Privacy Policy
Last updated: 14 January 2026
This policy describes how Lumtrixo d.o.o., with its registered seat at Ulica Hrvatske Republike 14, 10000 Zagreb, Croatia, VAT/OIB 56872349017 ("Lumtrixo", "we"), processes the personal data of visitors and users of its real estate crowdfunding platform. The document is aligned with Regulation (EU) 2016/679 (GDPR), the Croatian Act on the Implementation of the GDPR (OG 42/2018) and Regulation (EU) 2020/1503 on European crowdfunding service providers.
1. Data controller
The data controller is Lumtrixo d.o.o., court reg. No. 081 248 376, registered at the Commercial Court of Zagreb. Privacy contact: privacy@lumtrixo.com, +385 1 5550 184.
2. What data we collect
We collect: (a) identification data (first name, surname, date of birth, OIB if you register as an investor); (b) contact data (email, phone, address); (c) financial data necessary for suitability checks (income range, investment experience); (d) technical data (IP address, device type, cookie identifiers); (e) communication content when you contact us via the form or email.
3. Purposes and legal bases
We process data for: performance of contractual obligations (Art. 6(1)(b) GDPR); compliance with anti-money-laundering rules and Regulation 2020/1503 (Art. 6(1)(c)); legitimate interest in fraud prevention and service improvement (Art. 6(1)(f)); and on the basis of your consent for marketing and analytics (Art. 6(1)(a)).
4. Sharing with third parties
We may share data with carefully selected processors: EU/EEA-based cloud providers, identity verification (KYC/AML) providers, Croatian banking partners, accounting and audit firms, and competent authorities (HANFA, Tax Administration). Data is shared with marketing partners (Google Ads, Meta) only with your consent under Consent Mode v2.
5. Retention period
Investor data is retained for at least 10 years after the end of the business relationship, in accordance with anti-money-laundering rules. Marketing data is kept until consent is withdrawn; technical logs are retained for up to 14 months.
6. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and the right to object. You can withdraw consent at any time by writing to privacy@lumtrixo.com. You also have the right to lodge a complaint with the Croatian Personal Data Protection Agency (azop.hr).
7. Security
We apply encryption in transit (TLS 1.3) and at rest (AES-256), two-factor authentication for staff and regular penetration tests by certified Croatian companies. Data access is limited to personnel with a strict need-to-know.
8. Changes to this policy
We may update this policy in response to changes in legislation or services. We will notify you by email of material changes at least 30 days before they take effect.