Privacy Policy
Date of entry into force: 19 June 2023
1. Introduction
Franck d.d. Vodovodna 20, VAT No.: 07676693758 (hereinafter referred to as Franck), as the controller, processes and protects personal data concerning the users of its services and visitors of www.franck.eu, www.shop.franck.eu and the related microsites in accordance with the regulations applicable to personal data protection.
Provided below please find information about the treatment of personal data collected from users of the website and webshop, consumers, job applicants, contractors and participants in prize contests, competitions and other similar activities, which we collect through this website or otherwise.
Franck has appointed its data protection officer whom you can contact if you have any questions regarding this Privacy Policy at gdpr@franck.eu.
2. Electronic communications
Access to our website is free and requires no registration. If you would like to receive a newsletter about our offerings, new content on our website, prize content or competitions, you can simply select to register your e-mail address using the relevant form and become duly subscribed. An e-mail confirmation of the data subject’s subscription to the newsletter will be sent to the e-mail address registered by the data subject before the newsletter is sent for the first time, for double authentication purposes. Such confirmation is used to demonstrate whether or not the e-mail owner, being a data subject, agrees to receive the newsletter. The personal data collected as part of subscribing to the newsletter will only be used for the purposes of distributing our newsletter.
To our existing buyers and registered users, we send updates regarding our services and products based on legitimate interest, in accordance with the Act on Electronic Communications. The data is used for buyer segmentation and profiling based on their past purchases and expressed and determined interests. By processing the data, personalized content is achieved, and products and services can be customized for each individual buyer (for instance, based on previous purchases, future buyer purchases can be predicted, and relevant content can be sent to the buyer. Additionally, if certain products are left in the shopping cart without finalizing the purchase, a message can be sent to the user). Furthermore, we send registered users updates on Franck Club benefits, as well as information about points and the duration of specific promotions.
To manage newsletter subscriptions and distribution, Franck uses Salesforce platform and related processors providing IT and data storage services (Agilcon and Amazon AWS), as instructed by us, and takes all necessary data protection measures. The system records newsletter openings and clicks on links in order to offer statistical data on which content is interesting to newsletter recipients.
You can opt out of the newsletter at any time by selecting the option of withdrawing your consent within the newsletter received or by using the gdpr@franck.eu contact address provided for privacy and personal data protection matters. If you withdraw your consent, this shall not affect the lawfulness of the processing completed prior to such withdrawal. Receiving of the newsletter is voluntary and the data subject shall not be responsible for any adverse consequences if he denies or withdraws his consent.
In case you withdraw your consent, you will no longer receive our newsletter and the canceled e-mail addresses will remain on our unsubscribe list for up to 5 years following the opt-out date to demonstrate Franck’s compliance with the obligations imposed on it under the applicable law.
3. Webshop and Franck Club
For the purpose of shopping in the webshop using our website, the buyer should enter his personal data: full name, address, e-mail address, optionally phone/mobile phone number, date of birth and interests. If the user does not provide a mobile phone number during making a purchase on the webshop, they will be required to enter a contact phone/mobile number that will be used for contract fulfilment. The contact number will be forwarded to the delivery service for product shipment.
By proceeding to make a purchase/registration, the buyer confirms his acceptance of the General Terms and Conditions and the Privacy Policy available on our website.
Buyers’ personal data provided at the time of purchasing shall be processed for the purpose of performing the contract, including prior verification of the conditions precedent to entry into the contract, and for the purpose of conducting the payment transaction and delivering the product and personalization of direct marketing communication to the buyer and adjustment of the product and service offer according to the buyer's interests.
In accordance with our General Terms and Conditions, buyer data is also used for membership in the Franck Club, where buyers accumulate points based on their purchases and spend points to convert them to certain products. For this purpose, data related to orders, points, discount amounts, points tier, and buyer interests are processed. Regarding each order, the following data is processed: order date, order ID, total price, and earned points.
The data is analyzed for the purpose of monitoring buyer’s interests, sending promotional messages to buyers, personalizing the buyer’s experience and purchase, segmenting and profiling buyers based on purchases made in retail stores, webshop and in the Snogoo application and analysis of interests provided by the user, as well as interests based on their past purchases and clicks on newsletters and website, leading to the creation of a specific user profile. For example, based on user behavior, purchases, newsletter opens, and link clicks, buyers can be categorized into interest groups (loyal, highly interested, not interested, etc.). User profiles are generated through automated data processing in an artificial intelligence-based system, which utilizes specific algorithms to provide predictions about the buyer's future engagement in the form of probabilities or percentages.
We use the buyer's date of birth data to send birthday greetings to the buyer along with a certain number of points added to their account. It is also used for age verification to ensure that the buyer is a legal adult, in accordance with the General Terms and Conditions.
Based on the buyer's email address, buyer data is integrated from the Snogoo application with data from the webshop. The data is used for the accumulation and utilization of points.
During registration, Franck uses the Google reCAPTCHA system to verify if the form submission is being done by a human. In this process, Google, in accordance with its Privacy Policy, may collect data such as network identifiers and clicks within the information system.
Personal data shall also be processed for the purpose of preventing any abuse, fraud, and for the purpose of informing buyers of news and offerings, in accordance with the legitimate interest and in compliance with the Electronic Communications Act.
Buyers are required to provide accurate, current and complete personal data. In order to register on our webshop, a person must be of legal age and have legal capacity. In case this obligation is violated, Franck may deny such user access to or refuse to supply him with all or part of the services and products offered by it. The provision of the service is conditional upon the processing of personal data for contract performance purposes, which may as such not be restricted or revoked. In case the buyer refuses to provide his personal data, which are marked as mandatory, he shall not be able to enter into a contract or make any purchase. In case a buyer does not wish to become a registered user or a member of the Franck Club, they can proceed with their purchase as a guest buyer.
Users can manage their personal data and interests within their user profiles. However, to prevent misuse, users cannot independently change their email address and date of birth. They can contact customer support for assistance with such modifications.
During the checkout process, the buyer has the option to save their card details for easier future transactions. If the buyer chooses to save their card details, it is considered as providing consent for such saving. However, the buyer has the right to withdraw their consent for saving card details. They can do so by either clicking the button to delete card data during the next transaction or by contacting via email at info@shop.franck.eu. Please note that the card data will not be accessible to Franck but will be securely stored in an encrypted format within the information system of the service provider who is in charge of the so-called payment gateway i.e. for executing online transactions securely.
The accepted payment methods include MasterCard, Visa, and Maestro. In addition, transactions can be made using Keks Pay account. Franck has entrusted the security of card payments to Monri Payments Ltd., with a registered office at Ulica grada Vukovara 269F, Zagreb, Croatia, VAT No-: 82551932122. When selecting this payment method, the buyer directly accesses a secure SSL connection where they enter the payment card details. This connection is protected with a minimum of 128-bit encryption protocols, ensuring security against identity theft and fraud. Franck does not have access to the provided card data. After completing the form, the buyer confirms the transaction and completes the ordering process. A confirmation email is then sent to the provided email address. The charged amount may be equal to or less than the authorized amount if, for any reason, it is not possible to deliver all the ordered products. In such cases, the buyer will be notified accordingly.
The Seller shall not disclose or transmit any buyers’ personal data except for the purpose of performing the product purchase contract (which pertains to financial institutions through which payments are made, making secure online purchases, business banks, suppliers of the purchased product for accounting, supply and delivery purposes, and persons responsible for maintaining the IT system used to conduct purchase transactions), protecting buyers’ interests, and to prevent any abuse. Franck uses the Salesforce platform and related processors that provide IT and data storage services (Agilcon, 404 Agency and Amazon AWS). Such personal data shall also be provided to the competent authorities if so required by them by operation of the law.
Personal data shall be retained as long as the user is registered on the webshop. After deleting the profile, the buyer’s data is stored for the period defined by the applicable law, which is presently up to 11 years following the expiry of the year in which the transaction is performed. Transaction and purchase data is also retained in accordance with applicable law, which is presently up to 11 years following the expiry of the year in which the transaction is performed.
For any questions or complaints regarding the webshop, deletion of data and management of profile data, buyers may contact the Contact Center at info@shop.franck.eu or at 01 3710 300.
The legal ground for data processing is a legal obligation because Franck is required to communicate with its consumers and respond to complaints and instructions in accordance with the applicable law. In case you refuse to provide your information, we will not be able to handle your complaint or query. Personal data shall be retained for up to 5 years of the resolution of the request/inquiry.
4. Queries and complaints
Our website contains forms and information that will allow you to contact us quickly and you can also communicate directly with us using the 0800 33 44 33 toll free line every day between 8 a.m. and midnight or contact us at info@franck.eu.
Our contact center partner Margon Media d.o.o., Avenija Većeslava Holjevca 60, 10 000 Zagreb, is responsible for such direct communication and provision of information and this company acts as the processor under its agreement with Franck, acts solely as instructed by us and takes all necessary data protection measures.
If a user contacts the controller or processor by e-mail or using a contact form, the personal data submitted by him will be automatically stored and processed exclusively for the purpose of providing the requested information. The legal ground for data processing is a legal obligation because Franck is required to communicate with its consumers and respond to complaints and instructions in accordance with the applicable law. In case you refuse to provide your information, we will not be able to handle your complaint or query.
The personal data necessary to resolve a complaint shall be retained for up to 5 years from the date of resolution of the request/complaint, in compliance with the regulations applicable to consumer rights.
5. Open job applications
Franck receives open job applications through its e-mail address specified on the website. For this purpose, the processing involves the personal data of a job applicant which he voluntarily specified in the application and CV (full name, date of birth, contact particulars, prior work experience, professional qualifications, education degree, photograph). The same e-mail address is used to receive job applications from students for job vacancies advertised via the Student Service.
Such open applications are received by an employee of the Human Resources Department who saves them in the relevant folders within the information system. Only authorized persons and processors authorized by Franck for providing IT support are allowed access to open job applications.
The data you send us through open job applications are processed based on legitimate interest and solely for the purpose of recruiting new employees and are retained for 12 months.
6. Job vacancies
In the course of the recruitment process, the job description is defined and a job vacancy is published using the relevant service providers for the purpose of recruiting new employees. Depending on the job description, job vacancies are advertised through different facilities. All data are collected and processed in TalentLyft.
Franck receives job applications and, for this purpose, the processing involves the personal data of a job applicant which he voluntarily specified in the application and CV (full name, date of birth, contact particulars, prior work experience, professional qualifications, education degree, photograph). Depending on the job description, Franck also conducts professional and psychological tests and interviews for the purpose of selecting job applicants.
Such data are retained until the job vacancy is finalized, but no more than one year following the finalization date of the job vacancy provided that if a candidate’s data are desired to be retained for another job vacancy, consent must be obtained from such candidate. Participation in job vacancies is voluntary and candidates’ data are processed as activities preceding the execution of an employment contract.
If a candidate gives his consent to the retention of his data after the job vacancy is completed, such data may be retained for up to 2 years. If a candidate voluntarily provides his data for future job vacancies, he may at any time withdraw his consent without suffering any adverse consequences. Such withdrawal of consent does not affect the lawfulness of the processing completed up to the time of such withdrawal.
Only authorized persons are allowed access to data concerning job applicants. Psychological tests are conducted by a person duly licensed to conduct psychological tests and the interview with the psychologist and psychological tests are conducted in accordance with the applicable law.
7. Promotional prize contests and prize competitions
We occasionally organize prize contests and prize competitions. We only process the personal data collected as part of this for the purpose of conducting such contests or competitions (e.g. publication of the winners’ names for the purpose of contacting them, delivering the prizes, etc.). To allow you to participate in a prize contest or competition, we need your full name, e-mail address, contact phone, and address for prize delivery. If necessary, we may request further information as defined by the rules of the prize contest or competition (e.g. your account number). Participation in such prize contests and competitions is voluntary. If a participant refuses to provide his personal data, he will not be able to participate in the prize contest or competition.
The participant may withdraw his consent to participate. Such withdrawal of consent will not affect the lawfulness of the processing completed up to the time of such withdrawal.
We will erase the data collected 12 months after the prize contest or competition is completed. We retain the information and written report concerning the winners in accordance with the relevant accounting regulations (we are presently allowed to retain them for 11 years following the end of the relevant year). We forward such data to our processors with whom we have processing contracts in place and to postal service providers.
In all prize contest or prize competition rules, we explain in detail how personal data are processed and the participant is invited to consult the privacy policies of the social networks where a particular prize competition is announced.
If you agree to receive our newsletter in a prize contest or competition registration form, you can opt out of the newsletter at any time by selecting the option of withdrawing your consent within the newsletter received or by using the gdpr@franck.eu contact address provided for privacy and personal data protection matters.
8. Data tracking – Cookies and web analytics
Franck stores “cookies” in your computer, which contain information about the user and are used to the save user’s time while using Franck’s website and for the purpose of tracking and directing user’s interests and providing services adapted to each user.
Many cookies contain the so-called cookie ID. Such cookie ID is a unique identifier of the cookie. It comprises a series of characters whereby websites and servers may be assigned to a specific web browser in which the cookie is stored.
By using cookies, Franck is able to provide users of its website with a user-friendly experience that would not be possible to achieve without using cookies. Once the user accesses the website, the cookie is stored in the user’s computer system.
Necessary cookies (e.g. cookies used to register a product in the cart) are stored on the user's terminal equipment for the purpose of providing a service at the user’s request in accordance with the Act on Electronic Communications, whereas the storage of any unnecessary cookies (e.g. cookies for advertising and analytics or functional cookies) requires data subject’s consent which may be given using the cookie management window.
Below please find a description of the cookies we use on the website:
Name of cookie | Duration of cookie | Purpose | More information | Website / microsite | Classification |
_ga | 2 years | User by Google Analytics to differentiate users. | Google Analytics Cookie Usage | .franck.eu; .jubilarna.franck.eu | Statistics |
_gat_UA-56115183-11 | 2 minutes | User by Google Analytics to differentiate users. | Google Analytics Cookie Usage | .franck.eu | Statistics |
_gat_UA-56115183-1 | 1 minute | User by Google Analytics to differentiate users. | Google Analytics Cookie Usage | .franck.eu | Statistics |
_gat_UA-56115183-12 | 2 minutes | User by Google Analytics to differentiate users. | Google Analytics Cookie Usage | .franck.eu | Statistics |
_gat_UA-56115183-13 | 2 minutes | User by Google Analytics to differentiate users. | Google Analytics Cookie Usage | .franck.eu | Statistics |
_dc_gtm_UA-46339619-6 | xx | xx | xx | .jubilarna.franck.eu | xx |
_gid | 24 hours | Used for user identification. | Google Analytics Cookie Usage | .franck.eu; .jubilarna.franck.eu | Statistics |
cookies_accepted | xx | xx | xx | .franck.eu | xx |
csrftoken | xx | xx | xx | bianka.franck.eu; capsules.franck.eu | Mandatory cookies |
sessionid | xx | xx | xx | bianka.franck.eu | Mandatory cookies |
APISID, HSID, LOGIN_INFO, SAPISID, SID, SSID | 2 years | Used for collecting data about page visits and YouTube video viewing. | Google Privacy policy | jubilarna.franck.eu capsules.franck.eu |
Functional cookies |
CONSENT | 20 years and 1 mmonth | Used for collecting data about page visits and YouTube video viewing. | Google Privacy policy | jubilarna.franck.eu capsules.franck.eu |
Functional cookies |
NID | 6 months | Used for collecting data about page visits and YouTube video viewing. | Google Privacy policy | jubilarna.franck.eu capsules.franck.eu |
Functional cookies |
PREF, VISITOR_INFO1_LIVE | 8 months | Used for collecting data about page visits and YouTube video viewing. | Google Privacy policy | jubilarna.franck.eu capsules.franck.eu |
Functional cookies |
SIDCC | 3 months | Used for collecting data about page visits and YouTube video viewing. | Google Privacy policy | jubilarna.franck.eu capsules.franck.eu |
Functional cookies |
YSC | Until the end of the page visit | Used for collecting data about page visits and YouTube video viewing. | Google Privacy policy | jubilarna.franck.eu capsules.franck.eu |
Functional cookies |
Google Double Click (e.g. DSID, NID, ANID, IDE) | 6 - 13 months | Used to show you relevant ads. They serve to prevent the same ad from appearing again and ensure that ads are delivered correctly based on your preferences. | Google Privacy policy | .franck.eu | Advertising cookies |
Depending on the user's settings, Google services via YouTube may also use other cookies, such as the VISITOR_INF01_LIVE cookie for advertising.
Franck also utilizes collect.js, a JavaScript technology, to track products added to the shopping cart in the webshop. This technology is necessary to provide information society services upon user request, in accordance with the Act on Electronic Commerce and the Act on Electronic Communications. If the user does not complete the transaction, Franck, as per the General Terms and Conditions, sends an email notification to the user stating that there are products in the cart for which the purchase has not been finalized. After completing the purchase, the collect.js script is automatically deleted.
The user may at any time disable cookies on our website by selecting the relevant setting of the web browser being used, and may thus permanently disable cookies. Furthermore, enabled cookies may be erased at any time using the web browser or other software. If the user disables cookies in the web browser used, all functions on our website may not be fully available.
Franck uses cookies to track website traffic and obtain the necessary website performance information and in this process also uses the services of a third party of Google, as a processor, named Google Analytics. Franck also uses cookies to advertise Franck products both on the website and on display networks, and third parties (including Google services Google Double Click i Google AdWords, Google Ad services, Google Tag Manager) display Franck’s advertisements in cooperation with Franck on websites across the internet. Data processed for the stated purposes include IP address, browser type, set language, request time, cookie identifier. It is Google's practice to delete IP address data after 9 months and cookie data after 18 months.
Please note that you can disable Google Analytics for advertising on the display network and adjust ads for Google Display Network using the Ad Settings Manager tool (http://www.google.com/settings/ads).
Franck collects information that does not identify a specific end user, including the URL (Uniform Resource Locator) of the page that the user visits before opening the website www.franck.eu and related microsites, URL of the website that is visited by the user after leaving Franck’s website, the type of browser used by the user, and anonymized user’s IP address (Internet Protocol Address). Authorized service providers and advertisers may automatically collect such information when you visit Franck’s website or by using cookies or other tools. Franck only uses such information for problem solving, to administer its website, to analyze trends, to collect demographic information, to analyze its compliance, or in cooperation with the relevant law enforcement authorities. Personal data is transferred outside the EU/EEA based on standard contractual clauses for the transfer of personal data to third countries approved by the European Commission.
9. Social networks
Franck uses social networks and channels to process data concerning persons following the published content, liking our posts and leaving their comments. Franck collects data about its social network contacts for the purpose of sending promotions to specific target groups (anonymized information including gender, age, etc.). Franck uses Facebook Business Tools, Instagram Business and LinkedIn Marketing Solutions and Tik Tok Ads tools. The information we send is information concerning your social network activities collected based on clicks and cookies, including but not limited to: information about your devices, your purchases, the advertisements viewed by you or how you use the services (e.g. whether or not you have a Facebook account, whether or not you are logged in, etc.). In relation to personal data processing for such marketing purposes, such social networks are considered to be joint controllers with Franck. These data are transferred outside the EU/EEA based on standard contractual clauses for the transfer of personal data to third countries approved by the European Commission. For further information about personal data processing by such social networks, please read the Privacy Policy – Facebook, Linkedin, Youtube, Instagram,Tik Tok. You can find more details about Facebook Ireland as a joint controller, the purposes of data processing, Facebook products, and data subjects' rights at the following link https://www.facebook.com/about/privacy.
10. Business cooperation
Franck processes the personal data of its business partners and personal data provided to Franck by its business partners, which are necessary for the uninterrupted conduct of daily business, invoicing and performance of legal and contractual obligations (e.g. directors’ and contact persons’ names, IBAN, PIN (OIB)).
Franck processes data for the purpose of undertaking its commercial activities, selecting contractors and entering into and performing contracts. Data will be processed for the purpose of performing legally defined obligations (including tax and accounting obligations, obligations arising from public tendering or occupational safety regulations, for supplier qualification purposes), for contract administration, for receiving goods and/or services, for the conduct of judicial proceedings, for internal audit purposes (security, productivity, product quality, preservation of financial integrity), for management control purposes, and for certification purposes. The processing of data for such purposes requires no consent from the data subject because the legal ground for such personal data processing is a contractual obligation/pre-contractual measure. Such collection of data is required because otherwise, Franck will not be able to enter into a contract or duly perform its relevant obligations.
11. Recording or photographing of events
Subject to a legitimate interest, we record and photograph public events we organize or participate in as a sponsor. For such purposes, we publish on our website and social networks photographs and recordings of people participating in such events. For the purposes of such recording and photographing, we engage processors acting as instructed by us.
No consent is required for this purpose because such photographing and recording does not override data subjects’ rights and freedoms, for example, if no publicly exposed person is involved, if a person is photographed merged in a group of other people, and certain photographs may be blurred or trimmed to achieve a balance between our legitimate interest in promoting our events and data subjects’ rights.
12. Data export
Franck forwards personal data to its processors. Franck conducts investigations in the process of selecting its processors and checks that they use adequate controls to protect personal data. Franck enters into a processing contract with each processor. Data are exported from the EU/EEA with the conclusion of standard data protection clauses approved by the European Commission.
Such personal data may, subject to the purposes specified above, be disclosed to:
- entities that need them to fulfill an order, deliver a parcel, send mail and e-mail, analyze data, process payments, or provide customer services, being our consultant.
- processors providing or maintaining IT solutions and providing data storage services (Agilcon, 404, Salesforce, Google, Microsoft, Jira and Amazon).
- law enforcement authorities and other public authorities if required by the applicable law or in good faith (e.g. to inform them of our compliance with the relevant legislation, to protect and defend our rights or property; or to have them act to protect service users’ personal safety in an emergency).
- social networks and advertisers in the manner described in this Privacy Policy (section 9),
- Cloudinary platform for saving and processing images for websites. Images are stored on Amazon servers owned by Cloudinary. Personal data is transferred outside the EU/EEA based on standard contractual clauses for the transfer of personal data to third countries approved by the European Commission.
- Google for the purpose of updating and enabling Google fonts on the page in case a certain font is not stored locally on our server, Google analytics and cookies and Google re-captcha services. For this purpose, Google processes certain data, such as the IP address of the user of the site and makes requests from third parties on the site. Personal data is transferred outside the EU/EEA based on standard contractual clauses for the transfer of personal data to third countries approved by the European Commission with additional protective measures.
13. Personal data protection measures
Franck implements appropriate technical and security measures for the purpose of ensuring the security and confidentiality of personal data and to prevent any unauthorized access to or unauthorized use of personal data or any technical equipment used by Franck. In case of a security incident, which is considered to be a personal data breach under the General Data Protection Regulation, Franck will conduct a risk assessment and, based on its results, take the necessary actions and notify the supervisory authority and data subjects.
To be able to take the necessary technical and integral data protection measures in our business, we:
- ensure, based on advice from our data protection officer, that only the personal data necessary for each purpose are processed according to the relevant settings;
- ensure, based on advice from our data protection officer, that only the personal data necessary for each purpose are processed according to the relevant settings;
- ensure, based on advice from our data protection officer, that only the personal data necessary for each purpose are processed according to the relevant settings;
- ensure, based on advice from our data protection officer, that only the personal data necessary for each purpose are processed according to the relevant settings;
- ensure, based on advice from our data protection officer, that only the personal data necessary for each purpose are processed according to the relevant settings;
14. Data subject’s rights
The data subject may at any time request from us information about the processing of his personal data and may, subject to the applicable law, request to exercise the following rights:
- right of access to personal data;
- right to rectification or supplementation of personal data;
- right to data erasure;
- right to restrict of personal data processing, for example, if the accuracy of the personal data is challenged and verification is necessary;
- right to withdraw consent to data processing;
- right to object to the processing of his personal data;
- right not to be subject to an automated decision with legal effect (this right does not apply to processing based on consent, contract and legal obligation).
The data subject may also object to a legitimate interest in the field of direct marketing.
The data subject has the right to lodge a complaint with the supervisory authority, with the Personal Data Protection Agency at www.azop.hr.
15. Applicable law and transfer of assets
All matters concerning this Privacy Policy shall be governed by the law of the Republic of Croatia. In the course of our business, we may sell or purchase certain assets. If another company acquires Franck or part of our assets, the personal data collected by us may be transferred to such a company.
16. Severability
If any provision of this Privacy Policy is held or declared invalid, illegal or unenforceable, such provision shall not apply to the extent it is invalid or unenforceable, whereas the remaining provisions shall continue in full force and effect.
17. Modifications and updates of this Privacy Policy
Franck reserves the right to modify or update this Privacy Policy at any time without prior notice. Please check for any modifications or updates of our Privacy Policy from time to time on the website, where the updated effective date of this Privacy Policy will appear.