Privacy policy
DUPLIĆ STRUKIĆ ŠARIĆ Law Firm GP (“DSS”) as the data controller gives great importance to your privacy and has fully implemented European Parliament General Data Protection Regulation (GDPR).
This Privacy Policy explains in detail what types of personal data we collect and/or process, the reasons for such processing, how we use such data, with whom we share your personal data, how we store and safeguard it, and what rights you have in relation to the protection of your personal data.
This Privacy Policy shall apply as of 7 November 2025 and is available on our website at https://dss-law.hr. Any future amendments to this Privacy Policy shall also be published there.
The controller responsible for data processing is:
DUPLIĆ STRUKIĆ ŠARIĆ Law Firm GP
Zagreb, Froudeova ulica 1
mobitel: +385912531416
e-mail: office@dss-law.hr
web: https://dss-law.hr
-
Personal data we collect about you
Personal data is defined as any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
You may provide us with your personal data yourself, for example when you contact us in any way, either by telephone, email or by regular mail, or by our website and when you talk to our personnel in person or fill in our documents (such as powers of attorney).
Types of personal data we collect about you include:
-
basic personal details such as name and surname, residential address, date, place and country of birth, gender, personal identification number (OIB), citizenship, the name and number of an identification document (identity card, passport), as well as the data contained in such documents;
-
contact details such as the mailing address, contact telephone number and mobile phone number, and e-mail address;
-
additional data for the purpose of providing legal services, depending on the requirements of a specific case.
-
Why we collect your personal data and what is the legal basis for that
We collect your personal data where necessary for the exercise of your rights or for the purposes of our business, i.e. the provision of legal services, as well as for the fulfilment of our legal obligations.
Your personal data is exclusively processed based on:
Fulfilment of the Contract. We use personal data in processing activities in order to fulfil our contractual obligations.
Consent. On the basis of consent, we process personal data strictly to the extent and for the purposes for which you have given your consent. Consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
Legitimate Interest. Certain categories of your personal data, as previously listed, are collected on the basis of our legitimate interest. In cases where processing is based on legitimate interest, we have, where possible, carried out a prior assessment of your interests.
Legal basis. We process personal data for the purpose of complying with a legal obligation, in accordance with the law and within the scope prescribed by law.
DSS does not use any automated decision-making or profiling.
-
Who we share your personal data with
Access to your personal data is granted only to those of our employees or other persons for whom such access is necessary in order to provide you with the services you have requested. Our employees are regularly trained on the importance of data confidentiality and on maintaining the privacy and security of your personal data.
The transfer of personal data to third parties is carried out subject to the consent of the data subject, in cases of a legal obligation, or where an exception applies in circumstances where such transfer is necessary for the protection of the data subject’s interests. Personal data are not transferred outside the European Economic Area.
Such third parties may include, inter alia, legislative, supervisory and regulatory authorities within and outside the territory of the Republic of Croatia; third-party service providers acting on our behalf or with whom we cooperate (we work with carefully selected third parties, such as IT service providers, accountants, translators, notaries public, etc.); and partners with whom we have concluded a business cooperation agreement or a similar agreement, provided that the relevant purpose and processing are lawful and that personal data are processed in accordance with the instructions of the data controller and on the basis of a valid legal ground.
DSS does not sell your personal data nor does it lease or rent them.
-
How long will we keep your personal data
We keep your personal data only for as long as is necessary to fulfil the purpose for which they were collected.
With regard to your personal data used for the performance of any contractual rights and/or obligations with you, we may keep such personal data until you or we have fully performed those obligations, allowing for a reasonable period thereafter to update our records and any public or statutory registers.
With regard to any personal data that we reasonably believe may be necessary for the establishment, exercise and/or defence of legal claims against you, we may retain such personal data for as long as a claim may be brought under the applicable law or as otherwise required in such judicial proceedings, also taking into account the general limitation period (5/3 years) and the limitation period for claims established by a final and binding decision of a court or other competent public authority (10 years).
With regard to any personal data used for compliance with legal, tax, audit or similar data retention requirements, we will not store or use such personal data for longer than is required under the applicable specific retention obligations.
-
Your rights
In the event of the processing of personal data, you have the following rights:
-
Right to be informed, i.e. you have the right to obtain information about the personal data collected about you;
-
Right of access, which includes, inter alia, your right to obtain confirmation as to whether or not personal data concerning you are being processed and, where that is the case, access to the personal data;
-
Right to rectification. You have the right to obtain the rectification of inaccurate personal data concerning you;
-
Right to erasure (“right to be forgotten”). Subject to certain conditions, you have the right to obtain the erasure of personal data concerning you, for example where you withdraw your consent. We will not be able to erase your personal data where such data are necessary for compliance with legal obligations, the performance of contractual obligations, or other lawful bases under the General Data Protection Regulation;
-
Right to restriction of processing. This right arises, inter alia, where the processing of personal data is unlawful or, temporarily, where you contest the accuracy of the personal data;
-
Right to data portability, meaning that, in certain circumstances, you have the right to receive your personal data in a structured, commonly used and machine-readable format or to request the transmission of those data to another data controller in a machine-readable format;
-
Rights related to automated decision-making, including profiling, meaning that, based on your particular situation, you have the right at any time to object to the processing of personal data concerning you which is based on automated decision-making and/or profiling, and to request human intervention by the data controller, as well as the right to express your point of view and to contest the decision;
-
Right to object to the supervisory authority as to whether the processing of personal data relating to the data subject is lawful;
-
Right to compensation if you have suffered damage as a result of the processing of your personal data.
At any time, you may notify us of your intention to withdraw your consent to the processing of your personal data. The withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal.
You may exercise your rights by sending a request to the e-mail address office@dss-law.hr, or in person or in writing to the following address: DUPLIĆ STRUKIĆ ŠARIĆ Law Firm GP, Zagreb, Froudeova ulica 1. Further information on how to submit a request for the exercise of data subject rights may be obtained by e-mail at office@dss-law.hr.
In the event of any questions, requests or objections relating to the processing of personal data, you have the right to contact DSS at the above address. When submitting a request, identification of the applicant is required. This is necessary in order to protect you as the holder of the personal data.
You have the right to file an objection to DSS or, if you consider that the processing of your personal data is contrary to the General Data Protection Regulation, you have the right to file an objection to the competent supervisory authority (for the territory of the Republic of Croatia, the competent supervisory authority is the Personal Data Protection Agency (AZOP), with its registered office at Ulica Metela Ožegovića 16, 10000 Zagreb, Croatia, website: http://azop.hr/, telephone: +385 1 4609 000, e-mail: azop@azop).
-
How do we secure your data?
To protect your data, we will take appropriate technical and organizational measures in line with the applicable data protection and data security laws, including requiring our service providers, business partners or professional advisors to use appropriate measures to protect the confidentiality and security of your data. We put in place measures to prevent risks such as destruction, loss, alteration, unauthorized disclosure of, or access to your data.
-
Personal data of children
Our website is not intended for minors. We advise parents and guardians to teach children safety and the use of personal information on the Internet.
-
Amendments
We may update this Privacy Policy from time to time by publishing a new version on our website. You should check this page occasionally to ensure you understand any changes to this Privacy Policy.
-
Third party websites
We do not include or offer third-party products or services on our website.
-
Cookies
A cookie is a file that is stored on your computer or mobile device when you visit websites. Cookies allow websites to remember your actions and preferences which relate to the display of the website or contacting DSS and therefore do not need to be re-entered each time you return to the website or when browsing different pages of a particular website.
The cookies we use do not collect personal data such as name, surname, email address, etc.
We use functional cookies to recognize when users visit our website, to remember your preferences in order to improve and provide a personalized user experience.
You can remove cookies by deleting them or you can block them by changing the settings for each individual browser.
We also use the following cookies:
-
temporary user input cookies (session-id) or persistent cookies limited to a few hours in some cases,
-
authentication cookies, which are used for authentication services, for the duration of the browsing session,
-
user security cookies, which are used to detect authentication abuse, of limited duration,
-
cookies enabling page loading, for the duration of the browsing session;
-
analytical cookies.
We only process cookies with your consent. You can accept, partially accept, or reject the use of cookies. By requesting consent, we will present the purpose for which we will process this type of information and we will inform you of your rights. You can adjust your cookie selection at any time through a pop-up window.
DSS is not responsible for any loss or damage caused by virus attacks or any other malicious software that may affect computer equipment, data or materials, and is a consequence of using DSS website.