Privacy Policy
1. Purpose and Objective
Using the services of FINA Cash Services Ltd., Zagreb, Ulica Julija Knifera 10 (hereinafter: “Fina GS”), you entrust us with your data. All personal data that Fina GS collects through the website on which this Privacy Policy (hereinafter: the “Policy”) is published, as well as through other forms of direct, written, or electronic communication conducted in the course of its business activities that contain or refer to this Policy, are collected, processed, and stored in accordance with the terms of this Policy, Fina GS’s internal personal data protection documents, and the regulations applicable in the Republic of Croatia.
This Policy describes the data we collect, how we process it, and the purposes for which we use it, as well as your rights in relation to your personal data. By accessing or using this website, you acknowledge that you have read and understood its contents, your rights, and the ways in which those rights may be exercised. We will process your data only for the purposes for which it was collected. In accordance with the applicable personal data protection legislation, upon your request you will be granted access to your personal data, the right to have such data corrected where necessary, and all other rights set out in Section 8.
Where the processing of your personal data is based on your consent given for specific processing purposes, you have the right to withdraw your consent for any of those purposes at any time. This includes consent to receive information about our news and events. In addition, every email we send provides you with the option to unsubscribe from the mailing list.
This Privacy Policy is effective as of 3 November 2025.
2. Contact Information
If you have any questions regarding the processing of your personal data, or if you wish to withdraw, for any reason and at any time, your consent to the processing of personal data collected through this website, please contact us using the following contact details:
FINA Cash Services Ltd.
Ulica Julija Knifera 10
10000 Zagreb, Croatia
Phone: +385 (0)1 6419 000
Data Protection Officer: dpo@finags.hr
Please use the contact forms available to you, as they contain all the information we require to continue our communication and process your requests efficiently.
3. Personal Data We Collect and Process
Depending on the service we provide to you, which determines the purpose of collecting personal data, and on the communication channels we use, we may collect the following personal data:
a) your basic personal data: name and surname, address, personal identification number (OIB), date of birth, gender, mobile phone number and contact details (email address and telephone number), as well as information relating to the type of contractual relationship.
b) other personal data: data that you or third parties provide to us when entering into a contract or during the course of a contractual relationship, such as data contained in an identity card, signatory authorisations, or powers of representation. This does not include special categories of personal data as defined by data protection legislation, in particular data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, genetic data, or data concerning health.
c) data relating to the use of Fina GS services: for example, the type of services used, the number of services provided, and the location where the services are delivered.
Fina GS does not collect personal data relating to children (defined as persons under the age of 16) without the prior, verifiable consent of their parent or legal guardian. A parent or legal guardian has the right, upon request, to review the data provided by the minor and/or to request the deletion of such data.
4. Access to and Protection of Personal Data
All collected personal data is processed fairly and lawfully and is accessible only to Fina GS employees and authorised persons (data processors to whom such data has been lawfully disclosed and is necessary for the performance of the agreed processing activities), as well as to public authorities and organisations, or authorities and organisations exercising official powers in accordance with the applicable legal regulations, where they have a lawful right of access to personal data. All our employees and other authorised persons are responsible for complying with data protection and privacy principles.
Access to and processing of the personal data of natural persons, as well as the purposes for which such data is processed, are governed by agreements concluded with Fina GS’s clients, employees, suppliers, subcontractors, and other contractual partners, as well as by the authorisations and responsibilities relating to data access within Fina GS and the applicable legal and regulatory framework.
We protect the personal data we process (including collecting, recording, organising, structuring, storing, adapting or altering, retrieving, consulting, using, disclosing by transmission, disseminating or otherwise making available, aligning or combining, restricting, erasing, or destroying such data) by implementing appropriate technical and organisational measures and applying high standards of information security.
Fina GS has certified its Information Security Management System in accordance with ISO 27001, its Quality Management System in accordance with ISO 9001, its Environmental Management System in accordance with ISO 14001, and its Occupational Health and Safety Management System in accordance with ISO 45001. In addition, Fina GS holds a certificate of conformity for its Risk Management System in accordance with ISO 31000.
Fina GS employs technological and security measures, policies, and other procedures to protect the personal data of users of its website against unauthorised access, misuse, disclosure, loss, or destruction. To ensure the protection of website user data, Fina GS applies industry-standard security measures, including firewalls and password protection.
However, users are responsible for ensuring that the devices they use are secure and protected against malicious software, such as Trojan horses, computer viruses, and worms. Users of the website should be aware that, without appropriate security measures in place (for example, a securely configured web browser, up-to-date antivirus software, a personal firewall, and avoidance of software from untrusted sources), there is a risk that the data and passwords used to protect access to personal data may be disclosed to unauthorised third parties.
5. Use of Cookies
The Fina GS website uses cookies to ensure a better user experience and improved website functionality.
More information describing the use of cookies can be found in the Cookie Policy. Cookie Policy.
6. Retention of Personal Data
Fina GS adheres to the principle of retaining personal data only for as long as necessary to fulfil the purpose for which the data is processed. For each data storage system, Fina GS defines the period during which personal data will be stored or, where this is not possible, the criteria used to determine that period.
Personal data is retained and stored using appropriate technical and organisational measures designed to ensure its confidentiality, integrity, and availability.
Fina GS may be subject to various obligations regarding the retention and storage of personal data. These obligations include requirements governing how long personal data may or must be retained and stored, as well as when and how such data may be deleted or destroyed.
Retention and storage obligations relating to personal data may arise from laws or other regulations, as well as from contracts and declarations entered into by the data controller with employees, customers, suppliers of products and services, and other business partners.
Fina GS may also be involved in unforeseen events, such as legal proceedings, warranty period extensions, or disasters, which require access to original documents in order to protect its interests or the interests of its employees, customers, suppliers, and other partners. For these reasons, certain personal data may need to be retained for longer than the prescribed retention period.
7. Disclosure of Personal Data
Fina GS may disclose personal data to third parties for the following purposes:
a) in connection with the provision of services, provided that the client has been lawfully informed of such disclosure;
b) in response to requests from public authorities or where such use is required by law, court orders, or competent governmental authorities;
or c) for the purposes of conducting audits, investigations, or responding to complaints or security threats.
Where Fina GS engages external service providers to process your personal data, Fina GS will inform you in advance in accordance with the applicable personal data protection.
Your personal data will not be transferred to third countries or international organisations without prior notice to you. Your personal data may be disclosed to external service providers located within the European Union, as well as to external service providers in third countries for which the European Commission has issued an adequacy decision, or where Fina GS has agreed appropriate safeguards with the service provider or ensured compliance with binding personal data protection obligations.
Prohibition of Use for Direct Marketing Purposes: without your explicit consent, Fina GS will not use your personal data for direct marketing purposes, nor will it sell, disclose, or otherwise make your personal data available to third parties for use in their own direct marketing activities.
8. Your Rights and How to Exercise Them
a) Right to Be Informed
At the time of collecting your personal data, we are required to provide you with information in a clear and easily accessible manner, in accordance with applicable legal requirements. Such information includes, but is not limited to, the purposes of processing, the legal basis for processing, the recipients of the data, the retention period, and your rights in relation to your personal data. Where we have obtained your personal data from a third party through lawful means, we will, at the time of our first communication with you, provide you with the aforementioned information as well as information regarding the source of the personal data
b) Right of Access
You may request confirmation as to whether your personal data is being processed and, where such personal data is being processed, access to that personal data.
c) Right to Rectification
If we process personal data relating to you that is incomplete or inaccurate, you may request that we correct or supplement such data at any time.
d) Right to Erasure
You may request the erasure of your personal data if we have processed it unlawfully or where such processing constitutes a disproportionate interference with your protected interests. Please note, however, that there may be reasons preventing the immediate deletion of your data, for example where retention is required to comply with statutory record-keeping or archiving obligations.
e) Right to Withdraw Consent
Where the processing of your personal data is based on the consent you have provided, you have the right to withdraw that consent at any time.
f) Right to Restriction of Processing
You may request the restriction of the processing of your personal data in the following circumstances:
- if you contest the accuracy of the personal data, for a period enabling us to verify its accuracy;
- if the processing is unlawful and you oppose the erasure of the personal data and request the restriction of its use instead;
- if we no longer need the personal data for the purposes of processing, but you require it for the establishment, exercise, or defence of legal claims; or
- if you have objected to the processing of your personal data, pending verification of whether our legitimate grounds override your interests, rights, and freedoms.
g) Right to Data Portability
You may request that we provide the personal data you have supplied to us in a structured, commonly used, and machine-readable format:
- where we process such data on the basis of your consent, which you may withdraw, or where the processing is necessary for the performance of a contract; and
- where the processing is carried out by automated means.
h) Right to Object
If we process your personal data for the performance of a task carried out in the public interest or in the exercise of official authority, or where the processing is based on our legitimate interests, you have the right to object to such processing where there are grounds relating to your particular situation and your interest in protecting your personal data.
i) Right to Lodge a Complaint
If you believe that we have violated Croatian or European data protection regulations in the course of processing your personal data, we encourage you to contact us so that we may clarify and resolve any concerns you may have. You also have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) or with another competent supervisory authority within the European Union.
Exercise of Rights
If you wish to exercise any of the rights described above, please contact us using the contact details provided in Section 2 of this Policy and by using the forms available on our website for that purpose.
Identity Verification
In the event of doubt, we may request additional information to verify your identity. This is done in order to protect your rights and privacy.
Abuse of Rights
If you exercise any of the above rights excessively and with an evident intention to abuse those rights, we may charge a reasonable administrative fee or refuse to process your request, in accordance with applicable personal data protection legislation.
9. Changes and Updates
Fina GS will periodically review and update this Privacy Policy. Any amendments or updates to this Privacy Policy will be published on our website.
10. Scope of Application
All employees of Fina GS, all individuals temporarily engaged under contractual arrangements, and all external associates or partners of Fina GS who come into contact with personal data processed by Fina GS in its capacity as a data controller or data processor are required to comply with the provisions of this Policy.
Forms for Submitting Data Subject Rights Requests:
Prigovor na obradu osobnih podataka
Zahtjev za brisanje osobnih podataka
Zahtjev za ispravak ili nadopunu osobnih podataka
Zahtjev za ograničenje obrade osobnih podataka
Zahtjev za pristup osobnim podacima
Please ensure that, when submitting a request, you provide all required information and submit the request using one of the methods specified in the relevant form.

