Privacy Policy for the Webpage www.nutris.hr

Date of entering into force April 10th 2021 The company NutriS d.o.o., Varaždinska 68, 33520 Novi Senkovac, OIB: 82577226318, e-mail: info@nutris.hr, respects your privacy and commits to protect it during and after your visit to this website (further in the text “Site”). This Privacy Policy (“Privacy Policy”) provides insight into our actions regarding the collection and processing of personal data. This Privacy Policy also provides you with complete information so that you can consent to the processing of your personal data in an explicit and informed manner, when necessary or appropriate. In general, all information and data that you provide to us or that we collect in any other way in the context of the use of this Site, NutriS will use in accordance with the Data Protection Regulation (EU) 2016/679 (“GDPR”). This means in particular that any data processing performed by NutriS respects the principles of legality, fairness, transparency, purpose limitation, storage period limitation, data storage limitation to a minimum, accuracy, integrity and confidentiality. Head of personal data processing The controller is responsible for all personal data processing operations performed through this Site is NutriS. To contact the officer regarding any information related to the processing of personal data by NutriS, please contact e-mail: info@nutris.hr. Contact details of the personal data protection officer: Ivan Balaško e-mail address: info@nutris.hr Types of personal data that will be processed NutriS d.o.o. collects and processes your personal data (for example, information that can directly or indirectly identify you, by identifiers such as name, surname, address, e-mail address, phone number, OIB, company name if personal data are included in the name of the company if you provide them (“Personal Information”), when:

  • you access our Site,
  • contact us via the contact form posted on the Site,
  • contact us or connect with us through social networks,
  • fill in the contact form of our subcontractors and with your consent you agree to contact you for possible cooperation,
  • we work with you as our suppliers and business partners.

We process personal data based on your consent and legitimate interest. The processing of Personal Data is limited only for the purpose for which it was collected in accordance with the terms of this Privacy Policy. NutriS will not collect Personal Data if you do not provide it to us voluntarily, except for certain Personal Data collected through information systems and programs used to operate the Site, the transmission of which is inherent in the use of Internet communication protocols (eg IP addresses when registering – registration form). and will not require more information than is necessary to participate in certain activities. If you do not wish to provide us with Personal Information (other than Personal Information relating to the use of Internet communication protocols normally collected when visiting the Website), you may still access our Site, but will not be able to contact us or subscribe to the newsletter. The processing of your personal data for which you have explicitly given us your consent when subscribing to the newsletter and / or filling out the contact form, is based on consent and associated rights in accordance with the GDPRUredbe. The provision of visitor information is voluntary and there is no contractual obligation or condition for the visitor to do so. The processing manager will not create profiles from the collected information, ie there is no automated decision making. By registering to receive the newsletter on the web www.nutris.hr, the user receives an e-mail with a request to verify the e-mail address in order to receive the newsletter for which he has expressed interest in the future. By filling out the contact form on the website www.nutris.hr, the user enters the required information (name and surname, e-mail address, company and country) so that his request can be sent to NutriS. By completing the registration for receiving the newsletter, or by filling out the contact form for sending inquiries, the user accepts responsibility for all activities caused by the use of services on www.nutris.hr.

Cookies Our website uses cookies. Cookies are data files that are stored in a computer system via an Internet browser, and which contain information about user activity on the Site. Cookies do not harm your device and allow us to offer you a better search experience and faster response on our site. Cookies that are not necessary for the functionality of the site or the provision of services are stored on your device only after you have given your consent. This Site uses different types of cookies. Some cookies are set by third parties that appear on our site.

Necessary cookies Necessary cookies help make the site useful, enabling basic functions such as navigating the Page and accessing safe areas of the site. The website cannot function properly without these cookies. Necessary cookies can be stored regardless of the consent of the user of the Site in accordance with legal regulations. Cookie name: PH_HPXY_CHECK Provider: nutris.hr Purpose: Needed for user search. It is used for the normal functioning of the website. Duration: session Cookie name: cookieControl and cookieControlPrefs Provider: nutris.hr Purpose: Necessary to accept consent for cookies. Duration: 30 days

Analytical cookies These cookies collect information about how visitors use the site, such as which pages visitors visit most often. We use them to improve the functioning of our site. However, some of them may be third party cookies, and the information we collect may be classified as purposes unknown to us as the owner of the Site. For more information, see the privacy policies of these third-party processors.

Marketing cookies Marketing cookies are used to track visitors through websites. The intent is to show ads that are relevant to a particular user and encourage them to participate, which is important for third-party advertisers. Cookie name: IDE, DSID Provider: doubleclick.net – google.com, Google Analytics | Google Ireland Ltd. | analytics.google.com | +35314361000 Barrow St, Grand Canal Dock, Dublin, 4, Ireland Purpose: Targeted ads that may appear based on your previous visits to this site. For example, ads on a topic that you may be interested in while browsing our site may appear on the entire web. In addition, these cookies determine the conversion rate of the ads displayed to the user. These cookies are set by a third party (DoubleClick) and are used to provide targeted ads that are relevant to you across the web. Duration: DSID expires after 1.5 years / IDE expires after 1.5 years. They are based on the consent of the respondents Cookie name: Facebook _fbp Provider: Facebook, Inc., 1 Hacker Way, Menlo Park, CA 94025, United States. If the person lives outside the United States or Canada, the processing manager is Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbor, Dublin 2, Ireland. The data protection policy he published is available at https://facebook.com/about/privacy/ Purpose: This cookie helps to provide ads to people who have already visited our website when they are on Facebook or a digital platform powered by Facebook advertising. It is used by Facebook to deliver a series of advertisements on Facebook Duration: session. It is based on the consent of the respondents.

•    Newsletter

If you do not wish to provide us with Personal Information (other than Personal Information relating to the use of Internet communication protocols normally collected when visiting the Website), you may still access our Site, but will not be able to contact us or subscribe to the newsletter. By registering to receive the newsletter on the web www.nutris.hr, the user receives an e-mail with a request to verify the e-mail address in order to receive the newsletter for which he has expressed interest in the future. By filling out the contact form on the website www.nutris.hr, the user enters the required information (name and surname, e-mail address, company and country) so that his request can be sent to NutriS. By completing the registration for receiving the newsletter, or by filling out the contact form for sending inquiries, the user accepts responsibility for all activities caused by the use of services on www.nutris.hr.

•    Open job applications and tenders

NutriS collects open applications from candidates who want to work with us and applications from candidates for the competitions we announce. Only authorized persons have access to personal data from job applications, and the data are kept for 2 years from the day of receiving the open application.

• Social networks

NutriS collects Personal Information about its contacts on social networks (Facebook, Instagram, etc.) but does not contact them except in the case of answering a query or comment.

Provisions on data protection on application and use: Facebook, Instagram, LinkedIn On his website, the processing manager can integrate or have integrated components of the social networks Facebook, Instagram and LinkedIn. Facebook and Instagram are social networks, operated by Facebook, Inc., 1 Hacker Way, Menlo Park, CA 94025, United States. If the person lives outside the United States or Canada, the processing manager is Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbor, Dublin 2, Ireland. The data protection rules published by Facebook and Instagram are available at https://facebook.com/about/privacy/ and https://help.instagram.com/519522125107875?helpref=page_content and provide information on collection, processing and the use of personal information on those social networks. “LinkedIn” is a business social network operating company for users who use the service within the EU, EEA and Switzerland, LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The privacy policy published by LinkedIn is available at: https://www.linkedin.com/legal/privacy-policy?trk=uno-reg-guest-home-privacy-policy and provides information on the collection, processing and the use of personal information on that social network.

Newsletter In accordance with the legitimate interest of NutriS (Processing Manager), it can inform the subscribed subscribers to the newsletter about news related to future activities within the business topics of NutriS, all in accordance with their interest shown by signing up and registering to receive the newsletter. The data is kept until the person withdraws consent or until he objects to our contact based on a legitimate interest. To send information, we use the Microsoft Office 365 system, which complies with the EU Personal Data Protection Regulation 2016/679. Purposes, legal basis of processing and possible consequences of non-disclosure of Personal Data When you provide your Personal Information, we will limit the use of Personal Information for the purpose for which it was collected in accordance with the terms of this Privacy Policy. Use of your Personal Information includes:

A. Taking steps upon your request, eg answering your questions and comments, or communicating with you following your inquiry via the contact form;

B. The process of investigating suspected fraud, harassment, physical threats or other violations of the rules of the Site or any suspicious conduct that we deem inappropriate. Giving Personal Data for the purpose under A. is voluntary, but in certain situations it is necessary and refusing to provide such data may prevent NutriS from responding to your requests. The processing of data under B. is based on the public and legitimate interest. In case you have given your consent for marketing purposes, ie you have signed up as a subscriber to the newsletter, you can withdraw your application at any time. Transfer of Personal Data to third countries NutriS transfers Personal Data outside the EU and the EEA, except Switzerland, especially to the USA, but always on the basis of data protection measures in accordance with the provisions of the GDPR Regulation, especially on the basis of Privacy Shield, thus guaranteeing adequate protection of personal data. Recipients Your Personal Information may be disclosed in the following cases:

o Entities we use to organize and conduct events (eg photographing or filming events) o Authorized PR agencies and entities directly involved in the implementation and realization of certain events or activities o Entities that maintain our information systems, o Persons authorized by NutriS to process Personal Data, who are subject to the obligation of confidentiality (NutriS employees), o Law enforcement services and public authorities when required by applicable law, legitimate or public interest (to protect and defend the rights or property of NutriS and the Site, or, in urgent circumstances, to act to protect the personal safety of NutriS users, the Site or the public), o NutriS Legal Advisers in case of need for forwarding data for legal proceedings, on Media houses and digital marketing agencies for the purpose of publishing photos in print media, on websites and social networks Keeping NutriS will only process your Personal Information for the time necessary to achieve the purposes described in this Privacy Policy. Unless otherwise provided by this Privacy Policy, your Personal Data will be processed until you exercise your right to object or withdraw your consent to the processing of Personal Data. You may withdraw your consent to the processing of your Personal Data at any time, and the withdrawal of your consent will not affect the lawfulness of the processing based on the consent before it was withdrawn.

NutriS will process your Personal Data collected in order to respond to an inquiry sent via the contact form for a maximum of 6 months from receipt of the inquiry, and in the case of subscribing to the newsletter until the cancellation of the subscription to receive the newsletter. Exceptionally, we will keep your personal data longer than the stated deadlines when it is necessary to meet mutual legal requirements. Upon expiration of the deadlines, we will destroy the stored personal data printed on paper in a safe way, for example by cutting or burning, while we will permanently delete the data in electronic form. Your rights NutriS informs you that, to the extent permitted by applicable law, you have the right to request from NutriS access and rectification or deletion of Personal Data or processing restrictions in relation to your Personal Data or to object to the relevant processing activity, and to object to the competent supervisory authority. Republic of Croatia to the Agency for Personal Data Protection). Security practices All personal data collected through the Site is stored and processed in a manner that minimizes the risk of destruction, loss (including accidental loss), unauthorized access / use, or use that is inconsistent with the initial purpose of the data collection. This is achieved by the technical and organizational safety measures introduced by NutriS. However, due to the inherent open nature of the Internet, we cannot guarantee that communication between you and us or the information stored on the Site or on our servers will be completely secure from unauthorized access by third parties. To the fullest extent permitted by applicable law, we disclaim all liability and liability for any damage you may have suffered as a result of any loss, unauthorized access, misuse or alteration of any information you submit to the Site. Changes and updates to our Privacy Policy NutriS reserves the right to change or update these Privacy Policy at any time and without prior notice. Please check from time to time any changes or updates to our Privacy Policy, which will be posted here and will show the updated effective date on the first page of the Privacy Policy if any changes or updates are made. Contact information If you have any questions or comments regarding the Site or the Privacy Policy, you can contact us via our info e-mail: info@nutris.hr.

Head of personal data processing NutriS d.o.o. Varaždinska 68 33 520 Novi Senkovac, Croatia Tel .: +385 (0) 43 231 920 Email: info@nutris.hr