Skip to content

Language

Cart

Privacy policy

Privacy Policy

Last updated: 1 May 2026

1. Who We Are (Data Controller)

The data controller responsible for the processing of your personal data on this website is:

Eko Flow d.o.o. (trading as Floena)
Brodarjev trg 11
1000 Ljubljana
Slovenia

Company registration number: 9844015000
VAT number: SI74015087
Email: info@floena.com
Phone: +386 70 462 391

For all data protection enquiries, including requests to exercise your GDPR rights, please contact us at info@floena.com.


2. Scope of This Policy

This Privacy Policy explains how Eko Flow d.o.o. collects, uses, shares, and protects your personal data when you visit floena.com, place an order, sign up for our newsletter, or otherwise interact with us. We process personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and the Slovenian Personal Data Protection Act (ZVOP-2).


3. What Personal Data We Collect

Identity and contact data: first and last name, billing and shipping address, email address, phone number.

Order and transaction data: products purchased, order value, payment method (last 4 digits of card only - full card data is processed by our payment providers and never stored by us), order history, returns.

Account data: username, password (stored hashed), saved addresses, preferences.

Communications data: contents of emails, support messages, contact form submissions, product reviews.

Marketing preferences: newsletter subscription status, email open/click history (where you have consented).

Device and technical data: IP address, browser type and version, operating system, referring URL, pages viewed, time spent, cookie identifiers.

Marketing and behavioural data (with consent): data collected via Meta Pixel, Google Analytics, AdScale, and similar tools - used to measure ads and personalise marketing.


4. Legal Basis and Purposes of Processing

We process your personal data on the following legal bases under Article 6 GDPR:

Performance of a contract (Art. 6(1)(b)): to process and ship your order, handle returns, provide customer support, manage your account.

Compliance with legal obligations (Art. 6(1)(c)): to keep accounting records, issue invoices, comply with tax and consumer law.

Legitimate interests (Art. 6(1)(f)): to secure our website against fraud and abuse, to analyse non-personalised website performance, to send transactional emails about your order.

Consent (Art. 6(1)(a)): to send marketing emails, to set non-essential cookies (analytics, advertising), to use marketing pixels. You may withdraw consent at any time.


5. Third Parties Who Process Your Data

We use the following service providers (processors) to operate our store. Each processor is bound by a Data Processing Agreement under Article 28 GDPR:

Shopify International Ltd. (Ireland/Canada) - E-commerce platform, hosting, checkout, order management.

Stripe / PayPal / Klarna (Ireland/EU/Sweden) - Payment processing.

DPD, GLS, national postal carriers (EU and destination country) - Order fulfilment and delivery.

Klaviyo, Inc. (USA, Standard Contractual Clauses) - Email marketing (with consent).

Meta Platforms Ireland Ltd. (Ireland, EU) - Meta Pixel, Facebook/Instagram advertising (with consent).

Google Ireland Ltd. (Ireland, EU) - Google Analytics, Google Ads, Consent Mode (with consent).

Smile.io (Canada) - Loyalty/referral program.

Judge.me (Hong Kong, Standard Contractual Clauses) - Product reviews.

AdScale (Israel, Adequacy Decision) - Advertising performance optimisation (with consent).

Consentmo (EU) - Cookie consent management.

Where data is transferred outside the European Economic Area, we rely on adequacy decisions of the European Commission, Standard Contractual Clauses, or other recognised transfer mechanisms in line with Chapter V of the GDPR.


6. Cookies and Tracking

We use cookies and similar technologies, managed via our consent banner (powered by Consentmo): strictly necessary cookies (always on); analytics cookies (only with consent); marketing cookies (only with consent). You can change your cookie preferences at any time by clicking the cookie icon in the bottom corner of any page.


7. How Long We Keep Your Data

Order and accounting data: 10 years (Slovenian tax law, ZDavP-2). Customer accounts: as long as the account is active; inactive accounts deleted after 3 years. Marketing data: until you unsubscribe, plus 30 days. Customer support correspondence: 3 years. Cookies: most expire within 12 months.


8. Your Rights Under the GDPR

As a data subject in the EU/EEA, you have the right of access (Art. 15), the right to rectification (Art. 16), the right to erasure (Art. 17), the right to restriction (Art. 18), the right to data portability (Art. 20), the right to object (Art. 21), the right to withdraw consent (Art. 7), and the right not to be subject to automated decision-making (Art. 22).

To exercise any of these rights, email info@floena.com. We will respond within one month, in line with Article 12 GDPR.


9. Right to Lodge a Complaint

If you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with the Slovenian data protection authority:

Informacijski pooblascenec (Information Commissioner of the Republic of Slovenia)
Dunajska cesta 22, 1000 Ljubljana
Email: gp.ip@ip-rs.si
Web: www.ip-rs.si

You may also lodge a complaint with the supervisory authority in your country of residence.


10. Children

Our services are not directed at children under 16. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at info@floena.com and we will delete it.


11. Security

We use industry-standard security measures, including TLS encryption for all data in transit, hashed password storage, restricted internal access, and PCI-DSS compliant payment processing.


12. Changes to This Policy

We may update this Privacy Policy from time to time. The Last updated date at the top reflects the most recent revision. Material changes will be notified by email (where we have your address) or through a notice on our website.


13. Contact

Eko Flow d.o.o.
Brodarjev trg 11, 1000 Ljubljana, Slovenia
Email: info@floena.com
Phone: +386 70 462 391