Legal

Document 2 of 6

Privacy policy

How Version2 j.d.o.o. collects, uses, stores, and protects your personal data under GDPR.

Last updated
Sections
10
Contents

This Privacy Policy explains how Version2 j.d.o.o. collects, uses, stores, and protects your personal data when you visit our website or use our services. We are committed to processing your data lawfully, fairly, and transparently in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Croatian GDPR Implementation Act (Zakon o provedbi Opće uredbe o zaštiti podataka).


1. Data Controller

Version2 j.d.o.o. za digitalni marketing Novigradska ulica 21, 23000 Zadar, Croatia

  • Court of registration: Trgovački sud u Zadru
  • MBS: 110121143
  • OIB: 91496405628
  • Director: Marko Matošević
  • Email: office@version2.hr
  • Phone: +385 99 561 7706
  • Website: www.version2.hr

Version2 j.d.o.o. is the data controller responsible for processing your personal data as described in this policy.

Data Protection Officer: Not appointed. As a small enterprise that does not carry out large-scale processing of special categories of data or systematic monitoring, we are not required to appoint a DPO under Article 37 of the GDPR. For all data protection inquiries, please contact us at office@version2.hr.


We process personal data only when we have a lawful basis to do so. The table below describes each processing activity, the data involved, the purpose, the legal basis under GDPR Article 6(1), and how long we retain the data.

a) Contact Form Submissions

Details
Data collected Name, email address, phone number (optional), message content
Purpose Respond to your inquiry, provide quotes, initiate pre-contractual discussions
Legal basis Art. 6(1)(b) GDPR: necessary for taking steps at the request of the data subject prior to entering into a contract. Art. 6(1)(f) GDPR: our legitimate interest in responding to business inquiries
Retention 2 years from the date of submission, then permanently deleted

b) Digital Business Card Orders

Details
Data collected Name, email address, phone number, shipping address, payment information, business/brand details, and (for "we design it for you" orders) the design brief you provide
Purpose Fulfill orders, produce and ship digital business cards, and issue a one-time setup link so you can create your digital profile on our profile app at app.version2.hr
Legal basis Art. 6(1)(b) GDPR: necessary for the performance of a contract to which you are a party
Retention Order and accounting records: duration of the business relationship plus 11 years, as required by the Croatian Accounting Act (Zakon o računovodstvu, Art. 10)

c) Uploaded Artwork and Logo Files

Details
Data collected Print-ready artwork, logo, image, or photograph files you upload (or supply as part of a design brief). These files may contain images, logos, photographs, or other personal data depending on what you include.
Purpose Print the artwork on your physical card. We print uploaded files as supplied; we do not use them for any other purpose.
Legal basis Art. 6(1)(b) GDPR: necessary for the performance of a contract to which you are a party
Retention Deleted within 90 days after the order is fulfilled (card shipped), unless a longer period is required to handle a defect claim or to comply with a legal obligation

d) Website Analytics (Google Analytics GA4)

Details
Data collected IP address (anonymized), pages visited, session duration, device type, browser, approximate geographic location, referral source
Purpose Understand how visitors use our website, improve user experience, identify technical issues
Legal basis Art. 6(1)(a) GDPR: your consent, collected via our cookie consent banner. Analytics cookies are only activated after you explicitly opt in.
Retention 14 months (Google Analytics default retention setting)

e) Custom Backend Analytics

Details
Data collected Page views, session data, interaction events, all anonymized with no personal identifiers
Purpose Monitor website performance, identify errors, improve site reliability
Legal basis Art. 6(1)(f) GDPR: our legitimate interest in monitoring and maintaining website performance
Retention 90 days, then automatically deleted

f) AI Chatbot Conversations

Details
Data collected Conversation content, timestamp, session identifier, and technical connection data (IP address) recorded for abuse prevention. No personal data is required to use the chatbot.
Purpose Provide automated customer support, answer questions about our services
Legal basis Art. 6(1)(a) GDPR: your consent, given by voluntarily initiating and using the chat. Art. 6(1)(f) GDPR: our legitimate interest in providing responsive customer support
Retention Deleted automatically after 6 months of conversation inactivity

Important notices regarding the AI chatbot:

  • Conversations are stored solely for support quality and service improvement purposes. They are not used to train AI models.
  • Chatbot messages are processed by OpenRouter, Inc. (US), which routes them to the underlying AI model provider (see section 3). The specific model may change over time; we maintain current data processing agreements with all AI service providers.
  • EU AI Act transparency disclosure (Art. 50): When interacting with our chatbot, you are communicating with an AI-powered system, not a human. The chat interface clearly indicates this.
Details
Data collected Your consent choices (which cookie categories you accepted or rejected), timestamp of consent
Purpose Record and respect your cookie preferences across visits
Legal basis Art. 6(1)(c) GDPR: compliance with our legal obligation under the ePrivacy Directive (2002/58/EC) and the Croatian Electronic Communications Act (Zakon o elektroničkim komunikacijama, Art. 104)
Retention Until you withdraw consent or reset your preferences, up to a maximum of 2 years

h) Payment Data

Details
Data collected Payment card details are handled entirely by Stripe. Version2 j.d.o.o. does not store, process, or have access to your credit card number, CVV, or full payment card details.
Stripe's role Stripe acts as an independent data controller for payment processing and is certified under the Payment Card Industry Data Security Standard (PCI DSS). See Stripe's privacy policy.
Bank transfers If you pay by bank transfer, the IBAN and account holder name you provide are stored as part of your order records for the retention period described in section (b) above.
Legal basis Art. 6(1)(b) GDPR: necessary for the performance of a contract

i) Free Website Analysis

Details
Data collected Your name, email address, the website URL you submit, technical connection data (IP address), and the generated audit report
Purpose Run the automated website audit you request, deliver the report to you, and follow up on your request
Legal basis Art. 6(1)(b) GDPR: performance of the service you request. Art. 6(1)(f) GDPR: our legitimate interest in following up on inbound enquiries
Retention 365 days, then automatically deleted

j) Advertising Measurement (Google Ads and Meta Pixel)

Details
Data collected Cookie identifiers (_gcl_au, _fbp, _fbc), ad-click identifiers, pages visited, and conversion events (for example an inquiry sent or an order placed)
Purpose Measure which of our advertising campaigns lead to inquiries and orders, and build advertising audiences for our own campaigns on Google and Meta platforms
Legal basis Art. 6(1)(a) GDPR: your consent, collected via the marketing category of our cookie consent banner. Marketing cookies are only activated after you explicitly opt in.
Retention Cookies expire within 3 months; campaign statistics in Google Ads and Meta are aggregated and contain no directly identifying data

Google and Meta also process this data as independent controllers for their own purposes, such as ad delivery and measurement on their platforms, as described in their privacy policies (see section 3). If you do not enable the marketing category, none of this processing takes place.

3. Recipients and Data Processors

We share your personal data only with the third-party processors listed below, and only to the extent necessary for the purposes described in this policy.

We do not sell personal data. Outside the consent-based advertising measurement described in section 2(j), we do not share personal data with third parties for their marketing purposes.

Processor Role Data Received Data Location Transfer Mechanism
Hostinger International Ltd. Web hosting All data stored on our website and backend systems EU (Lithuania) No international transfer. Data stays within the EU/EEA
Stripe Payments Europe, Ltd. Payment processing Payment transaction data, billing details Ireland (EU); data may transfer to the US Standard Contractual Clauses (SCCs) and supplementary measures
Google Ireland Ltd. (Google Analytics) Website analytics Anonymized analytics data (see section 2d) Ireland (EU); data may transfer to the US EU-US Data Privacy Framework (adequacy decision)
Google Ireland Ltd. (Google Ads) Advertising conversion measurement Marketing cookie data and conversion events (see section 2j), only with your consent Ireland (EU); data may transfer to the US EU-US Data Privacy Framework (adequacy decision)
Meta Platforms Ireland Ltd. (Meta Pixel) Advertising measurement and audiences Marketing cookie data and conversion events (see section 2j), only with your consent Ireland (EU); data may transfer to the US EU-US Data Privacy Framework (adequacy decision)
Zoho Corporation (Titan Email) Email services Email correspondence (when you email us) EU data centers No international transfer. EU data centers used
Version2 profile app (app.version2.hr) Digital-profile setup (our own sub-system) Your name and email address, transferred as part of order fulfilment so we can issue your one-time profile setup link EU (Hostinger infrastructure) No international transfer. Operated by Version2 j.d.o.o. within the EU
OpenRouter, Inc. AI chatbot inference routing Chatbot conversation content (what you type into the chat) United States Standard Contractual Clauses (SCCs); conversations carry no required personal data

Our custom backend analytics system is built and hosted by Version2 j.d.o.o. on Hostinger infrastructure within the EU. No personal data from this system is shared with any third party.


4. International Data Transfers

Where your data is transferred outside the European Union or European Economic Area, we ensure that adequate safeguards are in place as required by Chapter V of the GDPR:

  • Stripe: Transfers to the United States are governed by Standard Contractual Clauses (SCCs) adopted by the European Commission, supplemented by additional technical and organizational measures.
  • Google Analytics: Transfers to the United States are covered by the EU-US Data Privacy Framework, for which the European Commission has issued an adequacy decision (July 10, 2023).
  • OpenRouter: Chatbot messages are processed in the United States under Standard Contractual Clauses (SCCs). The chat does not require you to enter personal data.
  • Google Ads and Meta: With your marketing consent, transfers to the United States are covered by the EU-US Data Privacy Framework (both providers are certified participants).

We do not transfer personal data to any country or organization unless an appropriate legal mechanism ensuring the protection of your data is in place.


5. Your Rights Under GDPR

Under the GDPR, you have the following rights regarding your personal data. You may exercise any of these rights free of charge by emailing us at office@version2.hr.

Right of Access (Art. 15)

You have the right to request confirmation of whether we process your personal data and, if so, to obtain a copy of that data along with information about how it is processed.

Right to Rectification (Art. 16)

If any personal data we hold about you is inaccurate or incomplete, you have the right to request its correction or completion.

Right to Erasure (Art. 17)

You have the right to request the deletion of your personal data ("right to be forgotten") where there is no compelling reason for its continued processing. This right applies, for example, when the data is no longer necessary for its original purpose or you withdraw your consent.

Right to Restriction of Processing (Art. 18)

You have the right to request that we limit how we process your data in certain circumstances, for example while we verify the accuracy of your data or assess whether our legitimate interests override your objection.

Right to Data Portability (Art. 20)

You have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance.

Right to Object (Art. 21)

You have the right to object to the processing of your personal data where we rely on legitimate interest as the legal basis. Upon receiving your objection, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Right to Lodge a Complaint

If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the supervisory authority:

Agencija za zaštitu osobnih podataka (AZOP) Selska cesta 136, 10000 Zagreb, Croatia Phone: +385 1 4609 000 Email: azop@azop.hr Website: www.azop.hr

How to Exercise Your Rights

Send your request to office@version2.hr. We may ask you to verify your identity before processing your request. We will respond within 30 days of receiving your request. If your request is particularly complex, we may extend this period by an additional 30 days (60 days total), in which case we will notify you of the extension and the reasons for it within the initial 30-day period.

There is no fee for exercising your rights unless requests are manifestly unfounded or excessive (in particular because of their repetitive character), in which case we may charge a reasonable fee or refuse to act on the request.


6. Automated Decision-Making and Profiling

Our AI chatbot provides automated responses to your questions about our services. However, it does not make decisions that produce legal effects concerning you or similarly significantly affect you.

We do not engage in automated profiling that produces legal effects or similarly significant effects on individuals.


7. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

Technical measures:

  • All data transmitted between your browser and our website is encrypted using HTTPS/TLS
  • Hosting infrastructure is secured with firewalls, intrusion detection, and regular security updates
  • Access to systems containing personal data is protected by strong authentication

Organizational measures:

  • Access to personal data is restricted to personnel who require it for their specific duties
  • All data processing is carried out in accordance with documented internal procedures

Data breach response:

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the Agencija za zaštitu osobnih podataka (AZOP) within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will inform you without undue delay.


8. Children's Privacy

Our website and services are not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If we become aware that we have inadvertently collected personal data from a child under 16, we will take immediate steps to delete that data. If you believe a child has provided us with personal information, please contact us at office@version2.hr.


9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing practices or applicable law. The "Last updated" date at the top of this page indicates when the policy was last revised.

Where changes are material, for example a new processing purpose, a new category of data collected, or a new data processor, we will provide a prominent notice on our website before the changes take effect.

We encourage you to review this page periodically to stay informed about how we protect your data.


10. Contact

If you have any questions about this Privacy Policy, about how we process your personal data, or if you wish to exercise any of your rights, please contact us:

Version2 j.d.o.o. za digitalni marketing Novigradska ulica 21, 23000 Zadar, Croatia


Related policies:

Write to us

Questions about this document?

A person from the studio will answer. The other documents in the set are here too.

Email
office@version2.hr
Phone
+385 99 561 7706

ContactWhatsApp