Privacy Policy
Data Controller Information
- WERXE d.o.o.
- Rijeka, Šetalište trinaeste divizije 17
- dpo@werxe.eu
Data Protection Officer (DPO)
- E-mail: dpo@werxe.eu
- Tel: +385 95 3472130
Scope of the Privacy Policy and Types of Your Data We Process
This Privacy Policy applies to the processing of personal data within our regular business operations, which includes business relationships with clients, potential clients, and external service providers, negotiating services, conducting ISO audits, and ensuring general and information security. It also applies to processing via websites on the werxe.eu domain, when participating in business meetings, fairs, presentations, and educational events, as well as on social media.
This Privacy Policy does not cover the processing of personal data of our employees and job applicants. The rules regarding the processing of their data are regulated by a separate 'Employee and Candidate Privacy Policy', which candidates and employees are directly introduced to during the selection process or upon employment.
We process your personal data through collection, storage, delivery, recording, structuring, and other processing methods. In accordance with our business processes and established legitimate interests, the categories of personal data we collect include: first name, last name, age, address, telephone number, email address, job title, photograph, video recording, and other data in this category applicable to business relations. We will also process business data obtained directly from you, such as professional qualifications, intent to develop cooperation, and the like. We will also process available data on social media through our official profiles, such as your comments and visits.
Data Sources: Personal data not collected directly from you may be collected from publicly available registers (e.g., Court Register, Trade Register, Register of Chambers), from publicly available professional profiles (e.g., LinkedIn), and from our private business partners and suppliers.
Obligation to Provide Personal Data: Providing personal data for the purpose of a business inquiry or negotiation is not a legal obligation; however, without providing basic contact information, we will not be able to respond to your inquiry.In the event of entering into a contract, providing certain data (e.g., company name, PIN/tax ID) becomes a contractual and legal obligation, and without it, concluding the contract will not be possible.
Restriction of Data Subjects, Special Categories, and Accidental Data Collection
Our services, websites, and digital communication channels are directed at business entities and adults. Accordingly, our business is not intended nor designed for the collection and processing of personal data of persons under the age of 18.
Furthermore, our regular processing activities do not require the collection of special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, biometric data, or health data) or specific data of vulnerable groups of individuals.
If a data subject provides such personal data on their own initiative (e.g., in the text of an inquiry or communication) or if we collect it accidentally and unintentionally, it will not be used for our processing purposes (especially not in artificial intelligence tools) and we will, in accordance with the data minimization principle, permanently and securely delete it from our systems without undue delay.
Why Do We Collect Your Personal Data?
To ensure full transparency, we process your data relying on clearly separated legal bases:
-
1. Pre-contractual Actions and Contract Performance: We process your personal data to respond to your business inquiries, send offers, negotiate services, and perform the contract concluded with you (or your company).
— Business inquiries and negotiations (without a concluded contract): Retained for one year from the last contact.
— Concluded contracts (clients and partners): Retained for the duration of the contractual relationship. - 2. Compliance with Legal Obligations: We process your data to fulfill our legal obligations and cooperate with competent authorities and regulatory bodies, including complying with their lawful requests. Personal data is stored for this purpose within legally defined limits, i.e., exclusively within the periods directly mandated by specific laws and regulations. For example, financial and accounting documentation (such as issued invoices) is kept for 11 years.
- 3. Legitimate Interest: Based on our legitimate interest, we process your data for market research and interest in our services, improving our services, preparing, applying for, and implementing project proposals for co-financing from EU and national funds (which may include processing data on the professional qualifications of associates and partners to prove the company's capacity), conducting ISO audits (verifications) and corrective actions to comply with standards requirements, preventing fraud, and ensuring information and physical security. Also, based on legitimate interest, we may occasionally publish your personal data (photographs and videos from fairs and events) on our website and social media to showcase our activities. The criteria used to determine the data retention period depend on the duration of the specific analytical project, the relevance of the information collected, and the results of our regular internal audits. After the specific purpose is fulfilled or the legitimate business interest ceases, your personal data is securely deleted or permanently anonymized without undue delay.
- 4. Consent: Based on your consent, we may collect your personal data (for example, subscribing to a newsletter), about which we will specifically inform you at the time of collection. Data is kept until the purpose expires or until you withdraw your consent. After withdrawal of consent, we delete your data without undue delay, unless another lawful legal basis exists for its further processing.
We will not process your personal data on the werxe.eu domain using cookies. We will not further process your personal data for purposes other than those for which they were collected without first providing you with more information about that other purpose, giving due regard to your rights, the purpose, and the legal basis for processing.
Organizational and Technical Measures
We take special care of your personal data and, through the application of appropriate organizational and technical measures, ensure appropriate security and confidentiality of personal data. To ensure an appropriate level of security given the risk, the following measures have been implemented:
- pseudonymization and encryption of personal data, especially when there is an increased risk of unauthorized data access,
- ensuring accurate data, ongoing confidentiality, integrity, availability, and resilience of processing systems and services,
- the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident, through appropriate backup and recovery processes,
- regular testing of technical and organizational measures to ensure the security of processing.
Use of Artificial Intelligence (AI) Tools: When using AI tools to improve internal operational tasks, we have determined the necessary and specific activities, which are carried out exclusively for the purposes previously described in the chapter "Why Do We Collect Your Personal Data?", and we have strictly established the scope of the categories of personal data we process for these purposes. We will never use your personal data to train artificial intelligence, build your profiles, or make automated decisions relating to you that could result in high-risk consequences.
Some of the measures by which we additionally ensure the protection of your personal data include omitting first names, last names, job titles, and other metadata whenever possible during text processing and other similar activities. We will explicitly not process special categories of your data (such as health data, biometric data, or data on religious or trade union membership) through AI.
When using AI tools, we have chosen verified service providers who process personal data for our needs as data processors and are contractually bound not to use the data for training artificial intelligence.
Your Rights
You have the right to access, rectification, erasure, restriction of processing, data portability, the right to withdraw consent, the right to object, and the right not to be subject to a decision based solely on automated processing, including profiling.
In exercising your rights, there are exceptions to the exercise of rights in accordance with the provisions of the General Data Protection Regulation (GDPR). For example, in the case of a concluded contractual relationship, there will not be an automatic obligation to comply with your request for erasure of a specific personal data item.
An objection and request for information are submitted in writing or electronically to the addresses listed at the beginning of this document. Within the process of exercising your rights or resolving your inquiries, the Director and the Data Protection Officer (DPO) are authorized to independently provide you with an oral response to questions, with reference to this written document for all details. In the case of an objection or request for information, we may ask you to take part in security checks (in the sense of identity verification) before we comply with the request; this will not affect the exercise of your right. The deadline for responding to a request is within one month of the request, and if it is complex or a large number of requests have been received within a short period, the deadline may be extended by up to a further two months, with mandatory notification of the individual.
- Right to Access Data: you may request confirmation as to whether personal data relating to you is being processed, and if so, access to the personal data and information, among other things, about the personal data processed, the purpose of processing, the retention period, and transfers to third countries.
- Right to Erasure ("Right to be Forgotten"): you have the right to obtain the erasure of personal data relating to you without undue delay. We will erase personal data without undue delay if, among other things, the personal data is no longer necessary for the purpose of processing, if it has been unlawfully processed, or in similar situations. If we have publicly published your photographs/videos and a justified request exists, we will delete the personal data in question. If we have also published a photograph or other personal data on a social network, you have the right to request the deletion of that personal data directly from the social network as well.
- Right to Rectification/Completion: you have the right to request the rectification of inaccurate personal data relating to you, and, taking into account the purposes of processing, you have the right to have incomplete personal data completed.
- Right to Restriction of Processing: in certain situations — when the accuracy of the data is contested, when you do not want us to erase the data, when the personal data is no longer needed for the original purpose but cannot be erased due to legal grounds, or while a decision on your objection to processing is pending — you have the right to request that processing be restricted, with the exception of storage and certain other types of processing.
- Right to Portability: you have the right to receive the personal data you have previously provided to us in a structured, commonly used, and machine-readable format, and, where applicable, to transmit that data to another controller without hindrance, if the processing is carried out by automated means and is based on consent or a contract.
- Right to Withdraw Consent: you have the right to withdraw your consent at any time if you have given it for any processing of your personal data. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. We will inform you of this before consent is given. Withdrawing consent is as easy as giving it.
- Right to Object: Since we process certain personal data of yours relying on our legitimate interest (such as relationships with clients and suppliers, conducting ISO audits, preventing fraud, and ensuring security), you have the right to object at any time to such processing on grounds relating to your particular situation. In that case, we will no longer process your personal data for that purpose, unless we demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the data is necessary for the establishment, exercise, or defense of legal claims.
- Right Regarding Automated Individual Decision-Making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. As stated above, our company does not carry out this type of automated decision-making or profiling.
Right to Lodge a Complaint with a Supervisory Authority (the Personal Data Protection Agency)
Before submitting a request to establish a violation of rights, we advise you to first contact us as the data controller in writing to exercise your rights.
If you believe that our processing violates the regulations relating to the protection of your personal data, you have the right to submit a request to establish a violation of rights (a complaint) to the Personal Data Protection Agency (AZOP). Your request must be clear and complete, and must include basic information (first name, last name, OIB/personal identification number, address), a detailed description of the violation, and copies of relevant documents.
You can submit a request to the Agency in the following ways:
- — in person (verbally, stated for the record)
- — in writing to the address:
Personal Data Protection Agency, Ulica Metela Ožegovića 16, 10 000 Zagreb, Croatia - — by completing the online form available on the website: www.azop.hr
- — by sending an e-mail to: azop@azop.hr
- — by sending a fax to: +385 1 4609 099
Information on Data Recipients, Categories of Recipients, and Transfers of Data to Third Countries and International Organizations
We take special care not to disclose your personal data to recipients to a greater extent than is necessary for the previously described purposes of processing.
We will disclose your data to recipients in connection with certain internal activities, such as data storage on a web server and system maintenance, as well as to providers of IT and communication solutions, external AI service providers, and other business service providers who act exclusively as our data processors and process data strictly according to our instructions. In these cases, processing will be carried out through verified external services, i.e., our processors, who may be located within or outside the European Economic Area.
If, when using the aforementioned external services and AI tools, your personal data is transferred outside the European Economic Area (EEA), we carry out such transfers strictly in accordance with the requirements of the General Data Protection Regulation in order to continuously protect your security. For such transfers to third countries, we primarily rely on official adequacy decisions of the European Commission (such as, for example, the application of the Data Privacy Framework - DPF for transfers of data to our service providers in the USA).
Your data may be made available to external auditors, competent national and European institutions, agencies, and intermediary bodies for the purpose of applying for and implementing EU projects, and to certification bodies (e.g., as part of ISO audits), as well as to competent public authorities in order to fulfill legal obligations.
When you communicate or interact with us via external communication platforms (such as messaging applications) or social networks, please note that these service providers generally act as separate or joint data controllers. When using such communication channels, these platforms collect and process your data in accordance with their own privacy policies, terms of use, and purposes, which you can find on their official websites.
Last modified: June 2026