Privacy Policy
IZI Energy d.o.o. | Version 1.0 | Effective from 22 September 2026.
This Privacy Policy explains what personal data we collect, why we collect it, on what legal basis we process it, who we share it with, how long we keep it and what rights you have. It is written to be understood, not to be long.
It applies to the website izi.energy and to the services we provide at the IZI energy service station and the IZI WASH car wash. Cookies and similar technologies are described in detail in a separate Cookie Policy, which forms an integral part of this Policy.
This is a translation provided for convenience. In case of any discrepancy, the Croatian version prevails.
1. Who is the controller
| Item | Value |
|---|---|
| Company | IZI Energy d.o.o. |
| Registered office | Radnička cesta 80, 10000 Zagreb, Republic of Croatia |
| OIB (tax number) | 17570235951 |
| Company register number (MBS) | 05154740 |
| Energy service station location | Donji Kneginec (Varaždin), next to Green Park |
| Privacy contact e-mail | support@izi.energy |
| Customer support phone | 0800 0404 |
| Website | izi.energy |
In this Policy, "we", "us" and "IZI" mean IZI Energy d.o.o. "You" means you as a data subject — a website visitor, a customer of the energy service station or the car wash, or a person who has contacted us.
1.1. Data Protection Officer
We have not appointed a Data Protection Officer because there is no obligation to do so under Article 37 GDPR. For any privacy question, please contact support@izi.energy.
2. Principles we follow
- We collect only the data we actually need, and only for a clearly defined purpose.
- We do not sell your personal data and we do not pass it to third parties for their own marketing purposes.
- We do not ask for data we do not need. The energy service station has no cashier, no registration and no mandatory account in order to refuel or wash your vehicle.
- We keep data only as long as it is needed for the purpose or as long as the law requires, and then we delete or anonymise it.
- We set analytics and marketing cookies only after your consent, and you can withdraw that consent at any time.
3. What data we process and why
The table below sets out, for each processing activity, the data, the purpose, the legal basis under Article 6 GDPR and the retention period.
| Activity | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Website visit | IP address (truncated where technically possible), browser, operating system, language, date and time, URL requested, referrer, status code | Delivering the site, system stability and security, detecting abuse and attacks, fixing errors | Art. 6(1)(f) — legitimate interest | Up to 30 days of server logs |
| Contact form and e-mail | Name, e-mail, phone if provided, content of your message, date and time | Handling and answering your enquiry | Art. 6(1)(b) or Art. 6(1)(f) | Up to 12 months after the matter is closed |
| Support line 0800 0404 | Calling number, date, time and duration, content of the enquiry, transaction or vehicle details, call recording if calls are recorded | Customer support, resolving faults and complaints, evidence of the report | Art. 6(1)(b), (c) and (f) | Up to 3 months for recordings, if calls are recorded |
| Card payment at the station and car wash | Transaction amount, date and time, terminal and dispenser ID, product, authorisation code, masked card number (last four digits), transaction status, invoice number | Executing the transaction, issuing the invoice, bookkeeping, handling refunds and complaints, fraud prevention | Art. 6(1)(b), (c) and (f) | At least 11 years (Art. 10 Accounting Act) |
| Issuing and delivering invoices | Statutory invoice data; for business invoices also company name, address and OIB | Invoicing, fiscalisation, bookkeeping, tax obligations | Art. 6(1)(c) — legal obligation | At least 11 years |
| Complaints | Name, address or e-mail for the reply, content of the complaint, transaction data, attachments | Receiving, resolving and recording complaints, delivering a written reply | Art. 6(1)(c) — Consumer Protection Act | One year from receipt of the written complaint, longer if proceedings are pending |
| Analytics and advertising cookies | Cookie identifiers, truncated IP, device and browser data, pages viewed, time on site, traffic source, interactions, ad impressions and clicks | Measuring traffic and behaviour, improving the site, measuring campaign performance, showing relevant ads and remarketing | Art. 6(1)(a) — your consent, in conjunction with Art. 43(4) of the Electronic Communications Act | Per the lifetime of each cookie; GA4 user and event data max. 14 months |
| Social media | Interactions with our profiles, aggregated page statistics, content of messages you send us | Presence on social channels, community management, aggregated statistics | Art. 6(1)(f); joint controllership with the platform for page insights (Art. 26 GDPR) | Messages up to 12 months after the conversation is closed |
| System security and fraud prevention | Technical logs, transaction data, system access data | Detecting unauthorised access, abuse, fraud attempts and technical attacks | Art. 6(1)(f) — legitimate interest | As long as needed for the purpose, then deleted |
Please do not send special categories of personal data under Article 9 GDPR in the contact form.
If telephone calls are recorded, you are informed of that at the start of the call, before recording begins, together with the purpose, legal basis, retention period and a link to this Policy.
3.1. How card payment works
The energy service station operates without staff and without a cash desk. Payment is made by card directly at the dispenser or at the car wash unit:
- On the screen you select the maximum amount in euro you wish to fuel for.
- Your card is authorised, meaning that amount is reserved. This is not a charge.
- After fuelling, only the amount actually dispensed is charged and the difference is released. The reservation is normally released within 24 hours, depending on your bank.
Card data is processed by the authorised card acquirer or payment service provider. We do not see and do not store your full card number, CVV/CVC code or PIN.
You can withdraw consent for analytics and marketing cookies at any time, as easily as you gave it, through the Cookie settings link.
We are present on Instagram and Facebook (Meta Platforms Ireland Limited) and on LinkedIn (LinkedIn Ireland Unlimited Company). When you visit or interact with our profile, the network provider processes your data under its own privacy rules, which we do not control. Page statistics made available to us are aggregated. We and the network provider are joint controllers for those insights under Article 26 GDPR. An external agency produces and publishes social content for us as a processor under Article 28 GDPR. Direct messages, comments and reviews are kept for up to 12 months after the conversation is closed, on the basis of Article 6(1)(f) GDPR.
4. Legal bases we rely on
| Legal basis | When we use it | Your key right |
|---|---|---|
| (a) Consent | Analytics and marketing cookies, third-party embedded content, newsletter if introduced | Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal |
| (b) Performance of a contract | Purchase of fuel, AdBlue, screen wash and wash services, payment processing, service-related enquiries | Right to data portability |
| (c) Legal obligation | Invoicing, fiscalisation, bookkeeping, consumer complaint handling, responding to authorities | Limited right to erasure while the legal obligation lasts |
| (f) Legitimate interest | Site and system security, fraud prevention, answering enquiries, social media statistics, establishing and defending legal claims | Right to object at any time on grounds relating to your particular situation |
Where we rely on legitimate interest, we first carry out and document a balancing test. We can provide a summary of that assessment on request.
5. Who we share your data with
We do not sell your data. We share it only where necessary and only to the extent required, with the following categories of recipients:
- IT service providers: hosting, website maintenance, development, support and system security
- payment service providers, card acquirers and banks, for authorisation and settlement
- the supplier and maintenance provider of the equipment at the station and the car wash
- the fiscalisation and invoicing service provider and the accounting service
- analytics and advertising providers, strictly subject to your consent (Google, Meta, LinkedIn)
- agencies managing our marketing and social media content
- the virtual assistant provider, if active
- lawyers, auditors and other advisers, where needed to establish or defend legal claims
- competent authorities (Tax Administration, inspectorates, police, courts) where there is a legal basis
All processors are bound by data processing agreements under Article 28 GDPR covering the subject matter, duration, nature and purpose of processing, confidentiality, security measures and the treatment of data after the contract ends.
6. Transfers outside the European Economic Area
Our servers and core business processes are located in the European Union. Transfers outside the European Economic Area (EEA) may occur when analytics, advertising and social media tools are used, and only if you have consented.
| Recipient | Purpose | Safeguard |
|---|---|---|
| Google Ireland Limited and affiliates (Google LLC, USA) | Google Analytics 4, Google Ads, Google Tag Manager, Google Maps, YouTube | European Commission Standard Contractual Clauses and EU-US Data Privacy Framework certification, with supplementary technical and organisational measures |
| Meta Platforms Ireland Limited and Meta Platforms, Inc. (USA) | Meta Pixel, advertising and measurement on Facebook and Instagram | Standard Contractual Clauses and EU-US Data Privacy Framework certification |
| LinkedIn Ireland Unlimited Company and LinkedIn Corporation (USA) | LinkedIn Insight Tag, advertising and measurement | Standard Contractual Clauses and EU-US Data Privacy Framework certification |
The European Commission adequacy decision for the EU-US Data Privacy Framework is in force and was upheld by the General Court of the European Union in September 2025. That judgment has been appealed to the Court of Justice of the European Union, so the legal framework for transfers to the United States may change. For that reason we rely on Standard Contractual Clauses in addition to the Framework.
Despite these measures, the level of data protection in third countries may be lower than in the European Union and public authorities there may have broader access powers. If you do not want such transfers to occur, do not give consent for analytics and marketing cookies, or withdraw it via the Cookie settings link.
On request we can provide a copy of the safeguards applied. Send the request to support@izi.energy.
7. How long we keep data
| Data category | Retention period | Basis |
|---|---|---|
| Web server logs | Up to 30 days | Legitimate interest, system security |
| Form and e-mail enquiries | Up to 12 months after the matter is closed | Legitimate interest, evidence of communication |
| Call recordings on 0800 0404, if recorded | Up to 3 months | Legitimate interest, service quality |
| Transactions, invoices and accounting records | At least 11 years from the last day of the business year | Art. 10 Accounting Act and fiscalisation rules |
| Consumer complaint records | One year from receipt of the written complaint | Consumer Protection Act |
| Cookie data | Per the lifetime of each cookie, see the Cookie Policy | Consent |
| Google Analytics 4 user and event data | Maximum 14 months | Consent and tool configuration |
| Record of consent given and withdrawn | 12 months from the last action | Art. 7(1) GDPR, obligation to demonstrate consent |
| Legal claims and dispute documentation | Until final resolution and expiry of limitation periods | Establishing and defending legal claims |
After the period ends we delete the data or permanently anonymise it so that you can no longer be identified. Where more than one period applies to the same data, the longer one applies.
8. Your rights
| Right | What it means |
|---|---|
| Access (Art. 15) | Ask whether we process your data, what data, for what purposes, who we share it with and how long we keep it, and obtain a copy |
| Rectification (Art. 16) | Ask us to correct inaccurate data and complete incomplete data |
| Erasure (Art. 17) | Ask us to delete data, for example when it is no longer needed or when you withdraw consent. This does not apply where we must keep the data by law, such as invoices |
| Restriction (Art. 18) | Ask us to temporarily stop using the data, for example while we verify its accuracy or handle your objection |
| Portability (Art. 20) | Receive data you gave us based on consent or contract, processed by automated means, in a machine-readable format, or have it transmitted directly to another controller where technically feasible |
| Objection (Art. 21) | Object to processing based on legitimate interest on grounds relating to your particular situation. You may object to direct marketing at any time, without giving reasons, and we will stop immediately |
| Withdraw consent (Art. 7(3)) | Withdraw consent at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of processing before it |
| Complaint (Art. 77) | Lodge a complaint with the Croatian Personal Data Protection Agency |
Send your request to support@izi.energy or by post to the registered office in section 1. Requests are free of charge. We respond without undue delay and within one month of receipt at the latest; this period may be extended by up to two further months for complex or numerous requests, and we will tell you within the first month if that happens.
If there is reasonable doubt about the identity of the person making the request, we may ask for further information needed to confirm identity. We do not ask for a copy of an identity card where identity can be confirmed in a less intrusive way. If a request is manifestly unfounded or excessive, in particular because of its repetitive character, we may charge a reasonable fee or refuse to act on the request, and we will explain why.
Supervisory authority: Agencija za zaštitu osobnih podataka (AZOP), Ulica Metela Ožegovića 16, 10000 Zagreb, +385 1 4609 000, azop@azop.hr, azop.hr. We would appreciate the chance to resolve your concern directly first.
9. Data security
We apply technical and organisational measures appropriate to the risk, including HTTPS/TLS across the site, need-to-know access control with individual accounts, system separation and regular patching, backups with restore testing, confidentiality obligations for everyone with access, contractual and security vetting of processors, and processing of card data exclusively by authorised payment service providers under the PCI DSS standard.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify AZOP without undue delay and within 72 hours of becoming aware. Where the risk is high, we will also notify you directly.
10. Automated decision-making and profiling
We do not make decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
If you have consented to marketing cookies, advertising platforms may place you in audience segments based on your online behaviour in order to show more relevant ads. This has no legal effect on you and can be switched off at any time by withdrawing consent.
11. Children
Our services and website are not directed at children and we do not knowingly collect children's data. If we learn that we have collected a child's data without an appropriate basis, we will delete it without delay. If you believe we have collected a child's data, contact us using the details in section 1.
12. Third-party links
Our site may contain links to third-party sites, such as social networks, Google Maps or partner sites. This Policy does not apply to those sites and we are not responsible for their content or for how they process your data. We recommend that you read their privacy policies.
13. Changes to this Policy
We may amend this Policy when our services, the tools we use or the applicable law change. The current version is always published on our website with its version number and effective date. We will notify you of material changes in an appropriate way, for example by a prominent notice on the site. Where a change concerns processing based on consent we will ask for new consent.
14. Contact
For any question about this Policy or the processing of your personal data, contact support@izi.energy or write to IZI Energy d.o.o., Radnička cesta 80, 10000 Zagreb, marked "Data protection".
Version 1.0 | Effective from 22 September 2026. | Previous versions are available on request.