Diversus res d.o.o. Privacy Policy

Introduction
We are extremely committed to protecting your personal data. We will use your personal data in accordance with the purpose for which you entrusted them to us. Diversus res d.o.o. collects, processes and uses personal data only with your permission and in accordance with legal regulations.
Please read our Privacy Policy carefully to understand our actions concerning your personal data, as well as your rights arising from the application of the General Data Protection Regulation.
By using the Heraldi website, owned by Diversus res d.o.o.,

www.heraldi.hr

you also accept our Privacy Policy and our cookie policy.

Personal data
According to the Regulation, personal data imply one piece or a set of data that unambiguously indicate a specific individual and establish or allow the establishment of their identity.
An individual whose identity can be established by personal data directly or indirectly is called a “subject”.

Data collection
Diversus res d.o.o. collects only personal data that you have entered of your own free will through available web forms at the invitation to receive notifications (newsletters) or through contact with the employees of Diversus res d.o.o. or its proxies. A written expression of your will is necessary for establishing contact.
Some personal data about you or your business may be collected from forms and surveys you fill out on our website and the details of your visit to our website, including data that may result in your identification, such as an Internet Protocol (IP) address.
We collect some data automatically – using cookies, of which you can read more in the Cookies section.
Diversus res d.o.o. does not sell or share your data, but it is possible that information about you could accidentally be contained in the data obtained by Diversus res d.o.o. from third parties within the scope of communication with clients.
After withdrawing the consent to receive advertising materials, participation in the programme is still possible. To withdraw, please contact us at gdpr@heraldi.hr.

Data processing
According to the General Data Protection Regulation (GDPR), processing is defined as any procedure or set of procedures performed on personal data or on sets of personal data, either by automated or non-automated means, such as collecting, recording, organising, structuring, storing, adapting or modifying, finding, inspecting, using, disclosing by transfer, disseminating or otherwise making available, harmonising or combining, restricting, deleting or destroying.

Purpose and access
Diversus res d.o.o. collects your personal data from you in order to contact you, exchange information, and send you notices and marketing messages which Diversus res d.o.o. believes could be important, interesting and useful to you, or which you should receive pursuant to the contract and the law.
If you give us the appropriate consent when visiting our website, you allow Diversus res d.o.o. to maintain promotional communication with you. Such communication may take place until you exercise your right to terminate the communication at any time with a request or if Diversus res d.o.o. decides to stop the practice of such communication.
In certain situations, Diversus res d.o.o. acts on behalf of its clients as the personal data processor, in which it acts exclusively according to the client’s orders and ensures that all actions are in full compliance with the General Data Protection Regulation.
Diversus res d.o.o. may, from time to time, use that data to identify its visitors on the website, as well as to use such data for the purpose of better understanding the conduct of visitors on the website.

Cookies
The website of Diversus res d.o.o. use cookies. These are small pieces of code that your browser automatically executes, and are necessary for adequate display of the website contents on all devices. Without them, the use of the website would not be possible. The information collected in this way does not contain personal data and serves to improve the functioning of the website and your user experience.
You can delete the cookies through your browser settings, and for more information on how to delete them, contact the browser developer.

COOKIES SET ON THIS WEBSITE

First-party functional cookies
ASP.NET_SessionId cookie stores the session status of a visitor on the website requests. For example, it memorises your shopping cart status for the duration of your website visit. This cookie is created by our website and is the only one using it. The cookie is removed when you close your internet browser. If the user declines the cookie, the shopping cart feature may be non-functional.

Third-party analytics cookies
Analytics cookies collect data on how visitors use the website so that third parties could make an analysis with the aim of increasing the functionality and creating contents that will best meet the users’ needs for information. We use Google Analytics services.
_gat i _gid cookies are removed after closing the internet browser, while the _ga cookie remains stored on the device and is not deleted, i.e. does not expire automatically.
If you want to prevent the specified service from storing the cookie, you can do so according to the instructions on the following website:
https://tools.google.com/dlpage/gaoptout 

Third-party advertising cookies
We use third-party services to display ads based on the interests of users who have previously visited the website www.heraldi.hr and which are determined based on their internet searches. These cookies collect demographic data and/or data on the websites users have visited, the products they have viewed, and the conversions they have made as a result of advertising campaigns. For example, these cookies are used to:

  • Determine the number of users who viewed the service after clicking on the ad
  • Show ads tailored to the user’s demographic profile or based on their specific interests, including ads on other websites
  • Show ads on other websites that are related to services that the user viewed on this website
  • Avoid repeated ads that the users have already seen

We use the following advertising cookies:
Service provides: Google Adwords

  • Cookies: _gads i _gac
  • Duration: removed after closing the internet browser

You can find the privacy policy on the following link: 

https://www.google.com/intl/hr/policies/privacy/

You can find the consent form on the following link: 

https://adssettings.google.com/anonymous?hl=hr

Service provider: Facebook (Facebook Pixel)

  • Cookies: fr, impression.php/#, tr
  • Duration: fr remains stored on the user’s device for up to 3 months, impression.php/# and tr cookies are removed after closing the internet browser.

You can find the privacy policy on the following link:
https://www.facebook.com/privacy/explanation

You can find the consent form on the following link:
https://www.facebook.com/ads/preferences/

Legal basis for the personal data processing
The legal basis for collecting personal data may consist of:

  • Consent given by the visitors of the Heraldi website of Diversus res d.o.o., allowing the collection for a clearly stated purpose,
  • Contractual obligations to clients
  • Legitimate interest of Diversus res d.o.o.
  • Need to respond to marketing inquiries
  • Legal obligation.

The legal basis complies with the provisions of the General Data Protection Regulation (GDPR)

Legitimate interest of Diversus res do.o.
Promoting all services and products offered by Diversus res d.o.o. on its website is generally done for the purpose of business improvement and increase of the quality level of services and products, as well as for increased customer satisfaction.

Consent
By taking a conscious action necessary to give a positive answer to the question of Diversus res d.o.o. regarding the permission to collect your personal data when visiting the website of Diversus res d.o.o., you have given your consent to the processing of your personal data for the aforementioned purpose.
Diversus res d.o.o. will carry out the processing according to the consent, taking into account the provisions of the General Data Protection Regulation.
You can withdraw your consent at any time by sending an e-mail with the appropriate content to the address gdpr@heraldi.hr  or by sending a letter to the address indicated at the end of the document.

Data forwarding statement
In certain cases, Diversus res d.o.o. may forward your personal data to third parties, but only for the purpose of activities related to its own activities and in terms of the consent obtained from you. In such cases, Diversus res d.o.o. requires that the third party agrees to process the obtained data only based on our instructions and the needs that are in accordance with your consent, this Privacy Policy, and the General Data Protection Regulation (GDPR).
We will not forward or sell the information obtained from you without your permission, but it is extremely possible that we may disclose your personal data only to comply with the relevant legal provisions or legally applicable requirements of the competent state authorities.

Retention policy
Diversus res d.o.o. will process personal data during the term of each contract and the official business relationship, and it will continue to keep the personal data only for the duration of the statute of limitations in accordance with the applicable legal regulations in the Republic of Croatia.
After the expiration of the statute of limitations, the data from the contract and the relationships that have been terminated will be deleted.
Diversus res d.o.o. will delete the personal data of the person who withdrew their consent, unless a valid legal reason for retaining the data has arisen in the meantime.
Diversus res d.o.o. will delete all your personal data that is not necessary for the realisation of a legitimate interest and when that interest ceases without delay.

Data storage
Diversus res d.o.o. stores data in accordance with all necessary criteria provided by legal regulations and the General Data Protection Regulation, and does not store data outside the EU.

Links to other websites
This privacy policy applies to the website of Diversus res d.o.o. www.heraldi.hr and all sub-domains and pages that are available at the time of your visit.
The website of Diversus res d.o.o. contains links to the websites of other entities not covered by this Privacy Policy.
When you leave the website of Diversus res d.o.o., we recommend that you read the privacy statements on each website that collects personal data because we shall not be responsible for them.

Notice on changes
Any changes regarding our Privacy Policy will be published on our website and elsewhere as necessary.

Your rights as a subject
We provide the conditions so that you would decide on the processing of your personal data. In addition to the aforementioned right to withdraw consent, we provide you with the following rights:

  • Right of Access. You have the right to receive confirmation on whether or not your personal data are being processed. If the data are being processed, we must provide you with access to those data.

You may request the following information based on the Right of Access:

  • The identity and contact details of the person or organisation (Diversus res d.o.o.) that determined how and why your data should be processed.
  • Contact details of the data protection officer, where applicable.
  • Purpose of the processing, as well as the legal basis for the processing.
  • If the processing is based on the legitimate interests of Heraldi members or a third party, such as one of its clients – information on those interests.
  • Categories of personal data collected, stored and processed.
  • Recipient(s) or categories of recipients to whom the data is disclosed/will be disclosed.
  • How long will the data be stored?
  • Details of your rights to correct, delete, restrict or oppose such processing.
  • Data on your right to withdraw consent at any time.
  • How to file a complaint to the supervisory authority (data protection regulator).
  • Whether the provision of personal data is a legal or contractual requirement or a requirement necessary for the conclusion of a contract, and whether you are required to provide personal data and the possible consequences of the failure of such data.
  • The source of personal data if they were not collected directly from you.
  • Details and information on automated decision making, such as profiling and all relevant information on the logic involved, as well as the meaning and expected consequences of such processing.
  • Right to correction. You have the right to request the correction of incorrect personal data and the right to add personal data that will fill in any incomplete personal data.
  • Right to forget. In certain cases, you have the right to request deletion of your personal data.
  • Right to data transfer. You have the right to ask that the data someone has about you be transferred to another entity.
  • Right to restrict processing. In certain cases, you have the right to request the restriction of processing.
  • Right to object. You have the right to object to certain types of processing and collection of data, such as direct marketing.
  • Right to object to automated personal data processing and profiling
  • Right to complain to a supervisory authority. If you believe that the processing of your personal data is contrary to the General Data Protection Regulation, you have the right to file a complaint to the competent supervisory authority.

For the territory of the Republic of Croatia, the supervisory body is the Personal Data Protection Agency, with its registered office at: Martićeva ulica 14, 10000 Zagreb, Croatia, web: http://azop.hr/, tel.: +385 1 4609 000.
You can request the fulfilment of the said requests by:

  • Personal contact at the registered office of Diversus res d.o.o., Zagreb, Frankopanska 6
  • Sending a request to the e-mail address gdpr@heraldi.hr
  • Writing to the address of the registered office

In order to protect you as the owner of personal data, it will be necessary for you to identify yourself as the applicant in an appropriate manner, which will be sufficient guarantee to Diversus res d.o.o. that the personal data are given to their owner.

Contact for objecting, resolving misunderstandings and answering questions
To send your complaint or objection and if you want to resolve any misunderstanding, ambiguity or doubt regarding your personal data processed by Diversus res d.o.o., please use our following contacts:

Diversus res d.o.o.
Frankopanska 6
10000 Zagreb
Republic of Croatia
e-mail: gdpr@heraldi.hr