Effective Date: 16.06.2025
Last Updated: 16.06.2025
- This Privacy Policy describes how Spika Group d.o.o., located at Ulica
- Gračansko borje 5C, 10000 Zagreb, Croatia ("Spika Solutions", "we",
"us", or "our") collects, uses, and protects your personal data in
- accordance with the General Data Protection Regulation (EU) 2016/679
- (GDPR) and the Croatian Law on the Implementation of the General Data
Protection Regulation.
1. Important Information and Who We Are
- This Privacy Policy explains how we process your personal data when you
- visit our website, use our services, or otherwise interact with us. This
- website and our services are not intended for children, and we do not
knowingly collect data relating to children.
Controller:
Spika Group d.o.o.
Ulica Gračansko borje 5C
10000 Zagreb, Croatia
OIB: 15837863393
Email: [email protected]
2. Types of Personal Data We Collect
- We may collect, use, store, and transfer different kinds of personal
data about you, which we group as follows:
- Identity Data – Name, surname, username, date of birth, gender
- Contact Data – Address, email address, phone number
- Financial Data – Payment card or account details
- Transaction Data – Details of services purchased and payments made
- Technical Data – IP address, browser type/version, device IDs, location
- data
- Usage Data – Interaction with our website, content, and services
- Profile Data – Login details, preferences, feedback, survey responses
- Marketing and Communications Data – Your preferences in receiving
- communications from us
- We may also collect and use aggregated data (e.g., statistical or
- demographic data), which is not personal data under GDPR as it does not
reveal your identity.
3. How We Collect Your Data
We gather personal data through:
- Direct interactions – via forms, emails, phone, or chat when you contact
- us, request services, or provide feedback
Third-party sources – including:
- GoHighLevel (CRM and automation)
- Kit (business automation)
- Calendly (scheduling)
- Zapier (integration between platforms)
- Meta & Google (advertising and analytics)
- We may also collect publicly available data, such as company
registration information.
4. How We Use Your Personal Data
- We will only use your personal data when the law allows us to. This
includes:
- To register you as a client – based on the performance of a contract
- To provide and manage our services – including handling payments, fees,
- and charges
- To manage our relationship with you – such as responding to inquiries or
- notifying you of changes to our terms or policies
- To improve our website and services – using analytics to understand how
- users interact with our content
- To send relevant content and marketing – where you’ve given consent, or
- where we have a legitimate interest
- To comply with legal obligations – including fraud prevention and
- fulfilling tax or accounting requirements
- To protect our systems and data – ensuring website functionality,
- security, and performance
- To carry out surveys and research – to improve our services and
- understand customer needs
- We rely on different legal bases depending on the specific activity,
- including contractual necessity, legitimate interests, legal obligation,
and consent where required.
5. Direct Marketing
You may receive marketing from us if:
- You’ve purchased services or requested information
- You’ve opted in to receive marketing
- You haven’t opted out of communications
- You can opt out at any time via the link in our emails or by contacting
- We will never share your data with third parties for their own marketing
purposes without your explicit consent.
6. Disclosures of Your Personal Data
We may share your personal data with trusted third parties, including:
- Software providers: GoHighLevel, Kit, Calendly, Zapier, Meta, Google
- Email platforms, subcontractors, and service partners
- Legal or regulatory authorities, where legally required
- Business partners in the case of a company merger, acquisition, or sale
- All third parties are required to handle your data in compliance with
GDPR and under strict confidentiality agreements.
- No mobile information will be shared with third parties/affiliates for
- marketing/promotional purposes. Information sharing to subcontractors in
- support services, such as customer service is permitted. All other use
- case categories exclude text messaging originator opt-in data and
consent; this information will not be shared with any third parties.
7. International Transfers
- Some of our service providers are based outside the European Economic
- Area (EEA). When we transfer your data internationally, we ensure that
one of the following safeguards is in place:
- The country has been deemed to provide an adequate level of protection
- by the European Commission
- We use Standard Contractual Clauses (SCCs) approved by the European
- Commission to ensure appropriate protection
8. Data Security
- We use a range of technical and organizational measures to protect your
data from loss, misuse, or unauthorized access, including:
- Encryption of data during transmission
- Access control measures
- Secure servers and data backups
- Only employees and partners with a valid business need can access your
personal data.
9. Data Retention
- We retain your personal data only as long as necessary for the purposes
for which it was collected, including:
- Service delivery and support
- Legal, accounting, and tax obligations (up to 6 years)
- Handling legal claims or complaints
You may request earlier deletion of your data when legally permissible.
10. Your Legal Rights
You have the following rights under GDPR:
- Right to access – to request a copy of your personal data
- Right to rectification – to correct inaccurate or incomplete data
- Right to erasure – to request deletion of your data in specific
- circumstances
- Right to restrict processing – to limit how we use your data
- Right to object – to stop processing for certain purposes, like
- marketing
- Right to data portability – to receive your data in a structured,
- machine-readable format
- Right to withdraw consent – at any time if processing is based on your
- consent
To exercise your rights, contact us at [email protected].
- We may need to verify your identity before fulfilling any request. We
aim to respond within one month.
11. Complaints
- If you believe we have not respected your privacy rights, you may
contact:
- Croatian Personal Data Protection Agency (AZOP)
- Website: https://azop.hr
Email: [email protected]
Phone: +385 1 4609 000
- We encourage you to contact us first at [email protected] so we
can resolve your concern directly.
12. Changes to This Policy
- We regularly review and update this Privacy Policy. Any material changes
- will be communicated clearly, and the latest version will always be
available on our website.
- Please inform us of any changes to your personal data so we can keep our
records accurate.
13. Third-Party Links
- Our website may include links to third-party websites or services. We
- are not responsible for their privacy practices. We recommend reviewing
their policies before submitting any data.