Privacy Policy

At MIŠKOVIĆ & MIŠKOVIĆ, we believe that transparency is the foundation of all trust. Every time you visit our website, use our services, or get in touch with us, you share certain personal data with us, which we handle responsibly, applying appropriate security standards to it in order to be fully compliant with the regulations governing the protection of personal data.

If you have any questions regarding the collection or processing of your personal data, you can always contact us at: office@miskovic.eu.


A. Data Controller

This Privacy Policy explains how MIŠKOVIĆ & MIŠKOVIĆ Law Firm Ltd with registered seat in Zagreb, Mesnička ulica 15A, PIN (OIB): 72357889876 (hereinafter: “MIŠKOVIĆ & MIŠKOVIĆ“ or “we”) as the Data Controller, collects, uses, and protects personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”).

This Privacy Policy applies to individuals whose personal data we process in the course of our business activities and the provision of legal services, including clients who are individuals,
representatives, members of corporate bodies, shareholders or members, employees and other
contact persons of clients that are legal entities, individuals whose personal data is processed in
connection with a particular legal engagement, suppliers and business partners and their
representatives and contact persons, job applicants and other individuals who contact us
(hereinafter collectively referred to as “Data Subjects” and individually as a “Data Subject”).


By means of this Privacy Policy, in order to ensure fair and transparent processing of personal data, MIŠKOVIĆ & MIŠKOVIĆ provides Data Subjects with clear and comprehensible information regarding the manner in which their personal data are collected, processed, stored, and protected, as well as the rights to which they are entitled in accordance with the applicable personal data protection regulations.

B. Purpose and Legal Basis for Processing

Your personal data is processed for the following purposes and on the following legal basis:

1)  Business communication and responding to inquiries:

We process personal data for the purpose of responding to your inquiries, providing the requested information, conducting business communication, and, where applicable, assessing the possibility of establishing future business cooperation.

In doing so, we process the personal data you provide to us during communication with us, such as your first and last name, contact details, information about the employer or organization you

represent, information about your job title/position, and other information contained in your inquiry or communication.

Depending on the content of your inquiry, the legal basis for processing may be:

• our legitimate interest to conduct business communications or, depending on the content of the inquiry;

• taking steps at your request prior to entering into a business relationship.

When determining the appropriate legal basis, we take into account whether the inquiry/proposal was made by a natural person or on behalf of a legal persons representatives.

Our legitimate interest in processing personal data for this purpose is to enable regular business operations, maintain communication with individuals who contact us, and assess and develop potential business relationships.

2)  Provision of Legal Services to Clients

We process personal data for the purpose of providing legal services to our clients. The type and scope of personal data we process depend on the nature and circumstances of the particular
engagement.

Where our clients are individuals, we process their personal data, such as their first and last name, address, personal identification number (OIB), email address, telephone number and other contact details.

Where our clients are legal entities, we process the personal data of their representatives, authorised representatives, shareholders or members, employees and other contact persons, such as their first and last name, employer, position or job title, email address and telephone number.

In both cases, we also process personal data provided in the course of oral and written
communications, in particular data relating to the provision of the specific legal service.

When providing legal services, we may also process personal data relating to individuals whose
information is relevant to a dispute, transaction, proceeding, or legal matter in connection with which we provide legal services. Depending on the nature and circumstances of the particular matter, such individuals may include, for example, opposing parties and their representatives, authorised representatives, witnesses, experts, notaries public, and other persons connected with the matter.

The personal data we process in this context depends on the nature and circumstances of the
specific engagement and may include, for example, first and last name, contact details, information regarding an individual’s status or role in a particular proceeding or matter, employment information, financial and transaction data, as well as other personal data relevant to the provision of legal services in connection with the specific engagement.

Where special categories of personal data within the meaning of Article 9 of the GDPR, such as data concerning health or trade union membership, are relevant to the provision of legal services in connection with a particular engagement, and their processing is necessary for the provision of legal advice or other legal services in connection with that engagement, we process such data on an appropriate legal basis, as set out below, and where an applicable condition for processing under Article 9(2) of the GDPR is met.

The legal basis for processing personal data for this purpose may be:
• our legitimate interests; or
• the performance of a contract, where the Data Subject is a party to that contract.

Our legitimate interest in processing personal data for this purpose is to ensure the smooth and
effective provision of legal services to our clients.

3)  Management of Relationships with Suppliers and Business Partners

Once a business relationship has been established, we process personal data for the purpose of managing and maintaining our relationships with suppliers and other business partners. This includes business communications, coordination of activities, and the exercise of rights and performance of obligations arising from the business relationship.

Where our suppliers or business partners are individuals, including sole traders, we process their personal data, such as their first and last name, address, personal identification number (OIB), information relating to their business, email address, telephone number and other contact details.

Where our suppliers or business partners are legal entities, we process the personal data of their representatives, persons authorised to represent them, employees and other contact persons, such as their first and last name, employer, position or job title, email address, telephone number and other data necessary for the conduct of the business relationship.

The legal basis for processing personal data for this purpose may be:

• our legitimate interests; or

• the performance of a contract, where the Data Subject is a party to that contract.

Our legitimate interest in processing personal data for this purpose is to ensure the smooth and effective conduct of our business relationships with suppliers and business partners and to exercise rights and perform obligations arising from such business relationships.

4)  Compliance with Anti-Money Laundering and Counter-Terrorist Financing Obligations

Where required under applicable laws and regulations, we process clients’ personal data for the purpose of complying with our obligations relating to the prevention of money laundering and terrorist financing, including identifying and verifying the identity of clients, carrying out required checks and customer due diligence measures, maintaining appropriate records, and reporting to the competent authorities.

For these purposes, we may process clients’ identification and contact details, such as their first and last name, address, date of birth, nationality, personal identification number (OIB), and contact details, as well as personal data relating to persons associated with the client, including persons authorised to represent the client, persons performing equivalent functions, and beneficial owners. Depending on the circumstances of the particular case and applicable legal requirements, we may also collect other data and documentation containing personal data, including copies of identification documents and information and documentation concerning the source of funds.

The legal basis for processing personal data for this purpose is compliance with our legal obligations relating to the prevention of money laundering and terrorist financing.

5) dministrative and Accounting Activities

We process personal data for administrative and accounting purposes related to our business operations, including issuing and receiving invoices, issuing itemised statements of legal services provided, recording payments, maintaining accounting records, and complying with accounting and tax obligations.

For these purposes, we may process identification and contact details of clients, suppliers, and business partners who are natural persons, as well as those of representatives and other contact persons of clients, suppliers, and business partners that are legal entities. We may also process personal data contained in invoices, itemised statements of legal services provided, and other accounting documents, as well as payment and bank account details, including IBANs, and other personal data necessary for these purposes.

The legal basis for processing personal data for administrative purposes is our legitimate interest in the efficient administration of our business operations and the collection of payment for our services. Where we process personal data for the purpose of maintaining accounting records and complying with accounting, tax, and other obligations imposed by applicable laws and regulations, the legal basis for such processing is compliance with our legal obligations.

6) Recruitment Process

We process candidates’ personal data for the purpose of conducting the recruitment process, including receiving and reviewing applications, assessing candidates’ qualifications and experience, conducting the selection process and communicating with candidates.

For this purpose, we process personal data contained in your job application (including your CV and any supporting documentation you provide to us), which may include your first and last name, contact details, information about your education, professional qualifications, work experience, professional skills and references, as well as other information relevant to the assessment of your application

The processing of personal data for this purpose is based on:

• Your consent, where you submit an unsolicited job application to us on your own initiative by email, through social media or via other communication channels; or

• Taking steps at your request prior to potentially entering into an employment contract, where you apply for an open position advertised by us.

We use the personal data provided to us during the recruitment process solely for the purpose of assessing your application, communicating with you and deciding whether to offer you employment.

If the recruitment process results in the establishment of an employment relationship, you will be provided with a separate privacy notice concerning the processing of our employees’ personal data.

C. Categories of Recipients of Personal Data and Transfer of Personal Data outside the EU

Access to personal data is limited to employees and other persons specifically authorised by MIŠKOVIĆ & MIŠKOVIĆ who require such access for the performance of their duties and specific responsibilities.

Depending on the purpose of processing and the nature of the business relationship, personal data may be disclosed to the following categories of recipients:

• Providers of hosting and cloud services;

• Providers of IT services and services relating to the maintenance and development of information systems;

• Providers of accounting, tax, audit, legal, and other professional services;

• Providers of electronic invoicing services;

• Croatian Bar Association

• Competent courts, regulatory authorities, public authorities, and other authorised institutions, where we are required to do so by law or where this is necessary for the establishment, exercise, or defence of our rights and interests, or for the purpose of providing our services.

When we disclose personal data to external service providers acting on our behalf as data processors, we enter into appropriate data processing agreements with such processors.

We strive to use service providers that enable the storage and processing of personal data on servers located within the European Economic Area and, where possible, we choose European regions for data storage.

However, certain service providers may have headquarters or have affiliated companies outside the European Economic Area, or may enable access to data from third countries, for example for the purpose of providing technical support, system maintenance, or other legitimate business needs. In such cases, we ensure the application of appropriate safeguards in accordance with the GDPR, including the conclusion of the European Commission's standard contractual clauses or the application of other lawful data transfer mechanisms.

For more information about the recipients of personal data, or for a list of recipients with their identification details, you may contact us via email at: office@miskovic.eu.

D. Data Retention Periods

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected and processed. When determining the appropriate retention period, we take into account the purpose of the processing, the nature and circumstances of the specific relationship or engagement, the type and scope of the personal data concerned, and the applicable legal obligations regarding its retention.

Certain personal data may be retained for a longer period where such retention is required by law or, considering the circumstances of the specific case, is necessary for the establishment, exercise or defence of legal claims. This includes personal data contained in accounting, tax or other documentation for which a specific retention period is prescribed by applicable law.

When personal data is no longer necessary for the purpose for which it was collected and there is
no legal basis for its continued retention, we delete or anonymise it.

Depending on the purpose of the processing, personal data is retained as follows:

i. Responding to enquiries and establishing business communication

Personal data is retained until the communication has been concluded or for as long as necessary
to process and resolve the relevant enquiry or request.

If the communication results in the establishment of a business relationship, the personal data
necessary for the continuation of that relationship will continue to be processed for the relevant
purposes specified in this Privacy Policy.

ii. Provision of legal services to clients

Personal data is retained for the duration of the engagement or business relationship with the client.

We retain case files relating to proceedings in which we have represented a client for at least ten
years following the final conclusion of the proceedings, in accordance with the laws and regulations governing the legal profession.

Where related proceedings are conducted following the final conclusion of the original proceedings, including enforcement proceedings, proceedings involving extraordinary legal remedies, or proceedings before competent national or international courts or other authorities, we retain the relevant case files and the personal data contained therein for the duration of such proceedings and for at least ten years following their conclusion or the termination of our representation, depending on the circumstances of the particular case.

In relation to other legal services, the retention period for personal data is determined taking into account the nature and circumstances of the particular engagement and the purpose for which the personal data is processed.

iii. Business relationships with suppliers and business partners

Personal data is retained for the duration of the business relationship and, following its termination, in accordance with the general personal data retention rules set out in this section.

iv. Administrative and accounting purposes

Personal data is retained for the periods prescribed by applicable accounting, tax and other regulations, or for as long as necessary to fulfil the purposes for which it is processed.

v. Compliance with anti-money laundering and counter-terrorist financing obligations

Personal data, information and documentation collected for this purpose are retained for ten years following the termination of the business relationship, or otherwise in accordance with the retention periods and conditions prescribed by the Anti-Money Laundering and Terrorist Financing Act and other applicable laws and regulations.

‍v. Recruitment process

Personal data of candidates who apply for an advertised position is retained until the completion of the selection process and the decision on the selection of the successful candidate.

If a candidate submits an unsolicited application for employment that is not related to a specific
advertised position, we will consider the application within a reasonable period in order to assess
whether there is a suitable recruitment need. If no such need exists, the personal data contained in the application will be deleted no later than one month after receipt.

After the expiry of the above periods, candidates’ personal data will be retained for consideration for future employment opportunities only where the candidate has given consent for this purpose. In such case, the personal data will be retained for a maximum period of 12 months from the date on which consent was given or until consent is withdrawn, whichever occurs first.

E. Your Rights in Relation to processing of personal data

In accordance with the GDPR, you have the following rights:

Right to information and access – you have the right to obtain confirmation as to whether we process personal data concerning you and, where we do, the right to access such personal data and information about its processing, including the right to obtain a copy of the personal data being processed (Article 15 of the GDPR).

Right to rectification – you have the right to request the rectification of inaccurate personal data and the completion of incomplete personal data (Article 16 of the GDPR).

Right to erasure (“right to be forgotten”) – you have the right to request the erasure of personal data in the circumstances provided for under the GDPR, for example, where the personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed, where it has been unlawfully processed, or where it must be erased in order to comply with a legal obligation (Article 17 of the GDPR).

• Right to restriction of processing – you have the right to request the restriction of the processing of your personal data if you contest its accuracy, for the period necessary to verify its accuracy; if the processing is unlawful but you oppose the erasure of the personal data and request the restriction of its use instead; if we no longer needs the personal data for the purposes of processing, but you require it for the establishment, exercise, or defence of legal claims; or if you have objected to the processing, pending verification of whether the our legitimate grounds override your grounds (Article 18 of the GDPR).

Right to data portability – where the conditions set out in the GDPR are met, you have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format and to transmit such data to another controller (Article 20 of the GDPR).

Right to object – where the processing of personal data is based on legitimate interests, you have the right, on grounds relating to your particular situation, to object to the processing of your personal data (Article 21 of the GDPR).

Right to withdraw consent – where processing is based on your consent, you have the right to withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal (Article 7(3) of the GDPR).

Right not be subject to a decision based solely on automated processing – although we do not use automated decision-making in the processing of personal data, Data Subjects generally have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them (Article 22 of GDPR).

To exercise these rights, contact us at: office@miskovic.eu.

We may need to verify your identity before processing your request.

If you believe your data has been handled unlawfully, you have the right to lodge a complaint with: Croatian Personal Data Protection Agency (AZOP), Ulica Metela Ožegovića 16, HR - 10 000 Zagreb

Telephone: +385 (0)1 4609-000,

E-mail: azop@azop.hr,

website: http://www.azop.hr

F. Obligation to provide data

As a rule, you are not obliged under the law to provide personal data.

However, provision of certain personal data may be necessary in order to respond to Data Subjects’ inquiries, establish and maintain a business relationship, fulfil the legal obligations of MIŠKOVIĆ & MIŠKOVIĆ, as well as to enable participation in a recruitment selection process or entering into a contract at your request.

If Data Subject does not provide the personal data necessary for the above-mentioned purposes, we may not be able to respond to the inquiry, establish or perform a contractual relationship, or comply with its legal obligations.

In certain cases, the provision of specific personal data and documentation is necessary for us to
comply with the legal obligations applicable to us in connection with the provision of legal services. This applies in particular to the personal data and documentation that we are required to collect in order to comply with our obligations in the area of anti-money laundering and counter-terrorist financing. If you do not provide us with the required personal data and documentation, we may be unable to accept an engagement, provide certain legal services or continue an existing business relationship.

G. Source of Personal Data

Personal data of Data Subjects processed for the purposes set out in this Privacy Policy is collected from the following sources:

• Directly from you, for example by email, post, through our website, social media (Linkedin) or otherwise in the course of business communication and cooperation;

• Directly from our clients, in particular where, in the course of providing legal services, they provide us with documentation or information containing personal data of other individuals;

• From other persons or authorities involved in proceedings or other matters in connection with which we provide legal services, for example courts and other competent authorities, opposing parties and their representatives or attorneys, notaries public and other participants in the relevant proceedings or matter;

• From publicly available sources and records, such as the court register, land registers, other public registers and records, and publicly available online sources;

• In relation to job applicants, from third parties who provide us with references concerning the applicant, such as former employers.

H. Automated Decision-Making

We do not make any decisions based solely on automated processing, including profiling.

I. How We Protect Your Personal Data

We place particular importance to the protection of personal data and information security and continuously take care to ensure the security of the personal data we process. To this end, we implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, as well as other forms of unauthorised or unlawful processing.

Our employees and other authorised persons perform their duties in compliance with applicable legal, professional, and contractual confidentiality obligations.

We have established and maintain an information security management system aligned with the requirements of ISO/IEC 27001, an internationally recognised standard that sets requirements for the secure and responsible management of information. In this way, we systematically manage information security risks and continuously work to ensure the protection of personal data and other confidential information.


J. Updates to this Privacy Policy

We retain right to update this Privacy Policy from time to time to reflect changes in our data practices or legal requirements.

Any updates will be posted on this page with a revised “Last updated” date.

For any questions or requests related to the processing of personal data, you may contact us at any time using the contact details provided in this Privacy Policy.

Last updated: March, 2026

Contact us

© Copyright 2024 - Miskovic.eu | All Rights Reserved | Company registered at Commercial Court in Zagreb under the number: 081198992 | Board: Iva Mišković and Pavo Mišković | Share capital: EUR 46.560,00, paid in full | IBAN: HR3023600001102728228, SWIFT/BIC: ZABAHR2X, Zagrebačka banka d.d. Zagreb.
Our TeamExpertiseContactNews