Privacy Policy

IZVIR-A d.o.o., poslovne storitve
Pribinova ulica 7, 1000 Ljubljana, Slovenia
Registration No.: 6732402000 · VAT ID: SI25882694

This Privacy Policy describes how IZVIR-A d.o.o. (the "Company", "we") processes the personal data of visitors to the website finplan.si and of clients, in accordance with the EU General Data Protection Regulation (GDPR).

1. Data Controller

The data controller is IZVIR-A d.o.o., Pribinova ulica 7, 1000 Ljubljana, Slovenia. For any questions regarding the processing of personal data, please contact [email protected].

2. What Data We Collect

Depending on how you interact with us, we may process contact details provided through the contact form or by email; data required to provide the service, including information and documents about income, investments, accounts, and tax residency; payment data processed by a third-party payment platform (the Company does not store card details); and technical website-visit data where cookies are used.

3. Purposes and Legal Basis for Processing

Purpose Legal basis
Responding to an inquiry via the contact form Legitimate interest / pre-contractual measures (Art. 6(1)(f), 6(1)(b) GDPR)
Providing the agreed service Performance of a contract (Art. 6(1)(b) GDPR)
Accounting and tax record-keeping Compliance with a legal obligation (Art. 6(1)(c) GDPR)
Sending information about our services Consent (Art. 6(1)(a) GDPR)

4. Who We Share Data With

We may share data only to the extent necessary to provide our services: Stripe (Stripe Payments Europe, Limited) and/or Wise for payment processing; Cloudflare Turnstile for protection of the contact form against automated abuse; IT infrastructure providers for hosting, email, and website operation; and our accountant or Slovenian tax authorities where required by law. We do not sell or share personal data for marketing purposes.

5. Transfers Outside the EEA

Where we use service providers that process data outside the European Economic Area, we ensure appropriate safeguards are in place, such as the EU Standard Contractual Clauses, in accordance with Articles 44–49 GDPR.

6. Data Retention

We retain personal data for no longer than necessary. Slovenian accounting and tax rules require permanent retention of business books, annual financial statements, and payroll records; 10 years for VAT documents; 5 years for other bookkeeping documents; and 3 years for payment transaction documents.

7. Your Rights

Under the GDPR, you may request access, correction, erasure where permitted, restriction, objection, and data portability; withdraw consent; and lodge a complaint with the Information Commissioner of the Republic of Slovenia. To exercise these rights, email [email protected].

8. Cookies

We use strictly necessary cookies required for the website to function. Analytics and marketing cookies are only enabled with your consent. On your first visit, you can accept all categories, reject optional cookies, or select individual preferences. You can change or withdraw your consent at any time through the cookie settings link in the footer.

9. Data Security

We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure.

10. Changes to This Policy

We may update this Privacy Policy from time to time. The current version is always published on the website together with the date of the last update.

11. Contact

For questions regarding personal-data processing, write to [email protected].

For our contractual and cancellation terms, see the Terms & Conditions and Refund & Cancellation Policy.


Last updated: 12 September 2026