Privacy statement - compliance with GDPR​

GDPR Compliance Statement

Company Information:

  • Company Name: Forma Brežice d.o.o.
  • Website:,, and (Each domain is for a specific language)
  • Trademark: Foto123®
  • Contact Email:



At Foto123, we are committed to protecting the privacy and security of our customers’ personal data. We understand the importance of complying with the General Data Protection Regulation (GDPR) and strive to uphold the highest standards of data protection.


Data Collection and Processing:

  • We collect and process personal data for the purpose of providing our photography products and services, including photo books, through our website.
  • The personal data we collect may include but is not limited to: name, email address, shipping address, payment information, and any other information necessary to fulfill orders and provide customer support.
  • We only collect personal data that is necessary for the purposes stated and do not retain it for longer than necessary.


Legal Basis for Processing:

We process personal data based on the legal bases outlined in the GDPR, including the necessity of processing for the performance of a contract, compliance with legal obligations, and legitimate interests pursued by the data controller.


Data Security Measures:

We implement appropriate technical and organizational measures to ensure the security and confidentiality of personal data.

  • Access to personal data is restricted to authorized personnel only, and all data is stored securely on our servers.


Data Subject Rights:

Data subjects have the right to request access to, rectification, erasure, or restriction of their personal data processed by Foto123.

  • Data subjects also have the right to data portability and the right to object to the processing of their personal data in certain circumstances.


Additional Requirements for Specific API Scopes:

  • When accessing and utilizing Google Photos API, we ensure compliance with Google’s API Terms of Service and Privacy Policy.
  • We only request access to the specific API scopes necessary for integrating Google Photos with our services, such as accessing and displaying photos for printing in our photo books.
  • Any personal data obtained through Google Photos API is processed in accordance with this GDPR compliance statement and our privacy policy.


Third-Party Services:


  • Google Maps: We may use Google Maps to provide location-based services. Your use of Google Maps is subject to Google’s terms of service and privacy policy.
  • Social Media Services: We may integrate social media services on our website for marketing and communication purposes. Your interactions with these services are governed by their respective privacy policies.
  • E-newsletter: If you subscribe to our e-newsletter, we may collect and process your email address to send you updates and promotional offers. You can unsubscribe from our newsletter at any time by following the instructions provided in the emails.


Google API Services User Data Policy Compliance Disclosure:

Our use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. For more information, please refer to the Google API Services User Data Policy.


Contact Information:

For any questions or concerns regarding data protection and GDPR compliance at Foto123, please contact us at


Changes to this Policy:

We reserve the right to update and modify this GDPR compliance statement as necessary to reflect changes in our data processing practices or legal requirements. Any updates will be posted on our website.

A legal notice

Forma Brežice d.o.o. (hereinafter the provider) is, in accordance with the regulations governing the protection of personal data, obliged to protect the personal data of users. Under no circumstances will the provider forward personal or other user data to a third party or will not allow a third party to view personal or other data of the user, unless it would be requested from him by state authorities, if such an obligation is stipulated by law, or in good faith that such action is necessary for proceedings before courts or other state authorities and for the protection and realization of the legal interests of the provider.

All personal and other data that the user will provide when logging into the online store, as well as when ordering products, including the content of orders, will be protected in accordance with the regulations governing the protection of personal data.

The provider will not use this data for a purpose that would in any way harm the user or another person involved. We will send you various e-editions only if you explicitly subscribe to them.

We will use the information you provide us to fulfill your order and to inform you about news, new products and services, which we can confidently say represent important information for you. The notification will take place only until your cancellation. The company Forma Brežice d.o.o. has no intention and will not send messages and notifications with inappropriate content.

Registered users can request the deletion of their data from the user pages at any time after ceasing to use the service. They do this by notifying us in writing of their request to be deleted from the user pages. The confidentiality of personal data and the privacy of users within the framework of this privacy policy will be protected even in the event of deletion from the user pages.

The website contains links to websites that are not managed by the provider. Such links are provided for informational purposes only and serve as a help. The provider of tek websites does not control and is not responsible for their data collection and management policies. We advise you to read the privacy statement published on the website you visit before using the websites you visit and possibly providing personal data.

The provider reserves the right to change, adapt, add or remove parts of the Statement on privacy and protection of personal data at any time at its own discretion. Please review the content of the Privacy and Personal Data Protection Statement from time to time for possible changes.

Your continued use of our websites after the terms of the Privacy and Personal Data Protection Statement have been changed will mean that you agree to the changes.

Data protection statement

1. Information about the collection of private data

We attach great importance to protecting your privacy and your private data. In this regard, it is very important for us to comply with all provisions related to data protection and to act transparently when processing your data. In the following, we inform you about the collection of personal data when using our website. Personal data is all data relating to a specific or identifiable individual, e.g. name, address, email address, IP address, user behavior.

The administrator according to the seventh paragraph of Article 4 of the EU Regulation on the Protection of Personal Data (SUVP) is the company listed below (hereinafter “we” or “Forma” or “” or “”). The contact person for questions about this data protection declaration is its controller.


Forma Brežice d.o.o.
Mladinska Street 3
8250 Brežice
In principle, we use your personal information only in our own company to provide the services you want.

In addition, we do not forward the data to third parties without your express permission, especially not for advertising purposes. We pass on your personal data only if you yourself have agreed to the transfer of data or if we are based on legal provisions and/or official or court orders entitled or obliged to do so. In particular, this may involve the provision of information for the purposes of law enforcement, the prevention of danger or the enforcement of intellectual property rights.

2. Your rights

In relation to your personal data, you have the following rights towards us:

right of access,
right to rectification,
the right to erasure,
the right to limit processing,
the right to data portability,
the right to object to the processing.
In addition, you have the right to complain to the data protection supervisory authority regarding the processing of your personal data by Forma. You will find the contact details of the supervisory authority for data protection at the following link (

3. Objection or cancellation of the processing of your data

If you have given your consent to the processing of your data, you can revoke this at any time with effect for the future. Such cancellation affects the admissibility of processing your personal data after you express it to us.

Insofar as the processing of your personal data is based on the assessment of interests according to the letter f of the first sentence of the first paragraph of Article 6 SUVP, you can file an objection against the processing. This is the case if the processing is not particularly necessary for the fulfillment of a contract with you. When making such an objection, please provide us with the reasons why we should not process your personal data in the way we have done so far. In case of your justified objection, we will check the actual situation and will either stop data processing or we will adjust it or provide you with urgent legitimate reasons for which we will continue processing.

Of course, you can object to the processing of your personal data for the purposes of advertising and data analysis at any time. You can notify us of your objection to advertising using the contact details provided in this data protection statement.

4. Obtaining personal data when visiting our website

4.1 User data

If you use the website for informational purposes only, i.e. if you do not register or provide us with other information, we only obtain the data that your browser transmits to our server. If you want to view our website, we obtain the following data, which we need from a technical point of view to display our website to you and to ensure stability and security (the legal basis is the letter f of the first sentence of the first paragraph of Article 6 SUVP):

IP address
date and time of inquiry
request content (specific page)
access status/HTTP status code
the amount of data transferred each time
website from which the request comes (referrer URL)
operating system and its interface
language and browser software version
end device
screen resolution
screen color depth
Flash support
Javascript support

4.2 Cookies

In addition to the above data, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive by assigning them to the browser you are using, and with the help of which certain information flows to the site that sent the cookie (in this case to us). Cookies cannot run programs or transfer viruses to your computer. They serve to make the online offer as a whole more user-friendly and more efficient.

This website uses the following types of cookies, the scope and mode of operation of which will be explained below:

Temporary cookies are automatically deleted when you close your browser. This includes session cookies in particular. These store a so-called session ID, with which different queries from your browser can be attributed to a common session. In this way, your computer can be recognized again when you return to our website. Session cookies are deleted when you log out or close your browser.

Persistent cookies are automatically deleted after a certain period of time, which may vary depending on the individual cookie. Cookies can be deleted at any time in the security settings of your browser.

You can configure your browser settings according to your preferences and e.g. refuse to accept third-party cookies or all cookies. Please note that you may not be able to use all features of this website.

5. Data processing as part of e-news and contact services

In addition to the purely informative use of our website, we offer you various services that you can use if you are interested in them. For this purpose, as a rule, you must provide further personal data that we use to provide the individual service.

We partially involve external service providers for data processing, for example to send newsletters. We have carefully selected them and forwarded the order to them, and they must adhere to our instructions.

5.1 E-newsletter

When you sign up for the e-newsletter, we save the sign-up time and the confirmation time. The purpose of the procedure is to prove your application and, if necessary, detect possible misuse of your personal data. With your confirmation, you agree to regularly receive newsletters with information about products, advertising campaigns, interesting news and also invitations to customer surveys, until cancellation.

By subscribing to the newsletter, you consent to us analyzing your data on purchasing and user behavior (for example, redemption of coupons, purchases made). Electronic messages sent for the analysis of user behavior contain web beacons or tracking pixels, which represent single-pixel image files stored on our website. For analysis, we connect the data specified in point 4 and web beacons with your email address and individual ID. With the data obtained in this way, we create a personalized user profile in order to adapt the news to your individual interests. In doing so, we record when you read our news and which links you click on, and on the basis of this we infer what your personal interests are.

The legal basis for this is your consent according to the letter a of the first sentence of the first paragraph of Article 6 SUVP.

Your data is stored for the duration of the relationship with you as a customer. You can withdraw your consent to receive newsletters and unsubscribe from newsletters at any time. You can exercise your cancellation by clicking on the link contained in each email newsletter or by sending a message to the contact details provided in this data protection statement.

5.2 Contact form

When you contact us by e-mail or using the contact form, we store the information you provide us (your e-mail address, your first and last name, your address, your telephone number and the reason and comment for establishing contact) so that we can let’s answer your question. The legal basis for this is your consent according to the letter a of the first sentence of the first paragraph of Article 6 SUVP. This data is used only for the purpose of processing the case.

6. Online analysis

To analyze the use of our website and optimize it, we use various services that partially use cookies and other technologies. If you do not agree to the use of these services, you can object to this data processing or set your browser to prevent the storage of cookies. For individual services, it is indicated how you can submit an objection. By exercising the objection, individual providers no longer process your data for the purposes of online analysis.

6.1 Use of Google Analytics

This website uses Google Analytics, a web analysis service from Google Inc. (“Google”). Google Analytics uses so-called “cookies”, text files that are stored on your computer and enable the analysis of your use of the website. The information generated by the cookie about your use of this website is generally transferred to a Google server in the USA and stored there. However, if you activate the anonymization of the IP address on this website, Google shortens your IP address beforehand in member states of the European Union or in other countries that are parties to the Agreement on the European Economic Area. Only in exceptional cases is the entire IP address transferred to a Google server in the USA and shortened there. Upon authorization by the operator of this website, Google will use this information to analyze your use of the website, prepare reports on website activity and to perform other services for the operator of the website related to internet usage.

The IP address transmitted by your server as part of Google Analytics is not combined with other Google data.

You can prevent the storage of cookies by setting your server software accordingly; however, we warn you that in this case you may not be able to fully use all the functions of this website. In addition, you can prevent Google from recording and processing the data generated by the cookie and relating to your use of the website (including your IP address) by downloading and installing the browser plug-in available at the following link: https ://

This website uses Google Analytics with the “_anonymizeIp()” extension. In this way, abbreviated IP addresses are further processed, which excludes the identification of an individual. If, on the basis of the data obtained about you, a connection with an individual is possible, this is therefore immediately excluded, and the personal data is thereby immediately deleted.

We use Google Analytics to analyze the use of our website and to regularly improve it. With the help of the obtained statistics, we can improve our offer and design it so that it is interesting for you as a user. In exceptional cases where personal data is transferred to the USA, Google is subject to the EU-US Privacy Shield, The legal basis for the use of Google Analytics is the letter f of the first sentence of the first paragraph of Article 6 SUVP.

Third party information: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, fax: +353 (1) 436 1001. Terms for users: =sl&gl=sl data protection overview: and statement on data protection:

7. Social Media Services

7.1 Inclusion of Social Media Services

On this website, we currently use the social media services Facebook, Instagram, Pinterest, Twitter and the YouTube video portal.

When you visit our online offer and click on the logo of an individual social service, you will be redirected to the respective external page of that network service provider. If you click on one of these buttons while you are logged in to the provider, the information that you have visited our online offer can be assigned to your user account there. If you are a member of an individual service and you do not want social networks to collect data about you through the online offer and link it to your membership data, log out of Facebook, Instagram, Twitter, Pinterest or Youtube before clicking on any of these logos.

The legal basis for the processing of your data is the letter f of the first sentence of the first paragraph of Article 6 SUVP.

Please note that we, as the provider of this website, do not know the content of the provided data and how social service providers use it. More information about which data is obtained when calling up the social media services of Facebook, Twitter, Pinterest or Youtube and how it is used is contained in the individual data protection declarations at:

Social Media Provider Address Data Protection Statement

Facebook Facebook Inc.

YouTube Google Inc.

Twitter Twitter Inc.

Pinterest Pinterest Europe Ltd.

Instagram Instagram, Inc[0]=Instagram%20Help&bc[1]=Privacy%20and%20Safety%20Center

7.2 Inclusion of Google Maps

We use Google Maps on this website. In this way, we can display interactive maps directly on the website and allow you to use the map function comfortably.

When you visit the website, Google receives the information that you have called up the corresponding subpage of our website. In addition, the information specified in point 4 of this statement is provided. This happens regardless of whether there is a Google account that you are signed in with or no account. If you are signed in to Google, your data is credited directly to your account. If you do not want them to be attributed to your Google profile, you must log out before activating the button. Google stores your data as user profiles and uses them for the purposes of advertising, market research and/or the design of its website tailored to your needs. Such an analysis is carried out in particular (even for unregistered users) for needs-based advertising and informing other users of social networks about your activities on our website. You have the right to object to the creation of these user profiles, and you must contact Google to exercise this right.

The legal basis for the processing of your data is the letter f of the first sentence of the first paragraph of Article 6 SUVP.

Further information on the purpose and scope of data collection and further processing by the additional provider can be found in the data protection statements that apply to the individual provider. There you also receive additional information about your rights of this kind and setting options to protect your privacy: Google also processes your personal data in the USA and is subject to the EU-US Privacy Shield,

8. Further information

8.1 Protection of minors

Children and adolescents under the age of 18 should not provide us with personal data without the knowledge of their parents or guardians. We do not purposefully request personal data from children and adolescents and do not knowingly collect it and do not forward it to third parties.

8.2 Links to other websites

Our online offer contains links to other websites. These links are generally marked as such. We have no influence on compliance with data protection provisions on linked websites. That’s why we recommend that you also check other websites about the respective data protection declarations.

8.3 Contact Information

You can revoke your consent to the processing of your data at any time with effect for the future also through the following channels:

e-news: Click on the unsubscribe link in the newsletter

by mail to the address: Forma Brežice d.o.o., Mladinska ulica 3, 8250 Brežice

8.4 Changes to this data protection statement

The status of the data protection declaration is indicated by indicating the date (below). We reserve the right to change this data protection statement at any time with effect for the future. The current version is always available on our website. Please visit our website regularly and inquire about the applicable data protection statement.

Status of this data protection statement: May 2023

Additional explanations
If you have questions, problems or comments regarding this privacy policy, you can let us know at