Privacy Policy and Cookie Notice
Privacy Policy and Cookie Notice
(“Privacy Policy”)
1. GENERAL PROVISIONS
This Privacy Policy applies to the collection and processing of personal data of users of the Boduel online store, available at www.boduel.hr (“Boduel Website”), in accordance with Regulation (EU) 2016/679 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation – GDPR) and relevant national data protection laws.
2. DATA CONTROLLER
The data controller is 73O d.o.o., with its registered office in Zagreb, Radmanovačka ulica 18, registered with the Commercial Court in Zagreb under registration number (MBS): 081435297, VAT number (OIB): 31262027429 (“Data Controller”).
Contact
73O d.o.o.
Radmanovačka ulica 18
Zagreb
Email: info@boduel.hr
3. PURPOSE AND LEGAL BASIS FOR PROCESSING PERSONAL DATA
We process your personal data to fulfill obligations arising from a sales contract or to take actions at your request prior to concluding a sales contract (Article 6(1)(b) GDPR), for purposes such as:
- Establishing and maintaining a user account;
- Enabling participation in a loyalty program;
- Processing orders received through the Boduel Website and complying with legal obligations arising from order processing (including potential returns);
- Carrying out payment transactions;
- Processing inquiries you submit via contact form or otherwise.
Providing personal data for the above purposes is a contractual obligation and a necessary condition for concluding and executing the sales contract. Failure to provide the necessary data will prevent us from delivering the ordered products, processing your order, or responding to your inquiries.
In certain cases, we process your personal data based on our legitimate interests (Article 6(1)(f) GDPR), for example:
- Preventing misuse and fraudulent activities;
- In connection with legal, enforcement, and similar proceedings involving the Data Controller;
- Processing inquiries you submit via contact form or otherwise;
- Informing you about news and offers if you are an existing customer and the information relates to products similar to those you previously purchased, unless you object to such processing.
Additionally, your consent (Article 6(1)(a) GDPR) serves as the legal basis for processing personal data in the following cases:
- Collecting and publishing product reviews;
- Informing you about news and offers if you are not our customer or if it concerns promotional content unrelated to your previous purchases;
- Use of cookies;
- Other purposes specified in the consent.
4. RECIPIENTS OF PERSONAL DATA
The company will not disclose or transfer your personal data to third parties unless necessary to fulfill contractual obligations or for other legitimate purposes provided by applicable regulations. Personal data may be shared with the following categories of recipients:
- Financial institutions for payment processing;
- Delivery services for the shipment of ordered products;
- IT service providers maintaining the technical infrastructure for purchase transactions;
- Accounting service providers to meet legal obligations in the field of accounting;
- Competent state authorities when required to fulfill legal obligations or based on their lawful requests;
- Authorized persons for protecting the rights and interests of you and the Data Controller, including the prevention of abuse and fraudulent activities.
When transferring personal data to third parties, we adhere to the principle of data minimization, ensuring only data necessary for the specific purpose are shared. All recipients are obliged to process personal data in accordance with applicable data protection laws and to implement appropriate technical and organizational safeguards.
5. DATA RETENTION PERIOD
We process your personal data for as long as necessary for the purposes for which they are processed. Data may be stored for longer periods if processed solely for archiving in the public interest, scientific or historical research purposes, or statistical purposes.
6. YOUR RIGHTS REGARDING PERSONAL DATA PROTECTION
You have the following data protection rights:
6.1. Right of Access
You have the right to request confirmation as to whether your personal data is being processed and, if so, access to such data. You can also request information about the purpose of processing, categories of data processed, recipients, and the envisaged storage period. Access may be restricted where provided by EU or national law to protect the rights and freedoms of others.
6.2. Right to Rectification
You have the right to request correction of inaccurate personal data and to complete incomplete data.
6.3. Right to Erasure (“Right to be Forgotten”)
You have the right to request the deletion of your personal data when:
- The data is no longer necessary for the purposes collected;
- You withdraw consent with no other legal basis for processing;
- You object to processing based on legitimate interests with no overriding legitimate grounds;
- Data has been unlawfully processed;
- Deletion is necessary for compliance with legal obligations;
- Data was collected in relation to information society services offered to children.
This right is not applicable when processing is necessary for:
- Exercising the right of freedom of expression and information;
- Compliance with a legal obligation or performance of a task in the public interest;
- Archiving in the public interest, scientific or historical research, or statistical purposes;
- Establishing, exercising, or defending legal claims.
6.4. Right to Restrict Processing
You may request restriction of processing if:
- You dispute data accuracy;
- Processing is unlawful, but you oppose deletion;
- The controller no longer needs the data but you require it for legal claims;
- You have objected to processing pending verification of overriding legitimate grounds.
6.5. Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller, where technically feasible.
6.6. Right to Object
You have the right to object to processing based on our legitimate interests.
6.7. Right to Withdraw Consent
Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
6.8. Right to Lodge a Complaint
If you believe your personal data is being processed unlawfully, you may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP). Contact details are available at: [Contact – Croatian Personal Data Protection Agency].
To exercise your rights, contact us using the contact details provided in section 2 of this Privacy Policy.
7. PERSONAL DATA SECURITY
We collect, process, and protect personal data using appropriate technical and organizational measures. We process data following principles of data minimization, purpose limitation, storage limitation, and access control. All employees of the Data Controller have signed confidentiality agreements committing to protect personal data they access while performing their duties.
8. COOKIES
This section explains what cookies are, how we use them, and what information we collect when you visit our website.
8.1. What are Cookies?
Cookies are small files stored by a web browser on your computer, mobile device, or other equipment when visiting websites. To enhance your browsing experience, the Boduel Website stores certain information (cookies) for tracking traffic and visitor characteristics, gathering information about preferences and behaviors, and collecting internal statistics to improve our services.
8.2. Types of Cookies
By Function:
- Technical (Necessary) Cookies – Essential for the website’s functioning (e.g., login, shopping cart). Blocking these may impact site functionality.
- Functional Cookies – Enable enhanced functionality and personalized content (e.g., remembering preferences, user interface adjustments).
- Statistical Cookies – Collect information on how visitors use the website (e.g., most visited pages, time spent, features used).
- Marketing Cookies – Used to track users and display targeted advertisements.
By Duration:
- Session Cookies – Temporary, deleted after closing the browser (e.g., shopping cart contents).
- Persistent Cookies – Remain stored after browser closure (e.g., login credentials).
By Source:
- First-party Cookies – Originating from the Boduel Website, can be persistent or temporary.
- Third-party Cookies – Coming from other websites (e.g., pop-ups, ads) displayed on the viewed website.
Cookies used on the Boduel Website
Name | Type | Usage | Cookie type and duration |
JSESSIONID | Nužni | Koristi se za održavanje sigurnosti sesije tijekom čitavog njezinog trajanja. | Kolačić prve strane, briše se nakon što ugasite pretraživač. |
LFR_SESSION_STATE_20120 | Nužni | Koristi se za održavanje sigurnosti sesije tijekom čitavog njezinog trajanja. | Kolačić prve strane, briše se nakon što ugasite pretraživač. |
SERVERID | Nužni | Koristi se za održavanje sigurnosti sesije tijekom čitavog njezinog trajanja. | Kolačić prve strane, briše se nakon što ugasite pretraživač. |
Social Media Plugins and Links
The Boduel Website uses social media plugins and/or links to social networks that process personal data in accordance with their own privacy policies. We recommend that you read the privacy policies of these social networks [Facebook, Instagram, Pinterest, TikTok ] to better understand how your personal data is being processed.
Consent for Cookies
All types of cookies, except for technical (necessary) cookies, are collected exclusively with your consent.
8.4. How to Disable Cookies?
You can change your cookie settings at any time via the following link [insert link].
Additionally, you can disable the storage of cookies on your computer through your internet browser settings. For information on managing cookie settings, please select the browser you are using: Chrome, Firefox, Internet Explorer 9, Internet Explorer 7 and 8, Opera (page in English), Safari (page in English).
Please note that disabling cookies may prevent you from using certain functionalities on the Boduel Website.
Some browsers allow you to browse websites in “private” or “incognito” mode, which limits the amount of data stored on your device and automatically deletes persistent cookies once you end your browsing session.
There are also numerous third-party applications you can add to your browser to block or manage cookies.
You can also delete previously stored cookies by selecting the option to clear your browsing history, making sure to include the deletion of cookies.
9. CHANGES TO THE PRIVACY POLICY AND COOKIE NOTICE
We regularly update our Privacy Policy to ensure its accuracy and relevance, and we reserve the right to change its content if deemed necessary.
You will be promptly informed of any changes or amendments via the Boduel Website, in accordance with the principle of transparency.