top of page
            Privacy Policy

We process your personal data in accordance with Act No. 18/2018 Coll. on Personal Data Protection and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).

Data Controller

The data controller is the Seller:

Petra Mešša – MESSA

Mojmírova 8073/1, 921 01 Piešťany

Company ID (IČO): 54829330

Tax ID (DIČ): 1079472625

E-mail: info@messa.design

Tel.: +421 944 396 146

Data Subject

A data subject is any customer of the online store www.messa.design whose personal data is being processed.

Personal Data Processed

We process the following personal data: name and surname, home address, delivery address (if different from home address), e-mail address, and telephone number.

Purpose and Legal Basis

Personal data is processed primarily for the purpose of concluding and fulfilling a purchase contract between the Controller (Seller) and the Buyer. This includes: completing the order form, order confirmation, order processing in the internal database, issuing an invoice, and shipping the goods.

Personal data may also be processed for measuring website traffic and user behavior on www.messa.design through analytics tools (e.g., Google Analytics). These data are anonymized.

Personal data may also be processed for marketing purposes (e.g., targeted advertising via Facebook Ads Manager), but outputs are anonymized and are not used for profiling individual persons.

The legal basis for processing is: performance of the contract (Art. 6(1)(b) GDPR), compliance with a legal obligation (Art. 6(1)(c) GDPR), and, for marketing purposes, the consent of the data subject (Art. 6(1)(a) GDPR).

Consent

By submitting an order, the Buyer grants consent to the processing of their personal data for the purposes stated above. This consent can be withdrawn at any time by sending an e-mail to info@messa.design.

Data Retention

Personal data will be stored for the period necessary to fulfill the order and meet legal obligations. Accounting records are retained for 10 years. Data not subject to statutory archiving will be deleted no later than 5 years after collection or upon the Buyer’s request.

Data Processors

Personal data may be shared with processors only to the extent necessary to fulfill the purchase contract, namely:

  • providers of delivery services (Slovak Post, Packeta, and other courier services),

  • payment service providers (e.g., bank, payment gateway).

Personal data is not transferred to third countries outside the EU.

Data Security

Personal data is stored in secured systems and protected against unauthorized access. There is no automated decision-making or profiling. Personal data is not disclosed to third parties for marketing purposes.

Data Subject Rights

As a data subject, you have the right to:

  • withdraw your consent to personal data processing at any time,

  • request access to your personal data,

  • request rectification of inaccurate or outdated personal data,

  • request erasure of your personal data when it is no longer necessary for the purposes of processing or after the statutory retention period expires,

  • request restriction of processing,

  • exercise the right to data portability to another controller,

  • object to processing, especially if data is used for marketing purposes,

  • file a complaint with the supervisory authority.​

The supervisory authority is:

Office for Personal Data Protection of the Slovak Republic

Hraničná 12

820 07 Bratislava 27

Slovak Republic

bottom of page