Effective Date: 6 October 2025
Website Owner: Vasco, craft business for production, trade, and services
Address: Tratinska 61, 10000 Zagreb, Croatia
E-mail: vasco.gram@gmail.com
Website: www.vasco.hr


1. Introduction

This Privacy Policy explains how we collect, use, and protect your personal data when you visit our website or make a purchase through our online shop.
The processing of personal data is carried out in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and applicable laws of the Republic of Croatia.

By using our website and purchasing products, you confirm that you have read, understood, and accepted this Privacy Policy.


2. Personal Data We Collect

We collect only the data necessary for order processing and improving user experience:

  • Full name
  • Delivery address
  • Email address
  • IP address (automatically collected through cookies and analytics tools)

Payment data (eg, card numbers) are not processed or stored on our servers but exclusively handled through secure payment systems (Woopay and PayPal).


3. Purpose and Legal Basis for Data Processing

Purpose of ProcessingLegal Basis
Order processing and deliveryPerformance of a purchase contract
Invoicing and compliance with tax obligationsLegal obligation
Communication with users (inquiries, complaints)Legitimate interest
Website traffic analysis and improvement (Google Analytics)User consent via cookies

4. Data Sharing with Third Parties

Your data may be shared with trusted partners only when necessary to provide the requested service:

  • Woopay and PayPal – for secure payment processing
  • Google Ireland Ltd. – via Google Analytics for website traffic statistics
  • Delivery services (HP, GLS, DPD, etc.) – for the delivery of ordered products

All listed partners are GDPR-compliant and bound by confidentiality obligations.


5. Data Storage and Protection

Personal data is stored on secure servers and protected against unauthorized access, alteration, or loss.
We retain data for the following periods:

  • Invoices and customer records: 11 years (in accordance with Croatian tax regulations)
  • Contact inquiries: up to 1 year after the end of communication
  • Analytical data: according to cookie settings (see Cookie Policy)

6. Cookies

Our website uses cookies to improve user experience and analyze traffic.
By using the site, you consent to the use of cookies unless you disable them in your browser settings.
For more information, please see our Cookie Policy.


7. Your Rights

In accordance with the GDPR, you have the following rights:

  • Right of access - request a copy of your personal data that we process.
  • Right to rectification – if your data is inaccurate or incomplete.
  • Right to erasure ("right to be forgotten").
  • Right to restrict processing.
  • Right to data portability.
  • Right to object - withdraw your consent for data processing at any time.

To exercise these rights, please contact us at vasco.gram@gmail.com.
We will respond within 30 days of receiving your request.


8. Data Transfers Outside the EU

Some of our partners (eg, PayPal, Google) may process data on servers outside the EU.
In such cases, Standard Contractual Clauses approved by the European Commission are applied to ensure an adequate level of data protection.


9. Automated Decision-Making and Profiling

We do note engage in any automated decision-making or profiling based on personal data.


10. Changes to this Privacy Policy

We reserve the right to update or amend this Privacy Policy at any time without prior notice.
The updated version will always be available on www.vasco.hr.


11. Contact

For any questions, requests, or complaints regarding privacy protection, please contact us at:
📧 vasco.gram@gmail.com
📍 Vasco, craft business for production, trade, and services
Tratinska 61, 10000 Zagreb, Croatia

If you believe your rights have been violated, you can complain to them Croatian Personal Data Protection Agency (AZOP), Martićeva 14, Zagreb.