Skip to content
TsunamiDigital

Privacy notice

This notice explains which personal data Tsunami Digital d.o.o. collects, why it processes them, how long it keeps them and which rights you have. It has been written in accordance with the General Data Protection Regulation (GDPR) and the Zakon o provedbi Opće uredbe o zaštiti podataka (Act on the Implementation of the GDPR). This is an English translation for convenience; the Croatian version at /privatnost/ prevails in case of any discrepancy.

1. Controller

Tsunami Digital društvo s ograničenom odgovornošću za informatičke usluge
Bolnička cesta 34K, 10000 Zagreb
OIB (personal identification number): 88115518559
MBS (court registration number): 081711791, Trgovački sud u Zagrebu (Commercial Court in Zagreb)
E-mail: [email protected]
Other company details: Imprint

We have not appointed a data protection officer because one is not required for our size and type of processing. For any questions about personal data, please write to the e-mail address above.

2. Which data we process and where we obtain them

2.1. Enquiries via the website and e-mail

When you send us a message via the contact form or by e-mail, we process the data you provide to us yourself: your name, e-mail address, telephone number if you provide it, and the content of the message. Your name, e-mail address and message are needed so that we can reply to you; the telephone number is optional.

2.2. Business contacts from the Sudski registar (Court Register)

We occasionally send a business offer by e-mail to companies and other legal persons entered in the Sudski registar (Court Register) of the Republic of Croatia. For this we use only the data that the Court Register has published through its open data service (sudreg.pravosudje.hr): the company name and short name, OIB, registered seat, legal form, main activity, date of incorporation and the e-mail address the company has filed with the register.

We do not obtain these data from you personally but from a public register. We therefore inform you of this processing at the latest in the first message we send you, as required by Article 14 of the GDPR.

Data from the register as a rule relate to a legal person, not to an individual. If an individual can nevertheless be identified through the e-mail address (for example where the owner's personal address is entered in the register), that address is considered personal data and this notice applies to it in full.

2.3. Message sending data

For each message sent we record the recipient, the date and time of sending, and technical delivery feedback (whether the message was delivered, rejected or reported as unsolicited). We need these data so that we do not send messages to those who do not want them and so that the sending system works properly.

2.4. Visiting the website

The website does not use analytics or advertising tools. On each visit, the hosting provider technically processes the IP address, browser type, requested page and time, in order to deliver the website and protect it from attacks.

3. Purposes and legal bases of processing

Purpose Data Legal basis
Replying to your enquiry and preparing an offer Enquiry data (2.1.) Steps taken at your request prior to entering into a contract, Article 6(1)(b) GDPR
Business offer to companies by e-mail Data from the Court Register (2.2.) Legitimate interest, Article 6(1)(f) GDPR: presenting our services to business entities whose contact details have been published precisely for the purpose of business contact. Sending to legal persons is also permitted by Article 50(4) of the Zakon o elektroničkim komunikacijama (Electronic Communications Act).
Honouring unsubscribes and objections E-mail address and OIB of the company that unsubscribed Legal obligation, Article 6(1)(c) in conjunction with Article 21 GDPR
Proper operation and security of the sending system Sending data (2.3.) Legitimate interest, Article 6(1)(f) GDPR
Delivering the website and protecting it from attacks Technical visit data (2.4.) Legitimate interest, Article 6(1)(f) GDPR: network and information security

Where we rely on legitimate interest, we always weigh our interest against your rights. For the business offer we have carried out this assessment in writing. In short: we write only to legal persons, not to sole traders, and only to the address the company itself published in the Court Register precisely for the purpose of business contact. We send rarely, one message per company per sending round, with no reminders and no click tracking, we clearly label it as an offer, we do not build profiles of individuals and we do not combine the data with other sources. Every message has one-click unsubscribe, and the unsubscribe applies permanently to the entire company. We will gladly send you the assessment on request.

4. Who else has access to the data

We do not sell the data or pass them on to third parties for their own purposes. They are processed on our behalf and according to our instructions by the following processors:

  • Amazon Web Services EMEA SARL: the Amazon SES service (Europe region, Paris) for sending e-mail and receiving delivery feedback, and the server and database of the business offer system (Europe region, Frankfurt).
  • Web3Creative (Web3Forms service), India, for forwarding messages from the contact form to our e-mail. It stores messages on servers in multiple regions and checks the IP address and e-mail address with anti-spam services.
  • Cloudflare, Inc., USA, for website hosting and protection from attacks.
  • Zoho Corporation B.V. (Zoho Mail, data centre in the EU) for our business e-mail, which receives enquiries and replies to messages.
  • Better Stack, Inc., USA, for technical availability monitoring and error diagnostics. We remove or mask personal data from technical logs before they are sent.

Data are transferred outside the European Economic Area in three cases: Web3Forms (India and other regions) on the basis of the European Commission's standard contractual clauses, and Cloudflare and Better Stack (USA) on the basis of the EU-U.S. Data Privacy Framework. All other processing takes place within the European Economic Area.

We may disclose data to the competent authorities when required to do so by law or by a court decision.

5. How long we keep the data

  • Enquiries: for as long as the communication lasts and for at most 12 months after the last message, unless the enquiry results in a contract. In that case we keep them for the duration of the business relationship and the statutory retention periods for business records. We regularly delete the copy of the contact form message held by the Web3Forms service, at the latest after 12 months.
  • Data from the Court Register: we refresh them from the register once a month. Companies that are no longer entered in the register are deleted from our records at the next refresh.
  • Sending data: at most 12 months from sending.
  • Unsubscribe records: permanently, because this is the only way to ensure we do not send you a message again. We keep only the e-mail address and OIB, with no other data.

6. Your rights

Under the GDPR you have the right:

  • of access to the data we process about you and to a copy of them,
  • to rectification of inaccurate data and completion of incomplete data,
  • to erasure of data when there is no longer a reason to process them,
  • to restriction of processing while your objection or request is being resolved,
  • to portability of the data you have provided to us yourself,
  • to lodge a complaint with a supervisory authority: the Agencija za zaštitu osobnih podataka (Croatian Data Protection Authority, AZOP), Zagreb, [email protected], azop.hr. We would prefer that you contact us directly first, so that we can resolve the problem right away.

Right to object and unsubscribe

You may at any time object to the processing of your data for the purpose of a business offer, without giving reasons. After an objection we will no longer send you messages. The simplest way is to click the unsubscribe link at the bottom of any of our messages, but you can also reply to the message or write to us at [email protected].

We respond to requests without undue delay and at the latest within one month. Before responding, we may ask you to confirm your identity so that we do not disclose data to the wrong person.

7. Cookies

The website does not set cookies and does not use tracking, analytics or advertising tools. Your choice of light or dark theme is stored in your browser's local storage, and a few technical flags for page animations in session storage, which is cleared when the browser is closed. None of this is sent to anyone.

8. Changes to this notice

We will amend this notice when the way we process data changes. The date of the last change is stated at the top of the page. The version published at this address applies.