Privacy policy
PRIVACY POLICY
The company Fertilite d.o.o., as a provider of personal development services, educational programmes and digital content available through the website https://petrabrzovic.com/ (hereinafter: the Controller), is committed to protecting the privacy and personal data of individuals who visit the Controller’s website, contact the Controller or use the services and programmes offered through the website (hereinafter: the Data Subject(s) or User(s)).
We process your personal data in accordance with the General Data Protection Regulation (GDPR), the Croatian Act on the Implementation of the GDPR, and other applicable regulations governing personal data protection. This Privacy Policy explains which categories of your personal data are processed, for what purposes and on which legal bases, how your personal data are used and what rights you have as a Data Subject. Personal data include any information that enables your identification, either directly or indirectly, as a Data Subject. The processing of personal data includes any operation performed on personal data, such as collection, organisation, storage, adaptation, use, transmission, erasure or destruction, whether carried out by automated or non-automated means.
CONTROLLER INFORMATION
Company name: Fertilite d.o.o.
Registration: Company registered with the Commercial Court in Zagreb
Registered seat/address: Gradečak Desni 14, Zagreb (City of Zagreb), Republic of Croatia
PIN (personal identification number): 71729980096
E-mail: info@petrabrzovic.com
Website: https://petrabrzovic.com/
CATEGORIES AND TYPES OF PERSONAL DATA WE PROCESS
a) Data of users of services and programmes (depending on the type of service):
First and last name, e-mail address, and, where necessary, telephone number; data related to reservations and participation (selected appointment or programme date, reservation confirmations, records of participation in the programme); financial data such as payment records, method of payment and transaction-related information (note: the Controller generally does not have access to the full card number, as payments are processed through authorised payment service providers); data necessary for issuing invoices; records relating to the use of the service; data required for the organisation of programmes, retreats or workshops; as well as photographs and video recordings taken during live workshops and retreats.
b) Website user data:
When you visit our website, we collect certain technical information such as your location data, IP address and other technical data necessary for the functioning of the website. For the purpose of sending newsletters, we process your first and last name and your e-mail address.
If you contact us through a contact form available on the website at the time of your inquiry, or via e-mail — whether to request information or to submit an unsolicited job application or proposal for another form of cooperation — we will collect the personal data that you provide to us, which will in any case include your e-mail address and your first and last name.
OBLIGATION TO PROVIDE PERSONAL DATA AND CONSEQUENCES OF FAILURE TO PROVIDE THEM
Providing personal data necessary for receiving enquiries, submitting applications, entering into contracts and performing services offered by the Controller through the website (including individual sessions, workshops, seminars, retreats, digital content and other programmes) constitutes a condition for the provision of the relevant service.
If the Data Subject does not provide the requested data, the Controller will not be able to process the request, enter into a contract or provide the agreed service.
Providing personal data for purposes based on consent (for example for the purpose of sending newsletters) is not a condition for using the Controller’s services.
Failure to provide such data or withdrawal of consent will not result in any adverse consequences for the Data Subject, except that such data will not be processed for the relevant purposes.
DATA RETENTION PERIOD
Personal data are processed and stored for the duration of the contractual relationship, i.e. during the provision of the relevant service, and for no longer than one (1) year after the completion of the agreed service, unless a longer retention period is required for specific data under applicable legal obligations of the Controller or where retention is necessary for the establishment, exercise or defence of legal claims.
After the expiry of the aforementioned period, personal data will be deleted or permanently anonymised, except in cases where the Controller is required to retain certain data for a longer period, particularly for accounting, tax or other statutory obligations.
Personal data processed on the basis of the Data Subject’s consent (for example for sending newsletters and other promotional communications) are retained until the consent is withdrawn, unless otherwise required by applicable law.
SHARING OF DATA WITH THIRD PARTIES
We share your personal data with third parties only where this is strictly necessary. Where required by the GDPR, we conclude data processing agreements with third parties in order to ensure the protection and confidentiality of your personal data. If personal data are transferred outside the European Economic Area (EEA), we implement appropriate safeguards (such as Standard Contractual Clauses) in order to ensure the protection of the Data Subject’s rights and the security of the data.
Your personal data may be shared in the following situations:
- In connection with the maintenance and protection of technical and software equipment, our contracted IT service providers responsible for maintaining such equipment may have access to your data.
- With competent public authorities and other entities where necessary in order to comply with legal obligations or to enforce and collect outstanding claims.
- For the purpose of fulfilling financial and other obligations arising from law or contractual relationships, your data may be shared with independent external advisers and service providers (for example accounting services and similar providers).
We may use certain third-party software solutions, and the relevant third parties acting as our contractual partners may have access to your data for the purpose of hosting, maintaining or supporting such systems.
YOUR RIGHTS AS A DATA SUBJECT
(I) RIGHT OF ACCESS TO PERSONAL DANA
You have the right to request information regarding the processing of your personal data at any time, in the manner specified in Section 8 of this Privacy Policy.
(II) RIGHT TO RECTIFICATION OR COMPLETION OF PERSONAL DANA
You have the right to request that the Controller rectify inaccurate personal data concerning you and, taking into account the purposes of the processing, to have incomplete personal data completed at any time, in the manner specified in Section 8 of this Privacy Policy.
(III) RIGHT TO ERASURE OF PERSONAL DATA (“RIGHT TO BE FORGOTTEN”)
You may request the erasure of your personal data from the Controller where the conditions for such erasure are fulfilled, in the manner specified in Section 8 of this Privacy Policy.
(IV) RIGHT TO RESTRICTION OF PROCESSING
You may request the restriction of the processing of your personal data from the Controller at any time, in the manner specified in Section 8 of this Privacy Policy. The Controller will restrict processing where one of the following conditions applies:
- the Data Subject contests the accuracy of the personal data, in which case processing will be restricted for the period necessary for the Controller to verify the accuracy of the data;
- the processing is unlawful and the Data Subject opposes the erasure of the personal data and instead requests the restriction of their use;
- the Controller no longer needs the personal data for the purposes of processing, but the Data Subject requires them for the establishment, exercise or defence of legal claims;
- the Data Subject has objected to processing and verification is pending as to whether the legitimate grounds of the Controller override those of the Data Subject.
(V) RIGHT TO DATA PORTABILITY
You may request from the Controller, at any time and in the manner specified in Section 8 of this Privacy Policy, that the personal data you have provided to the Controller be provided to you in a structured, commonly used and machine-readable format. You also have the right to transmit those data to another controller without hindrance from the Controller.
(VI) RIGHT TO OBJECT
You have the right to object to the processing of your personal data by the Controller at any time, in the manner specified in Section 8 of this Privacy Policy, in accordance with Articles 21 and 22 of the General Data Protection Regulation.
(VII) RIGHT TO LODGE A COMPLAINT WITH A SUPERVISORY AUTHORITY
If you believe that the processing of your personal data infringes applicable law, you may lodge a complaint with the competent data protection authority (Croatian Personal Data Protection Agency – AZOP) or with a competent court in order to exercise your rights.
Contact details of the competent authority:
Croatian Personal Data Protection Agency (Agencija za zaštitu osobnih podataka- AZOP)
Ulica grada Vukovara 54
10 000 Zagreb, Croatia
E-mail: azop@azop.hr
Tel: +385 (0)1 4609-000
Web: www.azop.hr
(VIII) RIGHT TO WITHDRAW CONSENT
You have the right to withdraw your consent at any time by means of a simple statement. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
EXERCISING YOUR RIGHTS
To exercise the rights listed in Section 7, you may contact us by e-mail at info@petrabrzovic.com
In order to ensure that the request is submitted by an authorised person, we may conduct an identity verification procedure before acting on the request. This may include requesting additional information or documentation. Such verification is carried out solely for the protection of your personal data and will not affect your rights.
We will respond to your request for the exercise of rights without undue delay and no later than one (1) month from the date of receipt of the request. If the request is particularly complex or if we have received a large number of requests within a short period of time, this period may be extended by up to two additional months. In such cases, you will be informed in due time, together with the reasons for the extension.
Please note that certain exceptions to the exercise of the above rights may apply in accordance with the GDPR. For example, if the processing is not based on a contract or consent, or if data portability is technically infeasible, the Controller may not be obliged to comply with a request for data portability.
DATA SECURITY
The Controller implements appropriate technical and organisational measures to ensure a level of security appropriate to the risks arising from the processing of personal data, particularly the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
Such measures include, among others:
- Device protection: Personal data are stored locally on the Controller’s personal computer, which is protected by password access, antivirus software and an updated operating system.
- Restricted access: Access to personal data is limited to the Controller and, where necessary and based on contractual arrangements, authorised external collaborators who are obliged to maintain confidentiality and comply with applicable data protection regulations.
- Regular maintenance: The Controller regularly updates its devices, software and tools and applies basic security practices in order to reduce the risk of unauthorised access, data loss or damage.
UPDATES TO THE PRIVACY POLICY
The Controller reserves the right to amend or supplement this Privacy Policy in order to ensure compliance with applicable regulations and to improve the protection of personal data. Any amendments will be published in a timely manner on the Controller’s website.
Date of the last update: 5 March 2026.