Privacy Policy
This privacy policy describes how Velnorexiumar d.o.o. (referred to as "Velnorexiumar", "we") collects, processes and protects your personal data when you use velnorexiumar.com and the associated digital services. The policy is aligned with EU Regulation 2016/679 (GDPR), the Croatian Act on the implementation of the GDPR (OG 42/2018) and EU Regulation 2020/1503 on European crowdfunding service providers.
1. Data controller
Velnorexiumar d.o.o., Domovinskog rata 27a, 21000 Split, Croatia, OIB: 48372910652. Data Protection Officer (DPO): dpo@velnorexiumar.com.
2. What data we collect
Contact form data (name, email, message), technical data (truncated IP address, device type, operating system), cookies according to your settings and — if you decide to invest — identification documents needed for KYC/AML checks under the Croatian Anti-Money Laundering Act (OG 108/17).
3. Purposes and legal bases
Responding to your enquiries (legitimate interest, Art. 6(1)(f) GDPR), pre-contractual measures (Art. 6(1)(b)), compliance with HANFA and ESMA obligations (Art. 6(1)(c)) and marketing communication strictly on the basis of your explicit consent (Art. 6(1)(a)).
4. Retention period
Contact enquiries are kept for 24 months from the last communication. Accounting records are kept for 11 years under the Croatian General Tax Act. KYC files are kept for 5 years after the business relationship ends.
5. Recipients of data
We do not sell your data. We share it with IT providers (hosting at Hetzner Online GmbH, Falkenstein), our accounting partner in Split and authorities when legally required. For any transfer outside the EEA we rely on the European Commission's Standard Contractual Clauses.
6. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection. You may also file a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, Zagreb.
7. Automated decision-making
We do not perform automated profiling that produces legal or similar effects. All decisions about platform admission are made by people in our compliance team.
8. Security
We use TLS 1.3 encryption in transit, AES-256 encryption at rest, two-factor authentication for admin access and weekly backups across two geographically separated EU data centres.
9. Changes to this policy
We notify you of material changes by email at least 30 days before they take effect. The current version is always available on this page.