Legal

Privacy Policy

Last updated: 14 August 2026

1. Who We Are

This website, indeloop.hr (the “Site”), is operated by:

INDELOOP d.o.o. za proizvodnju i razvoj
Kanalski put 1
10000 Zagreb, Croatia
OIB: 95862798984
MBS: 080740353
Email: info@indeloop.hr
Phone: +385 1 2481-300

INDELOOP d.o.o. za proizvodnju i razvoj (“Indeloop”, “we”, “us”) is the controller of the personal data processed as described in this Privacy Policy.

2. What This Policy Covers

This Privacy Policy explains how we collect, use, store, share and protect personal data when you visit our Site or interact with us through contact forms, newsletter subscriptions, email or other communication channels.

This Policy is intended to provide information in accordance with the EU General Data Protection Regulation (GDPR) and the Croatian Act on the Implementation of the General Data Protection Regulation.

3. Information We Collect

3.1 Information You Provide

Depending on how you interact with us, we may collect:

  • Contact forms — name, email address, company name (optional), topic and the content of your message.
  • Newsletter signup — email address.
  • Direct communications — information you choose to provide when contacting us by email or through other communication channels.

Please do not submit personal data that is not necessary for your inquiry.

3.2 Information Collected Automatically

When you visit the Site, certain technical information may be collected automatically:

  • Cookies — essential cookies used for language preferences, sessions and basic Site functionality. See Section 4.
  • Cookie consent log — when you interact with the cookie banner, we store a timestamp, your consent choice, language, a hashed IP address using HMAC-SHA256, and a partial user-agent string.
  • Server access logs — IP address, browser information and request time. These logs are retained for 30 days for security and technical purposes and are not used to track individuals.

4. Cookies

We use only essential cookies required for the operation and functionality of the Site.

We do not use Google Analytics, Facebook Pixel, LinkedIn Insight Tag or other analytics, advertising or behavioural tracking scripts.

The cookies used on the Site include:

  • indeloop_cookie_consent — remembers your choice on the cookie banner for 365 days.
  • pll_language — remembers your preferred language through Polylang.
  • PHPSESSID — server session cookie.
  • wpcf7_* — short-lived session cookies used for contact form protection.
  • wordpress_logged_in_* — used only for logged-in website administrators.

We do not use tracking, advertising or analytics cookies.

Information about your cookie choice is stored as described in Section 3.2.

5. How and Why We Use Personal Data

We process personal data only where we have an appropriate legal basis for doing so.

Contact Forms and Inquiries

We use information submitted through contact forms, email or other communication channels to respond to your inquiry and communicate with you.

Depending on the nature of your inquiry, the legal basis is:

  • our legitimate interest in conducting business communications and responding to inquiries; or
  • taking steps at your request before entering into a contract, where applicable.

Newsletter

If you subscribe to our newsletter, we use your email address to send Indeloop news, project updates, research and other relevant content.

The legal basis for this processing is your consent.

The newsletter is sent no more than once per quarter.

You may withdraw your consent at any time by using the unsubscribe option included in our emails.

Website and Server Security

Technical information and server logs may be processed to:

  • maintain the security and proper functioning of the Site;
  • prevent misuse, spam and malicious activity;
  • investigate technical problems; and
  • protect our systems and infrastructure.

The legal basis for this processing is our legitimate interest in maintaining a secure and functioning website.

Legal Obligations

Where necessary, we may process personal data to comply with obligations imposed by applicable law or lawful requests from competent authorities.

We do not use personal data for automated decision-making or profiling.

6. Sharing Personal Data With Third Parties

We do not sell, rent or trade personal data.

Personal data may be shared with service providers where this is necessary for them to provide services on our behalf, including:

  • email service providers — for newsletter delivery and business communications;
  • web hosting providers — for hosting, storage and technical operation of the Site;
  • technical service providers — where access is necessary for website maintenance, security or related technical services; and
  • competent authorities — where disclosure is required by applicable law, court order or other legally binding request.

Where third-party service providers process personal data on our behalf, appropriate contractual and data protection arrangements are used where required by applicable law.

We only provide service providers with access to personal data to the extent necessary for the relevant service.

7. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected or where retention is required by applicable law.

Our standard retention periods are:

  • Contact form submissions — 12 months after the inquiry has been resolved.
  • Newsletter subscriptions — until you unsubscribe or otherwise withdraw your consent.
  • Cookie consent log — the most recent 500 entries are retained, with older entries automatically removed.
  • Server access logs — 30 days.

Certain information may be retained for a longer period where necessary to establish, exercise or defend legal claims or to comply with applicable legal obligations.

8. Your Rights Under the GDPR

Subject to the conditions set out in applicable data protection law, you may have the right to:

  • Access — request confirmation of whether we process your personal data and obtain a copy of that data.
  • Rectification — request correction of inaccurate or incomplete personal data.
  • Erasure — request deletion of personal data where the applicable legal conditions are met.
  • Restriction of processing — request that the processing of your personal data be restricted in certain circumstances.
  • Data portability — receive certain personal data in a structured, commonly used and machine-readable format where applicable.
  • Object to processing — object to processing based on legitimate interests in circumstances provided by law.
  • Withdraw consent — withdraw your consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
  • Lodge a complaint — submit a complaint to the competent supervisory authority.

In Croatia, the competent supervisory authority is the Croatian Personal Data Protection Agency (Agencija za zaštitu osobnih podataka — AZOP).

To exercise your rights, contact us at info@indeloop.hr with the subject line “Privacy request”.

We will respond to your request without undue delay and, in any event, within one month, unless a longer period is permitted under applicable law due to the complexity or number of requests.

9. Security

We take appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, loss or destruction.

TLS (HTTPS) encryption is used for data transmitted through the Site. Server-side data is protected through access controls and regular security updates.

Although we take reasonable measures to protect personal data, no method of transmission or electronic storage can be guaranteed to be completely secure.

10. Children’s Privacy

Our Site is not directed at children under the age of 16.

We do not knowingly collect personal data from children. If you believe that a child has provided personal data to us, please contact us at info@indeloop.hr so that we can review and, where appropriate, remove the information.

11. International Data Transfers

Personal data processed through the Site is stored within the European Economic Area (EEA).

If we introduce a service in the future that requires personal data to be transferred outside the EEA, such transfers will only take place where an appropriate transfer mechanism or safeguard is available in accordance with applicable data protection law, such as an adequacy decision or Standard Contractual Clauses.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to the Site, our data processing activities, the services we use or applicable legal requirements.

The current version of this Policy and the date of the latest update will always be available on this page.

We recommend reviewing this Privacy Policy periodically.

13. Contact

If you have any questions about this Privacy Policy or the way we process personal data, or if you wish to exercise your data protection rights, please contact:

INDELOOP d.o.o. za proizvodnju i razvoj
Data Privacy
Kanalski put 1
10000 Zagreb
Croatia

OIB: 95862798984
MBS: 080740353
Email: info@indeloop.hr
Phone: +385 1 2481-300