Privacy Policy
This Privacy Policy establishes the legal and organizational framework governing the collection, processing, storage, and protection of personal data by the operator of this website (“the Operator”). The Operator conducts all processing activities in accordance with the requirements of Regulation (EU) 2016/679 (“GDPR”), the Telemedia Act (TMG), and other applicable data protection laws within the European Economic Area.
Given that the website may be accessed by individuals located outside the European Union, including but not limited to the United States, Canada, the United Kingdom, Switzerland, countries in the Asia-Pacific region (such as Singapore, Japan, South Korea, Hong Kong, and Australia), the Middle East, Latin America, and Africa, this Privacy Policy is intended to provide a comprehensive explanation of dataprocessing practices applicable to all users regardless of their jurisdiction.
While GDPR constitutes the primary regulatory framework governing the Operator’s processing activities, the Operator acknowledges that users from non-EU jurisdictions may be subject to additional or different privacy regimes, including the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), the Personal Information Protection and Electronic Documents Act (PIPEDA), the UK Data Protection Act 2018, the Singapore Personal Data Protection Act (PDPA), the Japanese Act on the Protection of Personal Information (APPI), and other regional or national privacy laws.
The Operator does not actively target or direct its services toward any specific non-EU jurisdiction; however, the Operator recognizes that international users may interact with the website and therefore provides this Privacy Policy to ensure transparency, legal clarity, and a uniform standard of protection for all data subjects, irrespective of geographic location.
In cases where local privacy laws impose additional obligations or grant additional rights to users, the Operator will, to the extent legally required and technically feasible, respect such rights and obligations. Where there is a conflict between GDPR and another applicable privacy regime, the Operator will apply the standard that affords the highest level of protection to the data subject, unless otherwise mandated by binding legal requirements.
1. Identity of the Controller and Hosting Information
The Operator acts as the controller within the meaning of Article 4(7) GDPR. The website is hosted by Zomro.com, a hosting provider responsible for server infrastructure, uptime, and technical availability. Domain registration and all related payments are carried out by a private individual who administers the domain and ensures its operational continuity. The Operator retains full control over the configuration of the hosting environment and the processing of personal data within this environment.
2. Scope and Purpose of Data Processing
The Operator processes personal data exclusively for the purpose of enabling communication with users who voluntarily submit their contact information through the website’s contact forms or other interactive elements. The processing is limited to data necessary to respond to inquiries, provide requested information, or maintain correspondence initiated by the user. No additional purposes, such as marketing, profiling, behavioral analysis, or automated decision-making, are pursued. The Operator does not enrich collected data with external sources and does not engage in any form of cross-context tracking.
3. Categories of Personal Data Processed
The Operator may process the following categories of personal data: identification data voluntarily submitted by the user (such as name and email address), communication content provided through contact forms, and technical data automatically generated by the user’s browser during website access. Technical data may include IP address, timestamp, device type, and browser version, insofar as such data are technically necessary for the secure and stable operation of the website. No sensitive data within the meaning of Article 9 GDPR are collected or processed.
4. Legal Basis for Processing
The processing of personal data is carried out on the basis of Article 6(1)(a) GDPR, namely the explicit consent provided by the user when submitting information through the website. Technical data necessary for the functioning of the website are processed under Article 6(1)(f) GDPR, as the Operator has a legitimate interest in ensuring the security, stability, and proper functioning of the website. The Operator does not rely on Article 6(1)(b) GDPR, as no contractual relationship is formed through the mere use of the website.
5. Use of Analytics Tools
For statistical analysis of website usage, the Operator employs Yandex Metrica. This service collects anonymized statistical data, including aggregated information about page views, session duration, navigation paths, and user interactions. The data processed by Yandex Metrica do not contain personally identifiable information and cannot be used to identify individual users. The Operator does not combine analytics data with any other datasets and does not use analytics for behavioral profiling. The processing performed by Yandex Metrica serves solely to improve website performance, usability, and content relevance.
6. Data Storage and Technical Infrastructure
Personal data submitted through contact forms are stored within Bitrix24, a cloud-based CRM and communication platform. Bitrix24 ensures encrypted data storage, controlled access, and compliance with GDPR requirements. The Operator has implemented technical and organizational measures to prevent unauthorized access, alteration, or disclosure of personal data. These measures include encrypted communication channels, access-control systems, secure authentication procedures, and regular audits of system integrity. Data are stored exclusively within the Bitrix24 environment and are not transferred to any other storage systems.
7. Absence of Data Transfer to Third Parties
The Operator does not transfer personal data to third parties, partners, advertisers, or external service providers. No personal data or analytics data are disclosed, sold, exchanged, or otherwise made available to any external entity. The Operator does not engage in cross-border data transfers outside the European Economic Area. All processing activities remain strictly internal and are limited to the systems directly controlled by the Operator.
8. Retention Periods
Personal data are retained only for the duration necessary to achieve the purposes for which they were collected. Once communication with the user has been completed and no further legitimate interest exists, the data are deleted or anonymized. Technical data processed for security and operational purposes are retained only for the period required to ensure system stability and detect potential security incidents. The Operator does not retain personal data beyond the legally permissible period and does not create long-term archives of user communications.
9. Rights of the Data Subject
Data subjects have the right to request confirmation as to whether personal data concerning them are being processed. They have the right to access their data, request rectification of inaccurate data, and demand erasure where processing is no longer necessary or where consent has been withdrawn. They may request restriction of processing under the conditions set out in Articles 16–18 GDPR and may exercise the right to data portability under Article 20 GDPR. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. Data subjects may lodge a complaint with the competent supervisory authority if they believe that their rights under the GDPR have been violated.
10. Security Measures
The Operator implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. These measures include encryption of communication channels, secure server configuration, controlled access to personal data, and continuous monitoring of system integrity. The Operator regularly reviews and updates security measures to maintain compliance with evolving data protection standards and technological developments.
11. Cookies and Tracking Technologies
The website uses necessary cookies essential for its operation. These cookies enable core functionalities such as secure session management and proper display of content. Additional cookies used for statistical analysis through Yandex Metrica are activated only with the user’s consent. Users may change their cookie preferences at any time through the “Cookies” link in the website footer. Detailed information about specific cookies used by the website is available under the “Individual Privacy Preferences” section.
12. Amendments to This Policy
The Operator may update this Privacy Policy to reflect changes in legal requirements, technological developments, or operational practices. The updated version will be published on this webpage and will supersede all previous versions. Users are encouraged to review this document periodically to remain informed about the processing of their personal data.
13. Contact Information
All inquiries related to data protection, as well as requests to exercise rights under the GDPR, may be directed to the Operator using the contact details provided in the Imprint section of this website.