timis
Start a project
// privacy

Privacy Policy

last updated 2026-09-23

Draft — have this reviewed by a lawyer before publishing, and adjust the list of tools to what you actually use. This policy explains how Timis Digital d.o.o. handles personal data when you visit this website, contact us, or work with us. We follow the EU General Data Protection Regulation (GDPR) and the Croatian Act on the Implementation of the GDPR.

1. Controller

Timis Digital d.o.o., Ivanićgradska ulica 33, 10310 Ivanić-Grad, Croatia, OIB 10380867550. Email: igor@timis.digital. Phone: +385 91 588 2884. We have not appointed a data protection officer; write to the address above for anything related to your data.

2. What we collect and why

2.1 Contact form and email

When you contact us we process your name, email address, company, the project details you send us and your IP address (for spam protection). Legal basis: steps prior to entering into a contract and our legitimate interest in answering enquiries (Art. 6(1)(b) and (f) GDPR). We keep enquiries for up to 24 months unless they lead to a contract.

2.2 Clients and suppliers

To deliver our services we process contact and billing details of our clients and their staff (name, role, email, phone, address, invoices, payment references). Legal basis: performance of the contract and legal obligations such as accounting rules (Art. 6(1)(b) and (c)). Accounting records are kept for 11 years as required by Croatian law.

2.3 Payments

Card payments are handled by our payment provider through a secure payment link; we do not receive or store card numbers. The provider processes your data under its own privacy policy. Bank transfer details appear on our bank statements as required by law.

2.4 Website analytics

This website does not use analytics or tracking tools. Server logs (IP address, time, requested page, browser) are kept for up to 30 days for security. Legal basis: legitimate interest in running and securing the website (Art. 6(1)(f)).

2.5 Cookies

This website sets no tracking cookies. Only technically necessary storage (for example remembering a form you started) may be used, which does not require consent.

3. Who receives your data

We share personal data only with service providers we need to run our business, under data processing agreements: email and hosting providers (servers located in the EU), our accounting firm and the payment provider for card payments. We do not sell personal data. Where a provider is located outside the EU/EEA, transfers are protected by EU Standard Contractual Clauses or an adequacy decision.

4. When we work on your website

When we host or maintain a client’s website we may have technical access to personal data stored in it (for example customer accounts in an online shop). In that case we act as a processor on the client’s instructions under a data processing agreement, and the client remains the controller.

5. How long we keep data

Enquiries: up to 24 months. Contracts, invoices and related correspondence: 11 years (accounting law). Server logs: 30 days. Backups of hosted sites: 30 days after a plan ends. We delete or anonymise data when it is no longer needed.

6. Your rights

You have the right to access, rectify and erase your personal data, to restrict or object to processing, to data portability, and — where processing is based on consent — to withdraw consent at any time. Write to igor@timis.digital; we answer within one month. You can also lodge a complaint with the Croatian Personal Data Protection Agency (AZOP, azop.hr) or the supervisory authority in your country.

7. Security

We use TLS encryption on this website, access controls and two-factor authentication on our accounts, encrypted backups, and servers located in the EU. No system is perfectly secure; if a breach affects your data we will inform you and the authorities as required by law.

8. Changes

We update this policy when our practices or the law change. The current version is dated 2026-09-23.