Privacy Policy

This Privacy Policy applies to Wehr, our iOS and Android mobile application (our “App”). In the below policy, we inform you about the scope of the processing of your Personal Data.

General Information

a) What law applies?

In principle, we will only use your personal data in accordance with the applicable data protection laws, in particular Croatia`s Act on Implementation of the General Data Protection Regulation (“AIGDPR”) and the EU counterpart the General Data Protection Regulation (“GDPR”).

b) What is Personal Data?

Personal Data is any information relating to personal or material circumstances that relates to an identified or identifiable individual. This includes, for example, your name, date of birth, e-mail address, postal address, or telephone number as well as online identifiers such as your IP address and device ID.

c) What is Special Category Data?

Special category data is Personal Data that needs more protection because it is sensitive. This includes Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data. As well as, data concerning health, a person’s sex life; and a person’s sexual orientation. In order to lawfully process Special Category Data, it is necessary to consent to the processing.

d) What is processing?

"Processing" means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means. The term is broad and covers virtually any handling of data.

e) Responsible for data processing

The responsible party within the meaning of the AIGDPR and the GDPR is Konfeks d.o.o. of Vlaška ul. 40, 10000, Zagreb, Croatia.

If you have any questions or if you wish to exercise your rights, please feel free to email info@konfeks.hr, call +00385 1 4814 226 or write to us at the above address.

f) The Legal Bases for processing Personal Data

In accordance with the the AIGDPR and the GDPR, we have to have at least one of the following legal bases to process your Personal Data: i) you have given your consent, ii) the data is necessary for the fulfillment of a contract / pre-contractual measures, iii) the data is necessary for the fulfillment of a legal obligation, or iv) the data is necessary to protect our legitimate interests, provided that your interests are not overridden.

Processing of Automatically Collected Data

a) Downloading the App

The App can be downloaded from the "Google Playstore" a service offered by Google LLC, or the Apple "App Store" a service of Apple Inc. Downloading it may require prior registration with the respective App store and/or installation of the respective App store software.

b) Installing the App

As far as we are aware, Google collects and processes the following data: License check, network access, network connection, WLAN connections, and location information. However, it cannot be ruled out that Google also transmits the information to a server in a third country. We cannot influence which personal data Google processes with your registration and the provision of downloads in the respective App store and App store software. The responsible party in this respect is solely Google as the operator of the Google Play Store.

As far as we are aware, Apple collects and processes the following data: device identifiers, IP addresses, location information, it cannot be excluded that Apple also transmits the information to a server in a third country. We cannot influence which personal data Apple processes with your registration and the provision of downloads in the respective app store and app store software. The responsible party in this respect is solely Apple as the operator of the Apple App Store.

c) Device information

Google and Apple may collect information from and about the device(s) you use to access the App, including hardware and software information such as IP address, device ID and type, device-specific and App settings and properties, App crashes, advertising IDs (AAID), information about your wireless and mobile network connection such as your service provider and signal strength; information about device sensors such as accelerometer, gyroscope, and compass.

d) Authorizations and Access

We may request permission to access your Geolocation (Coarse location), your Internet Connection and Network your Gallery and Media Storage. The legal basis for data processing is our legitimate interest and the provision of contractual or pre-contractual measures. You can deny access on your device via the Settings/Notifications/ options of your device; however, this means that our App may not function as intended.

e) Push messages

When you use our App, you will receive so-called push messages from us, even if you are not currently using our App. These are messages that we send you as part of the performance of the contract. You can adjust or stop receiving push messages at any time via the device settings of your device. Insofar as you consent to the use of push messages, consent is the legal basis for the processing.

Data processing by us

a) Contacting us

Personal Data is processed depending on the contact method. In addition to your name and email address, IP address or telephone number, we usually collect the context of your message which may also include certain Personal Data. The Personal Data collected when contacting us is processed for the purpose of dealing with your request and the legal basis is your consent. The use of your IP address takes place exclusively in the context of law enforcement and security measures in compliance with our legal requirements.

b) Account Registration

If you register, we will request mandatory and, where applicable, non-mandatory data in accordance with our registration form (Username Full Name, Email Address, Bio, Profile Picture). The entry of your data is encrypted so that third parties cannot read your data when it is entered. The basis for this storage is our legitimate interest and to fulfill our contractual obligations.Of course you can delete your account at any time using the Delete Account Feature in our App.

Alternatively, you are able to sign up using the convenience login and sign up from Google or Apple. For convenience log in and sign up, you will be asked to provide your basic information (i.e., name, email address, and display picture) linked to your account. When registering via convenience functions, you agree to the relevant terms and conditions and consent to certain data from your respective profile being transferred to us.

c) When using our services

We process the data of our registered users in order to be able to provide our contractual services as well as to ensure the security of our services and to be able to develop it further. This includes in particular our support, correspondence with you, invoicing, fulfillment of our accounting and tax obligations. Accordingly, the data is processed on the basis of fulfilling our contractual obligations as well as to fulfill our legal obligations.

d) When using our event listing services

If you wish to use our event listing services and its features, we process the Personal Data you voluntarily provide for the purpose of providing our event listing services. Depending on how you use our event listing services, you may provide images, contact information, company information, location data, search events and places near you, etc. and/or upload content such as text, photographs etc. or add and/or remove individual event managers. This content will be made public and may be viewed and otherwise accessed by others.

Special Category Data

Some of the Personal Data you provide may be considered “special” or “sensitive”. This includes Personal Data concerning for example your health, racial or ethnic origins, sexual orientation, and religious beliefs. By choosing to provide this data, you consent to our processing of that data. You have choices about the data you provide and how you share it. You don’t have to provide Personal Data or Special Category Data; however, information about you helps you to get more from our Services. It’s your choice whether to include Personal Data or Special Category Data and to make that information available to us. Please do not share information that you would not want to be available. The legal basis for the processing of your Personal Data and Special Category Data is the establishment and implementation of the user contract for the use of the service as well as your consent.

Personal Data of a third party

Where any Personal Data relates to a third party, you represent and warrant that the Personal Data is up-to-date, complete, and accurate and that you have obtained the third party’s prior consent for our collection, use and disclosure of their Personal Data for the Purposes. You agree that you shall promptly provide us with written evidence of such consent upon demand by us.

Facial-related information

In providing our event listing services including providing you teh function to add an event manager, we may derive facial-related information from your content solely for the purpose of providing our event listing services. We do not collect, use, or store any facial-related information for the purpose of recognising faces outside of this purpose.

Sharing with others

Of course, we also process the content you publish and share with others, as necessary for the operation of our event listing services. In addition to the information, you may provide us directly, we receive information about you from others. Users may provide information about you as they use our event listing services, for instance as they interact with you or if they submit a report involving you.

We also share some users’ information with service providers and partners who assist us in operating our event listing services. You share information with other users when you voluntarily disclose information on the service. Please be careful with your information and make sure that the content you share is stuff that you’re comfortable being visible.

Event Organizers

Please note when using our event listing services, you become the data controller and we become the data processor in accordance with the AIGDPR and the GDPR. As such we process your Personal Data as a data intermediary on your behalf and in accordance with your instructions and shall use it only for the purposes agreed between you and us.

Further, please be advised that some jurisdictions may require you to disclose your use of our services as your processor in your privacy policy and/or data processing agreement as applicable.

We ensure that access by our employees to your data is only available on a need-to-know basis, restricted to specific individuals, and is logged and audited. We communicate our privacy and security guidelines to our employees and enforce privacy and protection safeguards strictly.

The legal basis for the data processing is the fulfillment of our contractual obligations and, in individual cases, the fulfillment of our legal obligations as well as your consent.

e) Data management and technical support

If you create a support ticket, we will request personal and, where applicable, non- personal data in accordance with your request, this may include your name, email address and other order related data you voluntarily provide. The data provided is not shared with third parties and cannot read your data when it is entered. If you submit a support ticket, we process the data for the purpose of processing and handling your ticket. The legal basis of the data processing is our obligation to fulfill the contract and/or our legitimate interest in processing your support ticket. You can delete data provided at any time in the ticket or by contacting us.

f) Data processing in the context of bookings and reservations

The protection of your Personal Data is particularly important to us in the context of bookings and reservations. We therefore only want to process as much Personal Data (e-mail address) as is absolutely necessary and to that extent we provide a QR code system. Nevertheless, we rely on the processing of certain Personal Data and the event and booking details, to fulfill our contractual obligations and in the context of administrative tasks in relation to the event, your registration and the booking.

Provided that you consent to the sharing by using your QR code, we transmit your Booking and/or Reservation Details to the selected Event Organizer. In this way, we can ensure that your Booking and/or Reservation is verified and that the selected Event Organizer is aware of your Booking and/or Reservation. With the QR code exchange, you can also disclose your location. This in turn however may also reveal data that centers on your personal interests and may possibly reveal sensitive information. Accordingly, the processing of location data is limited to the strict needs of allowing you to claim your Booking and/or Reservation and is solely based on your consent. We and the selected Event Organizer involved in the process, are particularly vigilant not to collect Personal Data except if doing so is absolutely necessary for the purpose of processing. The legal basis for providing the QR code is the fulfillment of our contractual obligations and the fulfillment of our legal obligations. For sharing your Booking and/or Reservation Details or location through the QR code, the legal basis is your consent.

g) Payment Data

If you make a payment, your payment will be processed via the payment service provider Stripe and payment will solely be processed through the payment system of Stripe. The legal basis for the provision of a payment system is the establishment and implementation of the user contract for the use of the service.

General Principles

a) Minors

Persons under the age of 18 should not transmit any Personal Data to us without the consent of their parents or legal guardians. We do not request Personal Data from minors and children and do not knowingly collect such data or pass it on to third parties.

b) Automated decision-making

Automated decision-making including profiling does not take place.

c) Do Not Sell

We do not sell your Personal Data.

d) Sharing

We will not disclose or otherwise distribute your Personal Data to third parties unless this is a) necessary for the performance of our services, b) you have consented to the disclosure, c) or the disclosure of data is permitted by relevant legal provisions. In addition, we may disclose your Personal Data: in connection with law enforcement, fraud prevention or other legal proceedings; as required by law or regulation; if Konfeks or Wehr (or a part of Konfeks or Wehr ) is sold to or merged with another company; or if we have reason to believe that disclosure is necessary to protect Konfeks or Wehr.

e) International Transfer

Our main operations are based in Croatia and your Personal Data is generally processed, stored and used within the EU. We take steps to ensure there is an appropriate level of security, so your Personal Data is protected in the same way as if it was being used within Croatia. Where we need to transfer your data outside Croatia and EEA, we will use approved standard contractual clauses in contracts for the transfer of personal data to third countries.

f) Data Security

Our data processing is subject to the principle that we only process the Personal Data that is necessary for the use of our services. In doing so, we take great care to ensure that your privacy and the confidentiality of all Personal Data are always guaranteed.

Nonetheless, databases or data sets that include Personal Data may be breached inadvertently or through wrongful intrusion. Upon becoming aware of a data breach, we will notify all affected individuals whose Personal Data may have been compromised, and the notice will be accompanied by a description of the action being taken to reconcile any damage as a result of the data breach. Notices will be provided as expeditiously as possible after which the breach was discovered.

Your Rights and Privileges

a) Privacy rights

You can exercise the following rights:

If you wish to exercise any of your rights, please contact us.

b) Updating your information

If you believe that the information we hold about you is inaccurate or that we are no longer entitled to use it and want to request its rectification, deletion, or object to its processing, please do so by contacting us.

c) Withdrawing your consent

You can revoke consents you have given at any time by contacting us. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

d) Access Request

In the event that you wish to make a Data Subject Access Request, you may inform us in writing of the same. We will respond to requests regarding access and correction as soon as reasonably possible. Should we not be able to respond to your request within thirty (30) days after receiving your request, we will inform you in writing within thirty (30) days of the time by which we will be able to respond to your request. If we are unable to provide you with any Personal Data or to make a correction requested by you, we shall generally inform you of the reasons why we are unable to do so (except where we are not required to do so under the respective legal regulations mentioned above).

e) Complaint to a supervisory authority

You have the right to complain about our processing of Personal Data to a supervisory authority responsible for data protection. The competent data protection authority in Croatia is: Agencija za zaštitu osobnih podataka (Personal Data Protection Agency), Selska cesta 136 HR - 10 000 Zagreb www.azop.hr However, we would appreciate the opportunity to address your concerns before you contact the Personal Data Protection Agency.

Changes

We may update this policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal or regulatory reasons.

Contact us

For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us using email info@konfeks.hr, call +00385 1 4814 226 or write to us at the above address.

Effective Date

Friday, 6th of October, 2023