Privacy Policy
Last updated: June 2026.
1. Introduction and Data Controller Identity
MSS (hereinafter "MSS", "we", "us") is a sole proprietorship registered in the Republic of Croatia providing IT services and network infrastructure. This Privacy Policy describes how we collect, use, store and protect your personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Croatian data protection law.
Data Controller:
MSS – IT services and network infrastructure
Zadar, Croatia
Email: info@mss-it.com
2. Personal Data We Collect
Depending on how you interact with our services, we may collect the following categories of personal data:
- Identification data: first and last name
- Contact data: email address, phone number
- Inquiry data: selected service, message content
- Technical data: IP address, browser type, pages visited, session duration (via analytics cookies)
- Consent records: records of consent given for data processing and cookies
We do not collect special categories of personal data (e.g. health data, racial origin data, biometric data).
3. Purpose and Legal Basis for Processing
We process your personal data solely for the following purposes:
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Responding to your contact inquiry | Consent (Art. 6(1)(a)) |
| Entering into and performing a service contract | Contract performance (Art. 6(1)(b)) |
| Legal obligations (accounting, tax) | Legal obligation (Art. 6(1)(c)) |
| Improving the website and user experience | Legitimate interest (Art. 6(1)(f)) |
4. Data Retention Periods
We retain your personal data only for as long as necessary to fulfil the purpose for which it was collected:
- Contact inquiries without a contract: up to 12 months from receipt of the inquiry
- Business relationship data (contracted clients): 5 years from end of the business relationship, in line with accounting regulations
- Invoice-related data: 11 years (Accounting Act)
- Technical and analytics data (cookies): up to 12 months
Upon expiry of the retention period, we delete or anonymise the data.
5. Recipients and Data Transfers
MSS does not sell, rent or share your personal data with third parties for commercial purposes. Data may be accessible to the following categories of recipients only to the extent necessary:
- IT infrastructure providers: hosting providers storing data on servers within the EEA
- Accounting services: only data required for statutory reporting
- Public authorities: where required by applicable law or court order
All external processors are bound by a Data Processing Agreement (DPA) ensuring an adequate level of protection under GDPR. We do not transfer data outside the European Economic Area (EEA).
7. Your Rights as a Data Subject
Under GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): You may request confirmation of whether we process your data and receive a copy.
- Right to rectification (Art. 16): You may request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): You may request deletion when data is no longer needed or when you withdraw consent.
- Right to restriction of processing (Art. 18): You may request temporary suspension of processing while accuracy or grounds are verified.
- Right to data portability (Art. 20): You may request data in a machine-readable format.
- Right to object (Art. 21): You may object to processing based on legitimate interest.
- Right to withdraw consent: You may withdraw consent at any time without negative consequences.
Submit requests to: info@mss-it.com. We will respond within 30 days. If you believe your rights have not been respected, you may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr.
8. Data Security
We apply appropriate technical and organisational measures to protect personal data, including:
- Encryption of data in transit (TLS/HTTPS)
- Access restricted to authorised personnel only
- Regular software updates and security patch management
- Backups stored in a secure location
In the event of a personal data breach that may jeopardise your rights and freedoms, we will notify you and the competent supervisory authority (AZOP) within the timelines required by GDPR (72 hours from becoming aware of the breach).
9. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in legislation or business practice. All amendments will be published on this page with the date of the last update indicated. For material changes, we will notify you by email or via a prominent notice on the website.
Last updated: June 2026.