Back to home
Legal

Privacy Policy

for the online portal Samo Prijatelji accessible via www.samoprijatelji.si (hereinafter: Online Portal), effective from 26 November 2025 onwards

Effective from 26 November 2025

Controller of Personal Data

The controller of your personal data is:

Adiuvo d.o.o. (hereinafter: Controller)

Email: support@samoprijatelji.com

A Data Protection Officer has not been appointed in the company.

What is personal data?

Personal Data means any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Personal data do not include anonymized or pseudonymized data where it is not reasonably possible to identify or link them to an individual. The Online Portal collects the personal data listed in this document, as well as other data that do not qualify as personal data.

To whom does this Privacy Policy apply?

This Privacy Policy is provided alongside the Terms of Service but exists as a separate document.

The services of the Online Portal are available exclusively to users who are over 18 years of age. By using the Online Portal, the user expressly warrants that they are over 18 years of age.

Accuracy of data

It is important that the data we hold are accurate and up to date. Therefore, it is essential that the user notifies us of any changes to their personal data. Data can be updated via the profile settings on the Online Portal or notified via email to the Controller of personal data.

Links to other services, websites, and applications

The Online Portal may contain links to third-party services (plug-ins), websites, or applications. By clicking on these links or using such services, the user of the Online Portal enables third parties to collect and use their data. The Controller is not responsible for the privacy policies and practices of third-party services, websites, and applications. This Privacy Policy does not apply in such cases; instead, the privacy policies of those third parties apply.

Purpose of processing personal data and legal basis

Purpose of processingLegal basisPersonal data processed
Account creation, age verification and using our servicesConsent

Creators and co-authors:

First name, last name, date of birth, residential address, place of birth, country of residence, copy of identification document, facial image (selfie) while holding the identification document, email address, phone number (if provided), payment data, signature on consents (if provided), user account, password, profile picture, posts made on the Creator's user account, subscribers.

Followers:

First name, last name, date of birth, email address, phone number (if provided), username, password, subscriptions.

Billing and accountingCompliance with legal obligation (tax legislation)

Creators:

Payment card details, payment execution address (if provided), payment data, bank account details, company name, tax number, registration number, earnings, payout requests, failed payments, Follower Payments to Creator.

Followers:

Payment card details, payment data, address (if provided), Follower Payments to Creators.

Retention of data on blocked user accountsLegitimate interestFirst name, last name, address (if provided), payment data, IP address.
Essential cookiesLegal basis (strictly necessary)IP address, cookie ID.
Analytical cookiesUser consentIP address, cookie ID, referrer URL.

Categories of personal data we collect

Basic identification data: first name, last name, date of birth, residential address, place of birth, country of residence, copy of identification document, facial image (selfie) while holding the identification document, email address, phone number (if provided), payment data, signature on consents (if provided).

Contact data: email address, phone number (optional).

Payment data: payment card details, payment execution address (if provided), payment data.

Traffic data: IP address, cookie ID, referrer URL.

Cookies

The Online Portal uses essential cookies according to the Cookies Policy available through the Online Portal.

Sharing your data

We share personal data with the following categories of third parties:

Our third-party service providers: such as our IT and payment processing. The lawful basis we rely on for sharing personal data with these recipients is that it is necessary for our legitimate interests (namely the receipt of services to support business functionality).

Professional advisors: such as our legal advisors and accountants. Our professional advisors will process personal data as necessary to provide their services to us. The lawful basis we rely on for sharing Personal Data with these recipients is that it is necessary for our legitimate interests (namely the receipt of professional services).

Relevant authorities and regulators: Relevant governmental authorities (including law enforcement and tax authorities) and regulators. These recipients will use your Personal Data in the performance of their regulatory role. Depending on the context, the lawful basis we rely on for sharing personal data with these recipients may vary. The processing may be necessary to comply with a legal obligation to which we are subject, necessary for our, or a third-party's, legitimate interests, or may be in the interest of the wider public to do so. This may include, for example, reporting illegal content to / assisting with requests from, authorities, regulators and organisations (such as industry peers), to protect the safety of our users and third parties, and complying with our financial / tax reporting requirements (e.g. DAC7, in the European Union).

Transferring data to third countries

In order to provide this service, the Controller may provide your personal data to parties established outside the European Economic Area (EEA). The Online Portal will only do this if there is an adequate level of protection for the processing of personal data.

Personal data is transferred to processors located in the United States of America (the US) which under the GDPR constitutes a third country outside the European Union or the European Economic Area. Since the US does not have a blanket adequacy decision from the European Commission, we have implemented appropriate safeguards to protect your rights.

The Operator signed Data Processing Agreements (the DPA) and the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 (hereinafter the SCCs) with each processor located in third country to provide for appropriate safeguards to protect your rights.

Standard Contractual Clauses are a standardized contractual instrument approved by the European Commission. Through them, our partner provider in the US commits to handling your personal data in accordance with high protection standards comparable to those guaranteed by the GDPR. This includes obligations regarding: technical and organizational security measures, procedures in the event of personal data breaches, and assistance in exercising your rights.

However, certain risks remain which may result in a lower level of protection than within the European Union. There is a possibility of unjustified requests for access to data by public authorities. In such cases, the processor has committed to reviewing the legality of such requests and minimizing the data disclosed. The processor also implements extensive technical safeguards.

Upon request, we will provide you with a copy of the DPA together with the concluded and completed SCCs.

Retention period of personal data

Type of dataRetention period
User account dataUntil account deletion
Purchase data and accounting documents11 years (pursuant to VAT Act)
Data on blocked user accounts5 years from account deletion
Essential cookiesUntil the end of the session
Analytical cookies1 year

After the retention period expires, the data are securely deleted or anonymized.

Your rights under the GDPR

As a data subject, you have the right at any time to:

Request access to your personal data
Request rectification of inaccurate data
Request erasure of data ("right to be forgotten") when they are no longer necessary or if you withdraw consent
Request restriction of processing
Request data portability (in a machine-readable format)
Withdraw consent for receiving promotional messages (unsubscribe link in every email)
Lodge a complaint with the Information Commissioner of the Republic of Slovenia (www.ip-rs.si)

All requests should be sent to: support@samoprijatelji.com

We will respond within no more than 30 days.

Automated decision-making and profiling

We do not carry out automated decision-making or profiling that would produce legal effects or similarly significantly affect you.

Changes to the Privacy Policy

We reserve the right to amend this Privacy Policy. You will be notified of material changes by email or notice on the website at least 7 days before they take effect.

Contact

For any questions regarding the processing of your personal data, please write to: support@samoprijatelji.com