Legal & Data Protection

Privacy Policy

This policy explains how AD BUSINESS OPERATIONS d.o.o. collects, uses, stores and protects personal data submitted through its website, enquiry form and business communication channels.

Controller: AD BUSINESS OPERATIONS d.o.o.Jurisdiction: Croatia, European Union

1. Data Controller

AD BUSINESS OPERATIONS d.o.o., Ribnjak 40, 10000 Zagreb, Grad Zagreb, Croatia, is the controller of the personal data described in this policy.

Websiteadbusinessoperationsdoo.com

2. Personal Data We Process

Depending on how you interact with us, we may process:

  • Your name, business email address and other contact details you choose to provide.
  • The organisation you represent, your professional role and country, when provided.
  • The content of enquiries and business correspondence, including requested services, objectives and scheduling information.
  • Contractual, billing, invoicing and project-administration information where an engagement is established.
  • Records of scope, authorised contacts, deliverables, approvals and support requests.
  • Limited technical records required to operate and secure the website, such as timestamps, security logs and basic browser information produced by hosting infrastructure.

We generally obtain information directly from you or from an authorised representative of your organisation. We may also receive business contact details from a colleague who asks us to communicate with you about a proposed or existing engagement.

Do not send sensitive material through the enquiry form.

Please do not submit passwords, access credentials, special-category personal data, production datasets or confidential third-party information. If protected project information is required, an appropriate transfer method must first be agreed.

3. Purposes and Legal Bases

Enquiries and pre-contractual discussions

We use submitted contact information to review and respond to requests and to take steps requested before entering into a contract.

Service delivery and administration

Where a business relationship is established, information is processed to perform the agreement, coordinate authorised participants, provide deliverables, issue invoices and maintain appropriate records.

Legal, operational and security requirements

Information may be processed to comply with law, maintain business records, establish or defend legal claims, prevent misuse and protect our website, communications and operations.

Business development and marketing

Marketing communications are sent only where a valid legal basis exists and applicable electronic-communications rules permit them. Consent may be withdrawn at any time where processing relies on consent.

Legal bases

Depending on the circumstances, processing is based on steps requested before a contract, performance of a contract, compliance with a legal obligation, consent, or our legitimate interests in operating and protecting a professional B2B business. When relying on legitimate interests, we consider reasonable expectations and the potential impact on individual rights.

Automated decision-making

Information submitted through this website is not used to make decisions producing legal or similarly significant effects solely by automated means.

4. Service Providers and Other Recipients

We do not sell or rent personal data. Information may be disclosed where necessary to hosting, email, communications, document-management, accounting or other providers supporting our operations; professional legal or accounting advisers; authorised project counterparties; or competent courts, regulators and public authorities where disclosure is legally required.

Providers receive only the information reasonably required for their function and are expected to act under appropriate contractual, confidentiality and security obligations. Information may also be disclosed in connection with a lawful corporate reorganisation, subject to applicable data-protection requirements.

5. International Transfers

Some service providers may process information outside Croatia or the European Economic Area. Where safeguards are required, we use an applicable lawful mechanism, which may include an adequacy decision, the European Commission’s standard contractual clauses or another mechanism permitted by data-protection law. Information about relevant safeguards may be requested through our privacy contact, subject to lawful confidentiality restrictions.

6. Data Retention

We retain personal data only for as long as reasonably necessary for its purpose. Unsuccessful or inactive enquiries are periodically reviewed and deleted or anonymised when no longer required for business follow-up, security or legal purposes. Contract-related records may be retained for the relationship and afterwards for periods required by accounting, tax, limitation and other applicable laws.

Retention depends on the record type, sensitivity, risk of continued storage and legal requirements. When information is no longer needed, it is deleted, anonymised or securely isolated until deletion is possible.

7. Your Data-Protection Rights

Subject to applicable law, you may request confirmation and access; correction; deletion; restriction; portability of information you supplied in an applicable machine-readable format; or object to processing based on legitimate interests or direct marketing. You may withdraw consent at any time where consent is the legal basis. Withdrawal does not affect earlier lawful processing.

We may request information to verify identity and authority. Rights are not absolute, and an applicable legal exception may permit or require us to limit or refuse a request. Where permitted, we will explain the reason. You may lodge a complaint with the Croatian Personal Data Protection Agency or another competent supervisory authority.

Submit a request

Use our dedicated request page to provide the minimum information needed to locate and process your request.

Open Data Subject Request

8. Information Security

We apply organisational and technical measures designed to protect information against unauthorised access, disclosure, alteration, loss and unlawful use. Measures are selected according to risk and may include access limitation, confidentiality duties, secure communication methods, system maintenance, backup controls and incident-management procedures.

No internet transmission or storage method is completely secure. If a personal-data breach is identified, we assess it and notify supervisory authorities or affected individuals where required by law.

9. Cookies and Similar Technologies

The website may use strictly necessary technologies required for security and basic operation. Analytics, advertising or marketing technologies are not used unless separately disclosed and, where required, activated only after a valid choice. Further information is provided in the Cookie Policy.

10. Children, Contact and Policy Updates

Our services and website are intended for business representatives and are not directed to children. We do not knowingly request personal data from children through the enquiry form.

Privacy questions may be sent to contact@adbusinessoperationsdoo.com. We may update this policy when our services, processing practices, providers or legal requirements change. Material changes will be reflected on this page, and the effective date identifies the current version.