Custom production Interiors, facades and commercial spaces

Last updated: 10 July 2026.

This Privacy Policy explains how MICHELANGELO d.o.o. collects, uses, stores and protects personal data relating to website visitors and people who contact us through the contact form, email, telephone or other communication channels.

1. Data controller

The controller is MICHELANGELO d.o.o. za završne građevinske radove, OIB 15826431751, Ulica braće Radića 1, 40000 Pribislavec, Croatia.

For questions about personal data or to exercise your rights, contact us using the details above. The company has not appointed a separate data protection officer; requests are handled by the controller.

2. Personal data we process

We process only data needed for the purposes described in this policy. This may include:

  • identification and contact details you provide, such as your name, email address, phone number and message;
  • project information you voluntarily send for a quote, such as measurements, photographs, sketches, product preferences or a project address;
  • business correspondence and information in quotes, orders, invoices and delivery records when a business relationship is established;
  • technical data such as IP address, access time, browser and device type, server logs and security records;
  • cookie and similar-technology data, in line with your choices and our Cookie Policy.

3. Purposes and legal bases

  • Responding to enquiries and preparing quotes: steps taken at your request before entering into a contract or performance of a contract.
  • Communication with customers and business partners: contract, pre-contractual steps or our legitimate interest in orderly business communication.
  • Quotes, orders, invoices and business records: performance of a contract and compliance with tax, accounting and other legal obligations.
  • Website operation, maintenance and security: our legitimate interest in keeping the website secure, available and functional.
  • Strictly necessary cookies: provision of the website or service you request.
  • Optional analytics, marketing or other non-essential cookies, if introduced: your consent, which you may change or withdraw at any time.
  • Legal claims: our legitimate interests or a legal obligation, depending on the circumstances.

4. Contact form and communications

When you send an enquiry through the contact form, we process the name, email address, optional phone number and message you provide to reply, advise you, prepare a quote and continue communication about your project. Providing this data is not a statutory requirement, but without basic contact details and an enquiry we cannot respond or prepare a quote.

5. Cookies

The website uses cookies and similar technologies. Necessary cookies support basic operation. Details about cookie categories, purposes, duration and consent controls are available in our Cookie Policy. Rejecting optional cookies does not disable the website’s core functions.

6. Recipients

We do not sell personal data. Data may be shared only where necessary for website operation, communication, contract performance, legal compliance or protection of our rights. Recipients may include hosting and technical providers, email and form providers, accountants and professional advisers, delivery or installation partners, and competent public authorities. Appropriate contractual, technical and organisational safeguards are used for processors acting on our behalf.

7. Transfers outside the EEA

We aim to process personal data within the European Union or European Economic Area. Where a provider processes data elsewhere, a transfer takes place only with a valid legal basis and appropriate safeguards, such as an adequacy decision or standard contractual clauses.

8. Retention

  • Contact-form and email enquiries are generally retained for up to 24 months after the last communication, unless they develop into a business relationship or another justified reason applies.
  • Quotes, orders, invoices and business records are kept for periods required by tax, accounting and other applicable laws.
  • Technical and security logs are generally kept for up to 12 months, unless longer retention is needed for an incident, abuse prevention or legal protection.
  • Data processed on the basis of consent is kept until consent is withdrawn or the stated purpose ends.

9. Your rights

Subject to the GDPR conditions, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting prior lawful processing. Send requests to info@michelangelo.hr. To protect your data, we may ask for reasonable identity verification.

10. Supervisory authority

You may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, email azop@azop.hr, website https://azop.hr.

11. Security

We apply reasonable technical and organisational safeguards, including access controls, website security measures, regular maintenance and secure storage. Personal data is available only to people who need it to perform their work or provide a service.

12. Children

Our services and website are not intended for children and we do not knowingly collect children’s personal data. Contact us if you believe a child has provided data so we can take appropriate action.

13. Automated decision-making

We do not make decisions that produce legal or similarly significant effects based solely on automated processing, including profiling.

14. Changes to this policy

We may update this policy to reflect changes to the website, business processes or applicable law. The current version is always published on this page.