Information submitted through forms
When you send an enquiry or request a quote, we collect your name, business email address, telephone number, domain name, and project specifications necessary to deliver technical estimates.
This comprehensive policy details how IzradaSajtovaPro collects, processes, stores, and safeguards personal and technical data across our website, web development projects, and digital marketing activities in full compliance with global standards.
The data collected depends on how you interact with our web ecosystem. It encompasses submitted contact form details, diagnostic server logs, and measurement cookies needed to deliver performance and bulletproof security.
When you send an enquiry or request a quote, we collect your name, business email address, telephone number, domain name, and project specifications necessary to deliver technical estimates.
Automated server logs record IP addresses, user-agent strings, request headers, geographic locations, and firewall security alerts to guarantee website uptime and block malicious traffic patterns.
If consent is granted, performance measurement and advertising pixel tools process anonymized interaction metrics to help us refine campaign efficiency and user interface responsiveness.
This policy reflects our actual, live data-processing architecture. If new tracking software, custom API integrations, or CRM tools are implemented, this policy is updated immediately to remain completely accurate and compliant.
We process personal data strictly under valid legal bases: executing contractual agreements, fulfilling legal obligations, and pursuing legitimate interests in securing enterprise infrastructure.
Form inputs are processed strictly to formulate project proposals, deliver website development services, manage server setups, and maintain active commercial client relationships.
Inquiry records are retained for a maximum of 24 months unless an active client contract mandates longer statutory storage for accounting, domain administration, and web maintenance logs.
Data is transferred only to trusted cloud providers (e.g., cPanel hosting nodes, encrypted SMTP gateways, DNS providers) operating under strict data processing agreements (DPAs).
Navigating modern internet compliance requires complete transparency, legal compliance with international privacy laws, and robust technical infrastructure.
In an era defined by rapid digital transformation, data privacy is not merely a legal obligation—it is a cornerstone of corporate trust. Modern business websites, e-commerce stores, and custom software platforms collect multi-layered interaction data every second. At IzradaSajtovaPro, we design digital infrastructure with privacy engineered into the codebase from day one. This documentation serves as a comprehensive disclosure of how data moves through our network, from initial browser requests to secure server execution.
The primary objective of this Privacy Policy is to inform users, clients, prospective leads, and web visitors about how personal data is collected, stored, processed, and safeguarded. This policy applies to all domain names, subdomains, web applications, landing pages, and digital marketing channels controlled by IzradaSajtovaPro. Whether you visit our website to explore web design packages, request an technical SEO audit, or submit project requirements, your data privacy is handled under uniform EU General Data Protection Regulation (GDPR) standards and global privacy principles.
Understanding exactly what information is gathered allows users to exercise total control over their personal footprint.
When you fill out a quote request or contact form on our website, we process the specific details you submit. This typically includes your full name, business or corporate entity name, official email address, primary phone number, target domain URL, estimated budget, and written brief. This information is classified as direct identification data and is utilized exclusively to assess project technical scope and formulate custom proposals.
Every time a web browser initiates an HTTP/HTTPS connection to our web servers, dynamic telemetry data is captured automatically in web server logs (such as Nginx or Apache access logs). This technical telemetry includes your public IPv4/IPv6 address, request timestamp, HTTP status code, referrer URL, browser family and version, operating system, device screen resolution, and TCP connection parameters. This data is critical for system health, load balancing, and preventing DDoS attacks.
For clients engaging our team for custom website engineering, WordPress development, or server migration, additional operational data is handled. This includes CMS access keys, hosting control panel credentials, SSL certificates, brand graphics, product catalogs, database dumps, and API tokens. All client assets provided during development are kept under strict confidentiality protocols and encrypted storage environments.
How persistent client-side storage mechanisms work across web sessions to optimize experience and campaign performance.
Essential cookies are required for the basic functionality of the platform. These session-based and persistent HTTP cookies enable key navigation features, form security tokens (such as CSRF protection), language preferences (SR, EN, DE, FR, IT, ES, RU, etc.), and consent state retention. Because the website cannot function correctly without these essential cookies, they are active upon visiting the site.
We utilize privacy-conscious web measurement tools, such as Google Analytics 4 (GA4), to evaluate how visitors interact with our content. Analytical cookies track page duration, bounce rate, navigation pathways, scroll depth, and mobile user interaction patterns. We implement IP anonymization and disable ad personalization sharing within GA4 configurations to ensure compliance with privacy-first analytics mandates.
To measure the conversion efficiency of our digital advertising campaigns across platforms like Google Ads and Meta (Facebook/Instagram), we deploy tracking scripts, Meta Pixels, and Server-Side Conversions APIs (CAPI). These tools allow us to measure ad interactions and present tailored services to users who have expressed interest in web design or SEO solutions, provided explicit cookie consent has been granted.
Our operations rely on explicit statutory authorizations under Article 6 of the EU General Data Protection Regulation (GDPR).
Processing client-submitted contact details, billing data, and server specifications is strictly necessary to prepare contracts, issue official pro-forma invoices, establish cloud hosting spaces, manage domain transfers, and deploy web code. Without processing this information, providing professional agency web development services would be technically impossible.
We process network diagnostic logs and firewall entry telemetry under the legal basis of legitimate interest (GDPR Art. 6(1)(f)). This ensures our infrastructure remains resilient against malicious brute-force attacks, SQL injection attempts, spam abuse, and automated scrapers. Maintaining high website availability serves both our agency and our website visitors.
Non-essential tracking scripts, commercial newsletters, remarketing pixels, and targeted ad cookies are executed only after a user provides explicit, informed consent via our Cookie Banner setup. Consent can be updated, granularly adjusted, or fully revoked at any time through our privacy preference options without affecting basic site access.
Data is stored only as long as necessary for business, contractual, or statutory accounting purposes.
General lead inquiries submitted via our online form that do not convert into active client contracts are retained in our secure email archives for a period of up to 24 months. This allows our business development team to handle follow-up communication if requested by the client. After this window, lead records are systematically purged.
For active website engineering clients, backup archives, custom code databases, and configuration backups are retained throughout the active lifecycle of the maintenance agreement. Automated rolling database snapshots are retained for 30 to 90 days on encrypted external storage servers to support emergency system restoration if needed.
Upon reaching the expiration of statutory retention windows—or upon receipt of a valid Data Subject Erasure Request—all digital files, database records, and contact cards undergo cryptographically secure deletion routines. Server diagnostic logs are automatically overwritten in continuous 30-day log rotation loops.
We work exclusively with trusted global cloud infrastructure, analytics, and messaging vendors.
Our website and client applications rely on tier-4 datacenter cloud infrastructure (such as Hetzner, Cloudflare, and dedicated cPanel environments). Data routing through these networks is encrypted in transit via TLS 1.3 standards. Cloudflare processes IP addresses at the edge to mitigate malicious bot traffic and perform DDoS mitigation.
We leverage Google Tag Manager (GTM) and Google Analytics 4 (GA4) to evaluate website usage patterns. These platforms process pseudonymous client identifiers, device profiles, and interaction events. Google operates under Standard Contractual Clauses (SCCs) to ensure safe data processing standards across international borders.
For campaign attribution, user conversion events (e.g., submitting a contact form) may be sent to Meta Ads or Google Ads via server-to-server Conversions API (CAPI). Personal parameters like email addresses are cryptographically hashed using SHA-256 algorithms prior to transmission, rendering them unreadable to unauthorized external entities.
You maintain complete control over your personal data under global privacy statutes.
You have the legal right to request formal confirmation as to whether your personal data is being processed by IzradaSajtovaPro. Upon request, we will provide a complete copy of your personal data in a structured, machine-readable format (JSON or CSV). If any recorded data is inaccurate, you may demand immediate rectification.
Under GDPR Article 17, you have the right to request the complete deletion of your personal records from our databases. If you object to data processing conducted on legitimate interest grounds—such as direct B2B communication—we will immediately cease processing your data unless compelling statutory grounds apply.
To exercise any of your statutory privacy rights, please submit a written request to our Data Protection Team via email at info@izradasajtovapro.com. We verify the identity of all requestors to prevent unauthorized exposure and fulfill valid requests within 30 calendar days without administrative fees.
How we protect data against unauthorized interception, unauthorized access, and cyber threats.
All HTTP communication across IzradaSajtovaPro is enforced via HTTPS utilizing 256-bit Transport Layer Security (TLS 1.3) encryption. This cryptographic tunnel prevents eavesdropping, packet sniffing, and man-in-the-middle (MITM) attacks during data transit between your web browser and our servers.
Our server infrastructure employs strict principle of least privilege (PoLP) access controls. Database servers storing client interaction records are insulated behind virtual private networks (VPNs) and web application firewalls (WAF). Administrative login attempts require multi-factor authentication (MFA) and generate real-time security logs.
How we build fully compliant, privacy-first business websites and online web applications for our clients.
When engineering client websites—whether on WordPress, custom PHP, or web application frameworks—we integrate Privacy by Design (PbD) principles. This includes configuring form endpoints to avoid collecting unnecessary client details, sanitizing database inputs, setting up security headers (Content Security Policy, X-Frame-Options), and ensuring SSL certificates auto-renew.
We configure Consent Management Platforms (CMPs) on client websites to block third-party analytics and ad pixel scripts from executing prior to explicit user approval. Our implementations support Google Consent Mode v2, enabling businesses to measure conversions accurately while remaining fully compliant with EU ePrivacy directives.
Email info@izradasajtovapro.com with your name and primary email address. Our team will identify your data records and process your access, correction, or deletion request within 30 days in full accordance with GDPR standards.
Essential technical infrastructure partners—including specialized web hosting providers, domain registries, SSL vendors, and secure email server networks—process data strictly to operate our online infrastructure under signed Data Processing Agreements.
Whenever new analytics tools, custom plugins, software integrations, or advertising technologies are introduced, we perform a legal risk audit and update this policy to reflect exact live data flows.
No. IzradaSajtovaPro strictly refrains from selling, renting, licensing, or commercializing personal client or web visitor data to data brokers or third-party advertisers under any circumstances.
We integrate privacy-by-design standards into every site we build—implementing Consent Management Platforms (CMP), Google Consent Mode v2, HTTPS SSL encryption, automated log management, and custom Privacy Policy page templates.
No. Server access and error logs are stored in secure rolling log buffer cycles for a maximum of 30 days to facilitate firewall analysis and system integrity verification before being automatically overwritten.
Contact us if you would like clarification about this policy or want to make a request concerning your data.