CLIMBING HOLDS
MACROS

PRIVACY POLICY

This privacy policy describes how the controller processes personal data of users of the website and online store origo-holds.eu, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Slovenian legislation.

  1. Controller of personal data

Controller: ROGAN, storitve, d.o.o.

Address: Spodnje Stranje 34, 1242 Stahovica, Slovenia

Registration number: 3485757000

VAT ID: SI53430336

Contact: info@origo-holds.eu

  1. What personal data do we process

We process the following categories of personal data:

Order data (WooCommerce)

first and last name

delivery and billing address

email and phone

ordered products, amounts, order history

Payment data (Stripe)

technical and security transaction data

we do not receive or store full card data

Delivery data

name, address and contact for delivery purposes

Technical data

IP address

device and browser data

server logs

Analytic and marketing data (only with consent)

data on site usage via Google Analytics

data for advertising via Meta Pixel

  1. Purpose and legal basis of processing

Order fulfillment, delivery, customer support
Legal basis: performance of the contract (GDPR 6(1)(b))

Payments and fraud prevention
Legal basis: performance of the contract and legitimate interest (GDPR 6(1)(b), 6(1)(f))

Accounting, tax obligations, complaints
Legal basis: legal obligation (GDPR 6(1)(c))

Analytics and marketing
Legal basis: user consent (GDPR 6(1)(a))

Website security
Legal basis: legitimate interest (GDPR 6(1)(f))

  1. Recipients of personal data

We may transfer personal data to the following categories of processors:

Hosting and domain: Webicom d.o.o.

Payment processing: Stripe

Delivery up to approx. 100 kg: DPD, GLS

Heavy transport: Intereuropa, cargo-partner

Analytics: Google Analytics (only with consent)

Advertising: Meta Pixel (only with consent)

  1. Transfers to third countries

Some providers (e.g. Google, Meta, Stripe) may process data outside the EU/EEA.

Transfers are protected by appropriate mechanisms, such as:

EU-US Data Privacy Framework

Standard Contractual Clauses (SCC)

  1. Data Retention

Invoices and Orders: in accordance with tax and accounting legislation

Analytical and Marketing Data: until consent is withdrawn

Technical Logs: limited time for security and diagnostics

  1. Individual Rights

According to the GDPR, you have the following rights:

Right of Access

Right of Rectification

Right of Erasure

Right to Restrict Processing

Right of Objection

Right to Data Portability

Right to Withdraw Consent at Any Time

Requests can be sent to: info@origo-holds.eu

Supervisory Authority: Information Commissioner of the Republic of Slovenia

  1. Cookies

We use essential cookies for the operation of the online store.

Analytical and marketing cookies are loaded exclusively based on consent.

Consent management is enabled via the cookie banner.

Details are described in the Cookie Policy.

  1. Security

We use appropriate technical and organizational measures:

HTTPS/TLS

access control

backups

Complete security on the Internet cannot be guaranteed.

  1. Changes to the Privacy Policy

We may update the policy from time to time.

The version published on the website applies.

Last updated: 24. 12. 2025

Copyright © 2024 ORIGO CENTER. All Rights Reserved.