ELFRUFFY

Privacy and Cookie Policy

Website publication copy

OperatorOPBH Group s. r. o.
Websitehttps://elfruffy.com
Effective date23 July 2026
Company ID56 704 852
Contactruffyelf@gmail.com  |  +420 728 232 964

This document is drafted for publication on the Website. Mandatory consumer rights and country-specific restrictions prevail over any conflicting clause.

Privacy Policy

Effective date: 23 July 2026  |  Applies to: https://elfruffy.com

1. Data controller

OPBH Group s. r. o., Company ID 56 704 852, registered at Haanova 2601/46A, 851 04 Bratislava – Petržalka, Slovak Republic, is the controller of personal data processed through the Website and related sales channels.

Privacy contact: ruffyelf@gmail.com. Telephone: +420 728 232 964.

2. Personal data we process

Identity and contact data: name, date of birth or age-verification status, email, phone number, billing and delivery address.

Order and account data: products, quantities, order history, customer type, returns, complaints and communications.

Payment data: payment method, transaction status, transaction reference, billing information and limited payment metadata. Complete card details are normally processed by the payment provider.

Age-verification data: verification result, date, provider reference and, only where necessary, limited identity-document information. A verification provider may separately process an identity document, selfie or biometric comparison under its own privacy notice.

Delivery and customs data: recipient details, tracking information, customs declarations and proof of age or delivery.

Technical data: IP address, device, browser, operating system, security logs, cookie identifiers and Website activity.

Marketing and preference data: consent choices, newsletter status and communication preferences.

Information you provide through email, Telegram, reviews, support forms or other approved communication channels.

3. Purposes and legal bases

We process personal data only where a legal basis applies. Depending on the activity, the basis is performance of a contract, steps requested before a contract, compliance with a legal obligation, our legitimate interests or consent.

PurposeTypical dataLegal basis
Process orders, payments, delivery, returns and supportIdentity, contact, order, payment and delivery dataContract and pre-contract steps
Verify age and prevent sales to minors, fraud and abuseIdentity, verification result, technical and payment metadataLegal obligation and legitimate interests
Accounting, tax, product safety, regulatory and legal complianceOrder, invoice, payment, complaint and product dataLegal obligation
Secure and improve the Website and servicesTechnical logs, security events and usage dataLegitimate interests; consent for non-essential cookies
Send marketing communicationsContact and preference dataConsent, or another lawful basis where permitted
Establish, exercise or defend legal claimsRelevant order, communication and technical dataLegitimate interests and legal obligations

4. Age verification

We may use an age and identity verification service such as Yoti, Veriff or another provider selected at checkout. The actual provider and its privacy information will be shown before verification begins.

Where possible, we receive only a pass/fail or over-18 result and a verification reference rather than a copy of the identity document or biometric data. The provider may act as an independent controller or processor for parts of the verification process.

If verification is unsuccessful, we may request another lawful method or refuse the order.

5. Recipients and service providers

Website hosting, e-commerce, database, security and technical support providers.

Payment providers, banks, Paytriot Payments, Apple Pay, Google Pay and authorised P2P or transfer services.

GLS, DPD, shipping aggregators, fulfilment services, customs brokers and postal operators.

Age and identity verification providers.

Email, customer support, Telegram and communication service providers.

Analytics, consent-management and advertising providers where enabled and consented to.

Professional advisers, insurers, auditors and public authorities where legally required.

6. International transfers

Some providers or recipients may be located outside the European Economic Area. Where required, we rely on an adequacy decision, standard contractual clauses or another lawful transfer mechanism and apply appropriate safeguards.

The safeguards used for an international transfer depend on the recipient’s location, role and applicable law. Further information about relevant transfer safeguards is available on request.

7. Retention

We retain personal data only for as long as necessary for the relevant purpose and legal obligations.

Order, invoice and accounting records are retained for the statutory period, typically up to 10 years where required. Support and complaint data may be retained through the legal claim period. Security logs are generally kept for a shorter period unless needed for an investigation. Marketing data is retained until consent is withdrawn or the data becomes unnecessary.

Age-verification data is minimised and retained only for the period necessary to evidence compliance, prevent repeated unlawful attempts and handle disputes, subject to provider and legal requirements.

8. Your rights

Access your personal data and obtain information about its processing.

Correct inaccurate or incomplete data.

Request erasure where the legal conditions are met.

Request restriction of processing.

Receive portable data where processing is based on consent or contract and carried out automatically.

Object to processing based on legitimate interests and object at any time to direct marketing.

Withdraw consent at any time without affecting earlier lawful processing.

Request human review where a decision with legal or similarly significant effects is made solely by automated means, where applicable.

Lodge a complaint with a data protection authority.

9. Supervisory authority

The lead Slovak supervisory authority is the Office for Personal Data Protection of the Slovak Republic, Galvaniho Business Centrum II, Galvaniho 7/B, 821 04 Bratislava, Slovak Republic. Public enquiries: statny.dozor@pdp.gov.sk.

You may also contact the data protection authority in the EU or EEA country where you live, work or believe an infringement occurred.

10. Cookies and direct marketing

Necessary cookies may be used without consent where permitted. Analytics, advertising and other non-essential cookies are used only after a valid consent where required. Details are in the Cookie Policy and cookie settings.

Marketing messages include an unsubscribe mechanism. Transactional and legal notices may still be sent where needed to perform the contract or comply with law.

11. Security and minors

We use organisational and technical measures designed to protect personal data, including access controls, secure service providers, logging and payment tokenisation where available. No online system can be guaranteed completely secure.

The Website is not intended for minors. If we learn that a minor has submitted personal data or attempted to purchase a regulated product, we may delete the data, cancel the order and take steps required by law.

12. Changes

We may update this Privacy Policy when processing activities, providers or law change. Material changes will be communicated through the Website or another appropriate channel.

Cookie Policy

Effective date: 23 July 2026  |  Applies to: https://elfruffy.com

1. What cookies are

Cookies are small text files or similar technologies stored on or accessed from a device. They can make a website function, remember choices, measure performance, protect against abuse or support advertising.

2. Cookie categories

The Website may use the following categories. The live cookie settings or consent platform should identify the actual cookies and providers enabled at the time of use.

CategoryPurposeTypical durationConsent
Strictly necessaryCart, checkout, security, load balancing, age-verification flow, consent choices and account sessionSession to limited persistent periodNot required where legally necessary
PreferencesLanguage, currency, display and remembered choicesUsually days to monthsRequired where not strictly necessary
AnalyticsMeasure visits, performance, errors and how users interact with the WebsiteUsually days to monthsRequired in the EU/EEA unless an exemption applies
MarketingMeasure campaigns, personalise advertising and build audiencesUsually days to monthsRequired before activation
Third-party contentEnable embedded media, chat, maps or social functionsProvider-dependentRequired unless strictly necessary

3. Consent management

On the first visit, the Website should present a consent tool that allows users to accept or reject non-essential cookies by category. Non-essential cookies should remain disabled until a valid consent is given.

Users can change or withdraw consent at any time through the “Cookie Settings” control. Withdrawal does not affect processing that occurred lawfully before withdrawal.

The consent tool should store the user’s choice and provide a link to the current cookie list, including provider, purpose, type and duration.

4. Third-party services

Depending on the Website configuration, third parties may set cookies or similar identifiers, including payment providers, age-verification providers, analytics tools, advertising platforms, embedded social-media services, Telegram or customer-support tools.

Each third party processes information according to its own privacy terms. The actual providers must be listed in the live consent tool before their non-essential technologies are activated.

5. Browser controls

Most browsers allow users to delete or block cookies. Blocking necessary cookies may prevent the cart, checkout, age verification, login or other core Website functions from working correctly.

6. Contact

Questions about cookies or consent may be sent to ruffyelf@gmail.com.