Legal
Privacy policy
How Strateven collects, uses, and protects personal data through this website, and the rights you have under the GDPR.
1.Controller
The controller of personal data processed through this website is:
- Controller
- [ TO BE COMPLETED — registered company name ]
- Address
- [ TO BE COMPLETED — registered address ]
- OIB
- [ TO BE COMPLETED — OIB ]
- Data protection contact
- info@strateven.com
We have not appointed a Data Protection Officer. Our processing does not meet the criteria in Article 37 GDPR that would require one. Data protection enquiries go to the address above.
2.Scope
This policy covers personal data we process through www.strateven.com. It does not cover data processed under a signed client engagement, which is governed by that engagement agreement and any accompanying data processing agreement.
3.What we process and why
We process personal data only where we have a lawful basis under Article 6 GDPR. We do not process special categories of data through this website.
Contact form enquiries
Data: your name, role, organisation, email address, stated area of interest, and whatever you write in the message field.
Purpose: to read, assess, and respond to your enquiry, and to take steps at your request before entering into a possible engagement.
Legal basis: Article 6(1)(b) GDPR, steps taken at your request prior to entering into a contract; and, where you write to us on behalf of an organisation rather than in your own right, Article 6(1)(f) GDPR, our legitimate interest in responding to business enquiries addressed to us.
Provision: giving us this data is voluntary, but we cannot answer an enquiry without at least a name, an email address, and enough context to respond usefully.
Retention: 24 months from our last contact with you, after which the enquiry is deleted, unless it has become part of a client file or we are required to keep it for longer.
Email correspondence
Data: your email address, the content of your messages, and the associated message metadata.
Purpose and basis: as above, to correspond with you about your enquiry or engagement.
Server and delivery logs
Data: IP address, date and time of request, page requested, referrer, browser and operating system identifiers.
Purpose: to deliver the site, keep it secure, and diagnose faults and abuse. These logs are generated automatically by our hosting provider and are not used to profile visitors or to build any record connected to an identified person.
Legal basis: Article 6(1)(f) GDPR, our legitimate interest in the secure and reliable operation of the site.
Retention: for the short period applied by our hosting provider, after which logs are deleted or aggregated.
4.No tracking
This website sets no cookies and runs no analytics. There is no advertising technology, no tracking pixel, no social media embed, no session recording, and no profiling of visitors. Typefaces are served from our own domain, so loading this site discloses nothing to a font provider or any other third party.
That is also why you were not shown a cookie banner: there is nothing to consent to. See the Cookie Policy for detail.
5.Who else processes your data
We keep the number of processors deliberately small. Each acts on our documented instructions under a data processing agreement satisfying Article 28 GDPR.
- Netlify, Inc. (United States) — hosting of this website and processing of contact form submissions. Receives your form data and technical connection data.
- Microsoft Corporation — our business email, through which enquiries reach us and correspondence is held.
We do not sell personal data, and we do not share it with third parties for their own marketing. We may disclose data where we are legally required to, or to establish, exercise, or defend legal claims.
6.Transfers outside the EEA
Some of the processors above are established in the United States, so your data may be transferred outside the European Economic Area. Where that happens, the transfer is made under Article 46 GDPR safeguards — the European Commission’s Standard Contractual Clauses incorporated into our agreement with the processor, or the processor’s certification under the EU–U.S. Data Privacy Framework where that applies.
You can request a copy of the relevant safeguards by writing to info@strateven.com.
7.Retention
We keep personal data only as long as needed for the purpose it was collected for, or as long as a legal obligation requires. Contact enquiries are kept for 24 months from our last contact with you. Where data has become part of a client engagement record, it is retained under the retention terms of that engagement and applicable accounting and statutory limitation periods.
8.Security
This site is served exclusively over HTTPS with a valid TLS certificate. Form submissions are transmitted encrypted and stored in access-controlled systems. Access to enquiry data within Strateven is limited to those who need it to respond.
No system is perfectly secure. If a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will notify AZOP within 72 hours as required by Article 33 GDPR, and will notify you directly where Article 34 requires it.
9.Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy (Article 15).
- Rectification of inaccurate or incomplete data (Article 16).
- Erasure of your data where the grounds in Article 17 apply.
- Restriction of processing in the circumstances set out in Article 18.
- Portability — to receive data you provided in a structured, commonly used, machine-readable format, and to have it transmitted to another controller (Article 20).
- Object to processing based on our legitimate interests, on grounds relating to your particular situation (Article 21). Where you object, we stop unless we can show compelling legitimate grounds that override your interests.
- Withdraw consent at any time, where processing rests on consent. Withdrawal does not affect the lawfulness of processing before it.
To exercise any of these, write to info@strateven.com. We respond within one month of receiving your request, extendable by two further months for complex requests, in which case we will tell you within the first month. Exercising these rights is free; we may charge a reasonable fee or refuse only where a request is manifestly unfounded or excessive. We may ask you to confirm your identity before we act.
10.Complaints
If you believe we have handled your personal data unlawfully, please raise it with us first — we would rather fix it directly. You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work, or the place of the alleged infringement.
The Croatian supervisory authority is:
- Authority
- Agencija za zaštitu osobnih podataka (AZOP)
- Address
- Ulica Metela Ožegovića 16, 10000 Zagreb, Croatia
- azop@azop.hr
- Telephone
- +385 (0)1 4609-000
- Web
- azop.hr
11.Children
This website is aimed at business and professional users. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, contact us and we will delete it.
12.Changes
We may update this policy as our processing or the law changes. The date at the top of this page shows when it was last revised. Where a change materially affects how we handle your data, we will take reasonable steps to bring it to your attention.