Privacy Policy & GDPR
2026-05-17 · v2.0 / maj 2026
Findes Group & Partners (hereinafter: the controller) respects your privacy and undertakes to protect your personal data in accordance with Regulation (EU) 2016/679 (GDPR), the Zakon o varstvu osebnih podatkov (ZVOP-2) and all relevant EU legislation. This document has been thoroughly revised in line with the latest guidelines of the European Data Protection Board (EDPB) and the practice of the Informacijski pooblaščenec RS (IP RS).
1. Personal data controller and Data Protection Officer (DPO)
1.1 Primary controller
Findes Marketing d.o.o.
Litostrojska cesta 44A, 1000 Ljubljana, Slovenia
Company number: 8304912000 | VAT number: SI12345678
Email: info@findes.si
Website: https://findes.si
1.2 Data Protection Officer (DPO)
DPO contact
In accordance with Article 37 GDPR, Findes Group has appointed a Data Protection Officer (DPO).
DPO Findes Group
Email: dpo@findes.si
Address: Litostrojska cesta 44A, 1000 Ljubljana (mark: DPO)
Response time: 5 working days
The DPO is independent, receives no instructions regarding the performance of their tasks and reports directly to the management. You may contact the DPO directly for any matters relating to the protection of personal data.
1.3 When a DPO is mandatory (Article 37 GDPR)
| Condition | Applicability to Findes Group |
|---|---|
| Public authority or body | Not applicable |
| Large-scale systematic monitoring of individuals | Yes — web analytics, CRM, AI recommendations |
| Large-scale processing of special categories of data | Partially — financial data, KYC |
| Voluntary appointment | Yes — Findes Group has voluntarily appointed a DPO for all entities |
2. Which personal data we collect
2.1 Categories of personal data
| Category | Examples of data | Purpose of processing | Legal basis |
|---|---|---|---|
| Identification data | First name, surname, date of birth, EMŠO (for KYC) | Contract conclusion, KYC/AML | Art. 6(1)(b)(c) |
| Contact data | Email, telephone, address, postcode | Communication, delivery of documents | Art. 6(1)(b) |
| Financial data | IBAN, VAT number, income (for investments) | Payments, FURS reporting, MiFID II | Art. 6(1)(b)(c) |
| Usage data | IP address, cookies, on-site behaviour, time of visit | Analytics, security, personalisation | Art. 6(1)(a)(f) |
| Communication data | Emails, messages, calls (recorded with notice) | Support, documentation, quality | Art. 6(1)(b)(f) |
| Contract data | Content of contracts, orders, invoices | Contract performance, accounting | Art. 6(1)(b)(c) |
| Education data | Course progress, quiz results, certificates | Academy, certification | Art. 6(1)(b) |
| Real-estate data | Search preferences, listings viewed, enquiries | Brokerage, Investra.io platform | Art. 6(1)(b)(f) |
2.2 Data we do NOT collect
Statement of non-processing
Findes Group does not collect or process the following categories of data without explicit consent or a statutory obligation:
- Health or genetic data
- Biometric data used for identification
- Data on racial or ethnic origin
- Data on criminal offences (except mandatory KYC/AML checks)
- Data on children under 16 without parental consent
3. Legal bases for processing (Article 6 GDPR)
| Legal basis | GDPR Article | Examples of use at Findes Group |
|---|---|---|
| Performance of a contract | 6(1)(b) | Provision of services, delivery of products, issuing of invoices |
| Legal obligation | 6(1)(c) | Tax reporting (FURS), AML/KYC (ZPPDFT-2), accounting (ZGD-1) |
| Legitimate interest | 6(1)(f) | Fraud prevention, IT system security, direct marketing to existing customers, analytics |
| Consent | 6(1)(a) | Newsletter, marketing communications to new contacts, analytics cookies |
| Vital interests | 6(1)(d) | Exceptionally — in urgent cases (e.g. medical emergency) |
| Public task | 6(1)(e) | Not applicable to Findes Group |
Legitimate Interest Assessment (LIA)
Whenever Findes Group processes data on the basis of a legitimate interest (Article 6(1)(f)), it carries out a Legitimate Interest Assessment (LIA) which documents that our interest does not override the rights and freedoms of individuals. The LIA is available on request from the DPO.
4. Special categories of data (Article 9 GDPR)
Statement on special categories
Findes Group, as a rule, does not process special categories of personal data within the meaning of Article 9(1) GDPR (health data, biometric data, data on racial origin, religious beliefs, sexual orientation, etc.).
4.1 Exceptions — when special categories may arise
| Scenario | Legal basis (Article 9(2)) | Measure |
|---|---|---|
| Client voluntarily discloses health data (e.g. for insurance) | 9(2)(a) — explicit consent | Specific consent, restricted access |
| AML/KYC requirement on politically exposed persons (PEP) | 9(2)(g) — public interest, ZPPDFT-2 | Mandatory under law, DPIA |
| HR data on health status | 9(2)(b) — employment law | Restricted access, HR only |
5. Personal data retention periods
| Type of data | Retention period | Legal basis |
|---|---|---|
| Contract data | 10 years after termination of the contract | ZGD-1, Article 86 |
| Accounting records | 10 years | ZGD-1, Article 54 |
| Tax documentation | 10 years | ZDavP-2 |
| AML/KYC documentation | 5 years after the end of the business relationship | ZPPDFT-2, Article 157 |
| Marketing consent | Until withdrawal of consent + 1 year | GDPR Article 7(1) |
| Website visitor data (cookies) | 13 months | GDPR, EDPB Guidelines 03/2022 |
| HR data | 5 years after termination of employment | ZDR-1 |
| Education data (Academy) | 3 years after the last activity | Contract |
| Security logs | 12 months | NIS2 Directive |
| Video footage (security cameras) | 30 days | ZVOP-2, Article 77 |
| Complaints data | 5 years | ZVPot-1 |
Deletion procedure
Upon expiry of the retention period, Findes Group securely deletes or anonymises the data in accordance with the ISO 27001 standard. For digital data, a secure wipe method is used; for physical documents, certified destruction is applied.
6. Your rights (DSAR — Data Subject Access Rights)
| Right | GDPR Article | Description | Response deadline |
|---|---|---|---|
| Right of access | Article 15 | A copy of your personal data plus information about the processing | 30 days |
| Right to rectification | Article 16 | Correction of inaccurate or incomplete data | 30 days |
| Right to erasure | Article 17 | The 'right to be forgotten' — erasure of data where there is no statutory obligation to retain it | 30 days |
| Right to restriction | Article 18 | Restriction of processing in disputed cases | 30 days |
| Right to portability | Article 20 | Transfer of data in a machine-readable format (JSON, CSV, XML) | 30 days |
| Right to object | Article 21 | Objection to processing based on a legitimate interest or for direct marketing purposes | Immediately (marketing), 30 days (other) |
| Withdrawal of consent | Article 7(3) | You may withdraw consent for marketing or cookies at any time | Immediately |
| Objection to automated decisions | Article 22 | Request for manual review of automated decisions with a material effect | 30 days |
6.1 Procedure for exercising rights (DSAR procedure)
- Submission of the request: In writing to dpo@findes.si with the subject line 'DSAR request', or by post to the controller's address.
- Identification: Provide a copy of your identity document (to protect against unauthorised access). Findes Group does not require originals.
- Acknowledgement of receipt: Within 5 working days you will receive an acknowledgement and a reference number for your request.
- Processing: We process the request within 30 days. In complex cases, the deadline may be extended by a further 60 days with notice.
- Response: A written response by email or post, free of charge.
- Complaint: If you are dissatisfied with the response, you may lodge a complaint with the IP RS (ip-rs.si).
No charge
Exercising your rights is free of charge. Exception: in the case of manifestly unfounded or excessive requests, Findes Group reserves the right to charge a reasonable fee or to refuse the request (Article 12(5) GDPR).
7. Disclosure of personal data to third parties
7.1 Categories of recipients
| Recipient | Purpose | Legal basis | Safeguards |
|---|---|---|---|
| Contractual processors (IT, accounting, lawyers) | Provision of services | Article 28 GDPR — DPA contract | DPA, NDA, audit |
| FURS (Financial Administration of the Republic of Slovenia) | Tax reporting | Legal obligation | — |
| AML authorities (UOIM) | Anti-money-laundering | ZPPDFT-2 | — |
| Banks and payment providers | Payment transactions | Contract, legal obligation | PSD2, PCI-DSS |
| Partners in the EU/EEA | Service delivery | Article 6(1)(b), appropriate safeguards | SCCs or Adequacy |
| Courts and law-enforcement authorities | Legal obligation | Article 6(1)(c) | — |
7.2 Sale of data to third parties
Statement
Findes Group never sells, rents or trades customers' personal data with third parties for commercial purposes. Every transfer of data is based on a lawful legal basis and is documented.
8. Personal data security
8.1 Technical measures
| Measure | Standard/Protocol | Purpose |
|---|---|---|
| Transport encryption | TLS 1.3 | Protection of data in transit |
| Storage encryption | AES-256 | Protection of data at rest |
| Password management | bcrypt (cost factor ≥12) | Password protection |
| Two-factor authentication | TOTP / WebAuthn | Protection of system access |
| Backups | 3-2-1 rule, daily | Recovery after an incident |
| Penetration testing | OWASP Top 10, annually | Vulnerability discovery |
| Firewall and IDS/IPS | WAF + SIEM | Attack detection |
8.2 Organisational measures
- Minimum-access policy (need-to-know principle) — every employee may only access the data they require.
- Mandatory employee training on data protection (annual, documented).
- NDA (confidentiality agreement) for all employees and contractors.
- Procedure for managing access rights (onboarding/offboarding).
- Clean-desk and clean-screen policy.
- Regular internal data-security audits (at least once a year).
9. Joint Controllership (Article 26 GDPR)
In accordance with Article 26 GDPR, internal joint-controller agreements have been concluded between the following entities:
| Controller | Role | DPO contact |
|---|---|---|
| Findes Marketing d.o.o. | Primary controller (website, marketing, CRM, IT) | dpo@findes.si |
| Findes plus d.o.o. | Controller of clients' insurance data | dpo@findes.si |
| Findes plus 2 d.o.o. | Controller of clients' insurance data | dpo@findes.si |
Data flows between partner portals
Personal data you provide on the Findes.si website is not transferred automatically to partner portals (Investra.io, Unifyr.space). Any transfer of data requires your explicit consent or a lawful legal basis.
9.1 Specific notice — Insurance services
Separation of responsibility for insurance services
Insurance intermediation and advisory services on Findes Group platforms are provided exclusively by the registered insurance agency companies:
- Findes plus d.o.o. (company number: 8304912000) — registered with AZN
- Findes plus 2 d.o.o. (company number: 8955042000) — registered with AZN
Findes Marketing d.o.o. carries out only informational and marketing activities and does not provide insurance advice.
10. Cross-border transfers of personal data (Articles 44–49 GDPR)
10.1 Transfer of data outside the EU/EEA
In the course of its business, Findes Group works with partners and service providers in countries outside the EU/EEA. Every transfer of data is based on appropriate safeguards:
| Country/region | Safeguard mechanism | Legal basis |
|---|---|---|
| United Kingdom (UK) | Adequacy Decision — EU Commission, June 2021 | Article 45 GDPR |
| Switzerland | Adequacy Decision | Article 45 GDPR |
| Turkey | Standard Contractual Clauses (SCCs) — EU Decision 2021/914 | Article 46(2)(c) GDPR |
| Serbia | Standard Contractual Clauses (SCCs) | Article 46(2)(c) GDPR |
| UAE (Dubai) | Standard Contractual Clauses (SCCs) + additional measures | Article 46(2)(c) GDPR |
| USA | EU-US Data Privacy Framework (DPF) — since July 2023 | Article 45 GDPR |
| Other countries | Explicit consent of the data subject or necessity for a contract | Article 49 GDPR |
Data transfers to the UK after Schrems II
Notwithstanding the UK Adequacy Decision, Findes Group carries out regular Transfer Impact Assessments (TIA) to ensure an adequate level of protection. Should the adequacy status change, we will notify our clients without delay.
11. Automated decision-making, profiling and artificial intelligence
11.1 When Findes Group uses automated decision-making
| System | Purpose | Material effect? | Legal basis |
|---|---|---|---|
| AI property recommendations (Investra.io) | Personalisation of listings | No — recommendations only | Article 6(1)(f) — legitimate interest |
| Customer segmentation (CRM) | Targeted marketing | No — segmentation only | Article 6(1)(a) — consent |
| Creditworthiness assessment (investments) | MiFID II suitability | Yes — affects access to products | Article 22(2)(a) — necessary for a contract |
| AML/KYC screening | Anti-money-laundering | Yes — affects the business relationship | Article 22(2)(b) — legal obligation |
11.2 Your rights in automated decision-making
Where automated decision-making has a material effect on you (e.g. denial of access to a service), you have the right to:
- Request manual review of the decision by a qualified employee.
- Express your point of view and submit additional information.
- Contest the decision with reasoning.
- Request an explanation of the logic, significance and envisaged consequences of the automated decision-making.
Address your request to: dpo@findes.si with the subject line 'Objection to an automated decision'.
11.3 EU AI Act compliance
Findes Group develops and uses AI systems in accordance with Regulation (EU) 2024/1689 (EU AI Act). AI systems that affect individuals are classified by level of risk. For high-risk AI systems (e.g. creditworthiness assessment), we carry out a mandatory Fundamental Rights Impact Assessment (FRIA) and ensure transparency and human oversight.
12. Children and minors (Article 8 GDPR)
Protection of children
Findes Group services are intended exclusively for persons over 18 years of age, except for the educational content of the Academy, where the minimum age is 16 years, subject to parental consent.
12.1 Policy on minors
- Findes Group does not knowingly collect personal data of children under 16.
- For persons aged between 16 and 18, parental consent is required for services with financial implications (investments, insurance).
- If we discover that we have inadvertently collected data of a child under 16, we delete it immediately.
- Parents/guardians may request access to and erasure of a minor's data at dpo@findes.si.
13. Record of processing activities (Article 30 GDPR)
13.1 Obligation to maintain a record
In accordance with Article 30 GDPR, Findes Group maintains a written record of all personal data processing activities. The record contains:
| Record element | Content |
|---|---|
| Name and contact details of the controller | Findes Marketing d.o.o. + DPO contact |
| Purpose of processing | Description for each processing category |
| Categories of data subjects and data | Customers, employees, partners, visitors |
| Categories of recipients | Internal, contractual processors, regulators |
| Cross-border transfers | Countries, safeguard mechanisms |
| Retention periods | By data category |
| Security measures | Technical and organisational measures |
The record is available for inspection by the Informacijski pooblaščenec RS upon request. Individuals may request a summary of the record relating to their data from the DPO.
14. Security incidents and personal data breaches (Articles 33–34 GDPR)
14.1 Procedure in the event of a security breach
- Incident detection: An employee or threat-detection system (SIEM) triggers an alert.
- Severity assessment: The DPO and security team assess the risk to individuals within 4 hours.
- Notification of IP RS: Where there is a risk to the rights and freedoms of individuals — notification to the IP RS within 72 hours of detection (Article 33 GDPR).
- Notification of affected individuals: Where there is a high risk — direct notification to the affected individuals without undue delay (Article 34 GDPR).
- Documentation: Every incident is documented in the breach register.
- Post-incident analysis: Within 30 days, a report is produced with findings and measures to prevent recurrence.
14.2 The notification to affected individuals contains
- The nature of the personal data breach.
- The contact details of the DPO for further information.
- The likely consequences of the breach.
- The measures Findes Group has taken or intends to take.
- Recommendations for individuals (e.g. password change, vigilance against phishing).
15. Cookies and tracking technologies
15.1 Summary
The Findes Group website uses cookies and similar tracking technologies. The detailed cookie policy is available at: Cookies Policy.
| Cookie type | Purpose | Duration | Consent required? |
|---|---|---|---|
| Strictly necessary | Website operation, security, session | Session / 1 year | No |
| Functional | Storing preferences, language | 1 year | Yes |
| Analytical | Google Analytics, visit statistics | 13 months | Yes |
| Marketing | Targeted advertising, remarketing | 90 days | Yes |
You may change or withdraw your consent for cookies at any time via the Cookie Centre at the bottom of each page or at Cookies Policy.
16. Complaint to the supervisory authority
If you consider that we are infringing your rights relating to the protection of personal data, you may lodge a complaint with the competent supervisory authority:
| Authority | Competence | Contact |
|---|---|---|
| Informacijski pooblaščenec RS (IP RS) | Slovenia — primary supervisory authority | www.ip-rs.si | Dunajska cesta 22, 1000 Ljubljana | tel: 01 230 97 30 |
| ICO (Information Commissioner's Office) | United Kingdom (for UK data) | ico.org.uk |
| KVKK | Turkey (for TR data) | kvkk.gov.tr |
We recommend
Before lodging a complaint with the supervisory authority, please contact us at dpo@findes.si. We resolve most matters directly and quickly.
Findes Group & Partners
Date of adoption: 17 May 2026
Version: 2.0
Next review: May 2027
DPO: dpo@findes.si
Findes Marketing d.o.o.
Litostrojska cesta 44A, 1000 Ljubljana
info@findes.si | +386 70 774 277