Privacy policy

Last updated: 5 September 2026. Information notice under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") for users of aer-wsale.com and contact persons of our customers.

1. Controller

AER L.F. d.o.o., Ulica rijeke Rižane 4, 52466 Novigrad, Croatia, OIB 55800830610. For any request concerning personal data: [email protected] with "GDPR" in the subject line, or by post to the registered office.

2. Data we process

The Site is reserved to professional operators. The personal data we process therefore mainly concerns owners, employees and contact persons of customer companies:

  • Registration and account data: company name, VAT and tax numbers, billing and delivery addresses, name and surname of the contact person, e-mail, phone, password (stored encrypted), language and preferences.
  • Order and payment data: products purchased, amounts, invoices and credit notes, payment method chosen, bank details from which we receive transfers. We do not store card data: it is processed directly by the payment service providers (Viva Wallet, PayPal).
  • Support data: e-mail and phone communications, RMA requests with photos or videos of the product, complaints.
  • Browsing data: IP address, date and time of access, pages visited, browser and operating system, cookie identifiers (see section 7). They are collected automatically by our servers and by security and analytics services.
  • Self-declarations: confirmation of legal age and reseller status requested when entering the Site.

3. Purposes and legal bases

PurposeLegal basis
Account registration, verification of professional status (VIES, licences), order management, shipping, payments, invoicing, support and RMAPerformance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR)
Tax, accounting, customs, consumption-tax and tobacco-products traceability obligations; replies to requests from authoritiesLegal obligation (Art. 6(1)(c))
Prevention of fraud and unpaid invoices, IT security of the Site, defence of our rights in and out of courtLegitimate interest (Art. 6(1)(f))
Commercial communications on products and services similar to those purchased, sent to contact persons of existing customers, with the possibility to object in every messageLegitimate interest (Art. 6(1)(f))
Newsletter and promotions to non-customers; analytics and marketing cookiesConsent (Art. 6(1)(a)), which can be withdrawn at any time
Aggregate statistics on the use of the Site and service improvementLegitimate interest (Art. 6(1)(f)), with aggregated or pseudonymised data

Providing the data marked as mandatory in the forms is necessary to register and order; without it we cannot provide the service.

4. Recipients

Data may be disclosed, for the purposes above only, to:

  • affiliated companies providing AER with logistics, administration and customer-support services;
  • couriers and forwarders (GLS, BRT, Poste Italiane and their network partners) for delivery: they receive the recipient's name, address, phone and e-mail;
  • payment service providers and banks;
  • sales agents and representatives who follow the Customer in their territory;
  • providers of hosting, IT maintenance, e-mail, security and content-delivery networks and web analytics, acting as processors bound by contract under Art. 28 GDPR;
  • accounting, tax and legal advisers, auditors, insurers and debt-collection companies;
  • customs, tax, supervisory and judicial authorities, where required by law.

Data is never sold or passed on to third parties for marketing purposes.

5. Transfers outside the European Union

Some IT service providers (for example network security, e-mail and analytics services) may process data in third countries, in particular the United States. In such cases the transfer relies on an adequacy decision of the European Commission (including the EU-US Data Privacy Framework for certified companies) or on the standard contractual clauses approved by the Commission, with supplementary measures where needed. A copy of the safeguards can be requested through the contacts in section 1.

6. Retention

  • Account data: until the user requests deletion of the account or after prolonged inactivity (5 years from the last order), subject to the periods below.
  • Orders, invoices, transport documents and tax data: 11 years from the end of the financial year, as required by Croatian accounting law, and in any case for the tax retention periods applicable in the destination countries.
  • Data needed to defend our rights: until the relevant claims are time-barred.
  • Commercial communications: until consent is withdrawn or an objection is raised.
  • Security and browsing logs: up to 12 months.

7. Cookies and similar tools

The Site uses:

  • technical cookies, essential for operation: session, cart, authentication, language, storage of the age confirmation and of cookie preferences. They do not require consent.
  • analytics cookies (Google Analytics through Google Tag Manager), collecting aggregate data on visits. They are activated only with the consent given through the banner.
  • security and performance services (content-delivery network and bot protection) that may set technical cookies and log the IP address to prevent abuse.

Consent can be changed or withdrawn at any time from the cookie preferences of the Site or from the browser settings. Disabling technical cookies may prevent use of the Site.

8. Rights of data subjects

Under Articles 15 to 22 GDPR every data subject may exercise the right of access, rectification, erasure, restriction of processing, portability, objection (including to direct marketing, at any time) and withdrawal of consent, without affecting the lawfulness of processing already carried out. Requests are sent to the contacts in section 1 and answered within one month. From the account area it is also possible to download one's data and request deletion of the account.

Anyone who considers that the processing infringes the GDPR may lodge a complaint with the Croatian supervisory authority, Agencija za zaštitu osobnih podataka (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr, or with the authority of their Member State of residence or work.

9. Security

We adopt technical and organisational measures appropriate to the risk: encrypted connections (TLS), need-to-know access control, encrypted passwords, backups, access logging, staff training and confidentiality agreements. Access to data is limited to the staff and providers who need it for the stated purposes.

10. Minors

The Site and the products are intended exclusively for adult professional operators. We do not knowingly collect data of persons under 18; any data collected by mistake is deleted.

11. Changes

This notice may be updated to reflect changes in the law or in the service. The version in force is always published on this page with its update date; substantial changes are notified to registered customers by e-mail.