PRIVACY AND PERSONAL DATA PROTECTION POLICY
This policy ensures an adequate level of data protection in accordance with the Regulation (EU) on the protection of individuals with regard to the processing of personal data and on the free movement of such data (hereinafter: the Regulation) and other applicable laws related to the protection of personal data.
In accordance with the Regulation, we have harmonized our business activities related to the processing and protection of personal data, and as regulated by this Privacy and Personal Data Protection Policy (hereinafter: the Policy).
The controller for the processing of your personal data is &Andrea Solomun, sole proprietorship for marketing, consultation, artistic and creative work, Dominika Mandića 23, 10000 Zagreb (hereinafter: &Andrea). &Andrea includes the website point of sale https://andreasolomun.com.
&Andrea undertakes to provide protection to customers’ personal data, in such a way that it collects only necessary, basic data about customers / users that are necessary for the fulfillment of our obligations; informs customers about the way the collected data is used, regularly gives customers / users the option of choosing about the use of their data, including the option of deciding whether or not they want their name removed from lists used for marketing campaigns. All user data is strictly kept and is only available to employees who need this data to perform their work. All employees of &Andrea and business partners are responsible for respecting the principles of privacy protection
&Andrea processes the personal data that you have provided by filling out an order/purchase of certain programs and content on the website andreasolomun.com, which we need to open a user account and enable subscriber and other rights in accordance with the General Terms and Conditions and the Subscription Agreement in accordance with the provisions of this Policy.
This Policy is a fundamental act aimed at establishing a framework for the protection of personal data in accordance with the Regulation. This Policy applies to the processing of personal data that we perform in accordance with the activities of &Andrea, the provisions of the Regulation and applies to all processing of personal data within &Andrea. The aim of the Policy is to establish appropriate processes for the protection of data subjects’ personal data management.
Personal data are considered to be all data relating to an individual whose identity has been established or can be established (data subject).
Data subject is a natural person who can be identified directly or indirectly, in particular by means of identifiers such as name, PIN, location data, network identifier or by one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that individual.
Since we collect personal data directly from you, our users, in the following text we want to provide you with all the information about why we process your personal data that you provided when joining the association.
The policy applies to all personal data of members that &Andrea collects, uses or otherwise processes. Personal data is any data relating to a natural person whose identity has been or can be established, directly or indirectly (hereinafter: data or personal data). Data processing is any action performed on personal data, such as the collection, recording, storage, use, transfer of personal data and access to personal data.
1.1 Controller for the processing of personal data
The controller for the processing of personal data is &Andrea Solomun, sole proprietorship for marketing, consultation, artistic and creative work, Dominika Mandića 23, 10000 Zagreb, telephone: + 385 98 1637 627 e-mail: info@&andreasolomun.com.
The address of this website is https://andreasolomun.com.
1.2 Personal data
As a controller, we are aware of the importance of personal data for each individual and therefore it is extremely important for us to comply with applicable regulations. This is why we continuously work to maintain and improve the safety of your personal data and your privacy.
To understand data processing information, it is necessary to understand basic concepts such as personal data and data processing.
Personal data is any data or combination thereof which establishes the identity of a natural person or by means of which an individual can be identified, such as, for example, first name, surname, personal identification number, address, location, photograph, employment data, etc.
Data processing is any operation involving personal data such as collection, recording, structuring, storage, alteration, consultation, use, transmission and erasure.
&Andrea processes your personal data in accordance with the following processing principles:
- lawfulness, fairness and transparency of processing means that processing must comply with a specific legal basis and the principles of fair and transparent processing require that the individual is informed of the processing operation and its purposes;
- purpose limitation means that the data should be collected for specified, explicit and legitimate purposes and not further processed in a way that is incompatible with those purposes;
- data minimisation means that the data must be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
- accuracy means that data must be accurate and up to date, every reasonable step must be taken to ensure that personal data which are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;
- storage limitation means that the data must be kept in a form which permits identification of data subjects only for as long as necessary for the purposes for which the personal data are processed;
- integrity and confidentiality mean that the data must be processed in a manner that ensures an appropriate level of security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage;
- reliability means that &Andrea is the person responsible for adhering to the principles and that the burden of proof is on the controller.
In its work, &Andrea collects personal data for the purpose of concluding and achieving business objectives as well as for fulfilling obligations determined by law and other regulations, and the realization of a subscription with &Andrea is not possible without collecting and processing mandatory and business-related data. In addition, based on your explicit consent, &Andrea processes your data in order to provide the highest quality service.
3.1 Mandatory data
The purpose of processing your personal data is to use the andreasolomun.com website and to ensure and provide a subscription service in accordance with the General Terms and Conditions.
The personal data that &Andrea collects from you are: name and surname, address, e-mail address, subscription start and finish date.
3.2 Business-related data
Business-related data are those required to enter into and/or provide a subscription service and depend on the &Andrea program used.
Business-related data can also be contact information if it is needed for the implementation of a particular program (for example, e-mail address, mobile phone number for sending SMS messages with notifications, etc.)
Business-related data collected by &Andrea are: e-mail address, telephone number, program status, subscription program.
3.3 Contact data
Contact data are voluntarily provided and used so that &Andrea can inform you in the fastest and simplest way about facts and events relevant to the program/workshop you are interested in or use and provide information/documentation at your request.
In accordance with the purpose of processing &Andrea will process your personal data exclusively for:
- checking the subscription;
- checking the obligation of subscription payment;
- checking the accuracy and correctness, i.e., updating of personal data;
- telephone, SMS and/or e-mail communication with the user.
In addition, we will process your personal data for the purpose of sending notifications to your e-mail address that &Andrea may send about news, workshops, events, projects, activities, consultations, surveys and membership fees, new programs, etc. which is carried out for the purpose of achieving business objectives.
You decide which personal data to provide when purchasing a subscription, but by refusing to provide the information required to conclude a subscription agreement, you cannot enter into a subscription relationship. By providing complete information and consent to receive our notifications via e-mail, SMS and/or by telephone, we provide you with timely, accurate and relevant information about the status and content of your subscription and the maintenance of our programs.
In any case and at any time, you can revoke the given consent, send a request for restriction of processing, or any similar objection to which you are entitled in accordance with the Regulation, and we will act on your request.
Consent is any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her. You give your consent by hand signing the registration/application form. You can withdraw your consent by means of an appropriate notification to our e-mail address. The withdrawal of consent shall not affect the lawfulness of the processing based on consent before its withdrawal.
A processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of and at the direction of the controller.
&Andrea will carefully and cautiously store and preserve all your personal data you have provided to us and will not transmit it to any other person, except for the external data processor with whom Andrea has a signed Accounting Services Contract. We have concluded a contract with this partner providing for appropriate technical and organisational measures to protect your personal data, the obligation to process them only to the extent necessary for them to perform their accounting tasks and in accordance with the Regulation and our instructions; the contract includes an obligation to preserve their confidentiality, as well as a prohibition on using your personal data for purposes other than those specified in the relevant contract.
&Andrea does not transfer and will not transfer personal data to a third country or to an international organisation, or to any other third party
The competent authorities of the Republic of Croatia, as laid down by law, have the right to consult your personal data in the cases prescribed by law.
We will keep your personal data for the time necessary to achieve the relevant purposes described, i.e., for as long as you wish to remain in contact with us and for as long as you wish to receive our notifications in accordance with the consent given to us when accessing any of the subscription packages, i.e., until you withdraw your consent for specific purposes.
If and when we receive your request for deletion of data, revocation of consent, request for restriction of the processing of your personal data, or any similar objection, we will act immediately on your request and the storage of the personal data within a specified period will be the only way to process them before they are permanently deleted.
You can exercise these rights by sending a written request to firstname.lastname@example.org.
Protection and safety of your personal data is our task and priority. For this reason, we process your personal data in accordance with the Regulation, subject to appropriate technical and organisational safeguards to prevent unauthorised access, misuse, disclosure, loss or destruction of personal data. The data shall be preserved by means of an access password. The computer and server hosting your personal data are protected by appropriate firewalls and security programs.
&Andrea processes your personal data in accordance with your rights as defined under the Regulation. We are aware that your personal data is your property and you can always request and exercise the following rights at any time:
- The right to erasure (“right to be forgotten”) by which you can request the deletion of your personal data from the Association register:
- if they are no longer necessary in relation to the purpose of the collection;
- if you withdraw your consent and there is no other legal basis for data processing;
- if the personal data have been unlawfully processed;
- if they have to be deleted in order to comply with a legal obligation under applicable law.
- the right of access to data to which you have the right to obtain from the Association information relating to the collection and processing of your personal data, i.e., the right to obtain confirmation from us whether or not personal data concerning you are being processed and, if such personal data are processed, access to your personal data, including the right to obtain a copy of the personal data being processed.
- the right to correct or supplement any inaccurate personal data that entitles you to obtain from the Association without undue delay the rectification of inaccurate personal data concerning you;
- the right to restrict processing in the following cases:
- if you dispute the accuracy of your personal data, for a period allowing us to verify the accuracy of your personal data;
- if the processing is unlawful but you object to the deletion of your personal data and instead ask for their use to be restricted;
- if we no longer need personal data for processing purposes, but you want them in order to realize, exercise or defend legal claims;
- the right to object at any time to the processing of your personal data processed on the grounds of the controller’s legitimate grounds or interests.
You may request the exercise of any of the above rights at any time by sending an e-mail to email@example.com. &Andrea will provide a written reply by e-mail within 30 days of receipt of the request, up to a maximum extension of 30 days when necessary, to any requests concerning actions taken in relation to these rights.
If you have an account on this website, you can request to receive the export personal data file we have about you, including all the information you provided to us. You can also request a deletion of all personal data we have about you. This does not include data we have the obligation to keep for administrative, legal or safety purposes.
If, for any reason, you believe that &Andrea did not respect this Policy, please notify us by sending an e-mail to the above-stated e-mail address.
It, at any point, you wish to withdraw your consent for receiving notifications to your e-mail address, you can do it by sending a request to firstname.lastname@example.org.
The complaint related to the processing of personal data shall be submitted to the supervisory body: Agencija za zaštitu osobnih podataka, Martićeva 14, Zagreb.
Websites to which this policy applies
This Policy applies also to all services and subpages available within the andreasolomun.com domain. By visiting this website, you give your consent for the current and future terms of this policy which relate to these websites. If you do not wish to accept these terms, you should leave the website.
7.1 Types of data collected on the website
There are two types of data being collected on the website – data that identify you personally and data which are not related to you personally.
7.2 Data that identify you personally
Data that identify you personally (“personal data”) are data which identify you as a person sending the inquiry or payment for a certain program, such as your name and surname, e-mail address, telephone and the like. Personal data are obtained only during the registration process when you are providing that data voluntarily. This data is used in accordance with this policy. For example, you can be prompted to voluntarily state your e-mail address in communication with us.
After you state your personal data, you can be sure that they shall be used exclusively as a support to our relationship with you. We take your trust very seriously and we shall not share, sell or lease your personal data to other parties.
7.3 Data which are not related to you personally
Data which are not related to you personally (“non-personal data”) are data which do not identify you as an individual, such as type of browser, IP address, URL of the previous website you visited etc. When you are using the website andreasolomun.com, we can collect non-personal data which you voluntarily provide, such as information included in the response in some questionnaire or survey.
7.4 Data related to subscription payment and other purchases
&Andrea does not collect or process data necessary for payment. This data is collected and processed by the PayPal platform you are using to pay for our programs. All privacy and personal data protection policies related to this can be found on PayPal websites.
7.5 Purpose of data collection
The primary purpose of personal data collection on the website andreasolomun.com is to enable the services suited to your needs or requests. We collect only the data we consider necessary for achieving this purpose and which are described in this policy.
7.6 Means of data collection
We collect data when you give them to us or via web technologies.
7.7 Data collected from you
If you choose to send a query / application form on our website, we will ask you to enter basic identification and contact data. When possible, we state (non)mandatory fields. If you choose not to use our programs, you do not have to enter contact or identification data requested.
7.8 Data which are not related to you personally and which are collected using technology
Cookies and other tracking technologies
Information collected by these cookies help us understand how our users use the website in order to improve content quality and browsing experience. Optional cookies include Google Analytics cookies (cookies that track the visits and analyse the website performance, which are available to &Andrea as statistical data, without personal data of individual users) and social media cookies (e.g. Facebook) which enable the user to share certain content via their personal social media account,
When you access the website for the first time, you will see a message notifying you about the existence of cookies and requesting your consent for their acceptance.
Using web browser settings, the website user can at any time regulate (restrict or disable) the user of cookies. Please note that the disabling of cookies can affect the functionality and your interaction with the website, and we disclaim any responsibility for any loss of website functionality and/or content quality if the user chooses to regulate cookies.
Additional information about configuring browser cookies settings can be found on the following websites:
- find out more about private browsing and cookies settings in Firefox here
- more information about anonymous browsing and cookies settings in Google Chrome can be found here
- information about “InPrivate” mode and cookies settings in Internet Explorer are available at this link
- find information about “Private navigation” and cookies settings in Safari here
Anonymization of IP addresses
On this website, we use the “activate IP anonymization” function. As a result, Google will shorten your IP address in advance in member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, compile reports on website activity and provide other services related to website activity and internet usage to the user of the website. The IP address assigned by Google Analytics as part of Google Analytics will not be combined with other Google data.
Use of the Google Analytics service
This website uses the functions of the Google Tag Manager, Google Font, Google Analytics 4 services for the purpose of web analysis. The provider is Google Inc., 1600 Amphitheater Parkway Mountain View, CA 94043, USA.
When you visit this website, cookies are used to generate data that Google collects and processes. You can prevent this by downloading and installing the browser plug-in available at the following link:https://support.google.com/analytics/answer/6004245?hl=hr
How to accept or reject cookies
You can always block the use of some or all of the cookies we use on our website, but this may affect its functionality.
The cookie settings box is located on the Cookie Settings cookie notification. After selecting the settings, you can reset the settings at any time.
Additionally, you can accept or reject some or all cookies by adjusting your browser settings. The following links provide information on how to change settings for some of the most commonly used web browsers: Mozilla Firefox, Google Chrome, Microsoft Internet Explorer, Apple Safari, Opera. Some browsers allow you to surf in “anonymous” mode, limiting the amount of data placed on your computer and automatically deleting persistent cookies placed on your device when you end your browsing session. There are also many third-party applications that you can add to your browser to block or manage cookies. You can also delete cookies that were previously placed in your browser by selecting the option to delete browsing history and turning on the option to delete cookies. You can find more detailed information about cookies and adjusting your browser settings on the page www.allaboutcookies.org.
Persons we share data with
We take your trust in us seriously and we shall not in any case share, sell or lease your personal data to other parties.
&Andrea websites may contain links to pages maintained by third parties whose information and privacy policies are different from ours. We are not responsible for information or rules for personal data protection and privacy applied by third parties. We recommend that you read rules for personal data protection and privacy on all websites of third parties before visiting or submitting any personal data or other data on these websites.
Please remember that, if you are visiting other websites, including the websites of our partners, advertisers, dealers or other websites connected to our website, these other websites may collect personal and non-personal data on you. Practices regarding data on these other websites are not included in this Policy. We have no obligation or responsibility for these websites or their own policies.
Disclosure of personal data for legal purposes and protection of &Andrea and other websites: &Andrea reserves the right to share your personal data with third parties if &Andrea believes this is necessary in the following cases:
- to satisfy legal requirements or respond to any request by competent authorities in charge of implementing laws related to criminal investigation, i.e., by state or administrative authorities in relation to an ongoing civil procedure or administrative inquiry;
- when we have reasons to believe that the disclosure of this data is necessary for the identification, contact or taking measures against a person causing injury to you, or in any other way by violating or interfering with the rights, ownership or business of &Andrea and other users of our websites or any other persons that may suffer damage caused by these activities;
- protection or defending of our legal rights and ownership, of &Andrea, of our users, and
- investigation, prevention and taking measures in relation to illegal activities, possible fraud, situations which include potential threats to physical safety of a person or violation of &Andrea terms and provisions.
Embedded content from other websites
Articles on this website may contain embedded content (e.g., videos, photos, articles etc.). Embedded content from other websites acts as though the visitor visited this other website.
7.9 Your rights and exceptions
You may at any point and free of charge request information about your personal data we stored and ask for information on the type of your personal data we have, as well as the modification and/or deletion of your data, except for those that are related to the invoicing the services you subscribed to or whose storage is prescribed by law.
You can also request a correction or deletion of any incorrect data in the same way, as well as contact us for any additional clarifications regarding this Policy. You can request the correction or deletion of your personal data in writing.
&Andrea will contact you only if you allow it to.
If you choose to receive newsletter via e-mail, &Andrea may periodically send you e-mails describing content updates, new options or promotional offers related to the website and &Andrea program. You can unsubscribe from these messages at any time. Just follow the instructions in the message you received or send a response containing your request, and we will implement the requested changes.
Unless you explicitly choose to receive such informational messages, the only e-mails you will receive from &Andrea will be the notifications necessary for the delivery of a service/product you bought and responses to e-mails you sent to us.
7.10 Privacy and protection of children’s data
&Andrea services are not intended for children and we do not collect any data related to children. We advise parents and guardians to familiarize themselves with websites their children are visiting.
7.11 Safety of your data
The safety of your personal data is very important to us and we are committed to protecting the data we collect. Our facilities have protection measures against loss, misuse and modification of data we collected from you on our website.
Unfortunately, no data transfer via the Internet or any other wireless network cannot be a hundred percent safe. Because of this, although we take all measures to protect your personal data, &Andrea cannot ensure or guarantee the safety of data you transfer to us, so you are transferring that data at your own risk.
7.12 Accepting the Policy
By visiting the &Andrea website, as well as by submitting inquiries, purchasing a subscription or other service/product or by registering, you accept terms and conditions of this Policy for the part related to our websites, and &Andrea has the right to use your data as described here. We reserve the right to modify this Policy at any time and in accordance with applicable regulations. If you continue to use the website andreasolomun.com after being notified of such changes either personally or by publishing them on our website, this shall mean that you accept these changes.
If, for any reason, you believe that &Andrea did not respect this Policy, please notify us by sending an e-mail to the below-stated e-mail address.
Please note that, every time you provide us with any data related to any of the services connected to &Andrea, you are giving your consent for the processing of this data to the extent necessary for the provision of services in which you are participating or wish to participate in.
If you have any questions or comments about this Policy and/or the way it affects you, please do not hesitate to contact us
- by sending an e-mail request to email@example.com.
&Andrea may from time to time change or supplement this Policy. For the purpose of keeping you informed about the changes to this Policy, please note that the last revision was done in May 2022. The changes to this Policy will not affect our use of previously acquired personal data and obligations covered by this Policy.
In force as of 10 August 2022