Information on personal data processing


INFORMATION ON PERSONAL DATA PROCESSING
Data Controller Erste Nekretnine d.o.o., OIB HR12103019543 (hereinafter: ENEK) is the data controller. Depending on the purpose of processing, ENEK collects, processes, uses, and analyses your personal data.

For any questions or to exercise your rights regarding data processing, you may contact ENEK at erstenekretnine@erstebank.hr, by telephone at 0800 345 346, in person at ENEK offices, or by contacting the Data Protection Officer via SZ0P-ENEK@erstebank.hr or by mail to Ivana Lučića 2, Zagreb (marked “for the Data Protection Officer”).

Personal Data
As a data controller, ENEK recognizes the importance of personal data and is committed to handling such data in compliance with all applicable laws and regulations. ENEK continuously maintains and improves measures to protect the security and privacy of your data.

The protection of personal data is governed by Regulation (EU) 2016/679 of the European Parliament and Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, known as the General Data Protection Regulation (GDPR).

What Data Does ENEK Collect and Process?
ENEK collects personal data to establish and perform business relationships with clients and to fulfil legal obligations.

The provision of mandatory and businessrelated data is a prerequisite for entering into or maintaining a business relationship with ENEK. In addition, ENEK may process your data based on your explicit consent to improve the quality of its services.

Mandatory Data
Mandatory data are defined by applicable regulations and are necessary for ENEK to establish and/or maintain a business relationship. These include identification data such as name, surname, address, and OIB, collected pursuant to the Value Added Tax Act.

Business-Related Data
These are data required to conclude and/or perform a business relationship with ENEK and depend on the type of service provided. For services involving commercial real estate, ENEK may also need financial data related to your business operations. A business-related data item may also include contact information if needed for service delivery (e.g., email address).

Contact Data
Contact data are voluntarily provided and used to enable ENEK to promptly and efficiently notify you about matters related to the service you have expressed interest in or are using, as well as to deliver information or documentation upon your request. Contact data may include an address different from residence, phone number, fax, or email address.

How Does ENEK Collect and Process Data?
ENEK collects data directly from clients when expressing interest, contracting, or using services, during any communication with ENEK (e.g., via email, phone, or in person), as well as from publicly available registers such as Land Registry or the Real Estate Market Information System (eNekretnine).

ENEK also processes data obtained from Erste&Steiermärkische Bank d.d. and other Erste Group members for purposes of risk management, in accordance with relevant legislation.

Processing Based on Consent
Based on consent, ENEK processes only the data specified in the consent for the purposes stated therein. Consent is given voluntarily and may be withdrawn at any time without affecting the legality of prior processing.

You may grant consent for purposes such as:
• receiving information about ENEK’s services, news, and updates,
• improving ENEK’s services based on feedback or satisfaction surveys.

Automated Decision-Making and Profiling
NEK does not use automated decision-making that would produce legal effects or similarly significantly affect clients.

Data Sharing 
NEK may share your data with third parties for contract performance or regulatory obligations, e.g., with land registry offices, supervisory bodies such as the Croatian Financial Services Supervisory Agency (HANFA), Ministry of Finance, or members of the Erste Group for risk management purposes. ENEK uses data processors (e.g., IT, archiving, appraisal service providers) under strict contractual and security safeguards.

Data Security
ENEK implements technical and organizational security measures to ensure an appropriate level of protection for your personal data.

Data Retention
The retention period for personal data is determined by legal requirements applicable to specific business relationships.

Your Rights
Under the GDPR, you have the following rights: to be informed, to access, to rectification, to erasure, to restriction of processing, to data portability, and to object to processing.

You may exercise your rights by contacting ENEK at enekreklamacije@erstebank.hr, by phone at 0800 345 346, in person, or by contacting the Data Protection Officer at SZ0P-ENEK@erstebank.hr or by mail to Ivana Lučića 2, Zagreb.

You may also submit a complaint to the supervisory authority – the Croatian Personal Data Protection Agency (AZOP).

Erste Nekretnine d.o.o., 19 August 2025