Privacy Policy
Your privacy is very important to us. The Provider respects your privacy and understands the concerns that may arise regarding the privacy and protection of personal data that you provide to us when visiting or using our website or ticket sales platform. Therefore, we ask you to read how the Provider processes your personal data.
The purpose of this Privacy Policy is to present to you in a simple and transparent manner which personal data we collect about you, on which legal bases and for which purposes we process it, what options you have regarding the management of your privacy, and what rights you have in relation to the processing of personal data.
This Privacy Policy complies with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR), as well as with the applicable legislation of the Republic of Slovenia.
The Privacy Policy contains the following information:
contact information of the Provider and contact details of the Data Protection Officer,
legal bases and purposes of personal data processing,
types of personal data we collect,
management of privacy settings,
disclosure of personal data,
retention periods for personal data,
protection of personal data,
rights of individuals in relation to personal data, including the right to lodge a complaint,
changes to the Privacy Policy.
1. DATA CONTROLLER AND DATA PROTECTION OFFICER
Data Controller:
Bojan Koltaj s.p.
Hodoš 56C
9205 Hodoš
(hereinafter: the Provider)
email: skupinablueplanet@gmail.com
ticket sales website: https://vstopnice.blueplanet.si/platforma
Data Protection Officer:
WPM, spletne storitve, d.o.o.
Brnčičeva ulica 13,
1231 Ljubljana - Črnuče
email: info@wpm.si
You can contact the Controller and/or the Data Protection Officer using the contact details provided above.
Your questions regarding this Privacy Policy, the confidentiality of your personal data, the manner in which your personal data is processed, or your requests concerning the exercise of your rights in relation to personal data will be answered by the person responsible on behalf of the Controller and/or the Data Protection Officer.
2. LEGAL BASES AND PURPOSES OF PROCESSING
The Provider collects, records, organises, stores, transfers and otherwise processes the personal data we have about you on the basis of various legal grounds and for the purposes defined below.
2.1. Processing on the basis of a contract – purposes
The Provider processes individuals’ personal data for the exercise of rights and fulfilment of obligations arising from concluded contracts, in particular within the framework of contracts for the sale, purchase or reservation of products or tickets. This includes the processing of personal data of buyers or users of the online store for the purchase or reservation of tickets at the web address specified in Article 1, regardless of whether the individual creates a user account in the process.
In the exercise of rights and fulfilment of contractual obligations, the Provider processes individuals’ personal data for the purposes of identifying the individual, concluding the contract (where the contract is deemed to have been concluded at the moment when the Provider sends the buyer an email regarding the status of their purchase or reservation), communicating with the individual, providing user support, processing the order or reservation, sending notifications relating to the processing of the order or reservation, and for other purposes necessary for the performance of the contract.
In the case of a purchase, the Provider also processes personal data for the purpose of carrying out any debt collection procedures and for its own accounting and tax purposes.
2.2. Processing on the basis of legal obligations – purposes
The Provider also processes individuals’ personal data on the basis of legal obligations applicable to the Provider, in particular to fulfil obligations arising from tax, accounting and other applicable legislation.
2.3. Processing on the basis of legitimate interests – purposes
The Provider may process personal data on the basis of legitimate interests pursued by the Provider, except where such interests are overridden by the interests or fundamental rights and freedoms of the individual to whom the personal data relates that require the protection of personal data.
Where further processing of personal data collected about an individual is involved, the Provider carries out an assessment in accordance with the General Data Protection Regulation (GDPR). Such further use of data in pseudonymised or aggregated form may constitute lawful use of data for the Provider’s marketing, business and technical analyses. As an additional security measure, partial deletion or anonymisation of data may also be applied to certain forms of further processing.
On the basis of legitimate interest, the Provider processes personal data to the extent strictly necessary and proportionate to ensure the operation of online services, improve the user experience, and protect its intellectual property rights in relation to online services.
On the basis of legitimate interest, the Provider may also process customers’ personal data for the purposes of direct marketing of its products and services related to the purchase or reservation of tickets, including information about similar events, offers, news or benefits. The individual has the right to object to such processing of personal data at any time, free of charge and in a simple manner.
On the basis of legitimate interest, the Provider may also process personal data for the purposes of preventing misuse, asserting claims or defending against claims in administrative, judicial or other proceedings.
2.4. Processing on the basis of consent – purposes
The Provider processes individuals’ personal data on the basis of their explicit consent for the following purposes:
for the purpose of direct marketing and receiving notifications about events, offers, news and benefits;
for conducting marketing analyses, customer segmentation and profiling, and for providing personalised offers of products and services.
When purchasing or reserving tickets, the individual is informed about the possibility of processing their personal data for the purposes of direct marketing and may give consent for the Provider to send them marketing notifications and personalised offers by email, SMS or MMS messages, or in printed form to the address provided.
Where consent includes direct marketing based on an individual’s profile, the Provider may segment individuals based on their use of the Provider’s websites and services, exclusively for the purposes of personalised marketing content.
The individual may withdraw their consent at any time in the simple manner described in this Privacy Policy, whereby withdrawal of consent does not affect the lawfulness of the processing of personal data carried out prior to its withdrawal.
Direct marketing is not carried out through automated decision-making that would produce legal effects concerning the individual or similarly significantly affect them.
3. PERSONAL DATA WE COLLECT
The Provider collects various information about you, including personal data by which you can be directly or indirectly identified, where you or others choose to share such personal data with the Provider. We receive data in several ways, including through purchases in the online store, subscription to e-notifications (direct marketing), or visits to the Provider’s websites. The Provider collects information about your use of the services we offer.
Personal data we collect:
basic personal data such as first name and surname, date of birth, email address, residential address (street, street number, postal code, town/city, country) and telephone number;
4. COOKIES
When you use our online services, cookies are downloaded to your computer. In general, cookies and related technologies work by assigning a unique number to your browser or device that has no meaning outside the Provider.
The Provider uses these technologies to customise the experience and to help provide content that is specific to your use.
To manage the collection of information through cookies or related technologies, you can use the settings in your browser or mobile device. The Provider undertakes to enable you to manage your privacy and sharing, but assumes no responsibility for missed “Do Not Track” signals sent by your web browser. Refusing cookies may result in some features of the services offered not being available to you.
5. DISCLOSURE OF PERSONAL DATA
5.1. Data Processors
The Provider may disclose your personal data to third parties with whom we have entered into personal data processing agreements (hereinafter: data processors) for the purposes of supporting, analysing and continuously improving our services, processing payments or delivering orders. Data processors have access only to the personal data they strictly need to provide the services they perform for us, and only for the purposes of carrying out these tasks on our behalf, and may not use the data for any other purpose. Data processors are obliged to protect your personal data.
The Provider may cooperate with data processors who process statistical data on how you use our services for the purpose of advertising services or displaying information that may be of interest to you. Such processors only have access to anonymised data.
5.2. Joint Controllers
We may share your personal data with contractual partners with whom we act as joint controllers and who process your personal data in accordance with this Privacy Policy.
5.3. Universal Legal Succession
In the event of a merger or if the Provider becomes involved in a business combination, division or transfer of activities to a third party, we may transfer your data to a third party associated with the acquisition of the Provider.
5.4. Public Authorities
Regardless of the provisions regarding the retention period of personal data under the Privacy Policy, we may retain your personal data for a longer period and disclose it to third parties such as the police, prosecutor’s office, courts and other competent state authorities within or outside the Republic of Slovenia, if we determine that such disclosure is necessary and required by law, including for the purposes of preventing, investigating, detecting or prosecuting criminal offences. We may also disclose your personal data to state authorities where this is necessary for the exercise, enforcement or defence of legal claims in judicial proceedings or in administrative or out-of-court proceedings.
5.5. Transfer of Data to Countries Outside the EU or EEA
In the event of the use of online services outside the Member States of the EU, the data provided may, for the purpose of providing online services, be transferred, stored or processed in third countries where data protection legislation establishes standards different from those applicable in EU or EEA Member States. By using services in countries outside the EU, you consent to the transfer or disclosure of personal data to entities located in third countries. The Provider itself will not transfer your personal data to countries outside the EU or EEA.
6. RETENTION PERIODS FOR PERSONAL DATA
We retain personal data for as long as necessary to provide our services or longer where there are legal obligations.
Data relating to ticket orders and the associated contact details of individuals may be retained for the purpose of fulfilling contractual obligations until the services have been paid for in full or until any applicable limitation period relating to an individual claim has expired, which by law may be up to five years. In accordance with tax regulations, issued invoices are retained for another 10 years after the end of the year in which the invoice was issued.
We retain personal data obtained on the basis of a ticket order until consent is withdrawn, but for no longer than 5 years.
Data about you that are no longer necessary for the purposes for which they were collected or otherwise processed may be anonymised and aggregated with other data that do not enable the identification of an individual, in order to obtain statistical information that is commercially useful to the Provider, such as statistics on the use of the services we offer. Such personal data are anonymised and cannot be linked to an identifiable individual.
7. PROTECTION OF PERSONAL DATA
We implement several technical and organisational measures to ensure the security of personal data during collection, transfer and storage. The Provider strives to adequately protect your personal data, but does not guarantee the complete security of the personal data you provide to us and is not liable for the theft, destruction, loss, intentional or accidental disclosure of your personal data or information about you. The Provider follows generally accepted standards for protecting the information received both during transmission and after receipt; however, no method of electronic transmission or storage is 100% secure, and therefore complete security cannot be guaranteed. The Provider uses SSL (Secure Sockets Layer) technology, which provides encryption of personal data. The Provider cooperates with a company that provides security for our services and your personal data.
The user is also responsible for protecting their data by appropriately ensuring the security of their mobile device or computer, as well as by protecting their username and password and ensuring appropriate software (antivirus) protection of their electronic device. To ensure the effectiveness of these measures in preventing unauthorised access to your personal data, you should be aware of the security features available through your browser. Use a browser that allows you to configure security features before providing your personal data or credit card details over the internet. Please note that if you use a browser that does not support SSL technology, such transmission of personal data may be risky.
Most browsers allow you to receive a notification if you are on a website that does not provide a secure connection or if you are sending data over an unsecured connection. The Provider recommends that you enable these browser features, thereby helping to protect your personal data. You can also monitor the address at which you are located (URL). Secure web addresses begin with https:// instead of http://, together with the secure connection symbol used by your browser (usually a padlock at the beginning of the web address). Such a symbol indicates the use of secure communication with the server. Please also check the details (validity) of the security certificate of the website you are visiting.
Limitation of liability. The Provider undertakes to protect personal data and information about you; however, no connection over the internet can be 100% secure and complete security of the data you provide to us cannot be guaranteed. You provide your personal data to us at your own risk.
8. RIGHTS OF INDIVIDUALS
Requests from individuals concerning the exercise of their rights may be sent to the Provider’s email address or to info@wpm.si, or by post to the addresses stated above. An individual must provide proof of identity and/or address with any request that is not submitted from the email address of a registered user. The Provider will respond to your request in accordance with applicable regulations.
In relation to personal data, individuals have the following rights:
8.1 Right of Access to Data
An individual may request at any time that the Provider confirm whether data relating to them are being processed and, if so, provide access to the personal data and information concerning the processing of their personal data (e.g. the purpose of processing, types of personal data, users to whom the personal data have been or will be disclosed, the envisaged period of data retention, technical and organisational measures for data protection, etc.).
8.2 Right to Erasure
In accordance with the conditions set out in more detail by applicable regulations, an individual may request at any time that the Provider enable them to exercise their right to erasure of personal data (the so-called right to be forgotten).
8.3 Right to Data Portability
An individual may request at any time that the Provider provide their personal data in a structured, commonly used and machine-readable format, provide them to the individual or transfer them to a controller of the individual’s choice (where technically feasible), subject to the conditions set out in more detail by applicable regulations.
8.4 Right to Object
Where the Provider processes personal data on the basis of legitimate interests, as presented above, an individual may, in certain cases, object to such processing. The Provider will cease processing such personal data unless it determines that there are compelling and legitimate grounds for continuing the processing or that the processing is necessary for legal reasons.
8.5 Withdrawal of Consent
An individual may withdraw their consent at any time where they have given consent for a specific purpose of processing their personal data.
Withdrawal of consent does not affect the lawfulness of the processing of personal data carried out prior to its withdrawal.
8.6 Right to Lodge a Complaint with the Supervisory Authority
An individual has the right to lodge a complaint with the Information Commissioner of the Republic of Slovenia if they believe that their personal data are being processed in violation of applicable regulations governing the protection of personal data. The procedure for lodging a complaint with the supervisory authority is published on the website of the supervisory authority.
9. CHANGES TO THE PRIVACY POLICY
The Provider reserves the right to amend the Privacy Policy depending on circumstances and legislation in the field of personal data protection. Please review it periodically.
We will appropriately inform you in advance of any changes regarding the processing of your personal data and/or changes (updates) to the Privacy Policy. Changes to the Privacy Policy will also be published on our websites in a timely manner.
If you do not agree with the Privacy Policy, we ask you to stop using our online services and withdraw the consent you have provided.
The Privacy Policy was last updated on 17 September 2026.




