Privacy policy
2026-07-14
1. Data controller
The controller of personal data is Base 17, obrt za informatičke usluge, vl. Bernard Katičić, Otok, Skorotinci 1A, 32252 Otok, Croatia, OIB: 20890293794 (hereinafter: Base 17).
2. Privacy contact
For all questions regarding personal data processing and the exercise of your rights, contact us at office@base17.software or +385 99 574 5043.
3. Categories of personal data
Depending on how you interact with our website, we may process the following categories of data:
• Identity and contact data: full name, company or organisation name, email, phone
• Business enquiry content: process description, problem, desired outcome, timelines, and other information you voluntarily provide
• Technical data: IP address, browser type, operating system, date and time of access, referring URL
• Consent data: your choice regarding analytics technologies and the consent policy version
We do not collect special categories of personal data (such as health data) through this website.
4. Processing of contact enquiries
When you send an enquiry via the contact form or email, we process the data you provide to respond to your enquiry, assess the possibility of collaboration, and manage further communication. Enquiries are not stored in a database — they are delivered by email to office@base17.software.
5. Technical logs and security
The web server may automatically record technical access data to ensure security, prevent abuse, and diagnose technical issues. These logs are not used for user profiling.
6. Analytics
We use analytics technologies only with your explicit consent. Analytics tools are not activated before consent is given. Analytics helps us understand site usage and improve performance. For details on technologies used, see the Cookie policy.
7. Consent records
We store your choice regarding analytics technologies so we can respect your decision and request consent again if the purpose or set of tools changes materially.
8. Legal bases for processing
We process personal data on the basis of:
• Consent — for analytics technologies
• Legitimate interest — to respond to business enquiries, secure the website, and protect against abuse
• Pre-contractual measures — when you provide data for the purpose of assessing collaboration
The final legal basis for individual data categories is subject to legal review before publication.
9. Recipients and processors
Contact enquiry data is received internally only. Website technical infrastructure is provided by a hosting provider whose exact name will be documented at implementation. Analytics tools, if activated with your consent, may involve service providers whose list will be updated when configuration is finalised.
10. Transfers outside the EEA
If analytics or hosting providers process data outside the European Economic Area, we will ensure appropriate safeguards in accordance with applicable law. Details will be updated when configuration is finalised.
11. Retention periods
We retain contact enquiry data for as long as needed to process the enquiry and any potential collaboration. Technical logs are retained for the period required for security and diagnostics.
Exact retention periods for individual data categories require legal review before final publication. This policy will be updated when periods are approved.
12. Data subject rights
Under the General Data Protection Regulation (GDPR), you have the right to:
• Access your personal data
• Rectify inaccurate data
• Erasure (right to be forgotten)
• Restrict processing
• Data portability
• Object to processing
To exercise your rights, contact us at office@base17.software.
13. Withdrawal of consent
You may withdraw consent for analytics technologies at any time via cookie settings on the site or by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal.
14. Right to lodge a complaint
If you believe that processing of your personal data violates applicable law, you have the right to lodge a complaint with a supervisory authority. In Croatia, the competent authority is the Croatian Personal Data Protection Agency (AZOP), Martićeva 14, 10000 Zagreb, www.azop.hr.
15. Requirement to provide data
Data marked as required in the contact form is necessary to process your enquiry. Without it, we cannot respond. Data for analytics purposes is provided only with your consent and is not required to use the site.
16. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal effects or similarly significant effects on you.
17. Security measures
We apply appropriate technical and organisational measures to protect personal data, including security headers, input validation, rate limiting on the contact form, and abuse protection. Detailed measures are documented internally.
18. Policy changes
We may update this policy to reflect changes in data processing practices or applicable law. The last updated date is shown at the top of the page. For significant changes, we will notify you via the site or, where appropriate, direct communication.
19. Effective date
This privacy policy takes effect on 14 July 2026.
