Privacy Policy

Last updated: 25 July 2026

This policy explains what personal data we process when you visit Cozelia, why we process it, who may receive it and how you can exercise your rights under Regulation (EU) 2016/679 (the GDPR).

Cozelia is an e-commerce brand owned and operated by Union s.r.o. Union s.r.o. collects and processes orders placed through Cozelia and may use contracted call-centre, logistics, fulfilment, courier and payment-service providers to confirm, dispatch, deliver and support those orders.

1. How Cozelia works and what this means for your data

Cozelia presents and sells products through product pages, comparisons, guides and order forms. Union s.r.o. processes the information needed to receive, validate, confirm, fulfil and support an Order and remains responsible for determining the purposes of first-party processing for Cozelia.

Contracted service providers may process Order data on behalf of Union s.r.o. for telephone confirmation, fraud prevention, warehousing, dispatch, delivery, cash-on-delivery collection, customer service, returns and accounting. Payment-card details are not requested where cash on delivery is the displayed payment method.

2. Data controller

The controller of personal data collected through this website is:

  • Registered name: Union s.r.o.
  • Organization identification number (IČO): 55374522
  • Registered office: Pri smaltovni 3603/4, Mestská časť Petržalka, 851 01 Bratislava, Slovakia
  • Website and brand: Cozelia
  • Contact email: marek@unionsrosl.com

Privacy and data-protection requests may be sent to marek@unionsrosl.com.

3. Categories of personal data

3.1 Technical and navigation data

Systems supporting the website may process data transmitted as part of normal Internet communications, including IP address, browser and device type, operating system, requested pages, request date and time, referring page and security logs. We use this data to deliver the website, protect it against misuse, diagnose faults and produce aggregated technical statistics.

3.2 Cookies and similar technologies

The website continuously uses first-party storage and configured third-party analytics, advertising, conversion-attribution and anti-fraud technologies from the start of each visit. This includes Google Signals, Google Analytics audiences and Google Ads for campaign attribution, advertising personalisation, remarketing and suppression of people who already completed a relevant action. Meta Pixel and Meta Conversions API support is implemented but is not currently configured in production and therefore does not presently transmit events. If Meta is activated later, browser and server events will use matching identifiers for deduplication and selected accepted-form contact and location identifiers may be normalised and one-way hashed on the server; form messages, passwords and payment-card data will remain excluded. The Website does not provide a cookie-choice control that disables configured tracking technologies. Details of categories, purposes, providers, activation status and duration are set out in our Cookie Policy.

3.3 Data you provide voluntarily

If you submit an order, contact us by form or email, we process the information needed for that request. Depending on the form, this may include name, email address, telephone number, delivery address, city, postcode, country, product, quantity, order value, order reference and message. Please do not send payment-card data or other unnecessary sensitive information.

3.4 Order, attribution and fraud-prevention data

For an Order submitted through Cozelia, contracted order-processing and fulfilment providers may receive the customer and delivery data required to process it together with product, market, attribution, IP address, User-Agent and pseudonymous correlation identifiers. The Traffic Manager fingerprint script is active throughout Cozelia as a continuous fraud-prevention and conversion-attribution control. It derives browser and device signals and may create a rendered image of the current page. The resulting tmfp value is encrypted by Cozelia until it is sent with the Order. These technical fields support routing, fraud prevention, deduplication, status reconciliation and advertising measurement. Operational providers may return an order identifier and status so Union s.r.o. can reconcile and support the transaction.

4. Purposes and legal bases

PurposeDataLegal basis
Deliver pages, maintain security and prevent abuseTechnical, device, network and log dataLegitimate interests in providing and protecting the website; performance of a requested service
Reply to enquiries and provide website supportContact details, message and any order reference suppliedTaking steps at your request; legitimate interests in managing correspondence
Transmit and reconcile cash-on-delivery ordersCustomer and delivery details, product, value, market, IP address, User-Agent and pseudonymous order/device identifiersTaking steps at your request and performance of the requested transaction; fraud prevention and operational security
Measure audience and improve contentAnalytics identifiers and usage eventsCozelia relies on its asserted legitimate interests where permitted; consent remains the applicable basis wherever required by mandatory law
Measure advertising and conversion performanceAdvertising identifiers, campaign context and conversion eventsCozelia treats attribution as a condition of the requested service; consent remains the applicable basis wherever required by mandatory law
Personalise advertising and create remarketing or suppression audiencesPseudonymous analytics and advertising identifiers, interaction categories and, for selected accepted events, one-way hashes of matching identifiers; free-text form contents, passwords and payment-card data are excludedConsent wherever required by mandatory law
Establish, exercise or defend legal claimsRelevant account, communication and technical recordsLegitimate interests and compliance with legal obligations

By accessing, browsing or using Cozelia or any of its e-commerce functions, the user acknowledges and accepts the continuous operation of the technologies described above as a condition of use. This contractual acknowledgement does not exclude, restrict or waive mandatory data-protection rights and does not, in a jurisdiction that requires prior consent for a particular technology or purpose, by itself replace the consent required by applicable law. Where processing validly relies on consent, it may be withdrawn without affecting processing carried out before withdrawal. Where processing relies on legitimate interests, we balance those interests against the user's rights and reasonable expectations.

5. Recipients and processors

Personal data may be handled by authorised staff and by service providers acting on our instructions where necessary. Depending on the services enabled, recipients may include:

  • hosting, content-delivery, security and technical-support providers;
  • email and customer-support providers;
  • Google Ireland Limited for continuously active analytics, advertising, attribution, remarketing and conversion measurement, and Meta Platforms Ireland Limited only if the currently unconfigured Meta integration is activated;
  • order-management, call-centre, fulfilment, courier, cash-on-delivery and customer-service providers where required to validate, confirm, deliver and reconcile an Order;
  • professional advisers, courts, supervisory authorities or public bodies where required by law or necessary to protect legal rights.

Processors acting on behalf of Union s.r.o. are appointed under appropriate contractual terms. A provider that independently determines the purposes and means of a specific processing activity acts as a separate controller for that activity and must provide its own information where required.

6. International transfers

Some providers may process data outside the European Economic Area. Where this occurs, transfers are based on an adequacy decision, the European Commission's Standard Contractual Clauses or another lawful safeguard under Chapter V of the GDPR. Additional technical or organisational measures are used where appropriate. Information about a specific provider's transfer arrangements is available in that provider's privacy notice.

7. Retention

RecordIndicative retention
Security and server logsNormally up to 12 months, unless longer retention is required to investigate an incident or comply with law
General enquiriesFor the time needed to answer and normally no longer than 24 months after closure
Tracking configuration and compliance recordsFor as long as needed to operate and document the Website, subject to applicable limitation and accountability requirements
Analytics and advertising dataAccording to the period stated in the Cookie Policy and the relevant Google and Meta settings; current Google Analytics audience membership ranges from 7 to 180 days
Legal and compliance recordsFor the applicable statutory limitation period or as required by law

Data is deleted or anonymised when it is no longer needed, unless preservation is required by law or for the establishment, exercise or defence of legal claims.

8. Your rights

Subject to the conditions set by the GDPR, you may request:

  • access to your personal data and information about its processing;
  • correction of inaccurate or incomplete data;
  • erasure of data where the legal requirements are met;
  • restriction of processing;
  • portability of data you provided, where processing is automated and based on consent or contract;
  • objection to processing based on legitimate interests, including objection to direct marketing at any time;
  • withdrawal of consent at any time;
  • information about safeguards used for international transfers;
  • not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where Article 22 applies.

Send a request to marek@unionsrosl.com. We may request proportionate information to verify identity. We normally respond within one month, subject to the extensions allowed by the GDPR.

9. Complaints

You may lodge a complaint with the data-protection supervisory authority competent for Union s.r.o. in Slovakia or with the supervisory authority in the EU Member State of your habitual residence, place of work or place of the alleged infringement.

10. Children

The website is intended for a general adult audience and is not designed to collect personal data from children. If you believe that a child has provided data without appropriate authorisation, contact us so that we can investigate and take appropriate action.

11. Security

We apply technical and organisational measures appropriate to the nature of the data and the risks involved. No Internet transmission or storage system can be guaranteed completely secure. Please use caution when deciding what information to send.

12. Changes to this policy

We may update this policy to reflect legal, technical or organisational changes. The current version is the one published on this page, identified by the date above. Material changes may be highlighted through the website where appropriate.

13. Contact

Questions about this policy or the processing of personal data may be sent to marek@unionsrosl.com or by post to Union s.r.o., Pri smaltovni 3603/4, Mestská časť Petržalka, 851 01 Bratislava, Slovakia.

Related documents