Skip to Content

PRIVACY POLICY

Date of last modification: July 14, 2026.

Data Controller

Data controller of personal data collected through the online store www.drinx.hr is:

VINO d.o.o.
Borongajska cesta 81C
10000 Zagreb
Republic of Croatia
OIB: 12130498619
MBS: 080597440
Email:info@drinx.hr
Phone:+385 1 32 32 222
Website:www.drinx.hr

For questions about privacy and the exercise of rights, you can contactinfo@drinx.hror by mail to the registered office address with the note "Personal Data Protection".

Scope of Application

This Privacy Policy describes how VINO d.o.o. collects, uses, stores, transfers, and protects personal data of visitors, registered users, customers, recipients of shipments, newsletter subscribers, and other individuals who communicate with us through Drinx.hr.

Processing is carried out in accordance with Regulation (EU) 2016/679 – General Data Protection Regulation (GDPR), the Act on the Implementation of the General Data Protection Regulation, the Electronic Communications Act, the Consumer Protection Act, the Trade Act, and other applicable regulations.

Principles of Processing

We process personal data lawfully, fairly, and transparently. We only collect data that is appropriate, relevant, and limited to what is necessary for a specific purpose. We strive to keep the data accurate, retain it only as long as necessary, and apply appropriate technical and organizational measures for protection.

Categories of Personal Data

Depending on how you use Drinx.hr, we may process:

  • identification data: first name, last name, username, company name, tax identification number when required for billing or legal obligation;
  • contact information: billing and delivery address, email address, and phone number;
  • order data: products, quantities, prices, discounts, coupons, payment and delivery methods, order status, returns and complaints;
  • payment data: amount, status and transaction identifier, payment method, and limited or masked data provided by the payment service provider;
  • user account data: login information in a technically protected form, order history, saved addresses, settings, and wish list if active;
  • communication data: inquiries, written complaints, claims, return requests, content of correspondence, and attached evidence;
  • technical data: IP address, date and time of access, type of device, browser, operating system, source URL, security logs, and data on interaction with the site;
  • consent data: content, date, time, and source of consent, selected cookie categories, opt-out, and objection to marketing;
  • age verification data: result of a reliable verification and the minimum necessary technical proof that the verification was conducted when such recording is lawful and necessary.

We do not request a copy of the ID for the usual online age verification unless it is exceptionally necessary and lawful. Data obtained through the e-Citizens system is used solely for immediate age verification, in accordance with the Trade Act.

Purposes, Legal Bases, and Retention Periods

PurposeDataLegal basisFramework retention period
Order processing and contract executionidentification, contact, order, delivery, and paymentcontract execution and actions prior to contract conclusionuntil the fulfillment of the contract and the expiration of deadlines for requests; accounting documents according to legal deadlines
Issuance of invoices, accounting, tax and excise obligationsidentification, transaction, and accounting datalegal obligationat least 11 years when required by accounting and tax regulations
Delivery and tracking of shipmentsname, address, phone, email, and shipment statuscontract executionuntil the completion of delivery, then within the order documentation and deadlines for complaints
Card and other paymentamount, status, identifier, and limited payment method datacontract execution, legal obligation, and legitimate interest in preventing fraudaccording to legal deadlines and deadlines of the payment service provider; full card data is not stored by VINO d.o.o.
User accountidentification, contact, login data, settings, and historycontract execution and legitimate interest in secure account managementuntil account deletion or a maximum of three years after the last activity, except for data retained on another basis
Wishlistaccount identifier and saved productsexecution of the requested functionality and legitimate interestuntil the removal of the item, account deletion, or discontinuation of functionality
Returns, complaints, and written objectionscontact information, order, description, evidence, and communicationlegal obligation, contract execution, and defense of legal claimsrecord of complaints for at least one year; the subject may be kept longer until the applicable deadlines expire
Customer supportcontact details and content of communicationcontract execution, actions at the request of the person, and legitimate interest in quality supportgenerally up to five years, depending on the nature of the subject
Age verificationresult of the verification and necessary technical recordlegal obligation to protect minorsdata from e-Citizens is used immediately; only the minimum necessary proof is retained when permitted and necessary
Newsletter and direct marketingname, email, consent, unsubscribe, and basic interaction dataconsent; for existing customers only when permitted by special regulationsuntil consent or objection is withdrawn; proof of consent may be kept until the expiration of compliance verification deadlines
Analytics and traffic measurementonline identifiers, cookies, and usage dataconsent for non-mandatory analytical technologiesaccording to tool settings and Cookie Policy; data in Google Analytics is generally configured for the shortest reasonable period
Advertising and campaign measurementcookie, device, and campaign identifiers, interactions, and conversionsconsentaccording to the duration of cookies, tool settings, and withdrawal of consent
Security and prevention of abuseIP address, logins, security records, and fraud indicatorslegitimate interest in protecting users, systems, and property; legal obligation when applicablegenerally up to 12 months, and longer in the case of an incident, investigation, or legal claim
Management of cookie consentsconsent identifier, selected settings, date and timelegal obligation and legitimate interest in proving choicesuntil the replacement or withdrawal of consent and the period necessary to demonstrate compliance

Deadlines are approximate. Data may be retained longer when necessary for legal, administrative, or other proceedings, debt collection, fraud investigation, or specific legal obligations. After the deadline, data is deleted, anonymized, or access is permanently restricted.

Data Sources

We most often obtain data directly from you when you browse the site, create an account, place an order, select payment, subscribe to the newsletter, file a complaint, or communicate with us.

Certain data is obtained from Monri, banks, DPD, age verification system providers, hosting providers, and Odoo solutions, analytical and advertising partners, and public registers when it is lawful and necessary.

If a customer orders delivery to another person, they are required to inform that person that their data will be provided to VINO d.o.o. and the delivery partner for the purpose of fulfilling the delivery.

Is Providing Data Mandatory

Data marked as mandatory is required for the conclusion and execution of contracts, delivery, invoicing, payment processing, or age verification. Without it, we may not be able to accept or fulfill the order.

Providing data for newsletters, analytics, and personalized marketing is voluntary. Refusing or withdrawing consent does not affect the ability to purchase, except that certain non-mandatory functionalities may not be available.

Recipients and Processors

We can make data available only to the necessary extent to the following categories of recipients:

  • Odoo providers, hosting, maintenance, development, security, storage, and customer support;
  • Monri, banks, card companies, and other participants in the payment system;
  • DPD and other contracted carriers;
  • providers of email, newsletters, and business communication;
  • Google for analytics, advertising, and conversion measurement when consent is given;
  • Meta for Meta Pixel, measurement, and advertising when consent is given;
  • accounting, tax, auditing, legal, and insurance advisors;
  • competent courts, state bodies, the State Inspectorate, tax, customs, police, and other authorized bodies when delivery is legally required;
  • potential legal successors in the event of an allowed status change, with appropriate protective measures.

We enter into contracts with processors and require them to process data only according to our instructions, with appropriate confidentiality and security measures.

Certain partners, such as banks, card companies, Monri in certain roles, DPD for their own legal obligations, Google or Meta for parts of independently determined processing, may act as separate data controllers. Their privacy policies also apply to such processing.

International Transfers

Some service providers, particularly Google and Meta, may process data outside the European Economic Area or allow access to data from third countries.

When data is transferred to a third country, the transfer is based on a decision by the European Commission on adequacy, including the EU–US Data Privacy Framework for certified recipients where applicable, standard contractual clauses of the European Commission, or another permitted mechanism. A transfer assessment is conducted as necessary, and additional technical, contractual, or organizational measures are implemented.

Information about the applicable mechanism and a copy of the relevant safeguards can be requested viainfo@drinx.hr, subject to possible legal restrictions and the removal of business confidential parts.

Cookies and Similar Technologies

Essential cookies are used for the operation of the shopping cart, login, security, completing purchases, and storing privacy preferences. Prior consent is required for non-essential functional, analytical, and marketing cookies.

You can give, refuse, or adjust your consent in the banner and subsequently change it via the "Cookie Settings" link. You can change your choice later via the "Cookie Settings" link in the footer of the page.

Newsletter and Direct Marketing

We send newsletters to individuals who have given voluntary consent or in other narrowly permitted cases provided for by electronic communications and direct marketing regulations.

Each marketing message contains a simple option to unsubscribe. Unsubscribing does not affect service messages related to orders, account security, changes in terms, or other contractual relationships.

To prove legality, we can record the date, time, source, and content of consent as well as the withdrawal. We do not purchase arbitrary lists of private email addresses nor do we send newsletters to individuals without a proper legal basis.

Profiling and Automated Decision-Making

If you have given consent for marketing cookies, we can use data about viewed products, interactions, and purchases to shape audiences, limit ad frequency, measure campaigns, and display more relevant ads.

Such profiling does not produce legal effects nor does it significantly affect you in a similar way. We do not make decisions regarding the conclusion of consumer contracts solely based on automated processing without appropriate human intervention, except where permitted by law and with prescribed safeguards.

Automated security indicators may temporarily halt a suspicious transaction for manual review. The customer can request a human review of the decision by contactinginfo@drinx.hr.

Rights of the Data Subject

In accordance with GDPR, you have the right to:

  • obtain confirmation of whether we are processing your data and access the data;
  • request correction of inaccurate and completion of incomplete data;
  • request deletion when there is no longer a legal basis for processing;
  • request restriction of processing;
  • receive the data you provided to us in a structured, commonly used, and machine-readable format and transfer it to another controller when the conditions for portability are met;
  • object to processing based on legitimate interest;
  • at any time object to direct marketing, including related profiling;
  • withdraw consent without affecting the lawfulness of processing before the withdrawal;
  • not to be subject to a decision based solely on automated processing and which produces legal or similarly significant effects, except in cases permitted by law;
  • to file a complaint with the supervisory authority.

Send your request toinfo@drinx.hr. For data protection purposes, we may request additional information necessary to confirm your identity, but we will not ask for more data than is proportionate.

We respond to a proper request without unnecessary delay, usually within one month. The period may be extended by an additional two months for complex or numerous requests, of which we will inform you in a timely manner.

Rights are not absolute. A request may be limited or denied when required by law, for example, due to the obligation to retain records, the protection of the rights of others, or the defense of legal claims. You will be informed of the reasons.

Objection to Legitimate Interest and Marketing

When we base processing on legitimate interest, you have the right to object due to your particular situation. We will then cease processing unless we demonstrate compelling legitimate reasons that override your interests, rights, and freedoms, or the processing is necessary for legal claims.

In direct marketing, the objection applies without exception. After the objection, we will no longer use the data for that purpose.

15. COMPLAINT TO AZOP

If you believe that your data is being processed in violation of regulations, you can contact us to try to resolve the issue. You also have the right to file a complaint with the Personal Data Protection Agency (AZOP), the Croatian supervisory authority, or the supervisory authority of the member state where you have your habitual residence, place of work, or the place of the alleged infringement.

Data Security

We apply measures appropriate to the risk, including HTTPS/TLS transmission protection, access control, authorization management, backups, security event logging, system updates, confidentiality contractual obligations, and incident procedures.

No system is completely resistant to risk. In the event of a personal data breach, we will act in accordance with the GDPR, including documenting the incident, notifying the supervisory authority when necessary, and informing affected individuals when the breach may pose a high risk to their rights and freedoms.

Data About Minors

Drinx.hr and the sale of alcoholic beverages are not intended for individuals under the age of 18. We do not knowingly collect their data for the purpose of purchasing alcohol or marketing profiling.

If we become aware that a minor has provided data in violation of the rules, we will take reasonable measures to delete the data, block the order, and prevent delivery, unless we are required to retain the data for legal obligations, security, or to prove attempted abuse.

External Sites and Social Networks

Drinx.hr may contain links to partner sites, delivery services, payment providers, or social networks. When you leave Drinx.hr, processing may be carried out according to the rules of that provider.

If social media plugins are embedded directly on the site, they will not be activated until appropriate consent is obtained when such activation is not necessary for the explicitly requested service.

Policy Changes

We may change the policy due to changes in regulations, technology, providers, or business processes. A new version will be published on Drinx.hr with an updated date.

If a change significantly affects your privacy choices or requires new consent, we will request it before further processing.

Contact

VINO d.o.o.
Borongajska cesta 81C
10000 Zagreb
Email:info@drinx.hr
Phone:+385 1 32 32 222