The business of water conservation involves various optimization steps accompanied by mechanization, application, and technological innovative solutions.
Rudan d.o.o.
9. rujan 1/H
52341 Žminj
Croatia
OIB: 84430586938
Tel. 052 845 500
e-mail: privatnost@rudan.com
www.rudan.com
Family Hotel Pagus, Pag
www.hotel-pagus.hr
Ville Arausana & Antonina, Vodice
www.arausana-antonina.com
Hotel Villa Radin, Vodice
www.hotelvillaradin.com
Camp Almissa, Omiš
www.campingalmissa.com
Camp and hotel Terme Jezerčica, Donja Stubica
www.terme-jezercica.hr
Family Hotel Adria, Biograd na Moru
www.hoteladria.hr
Holiday Resort Sagitta, Lokva Rogoznica
www.sagitta.hr
Hotel Nestos, Dugi Rat
www.hotelnestos.com
Hoteli Vodice d.d. (Ul. Grgura Ninskog 1, 22211 Vodice, OIB: 94858559872)
Hotel Punta
www.hotelivodice.hr
Pine Beach d.d. (9. rujan 1/H, 52341 Žminj, OIB: 39508009387)
Pine Beach Resort, Pakoštane
www.pinebeach.hr
Angelo d'Oro Heritage Hotel, Rovinj
www.angelodoro.com
Villa Arausa, Vodice
www.hotelivodice.hr
Punta Longa d.o.o.( Kruge 46/A, 10 000 Zagreb, OIB: 41070360282)
Hotel La Luna, Pag
www.laluna.hr
TERRA PARK d.o.o. (Primorska ulica 8, 53291 Novalja, OIB:80944645955)Terra Park Spiritos, Pag
www.terrapark.hr
Terra Park Phalaris, Pag
www.terrapark.hr
The Controller has appointed a Data Protection Officer (DPO), whom you may contact at any time by email at: privatnost@rudan.com or by post at the Controller's address in connection with any matters relating to the protection of personal data and the exercise of all rights guaranteed by the Regulation.
The Controller respects the privacy of every person whose personal data it collects (hereinafter: the Data Subject) and undertakes to protect your personal data. Through this Privacy Policy, we wish to inform you which personal data we collect and for what purposes, how we protect them, and what rights you have as a Data Subject.
Data processing is carried out in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter: the Regulation or the GDPR), the Act on the Implementation of the General Data Protection Regulation (Official Gazette No. 42/2018), and other regulations governing this area that apply in the Republic of Croatia.
This Privacy Policy applies to all processing of personal data carried out by the Controller. The Controller processes personal data relating to the following categories of Data Subjects:
- employees of the Controller and members of their families (children),
- prospective employees of the Controller,
- business partners and employees of the Controller's business partners,
- customers/users of the Controller's services,
- guests staying at the Controller's tourist facilities,
- pupils and students who have entered into an agreement with the Controller,
- users of digital systems,
- users of energy solutions,
- representatives of investors,
- users of user accounts,
- contact persons,
- persons submitting website enquiries.
We process personal data exclusively in accordance with the General Data Protection Regulation. Accordingly, personal data must be (Article 5 of the Regulation):
- processed lawfully, fairly and transparently in relation to the Data Subject ("lawfulness, fairness and transparency");
- collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) shall not be considered incompatible with the initial purposes ("purpose limitation");
- adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed ("data minimisation");
- accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay ("accuracy");
- kept in a form that permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as they will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1), subject to the implementation of appropriate technical and organisational measures required by the Regulation in order to safeguard the rights and freedoms of the Data Subject ("storage limitation");
- processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures ("integrity and confidentiality").
We process personal data exclusively in accordance with the General Data Protection Regulation. Accordingly, personal data must be (Article 5 of the Regulation):
- processed lawfully, fairly and transparently in relation to the Data Subject ("lawfulness, fairness and transparency");
- collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) shall not be considered incompatible with the initial purposes ("purpose limitation");
- adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed ("data minimisation");
- accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay ("accuracy");
- kept in a form that permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as they will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1), subject to the implementation of appropriate technical and organisational measures required by the Regulation in order to safeguard the rights and freedoms of the Data Subject ("storage limitation");
- processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures ("integrity and confidentiality").
In the course of its regular business operations, the Controller enables Data Subjects to exercise all of their rights relating to the processing of personal data. In addition, a Data Subject may submit a request for the exercise of rights to the Controller or send it to the email address of the Data Protection Officer.
The rights of Data Subjects include:
Considering the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks arising from data processing, the Controller implements appropriate technical and organisational data protection measures.
The Controller implements appropriate technical and organisational measures to protect personal data, including access control for information systems, user authentication, management of user permissions, data backups, antivirus and anti-malware protection, protection of network infrastructure, encryption where applicable, maintenance of access logs, regular updating of information systems, employee training, and measures for the secure storage and destruction of documentation.
In the event of a personal data breach, the Controller will assess the risk to the rights and freedoms of Data Subjects.
Where the breach is likely to result in a risk to the rights and freedoms of natural persons, the Controller will notify the Croatian Personal Data Protection Agency without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach.
Where the breach is likely to result in a high risk to the rights and freedoms of Data Subjects, the Controller will also notify the affected Data Subjects without undue delay, unless the conditions for applying an exception under Article 34 of the GDPR are met.
Data relating to Data Subjects are processed and retained in accordance with applicable legislation where a retention obligation is prescribed (for example, employees' personal data and payroll data are retained in accordance with the Ordinance on the Content and Method of Keeping Records of Workers Employed by an Employer and other applicable regulations, while accounting documents on the basis of which data are entered in the journal, general ledger and subsidiary ledgers are retained for 11 years). In situations in which the Controller is authorised to determine retention periods independently, data are retained for as long as necessary for the purposes for which the personal data are processed.
As a rule, the Controller processes personal data of Data Subjects that the Data Subjects themselves provide, for the purposes and to the extent necessary for the fulfilment of its legal and contractual obligations. Based on legitimate interest, the Controller processes personal data of Data Subjects provided that the interests or fundamental rights and freedoms of the Data Subjects do not take precedence, taking into account the reasonable expectations of Data Subjects based on their relationship with the Controller.
The Controller does not process special categories of personal data unless this is necessary for the purpose of processing and the conditions set out in Article 9 of the Regulation are met.
The Controller processes workers' data falling within special categories of personal data, such as data concerning trade union membership (for example, when exercising special rights under relevant regulations), religious or philosophical beliefs (for example, when exercising the right to additional non-working days for religious holidays where the individual has voluntarily disclosed such data for that purpose), or health data (for example, under special occupational health and safety regulations, for maintaining employee records, or where particular health certificates are required for specific jobs), and similar data.
Where necessary, the Controller also processes personal data relating to criminal convictions and offences, such as certificates of no criminal record for workers.
The Controller shares personal data with others only where this is permitted.
In fulfilling its legal obligations, the Controller is required to disclose data to third parties. Examples include submitting guest data through the eVisitor system and submitting workers' data to the competent institutions: the Croatian Pension Insurance Institute (HZMO), the Croatian Health Insurance Fund (HZZO), the Tax Administration, the Central Registry of Insured Persons and pension companies.
In certain cases, the Controller is required to disclose or make available employment-related data to the Croatian Employment Service, for example in order to include workers in active employment policy measures; to competent police stations or the ministry responsible for internal affairs, for example where senior state officials stay at the Controller's facilities and for the issuance of work permits; to the ministry responsible for tourism in the case of employing scholarship holders; to the ministry responsible for the economy and entrepreneurship where investment incentives are used; to insurance companies, banks and in other cases required by applicable regulations.
Certain workers' data are also sent to banks or pension funds in connection with salary payments, and data may be sent to creditors in accordance with enforcement regulations. Data are sometimes disclosed in order to fulfil a contractual obligation (for example, in the case of pupils undertaking practical training, data are exchanged with schools or universities).
Certain personal data are also disclosed to business entities for the purpose of providing specific services, for example occupational health examinations of workers, institutions organising legally mandatory training (occupational safety, minimum hygiene training, toxicology), audit firms carrying out mandatory audits, notaries public where certification is required, the Financial Agency for the purpose of obtaining business certificates, contracting authorities where the Controller participates in public procurement procedures, and service providers for the allocation and use of corporate cards, business mobile devices or fuel purchases.
Data may be disclosed to business entities acting as processors which process data on behalf of the Controller. These are most often the Controller's business partners that provide information technology services, store data in their databases or are able to access personal data until the processing is completed. A data processing agreement (DPA) is concluded with such entities concerning their powers and obligations when processing personal data, in accordance with the requirements of the Regulation.
In certain situations, external entities may jointly determine the purposes and means of processing personal data together with the Controller, in which case those external partners and the Controller are joint controllers. In such relationships, the joint controllers determine their respective responsibilities for compliance with the obligations under the Regulation in a transparent manner, in particular as regards the exercise of Data Subjects' rights and their duties to ensure transparency of processing, unless those responsibilities are determined by law.
A specific case of disclosure to third parties arises from the fact that the Controller has entered into management agreements with companies under which it manages the tourism segment of their operations.
To znači da u određenim slučajevima gosti Voditelja obrade mogu dobiti od Voditelja obrade i ponude koje sadržavaju informacije o drugim hotelima i objektima kojima upravlja Voditelj obrade.
This means that, in certain cases, the Controller's guests may also receive offers from the Controller containing information about other hotels and facilities managed by the Controller. Furthermore, under such management agreements, the Controller has certain rights and obligations relating to human resources. In these cases, the Controller has the right to process the personal data of Data Subjects of those companies. All principles set out in this Policy also apply to the Data Subjects of those companies in the areas in which the Controller is involved; however, those companies are also responsible as controllers of their own processing of Data Subjects' data.
Where data processing involves transfers of data to third countries, the Controller ensures compliance with high protection standards so that the highest possible standard of personal data protection is maintained, in accordance with the strict requirements of the Regulation. Accordingly, where international transfers of personal data take place, the Controller will inform the Data Subject of the intention to transfer personal data to a third country or an international organisation and of the existence or absence of an adequacy decision by the European Commission. Every transfer of personal data to third countries will be carried out in accordance with Chapter V of the Regulation.
The Controller most commonly collects personal data directly from the Data Subject. When providing personal data in any manner (accommodation booking, job application, etc.), the Data Subject is responsible for the accuracy of the data and agrees that the Controller may use and collect the data in accordance with applicable law and the terms of this Privacy Policy.
In addition, the Controller may obtain a Data Subject's personal data from other natural and legal persons, for example from travel agencies forwarding guest data for accommodation purposes, guests booking accommodation for persons with whom they will stay at the facilities, and employment agencies or temporary-work agencies. The Controller ensures that Data Subjects are transparently informed about the processing of their personal data in accordance with Articles 13. and 14 of the General Data Protection Regulation (GDPR):
Where personal data are collected directly from the Data Subject, all information prescribed by Article 13 of the GDPR is provided to the Data Subject before or at the time of collection, including information about the Controller, the Data Protection Officer (if appointed), the purposes and legal bases of processing, recipients of the data, the storage period, the rights of the Data Subject, possible transfers to third countries and the right to lodge a complaint with the competent supervisory authority.
Where personal data have not been collected directly from the Data Subject, the Controller provides the Data Subject with the information prescribed by Article 14 of the GDPR within the time limits and in the manner prescribed by the Regulation, unless one of the exemptions provided for in Article 14(5) of the GDPR applies.
The Controller ensures that all information concerning the processing of personal data is available to Data Subjects in a concise, transparent, intelligible and easily accessible form, using clear and plain language.
Through its websites, the Controller provides users with access to information about its business operations, tourist facilities, energy solutions, digital services and other products and services, as well as the possibility of establishing contact through electronic forms, email and other communication channels.
When using the websites, the Controller may process users' personal data where such data are voluntarily provided by the users, for example through:
Depending on the purpose of the processing, the Controller may process the following categories of personal data:
Personal data are processed exclusively for the following purposes:
The legal bases for the processing of personal data are:
The Controller processes only those personal data that are necessary to achieve the relevant purpose of the processing and implements appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, loss or other unlawful processing.
Data provided through the websites are retained only for as long as necessary to achieve the purpose for which they were collected, or for the periods prescribed by applicable legislation or the Controller's internal rules.
The Controller uses official social media profiles to inform the public about its business operations, present its products and services, promote tourist facilities and energy and digital solutions, communicate with users and improve the quality of its services.
Visiting the Controller's official profiles on social media platforms (for example Facebook, LinkedIn, Instagram, YouTube or other social media platforms used by the Controller) may result in the processing of users' personal data by the provider of the relevant social media platform, regardless of whether the user has an account on that social media platform.
The Controller may process personal data that users voluntarily publish or provide through its official profiles, such as:
Personal data are processed for the purposes of:
The legal basis for the processing of personal data is the Controller's legitimate interest in communicating effectively with users, promoting its business operations and improving the quality of its services, pursuant to Article 6(1)(f) of the GDPR, or the Data Subject's consent where required under applicable regulations.
The Controller has no control over the manner in which social media providers process users' personal data after users visit their platforms. The processing of personal data carried out by social media providers is governed by their respective privacy policies and terms of use. Users are therefore advised to familiarise themselves with those policies and terms before using a particular social media platform.
Where the Controller uses statistical or analytical tools provided by social media platforms (for example Facebook Page Insights or similar services), the processing of data is carried out in accordance with the rules of the relevant social media provider. Where applicable, the Controller and the social media provider may act as joint controllers with respect to the preparation of aggregated statistical reports concerning the use of official profiles, pursuant to Article 26 of the GDPR.
The Controller collects and processes the personal data of Data Subjects who are guests at the Controller's tourist facilities for various purposes, with the ultimate aim of providing high-quality accommodation and related services in accordance with the highest standards applicable to tourism companies.
The Controller stores in its database the personal data that you are required to provide in order to receive accommodation services, for the purposes of performing the accommodation contract and complying with legal obligations relating to hospitality activities. If you do not provide the Controller with the minimum data required to book accommodation and, during your stay, to register you in all competent registers, the Controller will not be able to provide the accommodation booking service or accommodation service in accordance with the contract and the law.
Certain data are necessary in order to take steps at the request of the Data Subject before entering into an accommodation contract. For example, before accommodation is booked, accommodation offers are sent in response to enquiries from prospective guests, for which the Controller requires personal data (first and last name and email address) in order to send the offer.
The personal data collected by the Controller when accommodation is booked (bookings made online, by telephone, or by accepting an offer by email) for the purpose of fulfilling the reservation are:
- first and last name of the booking holder,
- country,
- name of the facility,
- date of birth,
- number and type of identification document and place of issue,
- nationality,
- accommodation unit number and type of accommodation unit (room type),
- date of arrival and departure,
- number of persons for whom accommodation is being booked and room allocation,
- which persons are minors.
Other possible details, depending on the request of the person booking the accommodation:
- email address,
- language of communication,
- telephone number,
- payment method,
- any additional data necessary to execute transactions or secure payment.
If a booking is cancelled, we must retain your data for the purpose of proving the booking and its cancellation. Upon arrival at a facility, guests are generally registered at the facility reception and their data are entered into the guest database, from which the data are sent to the eVisitor system (the central online information system for guest check-in and check-out) in order to comply with the Controller's legal obligations.
The following data are collected:
- first and last name,
- place, country and date of birth,
- nationality,
- number and type of identification document,
- permanent or temporary residence and address,
- date and time of arrival at and departure from the facility,
- sex,
- the basis for exemption from payment of the tourist tax or for a reduction in the tourist tax.
The above data are processed by tourist boards and public authorities of the Republic of Croatia for the following lawful purposes:
- monitoring compliance by persons subject to the guest registration and deregistration obligation (accommodation service providers),
- recording, calculating and collecting the tourist tax,
- maintaining guest books or guest lists by accommodation service providers and monitoring compliance with that obligation by inspection authorities,
- registering foreign nationals with the ministry responsible for internal affairs and monitoring compliance with that obligation by inspection authorities,
- maintaining tourist lists by tourist boards and performing statistical processing and reporting,
- supervising the operations of accommodation service providers in relation to the lawfulness of their activities or the provision of registered services and compliance with tax and other public-charge regulations.
Since the regulations require guest registration data to be entered on the basis of data contained in an identity card, passport or other identity document, the guest is required to present such a document to the Controller and provide all other information necessary for the entry of data that is not contained in the document.
The Controller may use a scanner to enter data from an identity card or other appropriate document. In that case, no image of the document is stored; only the necessary data are extracted from the document and stored in accordance with the purpose of processing.
Other data relating to the circumstances of a guest's stay, such as the mode of travel, persons travelling with the guest, marital status, number of children, pets and other interests, may also be collected and processed during the stay where they are directly related to the provision of accommodation services.
Before, during and after the stay, based on legitimate interest, the Controller may send you, as a guest, service messages by email, such as booking confirmations, stay reminders and other notices closely connected with the specific stay you have booked.
During and after the stay, based on legitimate interest, the Controller may also send you, as a guest, satisfaction surveys by email, SMS and/or instant messaging services (Viber, WhatsApp and similar services), which it will process itself or through a business partner. The primary purpose of satisfaction surveys is to collect information about the service for the Controller's legitimate interest in improving the service, and the Controller may de-identify the survey data and process them for statistical purposes.
Based on legitimate interest, the Controller may collect certain data and use them for direct marketing purposes.
In addition to managing tourist facilities, the Controller carries out activities relating to energy management, the development and implementation of digital solutions, ESCO projects, design and maintenance of technical systems, systems for monitoring and optimising energy and water consumption, IoT systems, and other services related to energy efficiency and infrastructure management.
Within these activities, the Controller processes the personal data of representatives of business users, investors, clients, suppliers, contractors, users of digital applications, persons authorised to access systems, contact persons and other persons involved in project implementation or the use of services.
Personal data are processed for the following purposes:
The following categories of personal data may be processed within the above activities:
Within its digital solutions, the Controller may process technical data relating to the operation of information systems, devices, metering points and communications infrastructure.
Such data are processed primarily to ensure the proper operation of systems, monitoring, diagnostics, maintenance, optimisation and information security. Data are processed only to the extent necessary to achieve those purposes and, wherever possible, in a manner that does not permit the identification of individuals.
The legal bases for processing personal data within the above activities are:
The Controller applies appropriate technical and organisational safeguards to ensure the confidentiality, integrity, availability and resilience of information systems and to protect personal data against unauthorised access, alteration, loss or destruction.
The Controller is the employer of many individuals and processes employment-related personal data. In this context, Data Subjects include current and former workers, prospective workers, persons undertaking practical training (pupils), persons undergoing professional training, students working under student employment agreements, scholarship holders and other persons whose data are processed in the context of employment-law and related relationships.
As a prospective employer, the Controller collects, processes and retains the data of candidates for employment with the Controller in a candidate database based on their voluntary application, in the following ways:
- a candidate application submitted through the online application form,
- an application submitted by email,
- attendance at organised auditions and completion of application forms,
- in another manner.
The data generally collected are: first name, last name, date of birth, address, nationality, OIB, mobile telephone number, email address (for contact purposes), sex, educational qualifications, language and preferred means of communication.
The Controller may obtain candidate data indirectly from domestic and foreign employment agencies, in which case those agencies are required to inform candidates about the processing of their personal data by the Controller.
Candidates submit their job applications:
- as unsolicited applications, in which case we process the data for the purpose of contacting candidates regarding employment for five years,
- as applications for specific vacancies with a stated closing date, in which case we process the data until completion of the recruitment procedure.
Where candidates applying for a specific vacancy with a stated closing date give separate consent, we process their data for the purpose of contacting them regarding employment for five years in connection with possible future vacancies.
As an employer, the Controller processes all worker data in a worker database maintained in an information technology system and in physical personnel files. Data are collected in accordance with the Labour Act, the Ordinance on the Content and Method of Keeping Records of Workers, the Ordinance on the Content of Payroll, Salary Compensation, Severance Pay and Compensation for Unused Annual Leave, and other legislation governing employment relationships.
The following personal data of workers are collected and processed:
- first and last name
- personal identification number (OIB)
- sex
- date of birth
- place of birth
- country of birth
- nationality
- permanent/temporary residence address
- telephone/mobile number
- email address
- educational qualifications
- occupation
- data on completed education and professional training (copies of diplomas and
certificates)
- pensionable service data (electronic employment record)
- place/municipality of work
- contracted working hours
- job position
- date of employment
- insured-person number with the Croatian Pension Insurance Institute (HZMO) and the Croatian Health Insurance Fund (HZZO)
- IBAN of the account used for salary payments
- IBAN of a protected account (if held by the worker)
- status under the mandatory second pension pillar (Pillar II)
- personal allowance data from the PK tax card
- data concerning children and dependent family members
- birth certificate where a child is under 15 years of age
- data concerning deductions from salary
- access-card number
- data concerning medical examinations of workers employed in jobs subject to special
working conditions
- trade union membership
- work permit data (where the worker is a foreign national)
- assessments, performance evaluations and warnings
- date of termination of employment
- reason for termination of employment
- application and curriculum vitae
- results of medical and psychological assessments carried out during the selection of a candidate for
a job position (where conducted).
The data generally required for entering into student or pupil work agreements are:
- confirmation from the university for the current year as proof of student status or a copy of the student record showing enrolment in the current year,
- data from the identity card (identity card presented for inspection),
- confirmation/card issued by the Student Centre,
- OIB,
- account IBAN (for the payment of tips, if received by the worker).
The data generally required for entering into a practical-training agreement are:
- agreement with the school attended by the pupil,
- referral by which the pupil is assigned to practical training,
- data from the identity card (identity card presented for inspection),
- OIB
- account IBAN (for the payment of tips, if received by the pupil).
In addition to these data, the Controller may retain in the worker's file other data collected during the recruitment procedure, as well as other data collected during the employment relationship and prescribed by internal rules (awards, warnings, certificates and similar records).
All worker data are stored in the worker database from the date on which the employment relationship is established, are kept up to date until the employment relationship terminates, and are thereafter retained as records of permanent archival value in accordance with relevant regulations.
The Controller also retains in its database data relating to other persons in a business relationship comparable to employment or persons undertaking practical or professional training. Such data are recorded from the commencement of work, kept up to date until work ceases and retained in accordance with relevant regulations. A special case concerns the data of pupils undertaking practical training who may be minors; particular care is taken in relation to them, and their data are collected and retained in accordance with special regulations and with the approval of the school and their parents.
In the course of its business operations, the Controller also processes personal data relating to employees of business partners or prospective business partners, and to natural persons with whom the Controller has or may have a business relationship.
The categories of personal data of Data Subjects that are collected are:
- first and last name,
- email address,
- telephone/mobile number,
- data concerning the position held within the legal person represented by the Data Subject,
- occupation where the Data Subject is a natural person entering into a contractual relationship (for example singer, painter, photographer, lawyer, doctor, etc.),
- references and brief curricula vitae where necessary,
- data stated on blank promissory-note forms, promissory notes and bills of exchange,
- bank account number (IBAN) where the business partner is a natural person entering into a contractual relationship,
- other data depending on the nature of the business relationship.
The Data Subjects' personal data are collected in the following ways:
- offers or enquiries received from Data Subjects regarding business cooperation,
- zdata received from Data Subjects in connection with the sale of the Controller's products/services or the purchase of products/services from a business partner (for example at trade fairs, congresses and similar events),
- business correspondence relating to a particular previous or current business cooperation (for example correspondence carried out in the course of performing a contract),
- publicly available data (for example court registers, business partners' websites, magazines, newsletters and similar sources).
In addition to the above types of data and sources of collection, personal data may also be processed for other specific purposes, but always within the framework prescribed by law or where the processing is necessary for the exercise of rights and obligations arising from the business relationship.
Data relating to Data Subjects who, as natural persons, are in a business relationship with the Controller are retained in accordance with applicable legislation (for example, the Controller is required to retain all invoices and the supporting documentation used for issuing invoices for 11 years in accordance with applicable law).
Where the Controller is authorised to determine data retention periods independently, those periods are determined with due regard to the purpose of processing and the interests of Data Subjects.
Where the Controller is authorised to determine data retention periods independently, those periods are determined with due regard to the purpose of processing and the interests of Data Subjects.
Where the website automatically records technical data necessary for its secure operation, data such as the IP address, web-browser information, operating system, access time and other technical data necessary to ensure information-system security, detect and prevent misuse and maintain access logs may also be processed.
Personal data are processed for the purposes of:
• responding to Data Subjects' enquiries,
• providing the requested information, quotations or documentation,
• establishing business communications,
• taking steps at the Data Subject's request prior to entering into a contract,
• protecting the information system and preventing misuse.
The legal bases for processing are:
• Article 6(1)(b) of the GDPR, where processing is necessary in order to take steps at the Data Subject's request prior to entering into a contract or for the performance of a contract,
• Article 6(1)(f) of the GDPR, where processing is necessary for the Controller's legitimate interest in conducting business communications, protecting the information system and establishing, exercising or defending legal claims.
Personal data are retained for as long as necessary to process the enquiry received, establish or perform a business relationship, and establish, exercise or defend legal claims, unless a longer retention period is prescribed by a specific regulation.
Where a Data Subject requests a quotation for the Controller's products or services through the website, personal data are processed for the preparation and delivery of the quotation, the establishment of business communications and, where appropriate, entering into and performing a contract.
Personal data will not be used to send promotional or marketing messages unless the Data Subject has given separate consent where such consent is required.
The Controller publishes information for promotional purposes through its websites, social media profiles and similar communication channels. Such publications may contain a limited set of personal data, such as first and last names, positions, professional information, videos, statements and photographs.
The legal basis for processing is the Controller's legitimate interest, while due consideration is always given to the interests of the Data Subject; personal data will therefore not be published where it is established that the Data Subject's interest overrides the Controller's interest. In certain situations, publication may be based on consent in accordance with the Regulation.
Publications are of a lasting nature in order to provide information about current events and an overview of previous activities. From a technical perspective, social media publications may be managed by our contractual partners (for example marketing agencies), which act solely on our instructions and in the capacity of processors.
Processing will cease where, following an objection by the Data Subject, it is established that the objection is justified, or where the Data Subject withdraws consent in situations in which consent is applicable, to the extent that cessation can be implemented.
The Controller has a legitimate interest in processing personal data for direct marketing purposes, primarily for sending marketing messages (newsletters) by email, SMS and/or instant messaging services (Viber, WhatsApp and similar services). Based on legitimate interest, the Controller may send different newsletters depending on the relationship that Data Subjects have with the Controller.
The personal data collected primarily include first and last name, email address, telephone/mobile number, address, sex and country/language of communication, as well as basic data relating to the relevant relationship with us.
On some of its websites, the Controller enables users to subscribe to newsletters by email. In order to ensure that no error or misuse has occurred when an email address is entered, we use a double opt-in process (double verification): after the email address is entered in the subscription field, the Controller sends a confirmation link to that email address.
Your email address is added to the database for sending the relevant newsletter only after you click the confirmation link. Such newsletters are sent on the basis of the consent you give us by completing and confirming the form on the website. The content and purpose of the newsletter will be stated when you subscribe.
The Data Subject may unsubscribe from the list at any time, and the Controller will immediately stop sending newsletters.
The Controller has a legitimate interest in implementing video-surveillance measures for the protection of property and persons and, in certain cases (for example, exchange offices located at facility receptions), also has a legal obligation to install surveillance cameras recording all persons moving within the camera's field of view (guests, employees, business partners and others).
The processing of employees' personal data through the video-surveillance system is also carried out subject to the conditions laid down in occupational health and safety legislation and in accordance with the Controller's Video Surveillance Policy.
The Controller marks all locations at which video surveillance is installed in the manner prescribed by law. The Controller is aware that video recordings contain the personal data of all persons moving within the camera's field of view and therefore safeguards them with particular care. It maintains an appropriate security and access system and a deletion policy governed by the Controller's internal security rules.
Video-surveillance recordings are retained for no more than 30 days from the date of recording. Where recordings need to be extracted or copied, they are retained for no more than six months, unless a longer retention period is prescribed by another law or the recordings constitute evidence in judicial, administrative, arbitration or other equivalent proceedings.
Where judicial and/or criminal proceedings are conducted, the Controller may use the recordings. Personal data contained in the recordings may also be accessed by third parties acting as processors, namely the Controller's contractual partners that are registered and qualified to provide services for the protection of persons and property and that do not use such data independently in any way, but ensure the security of central surveillance and alarm systems. All other matters relating to video surveillance are governed by the specific regulations applicable to that area.
The Controller does not currently use artificial intelligence systems to process Data Subjects' personal data. All decisions relating to the processing of personal data are made by authorised persons in accordance with applicable personal data protection legislation. The Controller does not carry out automated individual decision-making or profiling within the meaning of Article 22 of the GDPR using artificial intelligence systems.
The Controller may use artificial intelligence tools solely to assist employees in performing business processes. Artificial intelligence is not used to process personal data, does not make automated decisions producing legal effects for Data Subjects and does not replace human decision-making.
If artificial intelligence systems involving the processing of personal data are used in the future, the Controller will assess their compliance with the GDPR before implementation, carry out a data protection impact assessment (DPIA) where necessary, and update this Privacy Policy.
Cookies are small files that a website visited by a user stores on the user's computer for its own purposes. Those purposes may vary; for example, information may be stored about the language selected by the user, the list of items in a shopping cart in an online store, the user's IP address, username and password, email address, geolocation and similar data.
Cookies are classified according to their duration, their source and their function. According to duration, cookies may be:
- Persistent cookies - cookies that remain on the computer after the web browser is closed. They enable websites to store information such as login name and password, language settings or cookie preferences so that the user does not have to enter them again on each subsequent visit. Persistent cookies may remain on the computer for days, months or even years,
- Temporary cookies or session cookies - cookies that are removed from the computer when the web browser is closed. They enable websites to store temporary information, such as the last few pages opened by the user on the website being visited or items in a shopping cart where an online store is involved.
According to their source, cookies may be:
- First-party cookies - cookies stored by the website that the user is primarily visiting,
- Third-party cookies - cookies stored by other websites or online services that form part of the primary website visited by the user. They are usually used to track user habits on the primary website or may be used by online services to ensure the proper provision of those services.
According to their function, there are several types of cookies:
- Technical/necessary cookies - cookies that are essential for the functioning of the website and its core functionalities, such as the session identifier for the user's current visit or the contents of a shopping cart filled by the user when purchasing products through an online store,
- Functional cookies - cookies that enable the website to provide enhanced functionality and personalisation, such as remembering the language in which website content is displayed,
- Statistical cookies - cookies that collect information about how users visit the website. In principle, data are collected in aggregated form without identifying the individual user,
- Marketing cookies - cookies that collect information about users' habits and behaviour on the website for the purpose of displaying personalised advertisements.
For all other activities not covered by the reasons mentioned above, the Service Provider will request additional consent. The Service Recipient, at any time, has the right to withdraw the given consent.
We regularly update the Privacy Policy so that it remains accurate and up to date and reserve the right to amend its content where we consider this necessary. You will be informed of all amendments in a timely manner through our website, in accordance with the principle of transparency.
Žminj, July 1st 2026.
For any questions regarding the use of personal data, you can contact us by phone, email, or by using the form on our website.