Politique de confidentialité
Dernière mise à jour : 25.07.2026.
Service Provider
StormLine, obrt za informatičke usluge, vl. Anto Marić
Registered address: Dolenec 37, 10410 Velika Mlaka, Republic of Croatia
Email: [email protected]
The business is registered in the Croatian Craft Register.
Data controller: StormLine, obrt za informatičke usluge, vl. Anto Marić.
1. Introduction
This Privacy Policy explains how StormLine, obrt za informatičke usluge, vl. Anto Marić (hereinafter: "we" or "StormLine") collects, uses, stores and protects the personal data of visitors and users of the stormline.hr website, in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Act on the Implementation of the General Data Protection Regulation.
2. Data Controller and Processor
The data controller is StormLine, obrt za informatičke usluge, vl. Anto Marić, Dolenec 37, 10410 Velika Mlaka, Republic of Croatia, e-mail: [email protected].
In certain cases, StormLine may process personal data as a data controller, and in certain business relationships as a data processor, depending on the nature of the service provided.
When StormLine acts as a data processor (e.g. during the administration of client servers), processing is carried out solely on the basis of the controller's instructions, in accordance with a Data Processing Agreement (DPA) signed between the parties in accordance with Article 28 of the GDPR.
3. What Data We Collect
- Data you provide directly: first and last name, e-mail address, phone number, company name and message content — when you fill out the contact form or request a quote.
- Data from contractual relationships: data you provide when entering into a contract or purchasing a license (e.g. data required for invoicing and service provision).
- Technical data: IP address, browser type, operating system, pages visited and visit time — collected automatically via the server and (with your consent) analytics tools.
- Cookies: described in detail in our Cookie Policy.
- Fusion OTT Platform license technical data: license identifier, installation identifier, domain, IP address, software version, license verification time and security events — collected to verify license validity, prevent unauthorized use and ensure security updates.
4. Purpose and Legal Basis for Processing
- Responding to inquiries and quote requests — based on your request respectively taking steps prior to entering into a contract (Article 6(1)(b) GDPR).
- Performance of contracts for services and licenses provided (including Fusion OTT Platform) — based on contract performance (Article 6(1)(b) GDPR).
- Improving the website and understanding usage through analytics — exclusively with your prior consent (Article 6(1)(a) GDPR), in accordance with cookie settings.
- Fulfilling legal obligations (e.g. accounting, tax regulations) — based on legal obligation (Article 6(1)(c) GDPR).
- Protection of our legitimate interests, for example for system security protection, preventing abuse, maintaining security event logs and asserting or defending legal claims (Article 6(1)(f) GDPR).
- Verifying the validity of Fusion OTT Platform licenses and preventing unauthorized use — based on legitimate interest (Article 6(1)(f) GDPR).
5. Server Administration and Processing of Client Data
StormLine provides administration and maintenance services for servers that clients have with third-party service providers (e.g. OVH, Hetzner, Contabo, DigitalOcean, AWS, Azure, Google Cloud). During the provision of these services, StormLine may have access to data located on the client's server, including potentially personal data of the client's users.
In such cases, StormLine acts as a data processor for personal data processed on the client's server, and the client is the data controller. StormLine processes such data solely on the basis of the client's instructions and within the scope necessary for providing the contracted administration services.
For such relationships, StormLine and the client sign a Data Processing Agreement (DPA) in accordance with Article 28 of the GDPR, which defines the obligations of both parties, security measures, processing period and the procedure for deleting or returning data after the service ends.
6. Analytics and Cookies
Our website contains technical infrastructure for traffic analytics. Analytics tools are not activated and do not collect data until the visitor explicitly consents to their use via the cookie banner. If analytics is not currently active, this is clearly indicated in our Cookie Policy.
7. Recipients of Data
We do not sell your data to third parties. Access to data may be granted exclusively to:
- The server infrastructure provider on which the website runs (data is stored on own/rented server in EU/Croatia);
- E-mail service providers, solely for delivering responses to your inquiry;
- Infrastructure providers that StormLine uses for client server administration (e.g. OVH, Hetzner, Contabo, DigitalOcean, AWS, Azure, Google Cloud) — solely within the scope necessary for providing contracted services;
- Security and backup service providers;
- Accounting service, when necessary to fulfill legal obligations;
- Competent authorities, when legally required.
8. Data Retention Period
- Data from contact form and quote requests: up to 24 months from last contact, unless a contractual relationship arises from them, in which case they are stored in accordance with legal periods for business documentation.
- Data from contractual relationships: in accordance with legal obligations for retaining accounting and tax documentation, within the periods prescribed by applicable tax, accounting and other applicable regulations of the Republic of Croatia.
- Fusion OTT Platform license technical data: for as long as necessary for license validity verification, preventing unauthorized use and fulfilling legal obligations.
- Cookies: according to the periods specified in the Cookie Policy.
9. Your Rights
In accordance with the GDPR, you have the right to:
- access the personal data we process;
- rectification of inaccurate or incomplete data;
- erasure of data ("right to be forgotten"), where applicable;
- restriction of processing;
- data portability;
- objection to data processing;
- withdrawal of consent at any time, without affecting the lawfulness of processing prior to withdrawal;
- the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP).
Requests can be sent to [email protected].
10. Automated Decision-Making
StormLine does not use automated decision-making or profiling within the meaning of Article 22 of the GDPR. All decisions affecting the rights or interests of data subjects are made with human oversight.
11. Right to Lodge a Complaint with the Supervisory Authority
If you believe that the processing of your personal data is not in compliance with regulations, you have the right to lodge a complaint with the supervisory authority:
Croatian Personal Data Protection Agency (AZOP)
Selska cesta 136, 10000 Zagreb
Web: azop.hr
E-mail: [email protected]
12. Data Security
We take reasonable technical and organizational measures (including encrypted data transfer via HTTPS, restricted server access and regular system updates) to protect your personal data from unauthorized access, loss or misuse.
No method of data transfer or electronic data storage is completely secure, but we apply appropriate measures to minimize the risk.
13. International Data Transfer
Personal data is generally processed and stored within the European Economic Area (EEA).
If in the future certain service providers process data outside the EEA, StormLine will ensure appropriate safeguards in accordance with the GDPR, including the European Commission's standard contractual clauses or another legally permitted transfer mechanism.
14. Changes to This Policy
We reserve the right to amend this Privacy Policy. We will notify you of all significant amendments by publishing the updated version on this page, with the date of the last amendment.
15. Contact
For any questions regarding the processing of personal data, contact us at [email protected].
We will respond to requests related to exercising data subject rights without undue delay and at the latest within the period prescribed by the GDPR.