Last updated: 4 September 2025
This Privacy Policy explains how HQ28 processes personal data when you visit www.drinkhq28.com or purchase our products.
HQ28 d.o.o
Brezje pri Dobrovi 75A,
1356 Dobrova,
Slovenia
Email: info@drinkhq28.com
Website: www.drinkhq28.com
- Identity & contact: name, surname, billing/shipping address, email, phone.
- Order & invoicing: products purchased, order ID, totals, invoice details (processed/stored in Shopify and exported to accounting Metka Kocka).
- Payment: payment status, method, transaction ID (processed by Stripe / Shopify Payments; we do not see or store full card details).
- Communications: emails, messages, support requests.
- Marketing: newsletter preferences, engagement, consents.
- Usage & cookies: device/ browser data, IP address, pages visited, referring pages (see Cookie Policy).
- Order processing & delivery (contract, Art. 6(1)(b)): to accept payment, fulfil, ship, provide tracking, and handle support.
- Accounting & tax compliance (legal obligation, Art. 6(1)(c)): invoicing, bookkeeping in Metka Kocka, statutory record-keeping.
- Customer support & service messages (legitimate interests, Art. 6(1)(f) or contract): order updates, issue resolution .
- Marketing (email, ads, offers) (consent, Art. 6(1)(a); or legitimate interests where permitted): newsletters, promotions, remarketing.
- Website security, fraud prevention, and analytics (legitimate interests, Art. 6(1)(f)): to protect our services and improve performance.
- Legal claims (legitimate interests, Art. 6(1)(f)).
Data is provided by you at checkout/registration or collected automatically via cookies/analytics. Payment data comes from our payment processors.
- Shopify (store platform, checkout, hosting).
- Stripe / Shopify Payments (payment processing).
- GLS and other couriers (delivery & tracking).
- Metka Kocka (accounting software/services).
- Email & marketing providers (if used, e.g., newsletter service, ad platforms).
We enter appropriate data-processing arrangements with our processors.
Some providers may process data outside the EEA (e.g., EU/US/Canada). Where transfers occur, we rely on Standard Contractual Clauses and/or other safeguards in line with GDPR.
- Orders/invoices: typically 10 years to meet accounting/tax laws.
- Customer support: up to 36 months after last interaction, unless needed longer for legal claims.
- Marketing: until you withdraw consent or object.
- Cookies/analytics: per lifetimes stated in Cookie Policy.
- Access, rectification, erasure, restriction, portability, objection (including to direct marketing), and the right not to be subject to decisions based solely on automated processing.
- Withdrawal of consent at any time (does not affect past processing).
To exercise rights, email info@drinkhq28.com.
You may lodge a complaint with the Information Commissioner of the Republic of Slovenia.
With your consent, we may send newsletters and use limited profiling (e.g., purchase history) to tailor offers. You can unsubscribe anytime via link in emails or by contacting us.
See our Cookie Policy for details on cookie categories, purposes, lifetimes, and choices.
We apply organizational and technical measures, use reputable providers (Shopify, Stripe), TLS encryption, access controls, and least-privilege principles.
The Website is not intended for children. We do not knowingly process data of persons under 18 for purchases.
We may update this Policy; material changes will be posted on the Website with an updated “Last updated” date..