This Privacy Policy explains how Veridalis Recovery, d.o.o. ("Veridalis", "we", "us" or "our") collects, uses, discloses, stores and protects personal data relating to individuals who visit our website at veridalis.com, submit an enquiry through our contact or case assessment forms, or otherwise communicate with us. We are an investment fraud recovery firm based in Zagreb, Croatia, and we assist English speaking clients who believe they have been the victim of financial fraud.
We take the protection of your personal data seriously. This Policy has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the General Data Protection Regulation, or "GDPR") and with the Croatian Act implementing the GDPR (OG 42/2018) of 8 August, which ensures the implementation of the GDPR in the Croatian legal order (the Croatian GDPR Act). Where a conflict appears to exist between the two, the GDPR and the interpretations issued by the competent supervisory authority prevail.
Please read this Policy carefully. By submitting information to us or by continuing to use our website, you acknowledge that you have read and understood the practices described here. If you do not agree with any part of this Policy, please do not submit personal data to us.
The data controller responsible for your personal data is:
As the data controller, Veridalis determines the purposes and means of processing the personal data described in this Policy. We are established in Croatia, and Croatia is our main place of establishment within the European Union for the purposes of the GDPR. Our lead supervisory authority is therefore the Croatian data protection authority, AZOP (the Croatian Personal Data Protection Agency).
This Policy applies to personal data that we process about:
This Policy does not apply to third party websites that may be linked from our site. We are not responsible for the privacy practices of any third party, and we encourage you to read the privacy notices of any website you visit through a link on our site.
We collect personal data directly from you and, in limited circumstances, automatically through your interaction with our website. We do not knowingly collect more information than is necessary for the purposes described below.
When you complete our case assessment form, contact form, or otherwise correspond with us, you may provide the following categories of personal data:
Because our work concerns financial loss, the information you send us can be sensitive in nature, even though it does not usually fall within the special categories of data defined in Article 9 of the GDPR. We ask that you do not send us special category data (such as data concerning health, political opinions, or religious beliefs) or unnecessary financial account credentials through our web forms. If you do send such information voluntarily, we will process it only to the extent necessary to assist you and will apply appropriate safeguards.
When you visit veridalis.com, we and our service providers may automatically collect certain technical data, including:
Where you reach our website through an advertisement or a marketing link, your browser may transmit campaign tracking parameters, commonly known as UTM parameters (for example utm_source, utm_medium, utm_campaign, utm_term and utm_content). We store these parameters together with your enquiry so that we understand which of our communications led you to contact us and so that we can measure and improve the effectiveness of our outreach. UTM parameters are generally not identifying on their own but become associated with you when linked to a form submission.
Under the GDPR and the Croatian GDPR Act, we may only process your personal data where we have a lawful basis to do so. The table below describes each purpose for which we process personal data and the corresponding legal basis.
We use the information you submit through our forms to review your situation, to determine whether we may be able to assist, and to respond to you. The legal basis for this processing is the taking of steps at your request prior to entering into a contract (Article 6(1)(b) GDPR). Where you are not yet a prospective client but simply ask us a question, our legal basis is our legitimate interest in responding to enquiries about our services (Article 6(1)(f) GDPR).
If you engage us to assist with your matter, we process your personal data to perform that engagement, including opening and managing your file, communicating with relevant third parties on your behalf, and keeping you informed. The legal basis is the performance of a contract to which you are a party (Article 6(1)(b) GDPR).
Where you have provided your contact details, we may contact you to follow up on your enquiry or to provide information relevant to your matter. Depending on the context, our legal basis is your consent (Article 6(1)(a) GDPR), the performance of pre-contractual steps or a contract (Article 6(1)(b) GDPR), or our legitimate interest in maintaining a relationship with those who have contacted us (Article 6(1)(f) GDPR). Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
We use technical and usage data, including UTM parameters, to operate, secure, analyse and improve our website. The legal basis is our legitimate interest in understanding how our website is used and in maintaining its performance and security (Article 6(1)(f) GDPR). Where analytics rely on non essential cookies, we process the relevant data on the basis of your consent, which you provide through our cookie banner. Please see our Cookie Policy for further detail.
We may process personal data to comply with legal obligations to which we are subject, such as accounting, tax and anti money laundering obligations (Article 6(1)(c) GDPR), and to establish, exercise or defend legal claims, which is a legitimate interest of ours (Article 6(1)(f) GDPR).
Because of the nature of our work, we take steps to protect ourselves and our clients from recovery scams and other fraudulent activity. We may process personal data to verify the identity of persons contacting us and to detect and prevent misuse of our services. The legal basis is our legitimate interest in the security and integrity of our operations (Article 6(1)(f) GDPR).
Where we rely on legitimate interests, we have carried out a balancing exercise to ensure that our interests are not overridden by your interests or fundamental rights and freedoms. You may ask us for further information about that balancing exercise using the contact details in this Policy.
Some of our processing, particularly non essential cookies and certain optional communications, relies on your consent. Where this is the case, you are free to refuse or to withdraw consent at any time. Withdrawing consent is as easy as giving it: you may contact us at [email protected], or adjust your cookie preferences through the mechanisms described in our Cookie Policy. Withdrawal of consent does not affect the lawfulness of any processing we carried out before you withdrew it, and it does not affect processing that is based on a different legal basis.
We do not sell your personal data, and we do not share it for the independent marketing purposes of third parties. We disclose personal data only in the following circumstances and only to the extent necessary:
Every processor we engage is required to implement appropriate technical and organisational measures, to process personal data only on our documented instructions, to keep it confidential, and to assist us in meeting our obligations under the GDPR.
We aim to keep personal data within the European Economic Area ("EEA") wherever possible. However, some of our service providers may process personal data outside the EEA, for example where a hosting, analytics or communications provider operates infrastructure in a third country.
Where personal data is transferred outside the EEA, we ensure that an appropriate safeguard under Chapter V of the GDPR is in place. This may include a European Commission adequacy decision in respect of the destination country, or the use of Standard Contractual Clauses approved by the European Commission, supplemented where necessary by additional technical and organisational measures. You may request a copy of the relevant safeguard by contacting us at [email protected].
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting or reporting requirements, and to establish, exercise or defend legal claims. The retention periods we apply reflect the following principles:
When personal data is no longer required, we securely delete it or irreversibly anonymise it so that it can no longer be associated with you.
Subject to the conditions and exceptions set out in the GDPR and the Croatian GDPR Act, you have the following rights in relation to your personal data:
To exercise any of these rights, please contact us at [email protected]. We may need to verify your identity before acting on your request in order to protect your data. We will respond without undue delay and in any event within one month of receiving your request, though we may extend this period by two further months where the request is complex or numerous, in which case we will inform you.
If you believe that our processing of your personal data infringes the GDPR or the Croatian GDPR Act, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement. In Croatia, the competent supervisory authority is:
We would, however, appreciate the opportunity to address your concerns directly before you approach the AZOP, so we encourage you to contact us first.
Our website uses cookies, local storage and similar technologies to operate, to remember your preferences, to store marketing campaign parameters, and to analyse how our site is used. Detailed information about the technologies we use, their purposes and how to manage them is set out in our separate Cookie Policy, which forms part of this Privacy Policy. Where the law requires consent for non essential technologies, we obtain it through our cookie banner before those technologies are used.
We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include encryption of data in transit, access controls that limit who can view personal data, secure hosting arrangements, regular review of our systems, and confidentiality obligations imposed on our staff and processors.
No method of transmission over the internet or of electronic storage is completely secure, so while we strive to protect your personal data we cannot guarantee absolute security. In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the AZOP and, where required, affected individuals, in accordance with our obligations under the GDPR.
Our services are directed at adults. We do not knowingly collect personal data from children, and our website is not intended for use by anyone under the age of eighteen. If you believe that we have inadvertently collected data relating to a child, please contact us so that we can delete it.
If you have any question about this Policy, about how we handle your personal data, or if you wish to exercise any of your rights, please contact us using the details below. While we may not be legally required to appoint a Data Protection Officer, we have designated a point of contact for all data protection matters, and any communication sent to the address below will be directed to that point of contact.
We may update this Privacy Policy from time to time to reflect changes in our practices, in the technologies we use, or in the law. When we make material changes, we will update the date below and, where appropriate, notify you. We encourage you to review this Policy periodically. Your continued use of our website after any change takes effect signifies your acknowledgement of the updated Policy.
This Privacy Policy was last updated in 2026.