Privacy Policy

Effective from: 5 October 2026 · Version 2.0

We take the protection of your personal data seriously. As you also turn to us with personal, status-related and family matters, we are aware that you often entrust us with sensitive information. In this policy we explain which personal data we process, for what purposes and on what legal basis, to whom we may disclose them, how long we keep them and what rights you have.

This policy has been prepared in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter: GDPR) and the Personal Data Protection Act (ZVOP-2, Official Gazette of the Republic of Slovenia, No. 163/22).

1. Controller

The controller of your personal data is Lexibor, pravno in poslovno svetovanje d.o.o. (Lexibor, Legal and Business Consulting d.o.o.)

  • registered office: Ribnik 7, 1420 Trbovlje, Slovenia;
  • business premises (office): Obrtniška cesta 14 (1st floor), 1420 Trbovlje;
  • registration number: 9558896000; VAT ID: SI73038067;
  • email: [email protected]; telephone: +386 40 832 660.

For any questions concerning the processing of personal data and for exercising your rights, please write to us at [email protected] (subject: “Personal data protection”) or by post to the address of our registered office.

We have not designated a data protection officer, as this obligation under Article 37 GDPR does not apply to us.

2. Who this policy applies to

This policy applies to the processing of personal data of:

  • visitors to the website www.lexibor.si;
  • persons who send us an enquiry (via the form, by email or by telephone) or make initial contact with us;
  • clients who order a service from us, and their legal representatives;
  • other persons whose data are necessary to perform the service (e.g. family members in family reunification procedures, employers and their contact persons);
  • contact persons of our business partners and suppliers.

3. Purposes, legal bases and retention periods

We process personal data only for specified, explicit and legitimate purposes and to the extent necessary for each purpose:

a) Operation and security of the website (server logs, protection against misuse)

  • categories of data: IP address, date and time of access, page visited, browser and device type;
  • legal basis: legitimate interest – secure and uninterrupted operation of the website (point (f) of Article 6(1) GDPR);
  • retention period: in accordance with the hosting provider’s policy, as a rule up to 30 days.

b) Responding to enquiries and initial contact

  • categories of data: name and surname, email address, content of the message; optional: telephone number, citizenship;
  • legal basis: taking steps at your request prior to entering into a contract (point (b) of Article 6(1) GDPR);
  • retention period: 12 months from the last contact if no service is ordered.

c) Performance of the ordered service (legal advice, preparation of applications and documentation, representation in procedures on the basis of a power of attorney, company formation, etc.)

  • categories of data: identification and contact data, data from personal documents, data on foreigner status, residence, employment, education, means of subsistence, family members and other data necessary for the individual matter;
  • legal basis: entering into and performance of a contract (point (b) of Article 6(1) GDPR); for special categories of data, see Section 4;
  • retention period: 5 years after the matter is closed (general limitation period, Article 346 of the Obligations Code), unless the law provides for a longer period.

d) Invoicing and accounting

  • categories of data: name and surname or company name, address, tax number, data on services provided and payments;
  • legal basis: compliance with legal obligations (point (c) of Article 6(1) GDPR; ZDDV-1, ZGD-1, ZDavP-2);
  • retention period: 10 years after the end of the year in which the invoice was issued (Article 141 of ZDDV-1).

e) Prevention of money laundering and terrorist financing (when forming companies)

  • categories of data: data on the identity of the client and the beneficial owner, data on the business relationship;
  • legal basis: compliance with a legal obligation (point (c) of Article 6(1) GDPR; ZPPDFT-2);
  • retention period: 10 years after the end of the business relationship (Article 142 of ZPPDFT-2).

f) Establishment, exercise or defence of legal claims

  • categories of data: data necessary for the individual dispute;
  • legal basis: legitimate interest (point (f) of Article 6(1) GDPR);
  • retention period: until the final conclusion of the proceedings and the expiry of the time limits for extraordinary legal remedies.

g) Cookies and similar technologies

  • categories of data: see the Cookie Policy;
  • legal basis: strictly necessary cookies – paragraph two of Article 225 of ZEKom-2; other cookies – your consent (paragraph one of Article 225 of ZEKom-2 and point (a) of Article 6(1) GDPR);
  • retention period: see the Cookie Policy.

After the retention period expires, we erase or permanently anonymise the data. If proceedings are initiated in which the data are needed as evidence, we keep them until the final conclusion of those proceedings.

4. Special categories of personal data and data relating to criminal convictions

In some procedures (e.g. extension of a residence permit, admission to citizenship, health insurance for foreigners), data concerning health or certificates from the criminal record may also be needed, as regulations require them as evidence. We process such data:

  • only if they are provided to us by you or by a person who legally represents you, and only if they are actually necessary for your matter;
  • on the basis of point (f) of Article 9(2) GDPR (establishment, exercise or defence of legal claims and rights in administrative and judicial procedures) or, where appropriate, on the basis of your explicit consent (point (a) of Article 9(2) GDPR);
  • certificates from the criminal record exclusively for the purpose of submission to the competent authority in the procedure in which they are required by regulations (Article 10 GDPR).

Please do not send us such data and documents via the online form. If they are needed, we will agree with you on a secure method of handover.

5. Are you obliged to provide data?

Providing data is voluntary. In the contact form, only the data without which we cannot reply to you are mandatory (name and surname, email address and message). If you do not provide the data necessary to perform the ordered service, we will not be able to perform the service, or will not be able to perform it in full. We are required by law to obtain the data needed to issue an invoice.

6. Where we obtain data from

We obtain most data directly from you. We may also obtain data:

  • from a person who handles the matter on your behalf (e.g. an employer, family member or legal representative), who is obliged to ensure that you are informed of this;
  • from competent authorities (e.g. decisions, requests and orders that we receive as your authorised representative);
  • from publicly available records (e.g. the Slovenian Business Register / AJPES), where this is necessary for your matter.

7. To whom we disclose data

We do not sell personal data and do not disclose them to third parties for their marketing purposes. We disclose them only where this is necessary to perform the service, where required by law or where you have consented.

Processors

We have concluded data processing agreements (Article 28 GDPR) with the external providers that process data on our behalf. They are bound by confidentiality and may not use the data for their own purposes. They are:

  • website hosting provider: Webtasy, spletne storitve, d.o.o., Pod hribom 55, 1000 Ljubljana, Slovenia;
  • website protection and acceleration service provider: Cloudflare, Inc., USA;
  • email and office services provider: Google Ireland Limited, Ireland (Google Workspace);
  • accounting service: Romana Škrinjar s.p., Slovenia;
  • Google Ireland Limited – Google Analytics, only with your consent.

Third-party services on the website

  • Google reCAPTCHA (Google Ireland Limited, Ireland) – protection of online forms against misuse and automated (bot) messages; when you use the form, Google processes technical data about your device and behaviour on the site (e.g. IP address).
  • Google Maps (Google Ireland Limited, Ireland) – display of our office location on the Contact page; when the map loads, Google receives your IP address and may set its own cookies (see the Cookie Policy).

The processing of data in these services is also subject to Google’s privacy policy (policies.google.com/privacy).

Other recipients

Where necessary for your matter and in accordance with your order or power of attorney, we disclose data to competent authorities and other persons who process data as independent controllers: administrative units, ministries, the Employment Service of Slovenia, the Financial Administration of the Republic of Slovenia, AJPES, courts, notaries, court interpreters and banks. We inform you of who the data will be disclosed to in the context of each individual matter.

We may also disclose data to authorities entitled to request them by law (e.g. courts, the police, inspection services).

8. Transfers of data to third countries

As a rule, we process data in the European Union or the European Economic Area. With some providers (Google, Cloudflare), data may be transferred to the United States of America. We carry out such a transfer only:

  • to companies participating in the EU-US Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023; Article 45 GDPR), or
  • on the basis of standard contractual clauses adopted by the European Commission (Commission Implementing Decision (EU) 2021/914; Article 46 GDPR).

On request, we will provide you with information on the appropriate safeguards.

9. Data security

We implement appropriate technical and organisational measures to protect data against loss, misuse, unauthorised access, disclosure or alteration: an encrypted connection (HTTPS) on the website, access to data only for authorised persons, protection of user accounts with strong passwords and two-factor authentication, regular software updates and secure storage of physical documentation. All persons who process data on our behalf are bound by confidentiality.

10. Automated decision-making and profiling

We do not carry out automated decision-making, including profiling, that would produce legal or similarly significant effects for you (Article 22 GDPR). All matters are decided by people.

11. Your rights

With regard to your personal data, you have the following rights:

  • the right of access – to confirmation as to whether we process your data, to a copy of the data and to information about the processing (Article 15 GDPR);
  • the right to rectification of inaccurate data and completion of incomplete data (Article 16 GDPR);
  • the right to erasure (“right to be forgotten”) where the data are no longer necessary, where you withdraw your consent or where the processing is unlawful, unless we must keep them by law or for legal claims (Article 17 GDPR);
  • the right to restriction of processing (Article 18 GDPR);
  • the right to data portability for data that you have provided to us and that we process by automated means on the basis of consent or a contract (Article 20 GDPR);
  • the right to object to processing based on legitimate interest (Article 21 GDPR);
  • the right to withdraw consent at any time; withdrawal does not affect the lawfulness of processing before the withdrawal (Article 7(3) GDPR). You can withdraw your consent to cookies via the “Cookie settings” link in the website footer.

You can send your request to [email protected] or by post. We will reply without undue delay and at the latest within one month of receiving the request; in complex cases this period may be extended by a maximum of two further months, of which we will inform you (Article 12(3) GDPR). Exercising your rights is free of charge. If we cannot establish your identity beyond doubt, we may ask you for additional information to confirm it.

12. Right to lodge a complaint

If you believe that the processing of your data infringes regulations, you may lodge a complaint with the supervisory authority (Article 77 GDPR): Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, 1000 Ljubljana; telephone: +386 1 230 97 30; email: [email protected]; website: www.ip-rs.si.

We would appreciate it if you contacted us first so that we can resolve any issue together.

13. Minors

The website and its services are not intended for children under the age of 15. We process data of minors (e.g. children in family reunification or citizenship procedures) only when they are provided to us by parents or other legal representatives, and only to the extent necessary for the matter.

14. Changes to this privacy policy

We update this privacy policy from time to time, in particular when regulations or the way we work change. The current version is always published on this page together with its effective date. We notify existing clients directly of material changes that affect the processing of their data.

15. Contact

Lexibor, pravno in poslovno svetovanje d.o.o. (Lexibor, Legal and Business Consulting d.o.o.), Ribnik 7, 1420 Trbovlje · [email protected] · +386 40 832 660