GriffCraft protects your privacy in comply with the GDPR (General Data Protection Regulation). We don't collect or process more information than we need to fulfill your expectations and the obligations we have to you.

This policy applies to all data collected through our website.


In order for us to have the right to process your personal information, we need a so-called legal basis. We process your personal information because processing is necessary to fulfill the agreement we have with you as a customer through your purchase.

We process your personal data because processing is necessary in order to fulfill legal obligations concerning our company.

We also process your personal data because processing is necessary for purposes of our legitimate interest. The treatment of data is based on a weighing up of interest and applies to situations where we want or need to do something, for example communicate with you or promote our products and services, which is essentially to our advantage, provided that it does not harm your own interests or fundamental rights and freedoms.


We handle the data that you, as a customer, provide to us when shopping or visiting our website and communicating with us. The personal data we process is your e-mail address and your user account.

We also collect and process information from you when shopping or visiting our site. The personal data we process is information about your purchase and purchase history. We also process your personal information when you approve cookies, see separate section below.


We process the above-mentioned personal data in order to:

  • Process your purchase
  • Identify you
  • Process your payment
  • Unlock purchased product
  • Process any complaints
  • Contact you regarding problems with the usage of our platform
  • Provide you with a personalised experience of our services by collecting cookies
  • Fulfil our legal obligations (eg regarding requirements in the accounting act, product liability and product safety)
  • Prevent abuse of a service or to prevent and investigate crimes against GriffCraft


We store data on our own servers in Europe.

Our partners and service providers are all domiciled in the EEA, and their servers and other storage utilities are located there. The only exception is Google LLC, see your own paragraph under Cookies.

We may issue your personal information if we are required by the authorities to provide such information.

We may also share your personal information in order to allow a merger, acquisition or sale of all or part of our assets.


We only keep personal data as long as there is a need to to fulfil the purposes for which the information was provided or collected. The same personal data can be stored in several different locations for different purposes.

If you contact us by e-mail, our correspondence will be saved for as long as necessary to fulfill the purpose of the errand.

We process information in order to manage customer relationships, including your purchase and user account, or to fulfill contractual and legal obligations to you, such as fulfil a warranty, a complaint or reprisal obligations. The data is processed for the time necessary to manage the customer relationship and fulfill our agreement or our legal obligations or other obligations towards you.

Personal data we process for accounting purposes is retained in accordance with applicable accounting laws.

We will process your personal data for marketing purposes for one year after your customer relationship with us has expired.

Your personal data may be saved for a longer period than stated above if required to comply with legal requirements or governmental decisions.


When you shop with us you can feel safe and secure. We take steps to ensure that your personal information is always protected by us and that information processing is in accordance with applicable data protection rules and our internal guidelines and practices.

We also ensure through technical solutions and agreements with our partners and suppliers that these handle your personal information securely and comply with personal data laws.

Payment and billing information is transmitted via an encrypted connection from our payment partner who manages the payment.


Right to access: We want to be transparent and open about how we treat your personal data. If you want to know more about how we process your information, you can request a document from us. You are entitled to request to know what information has been registered about you. If you want this information, please submit a written request to us. If we receive a request for this information, we will ask for information to ensure that the information is provided to the correct person.

Right to rectification: You may request that your personal information be corrected if the information is incorrect or incomplete.

Right to delete: Under certain circumstances, you may delete your personal data if, for example

  • The data is no longer necessary for the purposes for which it has been collected or processed
  • You oppose our keeping your information for direct marketing purposes

However, this does not apply if we are required by law, for example, to keep the data.

Right to restriction: You are entitled to request that the processing of your personal data be limited.

Fair interest / interest balance: You are entitled to oppose information processing that relates to a balance of interest. However, we may continue to process your information, even if you oppose the processing of information, if we are required to do so by law or authority's instructions or decisions.

Direct Marketing: You are entitled at any time to oppose the processing of your personal data for direct marketing. The right also includes the analysis of personal data (ie profiling) performed for direct marketing purposes. Direct marketing refers to all types of outreach marketing methods(eg by mail, email and SMS).

You have the opportunity to choose which communication channels we will use for mailing and personal offers, for example you can choose to receive e-mail only, but not SMS. In that case, you do not need to object to personal data processing as such, but contact our customer service department.

Data Portability Right: You are entitled to receive a copy of the personal data relating to you in a structured format, and in some cases, transfer this data to another personally responsible person. The right includes only information that you have submitted to us and which we treat with legal basis, such as an agreement with you. A prerequisite for data portability is that the transfer is technically possible.

Right to file a complaint: If you are dissatisfied with how we processed your personal information, please contact us using our contact details below.


Cookies are used on our site. Cookies are small text files stored on the visitor's computer and are used to track what the visitor does on our site.

We use different types of cookies:

1. A permanent cookie remains on the visitor's computer for a specified time.

2. A session cookie is stored temporarily in the computer's memory while a visitor is on a web page. Session cookies disappear when you close your browser.

We use cookies to improve our site for the visitor e.g. by customising our site according to the visitor's wishes, choices and interests, as well as helping you keep track of the items you added to your shopping cart. We use cookies to analyse our site and how it is used (see the web analytics paragraphs below) and for retargeting.

By agreeing to this privacy policy and / or using our site, you agree to the processing of cookies as stated herein. If you do not want to accept cookies, you can turn off cookies in your browser's security settings. You can also set up the browser so that you get a query every time our site tries to place a cookie on your computer. Through the browser, previously stored cookies can also be deleted: see the browser's help pages for more information. Furthermore, you can manually delete cookies manually from your hard drive.

If you want to delete existing cookies on your computer: see the instructions in your browser.

Google Analytics and Google Tag Manager (web analytics)

Our site uses Google Analytics, a web analytics service provided by Google LLC (""Google""). Google Analytics uses cookies, ie. text files placed on your computer to analyse how users use the web page. The information generated by these cookies through your use of the webpage (including your IP address) will be forwarded to and stored by Google on servers in and outside the EEA.

Google will use this information in order to evaluate your use of the web page and compile reports of activities on our site.

Google may also transfer this information to third parties if required by law, or in cases where a third party processes the information on behalf of Google. Google will not match your IP address with other data held by Google. By using our site, you consent to Google processing your information in the manner and for the purposes described above.

If you do not want your visits to our site to appear in Google Analytics statistics, you can install an add-on to your browser. The add-on is available for browsers Internet Explorer, Google Chrome, Mozilla Firefox, Apple Safari and Opera, and is available here.


Viktor Ilich, Radosava Mirkovića 1/34, Smederevo 11300, Serbia. This is the person responsible for processing your personal information.

Please contact us at email if you have questions about the personal information we have stored about you.