tax legislation),
- Legitimate interests of the Operator (e.g., improving user experience, ensuring website security, analyzing website usage).
If the processing of personal data is based on consent, the User may withdraw their consent at any time by sending a request to the Operator’s email address.
Use and Protection of Personal Data
The Operator adheres to the principle of data minimization – collecting and processing only the personal data that is strictly necessary to achieve a specific purpose. Personal data is used in particular for:
- communication with Users,
- providing information about news, events, or offers,
- improving the content and functionality of the Website,
- delivering the services requested by Users.
The Operator will not disclose personal data to third parties, except if:
- there is a legal basis for doing so (e.g., contractual processors such as hosting providers, email service providers, etc.),
- it is necessary to comply with a legal obligation, or
- the User has given explicit consent for such disclosure.
The Operator ensures the security of personal data through appropriate technical and organizational measures to prevent loss, misuse, or unauthorized access.
The User is responsible for providing accurate and truthful data. The Operator shall not be liable for any consequences resulting from inaccurate or false data.
The User is also responsible for protecting their own data by ensuring the security of their computer, passwords, email account, and internet connection.
Collected Data
The Operator collects the following types of data on this Website:
Website Traffic Data
When a User visits our Website, certain data is automatically stored on our servers for the purpose of analyzing visits and managing the system. Analytical data is collected only if the User has consented to the use of analytical cookies. This data includes:
- the version of the browser and operating system used to access the Website,
- screen resolution,
- date and time of the visit,
- IP address (partially anonymized),
- country and city from which the User visits the Website (estimated based on IP address),
- the URLs of websites through which the User arrived at our Website,
- individual pages visited by the User,
- time spent on the Website and on individual pages,
- search terms entered by the User to find our Website.
For more information, see also the Cookies page.
Contact Form or Service Registration via Form
If a User uses a contact form or registers/orders a service via a form, the Operator collects the following data:
- first name,
- last name,
- email address,
- telephone number,
- device type, browser name and version, and the partial IP address from which the User confirmed consent for processing this data,
- date and time of opening sent messages and date and time of clicks on links within messages for newsletter subscribers.
Cookies and Third-Party Tools
The Website uses cookies and tools from third-party providers (e.g., Matomo, Google Analytics, YouTube) for analytics, improving website performance, or displaying content.
Detailed information about the cookies used and their retention period is available on the Cookies page of this Website.
Use of Social Media Plugins
The Website may include plugins for social media platforms, such as Facebook, YouTube, Vimeo, and others. These services are provided by external companies (hereinafter: Providers).
Through these plugins, a Provider receives information about which content on our Website the User has accessed. If the User is logged into their social media account (e.g., Facebook) while visiting the Website, the Provider may associate the User’s activities on our Website with their account. If the User interacts with the plugins (e.g., clicks the “Like” button or posts a comment), this information is transmitted to the Provider and stored on their servers.
If the User does not wish the Provider to link their visit to the Website with their social media account, they must log out of the respective social media platform before visiting the Website.
Additional information on the collection and use of data, as well as on Users’ privacy rights and options, is available on the Providers’ websites:
Retention Period and Storage of Personal Data
The Operator stores personal data on rented servers provided by hosting providers, and may also store data with companies whose tools are used (e.g., YouTube player).
Personal data is retained only as long as necessary to achieve the purpose for which it was collected, or in accordance with legal retention periods:
- Data collected based on consent (e.g., newsletter subscription, use of a contact form) is retained until the consent is withdrawn.
- Data collected based on a contractual relationship is retained as long as necessary to fulfill contractual obligations and comply with applicable regulations (e.g., tax laws).
- After the retention period expires, data is permanently deleted or anonymized.
If a User no longer wishes to receive our content, unsubscribes from newsletters, or withdraws their consent for the processing of personal data for this purpose, their data will be blocked and no longer used for this purpose.
Transfer of Personal Data to Third Countries
The Operator generally does not transfer personal data to third countries (countries outside the European Economic Area – EEA).
In certain cases, however, personal data may be processed by service providers located or storing data in third countries (e.g., when using services such as Google Analytics, YouTube, Vimeo, etc.). In these cases, the transfer of personal data is carried out only if:
- the European Commission has issued an adequacy decision for the respective country, or
- appropriate data processing agreements have been concluded with the service provider, including standard contractual clauses adopted by the European Commission, or other suitable safeguards that ensure the same level of data protection as required under the GDPR.
Users are informed that when using external plugins or services of third-party providers (e.g., Google, Meta, Vimeo), their personal data may also be processed in third countries, over which the Operator has no control regarding processing procedures.
We recommend that Users consult the privacy policies of these providers for additional information.
User Rights
In accordance with Regulation (EU) 2016/679 (GDPR), the User has the following rights:
- the right to access their personal data,
- the right to rectify inaccurate or incomplete data,
- the right to erase personal data (“right to be forgotten”),
- the right to restrict processing,
- the right to object to processing,
- the right to data portability.
To exercise these rights or to obtain additional information, the User may contact the Operator via the email address provided above.
The Operator will respond to requests without undue delay, and no later than 30 days after receipt.
If the User believes that their personal data has been processed in violation of the law, they may lodge a complaint with:
Informacijski pooblaščenec Republike Slovenije
Zaloška 59
1000 Ljubljana
phone: +386 1 230 97 30
e-mail: gp.ip@ip-rs.si
Changes to the Privacy Policy
The Operator reserves the right to modify this Privacy Policy at any time in order to ensure compliance with applicable law or to improve the transparency of data processing. All changes will be published on this Website, together with the date of the latest update.
By using the Website, the User confirms that they have read, understood, and agree to the entire content of this Privacy Policy.
This document was published on: 6 January 2020
This document was published last reviewed on: 29 January 2026