Legal
Privacy policy
How personal data is handled on this website and in the course of an engagement.
Last updated: TBC
Who is responsible
The controller of personal data is Contra Consulting, a registered craft business with its seat in Osijek, Croatia. The full registered business name, the register entry and the identification numbers are set out on the company details page.
For any question about how your data is handled, write to info@contra.hr.
What data is collected
Through this website, personal data is collected in two situations:
- When you send an enquiry through the contact form: your name, your email address, and — if you choose to provide them — your company and country, together with the content of your message.
- When you visit the site: your IP address and standard technical request data are processed by the hosting provider for the purpose of delivering the site and protecting it against abuse. These records are short-lived and are not used to build a profile of you.
This website sets no cookies, uses no advertising or tracking technologies, and loads no fonts, scripts or other resources from third-party servers. There is therefore nothing to consent to, and no cookie banner.
Why it is processed, and on what legal basis
- To answer your enquiry and take steps at your request prior to entering into a contract — Article 6(1)(b) GDPR.
- To operate and secure the website — our legitimate interest in providing a functioning and protected service, Article 6(1)(f) GDPR.
- To perform an engagement, invoice for it, and comply with accounting and tax obligations, where you become a client — Articles 6(1)(b) and 6(1)(c) GDPR.
Your details are not used to send marketing, are not added to any mailing list, and are not sold, rented or shared for anyone else's purposes.
Who else sees it
Personal data is disclosed only to the extent necessary, and only to:
- The hosting and email providers that operate this website and deliver its messages, acting as processors under written agreements.
- Where an engagement requires it and you have been informed, independent professionals engaged on your matter — for example an attorney, accountant or certified translator.
- Public authorities, where disclosure is required by law.
Providers are selected so that data is stored within the European Economic Area wherever possible. Where any transfer outside the EEA occurs, it takes place under the safeguards permitted by Chapter V of the GDPR, such as the European Commission's standard contractual clauses.
How long it is kept
- Enquiries that do not lead to an engagement: kept for up to twelve months, then deleted.
- Engagement records: kept for the duration of the engagement and afterwards for as long as required by statutory retention and limitation periods.
- Accounting documents: kept for the period required by Croatian accounting and tax law.
- Website server logs: kept only briefly, for security and diagnostics.
Your rights
Under the GDPR you have the right to:
- Ask what personal data is held about you and receive a copy of it
- Have inaccurate data corrected
- Have data erased, where there is no overriding obligation to keep it
- Ask that processing be restricted, or object to processing based on legitimate interest
- Receive data you provided in a portable format
- Withdraw consent at any time, where processing is based on consent — this does not affect processing that has already taken place
To exercise any of these, write to info@contra.hr. You will receive a response within one month.
If you believe your data has been handled unlawfully, you may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr.
Changes to this policy
If this policy changes, the revised version is published on this page with a new date. Material changes affecting existing clients are communicated directly.