Privacy policy
Komed d.o.o., located in Sveta Nedjelja, Brezje, at 14 Vladimira Nazora Street, registered under the Business Court Registry in Zagreb with the registration number (MBS): 080064026 and VAT ID: 77831468864, acting as the data controller, has prepared this Notice for you in order to acquaint you with the process of processing and protecting your personal data.
This notice has been posted on our website to make information about the processing of your personal data available to you at any time.
This notice is effective as of 1. april 2024.
DATA WE COLLECT
The data we collect falls into three categories:
(a) Information provided by you;
(b) Information collected automatically; and
(c) Information obtained from other lawful sources.
Generally, we collect data directly from you, and you provide it to us voluntarily. We will inform you when providing your personal data is necessary for the provision of a service or required by law. Please note that if the provision of data is necessary for the provision of a service or required by law, and you do not provide us with the necessary information, we will not be able to provide our service.
Collecting data directly from you
You can provide us with the following information:
- personal data, such as your name, postal and email address, phone number, date of birth, and other contact details when you register for our online or SMS services, participate in any of our contests, or contact us by phone or through online services to make an inquiry, give praise, or lodge a complaint about our products and/or services;
- transaction data, including details of products you purchase, prices, payment method, and payment details;
- data about your user account, such as your username and password used to access our online services or to purchase or use our products and services.
We collect the above-mentioned data for the purpose of entering into and fulfilling contracts with you, fulfilling our legal obligations, or based on our legitimate interests in accordance with Article 6. st. 1. tč. b, c, and f of the General Data Protection Regulation (hereinafter referred to as GDPR).
In addition to the above, based on your consent in accordance with Article 6. st. 1. tč. a of the GDPR, we may also collect the following data:
- information about your profile, including products and services you like, and the time at which you most frequently visit us; and
- other personal data that you voluntarily disclose to us during communication with us.
Collecting data by automated means
We may use automated technology to collect data from your computer or mobile device when you visit our restaurants, use our online services, or utilize technologies in our restaurants. Automated data collection methods may include "cookies," local shared objects, and web beacons. Below is more information about "cookies" and other technologies.
In this way, we may collect data about:
- internet protocol (IP) address;
- the operating system of your computer or mobile device and the Internet browser you use;
- the type of mobile device and its settings;
- the unique device identifier (UDID) or mobile equipment identifier (MEID) for your mobile device;
- device and component serial numbers;
- advertising identifiers (e.g., IDFA and IFA) or similar identifiers;
- your communication with us or about us on social media; and
- your activities concerning how you use our online services, such as the content you visit on our mobile applications.
We will endeavor, whenever technically feasible and reasonable to expect from us, to request and obtain your consent for the collection and processing of this data by us. You can withhold such consent for data collection by refusing to grant the requested consent, as well as by using your device or Internet browser settings and following the instructions of your mobile service provider, device manufacturer, or Internet browser provider, to whom you can address for this purpose. Some of the online services and technologies in restaurants may not function properly if they do not have information about your location, and we will strive to inform you about this. If you wish for us to delete information we have collected that may reveal your location, please contact us at the address provided below. It is possible that we may be required to retain some of such data by law.
Collecting data from other sources
We may collect information about you from other legitimate sources, ensuring that the data is legally obtained. We may also collect publicly available data. For example, we may collect information that you have posted on your public profile while communicating with us through that profile.
NOTICE TO BUSINESS PARTNERS' REPRESENTATIVES
Komed LLC commits to handling the collected personal data of owners, representatives, or other representatives of PARTNERS in accordance with the provisions of the General Data Protection Regulation and relevant applicable regulations on personal data protection. For this purpose, in accordance with the provisions of Article 12 i 13. of the General Data Protection Regulation, Komed LLC provides the following information:
Personal data collected in the process of entering into and fulfilling contracts as a data controller are collected by Komed LLC, Croatia, Sveta Nedjelja, Brezje, Vladimira Nazora 14, VAT ID 77831468864. The contact person for Data Protection Officer is labor@komed.hr
Komed may use the collected personal data for the purpose of drafting and fulfilling cooperation contracts. In accordance with the above, data is collected based on Komed's legitimate interest, for the purpose of entering into and fulfilling contractual relationships.
The data collected includes contact information of partners' contact persons – directors, owners, and/or employees responsible for communication with Komed (name, position, official mobile phone, and official landline).
The collected data may be disclosed to competent authorities in accordance with the provisions of applicable regulations (for example, police, courts, tax authorities, etc.). The collected data is not exported outside the EU.
The collected data is retained for the periods prescribed by positive regulations (tax and accounting regulations), and additionally for a period of 2 months from the expiration of the statute of limitations for rights and obligations of Komed.
Komed respects the data subjects' rights to access, rectification, erasure, and restriction of processing of personal data, as well as the right to object to processing and the right to data portability. Data subjects may exercise the aforementioned rights by submitting a written request to Komed and/or the Data Protection Officer. The right to lodge a complaint is exercised by lodging a complaint with the Croatian Personal Data Protection Agency.
HOW WE USE THE DATA WE COLLECT
We may use the data we collect in the following ways:
To provide you with our services and fulfill contractual obligations:
- fulfill your requests, process orders, and handle payments for our products and services;
- communicate with you regarding your orders, purchases, or your accounts with us, as well as regarding your requests, questions, or comments;
- enable you to use our online services (including mobile applications); and
- provide customer support services, including processing complaints about our services.
To offer or improve our services and for other legitimate business reasons:
- to inform you about our products and services, contests, offers, promotions, or special events that we believe may interest you (if you give us permission to do so);
- to personalize your experience in our restaurants and online services or to use analytics and profiling technologies to personalize your experience, deliver content tailored to your estimated interests, and adapt to how you use our online services or technologies in restaurants, to which you always have the right to object;
- to manage our business, including developing new products and services, conducting customer and business research, evaluating the effectiveness of our sales, marketing, and advertising;
- to manage our business, diagnose technical problems or service issues, manage our online services and technologies in restaurants, prevent fraud, collect demographic data about our customers, and determine usage patterns of our services;
- To maintain, manage, and improve our products, offers, promotions, online services, and other technologies;
- for selecting our employees in job vacancies
For the purpose of acting in accordance with legal regulations:
- for the protection against, detection, and prevention of fraud and other criminal activities, as well as for protection against or submission of our lawsuits and claims based on liability;
- for acting in accordance with legal obligations and our policies;
- for establishing, executing, or defending against legal claims against us; and
- monitoring and reporting compliance issues.
With your consent, we may use the data we collect for the following purposes:
- for providing location-based services;
- for providing online services to minors under the age of 16 (with parental consent);
- for the use of cookies and similar technologies;
- for providing online services (including mobile applications) to you.
We may use the data we collect about you in other ways, about which we will inform you at the time of data collection or for which we will seek your consent.
HOW WE SHARE THE DATA WE COLLECT
We do not sell your personal data, and we only share it with others as described in this Privacy Statement.
We may share your personal data with suppliers who perform certain services for us, such as order fulfillment, data processing, or other information technology services, promotion management, contest execution, prize drawing, research and analysis, and user experience personalization with Hotel Magdalena. In such cases, we take measures (such as using standard data protection clauses) necessary to ensure an adequate level of protection for your personal data. We do not allow these suppliers to use or share such data for any purpose other than providing services to us.
For strategic or other business reasons, we may decide to sell or transfer all or part of our business. As part of such sale or transfer, we may also transfer the data we have collected and stored, including personal data, to anyone involved in such sale or transfer.
Sometimes, we may share data that does not directly identify you. For instance, we may share anonymous, aggregate statistical data about your use of our online services. Or we may combine data about you with data about other users and share it with others in a way that cannot lead to the identification of individual subjects.
Additionally, we are authorized to use and share data when necessary to meet legal or regulatory requirements, to protect our online services and technologies in restaurants, to raise or defend against lawsuits and other legal claims, to protect the rights, interests, and safety of our society, our employees, or third parties, or as part of a fraud investigation or other criminal activities, or violations of our policies.
CHILDREN'S PRIVACY
We understand the importance of protecting your privacy when using our online services. We are particularly committed to protecting the privacy of children who visit or use our online services.
Individuals under the age of 16 may use our online services only with the consent of a parent or guardian, depending on what is applicable. We will not knowingly collect and retain personal data of individuals under the age of 16 (in terms of online services) or minors in terms of all other services, without seeking the consent of parents or guardians.
We encourage parents to regularly check and supervise their children's online activities. If you have any questions about our approach to children's privacy, please contact us using the contact information provided below.
YOUR OPTIONS AND CHOICES
If you have consented to receive marketing information from us, you can later opt out by following the unsubscribe instructions found in the marketing messages we have sent you. Similarly, in the general instructions found in the section of your user profile on the online services you use, you can find choices for communication preferences, including opt-out instructions. Additionally, your device may have the option to adjust your communication settings. You can also opt out by contacting us at the address, phone number, or email address provided below.
If you opt out of receiving our marketing messages, we may still send you messages related to your transactions, your user accounts, as well as any competitions, sweepstakes, or draws you have entered.
Opting out of one form of communication does not mean you have opted out of other forms. For example, if you opt out of receiving marketing email messages, you may still receive text (SMS) messages with marketing content if you have chosen to do so.
We do not sell or make personal data available to third parties for their direct marketing activities unless you allow us to do so. After our notice and your consent, we will share your personal data with third parties in accordance with your instructions.
Your data is retained for as long as necessary to fulfill the purposes stated in this Privacy Statement, which means that we will not keep your data for longer than the period for which you have given us your consent, or until the withdrawal of consent (for data collected and processed based on your consent), or generally not longer than a period of 6 years from the end of the calendar year in which the data was collected (unless a longer period is required by law, permanent retention, or when we determine that there is our legitimate interest for longer retention, for example, in situations where a procedure is expected or underway before the competent authority). For retention periods of data collected for special purposes, please review the notices provided in the introductory part of this statement.
YOUR RIGHTS REGARDING PERSONAL DATA
For data we collect and process based on your consent, you have the right to withdraw your consent at any time by submitting an appropriate request to the contact addresses below (this does not affect the lawfulness of processing before consent is withdrawn). Komed d.o.o. respects the rights of data subjects to access, rectify, and restrict the processing of personal data, as well as the right to object to processing and the right to data portability.
These rights include, for example, the following:
- When the processing of your personal data is based on your consent, you can withdraw your consent at any time; withdrawing consent will not affect the lawfulness of processing carried out before consent is withdrawn;
- Request access to your personal data and obtain a copy of such data;
- Receive your personal data in a structured, commonly used, and machine-readable format and request us to directly transmit them to another company, in cases where you have provided us with your personal data and when they are processed based on your prior consent or are necessary for the fulfillment of a contractual obligation;
- Rectify your personal data if they are inaccurate or incomplete;
- Object to reasons related to your specific situation against our processing of your personal data based on our legitimate business interest, including profiling and sending marketing communications;
- Delete your personal data, including all links to them and all copies and images thereof, to the extent permitted; for example, if your data is outdated, unnecessary, or unlawful, or if you withdraw your consent for processing based on that consent and when you succeed with an objection to processing;
- Obtain restriction of processing while we process your request or objection regarding the accuracy of your personal data or the lawfulness of our processing of your personal data and the legitimacy of our interest in processing that data, or if your personal data are needed for the purposes of conducting a lawsuit;
- Furthermore, you have the right to withdraw your consent previously given for the processing of your personal data at any time.
You can exercise these rights without being charged a fee for their realization, except in cases where the request is unfounded or excessive, for example because it is repetitive.
We may refuse to act on your request or impose some restrictions, to the extent permitted by applicable law. Before providing you with any information or correcting inaccuracies, we may ask you to confirm your identity and/or provide additional details to help us respond to your request.
Data subjects exercise the aforementioned rights by submitting a written request to Komed and/or the Data Protection Officer, at the contact details provided below. The right to lodge a complaint is exercised by lodging a complaint with the Croatian Personal Data Protection Agency.
USING OUR ONLINE SERVICES AND OTHER TECHNOLOGIES
Our website may use "cookies," web beacons, and other similar technologies on our online services, as well as in other areas of our business, such as online advertising, to collect data and deliver services or products you have requested. As stated earlier in this statement, we will seek your consent for the use of such functionalities in each case.
"Cookies" and Other Tools
"Cookies" are small text files placed on a user's web browser or device for the purpose of recording and/or collecting user data.
A web beacon (web-beacon) is a small object or image embedded in a website, application, or email and used to track activities. They are sometimes also referred to as "pixels" or "tags".
Please note the following:
- When using our online services, you may be sent a "cookie".
- "We use "cookies" and other tools temporarily ("session cookies" - lasting only for the duration of your visit to the page) and permanently ("persistent cookies" - lasting for a specified period of time).
- Our online services, as well as other areas related to our business, may have web beacons. "We use "cookies", web beacons, and other similar tools to collect data for the purposes described in this Statement.
We may use these technologies for the following purposes:
- To enable you to access and use our online services which may not function properly without these technologies;
- to improve our products and services;
- to monitor the effectiveness of our online services (e.g., traffic, errors, page response time, popularity of certain content, etc.);
- to customize our services to your preferences and interests;
- for marketing activities through targeted advertising; and
- for other purposes described in the section of this Statement titled "How We Use Collected Data."
For example, we may use certain tools to determine if you have opened an email message or clicked on a link contained in an email message, or how you use our websites and the content of our mobile applications, or if you have viewed our online advertisement.
Komed and third parties (e.g., advertising networks, whose privacy policies are not controlled by us) may use these technologies to collect data about your online activities over time and across websites and devices, including when you use our online content, for the purpose of tailoring our content to your interests.
We advise you to adjust the appropriate settings on your web browser if you do not wish to receive "cookies" or if you want your browser to notify you when you receive a "cookie." Using the "Help" content on your browser, familiarize yourself with how to change your settings regarding "cookies."
Some newer Internet browsers may have a "Do Not Track" option that sends a "Do Not Track" signal to all websites you visit, indicating that you do not wish your activities to be tracked. At this time, we do not take action in response to the "Do Not Track" signal because a universal technological standard for this has not yet been developed. However, we are monitoring the development of these technologies, and it is possible that we will adopt such a standard when it is developed.
Targeted advertising
When using our online services, we may collect information about your activities in order to offer you advertising content tailored to your interests. As previously stated in this statement, the provision of advertising content is conditional upon your consent, which you can always withdraw as described earlier in this statement.
Please note that our advertising messages may also appear on the websites of third parties from whom we or our partners (marketing agencies, or other companies) have purchased advertising space for posting advertising content. In this case, the collection and tracking of data on access to such advertising content are subject to the rules of the advertising pages on which the content is published. We do not influence the privacy policies of such advertising pages, but we will make reasonable efforts to ensure that our ads are not posted on advertising pages that have not implemented GDPR and other applicable data protection regulations.
LINKS TO OTHER WEBSITES AND SOCIAL NETWORKS
Our online services may contain links to websites that are not operated by us but by third parties. If you visit these linked websites, we advise you to read their privacy policies, terms of use, and other policies. We are not responsible for the policies and practices of third parties. Any data you provide to these organizations will be treated in accordance with their privacy policies, terms of use, and other policies.
Our online services may also feature applications, tools, gadgets, and widgets from other providers, such as Facebook's "Like," which may also use automatic information collection about how you use these features. These organizations may use your data in accordance with their policies, over which we have no control.
INFORMATION SECURITY
We are committed to taking all appropriate and reasonable measures to protect the security of your personal data. Our technical, administrative, and physical protection procedures are designed to protect your personal data from accidental, unlawful, or unauthorized loss, access, disclosure, use, alteration, or destruction. While we make every effort to protect our information systems, no website, mobile application, computer system, or data transmission over the internet or other public network is guaranteed to be 100% secure.
TRANSFER OF DATA ABROAD
The transfer of personal data abroad, for the purposes stated in this Privacy Statement or, for example, for the storage of your personal data, will be carried out in accordance with this Privacy Statement and applicable personal data protection regulations.
Your personal data may be transferred or stored within the European Economic Area (EEA). Data may also be transferred and stored outside the European Economic Area. In this case, the data may be processed by our suppliers as third parties. Data outside the European Economic Area may only be transferred provided that there is adequate protection such as (1) a European Commission decision on adequacy regarding the country to which the data are exported; (2) confirmation of the existence of a "privacy shield" in the case of data exports to the USA; or (3) an appropriate and binding data protection agreement in accordance with personal data protection regulations.
CHANGES TO THE PRIVACY STATEMENT
This Privacy Statement applies from the date indicated at the beginning of the Statement. The Statement may be amended from time to time. If there are any changes, we will publish the new version at this location with the amended "Date of Last Change" (i.e., the date from which it applies) at the beginning of the Statement. We recommend that you regularly check for the latest versions of the Statement here.
IF YOU HAVE QUESTIONS ABOUT THE PRIVACY POLICY
If you wish to contact us regarding a question, request (including withdrawal of consent or request for access, correction, and limitation of personal data processing, as well as the right to object to processing and the right to data portability), or inquiry regarding your personal data, you can do so at:
Komed d.o.o.
Vladimira Nazora 14, 10250 Sveta Nedjelja, Brezje
Data Protection Officer Contact: labor@komed.hr
VERSION: 1.0. FROM 1. april 2024.