Privacy Policy
Your privacy is very important to us. The Provider respects your privacy and understands the concerns that may arise regarding the privacy and protection of personal data that you provide to us when visiting or using our website or ticket sales platform. Therefore, we kindly ask you to read how the Provider processes your personal data.
The purpose of this Privacy Policy is to present, in a simple and transparent manner, which personal data we collect about you, the legal bases and purposes for which we process it, what options you have regarding the management of your privacy, and which rights you have in relation to the processing of your personal data.
This Privacy Policy complies with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons regarding the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation – GDPR), as well as with the applicable legislation of the Republic of Slovenia.
This Privacy Policy contains the following information:
contact details of the Provider and the contact details of the Data Protection Officer,
legal bases and purposes of personal data processing,
types of personal data we collect,
management of privacy settings,
disclosure of personal data,
personal data retention periods,
protection of personal data,
individuals’ rights regarding personal data, including the right to lodge a complaint,
changes to the Privacy Policy.
1. CONTROLLER AND DATA PROTECTION OFFICER
The controller of personal data is:
KLUB FC KOPER - CLUB CC CAPODISTRIA
Ljubljanska cesta 2
6000 Koper - Capodistria
(hereinafter: the “Provider”).
Email: info@fckoper.si
Ticket sales website: https://tickets.fckoper.si/platforma
Data Protection Officer:
WPM, spletne storitve, d.o.o.
Brnčičeva ulica 13
1231 Ljubljana - Črnuče
Email: info@wpm.si
You can contact the controller and/or the Data Protection Officer using the contact details provided above.
Your questions regarding this Privacy Policy, the confidentiality of your personal data, the methods of processing, or requests concerning the exercise of your personal data rights will be answered by the responsible person of the controller and/or the Data Protection Officer.
2. LEGAL BASES AND PURPOSES OF PROCESSING
The Provider collects, records, organizes, stores, discloses, and otherwise processes personal data held about you on the basis of various legal grounds and for the purposes defined below.
2.1. Processing based on a contract – purposes
The Provider processes individuals’ personal data to exercise rights and fulfil obligations arising from concluded contracts, particularly within contracts related to the sale, purchase, or reservation of products or tickets. This includes processing personal data of customers or users of the online store for purchasing or reserving tickets through the website listed in Article 1, regardless of whether the individual creates a user account.
For the purpose of exercising rights and fulfilling contractual obligations, the Provider processes individuals’ personal data for the purposes of identification, conclusion of the contract (where the contract is considered concluded at the moment when the Provider sends the customer an email confirming the status of their purchase or reservation), communication with the individual, providing customer support, processing orders or reservations, sending notifications related to the order or reservation, and other purposes necessary for fulfilling the contract.
In the case of a purchase, the Provider also processes personal data for the purpose of carrying out potential debt collection procedures and for its own accounting and tax purposes.
2.2. Processing based on legal obligations – purposes
The Provider also processes individuals’ personal data based on legal obligations applicable to the Provider, particularly for fulfilling obligations arising from tax, accounting, and other applicable legislation.
2.3. Processing based on legitimate interests – purposes
The Provider may process personal data based on legitimate interests pursued by the Provider, except where such interests are overridden by the interests, fundamental rights, or freedoms of the individual requiring protection of personal data.
Where further processing of personal data collected about an individual takes place, the Provider carries out an assessment in accordance with the General Data Protection Regulation (GDPR). Such further use of data in pseudonymized or aggregated form may represent lawful use of data for the Provider’s marketing, business, and technical analyses. As an additional security measure, partial deletion or anonymization of data may also be applied in certain forms of further processing.
Based on legitimate interests, the Provider processes personal data to the extent necessary and proportionate for ensuring the operation of online services, improving user experience, and protecting its intellectual property rights related to online services.
Based on legitimate interests, the Provider may process customers’ personal data for direct marketing purposes related to purchased or reserved tickets, including informing users about similar events, offers, updates, or benefits. Individuals have the right to object to such processing at any time, free of charge and in a simple manner.
Based on legitimate interests, the Provider may also process personal data for preventing misuse, enforcing claims, or defending against claims in administrative, judicial, or other proceedings.
2.4. Processing based on consent – purposes
The Provider processes individuals’ personal data based on their explicit consent for the following purposes:
direct marketing and receiving notifications about events, offers, updates, and benefits;
conducting marketing analyses, customer segmentation and profiling, and providing personalized offers of products and services.
When purchasing or reserving tickets, individuals are informed about the possibility of processing their personal data for direct marketing purposes and may provide consent for receiving marketing communications and personalized offers by email, SMS, MMS, or in printed form sent to the provided address.
Where consent includes direct marketing based on an individual profile, the Provider may classify individuals into segments based on their use of the Provider’s websites and services, exclusively for the purpose of providing personalized marketing content.
Individuals may withdraw their consent at any time in the manner described in this Privacy Policy. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Direct marketing is not carried out through automated decision-making that would have legal effects on an individual or similarly significantly affect them.
3. PERSONAL DATA WE COLLECT
The Provider collects various information about you, including personal data that can directly or indirectly identify you, if you or others decide to share such personal data with the Provider. Data may be obtained through several methods, including purchasing in the online store, subscribing to email notifications (direct marketing), or visiting the Provider’s websites. The Provider collects information about your use of the services we provide.
The personal data we collect includes:
basic personal data such as first name and surname, date of birth, email address, residential address (street, street number, postal code, city, country), and telephone number.
4. COOKIES
When you use our online services, cookies are stored on your computer. In general, cookies and similar technologies work by assigning a unique identifier to your browser or device, which has no meaning outside the Provider.
The Provider uses these technologies to personalize your experience and help provide content specific to your use.
You can manage the collection of information through cookies or similar technologies using the settings of your browser or mobile device. The Provider is committed to enabling privacy management and sharing preferences but does not assume responsibility for ignored “Do Not Track” signals sent through web browsers. Refusing cookies may result in some features of the services not being available.
5. DISCLOSURE OF PERSONAL DATA
5.1. Contractual processors
The Provider may disclose your personal data to third parties with whom it has concluded personal data processing agreements (hereinafter: contractual processors) for the purposes of support, analysis and continuous improvement of services, payment processing, or order delivery.
Contractual processors only have access to personal data necessary to provide the services they perform for us and may only use such data for performing these tasks on our behalf. They may not use the data for any other purpose and are required to protect your personal data.
The Provider may cooperate with contractual processors that process statistical data about how you use our services for advertising purposes or displaying information that may be of interest to you. Such processors only have access to anonymized data.
5.2. Joint controllers
Your personal data may be shared with contractual partners with whom we act as joint controllers and who process your personal data in accordance with this Privacy Policy.
5.3. Universal legal succession
In the event of a merger, business restructuring, division, or transfer of activities to a third party, your data may be transferred to a third party connected with the acquisition of the Provider.
5.4. Public authorities
Regardless of the retention periods defined in this Privacy Policy, your personal data may be stored for a longer period and disclosed to third parties such as the police, prosecution authorities, courts, and other competent state authorities in or outside the Republic of Slovenia where such disclosure is necessary and required by law, including for preventing, investigating, detecting, or prosecuting criminal offences.
Your personal data may also be disclosed to state authorities where necessary for exercising, enforcing, or defending legal claims in judicial, administrative, or out-of-court proceedings.
5.5. Transfers of data to countries outside the EU or EEA
When using online services outside EU Member States, data may be transferred, stored, or processed in third countries where data protection legislation may provide different standards than those in EU or EEA countries.
By using services outside the EU, you agree that personal data may be transferred or disclosed to entities located in third countries. The Provider itself will not transfer your personal data outside the EU or EEA.
6. PERSONAL DATA RETENTION PERIODS
We retain personal data for as long as necessary to provide our services or longer where legal obligations apply.
Data related to ticket orders and related contact information may be retained for fulfilling contractual obligations until full payment has been completed or until the expiry of any applicable limitation period, which may legally be up to five years. In accordance with tax regulations, issued invoices are retained for 10 years after the end of the year in which the invoice was issued.
Personal data obtained through ticket orders is retained until consent is withdrawn, but for no longer than five years.
Data that is no longer required for the purposes for which it was collected may be anonymized and combined with other data that does not allow identification of individuals, for statistical information useful to the Provider, such as statistics on the use of services.
Such data is anonymized and cannot be linked to an identifiable individual.
7. PERSONAL DATA PROTECTION
We implement various technical and organizational measures to ensure the security of personal data during collection, transfer, and storage.
The Provider strives to appropriately protect your personal data but cannot guarantee complete security and is not responsible for theft, destruction, loss, intentional or accidental disclosure of your personal data or information about you.
The Provider follows generally accepted standards for protecting received information during transfer and after receipt. However, no electronic transmission or storage method is 100% secure, and complete security cannot be guaranteed.
The Provider uses SSL (Secure Sockets Layer) technology to encrypt personal data and cooperates with companies providing security services for our services and your personal data.
Users are also responsible for protecting their own data by ensuring the security of their mobile device or computer, protecting usernames and passwords, and using appropriate antivirus protection.
8. INDIVIDUAL RIGHTS
Requests regarding the exercise of rights may be sent to the Provider’s email address or to info@wpm.si, or by post to the addresses listed above.
The individual must provide proof of identity and/or address if the request is not submitted from the registered user email address.
The Provider will respond to requests in accordance with applicable regulations.
Individuals have the following rights regarding their personal data:
8.1. Right of access
Individuals may request confirmation at any time whether their personal data is being processed and, if so, access to their personal data and information about its processing.
8.2. Right to erasure
Individuals may request deletion of their personal data under the conditions defined by applicable regulations (the “right to be forgotten”).
8.3. Right to data portability
Individuals may request that personal data be provided in a structured, commonly used, and machine-readable format or transferred to another controller where technically feasible.
8.4. Right to object
Where personal data is processed based on legitimate interests, individuals may object to such processing in certain cases.
The Provider will stop processing such data unless it demonstrates legitimate reasons for continued processing or processing is required for legal reasons.
8.5. Withdrawal of consent
Individuals may withdraw consent at any time where processing is based on consent.
Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
8.6. Right to lodge a complaint with a supervisory authority
Individuals have the right to lodge a complaint with the Information Commissioner of the Republic of Slovenia if they believe their personal data is processed contrary to applicable data protection regulations.
9. CHANGES TO THE PRIVACY POLICY
The Provider reserves the right to amend this Privacy Policy according to circumstances and applicable data protection legislation.
Please review it periodically.
You will be appropriately informed in advance about changes regarding the processing of your personal data and/or updates to this Privacy Policy.
Changes will also be published on our websites in a timely manner.
If you do not agree with this Privacy Policy, please stop using our online services and withdraw any provided consents.
The Privacy Policy was last updated on 18 May 2026.




