This privacy policy describes how we collect, use, and protect your personal data when you use our website. By using this site, you agree to the terms and conditions outlined in this document. Please read this policy carefully to understand our practices regarding your data.
Who We Are
The owner of this website is Pena Autokozmetika d.o.o., headquartered in the Republic of Croatia, 10451 Pisarovina, Gospodarska 8, registered at the Commercial Court in Zagreb, Company Registration Number (MBS) – 080583428, Personal Identification Number (OIB): 27073808980. We are committed to protecting the privacy of all visitors and users of our site. For any questions related to data protection, you can contact us via email at: pena@pena.hr.
What Data Do We Collect?
We collect various types of data, including:
- Personal Data: Name, email address, phone number, IP address, and other information you voluntarily provide when filling out forms on our site or contacting us via email.
- Automatically Collected Data: Information about your device, browser, IP address, geolocation, and data about your activities on our website (e.g., which pages you visit, how much time you spend on the site). We collect this data through cookies and similar technologies (more information on cookies can be found in our Cookie Policy).
How Do We Use Your Data?
We use your data for the following purposes:
- Ensuring Website Functionality: Using essential cookies and technologies to ensure the proper functioning of the website.
- Improving User Experience: Analyzing your data to understand your preferences and optimize the content and functionality of the website.
- Marketing and Promotions: We use your data to display relevant ads via Facebook Pixel, Google Ads, and similar platforms. These tools help us tailor marketing campaigns to your interests.
- Analytics: Collecting data via Google Analytics to monitor website usage and improve our offerings.
Legal Basis for Data Processing
We process your data based on the following legal grounds:
- Consent: When you give us consent to use cookies or when you subscribe to our newsletter.
- Contractual Obligation: If data processing is necessary to fulfill a contract (e.g., providing a service you requested).
- Legitimate Interest: Data processing for purposes of improving user experience and analytics, provided such processing does not infringe on your rights and freedoms.
Sharing Your Data
We do not share your personal data with third parties except in the following cases:
- When we use third-party services for analytics and advertising (e.g., Google, Facebook), in accordance with their privacy policies.
- When legally obligated to disclose data (e.g., at the request of courts or regulatory bodies).
Your Rights
Under applicable data protection laws (including GDPR), you have the following rights:
- Right to Access: You can request a copy of your personal data that we hold.
- Right to Rectification: If you believe your data is inaccurate or incomplete, you can request its correction.
- Right to Erasure: You can request the deletion of your data unless we are legally required to retain it.
- Right to Restrict Processing: In certain situations, you can request the restriction of your data processing.
- Right to Object: You can object to the processing of your data for marketing purposes or based on legitimate interests.
- Right to Data Portability: You can request the transfer of your data to another service provider.
To exercise these rights, contact us at pena@pena.hr
GDPR Compliance
Your privacy is extremely important to us, and we comply with all obligations set out by the General Data Protection Regulation (GDPR), which has been in effect in the European Union since May 25, 2018. GDPR is designed to protect individuals’ fundamental rights and freedoms in relation to the processing of their personal data, and it sets strict guidelines on how organizations can collect, process, and store personal data.
As part of our GDPR commitment, we undertake the following measures:
- Data Collection and Processing: We collect and process personal data solely for clear and lawful purposes. Data is collected with your explicit consent or based on legitimate interest, ensuring all appropriate protective measures.
- Transparency: This privacy policy ensures that you have complete information on which data we collect, why we collect it, how we use it, and how we share it with third parties (if applicable). Transparency is a key GDPR principle, so we provide you with a clear insight into our data processing practices.
- User Rights: In line with GDPR, you have the following rights regarding your personal data:
- Right to access
- Right to rectification
- Right to erasure (“right to be forgotten”)
- Right to restrict processing
- Right to data portability
- Right to object
- Third-Party Data Processing: When data processing involves third-party services (e.g., Google Analytics, Facebook Pixel), we ensure that these service providers also comply with GDPR and that your data is protected in accordance with applicable laws.
- Data Security: We have implemented technical and organizational measures to protect your data from unauthorized access, misuse, loss, or disclosure. Our goal is to ensure the highest level of security, keeping your personal data protected at all stages of processing.
If you have any questions or requests regarding your rights under GDPR, feel free to contact us at pena@pena.hr or via our contact form.
This privacy policy is designed to ensure our full compliance with GDPR and to protect your rights as a user.
Cookies and Consent Management
We use cookies to improve the functionality of our website, analyze traffic, and personalize content. The cookies we use include functional cookies, performance and analytics cookies, and marketing cookies.
We have integrated the CookieYes tool for managing cookies, allowing you to easily review and manage your consent for cookie usage. Using our tool, you can adjust your cookie preferences at any time.
For more information about cookie usage, please refer to our [Cookie Policy].
Google Analytics and GDPR Compliance
Our website uses Google Analytics to monitor and analyze user behavior in order to improve website functionality and content. Google Analytics collects data such as IP addresses, geolocation, device information, and activity on the website (e.g., pages you visit, duration of visits).
To comply with the General Data Protection Regulation (GDPR), we have implemented the following protective measures:
- IP Address Anonymization: Google Analytics on our website uses IP anonymization, meaning your IP address is shortened within member states of the European Union or other parties to the Agreement on the European Economic Area. This ensures that Google does not store your full IP address.
- User Consent: The use of Google Analytics cookies on our website is based solely on your consent. Through the integration of the CookieYes tool, you can choose whether to accept or reject analytics cookies. Your consent can be withdrawn at any time via the cookie settings.
- Data Processing Agreement with Google: As part of our GDPR compliance, we have entered into a Data Processing Agreement with Google, meaning that Google processes the collected data solely in accordance with our instructions and does not use it for its own purposes.
For more information on how Google processes your data, you can visit Google’s privacy policy and Google Analytics information.
By adhering to these measures, we ensure that the use of Google Analytics on our website complies with applicable data protection regulations, including GDPR.
Data Security
We take all reasonable technical and organizational measures to protect your data from unauthorized access, loss, or misuse. However, please note that data transmission over the internet is never 100% secure, so we cannot guarantee absolute security of your data.
Changes to the Privacy Policy
We reserve the right to modify this privacy policy at any time. Any changes will be posted on this page and will take effect immediately upon publication. We recommend reviewing this policy periodically to stay informed about how we protect your data.
Contact Us
If you have any questions or requests regarding this privacy policy, feel free to contact us via email at pena@pena.hr or through the contact form on our website.
Last updated: 30.09.2024
This privacy policy is crafted in accordance with the main data protection laws, including GDPR, and serves to ensure your rights and transparency in data processing.