Terms of personal data protection

Privacy Policy

Document version: 2.0
Effective from: January 25, 2026
Last update: January 25, 2026
Previous version: June 1, 2024

Who we are

We are BALIZA, s.r.o., registered office at Vysoká 28, 811 06 Bratislava, Company ID: 45 663 726, registered in the Commercial Register of the Bratislava III District Court, Section Sro, Insert No. 94261/B.

We operate an online store on the website www.gdmats.eu

When providing our services, selling goods, and operating our website, we process some of your personal data. We want you to understand what data we process, why we need it, and how we protect it.

Legal basis: The processing of personal data is governed primarily by Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) ("GDPR") and the Slovak Act on ensuring the protection of natural persons in the processing of personal data, effective from January 1, 2026.

I. Processing of Personal Data

In this section, you will learn what data we process, why we need it, and how long we retain it.

1. Contact Form and Pre-Purchase Communication

What data do we process?

If you contact us regarding our products and services via the contact form, email, or phone, we process:

  • First and last name
  • Email address
  • Phone number
  • Content of your message or inquiry

Why do we process this data?

Based on the submitted personal data, we will contact you so we can:

  • Answer your questions about our products and services
  • Provide you with information needed for purchasing decisions
  • Prepare an individual offer according to your requirements
  • Communicate with you before concluding a contract

Legal basis for processing

Article 6(1)(b) GDPR – performance of a contract or taking steps at your request prior to entering into a contract.

❗ Notice: Without providing this data, we will not be able to contact you and provide you with necessary information about our products and services.

How long do we retain the data?

If we do not establish further cooperation, we will process your personal data for a maximum of 4 years from our last communication. After that, we will securely delete them.

2. Purchase of Goods or Services

What data do we process?

When you make a purchase with us, we need the following data to process your order:

Billing information:

  • First and last name (or company name)
  • Billing address
  • Email address
  • Phone number
  • IČO, DIČ (for business orders)

Delivery information:

  • Recipient's name
  • Delivery address (if different from billing address)
  • Phone number for courier

Order information:

  • Information about purchased products
  • Price and payment method
  • Order communication history
  • Complaints and their resolution

Why do we process this data?

We need personal data for:

  • Order processing – delivery of goods to the correct address, to the correct person
  • Communication about order status – information about shipping, delivery, possible problems
  • Invoice issuance – fulfillment of accounting and tax obligations
  • Complaint handling – resolution of possible problems with goods
  • Warranty service provision – warranty and service intervention records

Legal basis for processing

  • Article 6(1)(b) GDPR – performance of a contract (delivery of goods, provision of service)
  • Article 6(1)(c) GDPR – compliance with our legal obligation (accounting, taxes, complaints)
❗ Notice: Without providing this data, we cannot conclude a contract and deliver goods or services to you.

How long do we retain the data?

We retain data during the term of the contract and afterwards:

  • 3 years from the last provision of service or delivery of goods (in case of complaints)
  • 10 years – accounting documents (according to accounting law)

3. Newsletter and Marketing Communication

What data do we process?

  • Email address
  • First and last name (if provided)
  • Your purchase history (to customize offers)

Why do we process this data?

We use your email address to send:

  • Information about new products in our offer
  • Special offers and discounts
  • Tips for products similar to those you have purchased
  • Information about promotions and sales

When can we send you marketing?

We will send you marketing emails if:

  1. You have already purchased something from us and have not refused to receive marketing communications, OR
  2. You have given us consent to receive the newsletter

Legal basis for processing

  • Article 6(1)(f) GDPR – our legitimate interest (marketing to existing customers)
  • Article 6(1)(a) GDPR – your consent (if you requested the newsletter without a purchase)

How to unsubscribe from the newsletter?

You can easily cancel the newsletter at any time:

We will process your unsubscription within 48 hours.

How long do we retain the data?

  • 5 years from your last purchase
  • After unsubscribing, we immediately remove your email address from the marketing database

II. Who Has Access to Your Data?

We only share your data with verified partners who help us operate the online store and deliver your ordered goods.

Our Processors and Partners

To ensure the operation of the online store, we cooperate with the following companies that have access to your personal data:

Technical Operation of the Online Store

Partner Purpose Processed Data
Shoptet a.s.
Dvořeckého 628/8, Břevnov
169 00 Praha 6, Czech Republic
IČO: 289 35 675
E-commerce platform, website hosting All data necessary for operating the online store (orders, customer data, communication)

Shipping and Logistics

Partner Purpose Processed Data
General Logistics Systems Slovakia s.r.o. (GLS) Goods delivery Name, address, phone, email
DPD Slovakia s.r.o. Goods delivery Name, address, phone, email
FedEx Express Slovakia s.r.o. International goods delivery Name, address, phone, email
UPS SCS (Slovensko), s.r.o. International goods delivery Name, address, phone, email
Packeta Slovakia s.r.o. Goods delivery to Z-BOX pickup points Name, address, phone, email

Payment Services

Partner Purpose Processed Data
ShoptetPay
(provided by Shoptet a.s.)
Processing online payments by card, Apple Pay, Google Pay Name, email, partial payment data (card payment data is encrypted and processed securely in accordance with PCI DSS standard)

Email Communication

Partner/Service Purpose Processed Data
Roundcube Webmail Management of email communication with customers Email address, name, email communication content

Accounting and Tax Advisory

Partner Purpose Processed Data
Moravec s.r.o. Bookkeeping, tax and payroll advisory Billing data, order and payment data necessary for accounting

Security and Data Protection

How do we protect your data?

  • Encryption – All data is transferred via secure HTTPS connection with SSL/TLS certificate
  • Secure servers – Data is stored on protected servers with regular backups
  • Limited access – Only authorized employees and contractual partners have access to the data
  • Processing agreements – We have concluded personal data protection agreements with all partners according to GDPR
  • Regular updates – We regularly update systems against security threats
  • Firewall and antivirus – Protection against unauthorized access and malware
  • Monitoring – Regular security checks and detection of unusual activities

Data Transfer Outside the EU

We process your personal data EXCLUSIVELY within the territory of the European Union. We do not transfer data to third countries outside the EU.

III. Your Rights

You have the right to control how we process your personal data. Here is an overview of your rights and how to exercise them.

You have the following rights:

1. Right of access to data

You have the right to know what data we process about you. You can request a copy of all data.

2. Right to rectification

If your data is incorrect or incomplete, you can request its correction.

3. Right to erasure ("right to be forgotten")

You can request the deletion of your data if it is no longer necessary or if you withdraw consent.

4. Right to restriction of processing

You can request temporary suspension of processing your data.

5. Right to data portability

You can obtain your data in a machine-readable format and transfer it to another controller.

6. Right to object

You can object at any time to processing based on legitimate interest (e.g., marketing).

7. Right to lodge a complaint

If you believe we are violating your rights, you can file a complaint with the Office for Personal Data Protection of the Slovak Republic.

How to exercise your rights?

Contact us:

Email: gdmats@gdmats.eu

Postal address: BALIZA, s.r.o., Vysoká 28, 811 06 Bratislava

By phone: +421 903 692 288


We will respond to you within 30 days of receiving your request.

Supervisory Authority

If you believe that we are not handling your data correctly, you have the right to file a complaint:

Office for Personal Data Protection of the Slovak Republic
Hraničná 12
820 07 Bratislava 27
www.dataprotection.gov.sk
Email: statny.dozor@pdp.gov.sk

IV. Use of Cookies

Cookies are small text files that improve the functioning of our website and help us tailor content to your needs.

What are cookies?

Cookies are text files containing a small amount of information that are downloaded to your device (computer, phone, tablet) when you visit our website. Cookie files are then sent back to the website with each subsequent visit.

What do we use cookies for?

Cookie files perform various tasks:

  • Enable website functionality – login, shopping cart, language settings
  • Remember your preferences – so you don't have to enter the same information repeatedly
  • Improve your user experience – faster loading, personalized content
  • Help us improve the website – we analyze how visitors use our pages
  • Display relevant advertising – tailored to your interests

What types of cookies do we use?

1. Necessary cookies (always active)

These cookies are necessary for the basic functioning of the website and cannot be disabled. Without them, the website could not function properly.

Examples:

  • Shopping cart maintenance
  • Secure login
  • Cookie consent memory

2. Analytical/Statistical cookies

Allow us to recognize and determine the number of visitors and track how our visitors use the website. They help us improve the way the pages work.

We only activate these cookies with your prior consent.

3. Marketing/Advertising cookies

Used to track preferences and allow displaying advertising that best matches your interest and online behavior.

We only activate these cookies with your prior consent.

Overview of Used Cookies

IMPORTANT: The following table contains typical cookies for Shoptet online stores. The exact list of cookies for your website needs to be verified in the browser's developer tools (F12 → Application → Cookies on www.gdmats.eu) or by contacting your web developer/Shoptet support. This list serves only as a template and must be modified according to actually used cookies.
Cookie Name Publisher Purpose and Description Duration
PHPSESSID gdmats.eu Session identifier for maintaining shopping cart state and logged-in user Session (until browser closure)
cookies_consent gdmats.eu Stores your cookie consent and preference settings 12 months
shp_cart_guid gdmats.eu (Shoptet) Shopping cart identification 30 days
shp_user_id gdmats.eu (Shoptet) Logged-in user identification 14 days / until logout
_ga Google Analytics Distinguishes individual website visitors for statistical purposes 2 years
_gid Google Analytics Distinguishes users for analytical purposes 24 hours
_gat Google Analytics Used to limit request rate 1 minute
_fbp Facebook Used to display advertising products on Facebook (Facebook Pixel) 3 months
_gcl_au Google AdSense Used by Google AdSense to experiment with advertising efficiency 3 months

Note: The exact list and description of cookies may be updated. You can find the current cookie list in your browser's developer tools (F12 key → Application/Storage tab → Cookies).

How to manage cookies?

You have full control over cookies:

1. Setting via our cookie banner

When you first visit the site, you will see a banner with the option to accept or reject analytical and marketing cookies. You can change your settings at any time in the cookie settings on our website.

2. Setting in your browser

You can manage cookies directly in your internet browser settings:

Warning: Complete blocking of cookies may limit website functionality and some features may not work properly (e.g., shopping cart, login).

Third-Party Cookies

Please note that third parties (including, for example, external service providers such as Google Analytics, Facebook Pixel) may also use cookies and/or access data collected by cookies on our websites. These services have their own privacy policies, which we recommend reviewing:

V. Additional Information

Data Protection Officer (DPO)

Our company does not have a designated Data Protection Officer (DPO), as the scope of our processing of personal data does not require it under Article 37 GDPR.

All questions regarding the protection of personal data can be addressed directly to email: gdmats@gdmats.eu or by phone at +421 903 692 288

Automated Decision-Making and Profiling

In our company, there is no decision-making based on automated processing or profiling that would have legal effects or significantly affect you within the meaning of Article 22 GDPR.

Security Incidents

In the event of a personal data security breach that could pose a high risk to your rights and freedoms, we will inform you without undue delay in accordance with Article 34 GDPR.

Contact for Questions

If you have any questions regarding the protection of personal data, contact us:

Email: gdmats@gdmats.eu

Address: BALIZA, s.r.o., Vysoká 28, 811 06 Bratislava

Phone: +421 903 692 288

We will respond as soon as possible, no later than 30 days from receipt of your request.

Changes to These Policies

We may update these policies from time to time, for example due to:

  • Changes in legislation (e.g., new law on personal data protection from January 1, 2026)
  • Changes in our business processes
  • Addition of new features or services
  • Update of used technologies

We will inform you about significant changes:

  • By notice on the website
  • By email (if we have your address and communication is activated)

We recommend that you regularly review these policies to stay informed about how we protect your data.

These policies are effective from January 25, 2026
Version 2.0 – Updated in accordance with legislative changes effective from January 1, 2026
Previous version: 1.0 (effective from June 1, 2024)


BALIZA, s.r.o. | IČO: 45 663 726 | Vysoká 28, 811 06 Bratislava
www.gdmats.eu | gdmats@gdmats.eu | +421 903 692 288