Privacy Policy

Last updated: September 20, 2026

ALICE IN BLOCKCHAINS, (“we”, “us”, “our” or the “Association”) respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, how long we retain it, and what rights you have under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Croatian data protection law.

1. Who is responsible for your personal data?

The data controller responsible for processing your personal data is:

ALICE IN BLOCKCHAINS
udruga za fintech, kriptovalute i blockchain
Registered address: Trg žrtava fašizma 6, 10000 Zagreb
Registration / identification number:
OIB: 45632684298, MB: 05598761
IBAN: HR3824020061101099209
Email: info@aliceinblockchains.io
Website: aliceinblockchains.io

If you have any questions about how we process your personal data or wish to exercise your data protection rights, you can contact us using the email address above.

2. What personal data do we collect?

Depending on how you interact with us, we may collect the following categories of personal data.

A. Membership applications

When you apply for membership through our membership application form, we collect:

  • first name and last name;

  • email address;

  • Croatian Personal Identification Number (OIB);

  • company or organisation;

  • professional position or job title;

  • industry;

  • LinkedIn profile URL; and

  • information you choose to provide in the “About yourself” field.

We use this information to process and assess your membership application, communicate with you about your application and membership, maintain accurate membership records, and administer the activities of the Association.

Your membership application information is also entered into and maintained in our membership database.

The “About yourself” field is intended for information about your professional background, interests and relevant experience. Please do not provide sensitive personal information or information about other individuals in this field.

We do not publish your OIB or other personal identification information publicly.

B. Contact forms

If you contact us through a contact form or by email, we may collect:

  • your name;

  • email address;

  • the content of your message and any information contained in it.

We use this information to respond to your enquiry and communicate with you.

C. Newsletter subscriptions

If you subscribe to our newsletter, we collect your email address and, where applicable, your name and information relating to your subscription and consent.

We use this information to send you newsletters and other communications for which you have subscribed.

You can unsubscribe from our newsletter at any time by using the unsubscribe link included in our emails or by contacting us directly.

3. Why do we process your personal data?

We process personal data only for specific and legitimate purposes, including:

  • processing and administering membership applications;

  • maintaining our membership database;

  • communicating with members and membership applicants;

  • responding to enquiries and requests;

  • sending newsletters where you have subscribed;

  • organising and administering Association activities and communications;

  • complying with applicable legal and administrative obligations;

  • protecting the security and integrity of our website, systems and records; and

  • establishing, exercising or defending legal claims where necessary.

We do not sell, rent or otherwise commercially provide your personal data to third parties.

4. Legal bases for processing

Depending on the circumstances, we process your personal data on one or more of the following legal bases under Article 6 of the GDPR:

Performance of a contract or taking steps at your request

Where processing is necessary to administer your membership or take steps at your request before establishing a membership relationship.

Legal obligations

Where processing is necessary for us to comply with a legal or regulatory obligation applicable to the Association.

Legitimate interests

Where processing is necessary for our legitimate interests, such as administering the Association, maintaining membership records, communicating with members, protecting our systems and records, and establishing or defending legal claims, provided that these interests are not overridden by your rights and freedoms.

Consent

Where we rely on your consent, for example for newsletter communications where consent is required, we will ask for your consent separately and clearly.

You can withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing that took place before you withdrew it.

5. Membership database

Membership applications are recorded in our membership database, which is maintained using Google Sheets.

The membership database may contain the personal information provided in your membership application, including your name, email address, OIB, company, position, industry, LinkedIn profile URL and information provided in the “About yourself” field.

Access to the membership database is restricted to authorised persons who need access for legitimate Association purposes.

We take reasonable technical and organisational measures to prevent unauthorised access, alteration, disclosure or loss of membership information.

6. Processing of forms and Make

Our website forms may use Make to automatically transfer submitted information to our internal systems, including our Google Sheets membership database.

For example, when you submit a membership application, the information you provide may be automatically transferred through Make to the relevant Google Sheet.

Make acts as a service provider in connection with this processing. We use appropriate contractual and organizational measures when engaging third-party service providers that process personal data on our behalf.

Make states that it provides GDPR-related contractual documentation and appropriate safeguards for international data transfers where required.

7. Google services

We use Google services for organizational purposes, including email and Google Sheets.

Depending on the service and account configuration, personal data may therefore be processed by Google as part of providing those services.

Our Google Sheets membership database is used to maintain membership records, and Google email services may be used to communicate with members, applicants and other contacts.

Access to our Google account and membership database is restricted to authorized persons.

Where applicable, Google Workspace customers may use Google’s Cloud Data Processing Addendum, which addresses Google’s processor obligations under applicable data protection laws.

Important: This Privacy Policy should be updated if we change the type of Google account or services we use, or if the applicable contractual arrangements change.

8. Newsletter and Noptin

We use Noptin, a WordPress newsletter and email automation plugin, to manage newsletter subscriptions and send newsletters.

Noptin states that subscriber and newsletter data is stored on the website owner’s own WordPress site rather than on Noptin’s servers.

Newsletter subscribers may unsubscribe at any time using the unsubscribe link included in our emails.

We do not use newsletter subscription information for purposes unrelated to the newsletter without an appropriate legal basis.

9. WordPress and website hosting

Our website is operated using WordPress and is hosted by [WORDPRESS HOSTING PROVIDER].

The hosting provider may process limited technical information necessary to operate, secure and maintain the website, such as IP addresses, server logs and technical information relating to requests made to the website.

We require relevant service providers to process personal data only as necessary to provide their services and to maintain appropriate security measures.

10. Who may receive your personal data?

Depending on the circumstances, your personal data may be accessible to:

  • authorized representatives, employees or volunteers of the Association who need the information for legitimate Association purposes;

  • our website and hosting service providers;

  • service providers involved in processing website forms and automations, such as Make;

  • providers of organizational services such as Google;

  • newsletter and website tools such as Noptin;

  • competent authorities, courts, regulators or other recipients where disclosure is required by law or necessary to protect our legal rights.

We do not sell your personal data.

We do not make your membership application information publicly available unless you have been separately informed and an appropriate legal basis exists for doing so.

11. International transfers of personal data

Some of the service providers we use may process personal data outside the European Economic Area (EEA).

Where personal data is transferred outside the EEA, we rely on an appropriate legal mechanism under Chapter V of the GDPR, where required. This may include an adequacy decision of the European Commission or appropriate safeguards such as Standard Contractual Clauses.

For example, Make states that it uses appropriate transfer mechanisms, including Standard Contractual Clauses where required for transfers to countries without an EU adequacy decision.

12. How long do we keep your personal data?

We retain personal data only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.

Membership applications and membership records

We retain membership application and membership information for as long as necessary to administer membership and maintain the Association’s membership records.

Where an application is unsuccessful, we retain the information only for as long as reasonably necessary to document and administer the application and protect our legitimate interests, unless a longer period is required by law.

Where a person becomes a member, relevant membership information is retained for the duration of the membership and for an appropriate period afterwards where necessary for legal, administrative or record-keeping purposes.

Contact enquiries

We retain contact-form and email correspondence for as long as reasonably necessary to respond to the enquiry, maintain appropriate records and, where applicable, establish or defend legal claims.

Newsletter subscriptions

We retain newsletter subscription information while you remain subscribed or until you withdraw your consent, where consent is the legal basis for processing.

After unsubscribing, we may retain limited information necessary to ensure that we do not send you further newsletters.

13. Your rights under the GDPR

Subject to applicable legal conditions, you have the right to:

  • request access to your personal data;

  • request correction of inaccurate or incomplete personal data;

  • request erasure of your personal data;

  • request restriction of processing;

  • object to processing based on legitimate interests;

  • withdraw consent where processing is based on consent;

  • request data portability where the right applies; and

  • object to direct marketing, including withdrawing your newsletter subscription.

You also have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, except where the conditions of Article 22 of the GDPR apply.

To exercise your rights, contact us at:

info@aliceinblockchains.io

We may need to verify your identity before responding to certain requests in order to protect your personal data.

We will respond to valid requests without undue delay and, in general, within one month of receiving the request, subject to the conditions and exceptions provided by applicable law.

14. Right to lodge a complaint

If you believe that your personal data has been processed in violation of applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority.

In Croatia, the competent supervisory authority is:

Agencija za zaštitu osobnih podataka (AZOP)
Ulica Metela Ožegovića 16
10000 Zagreb
Croatia
Email: azop@azop.hr
Telephone: +385 1 4609 000

AZOP is the Croatian supervisory authority responsible for personal data protection.

We encourage you to contact us first so that we can try to resolve your concern, but you have the right to contact the supervisory authority directly.

15. Security of your personal data

We take reasonable technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access.

These measures include restricting access to personal data to authorized persons, using access controls and passwords, and using reputable service providers with appropriate security measures.

No method of transmission or electronic storage can be guaranteed to be completely secure. However, we take reasonable steps to protect the personal data entrusted to us.

16. Cookies

Our website may use cookies and similar technologies that are necessary for the website to function properly.

We do not use Google Analytics on this website.

We do not use cookies for behavioral advertising or cross-site advertising based on the information currently described in this Privacy Policy.

For more information about the cookies used on our website, please see our Cookie Policy below.

17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our activities, services, technology or applicable legal requirements.

The latest version will always be published on this website, together with the date on which it was last updated.

18. Contact

If you have questions about this Privacy Policy, our processing of personal data, or your rights, please contact us:

ALICE IN BLOCKCHAINS
udruga za fintech, kriptovalute i blockchain
Trg žrtava fašizma 6, 10000 Zagreb
Email: info@aliceinblockchains.io
Website: aliceinblockchains.io


Cookie Policy

Last updated: September 20, 2026

This Cookie Policy explains how ALICE IN BLOCKCHAINS, udruga za fintech, kriptovalute i blockchain, uses cookies and similar technologies on https://aliceinblockchains.io

1. What are cookies?

Cookies are small text files that may be stored on your device when you visit a website. They can help a website function correctly, remember certain settings, maintain security and provide information about how the website is used.

2. Which cookies do we use?

Our website is intended to use only cookies that are necessary for the website to function properly and securely.

These may include cookies used for purposes such as:

  • maintaining website functionality;

  • security;

  • form functionality;

  • remembering necessary technical settings; and

  • maintaining a user’s session where required.

We do not currently use Google Analytics or similar analytics services.

We do not currently use advertising or behavioral tracking cookies.

The exact cookies placed on your device may depend on the WordPress plugins, hosting configuration and other technical components active on the website.

3. Do we need your consent?

Where cookies are strictly necessary for providing a service or functionality you have requested, they may be used without consent where permitted by applicable law.

If we introduce non-essential cookies in the future, such as analytics, advertising or other tracking technologies that require consent, we will update this Cookie Policy and, where required, request your consent before placing those cookies.

4. Third-party services

Some technical functions of our website may involve third-party service providers. Where those services place or access cookies or similar technologies, the relevant information will be reflected in this Cookie Policy.

We do not currently use third-party advertising cookies.

5. Managing cookies

You can control or delete cookies through the settings of your web browser.

Please note that disabling certain necessary cookies may affect the functionality of the website.

6. Changes to this Cookie Policy

We may update this Cookie Policy if our website, plugins, services or use of cookies changes.

The latest version will always be published on this website together with the date on which it was last updated.

7. Contact

If you have questions about our use of cookies, please contact:

ALICE IN BLOCKCHAINS
udruga za fintech, kriptofalute i blockchain
Email: info@aliceinblockchains.io
Website: https://aliceinblockchains.io

Alice in Blockchains
udruga za fintech, kriptovalute i blockchain 
Address: Trg žrtava fašizma 6, 10000 Zagreb
OIB: 45632684298, MB: 05598761 
IBAN: HR3824020061101099209

About
Partnerships
News
Contact
Contact Info

Subscribe to our newsletter

Copyright © Alice in Blockchains. All Rights Reserved.

[ MEMEBERSHIP INVITATION ]

Empower Your Future in Web3

Join a community of women leading the blockchain revolution. Access exclusive events, mentorship and governance opportunities