Privacy Policy
1. Purpose and Objective
By using the services of FINA Cash Services Ltd., headquartered in Zagreb, Julija Knifera Street 10 (hereinafter: Fina GS), you entrust us with your data. All personal data collected by Fina GS through the website on which this Privacy Policy is published (hereinafter: the Policy) and through other forms of direct, written, or electronic communication within the scope of its business activities that contain or refer to this Policy are collected, processed, and stored in accordance with the terms of this Policy, Fina GS internal personal data protection documents, as well as the regulations applicable in the Republic of Croatia.
This Policy describes the data we collect, how we process it, the purposes and legal bases for processing, retention periods, data recipients, and the rights you have regarding your personal data. The Policy is made available to ensure transparent information to data subjects regarding the processing of personal data carried out by Fina GS.
Your data will be processed only for the purposes for which it was collected.
In accordance with the applicable personal data protection legislation, upon your request you will be granted access to your personal data, any correction thereof, as well as all other rights listed in Section 9.
If the legal basis for processing your personal data is your consent, which you have provided to us for specific processing purposes, you have the right to withdraw your consent for any of those processing purposes at any time. This also includes receiving information about our news and events, whereby every email message contains an option to unsubscribe from the mailing list.
This Policy shall apply from 03 August 2026.
2. Contact Information
If you have any questions regarding the processing of your personal data, or if you wish to withdraw your consent for the processing of personal data collected through this website at any time and for any reason, please contact us using the following contact details:
FINA Cash Services Ltd.
Julija Knifera Street 10
10000 Zagreb
Tel. (+385) 1 6419 000
Data Protection Officer: dpo@finags.hr
Please use the contact forms available to you, as they contain all the information required for us to continue communication and process your requests.
3. Personal Data We Collect and Process, Legal Basis and Purpose of Processing
Depending on the service we provide to you, which determines the purpose of collecting personal data and the communication channels we use, we collect the following personal data:
a) your basic personal data: first and last name, address, personal identification number (OIB), date of birth, gender, mobile phone number and contact details (email address, telephone number), information regarding the type of contractual relationship. We process these data on the basis of Article 6(1)(b) of the General Data Protection Regulation, as processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract.
b) other personal data: data made available to us by you or third parties when entering into a contract or during the contractual relationship, such as data from an identity card, signing or representation authorizations; this does not include special categories of personal data, in particular data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, genetic data, or data concerning health. We process these data on the same legal bases and for the same purposes as the basic personal data referred to in point a).
c) data relating to the use of Fina GS services: for example, the type of services used, the number of services, and the location where services are provided. We process these data on the basis of our legitimate interest for the purpose of monitoring, improving, and ensuring the security of service provision (Article 6(1)(f) of the General Data Protection Regulation).
d) data processed through video surveillance systems: video recordings that may contain a person's image, physical appearance, posture, movements, behaviour, presence at a specific location and time, vehicle registration plates in the immediate vicinity, and other visual information that may be linked to an identified or identifiable natural person. Processing generally does not include special categories of personal data or data relating to criminal convictions and offences unless such data are incidentally recorded in the context of a security incident. The legal basis, purposes, and retention periods are described in detail in Section 4 of this Policy.
e) data processed through cookies: data relating to cookie settings and the user's language preferences, user session identifiers, and statistical data on website usage (unique user identifiers, traffic information, and information regarding how the website is used). We process these data on the basis of consent (Article 6(1)(a) of the General Data Protection Regulation) for the purpose of improving website functionality and providing a better user experience.
Fina GS does not provide services intended for children and, as a rule, does not collect children's personal data. Exceptionally, a child's personal data may be processed incidentally if the child is present within the video surveillance perimeter of Fina GS vehicles or premises, whereby such processing is carried out only to the extent necessary for the security purposes described in this Policy. Fina GS does not process children's personal data for marketing purposes, nor does it knowingly collect children's data on the basis of consent without prior verifiable authorization from a parent or legal guardian where such authorization is required.
4. Video Surveillance of Vehicles and Premises
Fina GS operates video surveillance in armored and other official vehicles used for the transportation and escort of security consignments, as well as in security-relevant Fina GS premises, particularly vaults, cash handling areas, storage facilities, access areas, and other premises where cash, valuable consignments, security containers, documentation, or other high-value assets are located or processed. Processing is based on the legitimate interest of Fina GS pursuant to Article 6(1)(f) of the General Data Protection Regulation, consisting of the protection of the life, health, and safety of employees and other persons, the protection of entrusted assets and valuable consignments, the prevention and investigation of robberies, thefts, acts of violence, traffic accidents, harmful events, and other security incidents, as well as the establishment, exercise, and defense of legal claims.
Video surveillance is not used for general, continuous, or preventive monitoring of employee performance, profiling, biometric identification, automated decision-making, or audio recording. Cameras are directed exclusively toward security-relevant areas: in vehicles, toward the vehicle interior, the vault compartment, the driver's cabin, and the immediate surroundings of the vehicle to the extent necessary for security purposes; and within Fina GS premises, toward areas necessary for the protection of persons, assets, and business operations. Recording of wider public areas, private premises, or areas that are not security-relevant is not permitted except where incidental and necessary due to the vehicle's position or a security-related event.
Recordings are reviewed, extracted, or disclosed only where there is a justified security, legal, supervisory, or organizational need, for example in the event of a security incident, traffic accident, robbery, theft, shortage, property damage, complaint, request from a competent authority, insurance claim, or the need to conduct judicial, administrative, misdemeanour, criminal, employment-related, or other proceedings. Access to recordings is granted only to authorized Fina GS personnel and, where necessary, authorized external service providers or competent authorities where there is a valid legal basis. Access, review, export, and extraction of recordings are logged and restricted in accordance with the principle of necessity.
Recordings are retained only for as long as necessary to achieve the purpose of processing, and for no longer than 6 months, unless a particular recording has been extracted due to a security incident, complaint, insurance claim, request from a competent authority, or the need to conduct or potentially defend legal proceedings, in which case it shall be retained for as long as there is a justified need, until the relevant proceeding has been concluded, or until the expiry of the limitation periods for legal claims. Upon expiry of the applicable retention period, recordings shall be securely deleted, overwritten, or destroyed.
Vehicles and premises under video surveillance are marked with visible notices or stickers containing basic information about the video surveillance, including the identity of the controller, the purpose of processing, the legal basis, and contact details for exercising data subject rights, and referring to this Privacy Policy as the place where more detailed information is available. Fina GS employees are additionally informed through internal acts, notices, training sessions, or other appropriate internal communication channels.
5. Access to and Protection of Personal Data
All collected personal data are processed fairly and lawfully and are accessible only to Fina GS employees and authorized persons (processors to whom such data have been lawfully disclosed and are necessary for carrying out the agreed processing, as well as authorities and organizations acting in the public interest or exercising official powers in accordance with applicable legislation) who have a lawful right of access to personal data. All our employees and other authorized persons are responsible for respecting privacy protection principles.
Access to and handling of personal data of natural persons, as well as the purposes of processing, are defined by contracts with Fina GS clients, employees, suppliers, subcontractors, and other contractual partners, as well as by authorizations and responsibilities regarding data access within Fina GS and applicable legal regulations.
The personal data we process (collect, record, organize, structure, store, adapt or alter, retrieve, consult, use, disclose by transmission, disseminate or otherwise make available, align or combine, restrict, erase, or destroy) are protected by appropriate technical and organizational measures while maintaining high security standards.
Fina GS has certified its Information Security Management System in accordance with ISO 27001, its Quality Management System in accordance with ISO 9001, its Environmental Management System in accordance with ISO 14001, its Occupational Health and Safety Management System in accordance with ISO 45001, and holds certification confirming compliance of its Risk Management System with ISO 31000.
Fina GS uses technological and security measures, policies, and other procedures to protect the personal data of users of its website from unauthorized access, misuse, disclosure, loss, or destruction. To ensure the protection of website user data, Fina GS employs industry-standard safeguards such as firewalls and password protection. However, users are responsible for ensuring that the computer they use is secure and protected against malicious software such as trojans, computer viruses, and worms. Website users should be aware that without appropriate security measures, such as a secure web browser configuration, up-to-date antivirus software, a personal firewall, and avoiding software from suspicious sources, there is a risk that data and passwords used to prevent unauthorized access to personal data may be disclosed to unauthorized third parties.
6. Use of Cookies
The Fina GS website uses cookies to ensure a better user experience and improved website functionality.More information describing the use of cookies can be found in the Cookie Policy.
7. Retention of Personal Data
Fina GS adheres to the principle of retaining personal data only until the purpose of the processing of personal data has been fulfilled and, for each storage system, defines the period during which personal data will be retained or, where this is not possible, the criteria used to determine that period.
Personal data are retained and stored using technical and organizational measures that ensure their confidentiality, integrity, and availability.
With regard to the retention and storage of personal data, Fina GS may be subject to various obligations. These obligations include how long personal data may or must be retained and stored and when and how they may be deleted and destroyed.
Obligations regarding the retention and storage of personal data may arise from laws or other regulations, or from agreements and declarations entered into by the controller with employees, customers, suppliers of products and services, or other partners.
Fina GS may be involved in unforeseen events such as litigation, extension of warranty periods, or disasters that require access to original documents in order to protect its interests or the interests of employees, customers, suppliers, and other partners. For these reasons, certain personal data may need to be retained for a longer period than otherwise prescribed.
8. Disclosure of Personal Data
Fina GS may disclose personal data to third parties for use for the following purposes:
a) in connection with the provision of services, provided that the client has been lawfully informed of such disclosure,
b) in response to requests from public authorities or where such use is required by law, court orders, or official authorities, or
c) for the purposes of business audits, conducting investigations, or responding to complaints or security threats.
If we engage external service providers to process your personal data, Fina GS will inform you thereof in advance in accordance with the applicable personal data protection regulations.
Your personal data will not be transferred to third countries or international organizations without informing you. Your personal data may be transferred to external service providers within the European Union, as well as to external service providers in third countries for which an adequacy decision has been adopted by the European Commission, or where we have agreed appropriate safeguards with the service provider or ensured compliance with binding personal data protection rules.
Prohibition of use for direct marketing purposes: without your explicit consent, Fina GS will not use your personal data for direct marketing purposes, nor will it sell or otherwise make personal data available to third parties for their own direct marketing purposes.
9. Your Rights and How You Can Exercise Them
a) Right to Information
At the time your personal data are collected, we are required to provide you with information in accordance with applicable legislation in a clear and easily accessible manner. Such information includes, but is not limited to: the purposes of processing, the legal basis for processing, data recipients, the retention period, and your rights relating to personal data. In situations where we have received your personal data from a third party (in a lawful manner), upon our first contact with you we will, in addition to the above information, also provide information on the source of the personal data.
b) Right of Access
You may request confirmation as to whether your personal data are being processed and, where such personal data are being processed, access to those personal data.
c) Right to Rectification
If we process your personal data that are incomplete or inaccurate, you may request at any time that we correct or complete such data.
d) Right to Erasure
You may request the erasure of your personal data if we have processed them unlawfully or if such processing constitutes a disproportionate interference with your protected interests. Please note that there may be reasons preventing immediate deletion, for example where statutory retention obligations apply.
e) Right to Withdraw Consent
If the processing of your personal data is based on the consent you have provided to us, you have the right to withdraw that consent at any time.
f) Right to Restriction of Processing
You may request the restriction of the processing of your data:
- if you contest the accuracy of the data during the period that enables us to verify the accuracy of such data;
- if the processing of the data was unlawful, but you oppose the erasure of the data and instead request the restriction of their use;
- if we no longer require the data for the intended purposes, but you still require them for the establishment, exercise, or defence of legal claims; or
- if you have lodged an objection regarding the distribution of such data.
g) Right to Data Portability
You may request that we provide the data you have entrusted to us in a structured, commonly used, and machine-readable format:
- if we process such data on the basis of your consent, which you may withdraw, or for the performance of a contract; and
- if the processing is carried out by automated means.
h) Right to Object
If the processing of your personal data is based on the legitimate interest of Fina GS or on the performance of a task carried out in the public interest, you may object to such processing in accordance with the General Data Protection Regulation. Fina GS will consider each objection on an individual basis and will continue the processing only where there are compelling legitimate grounds that override your interests, rights, and freedoms or where the processing is necessary for the establishment, exercise, or defence of legal claims.
i) Right to Lodge a Complaint
If you believe that we have violated data protection regulations in processing your personal data, please contact us first so that we may clarify any issues. In any event, you have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) or another competent supervisory authority within the European Union.
Exercising Your Rights
If you wish to exercise any of the rights listed above, please contact us using the contact details set out in Section 2 of this Policy and by using the forms available on our website for that purpose.
Verification of Identity
In case of doubt, we may request additional information to verify your identity. This serves to protect your rights and privacy.
Abuse of Rights
If you exercise any of the above rights excessively and with an evident intention of abuse, we may charge an administrative fee or refuse to process your request.
10. Changes and Updates
Fina GS will update this Policy on a regular basis.
Any amendments and updates to this Policy will be published on our website.
11. Scope of Application
All Fina GS employees, all persons temporarily performing work under a contract, and all external associates or partners of Fina GS who come into contact with personal data processed by Fina GS as a controller or processor are required to comply with the provisions of this Policy.
Forms for Submitting Requests to Exercise Data Subject Rights:
Objection to the Processing of Personal Data
Request for Erasure of Personal Data
Request for Rectification or Supplementation of Personal Data
Request for Restriction of the Processing of Personal Data
Request for Access to Personal Data
Please ensure that you provide all required information when submitting a request and that the request is submitted using one of the methods specified in the relevant form.

