Privacy Policy
This Privacy Policy explains how Nexventora d.o.o. (hereinafter: "Nexventora", "we") processes the personal data of visitors and users of the nexventora.com domain. The document has been prepared in accordance with the General Data Protection Regulation (EU) 2016/679 and the Croatian Act on the implementation of the GDPR.
1. Data controller
The controller of your personal data is Nexventora d.o.o., Ilica 191A, 10000 Zagreb, OIB: 47291038562. For data protection enquiries please contact privacy@nexventora.com.
2. Data we collect
We collect the data you voluntarily provide via the contact form (name, email address, message content) and technical data your browser sends when visiting the site (truncated IP address, device type, language). We do not collect special categories of data.
3. Purposes and legal bases
We process your data to respond to enquiries (legal basis: pre-contractual steps), to keep a record of communication (legitimate interest) and for analytics and marketing solely on the basis of your explicit consent recorded via the cookie banner.
4. Retention period
We keep data from the form for up to 24 months after the last contact, unless a legal obligation requires a longer period. Marketing consents are kept until withdrawn; anonymous analytics data is retained for up to 14 months.
5. Data recipients
Data is processed only by authorised Nexventora staff and carefully selected processors (hosting providers in the EEA, email tools, Google Ireland Ltd. for analytics and advertising). We do not sell personal data to third parties.
6. Transfers outside the EU
Where data is processed by partners established outside the EEA, we rely on the European Commission's standard contractual clauses or other appropriate safeguards under the GDPR.
7. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection, as well as the right to withdraw your consent at any time. You may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, Zagreb.
8. Security
We apply organisational and technical measures such as TLS encryption, least-privilege access control, regular system reviews and risk assessments for new features.
9. Changes to this policy
We may update this policy from time to time to reflect regulatory changes or changes in our services. The current version is always available on this page; significant changes will be highlighted.