Privacy Policy
Privacy Policy
Privacy Policy
Effective 21 August 2026 | Version 2026.08.21
1. Controller
The controller is:
evolved s. r. o.
Registered office: Valaská Belá 482, 972 28 Valaská Belá, Slovak Republic
Company ID: 56 841 540
Tax ID: 2122462947
VAT ID: SK2122462947, registration under Section 7a of the Slovak VAT Act; the company is not a VAT payer
Register: Commercial Register of the District Court Trenčín, Section Sro, Insert No. 55563/R
Email: info@evolved.sk
Telephone: +421 950 518 572
Website: https://evolved.sk
Send privacy questions and requests to info@evolved.sk. The controller is not required to appoint, and has not appointed, a data protection officer.
2. Data we process
Depending on the service used, we may process:
- identity and contact details and delivery and billing addresses,
- basket, order, payment, discount, delivery, withdrawal and complaint records,
- account, sign-in and security records,
- server-authored evidence of the terms accepted when an account is created: account linkage, exact server time, content version and hash, language and registration source, an HMAC IP digest and coarse browser family; the raw IP address and complete user-agent are not stored in this evidence,
- customer support communications,
- review data and evidence of its origin; only fields identified in the form are displayed publicly,
- newsletter email and consent evidence,
- email and server-authored evidence of separate consent to one neutral unfinished-order reminder: consent version and exact wording, language, time, source page, hashed IP address and truncated user-agent,
- email and a server-authored record of what we displayed at checkout about one product review request email, and whether the customer objected: notice version and exact wording, language, time, source page, hashed IP address and truncated user-agent,
- email entered as an explicit request for a one-time discount code, the issued code, issue and expiry times and redemption state; after the email is removed, only a purpose-separated HMAC digest is retained temporarily,
- IP address, timestamps, user-agent, technical logs and security identifiers,
- analytics and marketing identifiers only after the relevant consent,
- the email address and a server-authored record of the separate voluntary consent to the Heureka “Verified by Customers” satisfaction survey, where the customer gave it at checkout: the version and exact wording of the consent, language, time, source page, a hash of the IP address and a shortened user-agent,
- Google Customer Reviews is disabled in the current release and receives no new order data; re-enabling it requires a separate review of transparency duties and demonstrable consent,
- partner, influencer and B2B contact data required for contracts, settlement and legal obligations.
Data comes from the person, someone acting for the customer, payment or delivery partners and technical use of the service. When an external technical asset is loaded, its provider necessarily receives the network IP address, user-agent, time and requested-asset URL. For jsDelivr and fal.media images, Evolved does not send an account, order or customer identifier and the browser is instructed not to send an HTTP referrer. We do not request health data. If a person voluntarily includes it in a message, we use it only as necessary to handle that request and restrict access.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| basket, order, payment, account, evidence of the terms version accepted on account creation, delivery, withdrawal and complaint | pre-contract steps and contract performance, Article 6(1)(b) GDPR; for the minimal acceptance evidence, also legitimate interests in proving the contractual act and defending claims, Article 6(1)(f) GDPR |
| invoicing, accounting, tax, food-safety records and mandatory cooperation | legal obligation, Article 6(1)(c) GDPR |
| security, fraud prevention, legal claims, proportionate internal statistics without optional identifiers and secure delivery of technical site assets | legitimate interests, Article 6(1)(f) GDPR |
| answering a non-contract question or B2B communication | legitimate interests or pre-contract steps, depending on context |
| issuing and sending a one-time discount code expressly requested by the visitor | steps at the data subject's request before entering a contract, Article 6(1)(b) GDPR; after expiry, only necessary protection and defence of legal claims under Article 6(1)(f) GDPR |
| newsletter, Google Analytics, Microsoft Clarity, Heureka OCM, advertising measurement and persistent marketing attribution stored in your browser for 90 days | consent, Article 6(1)(a) GDPR |
| processing the parameters from an advertising link (gclid, fbclid, utm) during your visit so that we can measure the effectiveness of our own advertising, with nothing stored on your device | legitimate interests, Article 6(1)(f) GDPR; you can object under Article 21 GDPR |
| technical error reporting through Bugsnag for every visitor and from the server, with nothing written to your device | legitimate interest in keeping the site working and secure, Article 6(1)(f) GDPR; you can object under Article 21 GDPR |
| one neutral unfinished-order reminder without a discount or further emails | separate voluntary checkout consent, Article 6(1)(a) GDPR |
| passing your email address and the identifiers of the products you ordered to Heureka Group a.s. for the “Verified by Customers” satisfaction survey | separate voluntary checkout consent, Article 6(1)(a) GDPR |
| one product review request email after the order is delivered | legitimate interest in obtaining feedback on our own products, Article 6(1)(f) GDPR; you can object at checkout when placing the order, or at any time through the link in that email |
| three parcel updates (dispatched, ready for collection, delivered) | legitimate interest in keeping you informed about your parcel, Article 6(1)(f) GDPR; you can opt out through the link in any of those emails |
The single product review request email sent after delivery is not based on consent. Checkout displays that we will send it and lets you decline it there. Using the opt-out link in that email stops further review requests. It does not stop the order confirmation or the invoice, which are contract performance and an accounting obligation.
Consent is voluntary and can be withdrawn at any time without affecting earlier lawful processing. Consent is not a condition of purchase unless the processing is genuinely necessary for that purchase. Unsubscribing through a marketing link stops the newsletter and any not-yet-sent unfinished-order reminder at that email address. It does not stop the order confirmation or the invoice, which are contract performance and an accounting obligation. The three parcel updates (dispatched, ready for collection, delivered) are sent under legitimate interest, Article 6(1)(f) GDPR, and you can opt out of them through the link in any of those emails. You still receive the order confirmation and the invoice afterwards. Once the sole reminder is sent, the consent purpose is fulfilled and no further reminder or discount offer is sent.
Submitting the one-time-code form requests one specific message containing that code. It is not consent to a newsletter or further marketing. We do not add that email to a newsletter or send further offers without a separate legal basis.
4. Recipients and processors
Data is disclosed only on a need-to-know basis, in particular to:
- Stripe and participating banks or payment-method providers when an online payment is opened and processed; Stripe receives payment and billing data, email, amount, order reference and technical data needed for security and fraud prevention,
- Cloudflare, Inc. as the necessary reverse proxy, CDN and security layer for evolved.sk; on every HTTP request it receives the IP address, requested URL, HTTP headers, time and security signals and may set a necessary challenge identifier when protecting against an attack,
- Packeta, Slovak Post and the carrier or pickup point selected in the order; they receive the name, contact details, address or selected pickup point and shipment details needed for delivery,
- Fastmail Pty Ltd, the current SMTP provider for transactional and, only after consent, marketing email; it receives the name, email address, message content and technical delivery data,
- Google: Identity Services only for user-requested sign-in or account linking; Google Analytics after analytics consent; Google Ads after marketing consent in the browser and, from our server, server-side conversion measurement for orders that came from advertising, limited to the click identifier, value, currency, time and order number, on the basis of our legitimate interest under Article 6(1)(f) GDPR; Google Customer Reviews is disabled,
- Microsoft Ireland Operations Limited / Microsoft Clarity only after analytics consent,
- SmartBear Software Inc. / Bugsnag for every visitor and for server-side errors too, on our legitimate interest in keeping the site working, Article 6(1)(f) GDPR; the Bugsnag client configuration disables automatic session tracking, a persistent anonymous ID and the explicit IP field, so nothing is written to your device, although the network endpoint can technically receive the connection IP. Credentials, cookies, email addresses and phone numbers are stripped from reports. You can object under Article 21 GDPR,
- Heureka Group a.s. for OCM visit attribution only after marketing consent; for the “Verified by Customers” programme we pass your email address and the identifiers of the products you ordered only where you ticked a separate, unticked-by-default checkbox at checkout under Article 6(1)(a) GDPR. In that programme Heureka Group a.s. acts as a separate controller and sends the survey in its own name. Without that consent nothing is sent to them,
- Volentio JSD Limited / jsDelivr for Twemoji images and Features & Labels Inc. / fal.media for editorial images; a network request discloses the IP address, user-agent, time and asset URL, but Evolved does not add an account, customer or order identifier,
- hosting, database, backup, security and technical-support providers bound by confidentiality,
- accountants, tax advisers, auditors, legal advisers and authorities where a legal basis exists,
We do not sell personal data. A payment provider or carrier may also act as an independent controller for its own statutory purposes, in which case its notice applies alongside this policy.
5. Transfers outside the EEA
We prefer processing in the European Economic Area. Some global providers may process data outside the EEA. In that case we rely, as applicable, on an adequacy decision, the EU-US Data Privacy Framework for an eligible recipient, or European Commission standard contractual clauses with supplementary measures where needed. Information about the mechanism for a particular transfer is available on request.
6. Retention
- orders, invoices and accounting documents: 10 years after the relevant year, or longer during a required audit,
- contract and complaint evidence: while handled and generally 4 years afterwards, longer for an unresolved claim,
- unfinished orders automatically cancelled for non-payment or non-confirmation that were never paid, confirmed or released for fulfilment: no more than 90 days from creation; the record is then deleted or anonymised where separate minimal consent evidence still has to be retained,
- a requested one-time discount code: normally valid for 14 days or until the date displayed when issued; we retain the email during validity and for no more than 30 days afterwards for delivery and support, then deactivate the code and remove the raw email; a purpose-separated HMAC digest may be retained for no more than 4 years after expiry to evidence issuance, prevent abuse and defend a specific claim, after which the digest is also erased and the record no longer identifies a person,
- customer account: until deletion, followed only by data required for legal duties and claims,
- immutable evidence of the terms version accepted when the account was created: for the account lifetime and, after deletion, only to the minimum extent needed for statutory duties or to establish and defend specific legal claims,
- support and ordinary correspondence: generally 3 years after closure,
- a contact record in the B2B lead pipeline: while handled and for 3 years after the lead is marked won or lost; the contact and business name are then anonymised, while any resulting contract and accounting records follow their separate period below,
- voluntary feedback about a delivered order: 3 years after submission; the star rating and free text are then anonymised without deleting the accounting order,
- a completed online withdrawal matched to an order: 4 years after closure; an unmatched or rejected submission for no more than 180 days and a technically incomplete legacy record for no more than 30 days; an open matched submission is not anonymised before closure,
- public reviews: while published; non-public provenance, consent and moderation evidence generally while published and for 4 years after removal, or longer for a specific claim,
- partner, influencer and B2B contract and settlement records: for the relationship and generally 4 years afterwards; invoices, tax and accounting evidence for 10 years after the relevant year,
- a trusted 2FA device: 7 days after its last use; Evolved stores an HMAC IP digest, a coarse browser family and at most the country, not the raw IP, full user-agent or city,
- security and operating logs: generally 30 to 90 days, longer only for an incident; short-lived order antifraud data uses an HMAC IP digest and coarse browser family rather than the full IP and complete user-agent, and is automatically removed within 90 days,
- privileged administrator-action audit records: 12 months for accountability, misuse investigation and protection of customer and accounting records; they use an HMAC IP digest, coarse browser family and endpoint template without query parameters, while stored request bodies filter passwords, tokens and payment secrets,
- the public internal visitor-event endpoint is disabled in the current release and stores no payload; any older internal analytics events and Web Vitals expire within 90 days; non-identifying operational metrics (route template, method, status, latency, sizes and cache state) are retained for 7 to 90 days depending on type,
- newsletter: until unsubscribe or no more than 3 years after the last demonstrable engagement without renewed consent,
- evidence of consent or unsubscribe, including the separate evidence for the sole unfinished-order reminder: while effective and for 4 years after it ends,
- Google Analytics: user and event data for no more than 14 months according to service settings; browser cookies may have a different technical lifetime stated in the cookie register,
- Microsoft Clarity: playback data for 30 days, and click/heatmap data and labeled or favorited sessions for no more than 9 months under Microsoft's current documentation,
- Bugsnag: the limited period configured in the account or the provider's current plan retention,
- records of consent to Heureka “Verified by Customers” are kept as evidence for the period above; order data is passed to Heureka only where a valid checkout consent exists. Historical records of any consent for Google Customer Reviews are kept only as evidence, and the current release sends it no new order data,
- jsDelivr and fal.media request logs: under the relevant CDN's security and operational retention; Evolved does not determine or ordinarily access those external logs,
- Cloudflare technical and security logs: under the contractual settings and Cloudflare's published security retention; Evolved normally holds its own derived operating logs for 30 to 90 days,
After expiry we erase or anonymise the data unless law or a specific claim requires continued retention.
7. Automated decisions
We do not make decisions based solely on automated processing that produce legal or similarly significant effects. Automated fraud checks may flag an order for human review.
8. Individual rights
Subject to the GDPR, you may request access, rectification, erasure, restriction and portability, object to legitimate-interest processing and withdraw consent. You also have the right not to be subject to prohibited automated decisions. Send a request to info@evolved.sk. We may reasonably verify identity and normally respond within one month.
You may complain to the Office for Personal Data Protection of the Slovak Republic, Galvaniho 7/B, 821 04 Bratislava, email statny.dozor@pdp.gov.sk, https://dataprotection.gov.sk.
9. Security and changes
We use proportionate organisational and technical controls including encrypted transport, access controls, backups and security-event records. No system can truthfully be described as absolutely secure.
We will give appropriate notice of a material change. We will not use data for an incompatible new purpose without a new legal basis and the required information or consent. Published versions are retained separately.