1. Who we are
This website is operated by iPeeWell d.o.o., Celovška 14, 3000 Celje, Slovenia (“iPeeWell”, “we”, “us”). We are the data controller for personal data processed through this website and our online store.
Contact: info*ipeewell[.]com (without [] and @ instead of *)
2. What personal data we collect
Depending on how you use the website, we may collect the following categories of personal data:
A) Online store orders (checkout)
- Identity and contact data: name, email, phone (if provided)
- Delivery and billing data: address, country, VAT ID/company name (if provided)
- Order data: products purchased, quantity, price, tax/VAT information, order notes, order number
- Transaction data: payment status, authorization/capture status, timestamps, fraud-prevention signals provided by the payment provider
Important: Payment card details are processed by our payment provider(s) (e.g., Stripe). We do not store full payment card numbers.
B) Contact form / email communication
- Name, email, and any information you provide in your message
- Communication history related to your inquiry
C) Account data (if you create an account)
- Name, email, password (stored as a hash), addresses, order history
- Any profile fields you choose to provide
D) Website usage and technical data
- IP address, browser type, device information, approximate location derived from IP (country/city-level)
- Logs related to security and troubleshooting
E) Comments (if enabled)
When visitors leave comments, we collect the data shown in the comments form, plus IP address and browser user agent string to help spam detection. An anonymized string (hash) created from your email address may be provided to the Gravatar service (https://automattic.com/privacy/). After approval of your comment, your profile picture may be visible to the public in the context of your comment.
F) Media uploads (if enabled)
If you upload images to the website, avoid uploading images with embedded location data (EXIF GPS), as visitors may be able to extract that data.
3. Why we process your data (purposes) and legal bases
We process personal data only where we have a lawful basis under GDPR (EU) 2016/679:
A) To process and fulfill online store orders (contract performance)
- Processing your order, confirming payment status, delivery, returns, warranty handling, and customer support.
B) To comply with legal obligations
- Accounting and tax records, consumer law obligations, and regulatory/quality obligations related to medical device traceability and safety notifications (where applicable).
C) To communicate with you (contract performance / legitimate interest)
- Answering pre-purchase questions via the contact form, handling requests, and providing customer support.
D) Website security and fraud prevention (legitimate interest)
- Preventing abuse, detecting fraud, protecting our systems, and maintaining logs needed for security and troubleshooting.
E) Marketing communications (consent, where applicable)
- If you subscribe to newsletters or explicitly consent to receive marketing, you may withdraw consent at any time.
We do not use automated decision-making or profiling that produces legal effects about you (e.g., “fully automated acceptance/denial”) without human involvement.
4. Who we share your data with
We share personal data only as needed for the purposes above:
Payment providers
To process payments and prevent fraud (e.g., Stripe). The payment provider processes transaction-related data according to its own privacy information and contractual terms.
Delivery / logistics providers
To deliver your order (e.g., Pošta Slovenije or another carrier you select/that is available).
IT and hosting providers
Website hosting, email delivery, security services, backups, and technical support providers that operate our IT systems under appropriate contractual controls.
Auditors / certification bodies (limited access, confidentiality) / JazMP / Slovenske akreditacije
During ISO 13485 / regulatory audits, our certification body/notified body, JazMP and, where applicable, the national accreditation body may review selected records (which may include order-related records) only to the extent necessary and under confidentiality obligations.
Legal requirements
We may disclose data if required by law or lawful requests by public authorities.
5. International data transfers
Some service providers (especially payment and IT providers) may process data outside the European Economic Area. Where this occurs, we apply appropriate safeguards (e.g., Standard Contractual Clauses or other lawful mechanisms) to protect your data.
6. How long we retain your data
We retain personal data only as long as necessary for the purposes described:
- Online store orders, invoices, and related communications: typically up to 10 years to meet legal/accounting obligations and to support medical device safety notifications/traceability where relevant.
- Contact form inquiries (no purchase): up to 10 years, unless you request earlier deletion and we have no legal basis to retain it.
- User accounts: retained while the account remains active; you can request deletion (subject to legal retention obligations for transaction records).
- Comments: retained indefinitely (unless you request deletion and we can comply).
- Security logs: retained for a limited period necessary for security and troubleshooting.
7. Cookies
We use cookies for website functionality and security. Cookies may include:
- Essential cookies required for site operation (e.g., session/login, shopping cart and checkout functionality where applicable).
- Preference cookies (e.g., remembering settings).
If optional cookies (e.g., analytics/marketing) are used, they will be set only where required by law and, where applicable, only after your consent. You can control cookies through your browser settings (note that disabling essential cookies may affect website functionality).
8. Your rights
Subject to GDPR and applicable law, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase data (where applicable)
- Restrict processing
- Object to processing (where based on legitimate interests)
- Data portability (where processing is based on contract/consent and carried out by automated means)
- Withdraw consent at any time (where processing is based on consent)
To exercise your rights, contact us at info*ipeewell[.]com (without [] and @ instead of *). We may need to verify your identity before responding.
9. Right to lodge a complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the supervisory authority in Slovenia:
Information Commissioner of the Republic of Slovenia
Dunajska cesta 22, 1000 Ljubljana, Slovenia
Phone: +386 1 230 97 30
Email: [email protected]
Website: ip-rs.si
10. Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, or alteration. No internet system can be guaranteed 100% secure.
11. Embedded content from other websites
Articles on this site may include embedded content (e.g., videos, images, articles). Embedded content behaves in the same way as if you visited the other website, which may collect data about you, use cookies, embed third-party tracking, and monitor your interaction with that embedded content.
12. Changes to this policy
We may update this Privacy Policy from time to time by publishing a new version on this page. Material changes will be communicated on the website where appropriate.
13. Apps and games privacy policy
Privacy policy for our games and apps is provided separately and continues here: Privacy policy regarding our games and apps continue here.
