HomePrivacyTerms
Contact ↗
← Back to Cropol Labs Legal

Privacy Policy

This policy explains what personal data we process when you browse cropol-labs.com, use the contact form, or communicate with us.

Effective 5 August 2026Cropol Labs · Osijek, Croatia
On this page
Who we areData we processHow and why we use dataService providersTransfers and retentionYour rightsContact and complaints
In short

Your privacy, without the fog.

We use personal data to operate and secure this website, display our location, and reply to inquiries. We do not sell personal data, run behavioural advertising, or use website visitors for automated decision-making with legal or similarly significant effects.

01

Who we are

Cropol Labs is the controller of the personal data described in this policy. You can contact us at cropollabs@gmail.com or by post at Svete Ane 30A, 31000 Osijek, Croatia.

This policy covers the Cropol Labs website at cropol-labs.com. Websites linked from our portfolio or social profiles are operated under their own privacy notices.

02

Personal data we process

Information you send us

When you use our contact form or email us, we receive your name, email address, selected project type, message, and any other information you choose to include. Please do not send sensitive personal data unless it is genuinely necessary for your inquiry.

Technical and security data

When you visit the site, our hosting and security services may process your IP address, request date and time, requested URL, referring page, browser and device information, diagnostic data, and security events. Our contact endpoint also uses an IP-based attempt counter to limit abuse; this counter resets after 15 minutes.

Third-party content

The site loads Google Fonts and contains an embedded Google Map showing our business address. When these resources load, Google receives technical request data such as your IP address, the requested resource, HTTP headers, and referring page. Google Maps may also use cookies or similar technologies according to your Google and browser settings. We do not request your device's precise location through this website.

03

How and why we use personal data

Responding to inquiries

We use contact details and message content to understand your request, answer it, and take steps toward a possible project. The legal basis is taking steps at your request before entering a contract (GDPR Article 6(1)(b)) or our legitimate interest in handling general business communications (Article 6(1)(f)).

Operating and securing the website

We use technical data to deliver pages, diagnose faults, maintain availability, prevent spam and malicious traffic, and protect the site and its visitors. The legal basis is our legitimate interest in running a secure and reliable website (Article 6(1)(f)).

Displaying our address and typography

We use Google Maps to make our office address easy to find and Google Fonts to present the site consistently. The legal basis is our legitimate interest in providing a useful, accessible business website (Article 6(1)(f)). You can use the written address without interacting with the map.

Legal obligations and claims

Where necessary, we may retain or disclose relevant records to comply with law, respond to lawful requests, or establish, exercise, or defend legal claims. The legal basis is a legal obligation (Article 6(1)(c)) or our legitimate interests (Article 6(1)(f)), as applicable.

The contact form's required fields are necessary for us to understand and answer your inquiry. If you do not provide them, you can still browse the site, but we may be unable to respond through the form.

04

Service providers and recipients

We use a limited set of providers to operate the website:

  • Vercel hosts and delivers the website and may process request logs, IP addresses, device information, and data submitted to the website. Read Vercel's Privacy Notice and Data Processing Addendum.
  • Resend delivers contact-form messages to our inbox and therefore processes your email address, name, project type, message content, and delivery metadata. Read Resend's Privacy Policy and Data Processing Addendum.
  • Cloudflare Turnstile protects the contact form from bots. It processes a short-lived verification token and signals such as IP address, user-agent, TLS fingerprint, site key, and site origin. We also send the submitting IP address to Cloudflare for verification. Read the Turnstile Privacy Addendum.
  • Google provides Google Maps and Google Fonts. Google processes the technical data needed to return these resources and may process Maps activity under its own terms and privacy policy. Read the Google Privacy Policy and Google Fonts privacy information.

We may also disclose data to professional advisers, public authorities, courts, or other recipients where reasonably necessary and legally permitted. We do not sell or rent your personal data.

05

International transfers and retention

Some providers or their subprocessors operate outside the European Economic Area, including in the United States. Where required, transfers are protected through an applicable adequacy decision, the EU Standard Contractual Clauses, or another safeguard recognised by data protection law. You can contact us for more information about the relevant safeguards.

We keep inquiry correspondence only as long as needed to respond and manage the possible business relationship. Unless a project proceeds, a dispute arises, or law requires a longer period, we generally delete or anonymise inquiry records within 24 months after the last meaningful contact. Contract, accounting, and legal records are retained for the periods required by applicable law.

The website's 15-minute rate-limit record is temporary. Turnstile verification tokens expire after five minutes and are single-use. Hosting, email, security, and mapping providers retain their service logs according to their own documented retention schedules and legal obligations.

06

Your data protection rights

Subject to the conditions in applicable law, you may ask us to:

  • give you access to your personal data;
  • correct inaccurate or incomplete data;
  • erase your data;
  • restrict how we process it;
  • provide portable data where the right applies; or
  • stop processing based on our legitimate interests.

Where processing is based on consent, you may withdraw it at any time without affecting earlier lawful processing. We do not currently use consent as the legal basis for the core website activities described above. We may need to confirm your identity before completing a request and may retain limited information where an exemption or legal obligation applies.

We use Turnstile to decide whether a form submission is likely to be human or automated, but we do not use automated decision-making that produces legal or similarly significant effects about you.

07

Contact, complaints, and updates

To ask a privacy question or exercise a right, email cropollabs@gmail.com. We will respond in line with applicable data protection law.

You also have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), or with another competent supervisory authority where applicable. Visit azop.hr for more information.

We may update this policy when our website, providers, or legal obligations change. The effective date at the top shows when the latest version took effect.

Remote-first IT consulting and digital products for businesses ready to grow.

LegalPrivacy PolicyTerms & Conditions
Contactcropollabs@gmail.comSvete Ane 30A
31000 Osijek, Croatia
© 2026 Cropol Labs. All rights reserved.Back to the website