Niro Digital

Legal

Privacy policy

What Niro Digital collects when you use this site, why, who processes it and what you can ask us to do.

Legal documents

Controller
Niro Digital d.o.o.
Last updated
7 September 2026
Governing law
Croatia
Registration
MBS 070207485 · OIB 14876333927 · Commercial Court in Varaždin
  1. 01

    Data controller

    The controller responsible for your personal data is:

    Niro Digital d.o.o., Ulica Ruđera Boškovića 9, 40315 Mursko Središće, Croatia · OIB 14876333927

    Email: info@nirodigital.com

  2. 02

    Introduction

    Niro Digital d.o.o. (we, us) runs this website. This policy explains what personal data we collect when you visit it, write to us through one of its two forms or work with us afterwards, why we collect it, who processes it on our behalf and what you can ask us to do with it. It describes what the site actually does: there is no newsletter, no account and no tracking beyond what is written here.

  3. 03

    What we collect

    We collect personal data only when you send it to us:

    What you give us

    1. //01Through the contact form: your name, your email address and the message you write
    2. //02Through the short form on the home page: your email address and one sentence about your constraint
    3. //03By email, phone or in a call, when you contact us directly
    4. //04During a project, the data needed to deliver the work agreed in the contract

    We do not collect anything you did not type, and the forms ask for nothing that is not needed to reply.

    What third parties collect on our behalf

    1. //01Resend delivers the two emails a form sends: the notification to our inbox and the confirmation to you. It processes your email address and the message content.
    2. //02Google reCAPTCHA v3 checks that a form submission comes from a person. It loads only when you start filling in a form and processes interaction signals, your IP address and a browser identifier.
    3. //03PostHog (EU cloud, Frankfurt) — product analytics, session replay, error reports and application logs. It runs in cookieless mode: it stores no identifier in your browser, and your IP address is hashed server-side into a daily anonymous id. Replays mask everything you type.

    We run no analytics and set no tracking cookies. The only automatic processing is what hosting requires:

    What is collected automatically

    1. //01Vercel, our hosting provider, keeps server logs with your IP address, browser and the pages requested, to keep the site secure and running
    2. //02Your language preference, stored as a cookie when you switch the site's language
    3. //03reCAPTCHA's signals as described above, only on pages where you open a form
    4. //04PostHog, in cookieless mode: the pages you view, clicks, performance timings, errors and a replay of the session with every input masked, tied to a daily hash of your request rather than to a cookie

    Server logs are kept by Vercel for a short period and are not used to profile visitors.

  4. 04

    Lawful basis

    Under the GDPR we process your personal data on these bases:

    1. //01Steps before a contract and performance of a contract (Article 6(1)(b)): replying to your enquiry and delivering the work you ask for.
    2. //02Legitimate interest (Article 6(1)(f)): keeping the site secure and free of spam, and keeping the records of a business relationship.
    3. //03Legal obligation (Article 6(1)(c)): keeping accounting records for as long as Croatian tax and company law require.
    4. //04Consent (Article 6(1)(a)): nothing on this site relies on consent today. If we ever add processing that does, we will ask first.
  5. 05

    How we use it

    We use your data to:

    1. //01Reply to your message and prepare the first call
    2. //02Deliver the work agreed with you and keep the related records
    3. //03Send the two transactional emails a form triggers; nothing else is sent
    4. //04Keep the website secure and free of spam
    5. //05Meet our accounting and legal obligations
  6. 06

    Processors

    These companies process personal data on our behalf, under data-processing agreements:

    Processor

    Purpose

    Location

    Resend

    Transactional email delivery for the two forms

    US

    Google reCAPTCHA

    Spam protection for the forms

    US

    Vercel

    Website hosting and server logs

    US

    PostHog

    Analytics, session replay, error tracking and logs (cookieless)

    EU

    A client's project data lives in accounts in the client's name. Where we host something for a client, it runs in EU regions under that project's own data-processing agreement.

  7. 07

    Cookies

    This site sets no analytics or advertising cookies and shows no cookie banner, because none is needed. Analytics run through PostHog in cookieless mode, which stores nothing in your browser; the only cookies are your language preference and reCAPTCHA's, on pages where you open a form.

    Cookie policy

  8. 08

    Security

    We protect your data with access controls, encrypted connections and two-factor authentication on the accounts that hold it, and we keep the number of people and systems that can see it small. No transmission over the internet is completely secure, so we cannot promise absolute security, but we will tell you if something goes wrong with your data.

  9. 09

    Transfers outside the EEA

    Resend, Google and Vercel are based in the United States. Where your data leaves the European Economic Area, the transfer relies on:

    1. //01The EU–US Data Privacy Framework, where the processor is certified under it
    2. //02Standard Contractual Clauses approved by the European Commission, in the processor's data-processing agreement
  10. 10

    Retention

    Enquiries we do not follow up are deleted within twelve months. Data from a business relationship is kept for the length of the relationship and then for as long as accounting law requires, currently eleven years in Croatia. Server logs are kept by Vercel for days, not months.

  11. 11

    Your rights

    Under the GDPR you can ask us to:

    1. //01Access the personal data we hold about you
    2. //02Have inaccurate data corrected
    3. //03Have your data deleted
    4. //04Restrict how we process it
    5. //05Object to processing based on legitimate interest
    6. //06Receive your data in a portable format
    7. //07Withdraw consent, where processing relies on it
    8. //08Complain to a supervisory authority

    Write to info@nirodigital.com to exercise any of these; we reply within 30 days. You can also complain to the Croatian Personal Data Protection Agency (AZOP) or the authority in your own country.

  12. 12

    Children

    This site and our services are for businesses. We do not knowingly collect data from anyone under 16; if you think we have, write to us and we will delete it.

  13. 13

    Changes

    When we change this policy we update the date at the top of the page. We do not notify visitors individually; the current version is always the one published here.

Start here

Tell us the constraint

Operations, workers or customers. One sentence is enough, we'll reply within one working day.

One more field on the next page, your name, and it's sent. No newsletter. A person replies.