Your data.
We keep it short.
Last updated: 21 July 2026
We collect exactly one thing — your email, if you join the waiting list. We don't sell it, don't pass it on, and don't use it for anything other than what you gave it for. Here's the whole thing, plainly.
In one breath: one email, one message about the launch, unsubscribe with one click, deletion on request. No selling data, no profiling.
Who's the controller
OOZE s. r. o.
E-mail: info@ooze.sk
Web: www.ooze.sk
Given the scope of processing, we're not required to appoint a DPO. Everything is handled at the address above.
What we process
| Data | Why we have it |
|---|---|
| Email address | So we can message you when we launch the shop. You give it to us voluntarily. |
| Sign-up and confirmation date | So we can prove you actually gave consent — GDPR requires it. |
| Hashed IP address | Protection against spam and bots. We store only an unreadable fingerprint; we can't get the original IP back from it either. |
| Where you signed up | From the top or bottom form on the page. Helps us understand what works. |
That's all. We don't ask for your name, phone, address or anything else. No special categories of data, no automated decision-making or profiling.
On what basis
On the basis of your consent — Art. 6(1)(a) GDPR. That's why you tick a box on the form and why a confirmation email arrives right after. Until you click it, we don't add you to the list. Sounds like extra hassle, but it's the only way to be sure the email really is yours and not someone signing you up on purpose.
How long we keep it
- Unconfirmed sign-ups are deleted after 7 days — that's how long the email link is valid.
- Confirmed emails we keep until the shop launches, and at most 24 months from sign-up. If nothing launches by then, we delete the list.
- When you unsubscribe, we delete your record immediately and fully. No quietly “deactivated” copy remains.
- Anti-spam records (hashed IP) disappear after an hour.
Who we share it with
The database runs on our own hosting in the European Union. The same server sends the emails. We don't hand your email to any third party and don't transfer it outside the EU.
The only exception is the hosting provider, which has technical access to the server and is our processor under Art. 28 GDPR — bound by contract and confidentiality.
If we ever move to a newsletter tool, we'll tell you before the first send and update this page.
How we protect it
- The whole site runs strictly over HTTPS; form data is encrypted in transit.
- The database is not reachable from the internet — it sits outside the public web area.
- Confirmation and unsubscribe links are cryptographically signed and can't be guessed.
- The form is protected against bots and mass sending (rate limiting).
- The endpoint deliberately won't reveal whether an email is on the list — you can't probe who signed up.
Your rights
Under GDPR you have these rights, and it's enough to email info@ooze.sk:
- Access — tell you what we hold about you (Art. 15).
- Rectification — fix an incorrect detail (Art. 16).
- Erasure — delete you. Faster still via the unsubscribe link in the footer of every email (Art. 17).
- Restriction of processing (Art. 18).
- Portability — give you your data in a machine-readable form (Art. 20).
- Withdrawal of consent anytime, no reason needed. Withdrawal doesn't affect what was processed before (Art. 7(3)).
We reply within one month at the latest. There's no charge.
Complaint
If you feel we handle your data wrongly, reach out to us first — we usually sort it out right away. You also have every right to go straight to the supervisory authority:
Office for Personal Data Protection of the Slovak Republic
Hraničná 12, 820 07 Bratislava 27
dataprotection.gov.sk
Cookies
We handle cookies separately — see the cookie policy.
Changes
If we change this page, we'll put a new date at the top. For a material change (e.g. a new recipient of data) we'll email you and, if needed, ask for fresh consent.