GDPR Compliant
Last updated: February 23, 2026
The data controller responsible for your personal data is:
As a company registered in the Republic of Croatia, a member state of the European Union, we are fully subject to the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Croatian Act on the Implementation of the General Data Protection Regulation (NN 42/18).
We collect and process the following categories of personal data:
| Category | Data Types | Legal Basis |
|---|---|---|
| Contact Information | Name, email address, phone number, company name | Consent (Art. 6(1)(a)) / Contract performance (Art. 6(1)(b)) |
| Inquiry Data | Service interest, project description, budget range, messages | Contract performance (Art. 6(1)(b)) |
| Payment Data | Billing address, VAT ID, payment transaction records | Contract performance (Art. 6(1)(b)) / Legal obligation (Art. 6(1)(c)) |
| Technical Data | IP address, browser type, device information, cookies | Legitimate interest (Art. 6(1)(f)) |
| Chat Data | Messages sent via our AI chat widget | Consent (Art. 6(1)(a)) |
We process your personal data for the following purposes:
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
As a data subject, you have the following rights under the GDPR:
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) at azop.hr.
We do not sell your personal data. We may share your data with:
For any data transfers outside the EEA, we ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission or adequacy decisions.
Our website uses the following types of cookies:
You can manage your cookie preferences through your browser settings at any time.
We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit (TLS/SSL), access controls, regular security assessments, and secure data storage. In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours as required by Art. 33 GDPR, and affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Art. 34 GDPR).
Our services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will delete it promptly.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. We encourage you to review this page periodically. Material changes will be communicated to active clients via email.
For any privacy-related questions or to exercise your rights:
Supervisory Authority
Agencija za zaštitu osobnih podataka (AZOP)
Selska cesta 136, 10000 Zagreb, Croatia
Website: azop.hr