← Back

Legal

Privacy Policy

Last updated: 4 August 2026

This Privacy Policy explains what personal data we collect through cerno.agency and related communication, for what purposes, on what legal basis, and what rights you have. It is drawn up in accordance with Regulation (EU) 2016/679 (GDPR) and the Croatian Act on the Implementation of the General Data Protection Regulation.

This English version is provided for convenience. In the event of any discrepancy, the Croatian version of this policy prevails.

1. Data controller

Controller
CERNO LABS, obrt za marketing i računalno programiranje, vl. Marko Filipović
Donjozelinska ulica 16, 10380 Donja Zelina, Republic of Croatia
OIB: 22778960778
Email: [email protected]

The controller has not appointed a data protection officer, as there is no legal obligation to do so. For any data protection questions, please write to the email address above.

2. What data we collect

a) Data you provide to us

When you contact us by email or through links on the site, we process the data you send us: your name, email address, phone number, company or business name, and the content of your message.

The fit-check form is only sent when you submit it yourself. At that point we receive your answers to the four questions together with your first name, email address and, if you entered them, your last name and company. If you then book a slot, we also record the date, time and time zone you chose. Until you press submit, your answers stay in your browser only.

b) Technical data

When you visit the site, our hosting provider automatically records standard server logs: IP address, date and time of access, browser type, and pages visited. This data is used solely for security, abuse detection, and the correct operation of the site.

c) Cookies and similar technologies

We use cookies that are not strictly necessary (statistical and marketing) only with your consent. Details are described in our Cookie Policy.

3. Purposes and legal bases

  • Responding to enquiries and preparing quotes — steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR).
  • Performing agreed work and business communication — performance of a contract (Art. 6(1)(b)).
  • Invoicing and keeping business records— compliance with the controller's legal obligations (Art. 6(1)(c)).
  • Security and correct operation of the site (server logs) — legitimate interest (Art. 6(1)(f)).
  • Statistical and marketing cookies — consent (Art. 6(1)(a)), which you may withdraw at any time.

4. Recipients of data

We do not sell your data or pass it to third parties for marketing purposes. Your data may be processed by trusted service providers performing technical work on our behalf (processors): our hosting and domain provider, our email provider, and — only if you give consent via cookies — providers of analytics and advertising tools (e.g. Meta Platforms Ireland Ltd., Google Ireland Ltd.). Appropriate data processing agreements are in place with all processors.

Data may be disclosed to competent authorities where required by law.

5. Transfers to third countries

If you use the site with marketing or statistical cookies enabled, part of the processing may be carried out by companies established outside the European Economic Area (e.g. in the USA). Such transfers are based on an adequacy decision (EU–U.S. Data Privacy Framework) or the European Commission's standard contractual clauses.

6. Retention periods

  • Enquiries that do not lead to an engagement — up to 2 years from the last communication, after which they are deleted.
  • Contract documentation and correspondence — for the duration of the engagement and within the statutory limitation periods.
  • Invoices and accounting records — for the periods prescribed by tax and accounting regulations (at least 11 years).
  • Cookies — as set out in the Cookie Policy.

7. Your rights

In relation to your personal data, you have the right to:

  • access your data and information about the processing,
  • rectification of inaccurate or completion of incomplete data,
  • erasure (the “right to be forgotten”), where the conditions are met,
  • restriction of processing,
  • data portability,
  • object to processing based on legitimate interest,
  • withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.

You may exercise these rights by sending a request to [email protected]. We respond without undue delay and no later than 30 days.

If you believe your data is being processed unlawfully, you have the right to lodge a complaint with the supervisory authority: Croatian Personal Data Protection Agency (AZOP), Zagreb, www.azop.hr.

8. Data security

We apply technical and organisational measures appropriate to the risk: an encrypted connection (HTTPS), restricted access to data, and regular updates to the systems we use.

9. Automated decision-making

We do not carry out automated decision-making or profiling that would produce legal effects concerning you.

10. Children

The site and our services are intended for business users and persons over 16 years of age. We do not knowingly collect children's data.

11. Changes to this policy

We may amend this policy from time to time; the version published on this page, with the stated date of last change, is the one in force.