Effective date: 1st August 2026
Petrinić & Braut Joint Law Office (“the Office”, “we”, “us” or “our”) respects the privacy of visitors to its website https://bplaw.hr/ (the “Website”) and is committed to processing personal data responsibly.
This Privacy Policy explains what personal data we may collect, why we process it, the legal grounds for such processing, how long we retain it, with whom we may share it and what rights you have in relation to your personal data.
Personal data are processed in accordance with Regulation (EU) 2016/679 (the “General Data Protection Regulation” or “GDPR”), the Croatian Act on the Implementation of the General Data Protection Regulation and other applicable laws of the Republic of Croatia and the European Union.
1. Data controller
The controller of your personal data is:
Petrinić & Braut Joint Law Office
Jelačićev trg 7
51000 Rijeka, Republic of Croatia
Telephone: +385 51 579 397
E-mail: bp@bplaw.hr
For questions concerning the processing of your personal data, you may contact us using the above e-mail or postal address.
2. Personal data we collect
Depending on how you interact with the Website, we may process the following categories of personal data.
2.1. Data submitted through the contact form
When using the contact form, you may provide:
- first and last name;
- telephone number;
- e-mail address;
- subject of the message;
- content of the message;
- other information you voluntarily provide in your communication.
We recommend that you do not submit unnecessary special categories of personal data or other highly sensitive information through the contact form.
2.2. Technical data
When you visit the Website, certain technical information may be processed automatically, depending on the server, browser settings and technical services used, including:
- IP address;
- date and time of access;
- browser and device information;
- operating system;
- Website security and usage information;
- other technical information necessary for the proper and secure operation of the Website.
The exact scope of technical data depends on the technical configuration of the Website and its hosting provider.
3. Purposes and legal bases for processing
We process personal data only where an appropriate legal basis exists.
3.1. Responding to enquiries
Personal data submitted through the contact form or by e-mail may be processed to:
- receive and process your enquiry;
- respond to your enquiry;
- communicate with you;
- take steps at your request prior to entering into a contractual relationship.
Depending on the circumstances, the legal basis may be Article 6(1)(b) GDPR, where processing is necessary to take steps at the data subject’s request prior to entering into a contract, or Article 6(1)(f) GDPR, where processing is based on our legitimate interest in effective communication and management of business enquiries.
3.2. Provision of legal services
If you engage the Office, personal data may be processed for the purposes of:
- providing legal services;
- communicating with the client;
- performing contractual and professional obligations;
- managing client matters;
- establishing, exercising or defending legal claims;
- complying with legal and regulatory obligations.
Depending on the circumstances, the legal basis may include performance of a contract, compliance with a legal obligation, legitimate interests or another legal basis permitted by the GDPR and applicable law.
3.3. Website security
Technical data may be processed for the purposes of:
- protecting the Website against misuse;
- preventing unauthorized access;
- detecting and resolving technical problems;
- maintaining the security of information systems.
Depending on the circumstances, such processing may be based on our legitimate interest in maintaining the security of our information systems.
4. Recipients of personal data
Personal data may be made available or disclosed only where necessary for the relevant processing purpose and in accordance with applicable law.
Depending on the circumstances, recipients or categories of recipients may include:
- authorized employees and associates of the Office;
- other lawyers or professional advisers where necessary to provide legal services;
- IT, hosting, maintenance and other technical service providers;
- providers of electronic communications services;
- courts, governmental authorities and other public bodies where disclosure is legally required or necessary to establish, exercise or defend legal claims;
- other recipients where there is an appropriate legal basis for disclosure.
We do not sell your personal data or use it for purposes incompatible with the purpose for which it was collected, unless there is an appropriate legal basis for such processing.
5. Transfers outside the European Economic Area
We generally seek to process personal data within the European Economic Area.
If a service provider processes personal data outside the European Economic Area, such transfer will take place only where the requirements of the GDPR are satisfied, including an applicable adequacy decision or appropriate safeguards where required.
6. Data retention
We retain personal data only for as long as necessary to fulfil the purposes for which they were collected, or for as long as required to comply with legal, professional, accounting, tax or other obligations and to establish, exercise or defend legal claims.
Personal data submitted through the contact form which are not connected with a specific engagement are retained for as long as reasonably necessary to process the enquiry and any subsequent communication and are then deleted or anonymized when no longer necessary, unless another legal basis or retention obligation applies.
Personal data relating to specific client matters are retained in accordance with applicable laws, professional obligations and the Office’s internal policies.
7. Your rights
Subject to the conditions provided by the GDPR, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or completion of incomplete personal data;
- request erasure of your personal data where the applicable legal conditions are met;
- request restriction of processing where the applicable conditions are met;
- request data portability where applicable;
- object to processing where it is based on legitimate interests or another legal basis that gives rise to a right to object;
- withdraw consent where processing is based on consent.
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
These rights are not absolute and may be subject to limitations under the GDPR or other applicable laws.
8. How to exercise your rights
Requests concerning your rights may be sent to:
Petrinić & Braut Joint Law Office
Jelačićev trg 7
51000 Rijeka
E-mail: bp@bplaw.hr
For security reasons, we may request additional information necessary to verify your identity.
We will respond to requests without undue delay and, in principle, within one month of receiving the request, subject to any extension permitted by the GDPR.
9. Right to lodge a complaint with a supervisory authority
If you believe that the processing of your personal data infringes the GDPR or other applicable data protection laws, you have the right to lodge a complaint with a competent supervisory authority.
In Croatia, the competent supervisory authority is:
Croatian Personal Data Protection Agency (AZOP)
Ulica Metela Ožegovića 16
10000 Zagreb
Croatia
E-mail: azop@azop.hr
Telephone: +385 (0)1 4609-000
AZOP is the Croatian national supervisory authority for personal data protection.
10. Cookies
The Website may use cookies and similar technologies.
Cookies may be necessary for the basic functioning of the Website, security, remembering certain settings or providing other functionality.
Before this Privacy Policy is published, the exact cookies and technologies used by the Website should be verified, including any analytics, marketing, functional or third-party cookies.
Where cookies that are not strictly necessary for the basic functionality of the Website are used, users will be provided with appropriate controls for accepting or rejecting such cookies in accordance with applicable law.
Detailed information about the cookies used should be made available in a separate Cookie Notice or in a clearly identified section of this Privacy Policy. The Croatian Personal Data Protection Agency recommends that information concerning cookies be easily accessible to Website visitors.
11. Security of personal data
The Office implements appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, destruction, alteration or other unlawful processing.
However, no method of transmission or storage of information over the Internet can be guaranteed to be completely secure.
12. Children’s data
The Website is not specifically directed at children.
If we become aware that we have collected a child’s personal data in a manner that does not comply with applicable law, we will take appropriate steps to delete the data or otherwise process them in accordance with applicable requirements.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in applicable law, our processing activities, Website functionality or the Office’s business.
The updated version will be published on the Website and identified by its date of last update.
14. Contact
For questions concerning this Privacy Policy or the processing of personal data, please contact:
Petrinić & Braut Joint Law Office
Jelačićev trg 7
51000 Rijeka
Croatia
E-mail: bp@bplaw.hr
Telephone: +385 51 579 397
Last updated: 8th August 2026

