Skip to main content

Privacy policy

Personal Data Protection

When providing Services and selling Goods through the website www.flowandrea.com, we process your personal data as the controller – Mgr. Andrea Peniaková, ID No.: 47907754, with registered seat at Ul. 29. augusta 2281/28, 81109 Bratislava–Staré Mesto, Slovak Republic.

In this section of the Terms and Conditions, we aim to transparently provide all necessary information in accordance with Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as the “GDPR”), so that you know how we process your personal data. If you have any questions, feel free to contact us.

These rules for personal data processing are effective from October 25, 2024.

What Personal Data We Process, How We Use It, and How Long We Store It

Third-Party Login – Facebook Connect

If you choose to register or log in to your User Account via Facebook Connect, we receive the following personal data from Facebook (Meta Platforms Ireland Ltd.):

  • your public Facebook profile (name, profile picture, language, gender, and age group),

  • your email address,

  • and any other data you have made publicly available on your Facebook profile, depending on your privacy settings.

This data is used solely for the purpose of creating or logging into your User Account and will not be posted on your Facebook timeline without your consent.

The legal basis for processing this data is your consent and the performance of the contract (creating or accessing your account). You can revoke access at any time in your Facebook settings.

Data received from Facebook is stored for as long as your User Account is active or until you revoke access.

For more details on Facebook’s data use, see: https://www.facebook.com/about/privacy


Registration Data.

If you create a User Account on the Website, we process your email address (sufficient to create the account) for the purpose of account management and service provision. Providing your email is a contractual requirement and a necessary condition for registration and use of the Service. After registration, you may add more personal data to your account, such as photos, measurements, weight, and activity records. You may modify or delete these at any time. The legal basis is the performance of the contract. Data is stored for as long as your account is active. If you remain inactive for a long time, we may send a reminder email asking whether you wish to keep or delete your account. Upon account deletion, all entered personal data will be erased.

Data for FlowKlub and HeartCore memberships.

We process your email and data related to the conclusion and fulfillment of the contract (including membership payment) to deliver the services. The legal basis is the performance of a contract and our legitimate interest in proving the fulfillment of obligations. Data is stored for 4 years after contract termination.

Data necessary to fulfill the Purchase Agreement.

We process your name, surname, address, email, and phone number, along with data related to the purchase contract, to ensure delivery of the Goods. These are contractual requirements. The legal basis is contract performance and our legitimate interests in proving correct fulfillment. Data is stored for 4 years after the contract is fulfilled.

Payment-related data.

Invoices (including your personal data: for PREMIUM membership, only email; for purchase agreements, name, surname, address, email, phone) and bank statements (name, surname, bank account number) are stored for 10 years following the respective accounting year. The legal basis is compliance with the Accounting Act No. 431/2002 Coll.

Marketing.

With your consent, we may process your personal data for marketing purposes, including sending newsletters or promotional emails about our products, services, or third-party offers. The legal basis is your consent, which can be withdrawn at any time. We retain the data until you withdraw consent. Based on your consent, we may use profiling to personalize ads to your preferences.

Who We Share Your Personal Data With

In some cases, we provide your data to other parties (recipients), such as:

  • Third parties when allowed or required by law (e.g., public authorities, in case of business sale, or legal protection),

  • Our service providers (processors), who process your data based on a contract.

You can find the current list of recipients on our website. Since our services evolve, the list may change over time.

How We Protect Your Personal Data

We have implemented necessary technical and organizational measures to secure your personal data and prevent destruction, loss, alteration, unauthorized disclosure, or access.

Transfer of Personal Data to Third Countries

We plan to transfer personal data outside the EU (to third countries) only to the USA, where our provider must be part of the Privacy Shield Framework.

Your Rights

Under GDPR, you have the right to access, rectify, delete, or restrict the processing of your personal data, the right to object, the right to data portability, the right to withdraw consent, and the right to lodge a complaint with a supervisory authority.

Cookies

We use cookies on our website. By continuing to browse, you agree to their use. Details are provided in our Cookie Policy.

Questions? Contact Us.

If you have any questions, feel free to email us at: info@flowandrea.com. We’ll be happy to help.