Privacy Policy
This policy explains which personal data we process through this corporate website, why we process it and which rights you have.
Controller and scope
For this website and general enquiries, the controller is Biovega d.o.o., Majstorska 1E, 10000 Zagreb, Croatia, company ID (OIB) 84586153335, email: info@biovega.hr.
Biovega Group is the umbrella identity of connected business systems. When your enquiry concerns another company or institution within the group, we may forward the data to that organisation so it can respond. In that case, the organisation may become a separate controller for further communication.
This policy applies only to biovegagrupa.hr. The connected websites of Biovega, bio&bio, Zrno, Planetopija, Makronova and the recruitment system have their own privacy policies.
Data we process
Data you send us
Through the contact form, we may receive your full name, organisation, email address, telephone number, enquiry type, message and any other information you voluntarily include.
Email and direct communication
When you contact us by email, we process the sender address, communication content, attachments and the data needed to manage and document the response.
Technical data
The hosting provider may process the IP address, date and time of access, requested URL, browser type, device information and security logs to deliver the website, prevent misuse and maintain security.
Purposes and legal bases
- Responding to an enquiry and preparing cooperation: processing is necessary to take steps at your request before entering into a contract or to perform a contractual relationship.
- General business communication: we process data on the basis of our legitimate interest in communicating properly with partners, media, suppliers and other stakeholders.
- Legal and administrative obligations: we retain certain data where necessary to meet legal duties, evidence business communication or protect legal claims.
- Website security: we process technical logs for the legitimate interest of protecting the site, systems and users from fraud, attacks and misuse.
We do not use data from this form to send newsletters or promotional messages without a separate, clear legal basis.
Recipients and processors
Only employees and contractors who need the data to handle the enquiry have access. Depending on the topic, we may forward data to the relevant company or institution within the group.
The website is technically provided by Vercel, Inc. The contact form is processed by a Vercel server function and delivered to our business email address by Resend (Plus Five Five, Inc.). The web application itself does not maintain a separate database of form submissions. We also use email, IT and security service providers as needed.
Some providers may process data outside the European Economic Area. In such cases, transfer is based on an applicable transfer mechanism and appropriate safeguards made available by the provider.
How long we retain data
- General enquiries are retained for up to 12 months after communication ends, unless a longer period is necessary.
- Data connected with a business relationship is retained during the relationship and afterwards for periods required by legal, accounting and claims-related obligations.
- Unsolicited job applications sent by email are generally deleted after 6 months unless you request longer retention or another period applies.
- Technical logs are retained according to the hosting provider's periods and security needs.
Messages received through the form are retained in the business email system and periodically reviewed and deleted when no longer needed.
Your rights
Depending on the circumstances, you may request access, rectification, erasure, restriction, portability and object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it without affecting the lawfulness of earlier processing.
Send requests to info@biovega.hr. To protect data, we may request reasonable identity verification. We will respond without undue delay and within the statutory period.
If you believe your data is processed unlawfully, you may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), azop.hr.
Security
We apply reasonable technical and organisational measures, including access restrictions, HTTPS, security headers, automated-spam protection and user-account control. No system is entirely risk-free, so we review needs and adapt measures regularly.
Changes to this policy
We may change this policy when website functions, providers or legal requirements change. The current version will always be published here with the date of the latest update.
