Privacy Policy
Last updated: April 2026
1. Data Controller
The controller of your personal data is:
GROM ARCH d.o.o.
Vransko 27, 3305 Vransko, Slovenia
E-mail: info356grom@gmail.com
Phone: +386 51 305 596 / +386 41 989 191
We process personal data in compliance with Regulation (EU) 2016/679 (GDPR) and applicable Slovenian law.
2. Data We Collect
At checkout:
- First name and surname
- Delivery address (street, postal code, city, country)
- Phone number
- E-mail address
Via the contact form:
- Name
- E-mail address
- Vehicle chassis number (optional)
- Message content
Newsletter sign-up:
- E-mail address
3. Purpose and Legal Basis
| Purpose | Legal basis |
|---|---|
| Fulfilling the order and delivery | Contract (Art. 6(1)(b) GDPR) |
| Issuing invoices | Legal obligation (Art. 6(1)(c) GDPR) |
| Responding to contact messages | Legitimate interest (Art. 6(1)(f) GDPR) |
| Sending e-newsletters | Consent (Art. 6(1)(a) GDPR) |
4. Storage and Sharing
Data is stored in Google Firestore (EU data centres). Order data is retained for the period required by tax law (typically 10 years).
Contact messages are retained until the matter is resolved, typically no longer than 2 years.
We do not sell or share your data with third parties, except:
- Google LLC – data storage via Firestore (processor)
- Courier services – delivery address for fulfilment purposes
- Tax authorities – where legally required
5. Your Rights
Under the GDPR you have the following rights:
- Access – request a copy of the data we hold about you.
- Rectification – request correction of inaccurate data.
- Erasure – request deletion where there is no longer a lawful basis for retention.
- Restriction – request restriction of processing in certain circumstances.
- Portability – receive your data in a structured, machine-readable format.
- Objection – object to processing based on legitimate interests.
- Withdrawal of consent – withdraw newsletter consent at any time.
Submit requests to info356grom@gmail.com. You may also lodge a complaint with the Slovenian Information Commissioner (ip-rs.si).
6. Data Security
Data is stored in Google Firestore with security rules that prevent unauthorised access. Access to order data is restricted exclusively to the 356 Grom administrator.
All communications between your browser and our servers are encrypted via HTTPS.
7. Browser Local Storage
This website uses browser local storage (localStorage) for the following purposes:
- Shopping cart (
grom_cart) – stores your cart contents while you browse. This data stays on your device only and is never sent to our servers without your knowledge. - Newsletter subscription status (
newsletter_subscribed_*) – records whether you have subscribed to our newsletter, to avoid showing repeated prompts.
This website does not use cookies. See our Cookie Policy for details.
8. Policy Updates
We may update this Privacy Policy at any time. The date of the last revision is shown at the top of this page. For material changes, we will notify you by e-mail where we hold your address.
9. Contact
For any privacy-related questions, please contact us:
E-mail: info356grom@gmail.com
Phone: +386 51 305 596 / +386 41 989 191