Statement on the Collection and Use of Personal Data
GHIA STORE d. o. o. undertakes to protect customers’ personal data by collecting only the necessary, basic data about customers/users that are required to fulfil our obligations; informing customers about the manner in which the collected data are used; and regularly providing customers with the option to choose how their data are used, including the option to decide whether or not they want their name removed from lists used for marketing campaigns. All user data are strictly safeguarded and are available only to employees who need such data to perform their work. All employees of GHIA STORE d. o. o. and business partners are responsible for complying with the principles of privacy protection.
We respect your privacy whether you are using our services or merely seeking information about them.
You have the right to the protection of personal data: name, address, telephone number, e-mail address, and other data that may, directly or indirectly, with reasonable effort, be used to identify you.
This statement describes the process of collecting your personal data and the purposes for which they are collected, how your personal data are used, with whom they are shared, how they are protected, and what your options are with regard to personal data protection.
This statement applies to the processing of your personal data on the website ghiastore.hr, to marketing activities that may direct you to this website, to sponsored posts on social media, etc., within the scope of services managed by us or by a third party on our behalf.
Who is responsible for processing your personal data?
Ivan Kalac, Director
GHIA STORE d. o. o.
Industrijska ulica 31, Pazin
Who can you contact if you have questions or a request regarding personal data?
For any questions, requests, or complaints regarding this statement or to exercise your rights under this statement, you can contact us at the e-mail address provided in the header of this statement.
Core principles
We value the trust you place in us by sharing your personal data and we undertake to always process them in a fair, transparent, and secure manner. The key principles we follow when processing personal data are as follows:
- Lawfulness: We will collect personal data in a fair, lawful, and transparent manner.
- Data minimisation: We will limit the collection of personal data to those that are appropriate and necessary for the purpose for which they were collected.
- Purpose limitation: We will collect personal data only for specific, explicit, and legitimate purposes and will not process them in a manner incompatible with those purposes.
- Accuracy: We will ensure the accuracy and up-to-dateness of personal data.
- Security and protection of personal data: We will implement technical and organisational measures to ensure appropriate levels of data protection, taking into account, among other things, the nature of your personal data that must be protected. These measures are designed to prevent any unauthorised disclosure or access, accidental or intentional destruction, or accidental loss or alteration, as well as other unlawful forms of processing.
- Access and rectification: We will process your personal data while respecting your rights.
- Storage limitation: Your personal data will be stored in accordance with applicable personal data protection laws and only for as long as necessary to achieve the purpose for which they were collected.
- Protection in international transfers: We will ensure that, if your personal data are transferred to countries outside the European Economic Area, such transfers are carried out in accordance with the law and that your data are adequately protected during transfer.
- Protection of personal data when shared with third parties: We will ensure that any sharing of personal data with third parties and any third-party processing are carried out in accordance with applicable legislation and with appropriate contractual safeguards.
What data do we collect and on what legal basis?
You will always be clearly informed about which personal data we collect. We will present this information in a separate privacy notice included with specific services (including communication services), e-newsletters, reminders, surveys, offers, event invitations, etc.
In accordance with applicable personal data protection regulations, we may process your personal data if:
- you have given consent for specific processing purposes (as stated in the privacy notice related to a specific processing activity). You have the right to withdraw your consent at any time without giving reasons; or
- the processing of your personal data is necessary to fulfil the terms of a contract to which you are a party; or
- we pursue legitimate interests through such processing, e.g. we may process certain personal data for the purpose of preventing misuse or fraud, for establishing rights under warranty, or to verify, in certain cases, your satisfaction with products and services. We will inform you of such legitimate interests in the privacy notice related to that specific processing; or
- it is necessary to fulfil our legal obligations, e.g. if you have purchased a product or service from us, we must process data relating to your identity (name, surname, address, OIB, etc.), the purchased product (type, equipment, price, etc.), and the circumstances of the purchase (payment, place and date of delivery/pick-up, etc.).
For what purposes do we process your personal data
We process personal data only for specific, explicitly confirmed, and legitimate purposes and will not process them in a manner incompatible with those purposes.
Such purposes may include fulfilling your order, improving your visit to our website, improving products and services in general, offering services or applications, marketing communications and activities, etc. The purpose of processing your personal data is always clearly stated in a specific privacy notice related to the respective processing. A privacy notice is available, for example, on the website, on an order, on a sign-up form, in e-newsletters, etc.
Certain information (such as the categories of products you purchase) is used to assess or evaluate which content may be most interesting and useful to you. In this way, we aim to increase the chances of informing you about the most relevant product or service offers. For this purpose, individuals may be grouped into different segments (profiles) with whom we communicate differently, i.e. in a tailored (individualised) manner.
Ensuring the accuracy and up-to-dateness of your personal data
It is important to us that your data are always accurate and up to date. Please inform us of any changes or errors in our records of your personal data by contacting us via the contact e-mail address. We will take reasonable measures to ensure that any inaccurate or outdated personal data are deleted or corrected.
Access to your personal data
You have the right to access your personal data that we process, and if your personal data are inaccurate or incomplete, you may request the rectification or deletion of personal data. If you need information about your privacy rights or wish to exercise any of your rights, please contact us at the contact e-mail address.
How long we keep your personal data
We retain your personal data in accordance with applicable personal data protection regulations.
We keep your personal data only as long as necessary to achieve the purpose for which we process your personal data, for the period prescribed by law (e.g. 10 years for issued invoices), or for the period necessary to fulfil the terms of the contract, including warranty claims and possible claims (e.g. 5 years from the fulfilment of contractual obligations or the expiry of warranty obligations, unless otherwise indicated by the circumstances).
Personal data that we process on the basis of your consent are stored indefinitely, until your withdrawal, unless the purpose for which the data were collected has already been achieved earlier.
Protection of your personal data
We implement technical and organisational security measures to protect your personal data from illegal or unauthorised access or use, as well as from accidental loss or destruction. These measures are implemented taking into account our IT infrastructure, the potential impact on your privacy, and the costs of implementation, and in line with current standards and practices in the field of data protection.
We will entrust the processing of your personal data only to those authorised persons (third parties) who comply with the aforementioned technical and organisational measures for the protection of personal data.
Ensuring data protection means safeguarding the confidentiality, integrity, and availability of your personal data.
(a) Confidentiality: We will protect your personal data from unauthorised disclosure to third parties.
(b) Integrity: We will protect your personal data from alteration by unauthorised third parties.
(c) Availability: We will ensure that only authorised persons have access to your personal data when needed.
Use of cookies and similar technologies
We use cookies on our websites. In this way, we ensure a better experience while you browse our websites and we can also improve these websites. For more information about our use of cookies and how you can refuse their use, please read our Cookie Statement.
Sharing of personal data
For the purposes for which your personal data are collected, we may transfer, disclose, or allow access to the categories of recipients listed below, who process such data in accordance with the stated purpose. We require them to always comply with applicable legal regulations and data protection rules and to pay particular attention to the confidentiality of your personal data.
a) Within our organisation and within our trading brands/service brands:
- authorised officers;
- members of our network of authorised dealers and authorised service partners whom you have identified as selected or who are located near you (in relation to your postal code and address) or with whom you are in contact;
b) Business partners:
- advertising, marketing, and PR agencies that help us conduct and analyse the effectiveness of our campaigns and promotional activities (e.g. MailChimp, Google – cookie identifier only for remarketing purposes, e-mail address for displaying ads in Google Ads, cookie identifier for analytics in Google Analytics; Facebook – cookie identifier only for remarketing purposes, e-mail address for displaying ads in Facebook Custom Audiences);
- business partners: for example, trusted companies that may use your personal data to provide you with the services and/or products you have requested and/or deliver marketing material (provided that you have agreed to receive such material).
- external IT service providers, accounting services, law firms, etc.
c) Other third parties in connection with the following procedures:
- when required by law, at the request of authorities, court orders, legal proceedings, reporting obligations and informing competent authorities, etc.
- verification or control of our compliance with rules and agreements
- protection of the rights, property, or safety of the company and/or its clients
- in connection with corporate transactions: in a transfer or sale of all or part of the business, or otherwise in connection with a merger, consolidation, change of control, reorganisation, or liquidation of all or part of the company’s business
Please note that the recipients listed in items b) and c) of this document—especially service providers who may offer you products and services as part of our services or applications or through their own channels—may separately collect your personal data. In such cases, these recipients are solely responsible for the control of those personal data and your relationship with such recipients is subject to their terms.
Transfers outside the European Economic Area
Your personal data may be transferred to recipients located outside the European Economic Area (EEA) and may be processed by our company and such recipients outside the EEA. When transferring personal data to countries outside the EEA that generally do not ensure the same level of data protection as the EEA, we implement appropriate special measures to ensure an adequate level of protection of your personal data.
You will always be informed if your personal data are transferred outside the EEA by a separate privacy notice that will be included in certain services (together with communication services), e-newsletters, reminders, surveys, offers, event invitations, etc.
Your options and rights
We strive to be as transparent as possible and therefore offer you the option to choose how you want us to use your personal data.
- Your options for how we may contact you
You have various options for choosing how you want us to contact you, i.e. through which channel (for example, e-mail, post, social media, telephone, …), and for what purpose.
- Your personal data
You can always contact us via the personal data protection contact e-mail if you wish to find out which of your personal data we process and the source of those data.
- Rectification
If you find an error in your personal data, or if you believe the data are incomplete or inaccurate, you may request correction or completion.
- Restriction of processing
You have the right to request restriction of the processing of your personal data (for example, while the accuracy of your personal data is being verified).
- Your objections
You may object to the processing of your personal data for direct marketing purposes (if you wish, you can inform us through which channel and how often you want us to contact you) or to the sharing of your personal data with third parties for that purpose.
Refusing consent to the processing of personal data does not carry negative consequences or penalties and is entirely voluntary. However, please note that after withdrawing consent for the processing of personal data, we may not be able to provide you with certain individual services that cannot be provided without the use of personal data.
In addition, you may ask us to delete all your personal data (except in certain cases, e.g. for the purpose of proving a transaction or if required for compliance with legal regulations).
You have the right to lodge a complaint with a supervisory authority.
Personal Data Protection Agency (http://www.azop.hr , [email protected]).
Legal information
The provisions of these rules supplement and do not invalidate legislative provisions in the field of personal data protection. In the event of inconsistency between the provisions of these rules and the legislative provisions in the field of personal data protection, the legislative provisions shall prevail.
We may change these rules at any time. In such a case, we will notify you and invite you to read the latest version of the rules again.
Definitions
(a) Data controller means the organisation that determines the purposes and means of processing your personal data.
(b) Data processor means a person or organisation that processes personal data on behalf of the controller.
(c) EEA means the European Economic Area (includes the Member States of the European Union and Iceland, Norway, and Liechtenstein).
(d) Personal data means any data relating directly to you or by which you can be identified, such as your name, telephone number, e-mail address, vehicle identification number (VIN), geolocation, etc.
(e) Processing means the collection, access to, and all other forms of use of your personal data.