Skip to content
KriPa Web

Privacy policy

This site collects very little. What it does collect, and why, is set out below in plain terms.

Last updated: 29 August 2026

Who is responsible for your data

The controller of any personal data described here is KriPa Web, obrt za računalno programiranje, vl. Kristijan Pavlic Tumpa, with its registered office at Vankina ulica 8, 10000 Zagreb, Croatia, European Union, OIB 27744574396.

For anything to do with your data, write to kripaweb@kripaweb.com. Full registration details are on our legal notice.

What we collect

When you use the contact form. The form asks for:

  • Name, so we know who we are replying to.
  • Email address, so we can reply at all.
  • Company, optional, and only to understand the context of the enquiry.
  • Your message, the description of what you need.

Nothing on the form is hidden. What you type is what we receive, and it reaches us as an email. We do not enrich it with data from anywhere else, and we do not add you to a mailing list.

When you simply visit. Our hosting provider records ordinary server logs: the IP address of the request, the page asked for, the time, and the browser identification string your browser sends. These are kept briefly and used to keep the site running and to investigate faults or abuse.

Sending the form also touches your IP address for a different reason: we count recent submissions per address, in memory, for around ten minutes, so that a single sender cannot flood the form. It is not stored anywhere and not linked to your message.

Only if you allow it, which pages get visited. We count page views: which page was opened, where the visit came from if you arrived by following a link, your country, and the sort of browser and device you used. It tells us whether anyone is finding the site and which pages are worth improving. No cookie is involved and nothing is stored on your device. So that one person reading three pages is not counted as three people, a short-lived value is worked out from your request and used for nothing else. It is not kept as a lasting identifier and it is not used to follow you anywhere.

Only if you allow it, how quickly the page loaded. Your browser reports timing measurements back to us: how long the page took to become visible and usable, along with which page it was, your browser and device type, and an approximate location worked out from the connection. We use it to find pages that are slow for real visitors on real connections, rather than fast on our own machines. No cookie is involved, nothing is stored on your device, and it is not used to identify you or to recognise you on a later visit.

What we do not do

  • We set no cookies at all. The only thing kept on your device is your answer to the measurement question, which stays in your browser and never reaches us as data about you. See our cookie policy.
  • We use no advertising or marketing trackers: no tracking pixels, no ad networks, no social buttons reporting back, no session recording, and no heatmaps. What we measure is described above and goes no further than it says.
  • Our fonts are served from our own site, so visiting does not tell any font provider that you were here.
  • We do not build a profile of you, and no decision about you is made automatically. What we see are numbers about pages, not histories about people.
  • We never sell personal data. There is nothing to sell.

Why we are allowed to do this

Under the General Data Protection Regulation we rely on two grounds:

  • Steps taken at your request before entering a contract (Article 6(1)(b)). You asked us a question about work; we need your details to answer it.
  • Your consent (Article 6(1)(a)) for the page view counting and the loading measurements. Nothing is loaded until you allow it, and you can withdraw at any time from cookie settings or the small button in the corner of any page, as easily as you gave it. Withdrawing stops it immediately and does not make what went before unlawful.
  • Our legitimate interests (Article 6(1)(f)) in keeping the site available, secure, and free of automated abuse. This covers the server logs and the submission counting, neither of which we can switch off without losing the ability to run the site safely.

Who else sees it

We keep the list of parties who handle data on our behalf short, and each is bound by a data processing agreement:

  • Our hosting provider (United States). Hosts the site and serves it to your browser. Its servers keep short-lived request logs, which include IP addresses, and it receives the page loading times your browser reports back to us.
  • Resend (United States). Delivers the message you send through the contact form to our inbox.
  • Google Workspace (European Union and United States). Hosts our mailbox, so it stores the correspondence once it arrives and any reply we send you.

Beyond these, we disclose personal data only where the law requires it of us.

Transfers outside the European Economic Area

Some of the providers above are established in the United States. Where personal data reaches them, the transfer is covered by the European Commission’s Standard Contractual Clauses, or by the provider’s certification under the EU-US Data Privacy Framework, together with the technical safeguards those instruments require.

How long we keep it

  • An enquiry that does not lead to work: up to 12 months from our last exchange, then deleted. No law requires us to keep it at all, so we do not keep it long.
  • Correspondence with clients: for as long as we are working together, and 5 years after that. That matches the general limitation period for claims under Croatian law, so that we can still answer a claim if one is made.
  • Invoices and business records: 6 years from the end of the year the record belongs to, which is how long Croatian tax law requires us to be able to produce them. This period is set by law rather than chosen by us, and we cannot delete these records early even if you ask us to.
  • Server logs: kept briefly by our hosting provider and then discarded automatically.

Your rights

You can ask us for a copy of your data, to correct it, to delete it, to restrict what we do with it, to receive it in a portable form, or to object to our use of it. These are set out in full, with how to use them and how quickly we answer, on our data protection rights page.

If you think we have handled your data badly, we would rather hear it from you first. You are also entitled to complain to the Croatian supervisory authority, Agencija za zaštitu osobnih podataka (AZOP), Ulica Metela Ožegovića 16, 10000 Zagreb, Croatia, +385 1 4609 000, azop.hr, or to the authority in the country where you live.

Children

This site sells professional services to businesses. It is not directed at children, and we do not knowingly collect their data.

Changes to this policy

If what we do changes, this page changes first, and the date at the top changes with it. We do not make quiet edits.