Privacy policy
Updated: 27 September 2026
This is a translation. The Croatian version of this policy (Zaštita osobnih podataka) is legally binding and prevails in case of any difference.
This policy explains which personal data Lignea design d.o.o. processes when you visit www.ligneadesign.hr, send an enquiry or order products, for what purposes and on what legal basis, how long we keep the data and what your rights are. It has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, "GDPR").
1. Controller
- Lignea design d.o.o., Roškići 12, 52464 Kaštelir, Croatia
- Personal identification number (OIB): 01135311299
- E-mail: info@ligneadesign.hr
- Phone: +385 98 134 5998
For any questions about the processing of personal data and to exercise your rights, contact us at info@ligneadesign.hr.
2. What data we process and why
2.1. Orders
The online shop is intended exclusively for business customers. When you order, we process the data you enter in the order form: the name of the company or sole trader, the OIB, the registered address and, if needed, a delivery address, the contact person's name, e-mail address and phone number, the products and quantities ordered, and your note.
- Purpose: processing and delivering the order, communicating about it, issuing the invoice and keeping business records.
- Legal basis: performance of a contract and steps taken at your request before entering into a contract (Article 6(1)(b) GDPR), and compliance with legal obligations, in particular accounting and tax obligations (Article 6(1)(c) GDPR).
- The data marked as required is necessary to conclude and perform the contract and to issue the invoice. Without it we cannot accept the order.
If an order is sent by an employee or another person on behalf of a business customer, we process the contact person's data to perform the contract with that business customer and on the basis of our legitimate interest in efficient business communication (Article 6(1)(f) GDPR).
2.2. Enquiries
When you send us an enquiry through the form on the Contact page or by e-mail, we process your name, company name (if given), e-mail address, phone number (if given), the subject and content of the message and, if the enquiry was started from a product page, that product's reference.
- Purpose: answering the enquiry and, if you ask for it, preparing a quotation.
- Legal basis: steps taken at your request before entering into a contract (Article 6(1)(b) GDPR), or our legitimate interest in answering enquiries (Article 6(1)(f) GDPR).
2.3. Visiting the website
On every visit the server automatically records technical data needed to deliver the website and keep it secure: IP address, date and time of access, the address requested, and the type of browser and device.
- Purpose: delivering the website, detecting and preventing misuse, and fixing errors.
- Legal basis: legitimate interest in the secure and proper operation of the website (Article 6(1)(f) GDPR).
2.4. Protecting the forms from misuse
The order and enquiry forms are protected by Cloudflare Turnstile, which is loaded only on those pages. Turnstile processes technical data about the device, the browser and the interaction with the page (including the IP address) to tell people apart from automated programs.
- Purpose: preventing spam, automated messages and fake orders.
- Legal basis: legitimate interest in the security of the forms (Article 6(1)(f) GDPR).
2.5. Visitor statistics
- Vercel Web Analytics counts visits and page views without cookies and without building visitor profiles. For each page view it records the page address, the referrer, the approximate location (country, region, city), the device type, operating system and browser, in aggregated statistics only. A visit is recognised by a temporary hash of the request that is not linked to your identity and is automatically reset after one day. The legal basis is our legitimate interest in understanding how the website is used (Article 6(1)(f) GDPR).
- Google Analytics 4 is used only if you accept it in the cookie settings banner. Google then sets analytics cookies and processes data about how the website is used (for example pages viewed, visit duration, device type and approximate location). Google Analytics 4 does not store IP addresses. The legal basis is your consent (Article 6(1)(a) GDPR), which you can withdraw at any time in the Cookie settings section or through the "Cookie settings" link in the page footer. Withdrawing consent does not affect the lawfulness of processing before the withdrawal.
3. Cookies and browser storage
The website does not use cookies of its own. It keeps necessary data in your browser's local storage (localStorage), and that data does not leave your device until you send an order:
| Name | Content | Purpose | Duration |
|---|---|---|---|
lignea-cart |
product references and quantities in the cart | cart | until you empty it or send the order |
lignea-consent |
your choice about analytics cookies and the date of the choice | remembering your choice | 12 months |
_ga, _ga_* (Google) |
a random browser identifier | Google Analytics 4, only with consent | up to 2 years |
Cloudflare Turnstile may temporarily use browser storage for the security check, only on the pages with forms.
4. Recipients and processors
We do not sell personal data or pass it to third parties for their marketing. To the extent necessary for the purposes above, the data is processed by the following recipients:
- Vercel – hosting and delivery of the website and visitor statistics (Vercel Web Analytics); the server functions that handle the forms run in Frankfurt (EU)
- Resend – sending order confirmation e-mails and notifications about orders and enquiries
- Microsoft (Microsoft 365) – our business e-mail, where orders and enquiries arrive
- Cloudflare – form protection (Turnstile)
- Google – Google Analytics 4, only with your consent
- courier services – name, delivery address and phone number, for delivery
- accounting services, banks and tax advisers – for bookkeeping, payments and legal compliance
- competent authorities – where we are legally obliged
Providers that process data on our behalf (processors) may process it only on our instructions and under contractual data protection obligations in accordance with Article 28 GDPR.
5. Transfers outside the European Economic Area
Some providers (Vercel, Resend, Cloudflare, Microsoft and Google) are based in, or may process data in, the United States of America. Such transfers are based on the European Commission's adequacy decision for the EU–US Data Privacy Framework, for providers certified under it, or on the standard contractual clauses adopted by the European Commission, with supplementary safeguards.
6. How long we keep data
- Orders: for the duration of the business relationship and afterwards for as long as necessary to establish, exercise or defend legal claims. Invoices and accounting documents are kept for as long as accounting and tax regulations require, generally 11 years.
- Enquiries: until the enquiry is resolved and for no longer than two years after the last communication, unless the enquiry leads to a contract, in which case the periods for orders apply.
- Server logs: briefly, according to the hosting provider's settings, generally a few days.
- Google Analytics 4: no longer than 14 months, according to the data retention settings.
- Data in your browser: as described in section 3. You can delete it at any time in your browser settings.
7. Your rights
Under the GDPR you have the right:
- to access your personal data
- to have inaccurate or incomplete data corrected
- to have data erased, unless there is a legal obligation or another legitimate reason to keep it
- to restrict processing
- to data portability for data you gave us on the basis of a contract or consent
- to object to processing based on legitimate interest
- to withdraw your consent at any time, without affecting the lawfulness of processing before the withdrawal
Send your request to info@ligneadesign.hr. We will respond without undue delay and at the latest within one month. To protect your data, we may ask you to confirm your identity.
If you believe that the processing of your data does not comply with the regulations, you can lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), www.azop.hr.
8. Automated decision-making
We do not make decisions based solely on automated processing, including profiling, that would produce legal or similarly significant effects for you.
9. Security
The website uses an encrypted connection (HTTPS). Data can be accessed only by people who need it for their work, and we choose service providers that guarantee an appropriate level of protection. No data transmission over the internet can be completely secure, but we take reasonable technical and organisational protective measures.
10. Changes
We may change this policy when the regulations or the way we process data change. The current version is always published on this page, with the date of the last change.
