1. Introduction

Creek & Pine (legal: Supernormal d.o.o, Sveti Petar Orehovec 67, 48267 Orehovec, Croatia, VAT number HR18965816268) is committed to protecting the privacy and security of the personal data we collect, process, and store. This Data and Privacy Protection Policy outlines our principles and guidelines to ensure compliance with applicable data protection laws and regulations, and to uphold the privacy rights of individuals.

2. Purpose

The purpose of this policy is to:

  • Establish a framework for the protection of personal data.
  • Ensure compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) in the EU and relevant privacy laws in the USA.
  • Define the responsibilities of employees and third parties in handling personal data.

3. Scope

This policy applies to all employees, contractors, consultants, suppliers, and any other individuals or entities who process personal data on behalf of Creek & Pine (collectively referred to as “employees”).

4. Principles

Creek & Pine adheres to the following data protection principles:

  • Lawfulness, Fairness, and Transparency: Personal data will be processed lawfully, fairly, and in a transparent manner.
  • Purpose Limitation: Personal data will be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
  • Data Minimization: Personal data will be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
  • Accuracy: Personal data will be accurate and, where necessary, kept up to date.
  • Storage Limitation: Personal data will be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the personal data is processed.
  • Integrity and Confidentiality: Personal data will be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.
  • Accountability: Creek & Pine will be responsible for, and able to demonstrate compliance with, these principles.

5. Legal Basis for Processing

Creek & Pine will ensure that personal data is processed based on one or more of the following legal grounds:

  • Consent of the data subject.
  • Performance of a contract with the data subject or to take steps to enter into a contract.
  • Compliance with a legal obligation.
  • Protection of vital interests of the data subject or another person.
  • Performance of a task carried out in the public interest or in the exercise of official authority.
  • Legitimate interests pursued by Creek & Pine or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.

6. Data Subject Rights

Creek & Pine will uphold the rights of data subjects, including:

  • Right to be informed about the collection and use of their personal data.
  • Right of access to their personal data.
  • Right to rectification of inaccurate or incomplete personal data.
  • Right to erasure of personal data (right to be forgotten).
  • Right to restrict processing of their personal data.
  • Right to data portability.
  • Right to object to the processing of their personal data.
  • Rights related to automated decision-making and profiling.

7. Data Security

Creek & Pine will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data.
  • Regular testing, assessment, and evaluation of the effectiveness of technical and organizational measures for ensuring the security of processing.
  • Measures to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
  • Procedures to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident.

8. Data Breach Management

Creek & Pine will promptly assess and respond to data breaches in accordance with applicable laws, including:

  • Notification of data breaches to the relevant supervisory authority within 72 hours of becoming aware of the breach, where required.
  • Communication of data breaches to affected data subjects without undue delay, where required.
  • Documentation of all data breaches, including the facts relating to the breach, its effects, and the remedial actions taken.

9. Third-Party Processors

Creek & Pine will ensure that third-party processors who process personal data on our behalf provide sufficient guarantees to implement appropriate technical and organizational measures to meet the requirements of applicable data protection laws.

10. Training and Awareness

Creek & Pine will provide regular training to employees on data protection and privacy to ensure awareness and compliance with this policy and applicable laws.

11. Monitoring and Review

This policy will be reviewed regularly to ensure its continued relevance and effectiveness. Creek & Pine will monitor compliance with this policy and take appropriate corrective actions where necessary.

You are advised to review this policy periodically for any changes. Changes to this policy are effective when they are posted on this page.

12. Cookies Policy

Creek & Pine values the privacy of its users and is committed to ensuring a user-friendly and transparent experience. As part of our commitment to digital sustainability and privacy, we do not use cookies on our website. This means we do not track your browsing activity, store any personal information, or use third-party analytics services that rely on cookies.

If you have any questions about this Policy, contact us at hi@creekandpine.co

Latest update: 29 February 2024