Privacy Policy

PRIVACY POLICY

Effective date: 13/8/2026

This Privacy Policy explains how RIVERRA SRO, established and operating in the Slovak Republic, processes personal data in connection with the provision and sale of online services.

We process personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”), Act No. 18/2018 Coll. on Personal Data Protection, as amended, Act No. 452/2021 Coll. on Electronic Communications, as amended, where applicable, and other relevant Slovak and European legislation.

This Privacy Policy applies to visitors to our website, customers, registered users, subscribers, persons contacting us, and other individuals whose personal data we process in connection with our online services.


1. DATA CONTROLLER

The controller responsible for processing your personal data is:

RIVERRA SRO
CINOVA 1915/7B
90041, ROVINKA
Slovak Republic

Company registration number (IČO): 54886309
Tax identification number (DIČ): 2121830711

Represented by: Frank van Kronenburg

Email: riverra@riverra-marketing.com
Telephone: 00421948952481
Website: www.riverra-marketing.com

Hereinafter referred to as “we”, “us”, “our” or the “Company”.


2. APPLICABLE LEGISLATION

The processing of personal data is primarily governed by:

  • Regulation (EU) 2016/679 (GDPR);

  • Act No. 18/2018 Coll. on Personal Data Protection, as amended;

  • Act No. 452/2021 Coll. on Electronic Communications, as amended, where applicable;

  • applicable Slovak consumer protection legislation;

  • applicable Slovak and European legislation governing electronic commerce and contractual relationships.

Where our customers are consumers, additional mandatory consumer protection rules may apply.


3. PERSONAL DATA WE COLLECT

Depending on how you use our website and services, we may collect and process the following information.

3.1 Identification and contact information

This may include:

  • first name and surname;

  • company name;

  • email address;

  • telephone number;

  • billing address;

  • delivery address, where applicable;

  • country of residence;

  • company registration details, where applicable;

  • VAT number, where applicable.

3.2 Account information

If you create an account with us, we may process:

  • username;

  • email address;

  • password or authentication information;

  • account settings;

  • subscription information;

  • purchase history;

  • service usage information.

We do not store passwords in plain text. Where passwords are used, they are stored using appropriate security measures.

3.3 Payment and billing information

When you purchase our services, we may process:

  • billing information;

  • invoice details;

  • transaction amount;

  • payment status;

  • payment method;

  • VAT and tax information.

Where payments are processed through an external payment provider, payment card information may be processed directly by the payment provider rather than by us.

3.4 Communications

If you contact us, we may process:

  • your name;

  • email address;

  • telephone number;

  • the content of your message;

  • information relating to your customer account or service;

  • correspondence history.

3.5 Technical information

When you use our website or online services, certain technical information may automatically be collected, such as:

  • IP address;

  • browser type;

  • operating system;

  • device type;

  • language settings;

  • date and time of access;

  • pages visited;

  • referring website;

  • technical logs;

  • information concerning website interactions.

Such information may be used for security, technical operation, troubleshooting and improving our services.


4. HOW WE COLLECT PERSONAL DATA

We may collect personal data:

  • directly from you;

  • when you create an account;

  • when you purchase a service;

  • when you subscribe to a service;

  • when you submit a contact form;

  • when you communicate with us;

  • when you use our website or online platform;

  • through cookies and similar technologies;

  • from payment providers or other service providers involved in providing our services.

We only collect information that is reasonably necessary for the relevant purpose.


5. PURPOSES AND LEGAL BASES FOR PROCESSING

5.1 Providing online services

We process personal data where necessary to provide the online service you have purchased or requested.

This may include:

  • creating and managing your account;

  • providing access to purchased services;

  • processing subscriptions;

  • managing customer accounts;

  • providing customer support;

  • processing payments;

  • managing access rights;

  • communicating important information concerning your service.

The legal basis is generally Article 6(1)(b) GDPR, where processing is necessary for the performance of a contract.

5.2 Processing orders and payments

We process personal data to process purchases, subscriptions, payments and invoices.

This includes:

  • confirming orders;

  • processing payments;

  • issuing invoices;

  • managing refunds;

  • handling cancellations;

  • maintaining transaction records.

The legal basis may be Article 6(1)(b) GDPR or Article 6(1)(c) GDPR where processing is necessary to comply with legal obligations.

5.3 Customer support

We process your contact details and information concerning your account or purchase to respond to questions and provide technical or customer support.

The legal basis may be Article 6(1)(b) or Article 6(1)(f) GDPR, depending on the circumstances.

5.4 Legal and accounting obligations

We may process personal data to comply with applicable legal obligations, including:

  • accounting;

  • taxation;

  • invoicing;

  • financial reporting;

  • responding to lawful requests from public authorities;

  • maintaining legally required records.

The legal basis is Article 6(1)(c) GDPR.

5.5 Security and fraud prevention

We may process technical and account information to:

  • protect our website and systems;

  • prevent unauthorized access;

  • detect fraudulent activity;

  • prevent misuse of our services;

  • investigate security incidents;

  • protect our rights and property.

The legal basis is generally Article 6(1)(f) GDPR.

5.6 Improving our services

We may use certain information to understand how our website and services are used and to improve their functionality, performance and user experience.

Where consent is required, we will obtain the appropriate consent before carrying out such processing.


6. MARKETING AND NEWSLETTERS

Where legally permitted, we may send you information about our services, products, special offers and updates.

Where prior consent is legally required, we will obtain your consent before sending marketing communications.

You may unsubscribe from marketing communications at any time by:

  • clicking the unsubscribe link in the relevant email;

  • contacting us directly; or

  • using the relevant account settings, where available.

Withdrawal of marketing consent does not affect the lawfulness of processing carried out before the withdrawal.

We will not sell your personal data to third parties for their own marketing purposes.


7. COOKIES

Our website may use cookies and similar technologies.

Cookies may be used for:

  • essential website functionality;

  • authentication;

  • maintaining login sessions;

  • security;

  • remembering preferences;

  • analytics;

  • improving website performance;

  • marketing and advertising, where applicable.

Essential cookies

Essential cookies may be used where they are necessary for the website or online service to function properly.

Optional cookies

Non-essential cookies, including certain analytics, advertising and tracking cookies, will only be used where the required legal basis has been obtained.

Where consent is required, you can accept or reject optional cookies through our cookie-management system.

You can also manage cookies through your browser settings.


8. THIRD-PARTY SERVICES

We may use third-party service providers to operate our online business.

These may include:

  • payment providers;

  • website hosting providers;

  • cloud storage providers;

  • email service providers;

  • customer relationship management systems;

  • accounting software;

  • analytics providers;

  • customer support platforms;

  • fraud prevention services;

  • advertising platforms;

  • communication tools.

These providers may process personal data on our behalf where necessary to provide their services.

Where required, we enter into appropriate data processing agreements in accordance with Article 28 GDPR.


9. PAYMENT PROCESSING

Payments for our online services may be processed by external payment providers.

Depending on the payment method selected, payment providers may process information such as:

  • name;

  • billing information;

  • payment details;

  • transaction information;

  • IP address;

  • payment confirmation information.

Payment card details may be processed directly by the payment provider and may not be accessible to us.

The relevant payment provider’s own terms and privacy policy may also apply.


10. INTERNATIONAL DATA TRANSFERS

We primarily process personal data within the European Union and European Economic Area.

Some of our service providers may operate outside the EU/EEA.

Where personal data is transferred outside the EU/EEA, we will ensure that an appropriate legal transfer mechanism is used in accordance with the GDPR, such as:

  • an adequacy decision;

  • Standard Contractual Clauses;

  • or another legally recognized safeguard.


11. DATA RETENTION

We retain personal data only for as long as necessary for the purposes for which it was collected or for as long as required by applicable law.

For example:

Customer account information: retained while your account remains active and for a reasonable period thereafter where necessary.

Transaction and invoice information: retained for the period required by applicable Slovak accounting and tax legislation.

Customer support correspondence: retained for as long as reasonably necessary to handle your request and protect our legitimate interests.

Marketing information: retained until you withdraw your consent or otherwise object, unless another lawful basis applies.

Security logs: retained for a limited period appropriate to the security purpose, unless longer retention is necessary to investigate an incident or protect legal rights.

After the applicable retention period, personal data will be deleted, anonymized or securely destroyed.


12. YOUR RIGHTS

Under the GDPR and applicable Slovak legislation, you have the following rights, subject to applicable legal conditions and limitations.

Right of access

You may request confirmation as to whether we process your personal data and request access to that data.

Right to rectification

You may request correction of inaccurate or incomplete personal data.

Right to erasure

You may request deletion of your personal data in certain circumstances.

This right is not absolute. We may retain information where required by law or where necessary to establish, exercise or defend legal claims.

Right to restriction of processing

You may request restriction of processing in certain circumstances.

Right to data portability

Where applicable, you may request to receive personal data you have provided to us in a structured, commonly used and machine-readable format.

Right to object

You may object to processing based on our legitimate interests where grounds relating to your particular situation apply.

You have an unconditional right to object to processing for direct marketing purposes.

Right to withdraw consent

Where processing is based on consent, you may withdraw your consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.


13. AUTOMATED DECISION-MAKING

We do not make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals, unless expressly disclosed and permitted by applicable law.

Where automated tools are used for security, fraud prevention or service functionality, they will not be used to make unlawful decisions concerning you.


14. DATA SECURITY

We use appropriate technical and organizational measures to protect personal data against:

  • unauthorized access;

  • unauthorized disclosure;

  • loss;

  • destruction;

  • alteration;

  • unlawful processing;

  • security breaches.

Depending on the nature of our services, security measures may include encryption, access controls, authentication systems, secure hosting and monitoring.

No internet-based service can be guaranteed to be completely secure, and you should also take reasonable steps to protect your account information and login credentials.


15. CHILDREN

Our online services are primarily intended for adults and businesses.

We do not knowingly collect personal data from children where such collection is not legally permitted.

If you believe that a child has provided personal data to us without appropriate authorization, please contact us.


16. DATA DISCLOSURE TO AUTHORITIES

We may disclose personal data to public authorities, courts, law enforcement agencies, tax authorities or other competent bodies where required by applicable Slovak or European legislation or where necessary to establish, exercise or defend legal claims.


17. COMPLAINTS

If you believe that your personal data has been processed unlawfully, we encourage you to contact us first so that we can investigate the matter.

You also have the right to lodge a complaint with the competent supervisory authority.

In Slovakia, the supervisory authority is:

Office for Personal Data Protection of the Slovak Republic
Hraničná 12
820 07 Bratislava 27
Slovak Republic

Website: https://dataprotection.gov.sk

You may also contact the supervisory authority in the EU/EEA country where you normally reside, work or where the alleged infringement occurred, where applicable.


18. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect:

  • changes to our online services;

  • changes to our business;

  • changes to our technology;

  • changes to our service providers;

  • changes in applicable legislation;

  • changes in data protection requirements.

The latest version will be published on our website.

The effective date will always be stated at the beginning of the Privacy Policy.


19. CONTACT DETAILS

For questions, requests or complaints concerning the processing of your personal data, please contact:

RIVERRA SRO
CINOVA 1915/7B
90041, ROVINKA
Slovak Republic

IČO: 54886309
DIČ: 2121830711

Email: riverra@riverra-marketing.com
Telephone: 00421948952481
Website: www.riverra-marketing.com

Effective date: 13/8/2026