Personal data protection · GDPR

Privacy Policy

This policy explains which personal data we collect through the pixelproof.hr website, for what purpose we use it, and what rights you have under the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). Effective from October 5, 2026.

1. Data controller

The data controller is Pixel & Proof, owner Davor Špehar, Seišće 31, Rakitje, Croatia. For any questions about data protection you can contact us at info@pixelproof.hr or on +385 91 4410 447.

2. What data we collect

We collect only the data you provide to us yourself or that is technically necessary for the operation of the website:
  • Contact form: full name, business email address, and the content of the message (e.g., company name, type of products, module you are interested in).
  • Direct communication: data you provide when you email us or call us.
  • Technical data: IP address, browser type, and access time, which the server automatically records in security logs.
Please do not enter special categories of personal data (e.g., health data) in your messages.

3. Purpose and legal basis of processing

  • Responding to an inquiry and preparing an offer — steps prior to entering into a contract at the request of the data subject (Art. 6(1)(b) GDPR).
  • Business communication with company representatives (B2B) — legitimate interest in responding to business inquiries and maintaining a business relationship (Art. 6(1)(f) GDPR).
  • Security and proper operation of the website — legitimate interest in protection against abuse (Art. 6(1)(f) GDPR).
We do not use data for automated decision-making or profiling, nor do we send you marketing messages without your explicit consent.

4. Retention period

We retain inquiries and related correspondence for a maximum of 24 months from the last communication, unless the inquiry leads to a contractual relationship — in which case the data is retained for the periods prescribed by accounting and tax regulations. Technical server logs are deleted automatically after a shorter period determined by the hosting provider's settings.

5. Data recipients

We do not sell your data or disclose it to third parties for marketing purposes. Access to data may be had solely by our processors to the extent necessary to provide the service — the website hosting provider and the email service provider — who are contractually bound to confidentiality and data protection. We may disclose data to competent authorities where we are legally obliged to do so.

6. Cookies and external content

The website does not use cookies for analytics or advertising, nor does it load content from third-party external servers (fonts and scripts are served from our own domain). Only technically necessary cookies required for the operation of the website and the form are used. If in the future we introduce analytics or marketing cookies (e.g., to measure Google Ads campaigns), we will first ask for your consent and update this policy.

7. Data transfers outside the EU

We process data within the European Economic Area. If any processor were to process data outside the EEA, the transfer would be based on a European Commission adequacy decision or standard contractual clauses.

8. Your rights

Under the GDPR you have the right:
  • to access your personal data and obtain a copy,
  • to rectification of inaccurate or incomplete data,
  • to erasure of data ("right to be forgotten"),
  • to restriction of processing,
  • to data portability,
  • to object to processing based on legitimate interest.
You can send your request to info@pixelproof.hr. We will respond without undue delay and at the latest within one month.

9. Right to lodge a complaint with a supervisory authority

If you believe that the processing of your data violates regulations, you have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr.

10. Security and changes to this policy

We apply appropriate technical and organisational protection measures, including an encrypted connection (HTTPS) and restricted access to data. We may update this policy from time to time; the current version is always published on this page, together with its effective date.

Scroll to Top