Privacy policy
We value your privacy, so we always carefully protect your data.
We process personal data in accordance with applicable personal data protection legislation and other legislation that gives us a legal basis for processing personal data.
Any changes to this document will be published on our website. By using the website, you confirm that you are familiar with the full content of the privacy policy.
Controller
The controller of personal data is the organization:
Lutkovno gledališče Maribor
Vojašniški trg 2 A
2000 Maribor
Contact:
Tina Kren Mihajlović
tajnistvo@lg-mb.si
02 22 81 970
Authorized person for personal data protection:
e-mail: dpo@datainfo.si
telephone: +386 (0) 2 620 4 300
website: www.datainfo.si
1 Personal data
Personal data means any information relating to an identified or identifiable individual; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
2 Purposes of processing and grounds for processing
The organisation collects and processes your personal data on the following legal grounds:
the processing is necessary for compliance with a legal obligation to which the controller is party;
the processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of such a data subject prior to entering into a contract;
the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party;
the data subject has consented to the processing of his or her personal data for one or more specific purposes;
the processing is necessary to protect the vital interests of the data subject or of another natural person.
2.1 Fulfillment of legal obligations
Based on the provisions of the law, the organization processes data about its employees, which is enabled by labor and social security legislation. Based on the legal obligation, the organization processes primarily the following types of personal data for employment purposes: name and surname, gender, date of birth, EMŠO, tax number, place, municipality and country of birth, citizenship, place of residence, etc. The legal basis for processing personal data of individuals is also: the Act on the Realization of the Public Interest in Culture, the Act on the Promotion of the Development of Tourism, the Act on the Protection of Documentary and Archival Materials and Archives, the Act on the Provision of Funds for Certain Urgent Programs of the Republic of Slovenia in Culture and other legislation in the field of culture. In limited cases, the organization is also permitted to process personal data on the basis of public interest. All applicable sectoral regulations in the field are collected on the website of the competent ministry: https://www.gov.si/drzavni-organi/ministrstva/ministrstvo-za-kulturo/zakonodaja/.
2.2 Performance of contract
In the event that an individual concludes a specific contract with an organization, this constitutes the legal basis for the processing of personal data. Personal data may be processed in this way for the conclusion and performance of a contract, such as the sale of tickets, subscriptions, etc. If an individual does not provide personal data, the organization cannot conclude a contract, nor can the organization provide you with a service or deliver goods or other products in accordance with the concluded contract, as it does not have the necessary data for performance. The organization may, based on the performance of a legitimate activity, inform individuals and users of its services via their email address about its services, events, training, offers and other content. The individual may at any time request the termination of such communication and processing of personal data and cancel the receipt of messages via the unsubscribe link in the received message, or as a request by email or regular mail to the organization's address.
2.3 Legitimate interest
The organization may also process personal data on the basis of a legitimate interest that it pursues. The latter is not permissible when such interests are overridden by the interests or fundamental rights and freedoms of the data subject that require the protection of personal data. In the case of the use of a legitimate interest, the organization always carries out an assessment in accordance with the General Regulation. The processing of personal data of individuals for the purposes of direct marketing is considered to be carried out in a legitimate interest. The organization may process personal data of individuals that it has collected from publicly available sources or in the course of the lawful exercise of its activities, including for the purposes of offering goods, services, employment, informing about benefits, events, etc. To achieve these purposes, the organization may use regular mail, telephone calls, e-mail and other means of telecommunication. For the purposes of direct marketing, the organization may process the following personal data of individuals: name and surname of the individual, permanent or temporary address, telephone number and e-mail address. The organization may process the aforementioned personal data for direct marketing purposes without the individual's explicit consent. The individual may at any time request the termination of such communication and processing of personal data and cancel the receipt of messages via the unsubscribe link in the received message, or as a request by email or regular mail to the organization's address.
2.4 Processing based on consent
If the organization does not have a legal basis demonstrated by law, contractual obligation or legitimate interest, it may ask the individual for consent. Thus, it may also process certain personal data of the individual for the following purposes, when the individual provides this consent:
Residence address and email address for the purposes of information and communication;
Photos, videos and other content relating to the individual (e.g. publishing images of individuals on the organization's website) for the purposes of documenting activities and informing the public about the organization's work and events;
other purposes for which the individual agrees to consent.
If an individual gives consent to the processing of personal data and at some point no longer wishes to do so, they may request the termination of the processing of personal data by sending a request by e-mail or regular mail to the organization's address. The withdrawal of consent does not affect the lawfulness of the processing based on consent before its withdrawal.
2.5 Processing is necessary to protect the vital interests of the individual
The organization may process the personal data of the individual to whom the personal data relates, to the extent that this is necessary to protect their vital interests. In urgent cases, the organization may search for the individual's personal document, check whether this person exists in its database, examine their medical history or contact their relatives, for which the organization does not need the individual's consent. The above applies in the event that this is absolutely necessary to protect the vital interests of the individual.
3 Storage and deletion of personal data
The organization will retain personal data only for as long as it is necessary to achieve the purpose for which the personal data were collected and processed. If the organization processes data on the basis of the law, it will retain it for the period prescribed by law. Some data is retained for the duration of cooperation with the organization, while some data must be retained permanently. Personal data processed by the organization on the basis of a contractual relationship with an individual is retained by the organization for the period necessary to perform the contract and for 6 years after its termination, except in cases where a dispute arises between the individual and the organization in relation to the contract. In such a case, the organization retains the data for 10 years after the finality of a court decision, arbitration or court settlement or, if there was no court dispute, for 6 years from the date of a peaceful resolution of the dispute. Personal data processed by the organisation on the basis of the individual's personal consent or legitimate interest will be stored by the organisation until the consent is withdrawn or until a request for erasure is received. After receipt of a withdrawal or a request for erasure, the data will be deleted without undue delay. The organisation may also delete this data before withdrawal, when the purpose of the personal data processing has been achieved or if so provided by law. In the event of exercising the rights of an individual, the organisation shall store the personal data of that individual until a final decision has been taken on the matter, and after such decision has been taken in accordance with the final decision in the matter.
Exceptionally, the organisation may refuse a request for erasure for reasons set out in the General Regulation, such as: exercising the right to freedom of expression and information, fulfilling a legal obligation to process, reasons of public interest in the field of public health, archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, and the exercise or defence of legal claims. After the retention period has expired, the organization must effectively and permanently delete or anonymize personal data so that it can no longer be associated with a specific individual.
4 Contractual processing of personal data and data export
The organization may entrust individual personal data to a contractual processor on the basis of a contractual processing agreement. Contractual processors may process the entrusted data exclusively on behalf of the controller, within the limits of its authorization, which is recorded in a written contract or other legal act, and in accordance with the purposes defined in this privacy policy.
The contractual processors with which the organization cooperates are primarily:
accounting services and other providers of legal and business consulting;
infrastructure maintainers (video surveillance, security services);
information systems maintainers;
e-mail service providers and software providers, cloud services (e.g. Arnes, Microsoft, Google);
social media and online advertising providers (Google, Facebook, Instagram, etc.).
The organization will not under any circumstances provide personal data of an individual to unauthorized third parties. Contractual processors may process personal data only within the framework of the organization's instructions and may not use personal data for any other purposes. The organization as a controller and its employees do not export personal data to third countries (outside the member states of the European Economic Area - EU members and Iceland, Norway and Liechtenstein) and to international organizations, except for the USA, whereby relations with contractual processors from the USA are regulated on the basis of standard contractual clauses (model contracts adopted by the European Commission) and/or binding business rules (adopted by the organization and approved by supervisory authorities in the EU).
For the purposes of better oversight and control over contractual processors and the regulation of the mutual contractual relationship, the organization maintains a list of contractual processors, which lists all specific contractual processors with which the organization cooperates.
5 Transfer of personal data
The organization, as a controller of personal data, transfers this personal data to other public sector entities or other natural or legal persons provided that an appropriate legal basis for the transfer of data is demonstrated and based on a reasoned written request, in accordance with applicable personal data protection legislation. The request for the transfer of data must contain: the data and signature of the applicant or the applicant's authorized person, the specific legal basis for obtaining the data, the purpose and reasons for the acquisition, the types of requested data, the form and method of obtaining the data and the identification of the matter for which the data is needed and the indication of the authority handling it. The organization will transfer the personal data to the applicant within 15 days of receiving a complete request or will inform the applicant within this period of time of the reasons for refusing to provide the data.
6 Cookies
The organization's website works with the help of so-called cookies, which are important for providing online services, and are used to store data on the status of an individual website, to help collect statistics on users and website visits, etc. When entering the website, only those cookies that are absolutely necessary for the website to function are loaded onto the device. Other cookies will be loaded only with the individual's consent, which the individual provides in the notification upon entering the website. The individual can change the settings and delete cookies at any time (instructions are located on the individual browser's web pages).
This website uses the following cookies:
| Name | Duration | Function |
|---|---|---|
_ga | approx. 13 months | This cookie is used by Google Analytics to collect anonymous statistical data about website usage, such as the number of visitors and how they interact with the site. |
_ga_WLQNGX1WHF | approx. 13 months | Used by Google Analytics to maintain the session state and ensure accurate measurement of website visits. |
nf_country | Session duration | An essential cookie used to operate the website and provide an appropriate user experience based on the visitor's location. |
__Secure-ROLLOUT_TOKEN | approx. 6 months | A YouTube cookie used for the gradual rollout of new features and A/B testing. |
__Secure-YEC | approx. 6 months | A YouTube cookie used to store user preferences and improve the user experience and content presentation. |
__Secure-YNID | approx. 6 months | A YouTube security cookie used to authenticate users and protect against abuse. |
VISITOR_INFO1_LIVE | approx. 6 months | A YouTube cookie used to estimate the user's bandwidth and optimize the playback of embedded videos. |
VISITOR_PRIVACY_METADATA | approx. 6 months | A YouTube cookie used to store the user's privacy and cookie consent preferences. |
YSC | Session duration | A YouTube session cookie used to ensure the proper functioning of the video player and to record interactions with embedded videos. |
7 Video surveillance
The public institution Maribor Puppet Theatre carries out video surveillance. With the help of video surveillance (cameras are installed around the entrances to the organization), we monitor entries to and exits from the premises (based on Article 77 of the ZVOP-2). We also carry out video surveillance for the purpose of protecting individuals (users, employees and visitors) and the property of the organization (based on public interest, as determined by point (e) of paragraph 1 of Article 6 of the General Regulation, in conjunction with Articles 76 and following of the ZVOP-2). Within some workplaces, video surveillance is carried out where it is absolutely necessary for the safety of people or property or to protect classified information or business secrets. Video surveillance will help us detect, handle or resolve incidents or emergencies, criminal acts, compensation or other claims. The recordings are stored for 45 days. We do not carry out video surveillance in a way that would have a special impact on the processing. Video surveillance also does not allow for unusual further processing, such as transfers to entities in third countries, the possibility of audio intervention in the event of live monitoring. Video surveillance allows for live monitoring of events by an authorized person, but the above is not implemented. All information regarding the implementation of video surveillance can be obtained by calling or The organization's email address. The rights of individuals are described in this Privacy Policy. You can also address additional questions to the authorized data protection officer.
8 Data protection and data accuracy
The organization is responsible for information security and infrastructure security (premises and application system software). Our information systems are protected, among other things, by antivirus programs and a firewall. We have implemented appropriate organizational and technical security measures designed to protect personal data against accidental or unlawful destruction, loss, modification, unauthorized disclosure or access, and against other unlawful and unauthorized forms of processing. In the case of the transmission of special types of personal data, we transmit them in encrypted form and protected by a password. The individual is responsible for transmitting their personal data securely and for
The data provided is accurate and reliable. The organization will make every effort to ensure that the personal data it processes are accurate and, where necessary, updated, and may occasionally contact the individual to confirm the accuracy of the personal data.
9 Rights of the individual regarding data processing
The individual to whom personal data relate has the right to request access to personal data and rectification or erasure of personal data or restriction of processing concerning him or her, as well as the right to object to processing and the right to data portability. The individual's request will be handled in accordance with the provisions of the General Regulation and applicable personal data protection legislation.
All of the above rights and all questions may be exercised by the individual by means of a request sent to the organization's address. The organization will decide on a request relating to the rights of the individual on the basis of the law governing general administrative procedure within one month of receiving the request. This deadline may be extended by a maximum of two additional months, taking into account the complexity and number of requests, of which the individual will be informed, together with the reasons for the delay. The exercise of rights is free of charge for the individual, but the organization may charge a reasonable fee if the request is clearly unfounded or excessive, especially if it is repeated. In such a case, the organization may also refuse the request. In the event of doubt about the identity of the individual, additional information that the organization needs to establish the identity may be requested.
If the individual's request is justified, the organization will grant the request and inform the individual of the decision. In the event that the individual's request is not granted, the organization will issue a decision in accordance with the law governing general administrative procedure. In the decision, the organization will also inform the individual about the right to complain to the supervisory authority within 15 days of the service of the decision.
An individual may exercise the right to file a complaint with the supervisory authority at: The Information Commissioner of the Republic of Slovenia at Dunajska 22, 1000 Ljubljana (e-mail address: gp.ip@ip-rs.si, website: www.ip-rs.si).
The Privacy Policy was adopted by the responsible person of the organization on 11. 6. 2026.
Ksenija Repina
Director