PRIVACY AND PERSONAL DATA PROTECTION POLICY OF M SORA D.D. (Version 2.0)


Last Updated: June 19, 2026 Effective Date: June 19, 2026 and thereafter


At M Sora d.d. (hereinafter: “the Company” or “the Controller”), we respect your privacy. This policy explains how we collect, process, and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and the Personal Data Protection Act (ZVOP-2).

  1. PERSONAL DATA CONTROLLER AND CONTACT INFORMATION

The personal data controller is: M Sora d.d., Trg svobode 2, 4226 Žiri, Slovenia. Registration number: 5043324000

We have established a dedicated contact address for all questions regarding personal data protection: zaupnik@m-sora.si

Data Protection Officer (DPO): Given the scope of processing and the use of advanced tracking technologies, the company has appointed a DPO, who can be reached at the email address listed above.

  1. PURPOSES OF PROCESSING AND LEGAL BASIS

We process your data on the following grounds (Article 6 of the GDPR and Article 6 of ZVOP-2):

Performance of a contract or pre-contractual measures: Data processing for the preparation of quotes (windows, doors, architectural solutions), installation, servicing, and handling of complaints.
Legal obligation: Processing for the purposes of invoicing, maintaining accounting records, and fulfilling tax obligations.
Consent: Processing for the purposes of newsletters, targeted advertising on social media, and the use of non-essential cookies.
Legitimate interest: Ensuring website security, preventing fraud, statistical analysis of website traffic, and optimizing the user experience.

  1. TYPES OF DATA AND RETENTION PERIODS

Inquiries and contracts: First name, last name, address, email, phone number, property details. We retain this data for 5 years after the contract is fulfilled or until the statute of limitations expires (10 years in the event of disputes).
Web analytics (GA4): IP address (anonymized), device information, website behavior. Data is retained for up to 14 months.
Marketing data: Email address, click data. We retain this data until consent is revoked.

  1. COOKIES AND TRACKING TECHNOLOGIES

The website uses a Consent Management Platform (CMP) that allows you to choose between:

Essential cookies: Required for the website to function (always active).
Analytics cookies: Google Analytics 4 (anonymized processing).
Marketing cookies and pixels: Meta Pixel, LinkedIn Insight Tag, and TikTok Pixel for remarketing and segmentation purposes.
Important: Tracking is performed only if you give your explicit consent (“opt-in”) via the cookie banner.

  1. TRANSFERS TO THIRD COUNTRIES (U.S.)

For services such as Google Analytics and Meta, data may be transferred to the U.S. M Sora d.d. ensures that these transfers are lawful based on:

The EU-U.S. Data Privacy Framework (DPF), provided the provider is certified.
Standard Contractual Clauses (SCCs) following a risk assessment (TIA), in accordance with the Schrems II ruling.

  1. THE M SORA GROUP AND DATA SHARING

Within the M Sora Group (e.g., M Sora Finestre, M Sora Fenster), we may act as joint controllers (Article 26 of the GDPR). Data is transferred between entities only if it is necessary to fulfill your order or if there is a legitimate interest within the group for administrative purposes.

  1. YOUR RIGHTS AND PROCEDURE

In accordance with the GDPR and ZVOP-2, you have the right to access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, and objection.

Procedure under ZVOP-2 (Article 14):

Please send your request to zaupnik@m-sora.si.
We will decide on your request without undue delay.
We will notify you of our decision and the reasons for it, and inform you of your right to file a complaint with the Information Commissioner within 15 days of receiving your request.

  1. DATA SECURITY AND PROCESSING LOG

We implement strict technical and organizational measures. In accordance with Article 22 of ZVOP-2, we maintain a processing log for automated systems, where we record accesses, modifications, and deletions to ensure traceability and prevent misuse.

  1. COMPLAINT

If you believe your rights have been violated, you have the right to file a complaint with: the Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, 1000 Ljubljana.

Contact