PRIVACY NOTICE
for the website, Slovak B2C e-shop and related TIENS services
Version 1.0 | Effective from August 26, 2026
The controller of personal data is TIENS SLOVAKIA, s.r.o., Company ID No. 35 846 895, Tax ID No. 2020289392, VAT ID No. SK2020289392, with its registered office at Námestie SNP 2093/13, 960 01 Zvolen, Slovak Republic (“TIENS”, “we” or the “Controller”).
Contact point for privacy questions and the exercise of data-protection rights: office@tienssk.sk or info@tienssk.sk, telephone +421 2 4363 1977, postal address Námestie SNP 2093/13, 960 01 Zvolen, Slovak Republic. Customer centre: Kopčianska 14, 851 01 Bratislava, Slovak Republic.
2. Who this Notice applies to
This Notice applies in particular to visitors to tienssk.sk, customers using b2c-sk.tiens.com, users of customer accounts, persons contacting support, recipients of marketing communications and participants in events, training sessions and competitions. It applies to independent distributors to the extent stated below; their contractual relationship may be supplemented by a separate privacy notice.
3. What data we process, why and for how long
We process only data that is proportionate to the relevant purpose. If data is no longer required and there is no other legal ground for continued retention, we delete or anonymise it.
| Activity | Typical data | Purpose | Legal basis | Retention | |
| Website operation and security | IP address, technical logs, device, security events | Secure operation, diagnostics and prevention of misuse | Legitimate interests; strictly necessary technologies | As long as required, usually days to months | |
| Order, payment and delivery | Name, contact details, address, order, price, payment and delivery data | Contract conclusion and performance, delivery and support | Performance of a contract | For the contractual relationship and then for statutory and limitation periods | |
| Customer account | Identification and contact data, login, order history, settings | Account administration and security | Contract; legitimate interests in security | For the life of the account and a necessary period after closure | |
| Accounting and tax | Billing data, orders, payments and tax documents | Accounting, tax and record-keeping duties | Legal obligation | For statutory retention periods; generally 10 years depending on the document | |
| Withdrawal, defects and disputes | Identity, order, defect details, photographs and communications | Handling statutory rights and protecting legal claims | Contract, legal obligation, legitimate interests | For the case and then for the period in which claims may be asserted | |
| Enquiries and customer support | Name, e-mail, telephone, message, order or distributor number | Responding to and handling a request | Pre-contractual steps, contract or legitimate interests | For handling and a reasonable follow-up period | |
| Newsletter - consent | E-mail, possibly name, consent and opt-out records | Offers and news | Consent | Until withdrawal; evidence of consent as long as needed to demonstrate compliance | |
| Offers to existing customers | E-mail, necessary purchase history and opt-out record | Offers of our own similar products or services | Legitimate interests together with the statutory direct-marketing regime | Until opt-out or the statutory conditions cease to apply | |
| Website analytics and marketing | Online identifiers, events, device and approximate location | Usage and campaign measurement, marketing personalisation | Consent | By technology and consent validity; see Cookie Policy | |
| Events, training and competitions | Contact details, registration, participation, possibly photo or video | Organisation, communications, rules and documentation | Contract/rules; consent where required | By purpose, rules and limitation periods | |
| Independent distributors | ID, contact and contract data, sponsor/structure, orders, performance, commissions, payments, training and compliance data | Contract, network and reward administration, support, accounting and fraud prevention | Contract, legal obligation, legitimate interests | For the relationship and then for accounting, tax and limitation periods |
4. Sources of personal data
• directly from you when you order, register, contact us, attend an event or give consent;
• from use of the websites and applications where this is permitted by the legal basis and your cookie settings;
• from payment, delivery and other service providers to the extent required for a transaction or incident;
• for distributors, also from the TIENS distribution system and structure and from order, performance, reward and sponsorship records;
• from public sources only where proportionate to the purpose and legally permitted.
5. Health data and other sensitive data
We do not require information about your health for ordinary sales. Do not send diagnoses, medical reports or other sensitive health information through general contact forms unless it is necessary for a specific request.
If TIENS specifically collects or publishes a testimonial, case study or other material containing health information identifying a person, we will rely on an appropriate exception under Article 9 GDPR. Where the basis is explicit consent, it will be specific, informed, demonstrable and revocable.
6. Recipients and processors
We disclose data only to the extent necessary. Recipients may include hosting, IT and e-commerce platform providers, payment services, carriers, accounting, tax and legal advisers, CRM and e-mailing providers, analytics and advertising platforms activated according to your consent, TIENS Group companies where necessary for the relevant purpose, and public authorities where required by law.
The publicly accessible online environment uses in particular the Bitrix/Bitrix24 platform, TIENS global CRM and form services, the Weglot translation solution and, in the e-shop, services of the global TIENS e-commerce platform and Google Analytics. Technologies that store or read data on a device are described in more detail in the Cookie Policy.
7. Transfers outside the European Economic Area
Some service providers or TIENS Group companies may operate outside the European Economic Area (the “EEA”). Transfers take place only where GDPR requirements are met, in particular on the basis of a European Commission adequacy decision or appropriate safeguards, typically the European Commission’s Standard Contractual Clauses. We also apply supplementary technical and organisational measures where required by the risk.
For recipients in the United States, an adequacy decision may be relied upon only where the relevant recipient participates in the EU-U.S. Data Privacy Framework. Information about the safeguards used may be requested at office@tienssk.sk; confidential and security-sensitive parts will remain protected.
8. Marketing communications
We send newsletters to persons who are not our customers on the basis of consent. Subject to the statutory conditions, we may send existing customers offers for our own similar products or services where they could easily refuse such use when their contact details were collected and in every subsequent message.
Every marketing communication identifies the actual sender and provides an easy and free means of unsubscribing. We respect an opt-out without undue delay. We may retain a minimal suppression record so that the contact is not inadvertently returned to an active mailing list.
9. Automated decision-making and profiling
With your consent, analytics or marketing tools may create segments for measurement and communications. TIENS does not, without a separate lawful basis, make decisions based solely on automated processing that produce legal effects or similarly significantly affect you. If such processing is introduced, you will receive specific information about its logic, significance and expected consequences.
10. Your rights
Subject to the conditions of the GDPR, you have in particular the right:
• to information about and access to your personal data;
• to rectify inaccurate data and complete incomplete data;
• to erasure where the statutory conditions are met;
• to restriction of processing;
• to object to processing based on legitimate interests; you may object to direct marketing at any time;
• to data portability where the statutory conditions are met;
• to withdraw consent at any time without affecting the lawfulness of processing before withdrawal;
• not to be subject, where the statutory conditions apply, to a decision based solely on automated processing that has legal or similarly significant effects;
• to lodge a complaint or submit a proposal to initiate proceedings with the supervisory authority.
11. How to exercise your rights and lodge a complaint
You may send a request to office@tienssk.sk or to TIENS at its registered office. For security reasons, we may take proportionate steps to verify your identity. We will respond within the time limits laid down by the GDPR.
The supervisory authority is the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky), Galvaniho Business Centrum II, Galvaniho 7/B, 821 04 Bratislava, Slovak Republic. Enquiries from the public may be sent to statny.dozor@pdp.gov.sk.
Information on submitting a proposal is available on the Office for Personal Data Protection of the Slovak Republic website.
12. Data security
We apply technical and organisational measures appropriate to the nature of the data and the risks, including access management, account protection, logging, backups, system updates, supplier management, training of relevant persons and procedures for handling security incidents.
13. Children
The online shop and distribution programme are not primarily intended for children. If we discover that we have obtained a child’s personal data without an appropriate legal basis, we will take proportionate steps to remedy the situation. For events or promotional content involving children, we assess the correct legal basis and any requirement for consent from a legal representative in advance.
14. Changes to this Notice
We may update this Notice when services, providers or legal requirements change. The current version will always be identified by a version number and effective date. This version is effective from August 26, 2026. This English version is provided for convenience; in the event of any inconsistency, the Slovak wording prevails, without prejudice to mandatory data-protection rights.