CHIRON Croatia d.o.o. (hereinafter “CHIRON Croatia”) takes your legitimate concerns regarding data protection very seriously and complies with the provisions of the General Data Protection Regulation (GDPR), the Croatian Act on the Implementation of the General Data Protection Regulation (Official Gazette No. 42/18), the Electronic Communications Act (Official Gazette No. 76/22, 14/24, 45/26), and the provisions of other applicable data protection regulations.
CHIRON Croatia handles the data you provide with care and diligence. To the extent that data of any kind is collected, processed, or used, this is always done in accordance with legal provisions or with your express consent.
The protection of privacy is of crucial importance for the future of internet-based business models and for the development of an internet-based economy. With this privacy policy, CHIRON Croatia underscores its commitment to the protection of privacy.
This Privacy Policy applies to this website and explains how CHIRON Croatia collects and uses your personal data, as well as your rights regarding the processing of your personal data.
Data Controller
The Data Controller determines the purposes and means of processing personal data and is responsible for the storage and use of personal data in paper and/or electronic format. Pursuant to Article 4(7) of the General Data Protection Regulation (GDPR) is:
CHIRON Croatia d.o.o.
with its registered office in Zadar, Zagrebačka ulica 100, Croatia,
registered in the court register of the Commercial Court in Zadar under the registration number (MBS): 060033740,
Personal Identification Number (OIB): 84339137481.
Email: info.croatia@chiron-group.com
Phone: +385 23 205 405
Global Data Protection Standards
Our handling of personal data is aligned with global principles and standards regarding transparency in the use of personal data, the observance and granting of rights of choice, access regulations, rules on data integrity, data security, data transfer, and the monitoring of the lawfulness of processing. CHIRON Croatia complies in particular with the General Data Protection Regulation (GDPR).
Consent
By using this website, you consent to the electronic storage and use of your data as described below. Changes to this privacy policy will always be announced on this page so that you are always informed about what data the CHIRON Croatia stores and how it is used.
Where applicable data protection law requires it, we will also expressly request your consent for the further processing of personal data collected on this website or provided by you.
Where processing is based on consent, we retain your data until such consent is withdrawn. You have the right to withdraw your consent at any time. You may notify us of the withdrawal of your consent by email or by mail. Such withdrawal shall not affect the lawfulness of processing based on consent before its withdrawal.
Collection and Processing of Personal Data
CHIRON Croatia would like to better understand your needs and interests and provide you with optimal service. Therefore, CHIRON Croatia collects and uses personal information in the manner described below and in accordance with applicable data protection laws.
When you visit our website, we collect your IP address and use cookies and other internet technologies (hereinafter referred to as “automated tools” and “embedded web links”) to gather general information about our website visitors and their interests. Below, we explain which technologies are used and what types of information are collected through them.
In addition, we collect and process data that you voluntarily provide to us, for example when you share such data with us through the contact form available on our website.
What data do we collect and why?
CHIRON Croatia uses the collected data to provide you with consistent, personalized support. CHIRON Croatia uses your data exclusively as described in this statement or at the time of collection. Any subsequent change in the purpose of use is subject to your express consent, unless the change is otherwise justified by applicable laws.
We process your data for the following purposes, among others:
IP Addresses
When you access the website, certain information, such as your IP address, may be collected. This data is collected to analyse malfunctions, for website administration, and to obtain demographic information. Furthermore, we use IP addresses and, where applicable, other information you have provided to us on this website to determine which pages of our offering are accessed and which topics interest our visitors. We use the insights to provide you with an optimized range of information about our products and services. Such data is generally collected only in anonymized form. When you visit our website, only the domain name is collected by default.
CHIRON Croatia collects data only in connection with your visit to this website.
Cookies
a) We use cookies on our website(s). These are small files that your browser automatically creates and that are stored on your device (laptop, tablet, smartphone, etc.) when you visit our websites. Cookies do not cause any damage to your device and do not contain viruses, Trojans, or other malware. Information is stored in the cookie that relates to the specific device being used. However, this does not mean that we thereby gain direct knowledge of your identity. The use of cookies serves, on the one hand, to make the use of our services more convenient for you. For example, we use so-called session cookies to recognize that you have already visited individual pages of our websites. These are automatically deleted after you leave our site.
b) In addition, we also use temporary cookies to optimize user-friendliness; these are stored on your device for a specific, predetermined period. If you visit our website again to use our services, the system automatically recognizes that you have previously visited us and recalls the entries and settings you made, so you do not have to re-enter them.
c) We also use cookies to statistically track the use of our website and to evaluate it for the purpose of optimizing our offering for you. These cookies enable us to automatically recognize that you have already visited our website when you return. These cookies are automatically deleted after a defined period of time.
d) The cookies process data and are necessary for the aforementioned purposes to safeguard our legitimate interests as well as those of third parties pursuant to Art. 6(1)(f) of the GDPR.
e) Most browsers automatically accept cookies. However, you can configure your browser so that no cookies are stored on your computer or so that a notification always appears before a new cookie is created. However, completely disabling cookies may prevent you from using all features of our website.
Cookie management on this website
When you visit our website for the first time, a cookie banner will appear at the bottom. In the options, only necessary cookies, which are essential for the operation of the website, are pre-checked. You can enable statistical cookies yourself if you wish (more under the "Analytical Tools" section).
Cookie settings can be changed at any time by clicking on the "Cookie Settings" link at the bottom of the website. Clicking this link deletes existing cookies and reopens the cookie banner.
Cookie Name |
Provider / System |
Cookie Purpose |
Duration |
Type |
winter_session |
Winter CMS |
Necessary cookie: Used for the technical functioning of the website and maintaining your current server session. It is saved automatically upon entering the website. |
Until the browser is closed (Session) |
Technical (Necessary) |
cookie_settings |
Consent system |
Necessary cookie: Remembers the exact settings and categories of cookies (e.g., statistical) that you have chosen to receive. |
1 year |
Technical (Necessary) |
_ga |
Google Analytics |
Statistical cookie: Used to distinguish unique users and anonymously track website visit statistics. It is loaded exclusively with your consent. |
Up to 2 years |
Statistical |
_ga_JMYRV61D6N |
Google Analytics |
Statistical cookie: Used to maintain session state and track user activity within the Google Analytics tool. It is loaded exclusively with your consent. |
Up to 2 years |
Statistical |
Email Addresses
If you provide us with your email address or enter it via the contact form, we will also contact you by email. We will not share your email address with third parties, unless otherwise stated in this privacy policy.
Use of external service providers
We work with service providers who process certain data on our behalf. This is done exclusively in accordance with applicable data protection laws. In particular, we have entered into data processing agreements with our service providers that meet the requirements of Article 28 of the GDPR.
Disclosure of Personal Data
Your personal data will not be transferred to third parties for purposes other than those listed below. We will only disclose your personal data to third parties if:
a) you have given your express consent pursuant to Art. 6(1)(a) GDPR,
b) the disclosure is necessary pursuant to Article 6(1)(f) of the GDPR to assert, exercise, or defend legal claims, and there is no reason to assume that you have an overriding legitimate interest in the non-disclosure of your data,
c) in the event that there is a legal obligation for the disclosure pursuant to Article 6(1)(c) of the GDPR, and
d) this is legally permissible and, pursuant to Article 6(1)(b) of the GDPR, is necessary for the performance of a contractual relationship with you or for pre-contractual measures at your request.
No transfer to a third country or an international organization is intended, and no automated decision-making, including profiling, takes place, unless otherwise provided for below in this privacy policy.
If necessary, information may also be shared with business partners, service providers, third parties, or subcontractors. This may be necessary to provide a service or transaction you have requested, such as order processing, for customer service purposes, or to inform you about services or products.
Your personal data will not be shared, sold, or otherwise made available to third parties for marketing purposes without your prior consent.
CHIRON Croatia may be required to disclose your data and related information pursuant to a court order or government agency directive. We also reserve the right to use your data to assert or defend against legal claims.
In the event of an acquisition or merger with another company, disclosure or transfer of personal data to potential or actual buyers may be necessary. In such a case, CHIRON Croatia will strive to ensure the highest possible level of data protection.
In accordance with applicable law, we reserve the right to store and disclose personal and other data to detect and combat illegal activities, fraud attempts, or violations of CHIRON Croatia‘s Terms of Use.
Data Transfer to Third Countries
The adoption of the European General Data Protection Regulation (GDPR) has established a uniform framework for data protection in Europe. Your data is therefore primarily processed by companies to which the GDPR applies. Should processing nevertheless take place via third-party services outside the European Union or the European Economic Area, these must meet the specific requirements of Articles 44 et seq. of the GDPR. This means that processing is carried out on the basis of specific safeguards, such as the EU Commission’s official recognition of an adequate level of data protection comparable to that of the EU, or compliance with officially recognized specific contractual obligations, known as “Standard Contractual Clauses.”
Analytics Tools
Tracking measures are used solely for the purpose of website optimization, improving user experience, and analyzing website traffic. The legal basis for processing this data is your explicit consent pursuant to Article 6(1)(a) of the GDPR. You grant your consent by actively accepting statistical cookies via the cookie banner upon your first visit to our website.
Privacy Policy for the Use of Google Analytics
This website uses Google Analytics, a web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google Analytics uses text files called "cookies," which are stored on your device to help us analyse how users navigate this site.
Through this tool, we collect anonymized data regarding your behaviour on the website, including the pages you visit and the time spent on them, technical details such as browser type, operating system, and screen resolution, as well as an approximate geographic location based on your anonymized IP address.
More detailed information on how Google handles and protects data can be found at the following link: https://policies.google.com/privacy?hl=hr
The following separate regulations apply to in-house trade fair events:
Consent Form for Photography and/or Videography
I hereby consent to the taking of photos and/or videos of me, as a client/customer, for promotional purposes and to their publication
- The CHIRON Croatia website and social media channels (LinkedIn, YouTube, etc.)
- as presentations for trade shows, seminars, and similar events
- as part of a report, including in the press (e.g., newspapers)
- in publications (both online and in print), e.g., informational brochures, flyers, etc.
may be used and stored for this purpose. The photos and/or videos are intended solely for promotional purposes.
I am aware that photos and/or videos on the Internet can be accessed by anyone. Despite all technical precautions, it cannot be ruled out that such persons may reuse the photos and/or videos or pass them on to others.
CHIRON Croatia shall not be held liable, nor shall there be any right to damages, in connection with the use of this website by third parties, such as in the event of the downloading of photographs and their subsequent use by such persons.
For the photographing of an individual visitor of an event who is singled out from a crowd in a manner that allows their identity to be unequivocally established, and the use of such photograph for promotional purposes, the lawful legal basis is consent, pursuant to Article 6(1)(a) of the GDPR.
I do not derive any rights (e.g., remuneration) from the consent to publication. The consent as well as the provision of the photographs and/or video recordings is provided free of charge.
I have read and understood the information regarding the processing of personal data provided in this form, pursuant to Article 13 of the GDPR.
This declaration of consent is voluntary and may be revoked at any time with future effect by notifying CHIRON Croatia. If the recordings are available on the Internet, they will be removed to the extent that this is possible for CHIRON Croatia.
Privacy Notice Regarding the Creation and Use of Photographic and/or Video Recordings in accordance with Article 13 of the GDPR
1. Name and contact details of the controller:
CHIRON Croatia d.o.o.
with its registered office in Zadar, Zagrebačka ulica 100, Croatia,
registered in the court register of the Commercial Court in Zadar under the registration number (MBS): 060033740,
Personal Identification Number (OIB): 84339137481.
Email: info.croatia@chiron-group.com
Phone: +385 23 205 405
2. Purpose of processing:
The photos and/or videos are used exclusively for advertising purposes by CHIRON Croatia.
3. Legal basis for processing:
The processing of photos and/or videos (collection, storage, and disclosure to third parties (see section 5)) is based on the explicit consent of the legal guardian(s) or the data subject(s),
and is therefore in accordance with Article 6(1)(a) of the GDPR.
4. Categories of recipients of personal data:
The photos and/or videos will not be disclosed to third parties.
The publication of selected image and video files is limited to promotional activities in (print) publications as well as on their website and social media channels
(such as YouTube, LinkedIn, etc.) or similar platforms.
5. Duration of storage of personal data:
Photos and/or videos taken for the company’s promotional purposes will be stored for an indefinite period for the specified purpose, subject to the data subject’s withdrawal of consent.
6. Right to withdraw consent:
Consent to the processing of photos and/or videos may be revoked at any time with future effect. The lawfulness of data processing carried out on the basis of consent up until the time of revocation remains unaffected by this revocation.
7. Data subject rights:
Under the General Data Protection Regulation, you have the following rights:
a) If your personal data is processed, you have the right to obtain information about the data stored regarding you. (Art. 15 GDPR)
b) If incorrect personal data is being processed, you have the right to
correction (Art. 16 GDPR)
c) If the legal requirements are met, you may request the erasure or restriction of processing, as well as object to the processing
(Art. 17, 18, 21 GDPR)
d) If you have consented to the data processing or a contract for data processing exists and the data processing is carried out using automated means, you may have a right to data portability (Art. 20 GDPR)
Should you exercise the aforementioned rights, the controller will verify whether the legal requirements for doing so are met.
Links to social media platforms and other websites
This website may, only in exceptional cases, contain links to third-party websites, such as links leading to our official profile on the social network LinkedIn (operated for EU users by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland) and our channel on the YouTube platform (operated for EU users by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland).
Merely visiting our website does not establish a connection to the servers of these platforms. Data transmission occurs only if you actively click on the button or link of these platforms. At that moment, your browser opens the external page of the respective platform, and they become independent controllers of your data. This privacy policy applies only to this website; therefore, when visiting another website, it is necessary to read the privacy policies of those websites—for LinkedIn: https://www.linkedin.com/legal/privacy/eu and for YouTube: https://policies.google.com/privacy?hl=en-US
CHIRON Croatia is not responsible for the data protection measures or the content of websites outside of CHIRON Croatia.
Privacy Notice for the Use of Microsoft 365
We would like to inform you below about the processing of personal data in connection with the use of Microsoft 365 products:
CHIRON Croatia uses the Microsoft 365 application suite as a work tool. Microsoft 365 consists of various applications (e.g., MS Teams, MS Office, MS SharePoint, MS OneDrive), all of which are operated in the cloud.
We also use the Microsoft 365 tool to communicate with you and to conduct telephone conferences, online meetings, video conferences, and surveys, as well as to gather feedback from our clients, cooperation partners, service providers, suppliers, customers, and participants.
We use the Microsoft 365 software from Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA (hereinafter “Microsoft”). This software is operated as a cloud application. In some cases, a user account must be created to use individual components. To the extent that this user account was not created by us and made available to you, Microsoft is the responsible entity or the entity that provided you with the access credentials.
In addition, Microsoft reserves the right to process user data for its own business purposes. In this context, Microsoft is an independent controller. We have only limited influence over Microsoft’s use of your usage data. We take all possible measures to minimize the transfer of your usage data to Microsoft as much as possible but cannot completely prevent it.
For details and contact information, particularly regarding your rights vis-à-vis Microsoft, please refer to the link below if you have any questions about this topic:
https://www.microsoft.com/hr-hr/privacy/privacystatement
We have entered into data protection agreements with Microsoft to ensure a minimum level of data protection. To this end, we have agreed that Microsoft will generally process personal data on servers located within the EU.
For some services, however, data is still transferred to the U.S., a third country considered by the EU to be unsafe in terms of data protection. To ensure an adequate level of data protection comparable to that within the European Union even in this third country, we have also entered into so-called Standard Contractual Clauses with Microsoft.
Please note that we have only limited influence over Microsoft’s processing of your usage data. To the extent that Microsoft processes personal data in connection with Microsoft’s legitimate business operations, Microsoft is an independent data controller for this use and, as such, is responsible for complying with all applicable laws and obligations of a data controller.
3. Data processing for the technical delivery of the services:
Certain information is automatically processed as soon as you open one of the Microsoft 365 applications:
For the investigation and prosecution of legal violations:
If necessary to investigate illegal or abusive use of Microsoft 365 services or for legal proceedings, personal data will be forwarded to law enforcement agencies or other authorities, as well as, where applicable, to aggrieved third parties or legal counsel. However, this occurs only if there is evidence of illegal or abusive behaviour. Disclosure may also occur if it serves to enforce terms of use or other legal claims. We are also legally obligated to provide information to certain public authorities upon request. These include law enforcement agencies, authorities that prosecute administrative offenses subject to fines, and tax authorities.
The processing of this information serves our legitimate interest in the effective provision and security of the services used, as well as for legal enforcement. The legal basis is Art. 6(1)(f) GDPR.
When using Microsoft 365 Teams
We use the Microsoft 365 Teams tool as a platform for a variety of communication processes, including
In some cases, participation is possible without login credentials; in others, you must log in with your credentials to participate in such meetings.
The following data is collected and is typically visible to the other participants:
Possible additional identifying characteristics:
Personal information that you have provided as a user within Microsoft 365, in particular the following master data:
To enable video display and audio playback, data from your device’s microphone and any video camera on your device will be processed during the meeting. You can turn off the camera or mute the microphone at any time via the video conferencing application.
Additional technical usage data is collected:
To the extent that the meetings take place within the framework of a contractual relationship between us, data processing is based on Art. 6(1)(b) GDPR. If no contractual relationship exists, the legal basis is Art. 6(1)(f) GDPR. Here, our interest lies in the effective conduct of online meetings.
4. Recipients / Disclosure of Data
Personal data processed in connection with the use of Microsoft 365 products is generally not disclosed to third parties, except in the cases described in Section 5, unless it is specifically intended for disclosure.
5. Data Processing Outside the European Union
Your data is also transferred and processed, at least in part, outside the EU or the EEA, specifically in the United States and other third countries.
The appropriate level of protection is ensured through the conclusion of standard data protection clauses pursuant to Article 46(2)(c) or (d) of the GDPR.
6. Deletion of Data
We generally delete personal data when there is no longer a need for further storage. A need may exist, in particular, if the data is still required to fulfill contractual obligations, comply with retention obligations, or to assert or defend legal claims. In the case of statutory retention obligations, deletion is only considered after the respective retention obligation has expired. If you are registered as a user with Microsoft 365, reports on your usage data (login data and IP addresses, other metadata, data on phone dial-in, etc.) may be stored by the provider for up to 90 days.
If we store your data in backups, these are overwritten regularly and, in a manner, appropriate to our operations.
Privacy Notice for the Use of Microsoft Forms in Customer Surveys:
We use “Microsoft Forms” for our contact forms, as well as for internal and external surveys and inquiries, such as evaluating completed campaigns, registering for events, etc.
Microsoft Forms is a tool within the Microsoft 365 suite we use and a service provided by the third-party provider Microsoft Ireland Operations Limited.
When using Microsoft Forms, personal data is processed. This privacy notice provides information exclusively about our processing of your personal data. Information regarding Microsoft’s processing of personal data can be found at the following link:
https://www.microsoft.com/hr-hr/privacy/privacystatement
Data from users in the European Union is processed in data centres within the European Economic Area (EEA). However, it may be necessary for the provision of the service and for support purposes that data be processed at Microsoft Inc.’s headquarters in the United States.
Regarding the conclusion of a data processing agreement:
To fully comply with strict legal data protection requirements, we have entered into a data processing agreement with Microsoft under the “Online Service Terms” (OST). In this respect, Microsoft acts solely as a data processor. To the extent that the Microsoft website www.Office.com or “Microsoft Forms” processes personal data or uses cookies, Microsoft is responsible for the data processing. Cookies from Microsoft are used on the survey page to provide the Microsoft Forms service.
In addition, the EU Standard Contractual Clauses have been contractually agreed upon for data transfers to third countries. The EU Standard Contractual Clauses guarantee an adequate level of EU data protection. We would like to point out that, according to the case law of the European Court of Justice, the United States is currently not a safe third country within the meaning of EU data protection law. Due to surveillance laws in the U.S., U.S. service providers may be required to disclose personal data to security authorities without data subjects having the right to appeal this. It cannot therefore be ruled out that U.S. authorities, such as intelligence agencies, will process, analyse, and permanently store your data located on the servers of U.S. service providers for surveillance purposes. We have no influence over these processing activities.
Therefore, Microsoft has implemented additional technical and organizational measures to protect personal data. In particular, personal data transmitted via Forms is encrypted. Furthermore, Microsoft has contractually committed to challenging disclosure requests from U.S. authorities in court to the extent possible. Consequently, it can generally be assumed that Microsoft maintains an adequate level of protection when processing personal data.
The use of our contact forms and participation in our surveys is voluntary. To the extent that consent is granted through participation in the survey, the legal basis is Article 6(1)(a) of the GDPR (consent of the data subject). Consent that has been given may be revoked at any time with future effect. Revoking or withholding consent will not result in any disadvantages.
If the use of contact forms and surveys is necessary for the initiation and/or performance of contracts, the processing of personal data is carried out in accordance with Article 6(1)(b) of the GDPR.
If no contractual relationship exists, the use of the contact form is based on our legitimate business interest in providing you with efficient, cost-effective, and user-friendly services or, in the case of surveys, on our legitimate interest in the effective planning and implementation of projects and processes, etc., in accordance with Article 6(1)(f) of the GDPR.
Form owners have access to Microsoft Forms and can create and distribute surveys, forms, and questionnaires directly, either alone or with other owners. They are also the sole recipients of the responses.
These are presented graphically in Microsoft Forms and are available to the form owners.
When using “Microsoft Forms,” various types of data are processed. The scope of the data depends on the questions asked and answered, as well as any uploads of additional files.
Generally, this involves the following personal data:
If you participate in an anonymous survey, the response does not contain any contact information and cannot be traced back to you.
The service provider for “Microsoft Forms” necessarily becomes aware of this data in the course of providing its services as a data processor.
Data Retention
CHIRON Croatia retains personal data only for as long as necessary to achieve the purpose for which it was collected, or, in the case of mandatory legal provisions, the data is retained in accordance with the periods specified in such mandatory regulations.
Once personal data is no longer required for the purpose for which it was collected, it will be destroyed or anonymized so that it is no longer in a form that permits the identification of the data subject.
Information on data processing in the job application process pursuant to Art. 13 GDPR
The processing of candidates' personal data is necessary to enable the data controller, CHIRON Croatia, to determine whether the candidates meet the requirements of the job position they applied for, i.e., for the purpose of making an employment decision.
The data you provide as a job applicant for a published job vacancy will be processed and stored electronically until the selection of the successful candidate. The data of candidates who are not selected may be retained longer only with the explicit consent of such candidates for the purpose of future job openings. In the case of unsolicited job applications, the legal basis for data collection is consent, given that the prospective employee sent the application voluntarily.
Collection and storage of personal data, as well as the nature, purpose, and use thereof:
When you contact us as part of your job application, we collect the following information:
This data is collected for the purpose of corresponding with you. Data processing is based on your application and is necessary for the proper handling of your application in accordance with Article 6(1)(b) of the GDPR for the stated purposes. If you grant us explicit consent to retain your data in our candidate database even after the specific recruitment process has ended, the legal basis for such further processing is your consent pursuant to Article 6(1)(a) of the GDPR. Your personal data will not be transferred to third parties.
Access to the data
The data you provide will be treated confidentially. In the context of a specific application, only persons involved in filling this position will have access to the data you provide. These include, in particular, the management and the respective division heads.
Deletion of data
We store and use your data only for as long as is necessary to make a decision regarding the establishment of an employment relationship with you. If you receive a rejection of your application, the application process is thereby concluded.
In the event of employment, your personal data collected during the recruitment process will become part of the employee records and will be kept permanently, in accordance with special regulations. Otherwise, the data of other candidates will generally be kept for 6 months after the conclusion of the recruitment process and will thereafter be deleted from our records, unless there is another legal basis for processing—for instance, when statutory regulations prevent erasure, or further storage is necessary for evidentiary purposes in legal proceedings, or if you have given explicit consent for further storage in accordance with Article 6(1)(a) of the GDPR.
Data Subject Rights
You have the right to
a) pursuant to Art. 15 GDPR, to request information about your personal data processed by us. In particular, you may request information regarding the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction, processing, or objection, the existence of a right to lodge a complaint, the origin of your data if it was not collected by us, as well as information regarding the existence of automated decision-making, including profiling, and, where applicable, meaningful information regarding its details.
Access to personal data may be restricted only in cases prescribed by EU law or national legislation, or when such a restriction respects the essence of the fundamental rights and freedoms of others;
b) pursuant to Art. 16 GDPR, to request the immediate rectification of inaccurate personal data or the completion of your personal data stored by us;
c) pursuant to Art. 17 GDPR, to request the erasure of personal data stored by us, if your personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed, and there is no legal obligation for its retention (e.g., tax regulations); if you have withdrawn the consent on which the processing is based and there is no other legal ground for the processing; or if you have objected to the processing of your personal data and there are no overriding legitimate grounds for the processing; if your personal data has been unlawfully processed; or if it must be erased for compliance with a legal obligation under EU law or national legislation.
These rights shall not apply to the extent that processing is necessary:
- for exercising the right of freedom of expression and information;
- for compliance with a legal obligation which of the controller, or for the performance of a task carried out in the public interest;
- for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes in accordance with applicable regulations;
- for the establishment, exercise, or defense of legal claims.
d) pursuant to Art. 18 GDPR, to request the restriction of the processing of your personal data, provided that you contest the accuracy of the data, the processing is unlawful but you oppose its erasure, and we no longer need the data, but you require it for the assertion, exercise, or defend legal claims, or you have objected to the processing pursuant to Article 21 of the GDPR;
e) pursuant to Article 20 of the GDPR, to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, or to request the transmission of such data to another controller;
f) pursuant to Art. 7(3) GDPR, to withdraw your consent at any time. As a result, we may no longer process the data based on this consent in the future; and
g) pursuant to Art. 77 GDPR, to lodge a complaint with a supervisory authority – Croatian Personal Data Protection Agency (AZOP):
Agencija za zaštitu osobnih podataka (AZOP)
Selska cesta 136
10000 Zagreb, Croatia
email: azop@azop.hr
website available at the following link: www.azop.hr
To exercise the aforementioned rights or for questions regarding data protection, you may contact the data controller as specified in Section 1 above or send an email to: info.croatia@chiron-group.com
Right to Object
If your personal data is processed on the basis of legitimate interests pursuant to Article 6(1)(f) of the GDPR, you have the right, pursuant to Article 21 of the GDPR, to object to the processing of your personal data, provided there are grounds arising from your particular situation or the objection is directed against direct marketing. In the latter case, you have a general right to object, which we will honor without requiring you to specify a particular situation. If you wish to exercise your right of withdrawal or objection, simply send an email to: info.croatia@chiron-group.com
Data Security
a) During your visit to our website, we use the widely adopted SSL (Secure Sockets Layer) protocol in conjunction with the highest encryption level supported by your browser. This is typically 256-bit encryption. If your browser does not support 256-bit encryption, we will use 128-bit v3 technology instead. You can tell whether a specific page of our website is being transmitted securely by the closed key or lock icon displayed in the status bar at the bottom of your browser.
b) We also employ appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.
Changes to this privacy policy
The privacy policy may be amended periodically to ensure legal compliance, with the right to modify content as necessary and with notification provided on the website.
As of: July 7, 2026
Karriere
HSTec ist weltweit bekannt für seine Produktionsqualität, Produktinnovation und seine hochqualifizierten Mitarbeiter. Wir folgen globalen Trends in der industriellen Automatisierung und wenden ständig neue Technologien auf der Grundlage umfassender Marktforschung an. Da es immer Raum für Verbesserungen gibt, sind wir ständig auf der Suche nach Talenten, die helfen können, uns kontinuierlich weiterzuentwickeln. Im Gegenzug bieten wir Wachstum, Karrieremöglichkeiten und die Zusammenarbeit mit Top-Experten auf diesem Gebiet.