Privacy Policy
Last updated: April 2026
This Privacy Policy explains how Adriatic Allocation (INSERT: Company legal name, INSERT: registered address — "we", "us", "our") collects, uses, and protects personal data in accordance with the General Data Protection Regulation (GDPR) and applicable EU member state law.
1. Data controller
INSERT: Company legal name
INSERT: Street address, city, postal code, country
Email: hello@adriaticallocation.com
2. Data we collect and why
2a. Waitlist email address
What: Your email address, submitted voluntarily via the waitlist form.
Why: To notify you when a new batch of wines becomes available.
Legal basis: Consent (Article 6(1)(a) GDPR). You may withdraw consent at any time by emailing us.
Processor: Netlify, Inc. (form submission infrastructure). Netlify's privacy policy is available at netlify.com/privacy.
Retention: Until you request deletion or withdraw consent.
2b. Order and delivery data
What: Name, delivery address, email address, and payment information collected at checkout.
Why: To process and fulfil your order and comply with legal obligations (invoicing, tax records).
Legal basis: Performance of a contract (Article 6(1)(b) GDPR) and legal obligation (Article 6(1)(c) GDPR).
Processor: Stripe, Inc. (payment processing). Payment card data is processed exclusively by Stripe and never stored on our servers. Stripe's privacy policy is available at stripe.com/privacy.
Retention: Order records are retained for 7 years to comply with accounting and tax obligations.
2c. Analytics data
What: Anonymised usage data including pages visited, time on site, and general geographic region — collected only after you give cookie consent.
Why: To understand how visitors use the site and improve it.
Legal basis: Consent (Article 6(1)(a) GDPR). You may withdraw consent at any time by clearing cookies or adjusting your browser settings.
Processor: Google LLC (Google Analytics 4). Data is processed under Google's standard contractual clauses.
Retention: 26 months (Google Analytics default).
3. Sharing of data
We do not sell personal data. We share data only with the processors listed above (Netlify, Stripe, Google), each of which is bound by data processing agreements. We may also disclose data if required by law or court order.
4. International transfers
Netlify, Stripe, and Google are US-based companies. Data transfers to the US are covered by standard contractual clauses approved by the European Commission.
5. Your rights
Under the GDPR you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — ask us to delete your data ("right to be forgotten"), subject to legal retention obligations.
- Restriction — ask us to limit how we process your data in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email hello@adriaticallocation.com. We will respond within 30 days.
6. Complaints
You have the right to lodge a complaint with a supervisory authority. In Croatia, the competent authority is the Agency for Personal Data Protection (AZOP). You may also contact the supervisory authority in your country of residence.
7. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of the site after an update constitutes acceptance of the revised policy.
8. Contact
For any privacy-related questions, contact us at hello@adriaticallocation.com.