Law Office Toni Primorac
Last updated: 11 August 2026
1. Data controller
The controller of personal data is:
Law Office Toni Primorac
Prolaz Marije Krucifikse Kozulić 2/III, 51000 Rijeka, Republic of Croatia
OIB (personal ID no.): 22920810231
Email: t.primorac@primorac-legal.hr
Phone: 091 781 8171
The office is not required to appoint a data protection officer. For any questions about the processing of your personal data, please contact us directly using the details above.
2. What data we collect
a) Data you provide to us yourself. When you contact us via the contact form, by email or by phone, we collect your name and surname, email address, telephone number if you provide it, and the content of your message. Messages sent via the form are also stored in the website database.
b) Data in the course of providing legal services. If you become our client, we process the data necessary for representation and advice, including identification data and data from documents and case files. This data may also include special categories of personal data (for example health data in social law cases) and data on criminal convictions. We process them solely to the extent necessary for the establishment, exercise or defence of legal claims.
c) Website usage data. When you visit the site, technical data is recorded: IP address, browser and device type, pages visited, time of visit and the source from which you arrived. This data is collected via cookies and similar technologies and is described in more detail in the Cookie Policy.
3. Purposes and legal bases of processing
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Responding to your enquiry and pre-contractual communication | Art. 6(1)(b) — taking steps at your request prior to entering into a contract |
| Providing legal services and representation | Art. 6(1)(b) — performance of a contract |
| Fulfilling the office’s legal obligations | Art. 6(1)(c) — Attorneys Act, anti-money-laundering regulations, tax and accounting regulations |
| Establishment, exercise or defence of legal claims | Art. 9(2)(f) for special categories of data |
| Security and proper functioning of the website | Art. 6(1)(f) — legitimate interest |
| Traffic measurement and advertising | Art. 6(1)(a) — your consent, given via the cookie banner |
You may withdraw your consent at any time, without affecting the lawfulness of processing prior to withdrawal. You withdraw it by clicking the manage-consent link at the bottom of the page.
4. Cookies and third-party tools
The site uses cookies. Necessary cookies are set without consent because they are essential for the site to function. Measurement and advertising cookies are set only after your consent.
For advertising we use Google Ads (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Google Consent Mode is applied, so until you consent, no data enabling personalisation is passed to Google.
A complete list of cookies, their purposes and duration can be found in the Cookie Policy.
5. Who else may access the data
We do not sell data or share it with third parties for marketing purposes. Access may be had by: the website hosting provider: Plus Hosting Grupa d.o.o., Valturska ulica 82, 52100 Pula; the website maintenance provider: WEBPOINT, obrt za web i marketing, Vukovarska 10A, 51000 Rijeka, OIB: 99232673370; Google Ireland Limited — measurement of advertising effectiveness; the email service provider as part of the hosting service (Plus Hosting Grupa d.o.o.); trainee lawyers and office staff, bound by the obligation of attorney-client privilege; and public authorities and courts, where required by law.
Data processing agreements in accordance with Art. 28 GDPR have been concluded with all processors.
6. Transfers outside the European Economic Area
Data is generally processed within the EEA. When Google services are used, transfer to the United States is possible. That transfer is based on the EU–US Data Privacy Framework and on standard contractual clauses approved by the European Commission.
7. How long we keep the data
| Type of data | Retention period |
|---|---|
| Enquiries that did not result in representation | 1 year from the last communication |
| Case files | 10 years from the end of representation, unless a special regulation requires longer retention |
| Accounting documentation | 11 years, in accordance with tax regulations |
| Documentation under anti-money-laundering regulations | 10 years from the end of the business relationship |
| Cookie consent data | until consent is withdrawn or the cookie expires |
After the period expires, the data is deleted or anonymised.
8. Your rights
You have the right of: access — to request confirmation of whether we process your data and to obtain a copy of it; rectification — to request the correction of inaccurate or completion of incomplete data; erasure — to request deletion of data when there is no longer a basis for processing; restriction of processing — in the cases under Art. 18 GDPR; portability — to receive the data in a machine-readable format; objection — to object to processing based on legitimate interest; and withdrawal of consent — at any time, for processing based on consent.
Requests should be sent to t.primorac@primorac-legal.hr. We will respond within one month. To protect your data, we may request additional confirmation of identity.
Limitation: the exercise of these rights may be restricted where the data is covered by attorney-client privilege. The office is obliged to keep secret everything a client has entrusted to it, so we cannot comply with third-party requests for access to such data.
9. Right to lodge a complaint
If you believe that our processing of your data violates the regulations, you have the right to lodge a complaint with the supervisory authority: Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop@azop.hr, www.azop.hr.
10. Automated decision-making
We do not make decisions based solely on automated processing, including profiling, which would produce legal effects concerning you.
11. Security
We apply appropriate technical and organisational protection measures, including an encrypted connection (SSL), access control and regular system maintenance. Office staff are bound by the obligation of attorney-client privilege.
12. Changes to this policy
We may amend this policy from time to time to comply with regulations or changes in the way we work. The current version is always published on this page, with the date of the last amendment.

Hrvatski
Deutsch
Italiano
Français
Українська