Privacy Policy

Your privacy is very important to us. The Provider respects your privacy and understands the concerns that may arise regarding the privacy and protection of personal data you provide when visiting or using our website or ticket sales platform. We therefore encourage you to read how the Provider processes your personal data.

The purpose of this Privacy Policy is to present, in a simple and transparent manner, what personal data we collect about you, the legal bases and purposes for which we process it, the options available to you regarding the management of your privacy, and the rights you have in relation to the processing of your personal data.

This Privacy Policy complies with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR), as well as applicable legislation of the Republic of Slovenia.

This Privacy Policy contains the following information:

  • contact details of the Provider and contact details of the Data Protection Officer;

  • legal bases and purposes of processing personal data;

  • types of personal data we collect;

  • management of privacy settings;

  • disclosure of personal data;

  • retention periods for personal data;

  • protection of personal data;

  • rights of individuals regarding their personal data, including the right to lodge a complaint;

  • changes to the Privacy Policy.

1. DATA CONTROLLER AND DATA PROTECTION OFFICER

Data Controller:

Data Protection Officer:

  • WPM, spletne storitve, d.o.o.

  • Brnčičeva ulica 13

  • 1231 Ljubljana - Črnuče

  • Email: info@wpm.si

You can contact the Data Controller and/or the Data Protection Officer using the contact details provided above.

Your questions regarding this Privacy Policy, the confidentiality of your personal data, the manner in which your personal data is processed, or requests concerning the exercise of your rights in relation to your personal data will be answered by the responsible person of the Data Controller and/or the Data Protection Officer.

2. LEGAL BASES AND PURPOSES OF PROCESSING

The Provider collects, records, organises, stores, discloses and otherwise processes personal data relating to you on the basis of various legal grounds and for the purposes set out below.

2.1. Processing on the Basis of a Contract – Purposes

The Provider processes individuals’ personal data for the exercise of rights and fulfilment of obligations arising from concluded contracts, in particular in connection with contracts for the sale, purchase or reservation of products or tickets. This includes the processing of personal data of customers or users of the online store for the purchase or reservation of tickets at the web address specified in Article 1, regardless of whether the individual creates a user account in the process.

In exercising rights and fulfilling contractual obligations, the Provider processes individuals’ personal data for the purposes of identifying the individual, concluding the contract (where the contract is deemed to have been concluded when the Provider sends the customer an email regarding the status of their purchase or reservation), communicating with the individual, providing user support, processing the order or reservation, sending notifications relating to the processing of the order or reservation, and for other purposes necessary for the performance of the contract.

In the event of a purchase, the Provider also processes personal data for the purposes of carrying out any debt collection procedures and for its own accounting and tax purposes.

2.2. Processing on the Basis of Legal Obligations – Purposes

The Provider also processes individuals’ personal data on the basis of legal obligations applicable to the Provider, in particular for the fulfilment of obligations arising from tax, accounting and other applicable legislation.

2.3. Processing on the Basis of Legitimate Interests – Purposes

The Provider may process personal data on the basis of the legitimate interests pursued by the Provider, except where such interests are overridden by the interests or fundamental rights and freedoms of the individual to whom the personal data relates that require protection of personal data.

Where further processing of personal data collected about an individual is carried out, the Provider conducts an assessment in accordance with the General Data Protection Regulation (GDPR). Such further use of data in pseudonymised or aggregated form may constitute lawful use of data for the Provider’s marketing, business and technical analyses. As an additional security measure, certain forms of further processing may also involve partial deletion or anonymisation of data.

On the basis of legitimate interest, the Provider processes personal data to the extent strictly necessary and proportionate to ensure the operation of online services, improve the user experience and protect its intellectual property rights relating to online services.

On the basis of legitimate interest, the Provider may also process customers’ personal data for the purposes of direct marketing of its products and services related to the purchase or reservation of tickets, including information about similar events, offers, news or benefits. Individuals have the right to object to such processing at any time, free of charge and in a simple manner.

On the basis of legitimate interest, the Provider may also process personal data for the purposes of preventing misuse, pursuing claims or defending against claims in administrative, judicial or other proceedings.

2.4. Processing on the Basis of Consent – Purposes

The Provider processes individuals’ personal data on the basis of their explicit consent for the following purposes:

  • direct marketing and receiving notifications about events, offers, news and benefits;

  • conducting marketing analyses, customer segmentation and profiling, and providing personalised offers for products and services.

When purchasing or reserving tickets, individuals are informed of the possibility of processing their personal data for direct marketing purposes and may provide consent for the Provider to send marketing communications and personalised offers by email, SMS or MMS, or in printed form to the address provided.

Where consent includes direct marketing based on an individual’s profile, the Provider may classify individuals into segments based on their use of the Provider’s websites and services, exclusively for the purpose of delivering personalised marketing content.

An individual may withdraw their consent at any time in a simple manner described in this Privacy Policy. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Direct marketing is not carried out through automated decision-making that would produce legal effects concerning the individual or similarly significantly affect them.

3. PERSONAL DATA WE COLLECT

The Provider collects various information about you, including personal data that can directly or indirectly identify you, where you or others choose to share such personal data with the Provider. We receive data in several ways, including when you shop in the online store, subscribe to e-notifications (direct marketing), or visit the Provider’s websites. The Provider collects information about your use of the services we offer.

Personal data we collect includes:

  • basic personal data such as first name and surname, date of birth, email address, residential address (street, street number, postal code, city and country), and telephone number.

4. COOKIES

When you use our online services, cookies are downloaded to your computer. In general, cookies and related technologies work by assigning a unique number to your browser or device that has no meaning outside the Provider.

The Provider uses these technologies to personalise your experience and help provide content that is specific to your use.

To manage the collection of information through cookies or related technologies, you can use the settings available in your browser or mobile device. The Provider undertakes to enable you to manage privacy and sharing settings but assumes no responsibility for missed “Do Not Track” signals sent by your web browser. Refusing cookies may result in certain features of the services offered not being available to you.

5. DISCLOSURE OF PERSONAL DATA

5.1. Data Processors

The Provider may disclose your personal data to third parties with whom we have entered into data processing agreements (hereinafter: “data processors”) for the purposes of supporting, analysing and continuously improving our services, processing payments or delivering orders.

Data processors have access only to the personal data they strictly need to provide the services they perform for us, and only for the purpose of carrying out these tasks on our behalf. They may not use the data for any other purpose and are required to protect your personal data.

The Provider may cooperate with data processors who process statistical data on how you use our services for the purpose of advertising services or displaying information that may be of interest to you. Such processors have access only to anonymised data.

5.2. Joint Controllers

We may share your personal data with contractual partners with whom we act as joint controllers and who process your personal data in accordance with this Privacy Policy.

5.3. Universal Legal Succession

In the event of a merger, or if the Provider becomes involved in a business combination, division or transfer of business to a third party, we may transfer your data to a third party involved in the acquisition of the Provider.

5.4. Public Authorities

Notwithstanding the provisions concerning the retention period for personal data under this Privacy Policy, we may retain your personal data for a longer period and disclose it to third parties such as the police, public prosecutor’s office, courts and other competent state authorities within or outside the Republic of Slovenia, where we determine that such disclosure is necessary and required by law, including for the purposes of preventing, investigating, detecting or prosecuting criminal offences.

We may also disclose your personal data to state authorities where this is necessary for the assertion, exercise or defence of legal claims in judicial, administrative or out-of-court proceedings.

5.5. Transfer of Data to Countries Outside the EU or EEA

Where online services are used outside EU Member States, the data provided may, for the purpose of providing online services, be transferred, stored or processed in third countries where data protection legislation provides for standards different from those applicable in EU or EEA Member States.

By using services in countries outside the EU, you consent to the transfer or disclosure of personal data to entities located in third countries. The Provider itself will not transfer your personal data outside the EU or EEA.

6. RETENTION PERIODS FOR PERSONAL DATA

We retain personal data for as long as necessary to provide our services or longer where legal obligations apply.

Data relating to ticket orders and associated contact details of individuals may be retained for the purpose of fulfilling contractual obligations until the services have been paid for in full or until the applicable limitation period for an individual claim has expired, which may, by law, be up to five years. In accordance with tax regulations, issued invoices are retained for an additional 10 years after the end of the year in which the invoice was issued.

Personal data obtained in connection with a ticket order is retained until consent is withdrawn, but for no longer than five years.

Data about you that is no longer required for the purposes for which it was collected or otherwise processed may be anonymised and aggregated with other data that does not allow an individual to be identified, in order to obtain commercially useful statistical information for the Provider, such as statistics on the use of the services we offer. Such data is anonymised and cannot be linked to an identifiable individual.

7. PERSONAL DATA PROTECTION

We implement various technical and organisational measures to ensure the security of personal data during collection, transmission and storage. The Provider endeavours to appropriately protect your personal data but does not guarantee complete security of the personal data you provide and is not liable for the theft, destruction, loss, intentional or unintentional disclosure of your personal data or information about you.

The Provider follows generally accepted standards for protecting information received both during transmission and after receipt. However, no method of electronic transmission or storage is 100% secure, and therefore complete security cannot be guaranteed. The Provider uses SSL (Secure Sockets Layer) technology to encrypt personal data. The Provider cooperates with a company that provides security for our services and your personal data.

The user is also responsible for protecting their data by appropriately securing their mobile device or computer, safeguarding their username and password, and using appropriate software (antivirus) protection for their electronic device. To ensure the effectiveness of these measures in preventing unauthorised access to your personal data, you should be aware of the security features available through your browser.

Use a browser that supports security settings before providing your personal data or credit card information over the internet. Please note that if you use a browser that does not support SSL technology, the transmission of personal data may be risky.

Most browsers provide notifications when you are visiting a website that does not provide a secure connection or when you are sending data over an unsecured connection. The Provider recommends enabling these browser features to help protect your personal data.

You can also check the address of the website you are visiting. Secure web addresses begin with https:// rather than http://, together with the secure connection symbol used by your browser (usually a padlock displayed at the beginning of the web address). This symbol indicates that secure communication with the server is being used. Please also check the details and validity of the website's security certificate.

Limitation of liability. The Provider is committed to protecting personal data and information about you; however, no internet connection can be 100% secure and complete security of the data you provide cannot be guaranteed. You provide your personal data at your own risk.

8. RIGHTS OF INDIVIDUALS

Requests concerning the exercise of rights may be sent to the Provider’s email address or to info@wpm.si, or by post to the addresses specified above.

An individual whose request is not submitted from the email address of a registered user must provide proof of identity and/or address. The Provider will respond to your request in accordance with applicable regulations.

Individuals have the following rights in relation to their personal data:

8.1. Right of Access

An individual may request at any time that the Provider confirm whether personal data concerning them is being processed and, if so, provide access to the personal data and information concerning its processing (e.g. the purpose of processing, categories of personal data, recipients to whom personal data has been or will be disclosed, the envisaged retention period, technical and organisational measures for protecting the data, etc.).

8.2. Right to Erasure

Subject to the conditions specified in applicable legislation, an individual may request at any time that the Provider erase their personal data (the so-called “right to be forgotten”).

8.3. Right to Data Portability

An individual may request at any time that the Provider provide their personal data in a structured, commonly used and machine-readable format, either to the individual or, where technically feasible, transfer it to a controller of the individual’s choice, subject to the conditions specified in applicable legislation.

8.4. Right to Object

Where the Provider processes personal data on the basis of legitimate interests, as described above, an individual may, in certain circumstances, object to such processing.

The Provider will cease processing the personal data unless it determines that there are compelling and legitimate grounds for continuing the processing or that the processing is necessary for legal reasons.

8.5. Withdrawal of Consent

An individual may withdraw their consent at any time where they have provided consent for a specific purpose of processing their personal data.

Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.

8.6. Right to Lodge a Complaint with the Supervisory Authority

An individual has the right to lodge a complaint with the Information Commissioner of the Republic of Slovenia if they believe that their personal data is being processed in breach of applicable data protection legislation.

The procedure for lodging a complaint with the supervisory authority is published on the supervisory authority’s website.

9. CHANGES TO THE PRIVACY POLICY

The Provider reserves the right to amend this Privacy Policy in accordance with circumstances and applicable data protection legislation. We encourage you to review it periodically.

We will appropriately inform you in advance of any changes concerning the processing of your personal data and/or amendments (updates) to this Privacy Policy. Changes to the Privacy Policy will also be published on our websites in a timely manner.

If you do not agree with this Privacy Policy, please discontinue your use of our online services and withdraw any consent you have provided.

This Privacy Policy was last updated on 17 August 2026.