Privacy Policy

Effective date: January 29, 2026

Controller The controller responsible for processing your personal data is: Štefan Marinko, Stefan Pump-Turbine, Email: info@stefan-pump-turbine.com

(Hereinafter referred to as "we", "us", "our", or the "Company".)

We are committed to protecting your privacy in compliance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), the Slovenian Personal Data Protection Act (ZVOP-2), and other applicable laws.

1. Scope This Privacy Policy applies to personal data we collect through:

  • Your visits to and use of the Website https://stefan-pump-turbine.com/ (including subpages, blog, and any future features).
  • Contact/inquiry forms, email communications, or other interactions with us.
  • Any cookies or similar technologies (see our separate Cookie Policy).

It does not apply to third-party websites linked from our site, or to data processed by partners/clients in separate contexts.

2. Personal Data We Collect We collect only the personal data necessary for our legitimate business activities (primarily B2B/informational purposes). Categories include:

  • Contact and identification data: Name, surname, email address, phone number (optional), company name, position/job title, country/location (provided voluntarily via contact forms or email).
  • Technical / usage data: IP address, browser type/version, operating system, device information, pages visited, time/date of access, referral source (automatically collected via server logs).
  • Communication data: Content of messages/inquiries submitted to us.
  • Cookies & similar technologies: See our Cookie Policy for details (necessary cookies always; analytics only with consent).

We do not collect sensitive/special categories of data (e.g., health, political opinions), payment details (no e-commerce), or data from children.

3. Sources of Personal Data

  • Directly from you (when you submit a contact form, send an email, or interact with us).
  • Automatically from your device/browser during Website visits.
  • Rarely from public sources (e.g., LinkedIn/company websites) if we contact you proactively for legitimate business reasons (e.g., potential partnership).

4. Purposes and Legal Bases for Processing We process your personal data only when we have a lawful basis (Art. 6 GDPR):

 
 
Purpose Personal Data Involved Legal Basis Retention Period
Responding to inquiries, providing information about products/services (pumps, turbines, etc.) Name, email, company, message content Pre-contractual measures (Art. 6(1)(b)) or legitimate interest (Art. 6(1)(f)) – responding to business interest Up to 12 months after last contact (or longer if leads to contract)
Website operation, security, error detection IP address, logs, technical data Legitimate interest (Art. 6(1)(f)) – ensuring site functionality & security Up to 12 months (logs)
Analytics & site improvement (if tools enabled) Aggregated/anonymized usage data Consent (Art. 6(1)(a)) Up to 26 months (configurable)
Compliance with legal obligations (e.g., tax, accounting if contract arises) Contact & transaction data Legal obligation (Art. 6(1)(c)) As required by law (e.g., 10 years for accounting)
Direct marketing (rare – e.g., newsletter if subscribed) Email, name Consent (Art. 6(1)(a)) Until withdrawal
 

Legitimate interests are balanced against your rights (e.g., we do not process in ways that override your interests).

5. Recipients / Sharing of Personal Data We share data only when necessary:

  • With service providers acting as processors (e.g., hosting provider, email service like Google Workspace or similar, IT support) – bound by strict data processing agreements (Art. 28 GDPR).
  • With competent authorities if legally required (e.g., court order).
  • In case of merger/acquisition (data transferred as business asset).

We do not sell, rent, or share your data with third parties for their marketing purposes. No international transfers outside the EEA without safeguards (e.g., Standard Contractual Clauses if a provider is outside EEA).

6. Retention Periods We keep personal data only as long as necessary for the purpose + any statutory periods:

  • Inquiry data: max 12–24 months (unless contract or longer legal requirement).
  • Logs/technical data: up to 12 months.
  • Consent-based data: until withdrawal.

Afterwards, data is deleted or anonymized.

7. Your Rights (GDPR) As a data subject, you have the right to:

  • Access your data (Art. 15).
  • Rectify inaccurate data (Art. 16).
  • Erase data ("right to be forgotten") where applicable (Art. 17).
  • Restrict processing (Art. 18).
  • Data portability (Art. 20).
  • Object to processing based on legitimate interest or direct marketing (Art. 21).
  • Withdraw consent at any time (does not affect prior lawfulness).

To exercise rights, contact us at info@stefan-pump-turbine.com. We respond within one month (extendable if complex). No fee unless manifestly unfounded/excessive.

8. Security We implement appropriate technical and organizational measures (e.g., encryption where possible, access controls, regular updates) to protect your data against unauthorized access, loss, or destruction (Art. 32 GDPR). However, no system is 100% secure.

9. Automated Decision-Making & Profiling We do not carry out automated individual decision-making (including profiling) that produces legal effects or similarly significantly affects you (Art. 22 GDPR).

10. Changes to This Privacy Policy We may update this policy to reflect changes in law, our practices, or technology. Material changes will be notified (e.g., via Website notice or email if we have your address). Continued use after changes constitutes acceptance. Review periodically.

11. Contact Us For any questions, rights requests, or concerns: Email: info@stefan-pump-turbine.com Attn: Privacy / Data Protection

This Privacy Policy works together with our Cookie Policy and Terms and Conditions.

 

chevron-right