PRIVACY POLICY
How we collect, use and protect your personal data
1. Who we are
The data controller is Inventa d.o.o., Radnička cesta 52, 10000 Zagreb, Croatia, VAT ID (OIB) 99213847706, Registration No. 1392646 ("Inventa", "we").
Inventa is a strategic marketing and communications agency providing media services, creative strategy and influencer marketing. We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Croatian Act on the Implementation of the GDPR.
2. Data Protection Officer
We have appointed a Data Protection Officer. For any question about the processing of personal data, or to exercise your rights, please contact us:
- by e-mail: info@inventa.hr (subject: "Data protection")
- by post: Inventa d.o.o., attn. Data Protection Officer, Radnička cesta 52, 10000 Zagreb, Croatia
- by phone: +385 1 2361 500
3. What data we process and why
Website visitors. When you send an enquiry through our contact form, we process your name, e-mail address, phone number and message in order to respond (Art. 6(1)(b) and (f) GDPR). With your consent we use cookies for visitor analytics (Google Analytics). Consent is managed through Cookiebot and can be withdrawn at any time (Art. 6(1)(a) GDPR).
Clients, business partners and suppliers. We process business contact details (name, job title, business e-mail and phone) to conclude and perform contracts and for business communication (Art. 6(1)(b) and (f) GDPR), and to meet legal obligations such as accounting and tax requirements (Art. 6(1)(c) GDPR).
Job applicants. We process CV and application data to carry out the recruitment process (Art. 6(1)(b) GDPR), and after the process ends only with your consent.
Data we process for our clients. As part of campaigns and promotional activities (for example prize games and promotions), we process participants' personal data on behalf of and on the instructions of the client, as a processor under a contract pursuant to Art. 28 GDPR. In these cases the client is the controller, and the purpose, scope and retention period are set out in the terms of the promotion and in the client's privacy policy. We do not use such data for any other purpose.
4. Recipients
We do not sell personal data. We share it only where necessary for the purposes above, with:
- providers of IT, cloud storage and software services acting as our processors under data processing agreements;
- media owners and advertising platforms, to the extent required to run a campaign;
- public authorities, where required by law.
Where data is transferred outside the European Economic Area, the transfer is protected by appropriate safeguards, primarily an adequacy decision or the European Commission's Standard Contractual Clauses.
5. How long we keep data
We keep data only as long as necessary for the purpose for which it was collected:
- contact form enquiries: up to 12 months after the last communication;
- contract and accounting records: for the periods required by law (generally 11 years);
- job applications: until the recruitment process ends, and with consent for no more than 12 months;
- data processed for clients: for the period set by the client, after which it is deleted or returned to the client.
6. Your rights
Under the GDPR you have the right:
- of access to your personal data (Art. 15);
- to rectification of inaccurate data (Art. 16);
- to erasure (Art. 17);
- to restriction of processing (Art. 18);
- to data portability (Art. 20);
- to object to processing based on legitimate interest (Art. 21);
- to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
- to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr.
7. How to exercise your rights
Send your request by e-mail or post to the contacts in section 2. To protect your data we may ask you to confirm your identity. We respond without undue delay and at the latest within one month. In complex cases this period may be extended by two further months, and we will inform you if so. Exercising your rights is free of charge.
Legal representatives and authorised persons. For a minor or a person without legal capacity, a request may be submitted by a parent, guardian or other legal representative, with proof of representation. Another person may submit a request on your behalf with a written power of attorney. A legal representative has the same rights as the person they represent.
If a request concerns data we process for a client (section 3), we forward it to the client as controller without undue delay and assist the client in responding.
8. Data security
We apply appropriate technical and organisational measures: encryption of data at rest and in transit, access restricted to authorised staff, password protection and confidentiality obligations for employees. In the event of a personal data breach we act in accordance with Articles 33 and 34 GDPR.
9. Changes
We may update this policy from time to time. The current version is always published on this page together with its effective date.