{"id":9457,"date":"2022-05-24T13:31:28","date_gmt":"2022-05-24T11:31:28","guid":{"rendered":"https:\/\/m-chanaan.hr\/?page_id=9457"},"modified":"2022-06-08T14:26:23","modified_gmt":"2022-06-08T12:26:23","slug":"privacy-policy","status":"publish","type":"page","link":"https:\/\/m-chanaan.hr\/en\/privacy-policy\/","title":{"rendered":"Privacy Policy"},"content":{"rendered":"<p><strong>Protecting Your Personal Information <\/strong><br \/>\nM Chanaan ltd respects your privacy and handles your personal information in accordance with the General Data Protection Regulation (GDPR Regulation EC 2016\/679 ).<\/p>\n<p>We store your personal information electronically, and for the purpose of protection we apply the appropriate technical and organizational measures procedures and the protection of personal data in order to prevent unauthorized access to your personal information.<\/p>\n<p>Your personal information that you make available to us is only kept for a period that is sufficient to meet the initial purpose of collecting them. You are authorized at any time to request information about which personal information you have in our email base, as well as request that we change all or some personal information (Right to Correction) or delete it (Right to Forgive).<\/p>\n<p>You will do so by contacting us via the contact address info@m-chanaan.hr and provide us with a notification of your request that we will act within the statutory deadline. We do not deliver your personal information to other recipients except by the statutory principle and your explicit consent.<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Pursuant to EU Regulation 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free<\/span><\/p>\n<p><span style=\"font-weight: 400;\">movement of such data, and repealing Directive 95\/46\/EC &#8211; General Data Protection Regulation (Official Journal of the European Union L 119\/1 of 04 May 2016, hereinafter GDPR and applicable laws of the Republic of Croatia governing data protection, the Management Board of the Company <\/span><b>M. Chanaan<\/b><span style=\"font-weight: 400;\"> d.o.o. Pore\u010d, Istarskog razvoda 7, OIB: 64240260474, in the role of Head of Personal Data, <\/span>on 15 May 2018<span style=\"font-weight: 400;\"> issues the<\/span><\/p>\n<p>&nbsp;<\/p>\n<h1 style=\"text-align: center;\"><b>INTERNAL ORDINANCE ON THE PROTECTION OF PERSONAL DATA\u00a0<\/b><\/h1>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><span style=\"font-weight: 400;\">Article 1<\/span><\/p>\n<p><b>PURPPOSE<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The purpose of this Ordinance is to standardize and prescribe the rules related to the protection of natural persons with regard to the processing of personal data and rules related to the free movement of personal data within the company, in order to protect fundamental rights and freedoms of natural persons, especially their right to personal data protection.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Standardization and prescribing of procedures refer to the procedures of collecting, processing, storing, adapting or modifying, forwarding and\/or destroying personal data of data subjects, the rights and obligations of the manager and executor of processing and rights of data subjects.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><span style=\"font-weight: 400;\">Article 2<\/span><\/p>\n<p><b>MEANING OF TERMS AND PRINCIPLES\u00a0<\/b><\/p>\n<p><b>(1)\u00a0 Meaning of terms<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Certain terms used in the drafting of this Ordinance and accompanying acts have the following meanings:<\/span><\/p>\n<p><b>\u201ePersonal data\u201d<\/b><span style=\"font-weight: 400;\"> &#8211; means all data relating to a natural person whose identity has been or can be established.<\/span><\/p>\n<p><b>\u201eData subject\u201d &#8211; <\/b><span style=\"font-weight: 400;\">natural person whose identity can be established is a person who can be identified directly or indirectly, in particular by means of identifiers such as name, identification number, location data, network identifier or by one or more factors specific to physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.<\/span><\/p>\n<p><b>\u201eProcessing\u201d &#8211; <\/b><span style=\"font-weight: 400;\">means any operation or set of operations performed on personal data or on sets of personal data, whether automated or non-automated, such as collection, recording, organization, structuring, storage, adaptation or modification, retrieval, inspection, use, transmission, disseminating or otherwise making available, harmonizing or combining, restricting, deleting or destroying;<\/span><\/p>\n<p><b>\u201eRecords of processing activities\u201c <\/b><span style=\"font-weight: 400;\">(hereinafter: Records) &#8211; each controller and executor of the processing keeps a Record of personal data at his or her disposal and with which he is in contact. Each Processing Manager and Executor should keep the Records under his or her responsibility in order to prove compliance with the GDPR Regulation, cooperate with the supervisory body and provide it, upon request, with access to the Records.<\/span><\/p>\n<p><b>\u201eRestriction of processing\u201d<\/b><span style=\"font-weight: 400;\"> &#8211; means the marking of stored personal data with the aim of limiting their processing in the future.<\/span><\/p>\n<p><b>\u201eProfiling\u201d &#8211; <\/b><span style=\"font-weight: 400;\">means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&#8217;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements of that natural person.\u00a0<\/span><\/p>\n<p><b>\u201ePseudonymisation\u201d<\/b><span style=\"font-weight: 400;\"> means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.\u00a0<\/span><\/p>\n<p><b>\u201eFiling system\u201d<\/b><span style=\"font-weight: 400;\"> means any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.\u00a0<\/span><\/p>\n<p><b>\u201eController\u201d &#8211; <\/b><span style=\"font-weight: 400;\">\u00a0means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.\u00a0<\/span><\/p>\n<p><b>\u201eProcessor\u201d &#8211; <\/b><span style=\"font-weight: 400;\">means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;.<\/span><\/p>\n<p><b>\u201eRecipient\u201d &#8211; <\/b><span style=\"font-weight: 400;\">means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.\u00a0<\/span><\/p>\n<p><b>\u201eThird party\u201d &#8211; <\/b><span style=\"font-weight: 400;\">means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.<\/span><\/p>\n<p><b>\u201eConsent\u201d of the data subject &#8211; <\/b><span style=\"font-weight: 400;\">means any freely given, specific, informed and unambiguous indication of the data subject&#8217;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her. Data subject has the right to withdraw his or her consent at any time. The conditions of consent are laid down in Article 7 of the GDPR Regulation.<\/span><\/p>\n<p><b>\u201eLegitimate interests\u201c\u00a0 &#8211; <\/b><span style=\"font-weight: 400;\">means the legitimate interest of the controller may be the legal basis for processing and represent activities related to the sale of goods or services on the market and the need to collect data to identify potential customers or service users, direct marketing activities where it collects personal data, provided that the interests or the fundamental rights and freedoms of the data subject do not take precedence, taking into account the reasonable expectations of the data subject based on their relationship with the controller.<\/span><\/p>\n<p><b>\u201ePersonal data breach\u201d &#8211;<\/b><span style=\"font-weight: 400;\"> means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.<\/span><\/p>\n<p><b>\u201eGenetic data\u201d &#8211;<\/b><span style=\"font-weight: 400;\"> means personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question.<\/span><\/p>\n<p><b>\u201eBiometric data\u201d &#8211; <\/b><span style=\"font-weight: 400;\">means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data.<\/span><\/p>\n<p><b>\u201eDana concerning health\u201d &#8211; <\/b><span style=\"font-weight: 400;\">\u00a0means personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status;.<\/span><\/p>\n<p><b>\u201eMain establishment\u2019 \u201d<\/b><span style=\"font-weight: 400;\"> &#8211; means:\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">(a) as regards a controller with establishments in more than one Member State, the place of its central administration in the Union, unless the decisions on the purposes and means of the processing of personal data are taken in another establishment of the controller in the Union and the latter establishment has the power to have such decisions implemented, in which case the establishment having taken such decisions is to be considered to be the main establishment;\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">(b) as regards a processor with establishments in more than one Member State, the place of its central administration in the Union, or, if the processor has no central administration in the Union, the establishment of the processor in the Union where the main processing activities in the context of the activities of an establishment of the processor take place to the extent that the processor is subject to specific obligations under this Ordinance;.<\/span><\/p>\n<p><b>\u201eRepresentative\u201d &#8211; <\/b><span style=\"font-weight: 400;\">means a natural or legal person established in the Union who, designated by the controller or processor in writing pursuant to Article 27, represents the controller or processor with regard to their respective obligations under this Ordinance;.<\/span><\/p>\n<p><b>\u201eEnterprise\u201d &#8211; <\/b><span style=\"font-weight: 400;\">means a natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity.<\/span><\/p>\n<p><b>\u201eGroup of undertakings\u201d &#8211; <\/b><span style=\"font-weight: 400;\">means a controlling undertaking and its controlled undertakings.<\/span><\/p>\n<p><b>\u201eBinding corporate rules\u201d &#8211; <\/b><span style=\"font-weight: 400;\">means personal data protection policies which are adhered to by a controller or processor established on the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings, or group of enterprises engaged in a joint economic activity.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0<\/span><b>\u201eSupervisory authority\u201d<\/b><span style=\"font-weight: 400;\"> means an independent public authority which is established by a Member State pursuant to Article 51 of the GDPR Regulation.<\/span><\/p>\n<p><b>\u201eConcerned supervisory authority\u201d<\/b><span style=\"font-weight: 400;\"> means a supervisory authority which is concerned by the processing of personal data because:\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">(a) the controller or processor is established on the territory of the Member State of that supervisory authority;\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">(b) data subjects residing in the Member State of that supervisory authority are substantially affected or likely to be substantially affected by the processing; or<\/span><\/p>\n<p><span style=\"font-weight: 400;\">(c) a complaint has been lodged with that supervisory authority.<\/span><\/p>\n<p><b>\u201eCross-border processing\u201d &#8211;<\/b><span style=\"font-weight: 400;\"> means either:\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">(a) processing of personal data which takes place in the context of the activities of establishments in more than one Member State of a controller or processor in the Union where the controller or processor is established in more than one Member State; or<\/span><\/p>\n<p><span style=\"font-weight: 400;\">(b) processing of personal data which takes place in the context of the activities of a single establishment of a controller or processor in the Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State..\u00a0<\/span><\/p>\n<p><b>\u201eRelevant and reasoned objection\u201d &#8211; <\/b><span style=\"font-weight: 400;\">means an objection to a draft decision as to whether there is an infringement of this Ordinance, or whether envisaged action in relation to the controller or processor complies with this Ordinance, which clearly demonstrates the significance of the risks posed by the draft decision as regards the fundamental rights and freedoms of data subjects and, where applicable, the free flow of personal data within the Union.\u00a0<\/span><\/p>\n<p><b>\u201eInformation society service\u201d<\/b><span style=\"font-weight: 400;\"> means a service as defined in point (b) of Article 1(1) of Directive (EU) 2015\/1535 of the European Parliament and of the Council (1).<\/span><\/p>\n<p><b>\u201eInternational organisation\u201d<\/b><span style=\"font-weight: 400;\"> means an organisation and its subordinate bodies governed by public international law, or any other body which is set up by, or on the basis of, an agreement between two or more countries.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>(2) Meaning of principles<\/b><\/p>\n<p>&nbsp;<\/p>\n<p><b>Principles relating to processing of personal data <\/b><span style=\"font-weight: 400;\">should respect the fundamental rights and freedoms of the natural person, and in particular the right of the natural person to the protection of personal data regardless of the nationality or residence of the natural person.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Pursuant to the Art. 5, the GDPR Regulation binds to the following principles in the processing of personal data:<\/span><\/p>\n<ol>\n<li><b>a) lawfulness, fairness and transparency, <\/b><span style=\"font-weight: 400;\">whereas processing shall be lawful only if and to the extent that at least one of the following applies:<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>The data subject has given consent <\/b><span style=\"font-weight: 400;\">to the processing of his or her personal data for one or more specific purposes,<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>processing is necessary for the performance of a contract <\/b><span style=\"font-weight: 400;\">to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract,<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li aria-level=\"1\"><span style=\"font-weight: 400;\">processing is necessary for <\/span><b>compliance with a legal obligation to which the controller is subject,<\/b><\/li>\n<\/ul>\n<ul>\n<li aria-level=\"1\"><span style=\"font-weight: 400;\">processing is necessary in order <\/span><b>to protect the vital interests of the data subject or of another natural person,<\/b><\/li>\n<\/ul>\n<ul>\n<li aria-level=\"1\"><span style=\"font-weight: 400;\">processing is necessary <\/span><b>for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller,<\/b><\/li>\n<\/ul>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">processing is necessary for the purposes of the <\/span><b>legitimate interests pursued by the controller or by a third party<\/b><span style=\"font-weight: 400;\">, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><b>The principle of lawfulness of processing <\/b><span style=\"font-weight: 400;\">&#8211; legal obligation to process personal data for which no special consent of the data subject is required (e.g. records on employees that the employer is obliged to keep according to the provisions of the Labour Act and other records that include data prescribed by applicable laws of the Republic of Croatia such as: data on exercising the right of natural persons to pension and health insurance, data determining tax and other obligations and sim.).<\/span><\/p>\n<p>&nbsp;<\/p>\n<ol>\n<li><b>b) Purpose limitation, <\/b><span style=\"font-weight: 400;\">is the principle meaning that personal data must be collected for specific, explicit and lawful purposes and may not be further processed in a way that is not in accordance with those purposes.<\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li><b>c) Data minimisation <\/b><span style=\"font-weight: 400;\">is the principle meaning that personal data must be adequate, relevant and <\/span><span style=\"font-weight: 400;\">limited to what is necessary in relation to the purposes for which they are processed<\/span><span style=\"font-weight: 400;\">.<\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li><b>d) Accuracy, <\/b><span style=\"font-weight: 400;\">is the principle meaning that every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.<\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li><b>e) Storage limitation, <\/b><span style=\"font-weight: 400;\">personal data must be kept in a form which permits identification of data subjects <\/span><span style=\"font-weight: 400;\">for no longer than is necessary for the purposes for which the personal data are processed<\/span><span style=\"font-weight: 400;\">. Personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the GDPR Regulation in order to safeguard the rights and freedoms of the data subject.<\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li><b>f) Integrity and confidentiality, <\/b><span style=\"font-weight: 400;\">personal data <\/span><span style=\"font-weight: 400;\">must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.<\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li><b>g) Accountability <\/b><span style=\"font-weight: 400;\">is the principle meaning that <\/span><span style=\"font-weight: 400;\">the controller shall be responsible for, and be able to demonstrate compliance with all the above-mentioned principles.<\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><span style=\"font-weight: 400;\">Article 3<\/span><\/p>\n<p><b>RIGHTS OF THE DATA SUBJECT<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The data subject has the right to inspect the collection of personal data. The most important data subject rights are as follows:<\/span><\/p>\n<ul>\n<li><b> transparency<\/b><span style=\"font-weight: 400;\"> (Art. 12\u201314 of the GDPR Regulation): providing information when collecting personal data when the Controller must, among other information, <\/span><span style=\"font-weight: 400;\">inform the data subject about his identity and contact data, purposes of processing and legal basis for data processing, Recipients, export to third countries, storage period, withdrawal, deletion and destruction of data,<\/span><\/li>\n<li><b>access to personal data <\/b><span style=\"font-weight: 400;\">(Art. 15 of the GDPR Regulation): obtain confirmation from the controller whether personal data relating to him or her are being processed and, if so, access to personal data and information, inter alia, on personal data processed, purpose of processing, storage period, export to third countries, deletion and data destruction<\/span><span style=\"font-weight: 400;\">,<\/span><\/li>\n<li><b>right to rectification <\/b><span style=\"font-weight: 400;\">(Art. 16 of the GDPR Regulation): <\/span><span style=\"font-weight: 400;\">the data subject has the right to request the correction of inaccurate personal data relating to him, and taking into account the purposes of processing, the data subject has the right to supplement incomplete personal data, including by giving an additional statement<\/span><span style=\"font-weight: 400;\">;<\/span><\/li>\n<li><b>erasure \u2013 right to be forgotten<\/b><span style=\"font-weight: 400;\"> (Art. 17 of the GDPR Regulation): <\/span><span style=\"font-weight: 400;\">data subject has the right to obtain from the controller the deletion of personal data relating to him without undue delay and the Controller has the obligation to delete personal data without undue delay if, inter alia, personal data are no longer necessary for the purpose of processing, data subject has withdrawn consent for processing, personal data have been illegally processed and sim.<\/span><\/li>\n<li><b>right to restriction of processing <\/b><span style=\"font-weight: 400;\">(Art. 18 of the GDPR Regulation): in certain situations (for example when the accuracy of the data is disputed or when the right to delete the data subject wants the Controller to keep his data) the data subject has the right to request that processing be limited to storage and some other types of processing;<\/span><\/li>\n<li><b>right to data portability <\/b><span style=\"font-weight: 400;\">(Art. 20 of the GDPR Regulation): the data subject has the right to receive his personal data, previously provided to the controller, in a structured form and in a commonly used and machine-readable format, and has the right to transfer this data to another controller without interference by the controller to whom personal data are provided, if processing is carried out automatically and based on consent or contract;<\/span><\/li>\n<li><b>right to object<\/b><span style=\"font-weight: 400;\"> (Art. 21 of the GDPR Regulation): <\/span><span style=\"font-weight: 400;\">data subject has the right to object to the processing of personal data if it is based on tasks of public interest, the exercise of official powers of the controller or the legitimate interests of the controller (including profiling), then the Controller may no longer process personal data unless proves that his legitimate reasons for processing go beyond the interests of the data subject and to protect legal claims, also if the data subject opposes processing for direct marketing purposes, personal data may no longer be processed<\/span><span style=\"font-weight: 400;\">;<\/span><\/li>\n<li><b>right to object to automated individual decision-making &#8211; profiling <\/b><span style=\"font-weight: 400;\">(Art. 22 of the GDPR Regulation): <\/span><span style=\"font-weight: 400;\">the data subject has the right not to be subject to a decision based solely on automated processing, including the creation of a profile, which produces legal effects relating to him or similarly significantly affecting him, unless such a decision is necessary for the conclusion or execution of the contract between the data subject and the data controller, if permitted by EU or national law, which prescribes appropriate measures to protect the rights and freedoms and legitimate interests of the data subject or based on the express consent of the data subject<\/span><span style=\"font-weight: 400;\">.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">With this Ordinance, the Controller acquaints the data subject with the scope of collection and purposes of personal data processing, risks, principles of personal data processing, rules, safeguards and rights related to personal data processing and how to exercise his or her rights regarding processing.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><span style=\"font-weight: 400;\">Article 4<\/span><\/p>\n<p><b>The Controller, all its employees, natural and legal persons working for and on behalf of, undertake to comply with the GDPR Regulation and this Ordinance <\/b><span style=\"font-weight: 400;\">relating to all activities involving the processing of personal data including data on users of goods and services, customers, employees, suppliers and other partners, as well as all other data processed by the Controller from any source.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">A third party cannot access personal data that is processed without a previously concluded contract\/confidentiality statement.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>The Controller may select a Processor <\/b><span style=\"font-weight: 400;\">with whom he is obliged to enter into a contract on the processing of personal data which clearly defines the obligations of the Processor and which is in accordance with the GDPR Regulation<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><span style=\"font-weight: 400;\">Article 5<\/span><\/p>\n<p><b>SCOPE OF PERSONAL DATA COLLECTION<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Personal data is collected solely <\/span><b>on the basis of the purpose limitation principle and the legitimate right<\/b><span style=\"font-weight: 400;\"> of the Controller and may not be collected and processed in a manner inconsistent with those purposes.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">The processed personal data will be used exclusively for the following purposes:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Salary calculation, employee records, bookkeeping, accounting and tax purposes,<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Execution of contracts,<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Legitimate interest, and<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Consent.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Special categories of data do not need neither are allowed to be collected.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><span style=\"font-weight: 400;\">Article 6<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The processing of personal data implies <\/span><b>the identification of the legal basis<\/b><span style=\"font-weight: 400;\"> before the processing of personal data. Processing is lawful if and to the extent that at least one of the following is met:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The data subject has given consent to the processing of his or her personal data for one or more special purposes,<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Processing is <\/span><b>necessary for the execution of the contract<\/b><span style=\"font-weight: 400;\"> to which the data subject is a party or in order to take action on the data subject&#8217;s request before concluding the contract,<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Processing is <\/span><b>necessary in order to comply with the legal obligations of the Controller,<\/b><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Processing is <\/span><b>necessary to protect the key interests of the data subject <\/b><span style=\"font-weight: 400;\">or other natural person,<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Processing is <\/span><b>necessary for the legitimate interests<\/b><span style=\"font-weight: 400;\"> of the Controller or a third party, except when those interests are stronger than the interests or fundamental rights and freedoms of the data subject that require the protection of personal data, especially if the data subject is a child.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><span style=\"font-weight: 400;\">Article 7<\/span><\/p>\n<p><b>STORAGE AND PROCESSING OF PERSONAL DATA<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The controller must not keep personal data that can identify an individual <\/span><b>longer than the time required to fulfill the purpose<\/b><span style=\"font-weight: 400;\"> for which the data was collected and the time specified by law.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The head of personal data will store the processed personal data <\/span><b>in accordance with the legal obligation to keep<\/b><span style=\"font-weight: 400;\"> documentation, after which he will delete personal data (automated processing) and destroy (written records).<\/span><\/p>\n<p><b>Processing<\/b><span style=\"font-weight: 400;\"> can be <\/span><b>manual<\/b><span style=\"font-weight: 400;\"> (written record) <\/span><b>and automated<\/b><span style=\"font-weight: 400;\"> (PC and IT infrastructure).<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><span style=\"font-weight: 400;\">Article 8<\/span><\/p>\n<p><b>SECURITY OF PROCESSING<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The controller of personal data, for the purpose of security of processing and storage, takes appropriate organizational and technical measures.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">All employees of the controller and other persons working for and on behalf of the Controller are responsible for the security of all personal data that the Controller owns and processes.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Data should be <\/span><b>kept in a secure place<\/b><span style=\"font-weight: 400;\"> that prevents unauthorized access to personal data.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For this reason, all personal information must be kept:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">In a <\/span><b>locked<\/b><span style=\"font-weight: 400;\"> room with controlled access,<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">In a <\/span><b>locked<\/b><span style=\"font-weight: 400;\"> drawer or closet,<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">In the case of digital data, it must be <\/span><b>password protected<\/b><span style=\"font-weight: 400;\">, and<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Stored on <\/span><b>encrypted<\/b><span style=\"font-weight: 400;\"> computer media.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Written records must not be left in rooms accessible to unauthorized persons and may not be removed from the safe area without written permission.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Hard disks (HD) of computers that are no longer in use must be destroyed.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><span style=\"font-weight: 400;\">Article 9<\/span><\/p>\n<p><b>DEFINING ORGANIZATIONAL AND TECHNICAL MEASURES<\/b><\/p>\n<p><span style=\"font-weight: 400;\">It is the responsibility of the Controller to ensure accurate and up-to-date data of the data subject. Data kept by the Controller must be regularly updated and must not be kept if not accurate and up-to-date.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Personal data must be fit for purpose, relevant and limited in accordance with the framework necessary for processing according to defined obligations.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">The controller does not collect data that is not necessarily necessary to fulfil the purpose for which it was collected.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">The controller is obliged to provide organizational and technical measures to protect data from unauthorized access. Organizational measures are the procedures by which data are collected and processed, and technical measures are the procedures for storing personal data.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Organizational and technical measures The controller defines and records in the Record of processing activities by categories of data subject after the categorization and risk analysis.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">The following documents are an integral part of this Ordinance:<\/span><\/p>\n<ol>\n<li><span style=\"font-weight: 400;\"> Categorization and analysis of the current situation,<\/span><\/li>\n<li><span style=\"font-weight: 400;\"> Risk analysis,<\/span><\/li>\n<li><span style=\"font-weight: 400;\"> List of measures,<\/span><\/li>\n<li><span style=\"font-weight: 400;\"> Records of processing activities,<\/span><\/li>\n<li><span style=\"font-weight: 400;\"> Consent form,<\/span><\/li>\n<li><span style=\"font-weight: 400;\"> Confidentiality Statement.<\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li><b> Categorization and analysis of the current situation &#8211; <\/b><span style=\"font-weight: 400;\">in order to comply with the GDPR Regulation, the responsible person of the Processing Manager or the person to whom the delegation is delegated should make a categorization and analysis of the current situation in which at least the following should be identified;\u00a0<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data processing category,<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Source and basis of data collection,<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Method of recording,<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Type of processing,<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Method of processing and shelf life, and<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data Forwarding and Recipients.<\/span><\/li>\n<\/ul>\n<ol start=\"2\">\n<li><b> Risk analysis \u2013 <\/b><span style=\"font-weight: 400;\">a document that should contain a clear description of the processing operations that the Controller estimates may be risky.<\/span><\/li>\n<li><b> List of measures \u2013 <\/b><span style=\"font-weight: 400;\">is a document that should contain a list of risk points of processing, if any, and organizational and technical measures for each category of data processing.<\/span><\/li>\n<li><b> Records of processing activities <\/b><span style=\"font-weight: 400;\">is a key document, derived from the previously described procedures 1-2-3, which the Controller constantly monitors throughout the year and, if necessary, supplements the organizational and technical measures if he assesses that the rights of the data subject may be endangered.<\/span><\/li>\n<li><b> Consent form <\/b><span style=\"font-weight: 400;\">is a document by which the Controller receives written consent from the data subject for the processing of his data relating to employees, customers and suppliers and parents.<\/span><\/li>\n<li><b> Confidentiality Statement \u2013 <\/b><span style=\"font-weight: 400;\">is a document prepared by the Controller for employees within the company who directly collect and process personal data and who sign the statement.<\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><span style=\"font-weight: 400;\">Article 10<\/span><\/p>\n<p><b>Privacy policy<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The controller undertakes to protect personal data under the GDPR Regulation, recognizing the importance of protecting the privacy, security and data protection of service users and all persons who come into contact with the controller.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>Purpose of collecting personal data<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In accordance with the principle of limited purpose, personal data is collected solely to ensure the provision of the requested data subject service and the most efficient response to inquiries and for business purposes.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>Data covered by the Privacy Policy system<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The data covered by the privacy policy are as follows: Name and surname, date of birth, residential address, e-mail, telephone and\/or fax number, personal identification number (OIB). Other data may be collected only with the written consent of the data subject.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>Confidentiality of data<\/b><\/p>\n<p><span style=\"font-weight: 400;\">All personal data remains confidential, including data provided by the data subject by e-mail by which identification is possible. Such data is used only for the purpose of fulfilling the requirements of the data subject and the Controller is obliged to keep it secret in the storage system in accordance with the principle of storage restriction. The protection of the data of the data subject is permanent.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>Legitimate interest<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The controller defines its legitimate interest as the right to collect available data from potential customers from the Internet and other publicly available sources, respecting the principles of limiting the purpose and reducing the amount of data, provided that the interests or fundamental rights and freedoms of the subject matter to request the data subject, delete the collected data from its records.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">The legitimate interest we pursue is:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Marketing, and<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performing our activity.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><span style=\"font-weight: 400;\">Article 11<\/span><\/p>\n<p><strong>RESPONSIBILITY OF THE CONTROLLER<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">The responsibilities of the controller are as follows:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with the GDPR Regulation and, accordingly, carry out the activities referred to in Article 4 of this Ordinance,<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Respect and enforce the data subject referred to in Article 3 of this Ordinance,<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Instruct the processor to act in accordance with the provisions of this Ordinance, including additional restrictions if any, by a special legal act regulating the relationship with the processor.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adhere to the principles of personal data processing specified in Art. 2 Par. 2 of this Ordinance.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implement the privacy policy.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><span style=\"font-weight: 400;\">Article 12<\/span><\/p>\n<p><b>PENAL PROVISIONS<\/b><\/p>\n<p><span style=\"font-weight: 400;\">This Ordinance regulates penal provisions only in the part related to the violation of the provisions of the Confidentiality Statement signed by the employees of the company.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">In case of violation of the provisions of the Privacy Statement by the employee, the responsible person of the personal data controller may impose a fine on the employee in the amount of 1\/3 of the net salary.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">In case of gross or repeated violation of the provisions of the Confidentiality Statement by the employee, the responsible person of the Personal Data Manager may give the employee written notice and terminate the employment contract.<\/span><\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<h2><b>Rights of the data subject<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">In accordance with the GDPR Regulation EC 2016\/679, we have regulated the rights of data subjects with whom we hereby introduce you.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">The data subject has the right to inspect the collection of personal data. The most important data subject rights are as follows:<\/span><\/p>\n<ul>\n<li><b> transparency<\/b><span style=\"font-weight: 400;\"> (Art. 12\u201314 of the GDPR Regulation): providing information when collecting personal data when the Controller must, among other information, <\/span><span style=\"font-weight: 400;\">inform the data subject about his identity and contact data, purposes of processing and legal basis for data processing, Recipients, export to third countries, storage period, withdrawal, deletion and destruction of data,<\/span><\/li>\n<li><b>access to personal data <\/b><span style=\"font-weight: 400;\">(Art. 15 of the GDPR Regulation): obtain confirmation from the controller whether personal data relating to him or her are being processed and, if so, access to personal data and information, inter alia, on personal data processed, purpose of processing, storage period, export to third countries, deletion and data destruction<\/span><span style=\"font-weight: 400;\">,<\/span><\/li>\n<li><b>right to rectification <\/b><span style=\"font-weight: 400;\">(Art. 16 of the GDPR Regulation): <\/span><span style=\"font-weight: 400;\">the data subject has the right to request the correction of inaccurate personal data relating to him, and taking into account the purposes of processing, the data subject has the right to supplement incomplete personal data, including by giving an additional statement<\/span><span style=\"font-weight: 400;\">;<\/span><\/li>\n<li><b>erasure \u2013 right to be forgotten<\/b><span style=\"font-weight: 400;\"> (Art. 17 of the GDPR Regulation): <\/span><span style=\"font-weight: 400;\">data subject has the right to obtain from the controller the deletion of personal data relating to him without undue delay and the Controller has the obligation to delete personal data without undue delay if, inter alia, personal data are no longer necessary for the purpose of processing, data subject has withdrawn consent for processing, personal data have been illegally processed and sim.<\/span><\/li>\n<li><b>right to restriction of processing <\/b><span style=\"font-weight: 400;\">(Art. 18 of the GDPR Regulation): in certain situations (for example when the accuracy of the data is disputed or when the right to delete the data subject wants the Controller to keep his data) the data subject has the right to request that processing be limited to storage and some other types of processing;<\/span><\/li>\n<li><b>right to data portability <\/b><span style=\"font-weight: 400;\">(Art. 20 of the GDPR Regulation): the data subject has the right to receive his personal data, previously provided to the controller, in a structured form and in a commonly used and machine-readable format, and has the right to transfer this data to another controller without interference by the controller to whom personal data are provided, if processing is carried out automatically and based on consent or contract;<\/span><\/li>\n<li><b>right to object<\/b><span style=\"font-weight: 400;\"> (Art. 21 of the GDPR Regulation): <\/span><span style=\"font-weight: 400;\">data subject has the right to object to the processing of personal data if it is based on tasks of public interest, the exercise of official powers of the controller or the legitimate interests of the controller (including profiling), then the Controller may no longer process personal data unless proves that his legitimate reasons for processing go beyond the interests of the data subject and to protect legal claims, also if the data subject opposes processing for direct marketing purposes, personal data may no longer be processed<\/span><span style=\"font-weight: 400;\">;<\/span><\/li>\n<li><b>right to object to automated individual decision-making &#8211; profiling <\/b><span style=\"font-weight: 400;\">(Art. 22 of the GDPR Regulation): <\/span><span style=\"font-weight: 400;\">the data subject has the right not to be subject to a decision based solely on automated processing, including the creation of a profile, which produces legal effects relating to him or similarly significantly affecting him, unless such a decision is necessary for the conclusion or execution of the contract between the data subject and the data controller, if permitted by EU or national law, which prescribes appropriate measures to protect the rights and freedoms and legitimate interests of the data subject or based on the express consent of the data subject<\/span><span style=\"font-weight: 400;\">.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<hr \/>\n<div style=\"text-align: center;\"><b>Contact details of the controller:<\/b><br \/>\n<b>The controller<\/b><span style=\"font-weight: 400;\">: M. Chanaan d.o.o.<\/span><b>\u00a0 <\/b><span style=\"font-weight: 400;\">Pore\u010d, Istarskog razvoda 7, OIB:\u00a0 64240260474\u00a0\u00a0<\/span><br \/>\n<b>Responsible person of the controller<\/b><span style=\"font-weight: 400;\">:\u00a0 Justyna Aleksandra Vuku\u0161i\u0107, director\u00a0<\/span><br \/>\n<b>Tel:<\/b><span style=\"font-weight: 400;\"> +385 (0)52-433-370<\/span><br \/>\n<b>E-mail:<\/b> <a href=\"mailto:miro@m-chanaan.hr\"><span style=\"font-weight: 400;\">info@m-chanaan.hr<\/span><\/a><\/div>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"size-medium wp-image-9497 aligncenter\" src=\"https:\/\/m-chanaan.hr\/wp-content\/uploads\/2022\/05\/PNG_GDPR-768x768.png\" alt=\"\" width=\"180\" height=\"180\" srcset=\"https:\/\/m-chanaan.hr\/wp-content\/uploads\/2022\/05\/PNG_GDPR-768x768.png 768w, https:\/\/m-chanaan.hr\/wp-content\/uploads\/2022\/05\/PNG_GDPR-154x154.png 154w, https:\/\/m-chanaan.hr\/wp-content\/uploads\/2022\/05\/PNG_GDPR-1536x1536.png 1536w, https:\/\/m-chanaan.hr\/wp-content\/uploads\/2022\/05\/PNG_GDPR-2048x2048.png 2048w, https:\/\/m-chanaan.hr\/wp-content\/uploads\/2022\/05\/PNG_GDPR-624x624.png 624w\" sizes=\"(max-width: 180px) 100vw, 180px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Protecting Your Personal Information M Chanaan ltd respects your privacy and handles your personal information in accordance with the General Data Protection Regulation (GDPR Regulation EC 2016\/679 ). We store your personal information electronically, and for the purpose of protection we apply the appropriate technical and organizational measures procedures and the protection of personal data [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v21.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Privacy Policy - M Chanaan - Business Consulting and real estate<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/m-chanaan.hr\/en\/privacy-policy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Privacy Policy - M Chanaan - Business Consulting and real estate\" \/>\n<meta property=\"og:description\" content=\"Protecting Your Personal Information M Chanaan ltd respects your privacy and handles your personal information in accordance with the General Data Protection Regulation (GDPR Regulation EC 2016\/679 ). We store your personal information electronically, and for the purpose of protection we apply the appropriate technical and organizational measures procedures and the protection of personal data [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/m-chanaan.hr\/en\/privacy-policy\/\" \/>\n<meta property=\"og:site_name\" content=\"M Chanaan - Business Consulting and real estate\" \/>\n<meta property=\"article:modified_time\" content=\"2022-06-08T12:26:23+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/m-chanaan.hr\/wp-content\/uploads\/2022\/05\/PNG_GDPR-768x768.png\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"24 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/m-chanaan.hr\/en\/privacy-policy\/\",\"url\":\"https:\/\/m-chanaan.hr\/en\/privacy-policy\/\",\"name\":\"Privacy Policy - M Chanaan - Business Consulting and real estate\",\"isPartOf\":{\"@id\":\"https:\/\/m-chanaan.hr\/en\/#website\"},\"datePublished\":\"2022-05-24T11:31:28+00:00\",\"dateModified\":\"2022-06-08T12:26:23+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/m-chanaan.hr\/en\/privacy-policy\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/m-chanaan.hr\/en\/privacy-policy\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/m-chanaan.hr\/en\/privacy-policy\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/m-chanaan.hr\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Privacy Policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/m-chanaan.hr\/en\/#website\",\"url\":\"https:\/\/m-chanaan.hr\/en\/\",\"name\":\"M Chanaan - Business Consulting and real estate\",\"description\":\"Tridesetogodi\u0161nje poslovno iskustvo i cijeli niz uspje\u0161nih projekata pozicionirali su M. Chanaan kao vode\u0107i konzaltin\u0161ki tim na podru\u010dju Istre i Pore\u0161tine.Vrhunski doma\u0107i i inozemni stru\u010dnjaci snaga su i prednost M. Chanaana. Investiranje u Hrvatsku i regiju, uz stru\u010dnu podr\u0161ku i zadovoljstvo klijenata \u2013 na\u0161a su misija.\",\"publisher\":{\"@id\":\"https:\/\/m-chanaan.hr\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/m-chanaan.hr\/en\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/m-chanaan.hr\/en\/#organization\",\"name\":\"M Chanaan - Business Consulting and real estate\",\"url\":\"https:\/\/m-chanaan.hr\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/m-chanaan.hr\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/m-chanaan.hr\/wp-content\/uploads\/2021\/06\/logo_mcn.png\",\"contentUrl\":\"https:\/\/m-chanaan.hr\/wp-content\/uploads\/2021\/06\/logo_mcn.png\",\"width\":173,\"height\":118,\"caption\":\"M Chanaan - Business Consulting and real estate\"},\"image\":{\"@id\":\"https:\/\/m-chanaan.hr\/en\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Privacy Policy - M Chanaan - Business Consulting and real estate","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/m-chanaan.hr\/en\/privacy-policy\/","og_locale":"en_US","og_type":"article","og_title":"Privacy Policy - M Chanaan - Business Consulting and real estate","og_description":"Protecting Your Personal Information M Chanaan ltd respects your privacy and handles your personal information in accordance with the General Data Protection Regulation (GDPR Regulation EC 2016\/679 ). We store your personal information electronically, and for the purpose of protection we apply the appropriate technical and organizational measures procedures and the protection of personal data [&hellip;]","og_url":"https:\/\/m-chanaan.hr\/en\/privacy-policy\/","og_site_name":"M Chanaan - Business Consulting and real estate","article_modified_time":"2022-06-08T12:26:23+00:00","og_image":[{"url":"https:\/\/m-chanaan.hr\/wp-content\/uploads\/2022\/05\/PNG_GDPR-768x768.png"}],"twitter_misc":{"Est. reading time":"24 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/m-chanaan.hr\/en\/privacy-policy\/","url":"https:\/\/m-chanaan.hr\/en\/privacy-policy\/","name":"Privacy Policy - M Chanaan - Business Consulting and real estate","isPartOf":{"@id":"https:\/\/m-chanaan.hr\/en\/#website"},"datePublished":"2022-05-24T11:31:28+00:00","dateModified":"2022-06-08T12:26:23+00:00","breadcrumb":{"@id":"https:\/\/m-chanaan.hr\/en\/privacy-policy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/m-chanaan.hr\/en\/privacy-policy\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/m-chanaan.hr\/en\/privacy-policy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/m-chanaan.hr\/en\/"},{"@type":"ListItem","position":2,"name":"Privacy Policy"}]},{"@type":"WebSite","@id":"https:\/\/m-chanaan.hr\/en\/#website","url":"https:\/\/m-chanaan.hr\/en\/","name":"M Chanaan - Business Consulting and real estate","description":"Tridesetogodi\u0161nje poslovno iskustvo i cijeli niz uspje\u0161nih projekata pozicionirali su M. Chanaan kao vode\u0107i konzaltin\u0161ki tim na podru\u010dju Istre i Pore\u0161tine.Vrhunski doma\u0107i i inozemni stru\u010dnjaci snaga su i prednost M. Chanaana. Investiranje u Hrvatsku i regiju, uz stru\u010dnu podr\u0161ku i zadovoljstvo klijenata \u2013 na\u0161a su misija.","publisher":{"@id":"https:\/\/m-chanaan.hr\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/m-chanaan.hr\/en\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/m-chanaan.hr\/en\/#organization","name":"M Chanaan - Business Consulting and real estate","url":"https:\/\/m-chanaan.hr\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/m-chanaan.hr\/en\/#\/schema\/logo\/image\/","url":"https:\/\/m-chanaan.hr\/wp-content\/uploads\/2021\/06\/logo_mcn.png","contentUrl":"https:\/\/m-chanaan.hr\/wp-content\/uploads\/2021\/06\/logo_mcn.png","width":173,"height":118,"caption":"M Chanaan - Business Consulting and real estate"},"image":{"@id":"https:\/\/m-chanaan.hr\/en\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/m-chanaan.hr\/en\/wp-json\/wp\/v2\/pages\/9457"}],"collection":[{"href":"https:\/\/m-chanaan.hr\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/m-chanaan.hr\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/m-chanaan.hr\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/m-chanaan.hr\/en\/wp-json\/wp\/v2\/comments?post=9457"}],"version-history":[{"count":12,"href":"https:\/\/m-chanaan.hr\/en\/wp-json\/wp\/v2\/pages\/9457\/revisions"}],"predecessor-version":[{"id":9540,"href":"https:\/\/m-chanaan.hr\/en\/wp-json\/wp\/v2\/pages\/9457\/revisions\/9540"}],"wp:attachment":[{"href":"https:\/\/m-chanaan.hr\/en\/wp-json\/wp\/v2\/media?parent=9457"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}