This policy explains how Hiša dobrot d.o.o. (Rizibizi) collects, uses and protects your personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Slovenian law.
Last updated: May 2026The controller of your personal data is:
For any questions regarding the protection of your personal data, please contact us at the email address above.
We collect only the personal data strictly necessary to provide our services.
We process your data (name, contact details, date, preferences) for the purpose of confirming and managing table reservations and responding to your enquiries. The legal basis is the performance of a contract or pre-contractual measures (Article 6(1)(b) GDPR).
When you contact us, we process your data to communicate with you and resolve your queries. The legal basis is the legitimate interest of the controller (Article 6(1)(f) GDPR).
We process certain data because we are required to do so by law (e.g. accounting and tax regulations). The legal basis is compliance with a legal obligation (Article 6(1)(c) GDPR).
Where you have given us explicit consent, we send you notifications about special offers, seasonal menus and events. The legal basis is consent (Article 6(1)(a) GDPR). You may withdraw your consent at any time.
We retain your personal data only for as long as is strictly necessary for the purpose of collection, or as required by legal obligations:
After the retention period expires, data is securely deleted or anonymised.
We do not sell or share your personal data with third parties for their own purposes. Data may be shared with the following categories of processors:
We have data processing agreements in place with all processors, ensuring an appropriate level of protection.
We do not transfer data to third countries outside the EU/EEA without appropriate safeguards (standard contractual clauses, adequacy decision).
Under the GDPR, you have the following rights regarding your personal data:
If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the supervisory authority for data protection in Slovenia:
Our website uses cookies — small text files stored in your browser. We distinguish between:
These ensure the basic functioning of the website (sessions, WordPress security cookies). These cannot be disabled.
We use Google Analytics to understand how visitors use our website. Data is anonymous and aggregated. These cookies are not placed without your consent.
You may change your consent for non-essential cookies at any time via the cookie banner or your browser settings. Please note that disabling cookies may affect the functionality of certain features of the website.
We protect your data with appropriate technical and organisational measures:
Despite all measures, no method of transmission or storage is 100% secure. In the event of a data breach that endangers your rights, we will notify you in accordance with the GDPR.
We may update this Privacy Policy from time to time to reflect changes in our practices, legislation or technology. With each change, we will update the “Last updated” date at the top of this page.
For significant changes, we will notify you via the website or directly (where we hold your contact details and you have given consent for this). We recommend reviewing this policy regularly.
For all questions, requests or complaints regarding the processing of your personal data, please contact us:
Obala 20, 6320 Portorož, Slovenia
We respond to all requests within 30 days.