Terms and Conditions & Privacy Policy
TERMS AND CONDITIONS AND PRIVACY POLICY
Last updated: February 2026
Website owner: Društvo Ukrajincev v Sloveniji Razom
Jurisdiction: Republic of Slovenia
I. TERMS OF USE
1. General
This website is for informational purposes and is intended to provide information about the association's activities, publish news, events, and materials, and communicate with the public.
By using the website, you agree to these Terms and Conditions.
2. Permissible use
The user undertakes to:
use the website only in a lawful manner;
not to interfere with the operation of the website, servers, or security systems;
not to distribute malicious software, spam, or false information;
not to use the content of the website for discriminatory or illegal activities.
The content of the website may only be used for non-commercial purposes with reference to the source, unless otherwise agreed in writing.
3. Intellectual property
All texts, graphics, logos, photos, and other content are the property of the company or are used on legal grounds.
Any reproduction or distribution without the permission of the copyright holder is prohibited.
4. External links
The website may contain links to third-party resources. The organization is not responsible for their content, policies, or actions.
5. Disclaimer
The information on the website is provided "as is." The organization does not guarantee its complete relevance, accuracy, or absence of errors, in particular regarding the dates of events or changes in activities.
6. Applicable law
These Terms and Conditions are governed by the laws of the Republic of Slovenia.
II. PRIVACY POLICY
1. General principles
We process personal data lawfully, transparently, and in accordance with the principle of minimal adequacy in accordance with the GDPR and the laws of the Republic of Slovenia.
2. Data collected from all visitors
When you visit the website, the following technical data is automatically processed:
IP address and user agent;
technical information about the session.
This data is stored in the web protocol session system using a database driver. The session storage period is 120 minutes.
OpenPanel cookie-free analytics is used for statistics. It records page views and clicks on external links without using cookies and without identifying the user.
3. Contact forms
When sending a message via the contact form, the following data is processed:
name;
email address;
subject and text of the message;
time of consent to data processing.
This data is stored for up to 6 months, after which it is automatically deleted.
The IP address is used exclusively for rate limiting, is cached for 1 hour, and is not stored permanently.
4. Newsletter subscription
For newsletter subscribers, the following data may be processed:
email address;
name (optional);
language settings;
newsletter topic and frequency settings.
The data is stored until the user unsubscribes. After unsubscribing, the data is completely deleted during the next daily system cleanup.
A subscription confirmation token is used — a random string of 64 characters that is stored until the profile is deleted.
Tracking of opens and clicks in emails is optional. The user can opt out of this in the subscription settings. Aggregated logs are stored for up to 12 months and then deleted.
5. Administrative users
For site administrators (only organization staff), the following data is processed:
name;
email address;
hashed password.
Authentication is implemented using standard web protocol means.
6. Cookies and Local Storage
The site uses only technically necessary means of data storage:
session cookies for session management and CSRF protection (120 minutes);
XSRF-TOKEN cookies for CSRF protection during the session;
localStorage entry to remember that the cookie banner has been closed.
Tracking cookies are not used.
7. Third-party services
Third-party services may be used to ensure the functioning of the website, in particular:
OpenPanel — cookie-free analytics (self-hosted);
Mailgun — email delivery;
Bunny Fonts — web font loading;
GlitchTip — error monitoring without personal data transfer;
Meilisearch — internal search of website content;
DeepL — content translation in the administrative section
Our servers are located in the EU and comply with GDPR requirements.
Data transfer is limited to the minimum necessary to perform the relevant function.
8. User rights
The user has the right to:
access their personal data;
request its correction or deletion;
opt out of tracking within the mailing list;
receive their data in a transferable format.
Requests regarding the exercise of rights are processed manually by the administrator.
9. Activity logs
The website maintains a technical activity log. Records are stored for up to 365 days and may contain information about data changes (e.g., a subscriber's email change).
10. Mali Mlin d.o.o. has access to the data as your IT service provider responsible for development and maintenance.
11. Changes to the Policy
This Policy may be updated. The current version is always published on the website with the date of the update.