Protection of personal data
GDPR
PROTECTION OF PERSONAL DATA
Management of data processing
Kristal doo
Ružinovačka 2, Brezovac, 43000 Bjelovar
OIB: 32047404941
Our e-mail address for data processing and management is:
ruzica.dergez@kristal.hr
We collect only those personal data that you want to give us or those that are necessary in order to provide you (and improve) services. We collect direct personal data such as name, address, telephone number and e-mail address, as well as indirect data such as 'Cookies' (tracking), connection and system information.
Your personal data will be used exclusively for the purpose of operating Kristal doo and the website www.kristal.hr, as well as for management, support and obtaining feedback on the service provided and to prevent violations of security, laws or terms of the contract.
We will never share your personal information with business associates who intend to use it for direct marketing purposes, unless you have given us specific permission to do so.
Personal data is any data relating to a natural person whose identity has been determined or can be determined, directly or indirectly.
Data processing is any action performed on personal data, such as collection, storage, use, inspection and transfer of personal data.
These Rules do not apply to anonymous data. Anonymous data is data that cannot be linked to a specific natural person.
HOW WE COLLECT PERSONAL DATA
We collect your personal data, among other things, in the following cases:
- if you contact us directly through any website whose domain is under our lease to request information or an offer for our products or services
- if you buy a product or service directly from us
- if you fill out the data entry form on our website
- if our partners or principals provide us with your data in a permitted manner
- if we have received your personal data from other sources, for example from an intermediary for business addresses
- if you are under 18 years of age, please do not provide us with any information without the consent of your parents or guardians
COMMENTS
When visitors write a comment on the website, we collect the data displayed in the form of the comment, and also the IP address of the visitor as well as the user agent string of the browser in order to detect spam more easily.
COLLECTED DATA
We may collect the following types of data:
- Contact information - name, title, address, contact number, email address.
- Website Usage – the way you use our site, including information collected through cookies and other tracking technologies
- Photos and video recordings - in the case of presentations at fairs, conferences and other similar events, we can accompany the event by photographing or recording video material that we later publish on the website of Kristal doo and social networks
- Information about sales, services and service - information about purchases, including the customer's user identity, account or contract number and information about the fact of using our services, including complaints and requests
- Customer history information – customer satisfaction level, offers received, purchase information including item and date of purchase, delivery date, warranty information, response to campaigns, complaint history, service and service history
USE OF YOUR INFORMATION
The use of personal data in accordance with the regulations on the protection of personal data must be justified on the basis of one of the legal "basis", and in this regulation we determine the basis for any use of personal data.
The justified basis for use is Legitimate interest and Consent (consent).
Legitimate interest:
This processing is based on the legitimate interest of www.kristal.hr in promoting and providing information about its products and services, as well as for the purpose of maintaining the highest standards of sales and services from its offer.
The fundamental rights and freedoms of existing and potential customers are weighed against the interest of processing personal data for the stated purpose.
Your personal data will be used to process offers, sales, and services, as well as activities exclusively related to the operations of Kristal doo
Providing personal data for the purpose of sales and service is a contractual obligation, and if you do not provide it, it will affect the correct execution or even make it impossible.
We collect contact information, personal information and interests, information about offers, sales, vehicles you own and services and service provided] and we can use them to assess which offers you are interested in and contact you about those offers in accordance with your interests.
Consent (consent):
By accepting the Consent, it is considered that you agree to the processing of the same for the purpose of realizing the offer and contract, collecting claims, contacting and fulfilling legal obligations, as well as providing personal data to third parties solely for the purpose of fulfilling contractual obligations.
Kristal doo, as the manager of the collection of personal data, with headquarters in Brezovac, Ružinovačka 2, 43000 Bjelovar, undertakes all technical, personnel and organizational personal data protection measures that are necessary to protect personal data from accidental loss or destruction, from unauthorized access or unauthorized changes , unauthorized publication and any other misuse, and determine the obligation of persons employed in data processing.
Personal data are stored after the expiration of all legal obligations related to the storage of personal data, except in the case that the procedure for forced collection of unpaid claims has been initiated or if a complaint about a product or service has been lodged within the deadline, until the final completion of the complaint procedures in accordance with the applicable regulations .
Please note that you have the right at any time, in whole or in part, to withdraw the given consent and request the termination of the processing of your personal data, taking into account that there are reasons that prevent immediate deletion due to statutory archiving obligations. You can submit the revocation of consent in person at the branches of Kristal doo or by sending an e-mail to the address: snjezana@kristal.hr
By accepting the Consent and providing your personal data, you confirm that you have read and understood it and allow Kristal doo, as the Manager of the collection of personal data and user, to process and use your personal data for the purpose of realizing offers and contracts, collecting claims, contacting and fulfilling legal obligations as and providing personal data to third parties solely for the purpose of fulfilling contractual obligations. You hereby expressly declare that you are over 18 years of age and that you can legally consent to the processing of personal data as stated.
LEGAL OBLIGATIONS
We are subject to and required to comply with the laws of Croatia, including providing your information to law enforcement, regulatory and judicial authorities and third party litigants in connection with proceedings or investigations anywhere in the world where requested. Where permitted, we will make such a request directly to you or notify you in advance of a response, unless it could affect the prevention or detection of crime.
Providing personal data in order to comply with binding requests for your data is a legal obligation that depends on the specific request.
WE KEEP YOUR DATA SECURE
We use various security measures, including encryption and authentication, to protect and maintain the security, integrity and availability of your information.
Among other things, we use the following measures:
strictly limited personal access to your data according to the principle of "necessary access"
safe transfer of collected data,
installation of firewalls on IT systems to prevent unauthorized access
permanent monitoring of access to IT systems in order to detect and prevent misuse of personal data.
All your information is stored on our secure servers and our partners' secure servers and is accessed and used in accordance with our security policies and standards (or the equivalent standards of our subcontractors or business partners).
Privacy protection of your data is permanent, and we take all necessary measures to protect it in accordance with current regulations and good practices. We process personal data in a secure manner, including protection against unauthorized or illegal processing and against loss.
LOCATION INFORMATION
Certain services, for example parcel delivery, may be offered only if you choose to disclose your location.
We take the confidentiality of such location information very seriously and use the following safeguards for location information:
Information is collected or accessed in that form only when necessary to provide the requested service or where we are legally obligated to retain and/or provide that information (and where we are obligated to disclose that information to a law enforcement authority or other third party, in which case we will notify you, unless it could affect the prevention or detection of crime or we are not permitted to do so).
Any other use of location information for analysis purposes will be performed on irreversibly anonymized datasets
RETENTION OF YOUR DATA
We store and process personal data only for as long as is necessary for the execution of a specific legitimate purpose, unless the applicable regulations provide for a longer storage period for a particular purpose.
In the case of giving consent for marketing, we keep the data for as long as the consent is withdrawn or until it is revoked by you.
DATA PROTECTION RIGHTS AND OBJECTIONS
If you have any questions regarding the use of your data, please contact us at ruzica.dergez@kristal.hr
You have the right at any time: to ask us to provide you with additional information about how we use your data
- to send you a printout of the personal data you have given us
- ask us to correct any inaccuracies in the data we have
- ask us to delete all data in relation to which we no longer have a legal basis for use
in cases where the processing is based on consent and in relation to any direct marketing, withdraw your consent with effect in the future in order to stop such specific processing
to object to any processing [including profiling] based on a legitimate interest due to your specific situation, unless the reasons for carrying out such processing are stronger than the right to the protection of personal data - ask us to limit how we use your data, for example while a complaint is being processed