Privacy Policy
Last updated: 07/07/2026
1. Data controller
The controller of your personal data is Gloria Design (see full company details on our Imprint). Contact: info@gloria3d.hr.
2. Data we process
- Order data: name, delivery/billing address, email, phone, order contents.
- Payment data: processed directly by our payment providers; we do not store card numbers.
- Communication data: emails or messages you send us.
- Technical data: IP address, browser type, device information, cookies โ see our Cookie Policy.
3. Lawful bases (Art. 6 GDPR)
- Performance of a contract โ processing orders, delivery, warranty (Art. 6(1)(b)).
- Legal obligation โ tax, accounting, consumer-protection records (Art. 6(1)(c)).
- Legitimate interests โ fraud prevention, site security (Art. 6(1)(f)).
- Consent โ non-essential cookies, marketing emails (Art. 6(1)(a)).
4. Recipients & processors
Personal data may be shared with processors acting on our behalf:
- Shopify Inc. โ e-commerce platform, checkout and payments.
- Payment providers as displayed at checkout (e.g. Shopify Payments, Stripe, PayPal).
- Shipping carriers (e.g. HP Ekspres, GLS, DPD, DHL) for order fulfilment.
- Hosting and infrastructure providers.
When data is transferred outside the EU/EEA, we rely on adequacy decisions or Standard Contractual Clauses (Art. 46 GDPR).
5. Retention
Order and invoice data are retained for the legally required period (in Croatia, 11 years for accounting records). Communication data is retained only as long as necessary to answer your query.
6. Your rights
Under the GDPR you have the right to:
- Access your data (Art. 15).
- Rectify inaccurate data (Art. 16).
- Request erasure (Art. 17).
- Restrict processing (Art. 18).
- Data portability (Art. 20).
- Object to processing based on legitimate interests (Art. 21).
- Withdraw consent at any time, without affecting prior lawful processing.
Requests can be sent to info@gloria3d.hr. You also have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) at azop.hr.
7. Security
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss or alteration, including TLS encryption in transit and access controls.
8. Changes
We may update this policy from time to time. The current version is always available on this page.