HASHTAG BLUE
  • Architecture
  • Real Estate
  • Business Address
  • Contact
  • hr
  • |en
  • |de

PRIVACY POLICY

1. INTRODUCTION AND DATA CONTROLLER DETAILS

Hashtag Blue d.o.o., with its registered office at Mirka Viriusa 14, 10 000 Zagreb, OIB: 16186180581, MBS: 081488508 (Commercial Court in Zagreb) (hereinafter: the Company or we), is the controller of personal data within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation or GDPR), and the Act on the Implementation of the General Data Protection Regulation (Official Gazette 42/2018, hereinafter: ZOPOUD).

This Privacy Policy provides visitors to our website and all other interested persons with clear, concise and comprehensible information about:

  • who processes their personal data and how to contact us,
  • which personal data we collect and for what purposes,
  • the legal basis on which we process such data,
  • how long we retain such data,
  • with whom we share such data,
  • their rights and how to exercise them.

Data Controller contact details:

  • Name: Hashtag Blue d.o.o.
  • Address: Mirka Viriusa 14
  • Email: blue@hashtag-blue.com
  • Telephone: +385 95 511 5111
  • Website: www.hashtag-blue.com

2. PERSONAL DATA WE COLLECT

Personal data means any information relating to an identified or identifiable natural person, in particular by reference to an identifier such as a first name, surname, identification number, location data, an online identifier (IP address), or factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.

The Company collects the following categories of personal data solely to the extent necessary to achieve the specific purpose:

2.1. Data collected through the website

Technical website usage data: IP address, browser type, operating system, date and time of visit, pages viewed and referring URL — collected automatically through the web server, hosting infrastructure and security logs to ensure the website's technical operation and security.

2.2. Data collected through email contact

First and last name, email address, telephone number, company name and the content of the enquiry you submit to us. We collect only the data that you voluntarily provide.

2.3. Data collected through job applications (open applications or advertised positions)

First and last name, contact details, education and employment history, cover letter and other information included in a CV or application documents.

2.4. Data collected through cookies

See Section 3 of this Policy.

3. COOKIES

Further information about cookies is available in our separate Cookie Policy.

4. PURPOSES, LEGAL BASIS AND RETENTION PERIODS

We process personal data solely for specified purposes and only for as long as necessary:

  • Responding to enquiries by email (name, email, telephone number and content of the enquiry) – on the basis of steps taken at the data subject's request prior to entering into a contract (Article 6(1)(b) GDPR) or legitimate interests (Article 6(1)(f) GDPR). We retain the data until the enquiry has been resolved and for no longer than one year.
  • Job applications (contact details, CV, education and employment history) – on the basis of steps taken prior to entering into a contract (Article 6(1)(b) GDPR). We retain the data for up to 2 years and will delete it earlier at your request.
  • Website security and technical operation (IP address and technical logs) – on the basis of our legitimate interests (Article 6(1)(f) GDPR). We retain the data for up to 90 days, except in the event of a security incident.
  • Legal obligations and the establishment, exercise or defence of legal claims – where required by law (Article 6(1)(c) GDPR) or necessary to protect our rights (Article 6(1)(f) GDPR), for the periods prescribed by law or until the proceedings have been finally concluded.

Where we rely on legitimate interests, we have carried out a balancing test and determined that our interests do not override your rights and freedoms. You have the right to object to such processing (see Section 7).

5. RECIPIENTS OF PERSONAL DATA

Your personal data may be disclosed to the following categories of recipients solely to the extent necessary to achieve the purposes described:

  • Processors: Providers of IT and cloud services, hosting services and email services that process personal data on behalf of the Company under a written data processing agreement that meets the requirements of Article 28 GDPR.
  • Company employees: Authorised employees and associates who are bound by confidentiality obligations and require access to the data to perform their duties.
  • Business partners: Only on an appropriate legal basis and, where applicable, under written agreements.
  • Public authorities: Courts, regulatory authorities, the tax administration and other competent public authorities where required by law or court order or where necessary for the defence of legal claims.

The Company does not sell, rent or exchange your personal data with third parties for commercial purposes.

5.1. International data transfers

We do not currently transfer your personal data to third countries outside the European Economic Area (EEA).

6. PERSONAL DATA SECURITY

The Company implements appropriate technical and organisational measures to protect personal data in accordance with Article 32 GDPR, taking into account the nature, scope, context and purposes of the processing and the risks of varying likelihood and severity for the rights and freedoms of natural persons.

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, the Company will notify the competent supervisory authority (AZOP) within 72 hours of becoming aware of the breach in accordance with Article 33 GDPR and, where necessary, will also notify the affected data subjects in accordance with Article 34 GDPR.

7. YOUR RIGHTS

Under the GDPR and applicable law, you have the following rights regarding the processing of your personal data:

  • Right of access (Article 15 GDPR): You have the right to know whether we process your personal data and, if so, to obtain access to that data together with information about the purposes, categories of data, recipients, retention periods and your rights.
  • Right to rectification (Article 16 GDPR): You have the right to have inaccurate personal data relating to you corrected without undue delay and to have incomplete data completed.
  • Right to erasure ("right to be forgotten") (Article 17 GDPR): You have the right to request the erasure of your personal data where it is no longer necessary for the purpose for which it was collected, where you have withdrawn consent or objected, or where the processing was unlawful — unless there are legal grounds for retaining the data.
  • Right to restriction of processing (Article 18 GDPR): You have the right to request restriction of the processing of your data in certain circumstances (for example, while the accuracy of the data is being verified or while your objection is being considered).
  • Right to data portability (Article 20 GDPR): You have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format and to transmit it to another controller where the processing is based on consent or a contract and is carried out by automated means.
  • Right to object (Article 21 GDPR): You have the right to object at any time to the processing of your personal data based on legitimate interests (Article 6(1)(f) GDPR). We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms.
  • Right to withdraw consent (Article 7(3) GDPR): Where processing is based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
  • Right to lodge a complaint with a supervisory authority (Article 77 GDPR): You have the right to lodge a complaint with the competent supervisory authority:

Agencija za zaštitu osobnih podataka (AZOP) Selska cesta 136, 10 000 Zagreb Tel: +385 1 4609-000 Email: azop@azop.hr Website: www.azop.hr

Exercising your rights: You may submit a request to exercise any of the above rights in writing to the Company's address or by email to blue@hashtag-blue.com. We will respond without undue delay and no later than 30 days after receiving your request. In exceptionally complex or numerous cases, this period may be extended by a further 60 days, provided that you are informed in advance. Exercising your rights is free of charge unless requests are manifestly unfounded or excessive.

To verify your identity and protect against misuse, we may ask you to provide additional information necessary to confirm your identity.

8. CHILDREN

Our website and services are not intended for persons under 16 years of age. Pursuant to Article 8 GDPR and Article 4 ZOPOUD, the minimum age of consent for information society services for children residing in the Republic of Croatia is 16. We do not knowingly collect children's personal data. If we become aware that we have inadvertently collected data relating to a person under 16 years of age, we will delete it without delay.

9. LINKS TO EXTERNAL WEBSITES

Our website may contain links to third-party websites. This Privacy Policy applies exclusively to the Company's website. We recommend that you read the privacy policies of any third-party websites you visit.

10. CHANGES TO THE PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in data processing practices, legal requirements or business operations. The date of the last amendment is stated at the top of the document. In the event of material changes, we will notify you in an appropriate manner (for example, by a notice on the website or through direct communication). We recommend that you review this page periodically.

11. CONTACT

For any questions, requests or comments regarding this Privacy Policy and the processing of your personal data, please contact us:

Email: blue@hashtag-blue.com

Postal address: Hashtag Blue d.o.o., Mirka Viriusa 14, 10 000 Zagreb

Telephone: +385 95 511 5111

This Privacy Policy has been prepared in accordance with Regulation (EU) 2016/679 (GDPR), the Act on the Implementation of the General Data Protection Regulation (Official Gazette 42/2018), and the Electronic Communications Act (Official Gazette 76/2022, 14/2024), taking into account the guidelines of Agencija za zaštitu osobnih podataka (AZOP) and the European Data Protection Board (EDPB).

  • Architecture
  • Urban Planning
  • Real Estate

Spaces for the future.

  • Legal Notice
  • Privacy Policy
  • Cookie Policy

Copyright © 2026 Hashtag Blue d.o.o.
All rights reserved.