Legal
Privacy Policy
Concise, transparent and compliant: which personal data is collected, for which purposes, on what legal basis, how long it is retained and what rights you have.
Last updated: 6 August 2026
1. Data controller
The controller of personal data processed through the curcic.si website is:
- Denis Čurčić s.p.
- Registered address: Petronijeva ulica 4, 6000 Koper, Slovenia
- Tax number: 70680825
- Registration number: 8104778000
- VAT taxpayer: no (not a VAT payer – Article 76.a of ZDDV-1)
- SKIS: S.14100 – Self-employed employers
- Date of registration: 8 December 2017
- Main activity: computer and information services
- Email: denis@curcic.si
- Website: curcic.si
A data protection officer (DPO) has not been appointed, as the conditions set out in Article 37 of the General Data Protection Regulation (GDPR) are not met. For all data protection matters and to exercise your rights, please write to denis@curcic.si.
2. Categories of data processed
- Data provided when contacting the controller. When an email or enquiry is sent, the controller processes the sender's email address, first and last name (where provided) and the entire content of the message, including attachments.
- Technical hosting data (server logs). Upon each visit, the server automatically records the IP address, date and time of the request, browser type and version, operating system and requested URL. This processing is technically necessary for the operation and security of the website.
- Analytics data (only with consent). If the data subject gives explicit consent to analytics cookies, Google Analytics 4 collects anonymised data about the visit (pages viewed, time on site, approximate city-level location, traffic source and technical device characteristics).
The website has no user accounts, newsletter subscriptions or online store. Special categories of personal data under Article 9 GDPR are not collected, and no automated decision-making or profiling with legal effects takes place.
3. Purposes and legal bases of processing
- Responding to enquiries and pre-contractual activities. Processing of data submitted by email. Legal basis: Article 6(1)(b) GDPR (performance of a contract or steps taken at the data subject's request prior to entering into a contract).
- Ensuring the security and stability of the website. Processing of technical server logs to prevent unauthorised access and misuse and to fix errors. Legal basis: Article 6(1)(f) GDPR (the controller's legitimate interest in secure and uninterrupted operation of its network and information system).
- Measuring traffic and optimising content. Website analytics. Legal basis: Article 6(1)(a) GDPR and Article 226 of ZEKom-2 (prior explicit consent of the data subject). Analytics tools are not loaded without prior consent.
- Compliance with legal obligations. Retention of documentation in the event of business cooperation. Legal basis: Article 6(1)(c) GDPR (a legal obligation applicable to the controller under tax and accounting legislation).
4. Retention periods
- Email correspondence: up to 2 years after the communication ends or the reason for contact ceases, unless longer retention is required by law.
- Business and accounting documentation: 10 years from the end of the year to which the documentation relates (in line with tax legislation).
- Server logs: up to 30 days from creation.
- Analytics data (Google Analytics 4): up to 14 months.
- Record of cookie consent: 12 months from the moment consent is given.
5. Recipients and transfers to third countries
Personal data is not sold and is not shared with third parties for their own purposes. To ensure the operation of the website, the following processors may access data to a limited extent:
- website hosting and infrastructure provider,
- email service provider,
- Google Ireland Limited (Google Analytics 4) — solely on the basis of prior consent,
- accounting service — only within statutory obligations.
Where data is transferred to third countries (the USA, e.g. Google LLC), such transfers take place under the EU-U.S. Data Privacy Framework or on the basis of the Standard Contractual Clauses (SCCs) adopted by the European Commission.
6. Cookies
The website uses strictly necessary technical cookies and analytics cookies, the latter loaded only after the visitor's explicit consent has been obtained. Further information and consent settings, which can be changed or withdrawn at any time, are available in the Cookie Policy.
7. Rights of data subjects
Under the GDPR, data subjects have the following rights regarding their personal data:
- the right of access to the data (Article 15 GDPR),
- the right to rectification of inaccurate data (Article 16 GDPR),
- the right to erasure, the "right to be forgotten" (Article 17 GDPR),
- the right to restriction of processing (Article 18 GDPR),
- the right to data portability (Article 20 GDPR),
- the right to object to processing based on legitimate interest (Article 21 GDPR),
- the right to withdraw consent at any time, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal (Article 7(3) GDPR).
Requests to exercise these rights may be sent to denis@curcic.si. The controller will respond no later than one month from receipt. To prevent unauthorised access or misuse, the controller may request additional verification of the applicant's identity.
8. Right to lodge a complaint with the supervisory authority
If a data subject considers that the processing of their personal data infringes applicable data protection legislation, they have the right to lodge a complaint with the supervisory authority:
- Information Commissioner of the Republic of Slovenia
- Dunajska cesta 22, 1000 Ljubljana, Slovenia
- Email: gp.ip@ip-rs.si | Phone: +386 1 230 97 30
- Website: www.ip-rs.si
9. Data security
Data is transmitted over an encrypted connection (HTTPS/SSL). Access to email and databases is protected by appropriate technical and organisational measures, including strong passwords and two-factor authentication. Processing is carried out in strict accordance with the data minimisation principle (Article 5(1)(c) GDPR).
10. Changes to this privacy policy
The controller reserves the right to update this Privacy Policy from time to time to reflect changes in legislation or in the operation of the website. The version published on this page, bearing the date of the last update, is always the applicable one.
