Our story

Legal

Privacy policy

Who we are

AdriaFab is a brand of BeFly, oddaja nepremičnin, d.o.o., the data controller responsible for your personal data. Our registered seat is Ljubljanska cesta 38B, 1293 Šmarje-Sap, Slovenia (VAT SI51807742). We process personal data in line with the EU General Data Protection Regulation (Uredba EU 2016/679, GDPR) and the Slovenian Personal Data Protection Act (ZVOP-2). For any privacy question or request, email us at hello@adriafab.com.

What we collect

We collect what we need to run the shop: account data (your name, email, and a hashed password, never the password itself), your order details and shipping address, and your payment status. Card numbers are handled directly by Stripe and PayPal, so we never see or store them. We also collect messages you send through the contact form, your email address if you sign up for the newsletter, and basic analytics and usage data through cookies (see below).

Why we use it and our legal basis

We process your data to perform our contract with you when you place and receive an order (Article 6 lawful basis: contract). We keep order and invoice records to meet our legal obligations under Slovenian tax and accounting law (legal obligation). We send marketing email and load analytics cookies only with your consent (consent). We also rely on our legitimate interest to keep the shop secure and to prevent fraud.

Cookies and consent

Necessary cookies (cart, session, security) are always on because the shop cannot work without them. Analytics cookies (PostHog) and marketing cookies (Klaviyo) load only after you opt in. You can accept, reject, or change these choices at any time through the cookie banner. For the rules that govern your use of the shop, see our terms.

Who we share your data with

We share data only with the processors that run this shop: Stripe and PayPal (payment processing), Microsoft 365 / Microsoft Graph (sends transactional email from orders@adriafab.com), Klaviyo (newsletter and marketing email, only with your consent), PostHog (product analytics, only after analytics consent), Cloudflare (DNS, CDN, and security), and our hosting and database provider for the shop (Medusa with PostgreSQL). If you choose social sign-in, Google or Apple process your login. Some of these processors may process data outside the EU under GDPR safeguards such as Standard Contractual Clauses (SCCs).

How long we keep it

We keep order and invoice data for as long as Slovenian tax and accounting law requires us to. We keep your account data until you delete your account. We keep your newsletter subscription until you unsubscribe, which you can do from any marketing email.

Your rights

Under the GDPR and ZVOP-2 you have the right to access, rectify, and erase your data, to restrict or object to its processing, to data portability, and to withdraw any consent at any time. To exercise these rights, email us at hello@adriafab.com. You also have the right to lodge a complaint with the Slovenian supervisory authority, the Information Commissioner (Informacijski pooblaščenec RS, ip-rs.si).

How we keep it secure

We protect your data with encryption in transit (HTTPS), passwords stored only as one-way hashes, and access controls that limit who can reach personal data. No system is perfectly secure, but we work to keep our safeguards current.

Changes to this policy

We may update this policy from time to time. When we do, we post the new version on this page with an updated date below, so you can always see the current terms.

Last updated: 2026