Data protection

Maska Ljubljana is aware of the importance of privacy and strives to protect your
personal data in accordance with the legislation in force. To this end, we also
formulated internal rules and procedures and implemented technical and organisational
measures that help us ensure an adequate level of safety in the processing of personal data and enforcing the individuals’ rights. This Personal Data Protection Policy contain all the information about the processing of personal data at Maska Ljubljana, Metelkova 6, 1000 Ljubljana, info@maska.si, which is also the controller of your personal data: which personal data are collected, for what purpose, and how they are used.

WHICH PERSONAL DATA ARE PROCESSED AND HOW THEY ARE OBTAINED
The personal data that you provide when you fill out forms on the maska.si website or
send by phone or email or submit otherwise. This includes the information that you provide when you subscribe to e-notifications, purchase books or magazines or order other goods or services on offer or participate in discussions or use other social media functionalities on our website. The data you provide may include your name and surname, address, e-mail address, telephone number and status (unemployed, pensioner, student, primary or secondary school pupil), work address, title or position,
company name, VAT ID, payment amount, and the goods or services ordered. Upon every visit of the website maska.si, the following data will be collected automatically: the user’s IP address (anonymised), browser type and version and OS, the URL of the visited site, the exact date and time of each website action, and the mouse tracking history.

Cookies
Maska.si uses cookies to distinguish you from other website users. They help us ensure a good user experience when you browse the website. They also allow us to make improvements to the website. Detailed information about the cookies used and the purposes for which they are used are defined in the table at the end of this policy. A cookie is a small file that requires authorisation to be written onto the computer hard drive and can be reused. Cookies allow you to register on our website or for our
services and adapt how the website is displayed to you. An online application can tailor its activities to your needs and preferences by collecting and remembering information about your wishes. A cookie does not enable access to your computer or any data about you, except the data you choose to share with us. Cookies can be accepted or rejected. If your browser automatically accepts cookies, you can change the browser settings if you want cookies to be rejected.

Essential cookies enable basic functions such as website navigation and access to
protected website areas. As the website cannot function properly without these cookies,
their installation does not require authorisation.

Statistics cookies help understand how visitors use the website by anonymously
collecting and reporting information about user behaviour on the website.

Marketing cookies are used to track users through the website. Their purpose is to
display ads that would be appropriate and interesting for a specific user.

WHAT YOUR PERSONAL DATA ARE USED FOR
The personal data you provide will be used: – to meet the obligations under our contract
and to provide you with the information, services or goods for which you asked and any changes thereof; – to ensure that you receive the e-mails and information to which you subscribed; to ensure that the website content is displayed in the most efficient way for you and your computer; – to provide you with information about our services or goods and about the services or goods similar to those that you previously ordered or purchased on our website; – to protect our legal interests (information about the payment of our services and goods to ensure and prove compliance of our operations with accounting standards and tax regulations), and for the purpose of legal proceedings or until these are possible under the condition that your interests and fundamental rights do not outweigh such legal proceedings; – to fulfil our statutory obligations or for the purposes of our public service or activity in the public interest or to pursue public interest in the field of culture (carrying out cultural activities, providing public cultural goods and infrastructure). Personal data will not be shared with persons
outside the organisation or other organisations and/or unauthorised persons. The personal data collected from you will be used: – to manage the website and for internal operations, including troubleshooting, data analysis, testing, research, statistics and research purposes; – to improve the website in order to ensure that its content is displayed in the most efficient manner for you and your computer; – to enable you to participate in the interactive functions of our services when you choose to do so; – as part of our efforts to make the website safe; – to measure or understand the efficiency
of notification or advertising; to propose and recommend the services that the users might find interesting.

HOW LONG YOUR PERSONAL DATA ARE KEPT

The personal data obtained for the purposes of establishing and fulfilling our contractual obligations are kept for ten years after the contract has terminated or ten years after the processing of personal data has ended or ten years after the judicial proceedings initiated to collect unpaid debts have concluded. Other personal data are kept until the purpose for which they were collected has been fulfilled. The personal data processed based only on your consent are kept for five years from the withdrawal of your consent, unless your interests or fundamental rights and freedoms outweigh the need to do so; in that case, the data are processed only until your consent is withdrawn.

WHERE YOUR PERSONAL DATA ARE KEPT
The personal data collected from you will be processed and stored outside the European Economic Area (“EEA”). They will be transmitted to the United States only if you share your data through social media or if you agree to the installation of statistics tracking and marketing cookies. They will be processed by employees working with us, including external partners or the employees of our external partners who have concluded an appropriate contract with us or are bound by professional secrecy. This includes the staff whose responsibilities include fulfilling contractual obligations, processing your payment information, and providing support services. By submitting your personal data, you agree to such transfer, storage, or processing. We have taken all the necessary measures to ensure that your data are treated safely and in accordance with the applicable legislation and our internal acts. Transferring information via the Internet is not completely safe. Although we will make every effort to protect your personal data, we cannot guarantee the safety of any personal data transmitted via the website; any transfer of data is at your own risk. Once your data is received, strict procedures and safety functions will be used to prevent any unauthorised access.

HOW YOUR PERSONAL DATA ARE PROTECTED
Technical and organisational measures are in place to ensure the safety of your data. Specifically, we ensure that the rooms, equipment, and system and/or application software (including input-output units) are protected. We ensure the traceability of processing, efficient blocking, destruction and deletion and, if possible, anonymisation, pseudonymisation, and encryption of personal data. We ensure consistent confidentiality, integrity, accessibility, and resilience of processing systems and services and the possibility of making personal data available again in a timely manner in the event of a security incident. We ensure that regular testing, assessment, and evaluation of the effectiveness of technical and organisational measures are carried out, including the training of persons responsible for the processing of personal data and ensuring the legality of processing. The employees who use your personal data are obliged to protect them with due care. All our external partners also sign a contract to this effect.

SHARING PERSONAL DATA VIA SOCIAL MEDIA

The maska.si website contains integrated social media buttons. Share buttons are recognisable by their logo; they are adapted in accordance with personal data protection. Only if and when you click a share button on the maska.si website is a direct link between your browser and the server of a particular social media manager established. According to social media managers, no personal data is obtained from social media without clicking a share button. Such data, including the IP address, are obtained and processed only for registered members. If you do not want your visit to the website maska.si to be entered into any of your social media accounts, log out. Note that social media managers do not inform us of the content of the data submitted or their use in the social media. Further information about how the data are used by social media can be found in their data protection policies.

YOUR RIGHTS
You can unsubscribe from our notifications and information at any time and request a correction, deletion, limitation of processing, transfer of or access to your personal data at info@maska.si. Furthermore, all other privacy requirements stipulated in the legislation in force shall be complied with. In the event of personal data protection infringements, Maska Ljubljana shall immediately activate all internal and external procedures and measures (including technical and organisational measures) to protect the individual’s rights.

AMENDMENTS AND SUPPLEMENTS TO THIS POLICY
Any amendments or supplements to this policy shall be published on this website and,
where appropriate, sent by e-mail.

For any additional information and approval, contact:
Maska – zavod za založniško, kulturno in producentsko dejavnost (abbreviated: Maska
Ljubljana)
Metelkova 6
1000 Ljubljana
Slovenia
T: +386 1 431 31 22
E: info@maska.si