The controller of personal data is company ARRATHI, proizvodnja kozmetičnih izdelkov, d.o.o., Žabarjeva ulica 12, 1000 Ljubljana, Registration number: 8553092000.

By opening and using the Website, various information and data is exchanged between your device and the server, including personal data under the EU General Data Protection Regulation (Regulation (EU) 2016/670 hereinafter referred to as the General Regulation). Below we present you the exchange of information and define precisely the use, interest and reasons.

The website is accessible on the HTTPS secure protocol, which provides encrypted connection and data exchange, and our servers are updated to the latest versions, which increases the level of security.


Personal data is information that identifies you as a specific or identifiable individual. The Controller collects the following personal data in accordance with the purposes set out below in the Privacy Policy:

  • Basic customer information that is collected when placing an order or enquiry (first name, last name, address, email address and telephone number).
  • Device IP address.
  • Date and time of access.
  • Website URL and referring URL (channel and campaign – how the visitor was acquired or the source through which the visitor came to the site).
  • Website retention time, number and URLs of pages visited, and total visit time.
  • The type of browser you are using, and the operating system used.

The controller does not collect or process your personal information except when you enable or consent to it or there is a legal basis for it and the controller has a legitimate interest in the processing.


In accordance with the General Regulation, the controller may also process data on the basis of a legitimate interest. The Controller strives that the rights and freedoms of the individual or the visitor of the website prevail over said interests. If you do not want the data processed or want to delete or cancel the processing, you can send us an e-mail at


For the purpose of optimizing the website, monitoring the proper functioning of the website, analysing sales, re-purchases and customer behaviour, and for business optimization purposes and measuring business performance, we use the Google Analytics tool. The tool monitors sales by sales channels, how many buyers make repurchases, and in what quantity and value, we monitor responses to advertising campaigns and general visitor statistics. We use IP address anonymization so that your IP address is never forwarded. Once your IP address becomes anonymous, your identification is no longer possible, so Google Analytics cannot in any way associate your device with other Google data.


Controller’s staff can access your order history if you provide personal data for identification or order number. Upon access, they can offer you a better service or offers and effectively resolve any complaints.


Personalized communication (via email, browser notifications or social networks) is used to present a suitable offer, communicating discounts and provision of other content that may be of interest to you based on your past interactions with our site. We use your demographics (gender, age and location), product responses and views (opening messages, clicks on links), and behavioural conduct to initiate this type of communication. sending personalized messages.

When using personalized communication, we never create user profiles, nor do we profile you or analyse your personal data, we only perform processing on a large group basis, which makes it impossible for you to be identified as an individual.


The Controller may process and collect your personal information, subject to your consent, for the purposes of verifying and enabling your online account created by registering on the Website and for sending promotional messages and other content by email in case there is no other legal basis for this and you have given us your explicit consent. The controller may also process and collect your personal data for other purposes, but only if you have been accurately informed of these purposes and given explicit consent.

If you do not want the data processed or want to delete or cancel the processing, you can send us an e-mail at


Cookies Information

A cookie is a small file that stores on your computer when you first visit a website. When you visit that website again, the data are retrieved from the cookie, and the website recognizes the cookie. The purpose of this technology and obtained information is to improve the websites and your user experience.

We utilize cookies on the Arrathi website, but only if you have consented us to. Arrathi uses session cookies and persistent cookies that remain stored on your device for a certain period of time after you leave our website. With session cookies we count the number of visitors to the website, with persistent cookies we store your contact data, so you do not have to fill out the registration form on each subsequent visit to our website. We also use persistent cookies, which originate from other websites, namely advertising cookies, and Google Analytics cookies that we use to find out how you move on our websites, which content is the most interesting to you and how long you stay on particular content.

We process data collected through cookies only for statistical purposes, but only in aggregated form so that you cannot be identified, for diagnosing problems with our server and administering our website, to inform you about our products and services as well as enhancing the user experience with the website.

Necessary cookies

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, necessary website functionality, and for serving the selected language version.

Service Name Duration Description Source
WordPress / PHP PHPSESSID End of the session Native to PHP and enables websites to store serialized state data. WordPress
Polylang pll_language End of the session A cookie used to store information about the language version of the website. Polylang
GDPR Cookie Compliance moove_gdpr_popup 1 year A cookie used to remember your privacy preference settings. WordPress
6 months
End of the session
End of the session
These cookies are downloaded when a video is viewed or shared. They estimate available bandwidth and increment hit counter. Google / YouTube

Performance cookies

These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies, we will not be able to provide you with an excellent website user experience and will not be able to monitor website performance.

Service Name Duration Description Source
Google Analytics _ga 2 years This cookie is used to distinguish unique users by assigning a randomly generated number as a client identifier. It is included in each page request in a site and used to calculate visitor, session, and campaign data for the site’s analytics reports. Google
Google Analytics _gid 1 day It appears to store and update a unique value for each page visited. Google
Google Analytics _gat 1 minute This cookie name is associated with Google Universal Analytics, according to documentation it is used to throttle the request rate-limiting the collection of data on high traffic sites. Google
Google Analytics _gat_UA-[#] End of the session This cookie limits the number of requests made through Google. Google


Targeted cookies

These cookies are used to build a profile of your interests and show you relevant content with marketing campaigns and on social media e. g. Facebook, LinkedIn. We are using cookies to monitor and statistically analyse marketing activities’ performance. Cookies do not store directly personal information but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Service  Name Duration Description Source
Facebook Conversion Pixel _fbp 3 months A cookie is used for keeping statistics about users who come from Facebook and for the purpose of segmentation and an advertising campaign on Facebook. Facebook
LinkedIn Insight Tag 3 months A cookie is used for keeping statistics about users who come from LinkedIn and for the purpose of segmentation and an advertising campaign on LinkedIn. LinkedIn
Mautic mtc_sid /mtc_id End of session These are third-party cookies used by Mautic that allow us to use the Mautic service. We use Mautic to support our marketing activities. Arrathi
Mautic mautic_device_id 1 year These are third-party cookies used by Mautic that allow us to use the Mautic service. We use Mautic to support our marketing activities. Arrathi


Managing and disabling cookies

You can manage the cookies consent on our website anytime. Disabling cookies may impair the display and functioning of the website as well as the user experience itself.

Cookies can be also disabled in browser settings at any time. Information on cookie settings in individual browsers is available in browser settings.



The controller retains your personal data for as long as is necessary to accomplish the purpose for which the personal data was collected and processed. In case a special law prescribes the retention of data for a specified period, then the controller processes that data in accordance with said law.

Data in Google Analytics is deleted after 26 months.


By using the Website, you are aware that the controller may also entrust other contractors (processors) with your personal data solely on behalf of the controller and within the limits of the controller’s authorization. The controller employs the following contractors (processors):

  • Provider of accounting and customer relationship management program and direct messaging software for communication,
  • Accounting Service,
  • Email provider (e.g., Google Mail, Mailchimp),
  • Online advertising solution provider (e.g., Facebook, Google),
  • Delivery service.

In case of transfer of personal data to third countries outside the EU, the controller shall ensure that such transfer is justified by a Commission decision on the adequacy or specific contractual provisions between the employer and the processor or user from a third country, in accordance with Article 46 of Regulation (EU) 2016/679.


In accordance with Articles 15, 16, 17, 18, 20 and 21 of the General Regulation, you have the right of access, right to rectification, right to erasure (‘right to be forgotten’), right to restriction of processing, right to data portability and right to object.

For more information on data processing and additional questions, you can contact us via the email above.

This website is owned and provided by ARRATHI d.o.o.
Last updated: 9 June 2021