Last updated: March 2026
Blago.hr ("we", "our") is committed to protecting your privacy. This policy describes how we collect, use, and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and Croatian data protection law.
1. Data Controller
Blago.hr
Email: info@blago.hr
Location: Croatia
2. Data We Collect
- Account data: name, email address, password (encrypted) upon registration
- Order data: full name, delivery address, phone number, guest email
- Payment data: processed by a third-party payment provider; we do not store card details
- Usage data: session cookies, cart data (localStorage)
3. Purpose and Legal Basis
- Contract performance: order processing, delivery, order communications
- Legitimate interest: service improvement, site security
- Consent: analytics cookies (only with your explicit consent)
4. Cookies
We use the following types of cookies:
- Essential cookies: session cookie (authentication), required for site functionality and do not require consent
- Browser storage: cart (localStorage) — functionally necessary, not a cookie
- Analytics cookies: used only with your explicit consent to improve user experience
You can withdraw your consent at any time by clearing cookies from your browser.
5. Data Retention
- Account data: until you request deletion
- Order data: 5 years (legal obligation for accounting records)
- Session cookies: until logout or session expiry
6. Your Rights
You have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data ("right to be forgotten")
- Restriction — restrict how we use your data
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interest
To exercise your rights, contact us at: info@blago.hr
7. Third-Party Sharing
We do not sell your data. We share it only with:
- Payment service providers (transaction processing)
- Delivery services (order fulfillment)
- Hosting providers (data stored in the EU)
8. Security
We apply technical and organizational measures to protect your data, including password encryption, HTTPS communication, and restricted data access.
9. Supervisory Authority
If you believe your rights have been violated, you have the right to file a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr.
10. Policy Changes
We reserve the right to modify this policy. We will notify you of significant changes via the website or email.