Back-in-stock notifications
At your request, we store the selected product, the business account email, and login status in order to send a single notification when the product is back in stock. Signing up does not include the newsletter. You can unsubscribe from notifications in your account under "Notifications". When sending is active, the email is delivered by Brevo.
Data controller and contact
The data controller is Novi Forum d.o.o., Roberta Frangeša Mihanovića 6, 10000 Zagreb, Hrvatska, VAT ID 92006302133. For questions and requests regarding personal data, write to prodaja@rasvjeta.net with the subject "Personal data".
What data we use and why
For the business account, we process the contact's email and identity, the company name, tax ID (OIB), business address, membership, and authorizations. We also process inquiries, quotations, the cart, orders, delivery data, and related documents. Mandatory fields are marked on the form; without the identity of an authorized contact and company data, we cannot approve a business purchase, and without delivery data we cannot ship the goods. Access to company data depends on the employee's role.
Business communication, authorization management, and account protection rely on the legitimate interest of doing business securely with the company. A legal obligation applies to records we must retain. Where appropriate, separate consent is used for optional features. Acceptance of the purchase terms is not consent for marketing.
Selection, projects and login
Selections made before login and local projects are stored in your browser's local storage. You can remove them in the shop or by clearing the site's data in your browser. The business cart is saved with the account; logging out hides it on the device and does not delete orders or company records.
Shared projects of the approved company, rooms, requirements, deadlines, budgets, and selected products are stored with the business account and are available to its authorized members. We log changes together with the user who made them. The credit limit, liabilities, and recorded payments are used to manage the company's deferred payment.
Login via Supabase Auth uses a confirmed email address, identity, and sessions. If you choose the available Google or Apple login, the provider confirms the identity, and email login delivers a one-time link. Open it in the same browser. Necessary cookies serve login and account protection; social login alone does not approve the company for purchasing. Apple may forward a substitute email address if you choose the "Hide My Email" option.
The login remains saved after the browser is closed. The protected login cookie lasts up to 365 days and is renewed when the session is refreshed. Short-lived access tokens are refreshed automatically. Logging out, revoking the session, or deleting the cookie ends access on the device; private browsing mode may delete cookies on closing. On a shared device, log out after use.
We store the selected language in the necessary rasvjeta_language cookie for up to one year. Language selection does not include analytics.
Cookies and Google Analytics
Necessary cookies enable login, account protection, the cart, and saving cookie choices. For these functions, we do not request consent for analytics. The "Necessary only" choice allows normal use of the shop, login, and available AI features.
Google Analytics 4 is enabled only with your consent for analytics cookies. Before consent and after refusal, Google's analytics script does not load and we do not send analytics events. We measure visits to public pages, product views, adding to cart, starting a purchase, and confirmed purchases. Test orders are not included in purchase measurement.
Google receives technical browser and network connection data and approved usage events, including product and transaction identifiers. We do not send email, tax ID (OIB), delivery addresses, form and conversation content, photos, card data, search text, or URL parameters and fragments to analytics. Google's analytics script is separate from the shop's content. Advertising signals and ad personalization are excluded.
The consent choice, its version, and time are stored in a cookie rasvjeta_consent six months; the local record serves to synchronize selections across tabs. Google cookies _ga and _ga_…, if you accept analytics, have a set expiry of up to six months from the update. Upon withdrawal of consent we stop further analytics and remove these cookies. Previously sent data is not automatically deleted by withdrawal; for a deletion request, please contact us via the stated contact.
Consent for analytics does not include the newsletter or Lumen's personal memory. Google Ireland Limited and related Google services may process data outside the EEA as well, using applicable transfer mechanisms. More is described in Google's Privacy Policy.
AI conversation, voice and photos
When these services are enabled, conversation text and tasks may be sent to OpenAI and Anthropic's Claude. Voice is sent to the voice service provider only after the conversation is started and microphone permission is granted. You stop the microphone with the interrupt button or by switching from voice to another mode. AI functions are not required for a standard purchase.
With the user account we record the duration of voice calls, the connection identifier and the completion status for the purpose of calculating remaining time and preventing simultaneous use. Before the first paid order, a total of 35 minutes is available across all calls. The duration record does not contain an audio recording or conversation text and is kept separate from personal memory while the account is active. Deleting conversations or memory does not restore used minutes. To verify eligibility for a longer conversation we use confirmed orders and payments.
Text and voice use a shared conversation history. A logged-in user can enable personal memory in the Lumen window for future visits: in that case we store conversations and explicitly stated wishes, budgets, choices and information about spaces. You can review, correct or remove the notes. Turning off memory or "Forget everything" deletes personal notes and conversation history. "New conversation" deletes history while keeping saved notes. Personal memory is not available to other company members. Business projects and orders have separate access and retention rules.
A photo of the space is sent only after image creation is initiated. Photo processing is performed by OpenAI via the selected model. Input photos and results are stored in private storage linked to the session. Do not upload other people's personal data, confidential client information, or photos for which you do not have authorization.
For AI, only the data needed for the requested task is shared; you should not enter secrets or access keys. Providers may include processing outside the EEA. Such a transfer requires an applicable adequacy decision or appropriate safeguards, for example standard contractual clauses with the necessary additional measures. Information about recipients, processing locations, and a copy of the applicable safeguards can be requested via our privacy contact.
Recommendations and newsletter
The agent can analyze orders and quotations of an individual company to prepare a business conversation. The suggestion does not prove what the customer wants to buy. Item views and searches are recorded for personalization only when this setting is enabled; disabling it deletes events from that source.
Recommendations connect products, categories, shared projects, rooms and orders within your company. With personalization enabled, they can use the last 150 item views from a 90-day period. Disabling it also deletes the derived graph; recommendations from business history can be rebuilt. Conversation and search text is not stored in the graph.
The company administrator's setting does not replace employees' rights to personal data protection. An individual can contact the data controller to lodge a complaint and verify their data. The newsletter requires your separate voluntary sign-up in the account. We store the email, text and version of consent, approved content, and delivery status. When sending is activated, messages are delivered at the scheduled time by Brevo. You can unsubscribe in the account or via the link in the message. A company sign-up alone does not sign up an employee. To respect an unsubscribe, a minimal record of the sending ban may be kept.
Recipients and retention
Data is available to the seller's authorized persons and members of the affiliated company according to their role. For infrastructure we use Google Cloud, for login Supabase, and for available card payments Stripe. You enter the full card number and security code in Stripe's form; the store receives an identifier and payment status. When you use a connected service, Overseas processes recipient and shipment data, Brevo the address and message content, and e-racuni.com the data needed for business documents. For direct delivery, the supplier receives the data needed to prepare and deliver the order. Data may be available to the accountant, legal advisors and competent authorities when there is an appropriate basis.
Local projects remain on the device until deletion. The application log of AI conversations without enabled persistent memory expires 24 hours after the last processing. With memory enabled, history and notes remain until deleted by the user or until memory is disabled; this does not determine separate deadlines of the model provider. For photos and results in storage space, deletion is set after seven days, plus the time needed for the storage system to carry out the deletion. Business records are kept according to purpose, legal deadlines and the need to assert or defend claims.
We keep active account data as long as it is needed for access and the business relationship. After access ends, we retain only records with another valid basis, until the expiry of the applicable legal deadline or a justified need to prove a transaction and protect claims. Security logs serve to detect malfunctions and misuse. Dedicated application error reports do not include conversation text, photos, card data or access keys. Backups serve recovery and have limited access; deleted data may remain until the regular expiry of the backup. After restoration, recorded deletion requests are reapplied.
Your rights
An AI recommendation alone does not approve a company, credit limit, or conclude a contract. We do not make solely automated decisions about individuals with legal or similarly significant effects. You may object to direct marketing at any time.
Under the applicable terms, you can request access, correction or deletion of data, restriction of processing, lodge an objection, and request portability. You may withdraw consent without affecting the lawfulness of prior processing. Deletion is not absolute when there is a legal obligation to retain data or another valid basis.
We respond to requests within the period prescribed by GDPR, generally within one month, with the possibility of a legally permitted extension of which we will notify you. You can file a complaint with the Personal Data Protection Agency. The legal framework is General Data Protection Regulation.
Notice updated September 10, 2026 · B2B business terms