TACT
Privacy Policy
1. Introduction and Data Controller Information
CapriCo d.o.o., with its registered office at Petrinjska ulica 4/1, HR-10000 Zagreb, Croatia, Company Identification Number (OIB): 70595171425, registered with the Commercial Court in Zagreb under Company Registration Number (MBS): 081399095 (hereinafter referred to as the "Company", "we", "our", or "us"), acts as the Data Controller within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation – GDPR) and the Croatian Act on the Implementation of the General Data Protection Regulation (Official Gazette No. 42/2018).
The purpose of this Privacy Policy is to provide visitors to our website and other interested parties with clear, concise, and transparent information regarding:
- who processes their personal data and how to contact us;
- which personal data we collect and for what purposes;
- the legal basis for processing;
- how long we retain personal data;
- with whom we share personal data; and
- their rights and how those rights may be exercised.
Data Controller Contact Details
CapriCo d.o.o.
Petrinjska ulica 4/1, HR-10000 Zagreb, Croatia
Email: info@caprico.hr
Website: www.caprico-tower.hr
2. Personal Data We Collect
Personal data means any information relating to an identified or identifiable natural person, including identifiers such as a name, identification number, location data, online identifier (IP address), or factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
The Company collects the following categories of personal data only to the extent necessary for the specific purpose concerned.
2.1 Data Collected Through the Website
- Technical information regarding website usage, including: IP address, browser type, operating system, date and time of visit, pages viewed and referring URL. This information is collected automatically by our web server and technical systems to ensure the proper functioning and security of the website.
2.2 Data Collected via Email
- When you contact us by email, we may collect first and last name, email address, telephone number, company name and the contents of your inquiry. We collect only the information that you voluntarily provide.
2.3 Job Applications
- When you submit an open application or apply for a job opening, we may collect first and last name, contact details, education and employment history, cover letter and any additional information contained in your CV or application documents.
2.4 Cookies
- For information regarding cookies, please refer to Section 3 of this Privacy Policy.
3. Cookies
More detailed information regarding cookies is available in our separate Cookie Policy.
4. Purposes of Processing, Legal Basis and Retention Periods
We process personal data solely for specified purposes and retain it only for as long as necessary.
- Responding to inquiries via email (name, email address, telephone number, contents of the inquiry) based on steps taken prior to entering into a contract (Article 6(1)(b) GDPR) or legitimate interest (Article 6(1)(f) GDPR). Retention period: until the inquiry is resolved, and no longer than one year.
- Recruitment applications (contact details; CV; education and employment information) based on steps taken prior to entering into a contract (Article 6(1)(b) GDPR). Retention period: up to two years, unless you request deletion sooner.
- Website Security and Technical Operation (IP address, technical logs) based on legitimate interest (Article 6(1)(f) GDPR). Retention period: up to 90 days, unless required longer due to a security incident.
- Legal Obligations and Defense of Legal Claims: where processing is required to comply with legal obligations (Article 6(1)(c) GDPR) or to establish, exercise, or defend legal claims (Article 6(1)(f) GDPR), personal data will be retained for the period prescribed by applicable law or until the relevant proceedings have been finally concluded.
Whenever processing is based on legitimate interests, we have carried out a balancing test and concluded that our legitimate interests do not override your rights and freedoms. You have the right to object to such processing (see Section 7).
5. Recipients of Personal Data
Your personal data may be disclosed only where necessary to achieve the purposes described above and only to the following categories of recipients:
- Data Processors: IT service providers, cloud service providers, hosting providers and email service providers who process personal data on our behalf under written agreements compliant with Article 28 GDPR.
- Employees of the Company: authorized employees and contractors who require access to personal data to perform their duties and who are bound by confidentiality obligations.
- Business Partners: only where there is an appropriate legal basis and, where applicable, under written contractual arrangements.
- Public Authorities: courts, regulatory authorities, tax authorities and other competent public authorities where disclosure is required by law, court order or for the establishment, exercise or defense of legal claims.
The Company does not sell, rent or otherwise disclose personal data to third parties for commercial marketing purposes.
5.1 International Transfers
The Company currently does not transfer personal data to countries outside the European Economic Area (EEA).
6. Security of Personal Data
The Company implements appropriate technical and organizational measures in accordance with Article 32 GDPR, considering the nature, scope, context, and purposes of processing as well as the risks to the rights and freedoms of individuals.
In the event of a personal data breach likely to result in a risk to the rights and freedoms of individuals, the Company will notify the Croatian Personal Data Protection Agency (AZOP) within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR, and where required, notify affected individuals pursuant to Article 34 GDPR.
7. Your Rights
Under the GDPR you have the following rights:
- Right of Access (Article 15 GDPR): You have the right to obtain confirmation as to whether your personal data is being processed and, if so, access to that data and related information.
- Right to Rectification (Article 16 GDPR): You may request correction of inaccurate or incomplete personal data.
- Right to Erasure ("Right to be Forgotten") (Article 17 GDPR): You may request deletion of your personal data where the legal conditions are fulfilled.
- Right to Restriction of Processing (Article 18 GDPR): You may request that processing be restricted in certain circumstances.
- Right to Data Portability (Article 20 GDPR): Where processing is based on consent or contract and carried out by automated means, you may receive your data in a structured, commonly used, and machine-readable format and transmit it to another controller.
- Right to Object (Article 21 GDPR): You may object at any time to processing based on our legitimate interests. Unless compelling legitimate grounds exist that override your interests, rights, and freedoms, we will cease such processing.
- Right to Withdraw Consent (Article 7(3) GDPR): Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out before its withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP):
Croatian Personal Data Protection Agency (AZOP) Selska cesta 136, HR-10000 Zagreb, Croatia, Telephone: +385 1 4609 000, Email: azop@azop.hr, Website: www.azop.hr
Exercising Your Rights: Requests concerning your rights may be submitted by mail to the Company's registered office or by email to info@caprico.hr. We will respond without undue delay and no later than one month after receipt of your request. In complex cases this period may be extended by up to two further months, in which case you will be informed accordingly. Requests are free of charge unless manifestly unfounded or excessive.
To verify your identity and prevent misuse, we may request additional information where necessary.
8. Children
Our website and services are not intended for individuals under 16 years of age. Pursuant to Article 8 GDPR and the Croatian Act on the Implementation of the GDPR, the minimum age for providing consent for information society services in Croatia is 16 years. We do not knowingly collect personal data relating to children. Should we become aware that we have unintentionally collected such data, it will be deleted without undue delay.
9. Links to Third-Party Websites
Our website may contain links to third-party websites. This Privacy Policy applies solely to the Company's website. We encourage you to review the privacy policies of every third-party website you visit.
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in applicable legislation, regulatory guidance, our processing activities or business operations. The date of the latest revision will be indicated in this Policy. Where significant changes are made, we will notify you appropriately, for example by publishing a notice on the website or by direct communication where appropriate. We recommend reviewing this Privacy Policy periodically.
11. Contact
For any questions, requests or comments concerning this Privacy Policy or the processing of your personal data, please contact us:
- Email: info@caprico.hr
- Mail: CapriCo d.o.o., Petrinjska ulica 4/1, HR-10000 Zagreb, Croatia
This Privacy Policy has been prepared in accordance with Regulation (EU) 2016/679 (GDPR), the Croatian Act on the Implementation of the General Data Protection Regulation (Official Gazette No. 42/2018), the Croatian Electronic Communications Act (Official Gazette Nos. 76/2022 and 14/2024), and taking into account the guidance issued by the Croatian Personal Data Protection Agency (AZOP) and the European Data Protection Board (EDPB)