Privacy policy of the Varaždin Concert Office

Privacy policy of the Varaždin Concert Office


This Privacy Statement is an integral part of the General Terms and Conditions of the Varaždin Concert Office, which owns the Internet store

In accordance with the General Regulation on the Protection of Personal Data (GDPR), this Privacy Statement describes how Koncertni ured Varaždin, A.Cesarca 1, 42000 Varaždin (hereinafter the Controller) processes the personal data of the User Internet store (hereinafter referred to as Internet store).

The statement refers to the confidentiality of personal data collected in the process of the User’s purchase and/or registration on the Internet store and the acceptance of receiving notifications about products and actions from the Internet store. The processing manager, as an Internet store service provider, complies with applicable regulations with the aim of protecting the privacy of its Users. Any User who has any questions regarding personal data can send an e-mail to the following address: [email protected]. More detailed information about the Data Controller is available at the following internet link KONTAKT.


A user is any customer, recipient of notifications and/or visitor to the Internet store who, on any basis and in any way, decides to share their personal data with the Data Controller and agrees to their processing. Users of the Internet store are obliged to read and familiarize themselves with this Privacy Statement in order to better understand what data the Data Controller collects and processes, for what purpose, based on what legal basis, with whom and why it is shared, what protective measures it implements, and what rights each User has access to personal data, correction, deletion and the right to object. Providing personal data is the exclusive decision of the User. If the User does not want to provide the requested personal data, and the same is mandatory for the implementation of certain activities within the Internet store (e.g. conclusion of a contract at a distance, data for sending or order confirmation), the same will not be implemented.


In order for the User to automatically conclude a contractual relationship at a distance, which is the basis for the purchase of products and services of the User’s choice on the Internet store, which is contained in the General Terms and Conditions, the User must:

  • enter your personal data as part of the online store
  • double confirm the correctness of your e-mail address
  • confirm acceptance of the General Business Terms and Privacy Statement (by clicking)
  • confirm that the User is over 18 years old

The processing of all the User’s personal data is legal because actions are taken at the request and with the consent of the User in order to realize the following activity:

  • purchase of products and services as ordered by the User
  • conclusion of a contract at a distance in which the Data Controller and the User are contractual parties
  • receiving notifications about products and promotions

By accepting this Privacy Statement by clicking during registration and/or shopping, or by registering the User to the Internet store and/or accepting the receipt of notifications about products and promotions from the Internet store, the User confirms that he has read, understood and agrees with the processing of personal data as this Statement establishes them.

Since we understand how important your privacy is to each of you and the way in which your data is processed, we adopt the following privacy policy where we will explain when, why and how we collect personal data from people who visit our website or who ask us to contact them or contact us in any way.

These rules also state the conditions under which we may disclose this information to others and how we take care of its security.

You can read our privacy policy below. Please read them carefully to fully understand our position and practices regarding your personal data and how we treat it.


If you just browse our website, then we collect personal data in the form of your IP address. We collect such personal data, and in accordance with the GDPR, for security reasons such as preventing DDos attacks, hacking, fraud and the like, which is our legitimate interest as a data controller.

The principles we apply in our business, which relate to the protection of personal data, are as follows:

  • We do not sell your personal data.
  • We never share your personal data with a third party for third party marketing purposes.
  • We take care of the security of your personal data using strict encryption, complying with all regulations on the protection of personal data and applying the highest security IT standards.
  • To receive our newsletters, we ask for your express consent (opt-in) and you can withdraw your consent (opt-out) at any time using the “Unsubscribe” link found in every e-mail message sent.

In the premises of the Varaždin Concert Office and in other storage systems owned by the Varaždin Concert Office, personal data that we use in our business, and which we obtained during live communication, by signing contracts or exchanging messages via e-mail, can be found.

They are as follows: First and last name and maiden name, stage name, residential address, postal address if it is different from the residential address, gender, date, place and country of birth, MBG or no. identity cards, OIB, e-mail address, telephone numbers, data for payment of compensation (IBAN giro account and bank), data on pension insurance status, data on tax status (VAT system and/or business bookkeeping), data on membership in professional associations, data on performing capacity, data on instruments used in recordings (only for instrumentalists), data on orchestra/group membership with date of joining, data on previous engagements in orchestra/group with start and end dates, and copies of the passport if the police require it from us, and we are talking about foreign citizens from outside the European Union.

The Varaždin Concert Office uses personal data for the following purposes: Processing of employee salaries, recruitment, ticket sales, production of printed marketing materials, space supervision, employee education, medical examination, preparation of bids for public tenders, official trips, company websites, conclusion of various types of standard contracts, provision of customer services and responding to inquiries we receive via our contact forms, the sending of useful information and marketing material.


A cookie is a small file that is saved on your computer or mobile device when you visit a certain website. Cookies are used to remember your actions and settings for a certain period. By continuing to use our website, you consent to the use of cookies. You can also block cookies, however if you set your internet browser settings to block all cookies you may not be allowed access to all or some parts of our websites. If you do not set your browser settings to reject cookies, our system will send cookies as soon as you visit our website.


We store personal data on our own servers in our own business premises in the Republic of Croatia.

If any of the associations with which we cooperate for the protection of performance rights are located outside the territory of the European Economic Area, we will take all necessary measures to ensure that your personal data is secure and treated in accordance with this privacy policy and the General Regulation on the Protection of Personal Data.

By sending your personal data, you consent to the processing of that data outside the borders of the European Economic Area. Furthermore, your personal data will be forwarded and available to processors with whom the Varaždin Concert Office has signed contracts in accordance with the positive regulations of the Republic of Croatia and the previously mentioned Decree on the Protection of Personal Data.


All data collected physically (permits, contracts, powers of attorney and other documentation necessary for work) are stored in accordance with appropriate security standards. After being received physically, they are sometimes scanned for digital storage. All systems containing personal data are constantly monitored to detect possible vulnerabilities and attacks and are stored in accordance with the highest IT standards, which are taken care of by our staff in charge of IT security.


Taking into account the purpose of data collection, the Varaždin Concert Office stores your data as long as it is provided for by certain positive regulations valid on the territory of the Republic of Croatia or the Ordinance on the storage of documents (Regulations on the storage, use, selection and removal of archival and registry materials of the Varaždin Concert Office) as well as an additional 3-year statute of limitations for compensation claims. At the end of the mentioned retention periods, we delete, destroy and store your personal data in accordance with the opinion obtained by the state archive or anonymize them so that they can no longer be linked to anyone. You can request data deletion at any time by emailing [email protected].


With regard to the activity of the Varaždin Concert Office, we share your personal data with our processors, various associations and artistic organizations with whom we cooperate in organizing concerts and musical-stage performances for the needs of the City of Varaždin and music associations from the City and County. With all of them, the Varaždin Concert Office has concluded appropriate contracts that contain provisions on the protection of personal data.


We send the newsletter by e-mail only if we have your express consent. You can revoke your consent to receive such messages at any time by clicking on the unsubscribe link at the bottom of the message. If you have problems with logging out, please contact us at [email protected]. In this case, we will immediately delete your data regarding the delivery of the newsletter.

To distribute the newsletter, we use the MailChimp system (trademark of Rocket Science Group, LLC, 675 Ponce De Leon Ave NE 5000, Atlanta, GA 30308, USA). MailChimp is compliant with the Privacy Shield agreement for data protection, and must comply with EU privacy rules. Privacy policy by MailChimp: will use your data only for the purpose of delivering the newsletter, evaluating delivery and improving the service. MailChimp will not contact you directly or use your information. They will not be forwarded to third parties. The data used by MailChimp includes a “web beacon” that sends information to MailChimp about the opening of the newsletter and/or the activation of links within the newsletter. In this process, information about your Internet browser, your IP address and your location will be sent to MailChimp.


Koncetni ured Varaždin / Concert office Varaždin will disclose or share your personal data only in order to fulfill a legal obligation, or in order to exercise our rights or yours or to ensure safety. This includes the exchange of information with public authorities, including judicial authorities, and with companies and organizations to prevent information fraud and security breaches.


On our websites and we can place links to the websites of our business partners. If you follow any of those sites, please note that their own privacy policies apply to those websites and that the Varaždin Concert Office has no responsibility for those policies, and bears no responsibility for the accuracy of the information, the content of those sites, or the results that can be obtained by using them.


According to the OUZP, as of May 25, 2018, you have the following rights:

1. the right to restriction of processing
2. right of access
3. right to erasure (right to be forgotten)
4. right to correction
5. right to portability
6. the right to object

You can exercise all of the above rights by contacting us (see below how to contact us). No administrative fee will be charged for considering and/or complying with a request based on one of the aforementioned rights, unless it is repetitive, unnecessary or requires excessive effort.


You can make requests related to this Privacy Policy in the following ways:

  • via e-mail [email protected]
  • on weekdays from 8:00 a.m. to 3:00 p.m. on phone number +385 42/212-907
  • by mail to the address A. Cesarca 1, 42 000 Varaždin


If you are not satisfied with the way we handle your personal data, you have the right to contact the Agency for the Protection of Personal Data (AZOP) via the following link:

By accessing and using these websites, you accept and submit to Croatian substantive law as the sole authority for the interpretation, application and legal effects of all permissions, exclusions, and conditions of use. For all claims and disputes that arise as a result of the use of the website of the Varaždin Concert Office or in connection with them, the Croatian courts are exclusively competent.

This document must be amended if the number or structure of employees changes significantly, or if the Varaždin Concert Office changes its business policy.

This policy is effective on May 25, 2018.