• News
  • Blog Posts
  • Events
  • Webinars
  • FAQ
Log InSign Up
en English bg Български de Deutsch ar العربية cs Čeština da Dansk el Ελληνικά es Español et Eesti fi Suomi ru Русский tr Türkçe fr Français hu Magyar id Bahasa Indonesia it Italiano ja 日本語 ko 한국어 lt Lietuvių lv Latviešu nb Norsk Bokmål nl Nederlands pl Polski pt Português ro Română sk Slovenčina sl Slovenščina sv Svenska uk Ukrainian zh 中文 sr Srpski hr Hrvatski
landing-page-logo
  • Home
  • Tax Optimization & Legal Protection
    Insurance Brokerage
    IT & AI Development
    Marketing & Creative
    Media Marketing
    Business Venture Investments
  • Real Estate Services
    Investment Advisory
    Insurance Solutions
    Booking System
  • Akademija
  • About us
  • Contact us
Book a Call
landing-page-logo
  • en English bg Български de Deutsch ar العربية cs Čeština da Dansk el Ελληνικά es Español et Eesti fi Suomi ru Русский tr Türkçe fr Français hu Magyar id Bahasa Indonesia it Italiano ja 日本語 ko 한국어 lt Lietuvių lv Latviešu nb Norsk Bokmål nl Nederlands pl Polski pt Português ro Română sk Slovenčina sl Slovenščina sv Svenska uk Ukrainian zh 中文 sr Srpski hr Hrvatski
  • Book a Call
  • Log In
  • Sign Up
  • Home
    • Tax Optimization & Legal Protection
    • Insurance Brokerage
    • IT & AI Development
    • Marketing & Creative
    • Media Marketing
    • Business Venture Investments
    • Real Estate Services
    • Investment Advisory
    • Insurance Solutions
    • Booking System
  • Akademija
  • About us
  • Contact us
  • Vsebine
  • News
  • Blog Posts
  • Events
  • Webinars
  • FAQ
HomePrivacy Policy & GDPR
Legal · Privacy & GDPR

Privacy Policy & GDPR

Findes Group & Partners · GDPR compliance · Effective from: 17 May 2026

Versionv2.0 / maj 2026

Privacy Policy & GDPR

2026-05-17 · v2.0 / maj 2026

Findes Group & Partners (hereinafter: the controller) respects your privacy and undertakes to protect your personal data in accordance with Regulation (EU) 2016/679 (GDPR), the Zakon o varstvu osebnih podatkov (ZVOP-2) and all relevant EU legislation. This document has been thoroughly revised in line with the latest guidelines of the European Data Protection Board (EDPB) and the practice of the Informacijski pooblaščenec RS (IP RS).

Contents
  • 1. Controller and DPO
  • 2. Which data we collect
  • 3. Legal bases for processing
  • 4. Special categories of data
  • 5. Data retention periods
  • 6. Your rights (DSAR)
  • 7. Disclosure of data to third parties
  • 8. Data security
  • 9. Joint Controllership
  • 10. Cross-border data transfers
  • 11. Automated decision-making and AI
  • 12. Children and minors
  • 13. Record of processing activities
  • 14. Security incidents (Data Breach)
  • 15. Cookies and tracking technologies
  • 16. Complaint to the supervisory authority

1. Personal data controller and Data Protection Officer (DPO)

1.1 Primary controller

Findes Marketing d.o.o.
Litostrojska cesta 44A, 1000 Ljubljana, Slovenia
Company number: 8304912000 | VAT number: SI12345678
Email: info@findes.si
Website: https://findes.si

1.2 Data Protection Officer (DPO)

DPO contact

In accordance with Article 37 GDPR, Findes Group has appointed a Data Protection Officer (DPO).

DPO Findes Group
Email: dpo@findes.si
Address: Litostrojska cesta 44A, 1000 Ljubljana (mark: DPO)
Response time: 5 working days

The DPO is independent, receives no instructions regarding the performance of their tasks and reports directly to the management. You may contact the DPO directly for any matters relating to the protection of personal data.

1.3 When a DPO is mandatory (Article 37 GDPR)

ConditionApplicability to Findes Group
Public authority or bodyNot applicable
Large-scale systematic monitoring of individualsYes — web analytics, CRM, AI recommendations
Large-scale processing of special categories of dataPartially — financial data, KYC
Voluntary appointmentYes — Findes Group has voluntarily appointed a DPO for all entities

2. Which personal data we collect

2.1 Categories of personal data

CategoryExamples of dataPurpose of processingLegal basis
Identification dataFirst name, surname, date of birth, EMŠO (for KYC)Contract conclusion, KYC/AMLArt. 6(1)(b)(c)
Contact dataEmail, telephone, address, postcodeCommunication, delivery of documentsArt. 6(1)(b)
Financial dataIBAN, VAT number, income (for investments)Payments, FURS reporting, MiFID IIArt. 6(1)(b)(c)
Usage dataIP address, cookies, on-site behaviour, time of visitAnalytics, security, personalisationArt. 6(1)(a)(f)
Communication dataEmails, messages, calls (recorded with notice)Support, documentation, qualityArt. 6(1)(b)(f)
Contract dataContent of contracts, orders, invoicesContract performance, accountingArt. 6(1)(b)(c)
Education dataCourse progress, quiz results, certificatesAcademy, certificationArt. 6(1)(b)
Real-estate dataSearch preferences, listings viewed, enquiriesBrokerage, Investra.io platformArt. 6(1)(b)(f)

2.2 Data we do NOT collect

Statement of non-processing

Findes Group does not collect or process the following categories of data without explicit consent or a statutory obligation:

  • Health or genetic data
  • Biometric data used for identification
  • Data on racial or ethnic origin
  • Data on criminal offences (except mandatory KYC/AML checks)
  • Data on children under 16 without parental consent

3. Legal bases for processing (Article 6 GDPR)

Legal basisGDPR ArticleExamples of use at Findes Group
Performance of a contract6(1)(b)Provision of services, delivery of products, issuing of invoices
Legal obligation6(1)(c)Tax reporting (FURS), AML/KYC (ZPPDFT-2), accounting (ZGD-1)
Legitimate interest6(1)(f)Fraud prevention, IT system security, direct marketing to existing customers, analytics
Consent6(1)(a)Newsletter, marketing communications to new contacts, analytics cookies
Vital interests6(1)(d)Exceptionally — in urgent cases (e.g. medical emergency)
Public task6(1)(e)Not applicable to Findes Group

Legitimate Interest Assessment (LIA)

Whenever Findes Group processes data on the basis of a legitimate interest (Article 6(1)(f)), it carries out a Legitimate Interest Assessment (LIA) which documents that our interest does not override the rights and freedoms of individuals. The LIA is available on request from the DPO.

4. Special categories of data (Article 9 GDPR)

Statement on special categories

Findes Group, as a rule, does not process special categories of personal data within the meaning of Article 9(1) GDPR (health data, biometric data, data on racial origin, religious beliefs, sexual orientation, etc.).

4.1 Exceptions — when special categories may arise

ScenarioLegal basis (Article 9(2))Measure
Client voluntarily discloses health data (e.g. for insurance)9(2)(a) — explicit consentSpecific consent, restricted access
AML/KYC requirement on politically exposed persons (PEP)9(2)(g) — public interest, ZPPDFT-2Mandatory under law, DPIA
HR data on health status9(2)(b) — employment lawRestricted access, HR only

5. Personal data retention periods

Type of dataRetention periodLegal basis
Contract data10 years after termination of the contractZGD-1, Article 86
Accounting records10 yearsZGD-1, Article 54
Tax documentation10 yearsZDavP-2
AML/KYC documentation5 years after the end of the business relationshipZPPDFT-2, Article 157
Marketing consentUntil withdrawal of consent + 1 yearGDPR Article 7(1)
Website visitor data (cookies)13 monthsGDPR, EDPB Guidelines 03/2022
HR data5 years after termination of employmentZDR-1
Education data (Academy)3 years after the last activityContract
Security logs12 monthsNIS2 Directive
Video footage (security cameras)30 daysZVOP-2, Article 77
Complaints data5 yearsZVPot-1

Deletion procedure

Upon expiry of the retention period, Findes Group securely deletes or anonymises the data in accordance with the ISO 27001 standard. For digital data, a secure wipe method is used; for physical documents, certified destruction is applied.

6. Your rights (DSAR — Data Subject Access Rights)

RightGDPR ArticleDescriptionResponse deadline
Right of accessArticle 15A copy of your personal data plus information about the processing30 days
Right to rectificationArticle 16Correction of inaccurate or incomplete data30 days
Right to erasureArticle 17The 'right to be forgotten' — erasure of data where there is no statutory obligation to retain it30 days
Right to restrictionArticle 18Restriction of processing in disputed cases30 days
Right to portabilityArticle 20Transfer of data in a machine-readable format (JSON, CSV, XML)30 days
Right to objectArticle 21Objection to processing based on a legitimate interest or for direct marketing purposesImmediately (marketing), 30 days (other)
Withdrawal of consentArticle 7(3)You may withdraw consent for marketing or cookies at any timeImmediately
Objection to automated decisionsArticle 22Request for manual review of automated decisions with a material effect30 days

6.1 Procedure for exercising rights (DSAR procedure)

  • Submission of the request: In writing to dpo@findes.si with the subject line 'DSAR request', or by post to the controller's address.
  • Identification: Provide a copy of your identity document (to protect against unauthorised access). Findes Group does not require originals.
  • Acknowledgement of receipt: Within 5 working days you will receive an acknowledgement and a reference number for your request.
  • Processing: We process the request within 30 days. In complex cases, the deadline may be extended by a further 60 days with notice.
  • Response: A written response by email or post, free of charge.
  • Complaint: If you are dissatisfied with the response, you may lodge a complaint with the IP RS (ip-rs.si).

No charge

Exercising your rights is free of charge. Exception: in the case of manifestly unfounded or excessive requests, Findes Group reserves the right to charge a reasonable fee or to refuse the request (Article 12(5) GDPR).

7. Disclosure of personal data to third parties

7.1 Categories of recipients

RecipientPurposeLegal basisSafeguards
Contractual processors (IT, accounting, lawyers)Provision of servicesArticle 28 GDPR — DPA contractDPA, NDA, audit
FURS (Financial Administration of the Republic of Slovenia)Tax reportingLegal obligation—
AML authorities (UOIM)Anti-money-launderingZPPDFT-2—
Banks and payment providersPayment transactionsContract, legal obligationPSD2, PCI-DSS
Partners in the EU/EEAService deliveryArticle 6(1)(b), appropriate safeguardsSCCs or Adequacy
Courts and law-enforcement authoritiesLegal obligationArticle 6(1)(c)—

7.2 Sale of data to third parties

Statement

Findes Group never sells, rents or trades customers' personal data with third parties for commercial purposes. Every transfer of data is based on a lawful legal basis and is documented.

8. Personal data security

8.1 Technical measures

MeasureStandard/ProtocolPurpose
Transport encryptionTLS 1.3Protection of data in transit
Storage encryptionAES-256Protection of data at rest
Password managementbcrypt (cost factor ≥12)Password protection
Two-factor authenticationTOTP / WebAuthnProtection of system access
Backups3-2-1 rule, dailyRecovery after an incident
Penetration testingOWASP Top 10, annuallyVulnerability discovery
Firewall and IDS/IPSWAF + SIEMAttack detection

8.2 Organisational measures

  • Minimum-access policy (need-to-know principle) — every employee may only access the data they require.
  • Mandatory employee training on data protection (annual, documented).
  • NDA (confidentiality agreement) for all employees and contractors.
  • Procedure for managing access rights (onboarding/offboarding).
  • Clean-desk and clean-screen policy.
  • Regular internal data-security audits (at least once a year).

9. Joint Controllership (Article 26 GDPR)

In accordance with Article 26 GDPR, internal joint-controller agreements have been concluded between the following entities:

ControllerRoleDPO contact
Findes Marketing d.o.o.Primary controller (website, marketing, CRM, IT)dpo@findes.si
Findes plus d.o.o.Controller of clients' insurance datadpo@findes.si
Findes plus 2 d.o.o.Controller of clients' insurance datadpo@findes.si

Data flows between partner portals

Personal data you provide on the Findes.si website is not transferred automatically to partner portals (Investra.io, Unifyr.space). Any transfer of data requires your explicit consent or a lawful legal basis.

9.1 Specific notice — Insurance services

Separation of responsibility for insurance services

Insurance intermediation and advisory services on Findes Group platforms are provided exclusively by the registered insurance agency companies:

  • Findes plus d.o.o. (company number: 8304912000) — registered with AZN
  • Findes plus 2 d.o.o. (company number: 8955042000) — registered with AZN

Findes Marketing d.o.o. carries out only informational and marketing activities and does not provide insurance advice.

10. Cross-border transfers of personal data (Articles 44–49 GDPR)

10.1 Transfer of data outside the EU/EEA

In the course of its business, Findes Group works with partners and service providers in countries outside the EU/EEA. Every transfer of data is based on appropriate safeguards:

Country/regionSafeguard mechanismLegal basis
United Kingdom (UK)Adequacy Decision — EU Commission, June 2021Article 45 GDPR
SwitzerlandAdequacy DecisionArticle 45 GDPR
TurkeyStandard Contractual Clauses (SCCs) — EU Decision 2021/914Article 46(2)(c) GDPR
SerbiaStandard Contractual Clauses (SCCs)Article 46(2)(c) GDPR
UAE (Dubai)Standard Contractual Clauses (SCCs) + additional measuresArticle 46(2)(c) GDPR
USAEU-US Data Privacy Framework (DPF) — since July 2023Article 45 GDPR
Other countriesExplicit consent of the data subject or necessity for a contractArticle 49 GDPR

Data transfers to the UK after Schrems II

Notwithstanding the UK Adequacy Decision, Findes Group carries out regular Transfer Impact Assessments (TIA) to ensure an adequate level of protection. Should the adequacy status change, we will notify our clients without delay.

11. Automated decision-making, profiling and artificial intelligence

11.1 When Findes Group uses automated decision-making

SystemPurposeMaterial effect?Legal basis
AI property recommendations (Investra.io)Personalisation of listingsNo — recommendations onlyArticle 6(1)(f) — legitimate interest
Customer segmentation (CRM)Targeted marketingNo — segmentation onlyArticle 6(1)(a) — consent
Creditworthiness assessment (investments)MiFID II suitabilityYes — affects access to productsArticle 22(2)(a) — necessary for a contract
AML/KYC screeningAnti-money-launderingYes — affects the business relationshipArticle 22(2)(b) — legal obligation

11.2 Your rights in automated decision-making

Where automated decision-making has a material effect on you (e.g. denial of access to a service), you have the right to:

  • Request manual review of the decision by a qualified employee.
  • Express your point of view and submit additional information.
  • Contest the decision with reasoning.
  • Request an explanation of the logic, significance and envisaged consequences of the automated decision-making.

Address your request to: dpo@findes.si with the subject line 'Objection to an automated decision'.

11.3 EU AI Act compliance

Findes Group develops and uses AI systems in accordance with Regulation (EU) 2024/1689 (EU AI Act). AI systems that affect individuals are classified by level of risk. For high-risk AI systems (e.g. creditworthiness assessment), we carry out a mandatory Fundamental Rights Impact Assessment (FRIA) and ensure transparency and human oversight.

12. Children and minors (Article 8 GDPR)

Protection of children

Findes Group services are intended exclusively for persons over 18 years of age, except for the educational content of the Academy, where the minimum age is 16 years, subject to parental consent.

12.1 Policy on minors

  • Findes Group does not knowingly collect personal data of children under 16.
  • For persons aged between 16 and 18, parental consent is required for services with financial implications (investments, insurance).
  • If we discover that we have inadvertently collected data of a child under 16, we delete it immediately.
  • Parents/guardians may request access to and erasure of a minor's data at dpo@findes.si.

13. Record of processing activities (Article 30 GDPR)

13.1 Obligation to maintain a record

In accordance with Article 30 GDPR, Findes Group maintains a written record of all personal data processing activities. The record contains:

Record elementContent
Name and contact details of the controllerFindes Marketing d.o.o. + DPO contact
Purpose of processingDescription for each processing category
Categories of data subjects and dataCustomers, employees, partners, visitors
Categories of recipientsInternal, contractual processors, regulators
Cross-border transfersCountries, safeguard mechanisms
Retention periodsBy data category
Security measuresTechnical and organisational measures

The record is available for inspection by the Informacijski pooblaščenec RS upon request. Individuals may request a summary of the record relating to their data from the DPO.

14. Security incidents and personal data breaches (Articles 33–34 GDPR)

14.1 Procedure in the event of a security breach

  • Incident detection: An employee or threat-detection system (SIEM) triggers an alert.
  • Severity assessment: The DPO and security team assess the risk to individuals within 4 hours.
  • Notification of IP RS: Where there is a risk to the rights and freedoms of individuals — notification to the IP RS within 72 hours of detection (Article 33 GDPR).
  • Notification of affected individuals: Where there is a high risk — direct notification to the affected individuals without undue delay (Article 34 GDPR).
  • Documentation: Every incident is documented in the breach register.
  • Post-incident analysis: Within 30 days, a report is produced with findings and measures to prevent recurrence.

14.2 The notification to affected individuals contains

  • The nature of the personal data breach.
  • The contact details of the DPO for further information.
  • The likely consequences of the breach.
  • The measures Findes Group has taken or intends to take.
  • Recommendations for individuals (e.g. password change, vigilance against phishing).

15. Cookies and tracking technologies

15.1 Summary

The Findes Group website uses cookies and similar tracking technologies. The detailed cookie policy is available at: Cookies Policy.

Cookie typePurposeDurationConsent required?
Strictly necessaryWebsite operation, security, sessionSession / 1 yearNo
FunctionalStoring preferences, language1 yearYes
AnalyticalGoogle Analytics, visit statistics13 monthsYes
MarketingTargeted advertising, remarketing90 daysYes

You may change or withdraw your consent for cookies at any time via the Cookie Centre at the bottom of each page or at Cookies Policy.

16. Complaint to the supervisory authority

If you consider that we are infringing your rights relating to the protection of personal data, you may lodge a complaint with the competent supervisory authority:

AuthorityCompetenceContact
Informacijski pooblaščenec RS (IP RS)Slovenia — primary supervisory authoritywww.ip-rs.si | Dunajska cesta 22, 1000 Ljubljana | tel: 01 230 97 30
ICO (Information Commissioner's Office)United Kingdom (for UK data)ico.org.uk
KVKKTurkey (for TR data)kvkk.gov.tr

We recommend

Before lodging a complaint with the supervisory authority, please contact us at dpo@findes.si. We resolve most matters directly and quickly.

Findes Group & Partners

Date of adoption: 17 May 2026
Version: 2.0
Next review: May 2027
DPO: dpo@findes.si

Findes Marketing d.o.o.

Litostrojska cesta 44A, 1000 Ljubljana
info@findes.si  |  +386 70 774 277

Related legal documents

General Terms Cookie Policy Academy Terms Booking Management
Findes
© 2026 findes.si All rights reserved.

Navigation

  • Home
  • Akademija
  • Contact us

Content

  • Blog Posts
  • News
  • Events
  • Webinars
  • FAQ

Legal

  • General Terms
  • Privacy & GDPR
  • Cookie Policy
  • Impressum
  • Accessibility Statement
  • DPA (Data Processing)
  • Terms of Use
  • Academy Terms
  • Booking Management
  • Partner Policy (B2B)
  • Referrer Policy
  • Investment Disclaimer
  • Complaints: Findes plus d.o.o.
  • Complaints: Findes plus 2 d.o.o.