Privacy and Data Protection
MMM Agramservis d.o.o.
Samoborska cesta 145
10172 Zagreb, Hrvatska
OIB: 77209285118
E-mail: dpo@agramservis.hr
Personal Data Protection Policy
Updated: September 17, 2026.
At MMM Agramservis, we respect your privacy and protect your personal data in accordance with the General Data Protection Regulation (GDPR), the Act on the Implementation of the General Data Protection Regulation, and other applicable regulations. Our business operations encompass device repair, after-sales processes for operators and manufacturers, the design and maintenance of technological solutions for business clients, as well as retail and online sales under the Smartson brand; in each of these areas, we handle the data of individuals who have placed their trust in us. Protecting this data is a vital part of our business.
With this document, we wish to explain which personal data we collect—and why—when you use our repair services, place orders via our online store, collaborate with us as a business partner, or work for us. We also outline with whom and why we share this data, how long we retain it, what rights you have regarding it, and how we protect it.
This Personal Data Protection Policy applies to all business processes of MMM Agramservis d.o.o. at the location Samoborska cesta 145 in Zagreb, to our websites www.agramservis.hr and www.smartson.hr, and to the communication channels through which you contact us.
PURPOSES OF COLLECTING PERSONAL DATA
We collect your personal data directly from you, from our business partners when it is necessary to provide the service and, as necessary, from publicly available sources. We collect and process personal data in order to provide and improve our services, fulfill our legal obligations and establish and maintain business relationships, and in some cases based on your consent. Personal data is processed for the following purposes:
• Receiving devices for repair, diagnostics, repair, status updates, and returning devices to the user
• Billing for out-of-warranty repairs and processing refund requests
• Responding to inquiries and resolving customer complaints
• Receiving, processing, billing, and delivering orders from our online store
• Responding to visitor inquiries via the chat function on www.smartson.hr
• Measuring website traffic, analyzing website usage, and advertising via cookies
• Registering users for device manufacturers’ promotional programs
• Providing information about our products, services, and special offers, subject to your consent
• Organizing prize competitions and delivering prizes to winners
• Photographing and filming our events and publishing such materials on our websites and social media profiles
• Maintaining records of business customers for the purpose of issuing quotes, purchase orders, and invoices
• Managing system integration projects and communicating with clients
• Receiving data from business partners and publicly available sources when necessary for service delivery or business entity verification
• Processing personal data on behalf of clients—such as telecom operators, device manufacturers, insurance companies, and business customers—in accordance with their written instructions
• Conducting recruitment and selection processes and concluding employment contracts
• Establishing and managing employment relationships, calculating salaries, and tracking working hours
• Fulfilling our legal obligations towards… the Labor Act, regulations on pension and health insurance, tax regulations, the Accounting Act, and consumer protection regulations.
Processing of Personal Data of Users of Our Service Operations
When you bring a device to us for repair, we process your personal data for the purpose of concluding and performing the service contract. The performance of the contract constitutes the legal basis for processing this data.
Upon receipt of the device, we record your full name, the contact details you choose to provide, and device information—such as the model, IMEI or serial number, and a description of the reported fault. This data is entered into our ServisApp information system and, where necessary, onto a paper service form. We photograph and document the condition of the device as received.
We process your personal data to keep you informed about the repair status, any potential costs and the service price, and to ensure the device is returned to the correct person.
The device’s IMEI or serial number is recorded in the service documentation and retained as part of the record of the service performed. When necessary for warranty claims, technical support, or authorized service procedures, the IMEI or serial number may be shared with the device manufacturer or their authorized service and logistics partners. All our contractual partners and device manufacturers are required to process and store device data within the European Union (e.g., Huawei stores data in Ireland) and to protect it in accordance with applicable personal data protection regulations.
If you bring the device in person, we provide a printed receipt—a work order containing the entered data—which you use to collect the device later. This printout is intended solely for you. Internal service work orders are printed without your full name; your identity remains recorded only within the system and is visible solely to staff authorized to perform specific steps of the process.
We notify you of the repair status via SMS, email, or telephone. Upon collection, we verify the identity of the person picking up the device; if another person collects it on your behalf, we will record their ID card number to document the handover and prevent unauthorized collection.
For warranty repairs or repairs performed under a device insurance program, we necessarily share certain data with the device manufacturer (e.g., Apple, Xiaomi, Honor), the telecommunications operator with whom we have an after-sales service agreement, or the insurance company covering your device. We share only the data strictly necessary to carry out the specific procedure.
During diagnostics, repair, and testing, authorized technicians may access data stored on the device only to the extent necessary to perform the service. Data accessed in this manner is not stored, copied, or used for any other purpose. As data loss or deletion may occur during servicing, we recommend backing up your data before handing over the device. MMM Agramservis is not liable for data loss or for data recovery following servicing. We retain data associated with a service order for the duration of the warranty period and subsequently for as long as necessary to resolve potential complaints, exercise or defend legal claims, and fulfill legal obligations.
Access to the ServisApp system is governed by user permissions; devices awaiting repair or collection are stored in a locked area; workstation drives are encrypted; and system access is protected by multi-factor authentication. Our service technicians are strictly prohibited from viewing, copying, or using content stored on your device, except for actions necessary for diagnostics, functionality testing, or performing the repair itself.
If you contact us with an inquiry or complaint via the email address info@agramservis.hr or by phone, we log your inquiry within ServisApp. We retain inquiries and complaints for two years after their closure to address potential subsequent claims and to provide proof of the service rendered.
If you request a refund, we will require your full name, IBAN, work order or invoice number, and the refund amount. We are legally required to retain payment documentation—as part of our accounting records—for eleven years.
Processing of Personal Data of Customers and Visitors to Our Websites
When you order a product from our Smartson online store, you enter into a sales contract with us. To fulfill this contract, we require your full name, delivery address, e-mail address, phone number, and the details of your order. We receive orders via the online store at www.smartson.hr, record them in our system, and send you an order confirmation via e-mail. We also retain wholesale purchase orders in paper format, along with the associated shipping documents.
Payment is processed via the secure CorvusPay system. We do not collect, store, or have access to your payment card details. Payment card data processing is handled exclusively by CorvusPay, a payment service provider certified according to the PCI DSS security standard. Data transmission between your browser and our systems is protected by encryption.
We retain invoices and other financial and accounting documentation related to orders for eleven years in accordance with legal obligations, while other order data is kept for two years following the fulfillment of the contract, unless a longer retention period is required by law or necessary for the assertion or defense of legal claims.
If you have provided your consent, we will retain your e-mail address after the order is completed in order to occasionally inform you about our products, services, and special offers. When selecting the content we send you, we may take into account your past purchases or items in which you have shown interest. You may withdraw your consent at any time—by sending a message to dpo@agramservis.hr or using the unsubscribe link within the notification itself—after which we will stop sending you notifications.
If you contact us via the chat function on the www.smartson.hr website, we process your first name, surname, e-mail address, and the content of the conversation in order to respond to your inquiry. If the inquiry concerns a device you have handed over to us, an order you have placed, or a service you wish to arrange with us, the legal basis for processing is taking steps at your request prior to entering into a contract or the performance of a contract. For other inquiries—such as those regarding prices, our product range, or business hours—the legal basis is our legitimate interest in responding to individuals who contact us. The chat module uses cookies and loads only after you have given your consent; we retain conversations for six months following the last point of contact, after which we delete them. Please do not provide information via chat that is not necessary for your inquiry, particularly health data, financial information, or document numbers.
Certain device manufacturers occasionally organize promotional programs—such as extended warranties or additional device protection—for which users can register via our websites. If you choose to participate in such a program through our website, we will process your personal data based on your consent. We record the data in our internal system and forward it to the relevant device manufacturer (e.g., Honor, Motorola, LG, or Amica) to register your participation in the program and enable you to claim the associated benefits. We retain data related to promotional programs until the program ends and any deadline for exercising rights under the program has passed, but for no longer than one year from the date of registration. You may withdraw your consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out prior to the withdrawal, but it may result in an inability to continue using the benefits derived from the program you signed up for.
COOKIES ON OUR WEBSITES
A cookie is a piece of information that a website saves on your computer or mobile device. Cookies typically remember your preferences—such as your selected language or the contents of your shopping cart—so that when you return to the site, your browser sends them back, allowing the site to recognize you. There are first-party cookies, which originate from the site you are viewing, and third-party cookies, placed on the site by other service providers (such as analytics or advertising tools). Temporary cookies are deleted when you close your browser, while persistent cookies remain stored until they expire or you delete them yourself.
We use cookies on the website hosting our online store. We categorize them into four groups based on their purpose:
Necessary cookies enable the site’s basic functionality—such as remembering shopping cart contents, maintaining your login and session, and protecting against form abuse. Purchases would not be possible without them; therefore, they cannot be disabled. We place them based on our legitimate interest in ensuring the site operates correctly and securely.
Functional cookies enable additional features you have requested, such as the chat function used to send us inquiries.
Analytical cookies help us understand how the site is used—for example, which pages are viewed most often, where visitors come from, and where they stop—so that we can improve and enhance the site. Some of the tools we use for this purpose may also record your navigation path across the site. Advertising cookies are used to measure the performance of our advertisements and to display content tailored to your interests on other platforms.
We place functional, analytical, and advertising cookies solely based on your consent. You provide or withhold consent upon your first visit to the site and may change or withdraw it at any time via the cookie settings, which remain permanently accessible on the site. Refusing these cookies does not affect your ability to make purchases or the availability of content.
An up-to-date list of cookies is always available in the site’s cookie settings. This list updates automatically whenever changes occur, ensuring you always see the current status, regardless of when this Policy was last updated.
You can also manage cookies through your web browser, where you can delete or disable them. If you disable all cookies, you will still be able to browse the site, but some of its features may not be available to you.
PRIZE COMPETITIONS AND OUR EVENTS
We occasionally organize prize competitions. If you participate in one, we process your data based on the competition rules—published prior to the start—which specify the data collected and the retention period. If a competition involves a sponsor who delivers the prize directly, we forward the winner’s data necessary for delivery to that sponsor; this practice is explicitly stated in the competition rules.
We sometimes document product presentations, events, and similar gatherings we organize through photography and video recording, and we may publish this material on our websites and social media profiles. If you are identifiable as an individual in a photograph or recording, we will seek your consent before publication. You may withdraw your consent at any time by emailing dpo@agramservis.hr; we will then remove the content in question from our channels, noting, however, that we cannot control further sharing by third parties if the content has already been downloaded.
Processing of Personal Data of Business Partners and Clients
When you do business with us as a company, we process the data of your employees and other contact persons with whom we collaborate. We maintain data regarding the contact persons of our business customers (full name, job title, e-mail address, and telephone number, along with the company name and tax ID) in our systems to enable communication with the business partner and to issue quotes, purchase orders, contracts, and invoices. Such processing is necessary for establishing and maintaining the business relationship, executing the contract with the business partner, and fulfilling legal obligations related to the maintenance and retention of business and accounting records.
PROCESSING OF PERSONAL DATA OF JOB APPLICANTS AND EMPLOYEES
Before you become our employee, if you have submitted a job application via email, we use your CV and cover letter exclusively to conduct the selection process. Applications are reviewed, interviews are conducted, and selection decisions are made by personnel responsible for hiring; access to applications is restricted to those individuals who require the data to carry out the candidate selection process. We process the data from your application as a step preliminary to concluding an employment contract and retain it for a maximum of six months following the conclusion of the recruitment process, in order to protect against potential objections regarding the process.
Once you become our employee, we process your data for the purpose of fulfilling the employment contract and complying with our legal obligations as an employer. The data processed includes:
• Your full name
• Your Personal Identification Number (OIB) and date of birth
• Your address and contact details
• Your citizenship
• Your current account number (IBAN)
• Information regarding your work history, education, and qualifications
• Information from your job application and CV
For the purposes of managing the employment relationship, calculating and paying salaries, and maintaining records required by labor and tax regulations, we process data such as your full name, OIB, IBAN, salary details, and records of working hours, annual leave, and sick leave. Documentation is stored in both paper and electronic formats, subject to appropriate organizational and technical security measures, with access restricted to authorized personnel only. Sick leave data, as health-related information, is protected by additional access controls. An external accounting service handles pension and health insurance registrations and payroll processing for us, and we submit legally required data to the competent authorities. We retain the data for the periods prescribed by labor, accounting, and other applicable regulations.
Video Surveillance
The MMM Agramservis premises at Samoborska cesta 145 in Zagreb are under video surveillance to protect people and property—both our own and the devices entrusted to us by customers for repair.
We base this processing on our legitimate interest in protecting people, property, and devices in our possession, as well as—regarding employees—on occupational health and safety regulations. Recordings are retained for up to 30 days, after which they are automatically deleted. Exceptionally, we may retain a recording for a longer period if it is required as evidence in proceedings initiated before a competent authority, but only until the conclusion of such proceedings. Access to the recordings is restricted to a limited number of authorized persons, and every instance of access is logged. We do not publish the recordings or disclose them to third parties, except upon the request of competent authorities in accordance with applicable regulations.
STORAGE AND DELETION OF YOUR PERSONAL DATA
Your personal data will be stored in a form that allows for your identification for no longer than is necessary for the purposes for which the data are processed. Retention periods are specified alongside each processing activity described in this Policy; for certain processing activities, retention periods are mandated by laws requiring longer storage—primarily accounting and labor regulations. We retain data for as long as required by law, as long as there is a valid reason for doing so, or until you request that we stop using them, whichever occurs first.
Upon the expiration of the retention period, the data are deleted, irreversibly anonymized, or securely destroyed, depending on the storage method used.
If you request the deletion of your data or a restriction on their processing, we will comply with your request. However, we are required to retain the request itself and records of how we handled it as evidence that we have fulfilled our obligations under the GDPR. We retain this information for 5 years from the date the request was received, after which it is deleted.
TRANSFER OF DATA TO THIRD PARTIES
In the course of certain processing activities, the data you provide to us may be transferred to or made accessible to third parties. Under no circumstances do we sell, rent, or transfer ownership of your data to unauthorized third parties. Data transfer or access occurs for the following reasons:
• When we have received your consent for such a transfer (e.g., registration for a manufacturer’s promotional program)
• When the data is necessary to fulfill a contract concluded with you (e.g., forwarding data to a manufacturer for warranty repairs, to a delivery service for order fulfillment, or to a bank for processing a refund)
• When service providers we engage for specific processing activities access the data in accordance with a personal data processing agreement (e.g., ServisApp maintenance, the online store platform, online payment processing, accounting services)
• To fulfill our legal obligations (e.g., registering employees for social security, submitting JOPPD forms to the Tax Administration, or processing salary payments via a bank)
When transferring data for any of the aforementioned reasons, we strive to limit the transferred data to the absolute minimum necessary. The third parties to whom we transfer your data are contractually obligated to protect it in compliance with applicable personal data protection regulations.
TRANSFER OF DATA OUTSIDE THE EUROPEAN ECONOMIC AREA
In certain cases, specific service providers we use for business operations, communication, customer support, or the fulfillment of contractual obligations may process data outside the EEA.
When such a transfer occurs, it is carried out solely in compliance with appropriate safeguards prescribed by the GDPR, such as an adequacy decision by the European Commission, standard contractual clauses, or other legally permitted mechanisms for the protection of personal data.
We regularly verify that our service providers implement appropriate safeguards to ensure that personal data is processed with the same level of protection as within the European Economic Area.
YOUR RIGHTS REGARDING PERSONAL DATA
You may request information from us at any time regarding the personal data we process, the purpose of the processing, data recipients, and retention periods. Additionally, you have the right to:
• request access to your personal data and a copy thereof;
• request the correction of inaccurate data or the completion of incomplete data;
• request the deletion of data when there is no longer a legal basis for its processing;
• request a restriction on processing in cases prescribed by law;
• request data portability in a structured, commonly used, and machine-readable format, where applicable;
• object to processing based on our legitimate interest;
• withdraw your consent when processing is based on consent, without affecting the lawfulness of processing carried out prior to the withdrawal.
We will gladly fulfill your request to delete personal data in the following cases:
• if your personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
• if you withdraw the consent upon which the processing is based;
• if you object to the processing and there are no overriding legitimate grounds for the processing.
We will not be able to delete your data while a statutory retention period applies—for example, the retention period for accounting and HR records. In such cases, we will restrict the data to what is required by law and will not use it for other purposes. You may send your request via email to dpo@agramservis.hr or by mail to MMM Agramservis d.o.o., Attn: Data Protection Officer, Samoborska cesta 145, 10172 Zagreb, including your contact details and the note “Request regarding personal data.” We respond to requests without undue delay and no later than one month after receipt. We cannot provide access to personal data via telephone. To prevent the misuse of your personal data, we may ask for additional proof of identity in certain cases; we will be unable to fulfill the request without verifying your identity.
If you believe that we are not handling your data in a lawful and secure manner and are unable to resolve your concerns directly with us, you have the right to lodge a complaint with the supervisory authority – the Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, www.azop.hr.
Protection of Children’s Personal Data
We do not knowingly collect personal data from children, and our services are not intended for minors without the knowledge of a parent or guardian. If you are under the age of 16, please do not provide us with your data without their approval. Since we cannot always determine the age of a person contacting us via the website or bringing a device in for repair, we advise parents and guardians to instruct children on the safe and responsible handling of personal data. As a parent or guardian, you always have the right to request access to the personal data of your child that we have collected, as well as to request its deletion.
Personal Data Protection Security Measures
MMM Agramservis recognizes the importance of personal data protection and information security, and continuously evaluates and improves its technical, physical, and organizational safeguards. Personal data protection is an integral part of our integrated management system—aligned with ISO 9001, ISO/IEC 27001, and ISO 22301 standards—and is governed by internal rules, policies, and procedures.
Access to data within our systems is restricted to authorized personnel based on the “need-to-know” principle—specifically, only to the extent necessary to perform their job duties and for the purposes of which you have been informed. Access to business systems is secured via multi-factor authentication; data is protected by encryption during transmission and storage; and systems undergo regular backups, monitoring, and activity logging.
Paper documentation containing personal data is stored in locked rooms and cabinets, while user devices are kept in a secure service area. Our employees receive regular training on personal data protection and are bound by confidentiality obligations. We enter into personal data processing agreements with service providers who process personal data on our behalf and require them to implement appropriate security measures.
PERSONAL DATA BREACH
If, despite all measures, a personal data breach occurs, we will assess the risk it poses to the rights and freedoms of individuals. Where such a risk exists, we will report the breach to the Personal Data Protection Agency within 72 hours of becoming aware of it, and if the risk is high, we will also notify you of the breach without undue delay. When we process data as a processor, we will notify the controller of the breach without undue delay.
CHANGES TO THIS POLICY
We review this Personal Data Protection Policy at least once a year and update it whenever there are changes to regulations or our business processes. The current version is always available on our website, along with the date of the last update.
Should you have any questions regarding this Policy or the processing of your personal data, please feel free to contact us at dpo@agramservis.hr.