-
General Provisions
La-Chris
d.o.o., a company registered in Zagreb, Aleja Tišine 2, is the Data
Controller, responsible for processing personal data collected
through the website lacroa.hr ("Data Controller" or
"La-Chris d.o.o."). We handle our customers' personal data
with due diligence, processing and protecting it in accordance with
the standards established by Regulation (EU) 2016/679 of the European
Parliament and of the Council of 27 April 2016 on the protection of
natural persons regarding the processing of personal data and the
free movement of such data, repealing Directive 95/46/EC (General
Data Protection Regulation – GDPR).
The
purpose of this Privacy Policy is to provide a clear and transparent
overview of how we process personal data collected through our
website, inform data subjects about their rights, outline the legal
basis for data processing, and provide detailed information on
cookies related to lacroa.hr.
-
What personal data do we collect and for what purposes?
Personal
data refers to any information relating to an identified or
identifiable natural person, either directly or indirectly.
La-Chris
d.o.o. collects only the personal data necessary for specific
processing purposes, adhering to the principles set out in Chapter
II of the GDPR, ensuring lawful, fair, transparent, and minimally
invasive data processing.
The
Data Controller collects and processes your personal data to provide
services, fulfill purchase agreements, process payments and
transactions, and deliver purchased products.
Personal
data is processed only to the extent necessary to fulfill the lawful
purpose of processing.
La-Chris
d.o.o. may collect the following types of personal data:
-
Contact information;
-
Personal details;
-
financial
information,
such as credit card details (processed in accordance with PCI
DSS standards) used for payment processing, or in case of refunds,
the bank account number required for reimbursement.
When
you visit our website or online store, your web browser automatically
transmits certain information to our server, which may include
personal data, such as your IP address. We may also automatically
collect your data via cookies, which are detailed in our Cookie
Policy.
When
making a purchase through our online store, your personal data is
processed based on the purchase agreement and to fulfill the
contract, in accordance with Article 6(1)(b) of the GDPR. The
personal data processed includes:
Full name
Residential address and delivery address (if different)
Email address
Contact details (phone or mobile number)
If
you register and become a registered user, the following personal
data will be collected:
Full name
Residential address
Email address
In
this case, your personal data is processed based on your consent, in
accordance with Article 6(1)(a) of the GDPR.
If
you subscribe to our newsletter, La-Chris d.o.o. will process your
email address based on your consent for marketing purposes, in
accordance with Article 6(1)(a) of the GDPR. The Data Controller
will not share your personal data with third parties for marketing
purposes.
Your
data will be stored until you request its deletion or withdraw your
consent.
-
Sharing Data with Third Parties
In
certain cases, La-Chris d.o.o. may transfer your personal data to
third parties when required by law or disclose it to competent
authorities (law enforcement agencies and other government bodies) as
mandated by legal provisions or when necessary for the prevention,
detection, or prosecution of criminal offenses.
Your
personal data may be shared with courier and delivery services solely
for the purpose of delivering the ordered products based on the
purchase agreement.
In
specific cases, your personal data may be shared with data processors
with whom we have agreements regulating data processing. This may
include IT service providers and technical support providers.
Your
data will not be disclosed to unauthorized persons or any entity
without proper authorization. We process all personal data lawfully
and fairly, in compliance with GDPR principles.
-
Data Retention Period
Your
personal data will be retained only for as long as necessary to
fulfill the purpose for which it was collected, meaning:
For the duration of the contract
For as long as required by law
For as long as user consent is valid
As long as necessary within the scope of our legitimate interest
Personal
data collected through registration will be retained for the entire
period during which you remain a registered user.
Personal
data collected for purchases will be stored for as long as necessary
to manage product purchases, including any potential claims related
to the purchase (e.g., returns, complaints, or requests).
Personal
data collected through newsletter subscriptions will be stored until
you unsubscribe.
Personal
data collected based on consent will be processed until consent is
withdrawn.
In
certain cases, personal data must be stored for the period prescribed
by legal regulations, obliging the Data Controller to retain the
data.
If
you object to data processing based on legitimate interest, your
personal data will no longer be processed.
If
legal proceedings (civil, administrative, or criminal) are initiated,
personal data may be retained until the conclusion of such
proceedings, including any potential legal remedies.
All
collected personal data is protected from unauthorized access,
disclosure, use, modification, or destruction by any third party.
Once
the purpose of processing ceases, we will either delete, anonymize,
or securely dispose
of your data.
-
Your Rights Regarding Personal Data Protection
You
may exercise the rights listed below by contacting us at
info@lacroa.hr
Right of Access |
You
may contact the Data Controller to confirm whether we process your
personal data and request access to the information we hold.
|
Right to Rectification |
If
your personal data is inaccurate or incomplete, you have the right to
request correction or supplementation.
|
Right to Erasure (Right to be Forgotten) |
You
may request the deletion of your personal data if they are no longer
needed for the purpose for which they were collected or when
processing is no longer legally justified.
|
Right to Restriction of Processing |
You
may request restricted processing of your data if, for example, you
contest the accuracy of the data.
|
Right to Object |
You
may object to data processing based on legitimate interest. The Data
Controller will assess the objection and take appropriate measures.
|
Right to Data Portability |
You
have the right to receive your personal data in a structured,
commonly used, and machine-readable format, and transfer it to
another data controller.
|
Right to Withdraw Consent |
If
you have given consent for data processing, you may withdraw it at
any time without affecting the lawfulness of prior processing.
|
-
Contact Us
La-Chris
d.o.o. owns the lacroa.hr
domain and is responsible for its content and operation.
If
you have any questions, complaints, or wish to exercise your rights,
please contact us at info@lacroa.hr
If
you are dissatisfied with how we handle your personal data, you may
file a formal complaint with the competent data protection
authority:
Croatian
Personal Data Protection Agency
Selska cesta 136, 10000 Zagreb,
Croatia
https://azop.hr
Email: azop@azop.hr