Privacy Policy

IZI Energy d.o.o. | Version 1.0 | Effective from 22 September 2026.

This Privacy Policy explains what personal data we collect, why we collect it, on what legal basis we process it, who we share it with, how long we keep it and what rights you have. It is written to be understood, not to be long.

It applies to the website izi.energy and to the services we provide at the IZI energy service station and the IZI WASH car wash. Cookies and similar technologies are described in detail in a separate Cookie Policy, which forms an integral part of this Policy.

This is a translation provided for convenience. In case of any discrepancy, the Croatian version prevails.

1. Who is the controller

ItemValue
CompanyIZI Energy d.o.o.
Registered officeRadnička cesta 80, 10000 Zagreb, Republic of Croatia
OIB (tax number)17570235951
Company register number (MBS)05154740
Energy service station locationDonji Kneginec (Varaždin), next to Green Park
Privacy contact e-mailsupport@izi.energy
Customer support phone0800 0404
Websiteizi.energy

In this Policy, "we", "us" and "IZI" mean IZI Energy d.o.o. "You" means you as a data subject — a website visitor, a customer of the energy service station or the car wash, or a person who has contacted us.

1.1. Data Protection Officer

We have not appointed a Data Protection Officer because there is no obligation to do so under Article 37 GDPR. For any privacy question, please contact support@izi.energy.

2. Principles we follow

3. What data we process and why

The table below sets out, for each processing activity, the data, the purpose, the legal basis under Article 6 GDPR and the retention period.

ActivityDataPurposeLegal basisRetention
Website visitIP address (truncated where technically possible), browser, operating system, language, date and time, URL requested, referrer, status codeDelivering the site, system stability and security, detecting abuse and attacks, fixing errorsArt. 6(1)(f) — legitimate interestUp to 30 days of server logs
Contact form and e-mailName, e-mail, phone if provided, content of your message, date and timeHandling and answering your enquiryArt. 6(1)(b) or Art. 6(1)(f)Up to 12 months after the matter is closed
Support line 0800 0404Calling number, date, time and duration, content of the enquiry, transaction or vehicle details, call recording if calls are recordedCustomer support, resolving faults and complaints, evidence of the reportArt. 6(1)(b), (c) and (f)Up to 3 months for recordings, if calls are recorded
Card payment at the station and car washTransaction amount, date and time, terminal and dispenser ID, product, authorisation code, masked card number (last four digits), transaction status, invoice numberExecuting the transaction, issuing the invoice, bookkeeping, handling refunds and complaints, fraud preventionArt. 6(1)(b), (c) and (f)At least 11 years (Art. 10 Accounting Act)
Issuing and delivering invoicesStatutory invoice data; for business invoices also company name, address and OIBInvoicing, fiscalisation, bookkeeping, tax obligationsArt. 6(1)(c) — legal obligationAt least 11 years
ComplaintsName, address or e-mail for the reply, content of the complaint, transaction data, attachmentsReceiving, resolving and recording complaints, delivering a written replyArt. 6(1)(c) — Consumer Protection ActOne year from receipt of the written complaint, longer if proceedings are pending
Analytics and advertising cookiesCookie identifiers, truncated IP, device and browser data, pages viewed, time on site, traffic source, interactions, ad impressions and clicksMeasuring traffic and behaviour, improving the site, measuring campaign performance, showing relevant ads and remarketingArt. 6(1)(a) — your consent, in conjunction with Art. 43(4) of the Electronic Communications ActPer the lifetime of each cookie; GA4 user and event data max. 14 months
Social mediaInteractions with our profiles, aggregated page statistics, content of messages you send usPresence on social channels, community management, aggregated statisticsArt. 6(1)(f); joint controllership with the platform for page insights (Art. 26 GDPR)Messages up to 12 months after the conversation is closed
System security and fraud preventionTechnical logs, transaction data, system access dataDetecting unauthorised access, abuse, fraud attempts and technical attacksArt. 6(1)(f) — legitimate interestAs long as needed for the purpose, then deleted

Please do not send special categories of personal data under Article 9 GDPR in the contact form.

If telephone calls are recorded, you are informed of that at the start of the call, before recording begins, together with the purpose, legal basis, retention period and a link to this Policy.

3.1. How card payment works

The energy service station operates without staff and without a cash desk. Payment is made by card directly at the dispenser or at the car wash unit:

Card data is processed by the authorised card acquirer or payment service provider. We do not see and do not store your full card number, CVV/CVC code or PIN.

You can withdraw consent for analytics and marketing cookies at any time, as easily as you gave it, through the Cookie settings link.

We are present on Instagram and Facebook (Meta Platforms Ireland Limited) and on LinkedIn (LinkedIn Ireland Unlimited Company). When you visit or interact with our profile, the network provider processes your data under its own privacy rules, which we do not control. Page statistics made available to us are aggregated. We and the network provider are joint controllers for those insights under Article 26 GDPR. An external agency produces and publishes social content for us as a processor under Article 28 GDPR. Direct messages, comments and reviews are kept for up to 12 months after the conversation is closed, on the basis of Article 6(1)(f) GDPR.

Legal basisWhen we use itYour key right
(a) ConsentAnalytics and marketing cookies, third-party embedded content, newsletter if introducedWithdraw consent at any time, without affecting the lawfulness of processing before withdrawal
(b) Performance of a contractPurchase of fuel, AdBlue, screen wash and wash services, payment processing, service-related enquiriesRight to data portability
(c) Legal obligationInvoicing, fiscalisation, bookkeeping, consumer complaint handling, responding to authoritiesLimited right to erasure while the legal obligation lasts
(f) Legitimate interestSite and system security, fraud prevention, answering enquiries, social media statistics, establishing and defending legal claimsRight to object at any time on grounds relating to your particular situation

Where we rely on legitimate interest, we first carry out and document a balancing test. We can provide a summary of that assessment on request.

5. Who we share your data with

We do not sell your data. We share it only where necessary and only to the extent required, with the following categories of recipients:

All processors are bound by data processing agreements under Article 28 GDPR covering the subject matter, duration, nature and purpose of processing, confidentiality, security measures and the treatment of data after the contract ends.

6. Transfers outside the European Economic Area

Our servers and core business processes are located in the European Union. Transfers outside the European Economic Area (EEA) may occur when analytics, advertising and social media tools are used, and only if you have consented.

RecipientPurposeSafeguard
Google Ireland Limited and affiliates (Google LLC, USA)Google Analytics 4, Google Ads, Google Tag Manager, Google Maps, YouTubeEuropean Commission Standard Contractual Clauses and EU-US Data Privacy Framework certification, with supplementary technical and organisational measures
Meta Platforms Ireland Limited and Meta Platforms, Inc. (USA)Meta Pixel, advertising and measurement on Facebook and InstagramStandard Contractual Clauses and EU-US Data Privacy Framework certification
LinkedIn Ireland Unlimited Company and LinkedIn Corporation (USA)LinkedIn Insight Tag, advertising and measurementStandard Contractual Clauses and EU-US Data Privacy Framework certification

The European Commission adequacy decision for the EU-US Data Privacy Framework is in force and was upheld by the General Court of the European Union in September 2025. That judgment has been appealed to the Court of Justice of the European Union, so the legal framework for transfers to the United States may change. For that reason we rely on Standard Contractual Clauses in addition to the Framework.

Despite these measures, the level of data protection in third countries may be lower than in the European Union and public authorities there may have broader access powers. If you do not want such transfers to occur, do not give consent for analytics and marketing cookies, or withdraw it via the Cookie settings link.

On request we can provide a copy of the safeguards applied. Send the request to support@izi.energy.

7. How long we keep data

Data categoryRetention periodBasis
Web server logsUp to 30 daysLegitimate interest, system security
Form and e-mail enquiriesUp to 12 months after the matter is closedLegitimate interest, evidence of communication
Call recordings on 0800 0404, if recordedUp to 3 monthsLegitimate interest, service quality
Transactions, invoices and accounting recordsAt least 11 years from the last day of the business yearArt. 10 Accounting Act and fiscalisation rules
Consumer complaint recordsOne year from receipt of the written complaintConsumer Protection Act
Cookie dataPer the lifetime of each cookie, see the Cookie PolicyConsent
Google Analytics 4 user and event dataMaximum 14 monthsConsent and tool configuration
Record of consent given and withdrawn12 months from the last actionArt. 7(1) GDPR, obligation to demonstrate consent
Legal claims and dispute documentationUntil final resolution and expiry of limitation periodsEstablishing and defending legal claims

After the period ends we delete the data or permanently anonymise it so that you can no longer be identified. Where more than one period applies to the same data, the longer one applies.

8. Your rights

RightWhat it means
Access (Art. 15)Ask whether we process your data, what data, for what purposes, who we share it with and how long we keep it, and obtain a copy
Rectification (Art. 16)Ask us to correct inaccurate data and complete incomplete data
Erasure (Art. 17)Ask us to delete data, for example when it is no longer needed or when you withdraw consent. This does not apply where we must keep the data by law, such as invoices
Restriction (Art. 18)Ask us to temporarily stop using the data, for example while we verify its accuracy or handle your objection
Portability (Art. 20)Receive data you gave us based on consent or contract, processed by automated means, in a machine-readable format, or have it transmitted directly to another controller where technically feasible
Objection (Art. 21)Object to processing based on legitimate interest on grounds relating to your particular situation. You may object to direct marketing at any time, without giving reasons, and we will stop immediately
Withdraw consent (Art. 7(3))Withdraw consent at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of processing before it
Complaint (Art. 77)Lodge a complaint with the Croatian Personal Data Protection Agency

Send your request to support@izi.energy or by post to the registered office in section 1. Requests are free of charge. We respond without undue delay and within one month of receipt at the latest; this period may be extended by up to two further months for complex or numerous requests, and we will tell you within the first month if that happens.

If there is reasonable doubt about the identity of the person making the request, we may ask for further information needed to confirm identity. We do not ask for a copy of an identity card where identity can be confirmed in a less intrusive way. If a request is manifestly unfounded or excessive, in particular because of its repetitive character, we may charge a reasonable fee or refuse to act on the request, and we will explain why.

Supervisory authority: Agencija za zaštitu osobnih podataka (AZOP), Ulica Metela Ožegovića 16, 10000 Zagreb, +385 1 4609 000, azop@azop.hr, azop.hr. We would appreciate the chance to resolve your concern directly first.

9. Data security

We apply technical and organisational measures appropriate to the risk, including HTTPS/TLS across the site, need-to-know access control with individual accounts, system separation and regular patching, backups with restore testing, confidentiality obligations for everyone with access, contractual and security vetting of processors, and processing of card data exclusively by authorised payment service providers under the PCI DSS standard.

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify AZOP without undue delay and within 72 hours of becoming aware. Where the risk is high, we will also notify you directly.

10. Automated decision-making and profiling

We do not make decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.

If you have consented to marketing cookies, advertising platforms may place you in audience segments based on your online behaviour in order to show more relevant ads. This has no legal effect on you and can be switched off at any time by withdrawing consent.

11. Children

Our services and website are not directed at children and we do not knowingly collect children's data. If we learn that we have collected a child's data without an appropriate basis, we will delete it without delay. If you believe we have collected a child's data, contact us using the details in section 1.

Our site may contain links to third-party sites, such as social networks, Google Maps or partner sites. This Policy does not apply to those sites and we are not responsible for their content or for how they process your data. We recommend that you read their privacy policies.

13. Changes to this Policy

We may amend this Policy when our services, the tools we use or the applicable law change. The current version is always published on our website with its version number and effective date. We will notify you of material changes in an appropriate way, for example by a prominent notice on the site. Where a change concerns processing based on consent we will ask for new consent.

14. Contact

For any question about this Policy or the processing of your personal data, contact support@izi.energy or write to IZI Energy d.o.o., Radnička cesta 80, 10000 Zagreb, marked "Data protection".

Version 1.0 | Effective from 22 September 2026. | Previous versions are available on request.