Privacy Policy
Lumos Energy d.o.o. & Pimar d.o.o.

Last updated: 1 January 2026
1. Introduction
Pimar d.o.o. and Lumos Energy d.o.o. (“we”, “us”) are committed to protecting your personal data.
Pimar d.o.o. acts as the owner of the website and primary data controller, while Lumos Energy d.o.o. participates in service delivery and communication. Where applicable, we may act as joint data controllers in accordance with Article 26 GDPR.
2. What Personal Data We Collect
We may collect the following data:
- Name and contact details
- Company name
- IP address
- Browser and device information
- Form submissions
- Newsletter subscriptions
- Chat interactions
3. How We Use Your Data
We use your data to:
- Respond to inquiries
- Schedule meetings (Calendly)
- Communicate via WhatsApp Business
- Send newsletters and updates (Mailchimp)
- Analyze website traffic (Google Analytics, Hotjar)
- Improve our website and services
4. Legal Basis for Processing
We process your data based on:
- Your consent
- Legitimate interest (e.g., responding to inquiries, improving services, ensuring security)
- Legal obligations
5. Sharing of Your Data
We may share your data with trusted service providers, including:
- Google (Analytics)
- Hotjar
- Calendly
- WhatsApp Business (Meta Platforms Ireland Ltd.)
- Mailchimp
- IT and hosting providers
We have data processing agreements in place with all relevant providers.
6. International Data Transfers
Some providers may process data outside the European Economic Area (EEA), including in the United States.
In such cases, we rely on Standard Contractual Clauses (SCCs) or other appropriate safeguards.
7. Data Storage & Security
We implement appropriate technical and organizational measures, including:
- SSL encryption
- Access control
- Secure data storage
8. Data Retention
We retain personal data only as long as necessary:
- Contact inquiries: up to 12 months
- Analytics data: up to 26 months
- Marketing data: until consent is withdrawn
9. Your Rights
You have the right to:
- Access your personal data
- Request correction or deletion
- Withdraw consent at any time
- Object to processing
- Lodge a complaint with the Croatian Personal Data Protection Agency (AZOP)
10. Children’s Privacy
Our services are not intended for individuals under the age of 16. We do not knowingly collect data from children.
11. Cookies
We use cookies. Please refer to our Cookie Policy for more details.
12. Automated Decision-Making
We do not engage in automated decision-making or profiling that produces legal effects.
13. Social Media and External Links
Our website may contain links to third-party platforms (e.g., YouTube, LinkedIn, Instagram, Facebook, TikTok).
When you interact with these platforms, they may collect data independently according to their own privacy policies. We do not control these practices.
14. Future User Accounts
We may introduce user accounts in the future. Any such service will include appropriate data protection safeguards.
15. Contact
Radnička 20, 10000 Zagreb, Hrvatska


