Welcome to the world of premium aesthetic skincare by Lavrin.

PRIVACY POLICY (GDPR)

 

GDPR

This Privacy Policy (hereinafter referred to as the “Policy“) governs the method of processing personal data by the company MarxOne s. r. o. during the operation of the online store www.lavrin.eu (hereinafter referred to as the “Website“), during communication with customers and business partners, during marketing activities, and in the fulfillment of legal obligations.

The Policy is prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and the relevant legal regulations of the Slovak Republic and the European Union.


1. Personal Data Controller

The personal data controller is:

MarxOne s. r. o.
Registered office: Nová 4521/2, 940 02 Nové Zámky, Slovak Republic
Company ID (IČO): 57334871
Tax ID (DIČ): 2122670693
E-mail: info@lavrin.eu

The Controller processes personal data in accordance with the principles of lawfulness, fairness, transparency, data minimization, purpose limitation, accuracy, storage limitation, integrity, and confidentiality.


2. Scope of Processed Personal Data

We process the following categories of personal data in particular:

2.1 Data during the purchase of goods

  • first and last name

  • billing and delivery address

  • e-mail address

  • phone number

  • order data (content, price, date, delivery method)

  • payment information

We do not process payment card data directly. It is processed by the relevant payment service provider according to their own security standards.


2.2 Data during the creation of a customer account

  • e-mail address

  • username

  • order history

Passwords are stored in encrypted form; the Controller does not have access to them.


2.3 Communication data

  • content of e-mail or form communication

  • data necessary for processing claims, complaints, or inquiries


2.4 Marketing data

  • e-mail address

  • name (if provided)

  • data on interaction with marketing communication


2.5 Technical data and online identifiers

  • IP address

  • cookies

  • device and browser data

  • data on behavior on the Website


3. Purposes and Legal Bases for Processing

3.1 Performance of a contract (Art. 6 para. 1 point (b) GDPR)

We process personal data for the purposes of:

  • creating and processing an order

  • delivery of goods

  • processing claims and withdrawals from the contract

  • customer account management

The provision of data is a contractual requirement. Without providing it, it is not possible to conclude and fulfill the purchase contract.


3.2 Compliance with legal obligations (Art. 6 para. 1 point (c) GDPR)

In particular:

  • bookkeeping

  • archiving of tax documents

  • fulfillment of obligations under consumer regulations


3.3 Legitimate interest (Art. 6 para. 1 point (f) GDPR)

Based on legitimate interest, we process data primarily for:

  • protection of legal claims

  • fraud prevention

  • ensuring Website security

  • basic analytics and service improvement

  • sending information about similar products to existing customers

For each processing on this basis, we assess the proportionality of the interference with the rights of the data subjects.


3.4 Consent (Art. 6 para. 1 point (a) GDPR)

Based on consent, we process data primarily for:

  • sending the newsletter to non-customers

  • marketing cookies

  • personalized advertising

  • product availability notifications

Consent can be withdrawn at any time.


4. Recipients of Personal Data

We provide personal data only to the extent necessary to the following categories of recipients:

  • carriers and logistics partners

  • payment service providers and banking institutions

  • IT service and hosting providers

  • customer support and communication tool providers

  • marketing and analytical tool providers

  • accounting, tax, and legal advisors

  • public authorities, if required by law

We enter into personal data processing agreements with processors according to Art. 28 GDPR.

The Controller does not provide personal data to third parties for their own marketing purposes without the express consent of the data subject.


5. Transfer of Personal Data Outside the EU

If necessary, personal data may be transferred to countries outside the European Economic Area.

The transfer takes place exclusively in accordance with the GDPR, primarily on the basis of:

  • an adequacy decision by the European Commission, or

  • standard contractual clauses (SCC), or

  • another legal data transfer mechanism


6. Automated Decision-Making

The Controller does not perform automated decision-making or profiling that would have legal effects or similarly significant consequences according to Art. 22 GDPR.


7. Data Retention Period

We store personal data:

  • for the duration of the contractual relationship

  • for 1 year after the expiration of the warranty period for the protection of legal claims

  • for 10 years in the case of accounting documents

  • for 4 years in the case of marketing consent or until its withdrawal

  • for the period set for cookies according to their type

After these periods, the data is deleted or anonymized.


8. Cookies

The Website uses:

  • necessary cookies (ensuring Website functionality)

  • analytical cookies (traffic measurement)

  • marketing cookies (personalized advertising)

We use analytical and marketing cookies based on your consent, which you can change at any time in the cookie settings.


9. Personal Data Security

The Controller has adopted appropriate technical and organizational measures, in particular:

  • encrypted HTTPS connection (SSL/TLS)

  • limited access to data

  • protection against unauthorized access, loss, or misuse of data


10. Rights of Data Subjects

You have the right:

  • to access personal data

  • to rectification of data

  • to erasure of data

  • to restriction of processing

  • to data portability

  • to object to processing

  • to withdraw consent

  • to lodge a complaint with the Office for Personal Data Protection of the Slovak Republic

You can exercise your rights by e-mail at: info@lavrin.eu


11. Minors

The Controller’s services are not intended for persons under the age of 16.

The Controller does not knowingly process the personal data of persons under the age of 16 without the consent of their legal representative.
If the Controller becomes aware that personal data of a minor has been processed without the necessary consent, it will take appropriate measures for its immediate deletion.


12. Final Provisions

This Policy takes effect on February 27, 2026.

The Controller reserves the right to update this Policy.