Privacy Policy
Last updated: 2026-09-03
This policy explains which personal data we collect when you visit bellami.hr or buy from us, why we process it, who we share it with and how you can stay in control of it.
1. Controller
The controller responsible for your personal data is Dobar prijatelj j.d.o.o., Zagrebačka ulica – Via Zagabria 15, 52100 Pula, Croatia, OIB (company ID): 76701332462.
Send privacy questions and requests to exercise your rights to info@bellami.hr. We have not appointed a data protection officer, as this is not required for the scope of our processing.
This policy follows Regulation (EU) 2016/679 (GDPR) and the Croatian act implementing it (NN 42/18).
2. Data we collect
Data you give us: first and last name, delivery and billing address, email address, phone number and — for business customers — company name and OIB.
Order data: products purchased, amounts, payment and delivery status, order correspondence, complaints and returns. We never receive or store card details — you enter them directly with Stripe.
Account data, if you register: credentials in encrypted form, saved addresses, wishlist and order history.
Technical and usage data: IP address, device and browser type, referring page, pages and products viewed, and search terms. Analytics data is collected only if you consent.
Marketing data: newsletter sign-up, your consents and the history of messages sent to you.
3. Purposes and legal bases
Performance of a contract (Art. 6(1)(b) GDPR): processing and delivering orders, taking payment, order communication, handling complaints and returns, and running your account.
Legal obligation (Art. 6(1)(c)): issuing and retaining invoices, fiscalisation, tax and accounting duties, and responding to requests from competent authorities.
Legitimate interests (Art. 6(1)(f)): store security and fraud prevention, fixing technical faults, improving our range and service, and establishing or defending legal claims. We balanced our interests against your rights before relying on this basis.
Consent (Art. 6(1)(a)): newsletters and promotional messages, analytics and marketing cookies. You can withdraw consent at any time without affecting processing carried out beforehand.
4. Cookies
Necessary cookies keep your cart, login and site security working and cannot be switched off, because the store does not function without them.
Analytics and marketing cookies are set only after you consent, and you can change your choice at any time via the cookie settings in the footer. Details are in our Cookie Policy.
5. Who we share data with
We do not sell or trade personal data. We share it only with service providers that process it on our instructions under a data processing agreement, and only as far as the service requires.
These are: courier services (name, address, phone, for delivery), Stripe as our payment provider, providers of website hosting, the commerce platform and databases, our email delivery service, the invoicing and fiscalisation service, and — if you consented to analytics — our analytics provider.
We may also disclose data to our accountants, lawyers or competent authorities where the law requires it or where it is necessary to protect our legal claims.
6. Transfers outside the EEA
We aim to keep processing within the EEA. Where a provider processes data outside the EEA, the transfer relies on a European Commission adequacy decision or on standard contractual clauses, with additional safeguards where needed.
Write to info@bellami.hr and we will gladly explain which mechanism applies to a given service.
7. How long we keep data
Invoices and related documentation are kept for 11 years from the end of the year they relate to, as required by tax and accounting rules.
Account data is kept while the account is active; after closure or your erasure request we delete it, except where the law requires us to retain it.
Marketing data is processed until you withdraw consent or unsubscribe. Technical and analytics data is kept for at most 26 months, and complaint records for the statutory retention period.
8. Security
We apply technical and organisational measures appropriate to the risk: encrypted connections (TLS) for all traffic, one-way password hashing, access limited to staff who need it, regular system updates, and card processing handled exclusively by a certified payment provider.
No transmission over the internet is absolutely secure, but in the event of a data breach we act in accordance with the GDPR and, where required, notify the supervisory authority and you.
9. Your rights
Right of access (Art. 15) — confirmation of whether we process your data and a copy of it. Right to rectification (Art. 16) — correction or completion of inaccurate data.
Right to erasure (Art. 17) and right to restriction (Art. 18) — under the conditions set out in the Regulation. Right to data portability (Art. 20) — the data you provided, in a machine-readable format.
Right to object (Art. 21) — you may object to processing based on legitimate interests, and we always honour objections to direct marketing. Right to withdraw consent (Art. 7(3)) at any time.
We do not carry out automated decision-making with legal effect, including profiling within the meaning of Art. 22.
Send requests to info@bellami.hr. We reply within one month; in exceptional cases we may extend that period and will tell you if we do. To protect your data we may ask you to verify your identity.
10. Is providing data mandatory
We must collect the data needed for delivery, payment and invoicing — without it we cannot fulfil an order. Everything else, such as newsletter sign-up or opening an account, is entirely voluntary and there is no downside if you decline.
11. Children
The store is not intended for anyone under 16 and we do not knowingly collect their data. If you believe a child has given us their details, contact info@bellami.hr and we will delete them without delay.
12. Links to other sites
Our pages may link to manufacturer sites, social networks or partners. We are not responsible for how they process data, so please read their privacy policies before entering any details.
13. Changes to this policy
We update this policy from time to time to reflect changes in our services or in the law. The version published on this page, with its last-updated date, is the one that applies. We will notify registered customers by email about significant changes.
14. Complaints to the supervisory authority
If you believe we process your data unlawfully, please contact us first — we will try to resolve it. You may also lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, email: azop@azop.hr, web: azop.hr.