Privacy Notice
Contents
1. Who we are and how to contact us
The controller of your personal data is:
Company | Nutrisslim, proizvodnja in distribucija živil, d.o.o. (short form: Nutrisslim d.o.o.), a private limited company incorporated under the law of Slovenia |
Registered office | Obrtniška ulica 4, 1292 Ig, Slovenia |
Company registration number | 3711676000 |
VAT identification number (EU) | GB361629785 |
Companies register | District Court in Ljubljana (Okrožno sodišče v Ljubljani), file no. 2010/9888 |
Brand | Nature’s Finest |
Website | www.nutrisslim.uk |
Customer service telephone | The customer service number published on the website |
Support hours | Monday to Friday, 8.00 am to 4.00 pm |
Data protection officer | |
UK representative (Article 27 UK GDPR) | Our appointed UK representative can be reached at [email protected], and the representative’s name and UK postal address are published on the website alongside this notice |
We have appointed a data protection officer under Article 37 UK GDPR and under Article 45 of the Slovenian Personal Data Protection Act (ZVOP-2). The Data (Use and Access) Act 2025 did not remove the data protection officer role from UK law, so the same officer acts for our UK processing. You may contact the officer about any question concerning the processing of your personal data and about exercising your rights.
We are established in Slovenia and have no establishment in the United Kingdom. Because we offer goods to people in the UK, Article 27 UK GDPR requires us to appoint a representative in the UK. You may contact our UK representative in addition to, or instead of, contacting us directly, on all matters relating to the processing of your personal data. Contacting the representative has the same effect as contacting us.
2. Who and what this notice applies to
This notice explains how we handle the personal data of visitors to www.nutrisslim.uk, customers, newsletter subscribers, account holders, people who contact us by telephone or email, and users of our subscription purchases and our referral programme.
Cookies are covered by a separate Cookie Notice, and purchases are governed by our Terms and Conditions of Sale and our Subscription Terms.
This notice is issued for the purposes of Articles 13 and 14 UK GDPR — the retained EU General Data Protection Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018 and as amended, in particular by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 and by the Data (Use and Access) Act 2025 — read with the Data Protection Act 2018.
3. What personal data we process
- Identity and contact data: first name and surname, delivery address and billing address, email address, telephone number.
- Order data: the contents of your order, its value, the delivery method, the payment method, your purchase history, complaints and returns.
- Payment data: transaction details. We do not store and cannot access your full payment card number — it is handled by the payment service provider. For subscription purchases, the payment service provider stores a token that allows recurring charges.
- Account data: username, encrypted password, settings.
- Communications data: the content of emails and messages, notes of customer service calls, complaint records.
- Consent records: kept separately for each channel — channel, status, date and time, language, source of the consent, the version and wording of the consent, and the date of any withdrawal.
- Website usage data: IP address, device and browser type, pages viewed, click path and traffic source. More detail is in the Cookie Notice.
- Questionnaire and personalisation data: your answers about your goals and habits.
- Special category data: for the DNA Nutrigenetic test, genetic data and data concerning health, which we process only on your explicit consent under Article 9(2)(a) UK GDPR. We should also be straightforward with you about a subtler point: because we sell food supplements, the simple fact of what you buy — for example a joint, sleep or menopause product — can suggest something about your health. We do not treat ordinary purchase history as health data and we do not draw health inferences from it, but where in an individual case an inference about your health would in substance be drawn, we treat that data as special category data and rely on your explicit consent under Article 9(2)(a) UK GDPR.
- CCTV images at the entrances to our business premises.
Where we rely on explicit consent under Article 9(2)(a) UK GDPR, no additional condition in Schedule 1 to the Data Protection Act 2018 is required. Where we process special category data to establish, exercise or defend legal claims we rely on Article 9(2)(f) UK GDPR, and where we process such data to prevent or detect fraud or another unlawful act we rely on Article 9(2)(g) UK GDPR together with paragraph 10 (preventing, investigating or detecting unlawful acts) or paragraph 14 (preventing fraud) of Part 2 of Schedule 1 to the Data Protection Act 2018. We maintain the appropriate policy document required by paragraph 5 of that Part.
4. Purposes, lawful bases and retention periods
Purpose | Lawful basis | Data | Retention period |
|---|---|---|---|
Entering into and performing the contract of sale — processing the order, delivery, payment, complaints, returns | Performance of a contract (Article 6(1)(b) UK GDPR) | Identity and contact data, order and payment data | 6 years from completion of the order, matching the limitation period in England, Wales and Northern Ireland (section 5 of the Limitation Act 1980); the equivalent period in Scotland is 5 years |
Issuing and keeping invoices and tax records | Legal obligation (Article 6(1)(c) UK GDPR, UK and Slovenian tax law) | Invoice data | 6 years from the end of the accounting period, in line with HMRC record-keeping rules for VAT |
Customer account | Consent (Article 6(1)(a) UK GDPR) | Account data and purchase history | Until you delete the account, or 3 years of inactivity |
Customer service by telephone — taking and confirming orders, complaints, support | Performance of a contract (Article 6(1)(b) UK GDPR) | Contact data, the content of the call, call records | Call recordings 12 months; everything else with the order |
Marketing by email and SMS | Consent (Article 6(1)(a) UK GDPR); for existing customers, our legitimate interest in telling you about our own similar products (Article 6(1)(f) UK GDPR), relying on the soft opt-in in regulation 22(3) of the Privacy and Electronic Communications (EC Directive) Regulations 2003 | Name, email address, telephone number, purchase history | Until you withdraw consent or object; we keep the record of the withdrawal for 5 years as evidence |
Marketing by telephone (live calls) | Our legitimate interest in offering our products to our customers (Article 6(1)(f) UK GDPR), subject to regulation 21 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 and screening against the Telephone Preference Service; consent (Article 6(1)(a) UK GDPR) where you have given it, and consent is always required for automated recorded-message calls under regulation 19 | Name, telephone number, purchase history, objection and consent records | Until you object or withdraw consent; we keep the record for 5 years afterwards |
Personalising offers and recommendations | Consent (Article 6(1)(a) UK GDPR) | Purchase history, questionnaire answers, behaviour on the website | Until you withdraw consent, or 5 years from your last activity |
Subscription purchases | Performance of a contract (Article 6(1)(b) UK GDPR) | Subscription details, recurring payment token, charge history | For the life of the subscription and 6 years afterwards |
Referral programme | Consent (Article 6(1)(a) UK GDPR) | Name, contact detail, referral and reward records | Until you withdraw consent, or 2 years from your last activity |
DNA Nutrigenetic test | Explicit consent (Article 9(2)(a) UK GDPR) together with performance of a contract (Article 6(1)(b) UK GDPR) | Biological sample (saliva), first name and surname, date of birth, body weight and height, analysis results, contact data | 5 years after the end of the calendar year in which the analysis was carried out, or until you withdraw consent |
Product reviews and ratings | Consent (Article 6(1)(a) UK GDPR) | Name or nickname, the content of the review, confirmation of purchase | Until you withdraw consent or the review is removed |
General questions and enquiries | Our legitimate interest in answering enquiries (Article 6(1)(f) UK GDPR) | Contact data, the content of your message | 3 months after the matter is closed |
Handling data protection complaints | Legal obligation (Article 6(1)(c) UK GDPR, section 164A of the Data Protection Act 2018) | Your complaint, our acknowledgement, enquiries and outcome | 3 years from the date the complaint is closed |
CCTV at business premises | Our legitimate interest in protecting people and property (Article 6(1)(f) UK GDPR) | Camera images | 3 months |
Preventing fraud and abuse | Our legitimate interest in protecting against abuse (Article 6(1)(f) UK GDPR) | Order data, IP address, behaviour patterns | 2 years |
Establishing, exercising and defending legal claims | Our legitimate interest (Article 6(1)(f) UK GDPR) | The data needed for the claim | Until the matter ends and the limitation period expires — 6 years in England, Wales and Northern Ireland, 5 years in Scotland |
The legitimate interests we rely on are: protecting people and property, preventing fraud and abuse, answering enquiries, establishing and defending legal claims, and telling existing customers about our own similar products by email, SMS and telephone. Before relying on this basis we carry out a legitimate interests assessment and consider whether our interest is overridden by your rights and reasonable expectations. You may object to any processing on this basis at any time. We do not rely on the “recognised legitimate interests” list introduced into Article 6 UK GDPR by the Data (Use and Access) Act 2025, because those grounds are aimed at matters such as national security, crime and public protection rather than at commercial processing of this kind.
Do you have to provide your data? The data marked as required when you place an order — first name and surname, delivery address, email address and telephone number — is a contractual requirement. Without it we cannot process and deliver your order. Invoice data is a legal requirement. Everything else, in particular marketing consents, questionnaire answers and DNA test data, is entirely voluntary. If you do not provide it, this has no consequences for your purchase.
5. Marketing by email, SMS and telephone
We keep marketing permissions separately for each channel. Permission for one channel is not permission for another. Buying from us is never conditional on giving permission.
The rules that apply to electronic marketing in the UK are in the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), which sit alongside the UK GDPR and are enforced by the Information Commissioner’s Office.
5.1 Email and SMS
We send newsletters, special offers and personalised recommendations by email and SMS on the basis of your consent, as required by regulation 22 PECR.
If you have already bought from us, we may also send you offers for our own similar products by email or SMS without asking for separate consent. This is the “soft opt-in” in regulation 22(3) PECR: we obtained your contact details in the course of a sale or negotiations for a sale of our own similar goods, we gave you a simple means of refusing at the point we collected them, and we give you the same simple, free means of refusing in every message we send. The soft opt-in applies only to our own similar products and never to marketing on behalf of another organisation.
5.2 Telephone
The UK rules on live marketing calls work on an opt-out basis, which is different from the position in most EU countries. Under regulation 21 PECR we must not make an unsolicited live marketing call to you if you have told us you do not want such calls, or if your number is registered with the Telephone Preference Service (TPS) — or, for a corporate subscriber, the Corporate Telephone Preference Service (CTPS) — unless you have specifically told us that you are happy to receive our calls.
We therefore screen every number against the TPS and the CTPS before we call, and we screen against our own internal do-not-call list. If your number is registered and you have not told us you are happy to hear from us, we will not call you.
A telephone number you gave us so that we could process and deliver your order is not, by itself, permission for marketing calls, and we do not use it for that purpose. Our customer service team may call you without any marketing permission, but only about your order — confirming the order, arranging delivery, dealing with a complaint or return, or answering your question. That is not marketing.
Automated calls. We do not send recorded-message marketing calls. Under regulation 19 PECR those require your prior specific consent, and the soft opt-in does not apply to them.
On every marketing call we tell you which company is calling and why, we do not conceal our identity, and we present a valid telephone number that is not a premium-rate number, as regulation 24 PECR requires. We also remind you that you can object to further calls at any time. We act on an objection immediately and permanently.
5.3 How to stop marketing
You can withdraw your consent, or object, at any time and free of charge: through the link in every email, by replying to an SMS, in your account, by emailing [email protected], or during a telephone call. Withdrawal does not affect the lawfulness of processing carried out before it.
You have an absolute right under Article 21(2) UK GDPR to object to processing for direct marketing at any time, whatever the lawful basis, and we do not have to weigh anything against it. Once you object we stop processing your data for marketing. You can also register your number free of charge with the Telephone Preference Service at tpsonline.org.uk.
6. Personalisation and profiling
If you have consented, we build a profile of your interests — for example health, beauty, detox or weight management — from your purchase history, your questionnaire answers and your behaviour on the website. We use that profile to show and send you offers and recommendations that are more likely to be relevant to you, and to reduce content you are not interested in.
The logic involved. We group products into content categories, match your past purchases, answers and viewed pages to those categories, and calculate which categories are most likely to interest you. We do not assess your creditworthiness, your state of health or anything similar.
What it means for you. Profiling affects only which offers and content you see. It has no legal effects and no similarly significant effects within the meaning of Article 22 UK GDPR. The price of a product, its availability and the terms of purchase do not change because of your profile. We do not carry out automated decision-making that produces legal or similarly significant effects. The Data (Use and Access) Act 2025 relaxed parts of Article 22 for decisions that do not involve special category data, but it kept the safeguards of information, human intervention and the right to contest — and in any event we do not take such decisions about you.
You can object to profiling or withdraw your consent at any time. If you do, you will still see our general offers, just not tailored ones.
If you have taken the DNA Nutrigenetic test, the results are used for recommendations only within the test service itself and only on your explicit consent. We do not use genetic data for general marketing profiling and we do not disclose it to advertising platforms.
7. Where we obtain data we did not get from you
We get most data directly from you. In the following cases we may obtain it elsewhere, and this section is our notice to you under Article 14 UK GDPR:
- Referral programme. If an existing customer referred you to us, we receive your name and your email address or telephone number from them. The existing customer must confirm to us that they have your agreement. We tell you about this at first contact and let you refuse any further contact.
- Payment service providers and carriers. Information about the status of a payment or a delivery.
- Marketplaces and business partners. If you bought a product through a marketplace or a partner, we receive from them the data needed for delivery and for handling complaints.
- Publicly available sources. For business partners, information from public company registers such as Companies House.
We do not buy or rent personal data from third parties for marketing purposes.
8. Who we share personal data with
Inside the company, only those employees who need your data for their work have access to it, and only to the extent needed. All of them are bound by confidentiality.
Outside the company, we share personal data with the following recipients:
Recipient | Purpose | Location |
|---|---|---|
Klaviyo, Inc. | Sending newsletters and SMS messages, personalising messages | United States of America |
Stripe, Inc. and Stripe Payments Europe, Ltd. | Processing card payments and recurring charges, fraud prevention | Ireland and United States of America |
PayPal (Europe) S.à r.l. et Cie, S.C.A. | Processing payments through PayPal | Luxembourg |
General Logistics Systems (GLS) and its UK delivery partners | Delivering your order and sending you shipment updates | Slovenia, the European Union and the United Kingdom |
Customs broker and import agent | Customs clearance of your parcel into the United Kingdom and payment of import VAT and duty on our behalf | United Kingdom and the European Union |
Mention Me Ltd. | Running the referral programme and tracking referrals | United Kingdom |
Google Ireland Ltd. | Traffic measurement and advertising — only with your cookie consent | Ireland (with possible processing in the United States of America) |
Meta Platforms Ireland Ltd. | Advertising and measuring advertising performance — only with your cookie consent | Ireland (with possible processing in the United States of America) |
Microsoft Ireland Operations Ltd. | Analysing how the website is used — only with your cookie consent | Ireland (with possible processing in the United States of America) |
Functional Software, Inc. (Sentry) | Detecting and fixing technical errors on the website | United States of America |
Website hosting and maintenance provider | Running the online shop and providing technical support | European Union |
Genetic analysis laboratory | Carrying out the DNA Nutrigenetic test | Denmark and the United Kingdom |
Accountants, auditors and legal advisers | Bookkeeping, audit, legal advice | Slovenia and the United Kingdom |
Public authorities | Where the law requires it | Courts, HM Revenue & Customs, trading standards, the Information Commissioner’s Office and equivalent authorities |
We have a written contract meeting the requirements of Article 28 UK GDPR with every processor. We do not sell personal data.
You can ask for our current list of processors at any time at [email protected].
9. International transfers
Because we are established in Slovenia, personal data you give us is processed in the European Economic Area from the moment you place your order. Under Chapter V of the UK GDPR (Articles 44 to 49) and Part 2 of the Data Protection Act 2018, a transfer of UK personal data to another country is a restricted transfer and needs a lawful transfer mechanism.
- European Economic Area, including Slovenia. The UK has made adequacy regulations covering the EEA, so we may transfer your data there without further safeguards. This is the mechanism for our own everyday processing of your order.
- United States of America. Where the recipient is certified under the UK Extension to the EU–US Data Privacy Framework — the “UK–US data bridge”, which has been in force since 12 October 2023 — we rely on the UK adequacy regulations for that framework. Certification under the EU–US Data Privacy Framework alone is not enough: the recipient must be certified for the UK Extension specifically, and we check the public Data Privacy Framework list before relying on it. Where a recipient is not certified for the UK Extension, we use the International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum to the EU Standard Contractual Clauses, both issued by the Information Commissioner under section 119A of the Data Protection Act 2018 and in force since 21 March 2022, supported by a transfer risk assessment and additional safeguards where needed.
- Other countries. We use the IDTA or the Addendum with a transfer risk assessment, or, where neither is available, an exception under Article 49 UK GDPR.
The European Commission’s Implementing Decisions (EU) 2021/914 (standard contractual clauses) and (EU) 2023/1795 (EU–US Data Privacy Framework) are the equivalent EU-side instruments. They are not the operative mechanism for transfers of UK personal data, and we refer to them only because they govern onward transfers made from our EU operations.
Transfers in the other direction are also covered. The European Commission renewed its adequacy decisions for the United Kingdom on 19 December 2025, so personal data can flow freely between the EU and the UK until 27 December 2031.
You can obtain a copy of the safeguards we use, free of charge, by writing to [email protected].
10. Cookies
We do not store or read cookies that are not strictly necessary for the website without your consent, as regulation 6 PECR requires. You can change or withdraw your consent at any time through the “Cookie settings” button in the footer of the website. A detailed list of cookies with the name, provider, purpose and duration of each is in the Cookie Notice.
11. Security of personal data
We have put in place technical and organisational measures appropriate to the risk, as Article 32 UK GDPR requires: encrypted transmission using TLS, encrypted storage of passwords, access control on a least-privilege basis, access logging, regular backups, written contracts with our processors and regular staff training.
Special category data — the genetic and health data from the DNA Nutrigenetic test — is subject to further measures: separate storage, encryption at rest, a named and restricted group of people with access, and a processing log. We also maintain the appropriate policy document required by paragraph 5 of Part 2 of Schedule 1 to the Data Protection Act 2018.
If a personal data breach is likely to result in a risk to your rights and freedoms, we report it to the Information Commissioner’s Office within 72 hours under Article 33 UK GDPR, and we tell you directly without undue delay where the risk is high.
12. Your rights
You have the following rights in relation to your personal data:
- Access (Article 15). The right to be told whether we process your data and to receive a copy of it.
- Rectification (Article 16). The right to have inaccurate data corrected and incomplete data completed.
- Erasure (Article 17). The right to have data deleted where it is no longer needed, where you withdraw consent and there is no other basis, where you successfully object, or where the data was processed unlawfully.
- Restriction (Article 18). The right to ask us to pause our processing.
- Portability (Article 20). The right to receive the data you gave us in a structured, commonly used, machine-readable format and to send it to another controller.
- Objection (Article 21). The right to object to processing based on legitimate interests, including profiling. You may object to processing for direct marketing at any time and without giving a reason, under Article 21(2), whatever the lawful basis. Once you do, we stop processing your data for marketing.
- Rights relating to automated decision-making (Article 22). Including the right to human intervention and to contest a decision, if we ever took one about you.
- Withdrawal of consent. The right to withdraw a consent you have given, at any time.
- Complaint. To us and to the Information Commissioner — see section 14.
For the DNA Nutrigenetic test you also have the right to ask us not to disclose particular results to you, and the right to ask us to destroy your biological sample.
Send your request to [email protected] or [email protected]. We respond within one month of receipt. If the request is complex, or if we receive a number of requests from you, we may extend that by up to two further months and will tell you within the first month. Where we reasonably need more information to identify you or to find the data you want, the month runs from the point we receive it. Exercising your rights is free of charge. We may ask for further information to confirm your identity, so that we do not disclose your data to someone else.
13. Withdrawing your consent
Where processing is based on your consent, you may withdraw it at any time, and it must be as easy to withdraw as it was to give. Withdrawal does not affect the lawfulness of processing carried out before it. We keep consents separately by channel, so withdrawing for one channel does not withdraw the others. If you want all marketing to stop, tell us and we will withdraw every consent for you.
14. Complaints and the Information Commissioner
If you are unhappy with how we have handled your personal data, please tell us first. Since 19 June 2026, section 164A of the Data Protection Act 2018 — inserted by the Data (Use and Access) Act 2025 — requires us to give you a way of making a data protection complaint directly to us, and we do.
How to complain to us. Email [email protected] with “Data protection complaint” in the subject line, or write to us at our registered office, or contact our UK representative. You can also raise a complaint through any of our normal contact routes and we will treat it as a complaint. We will acknowledge your complaint within 30 days of receiving it, take appropriate steps to look into it without undue delay, keep you updated, and tell you the outcome. You do not have to use a particular form or wording.
You also have the right to complain to the supervisory authority. For people in the United Kingdom this is the Information Commissioner’s Office. There is no “one-stop shop” for UK complaints, so you should go to the ICO rather than to an EU authority:
Supervisory authority | Information Commissioner’s Office (ICO) |
Address | Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom |
Telephone | 0303 123 1113 |
Website | ico.org.uk |
The ICO also enforces PECR, including the rules on marketing emails, texts and calls and on cookies. Since the Data (Use and Access) Act 2025 raised PECR penalties to UK GDPR levels, the ICO can fine an organisation up to £17.5 million or 4% of total worldwide annual turnover, whichever is higher, for a serious PECR breach.
The Slovenian Information Commissioner (Informacijski pooblaščenec, Dunajska cesta 22, 1000 Ljubljana, [email protected]) is our lead supervisory authority for processing governed by EU law. It is not the authority for a UK data protection complaint. We would be glad if you came to us first — most questions can be sorted out quickly and directly.
15. Children
We sell our products and services to adults. We do not offer information society services directly to children. Where processing is based on consent, section 9 of the Data Protection Act 2018 sets the age at which a child can consent in their own right to an information society service at 13 in the United Kingdom. Below that age, the consent of a person holding parental responsibility is needed. The UK age of 13 is lower than the 16 that applies in several EU countries.
The DNA Nutrigenetic test for a person under 18 is possible only with the explicit consent of their parent or guardian.
16. Changes to this notice
We may change this notice when our services, our technology or the law changes. Every version shows a version number and the date it comes into force. We will tell you about important changes by email or by a notice on the website at least 15 days before they take effect. Where a change needs your consent, we will ask for it separately.
Nutrisslim d.o.o., Obrtniška ulica 4, 1292 Ig, Slovenia · Privacy Notice, version 2.0 · in force from 12 August 2026 · replaces the previous version