HomeTim Blažič

Websites

What a website needs - privacy policy, cookies, terms and company details

A practical list of legal pages and company details a small-business website in Slovenia usually needs - without lawyer language.

Author:
Tim Blažič
Published:
8 min read
8 min read
Slovensko
SL

A polished website without a company name, a privacy policy and a clear contact looks unfinished. Visitors cannot tell who stands behind the offer. If you collect email, measure traffic or sell a service, those details are not only a trust issue - they are also an obligation.

This article is not legal advice and does not replace a lawyer or accountant. It is a practical list that small businesses in Slovenia often need before a site goes live. For the content that sells - services, CTAs, proof - see what a good small-business website should include. This piece is about the pages and details visitors expect in the footer and legal links.

First: who stands behind the site

A website should make it obvious who is offering the service. That is not a logo and a slogan. It is company information a buyer can check.

In the footer (or on Contact / About) you typically include:

  • the full registered company or sole-trader name;
  • the registered address;
  • the company registration number (matična številka);
  • the tax number;
  • an email and phone that actually get answered;
  • if you are listed in the Business Register: a note that you are registered with AJPES.

If you are not registered for VAT, say so next to prices or in the terms. If you are, include your VAT ID. Prices should be clear: whether they are final, or whether VAT is added on the invoice.

This is not paperwork for its own sake. A buyer considering an order first checks whether a real business sits behind the site. A page with no name, address or contact looks like a template nobody finished.

Privacy policy

You need a privacy policy if you collect any personal data. For most small businesses that already means the contact form: name, email and message content are personal data.

A good privacy policy says, in plain language:

  • who the controller is (your business and a contact);
  • what you collect (form, analytics, any advertising cookies);
  • why you collect it (replying to enquiries, running the site, measuring ads);
  • on what basis (consent, contract, legitimate interest);
  • how long you keep it;
  • who you share it with (hosting, email, Google if you use it);
  • what rights the visitor has and where they can complain (in Slovenia, the Information Commissioner).

Copying someone else's policy and swapping the company name is a bad idea. If you do not use Google Ads, do not claim that you do. If the form sends mail through a third-party provider, say so. The policy has to match what the site actually does.

Link to the privacy policy in the footer and next to the form. Visitors should not have to hunt for it.

Cookies and consent

Cookies are not the same as a privacy policy. The policy explains data processing. The cookie notice (and consent) governs what is stored in the browser before the visitor clicks anything.

A practical split:

  • Essential settings - the site needs them to work (for example remembering the cookie choice). These usually do not need consent, but you should still mention them briefly.
  • Analytics - measuring visits. If it is not required for the site to function, load it only after consent, or use genuinely anonymised measurement and describe that clearly.
  • Advertising - Google Ads, a Facebook pixel and similar. Those scripts should load only after the visitor consents.

If you run no ads and install no marketing pixels, the setup is simpler. If you run ads and measure conversions, the banner is not decoration: measurement scripts must not load without consent.

Visitors must also be able to change consent. A clear instruction is enough: they clear this site's stored data in the browser, refresh the page, and the cookie notice appears again. A footer link that reopens the choice is even better.

Terms of service - when you need them

Terms are not required for every brochure site in the same way as company identification and privacy. They become important when you offer something under clear conditions: a package, a subscription, a fixed quote, a booking, an online store.

For a small business that takes enquiries on the site and then agrees work, terms usually explain:

  • what the service includes and what it does not;
  • how payment works;
  • timelines and what happens if content is late;
  • who owns and pays for the domain and hosting;
  • how either side can end the work;
  • that you do not guarantee uninterrupted uptime against hosting, outages or third-party services.

If you sell a managed package (setup plus monthly maintenance), the terms should separate the one-off build from the monthly service. If you do custom projects, they should say that the contract or quote is what applies.

Put terms in the footer next to privacy. Visitors rarely read them before sending an enquiry, but they need them when an agreement or a disagreement starts.

An online store needs more

A store is not the same as a brochure site with a form. The customer orders and pays before they call you. So besides privacy, cookies and terms you typically also need:

  • clear prices (and whether VAT is included);
  • payment and delivery methods;
  • delivery times and costs;
  • the consumer right of withdrawal (usually 14 days, with exceptions);
  • how to make a complaint;
  • who the seller is (the same company details as above).

Shopify and similar platforms ship templates. A template is not enough if the fields are empty or talk about US law. The text has to match your business in Slovenia.

A contact form is not just a button

A form collects personal data. So:

  • ask only for what you actually need (name, email, a short description; phone if you call back);
  • put a privacy-policy link next to the form;
  • do not hide a newsletter signup unless it is clearly marked;
  • say what happens next (for example a reply in under 24 hours).

If the form does not work, that is both a business and a trust failure. If it works but nobody knows who receives the message and why, that is a legal gap.

Where to put this on the site

The most predictable setup for a small business:

  1. Footer on every page: company name, address, registration and tax numbers, email, plus links to privacy, terms and cookies.
  2. Privacy policy and terms as real pages, not a PDF that opens in a new tab and never gets updated.
  3. A cookie notice on the first visit if you use non-essential cookies or ad measurement.
  4. Contact with the same details as the footer - they should not disagree.

Do not write the same facts in three places in three versions. One source of truth: what is in AJPES should also be on the site.

A short checklist before launch

Before the site goes live, check:

  • Does the footer show the full company name, address, registration number, tax number and contact?
  • Is there a privacy policy that describes the form and the tools you actually use?
  • Are cookies and ads loaded only after consent, if they are not essential?
  • Do you need terms (package, subscription, store, fixed quote)?
  • Are prices marked as final, or is VAT explained?
  • Does the form work, and does it link to privacy?
  • Do the details match your Google Business Profile and invoices?

If any answer is missing, fix it before you launch ads. An ad that lands on a site with no company identification starts the relationship badly.

Common questions

Do I need all of this if I only have one page?

Yes, if you collect enquiries or measure visits. Page count is not the test. A simple presentation site still needs company details and a privacy policy if it has a form.

Is a Wix, WordPress or ChatGPT template enough?

As a starting point, yes. As final copy, rarely. A template does not know whether you are a sole trader, whether you are VAT-registered, whether you use Google Ads, or who hosts your mail. You have to fill that in, or work with the developer who is actually building the site.

Do I need terms if I only collect enquiries?

A privacy policy is more urgent than terms. Terms become useful when you start agreeing work through the site or offering a package with a monthly fee. Many small businesses publish them anyway, so the rules are clear before a contract is signed.

What if an agency or developer builds the site?

Responsibility for the content of the legal pages stays with you as the client. A developer can prepare the structure, the links and the technical cookie consent. The company name, tax details and a description of what you actually collect have to be confirmed by you.

Conclusion

A small-business website is not finished when the design looks good. It is finished when a visitor can see who you are, how to reach you, what happens to their data and on what terms you work together.

This is not the most exciting part of the project. It is the part that separates a serious site from a template. If you are planning a new site, also read what a good website should include and how to write a brief. For a managed option, see websites for small businesses, or write through the contact section.

Back to the blog

Tell me your idea.

Tell me what you need - a managed small-business website or a custom project. I’ll reply in under 24 hours.

Location:
Slovenia · working remotely

By sending this you accept the processing of your data as described in the privacy policy and terms of use.