Skip to content

Privacy

What we know about you, why we have it, how long we keep it, and how to download or delete everything in two clicks.

Last updated: 7 August 2026

These pages are provided in English for convenience. The Croatian text remains the binding version until a certified translation is published.

Short version

  • Visit analytics run without cookies and without storing IP addresses.
  • We never see card details — billing is handled by Paddle.
  • You download all your data in one file and delete your account yourself, without sending a message.
  • We do not sell data or use it for advertising.

Data controller

Name
ANIM obrt za proizvode i usluge, vl. Nikola Nikša
Address
Stjepana Radića 93, 48350 Đurđevac
Company ID (OIB)
49059857692
Register
Obrtni registar Republike Hrvatske
Contact
[email protected]
Phone
095 861 2345

For questions about personal data processing, write to [email protected]. Report security issues to [email protected].

What data we process

Account. Email address, password in irreversible form (Argon2id), name if you enter it, account creation time, and last login time.

Business card. Name, activity, description, tags, phone, email, website, address, city, postal code, coordinates if you enter them, opening hours, logo and cover image, links. This data is public because the business card is public. When processing images, we remove EXIF data, including the photo location.

Business card visits. Event type (view, link click, contact download, QR scan), device type, country, referring domain, and a daily irreversible visitor fingerprint. We do not record IP addresses: the fingerprint is SHA-256 of the address, browser, date, and a secret salt, so the same visitor cannot be linked to yesterday tomorrow.

Subscription. Paddle customer and subscription identifiers, status, billing period, and cancellation date. Card data is processed by Paddle; it does not reach us.

Technical logs. Server logs with request time and response status, used to detect errors and attacks.

Legal bases

PurposeLegal basis
Account management, business card publication, and directoryContract performance — Art. 6(1)(b) GDPR
Business card visit statisticsLegitimate interest — Art. 6(1)(f); measured without identifying a person
Security, rate limiting, and abuse preventionLegitimate interest — Art. 6(1)(f)
Billing and accounting recordsContract performance and legal obligation — Art. 6(1)(b) and (c)

How long we keep data

DataPeriodNote
Account, business card, and linksUntil account deletionDeletion is immediate and irreversible, from the Account screen.
Raw business card visit events90 daysNo IP address; visitors are counted via a daily irreversible fingerprint.
Daily visitor fingerprint2 daysUsed only to count unique visits within a single day.
Daily visit totalsUntil business card deletionFigures per day, with no personal data.
Payment records11 yearsAccounting retention period; after account deletion, without email and without link to you.

Deletion of old data runs via an automated job, not a manual process — it does not depend on someone remembering to start cleanup.

Who receives data

  • Paddle.com Market Limited (Ireland) — merchant of record for subscriptions: email address and payment data.
  • Hosting provider in the European Union, where the application and database run.
  • Cloudflare — proxy and content delivery network for public pages.

We do not sell data, exchange it for advertising, or use it for profiling that would have a legal effect on you. Where transfer outside the EU exists, it is based on an adequacy decision or standard contractual clauses.

Your rights

Under the GDPR, you have the right of access, rectification, erasure, restriction of processing, portability, and to object to processing based on legitimate interest. Two rights you can exercise yourself, without waiting for a reply:

  • Export. On the Account screen, download one JSON file with everything you entered.
  • Deletion. On the same screen, delete your account; confirmation is your password, and deletion is immediate and irreversible.

For other rights, write to [email protected]. We respond within 30 days. If you believe we process data unlawfully, you may contact the supervisory authority: Agencija za zaštitu osobnih podataka (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr.

How we protect data

  • Traffic goes exclusively over HTTPS; session cookies are not accessible to JavaScript.
  • Passwords are stored as Argon2id hashes, never in readable form.
  • Only the application has database access; data is backed up daily.

Children

The service is intended for business users and is not designed for persons under 16. If we learn that a child opened an account, we delete it.

Changes to this policy

We change the policy when processing changes. Material changes are announced by email or in the interface before they take effect, and the date of the last change appears at the top of the document.

Privacy | digipass.space