Skip to content

Legal information

Privacy policy

CT Direct d.o.o. za trgovinu i usluge, Zagreb, Croatia

This notice explains how CT Direct d.o.o. processes personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Croatian Act on the Implementation of the GDPR (Official Gazette 42/18).

1. Controller

CT Direct d.o.o. za trgovinu i usluge, registered office Zagreb, Croatia, OIB 80199781062, entered in the court register of the Commercial Court in Zagreb under MBS 081619621. For any questions about personal data, write to info@ctd.hr. We have not appointed a data protection officer, as there is no legal obligation to do so (Art. 37 GDPR).

2. What data we process, why and on what legal basis

  • Enquiries and communication. When you contact us by e-mail, phone or WhatsApp, we process your name, contact details, company name and message to reply and prepare an offer. Legal basis: steps prior to entering into a contract (Art. 6(1)(b) GDPR) and our legitimate interest in answering enquiries (Art. 6(1)(f)). The form on this website does not send data to our server; it only prepares a message that you send yourself.
  • Business cooperation and contracts. We process the details of contact persons of partners and clients to perform contracts, deliver goods and issue invoices (Art. 6(1)(b)).
  • Partner access. For registered partners we store the company name, e-mail address, contact name and a cryptographic hash of the password. We never store the password itself. Legal basis: the cooperation agreement (Art. 6(1)(b)) and system security (Art. 6(1)(f)).
  • Legal obligations. We keep accounting and tax records under the Croatian Accounting Act and General Tax Act. As a dealer in precious stones, we carry out customer due diligence for cash payments above the statutory threshold under the Croatian Anti-Money Laundering and Terrorist Financing Act (Art. 6(1)(c)).
  • Technical data. When you visit the website, our hosting provider logs your IP address, time of access and browser type for security and abuse prevention (Art. 6(1)(f)).
  • Newsletters and marketing. We send promotional messages only with your explicit consent (Art. 6(1)(a)), which you may withdraw at any time without affecting the lawfulness of earlier processing.

3. Recipients and processors

We do not sell personal data or share it for third party marketing. Access is limited to:

  • our hosting and security provider (Cloudflare, Inc.);
  • our e-mail service provider;
  • WhatsApp (Meta Platforms), if you contact us through that channel, under its own privacy rules;
  • Google Fonts (Google LLC), which sees your browser’s IP address when fonts load;
  • our accountants, banks, carriers and shipment insurers, where necessary to perform a contract;
  • competent authorities, where required by law.

We have agreements or accepted data processing terms with our processors in line with Art. 28 GDPR.

4. Transfers outside the EU

Some of these providers (Cloudflare, Google, Meta) may process data in the United States. Transfers are based on the EU-U.S. Data Privacy Framework or the European Commission’s standard contractual clauses.

5. Retention

  • enquiries that did not lead to cooperation: up to 12 months after the last communication;
  • contract and accounting records: 11 years, under the Croatian Accounting Act;
  • data collected under anti-money laundering rules: 10 years after the transaction;
  • partner accounts: for the duration of the cooperation and up to 12 months after it ends;
  • hosting provider logs: briefly, under the provider’s rules;
  • data processed on the basis of consent: until consent is withdrawn.

6. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection to processing based on legitimate interest (Art. 21) and to withdraw consent. Send requests to info@ctd.hr. We will reply without undue delay and within one month at the latest. To protect your data we may ask you to confirm your identity.

7. Complaints

If you believe the processing is unlawful, you may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr, or with the supervisory authority in your EU country of residence.

8. Other

Providing data is not a legal requirement, but without contact details we cannot reply to an enquiry. We do not use automated decision making or profiling. We protect data with appropriate technical and organisational measures, including encrypted connections (HTTPS) and restricted access. For cookies, see our Cookie policy. We may update this notice; the version published on this page applies.