Privacy & Cookies
ELFRUFFY
Privacy and Cookie Policy
Website publication copy
| Operator | OPBH Group s. r. o. |
| Website | https://elfruffy.com |
| Effective date | 23 July 2026 |
| Company ID | 56 704 852 |
| Contact | ruffyelf@gmail.com | +420 728 232 964 |
This document is drafted for publication on the Website. Mandatory consumer rights and country-specific restrictions prevail over any conflicting clause.
Privacy Policy
Effective date: 23 July 2026 | Applies to: https://elfruffy.com
1. Data controller
OPBH Group s. r. o., Company ID 56 704 852, registered at Haanova 2601/46A, 851 04 Bratislava – Petržalka, Slovak Republic, is the controller of personal data processed through the Website and related sales channels.
Privacy contact: ruffyelf@gmail.com. Telephone: +420 728 232 964.
2. Personal data we process
Identity and contact data: name, date of birth or age-verification status, email, phone number, billing and delivery address.
Order and account data: products, quantities, order history, customer type, returns, complaints and communications.
Payment data: payment method, transaction status, transaction reference, billing information and limited payment metadata. Complete card details are normally processed by the payment provider.
Age-verification data: verification result, date, provider reference and, only where necessary, limited identity-document information. A verification provider may separately process an identity document, selfie or biometric comparison under its own privacy notice.
Delivery and customs data: recipient details, tracking information, customs declarations and proof of age or delivery.
Technical data: IP address, device, browser, operating system, security logs, cookie identifiers and Website activity.
Marketing and preference data: consent choices, newsletter status and communication preferences.
Information you provide through email, Telegram, reviews, support forms or other approved communication channels.
3. Purposes and legal bases
We process personal data only where a legal basis applies. Depending on the activity, the basis is performance of a contract, steps requested before a contract, compliance with a legal obligation, our legitimate interests or consent.
| Purpose | Typical data | Legal basis |
| Process orders, payments, delivery, returns and support | Identity, contact, order, payment and delivery data | Contract and pre-contract steps |
| Verify age and prevent sales to minors, fraud and abuse | Identity, verification result, technical and payment metadata | Legal obligation and legitimate interests |
| Accounting, tax, product safety, regulatory and legal compliance | Order, invoice, payment, complaint and product data | Legal obligation |
| Secure and improve the Website and services | Technical logs, security events and usage data | Legitimate interests; consent for non-essential cookies |
| Send marketing communications | Contact and preference data | Consent, or another lawful basis where permitted |
| Establish, exercise or defend legal claims | Relevant order, communication and technical data | Legitimate interests and legal obligations |
4. Age verification
We may use an age and identity verification service such as Yoti, Veriff or another provider selected at checkout. The actual provider and its privacy information will be shown before verification begins.
Where possible, we receive only a pass/fail or over-18 result and a verification reference rather than a copy of the identity document or biometric data. The provider may act as an independent controller or processor for parts of the verification process.
If verification is unsuccessful, we may request another lawful method or refuse the order.
5. Recipients and service providers
Website hosting, e-commerce, database, security and technical support providers.
Payment providers, banks, Paytriot Payments, Apple Pay, Google Pay and authorised P2P or transfer services.
GLS, DPD, shipping aggregators, fulfilment services, customs brokers and postal operators.
Age and identity verification providers.
Email, customer support, Telegram and communication service providers.
Analytics, consent-management and advertising providers where enabled and consented to.
Professional advisers, insurers, auditors and public authorities where legally required.
6. International transfers
Some providers or recipients may be located outside the European Economic Area. Where required, we rely on an adequacy decision, standard contractual clauses or another lawful transfer mechanism and apply appropriate safeguards.
The safeguards used for an international transfer depend on the recipient’s location, role and applicable law. Further information about relevant transfer safeguards is available on request.
7. Retention
We retain personal data only for as long as necessary for the relevant purpose and legal obligations.
Order, invoice and accounting records are retained for the statutory period, typically up to 10 years where required. Support and complaint data may be retained through the legal claim period. Security logs are generally kept for a shorter period unless needed for an investigation. Marketing data is retained until consent is withdrawn or the data becomes unnecessary.
Age-verification data is minimised and retained only for the period necessary to evidence compliance, prevent repeated unlawful attempts and handle disputes, subject to provider and legal requirements.
8. Your rights
Access your personal data and obtain information about its processing.
Correct inaccurate or incomplete data.
Request erasure where the legal conditions are met.
Request restriction of processing.
Receive portable data where processing is based on consent or contract and carried out automatically.
Object to processing based on legitimate interests and object at any time to direct marketing.
Withdraw consent at any time without affecting earlier lawful processing.
Request human review where a decision with legal or similarly significant effects is made solely by automated means, where applicable.
Lodge a complaint with a data protection authority.
9. Supervisory authority
The lead Slovak supervisory authority is the Office for Personal Data Protection of the Slovak Republic, Galvaniho Business Centrum II, Galvaniho 7/B, 821 04 Bratislava, Slovak Republic. Public enquiries: statny.dozor@pdp.gov.sk.
You may also contact the data protection authority in the EU or EEA country where you live, work or believe an infringement occurred.
10. Cookies and direct marketing
Necessary cookies may be used without consent where permitted. Analytics, advertising and other non-essential cookies are used only after a valid consent where required. Details are in the Cookie Policy and cookie settings.
Marketing messages include an unsubscribe mechanism. Transactional and legal notices may still be sent where needed to perform the contract or comply with law.
11. Security and minors
We use organisational and technical measures designed to protect personal data, including access controls, secure service providers, logging and payment tokenisation where available. No online system can be guaranteed completely secure.
The Website is not intended for minors. If we learn that a minor has submitted personal data or attempted to purchase a regulated product, we may delete the data, cancel the order and take steps required by law.
12. Changes
We may update this Privacy Policy when processing activities, providers or law change. Material changes will be communicated through the Website or another appropriate channel.
Cookie Policy
Effective date: 23 July 2026 | Applies to: https://elfruffy.com
1. What cookies are
Cookies are small text files or similar technologies stored on or accessed from a device. They can make a website function, remember choices, measure performance, protect against abuse or support advertising.
2. Cookie categories
The Website may use the following categories. The live cookie settings or consent platform should identify the actual cookies and providers enabled at the time of use.
| Category | Purpose | Typical duration | Consent |
| Strictly necessary | Cart, checkout, security, load balancing, age-verification flow, consent choices and account session | Session to limited persistent period | Not required where legally necessary |
| Preferences | Language, currency, display and remembered choices | Usually days to months | Required where not strictly necessary |
| Analytics | Measure visits, performance, errors and how users interact with the Website | Usually days to months | Required in the EU/EEA unless an exemption applies |
| Marketing | Measure campaigns, personalise advertising and build audiences | Usually days to months | Required before activation |
| Third-party content | Enable embedded media, chat, maps or social functions | Provider-dependent | Required unless strictly necessary |
3. Consent management
On the first visit, the Website should present a consent tool that allows users to accept or reject non-essential cookies by category. Non-essential cookies should remain disabled until a valid consent is given.
Users can change or withdraw consent at any time through the “Cookie Settings” control. Withdrawal does not affect processing that occurred lawfully before withdrawal.
The consent tool should store the user’s choice and provide a link to the current cookie list, including provider, purpose, type and duration.
4. Third-party services
Depending on the Website configuration, third parties may set cookies or similar identifiers, including payment providers, age-verification providers, analytics tools, advertising platforms, embedded social-media services, Telegram or customer-support tools.
Each third party processes information according to its own privacy terms. The actual providers must be listed in the live consent tool before their non-essential technologies are activated.
5. Browser controls
Most browsers allow users to delete or block cookies. Blocking necessary cookies may prevent the cart, checkout, age verification, login or other core Website functions from working correctly.
6. Contact
Questions about cookies or consent may be sent to ruffyelf@gmail.com.