Privacy Policy
1. Introduction and data controller identity
Kripton d.o.o., Martinišće 70a, 49210 Zabok, Croatia, VAT ID: HR48227356142 (hereinafter "we", "Company") is responsible for processing personal data collected through this website in accordance with Regulation (EU) 2016/679 (GDPR).
Data protection contact: info@kripton-grupa.hr
2. Data we collect
Through the contact form we collect: first name, last name, email address, phone number (optional) and message content. We automatically collect: IP address, browser type, referring page and visit timestamp (cookies - see section 6).
3. Purpose and legal basis
- Responding to enquiries - legal basis: legitimate interest (Art. 6(1)(f) GDPR)
- Establishing a business relationship - legal basis: pre-contractual steps (Art. 6(1)(b))
- Analytics and security - legal basis: consent (Art. 6(1)(a)) for non-essential cookies
4. Data sharing
We do not sell or transfer your personal data to third parties for commercial purposes. Data may be shared with trusted processors (hosting, email services) solely for service delivery, under appropriate contractual protections.
5. Retention
Contact form data is retained for a maximum of 2 years from receipt, unless an ongoing business relationship is established. After this period, data is deleted or anonymised.
6. Cookies
We use only necessary technical cookies (session, CSRF protection). Analytics and marketing cookies are activated only with your explicit consent via the cookie notice. Details are available in our Cookie Policy.
7. Your rights
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure ("right to be forgotten") (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent at any time
Submit a request to info@kripton-grupa.hr. We will respond within 30 days. You have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP): azop.hr.
8. Security
We implement technical and organisational security measures (HTTPS/TLS, restricted access, regular security reviews) in accordance with Art. 32 GDPR.
9. Changes
We reserve the right to update this policy. For significant changes we will notify you by posting on this page with a new update date.