Privacy Policy

Effective date: 28.04.2026.

How we use and protect your personal data

Data Controller

The data controller for your personal data is: HIDROCIBALAE d.o.o., OIB: 38874770240, Jurja Dalmatinca 33,Vinkovci.

In this Privacy Policy, "we", "us" and "Hidrocibalae" refer to the above entity.

Data Protection Officer

The Data Controller is not required to appoint a Data Protection Officer. For any data protection matter, please contact us at dpo@hidrocibalae.hr

Personal Data We Process

We process personal data in different contexts. Below we describe each scenario, the data collected, the legal basis, retention period, and recipients. Providing personal data may be necessary for entering into a contract. Failure to provide such data may result in our inability to provide services.

Website Visitors

When you visit our website, we automatically collect technical data through cookies and similar technologies:

  • Data collected: IP address, browser type and version, operating system, device type, pages visited, time and duration of visit, referral source
  • Legal basis: legitimate interest (Art.6(1)(f)) for strictly necessary cookies; consent (Art. 6(1)(a)) for analytics and marketing cookies
  • Retention: See our Cookie Policy for specific cookie durations
  • Recipients: Your personal data may be disclosed to hosting provider ([Webflow, USA]), analytics provider ([e.g. GoogleAnalytics, USA])

Contact Form / Inquiries

When you contact us through our website, email, or other channels:

  • Data collected: first name, last name, email address, company name, phone number (if provided), message content
  • Legal basis: pre-contractual steps takenat your request (Art. 6(1)(b) GDPR) where your inquiry relates to our servicesor a potential business relationship, legitimate interest (Art. 6(1)(f)) — responding to your inquiry and following up with relevant services
  • Retention: Duration of the inquiry + 1year; if a contractual relationship is established, for the duration of thecontract + 5 years (statute of limitations for potential legal claims)
  • Recipients: Your personal data may be disclosed within the internal platform.

Job Candidates

When you apply for a position through ourwebsite or other channels:

  • Data collected: first name, last name,email address, phone number, CV/resume, cover letter, links to online profiles(LinkedIn, portfolio)
  • Legal basis: Performance of a contract /pre-contractual steps (Art. 6(1)(b)); Consent (Art. 6(1)(a)) if we wish to retain your data for future opportunities
  • Retention: Duration of the recruitment process; data is erased if no employment results, unless you consent to retention for future openings (up to 2 years)
  • Recipients: Your personal data may be disclosed to HR via internal platform.

Recipients of Personal Data

We share your personal data with third parties who assist us in the delivery of our services, or in order to operate and expand our business activities. We will only do so on a strictly need-to-know basis and after entering into the necessary contractual arrangements with such parties. We may share your data with:

  • Hosting providers: [Webflow, USA]
  • Analytics providers: [e.g. GoogleAnalytics, USA]
  • Public authorities: when required by law(tax authorities, courts, regulatory bodies)

All processors are bound by data processing agreements in accordance with Art. 28GDPR.

Transfer of Data Outside the EU/EEA

Your personal data may be transferred outside the European Economic Area when we use service providers based in the United States or other third countries(e.g. Google Analytics).

These transfers are carried out on the basis of:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • EU adequacy decisions, where applicable

We apply appropriate supplementary safeguards in accordance with Art. 46 GDPR. Details about specific transfers are available upon request.

Your Rights

Under the GDPR, you have the right to:

  • Access - request confirmation of whether your data is being processed and obtain a copy (Art. 15)
  • Rectification - request correction of inaccurate data (Art. 16)
  • Erasure - request deletion of your data(“right to be forgotten”) (Art. 17)
  • Restriction of processing - request restriction of processing in certain circumstances (Art. 18)
  • Data portability - receive your data in a structured, machine-readable format (Art. 20)
  • Object - object to processing based on legitimate interest (Art. 21)
  • Withdraw consent - withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal(Art. 7(3))

To exercise your rights, contact us at: dpo@hidrocibalae.hr

We will respond without undue delay and in any event within one month of receipt of the request.

Right to Lodge a Complaint

You have the right to lodge a complaint with the supervisory authority:

Croatian Personal Data Protection Agency (AZOP) Selska cesta 136, 10000 Zagreb, Croatia Phone: +385 1 4609 000 Email: azop@azop.hr Web: www.azop.hr

Data Security

We apply appropriate technical and organisational measures to protect your personal data, including:

  • Ensuring confidentiality, integrity, availability, and resilience of processing systems
  • Restricting access to personal data to authorised personnel only
  • Requiring all staff handling personal data to comply with confidentiality obligations
  • Regular testing and evaluation of the effectiveness of security measures
  • Procedures for restoring data availability in the event of a technical incident
  • [If applicable: ISO/IEC 27001 certification or other relevant certifications]      

Automated Decision-Making and Profiling

We do not use automated decision-making or profiling, that produces legal effects concerning data subjects or similarly significantly affects them within the meaning of Art. 22 GDPR.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be published on this page with an updated effective date.