Privacy Policy

Last updated: September 2026

1. Introduction and Controller Identity

MSS (hereinafter "MSS", "we", "us") is a sole proprietorship registered in the Republic of Croatia providing IT services and network infrastructure. This Privacy Policy explains what personal data we collect through mss-it.com, why we collect it, on what legal basis, how long we keep it, and how you can exercise your rights.

Processing complies with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), the Croatian Act implementing the GDPR (OG 42/2018), and Croatian electronic communications law regarding storage of information on your device.

Data controller:
MSS – IT services and network infrastructure
Zadar, Republic of Croatia
Email: info@mss-it.com

We are not required to appoint a Data Protection Officer (Art. 37 GDPR), as our core activity involves neither large-scale regular monitoring of data subjects nor large-scale processing of special categories of data. For any data protection question, contact us directly at the address above.

2. What Data We Collect

We collect only what we need. The website requires no registration and you can browse it without providing any contact details.

a) Data you provide through the contact form

  • Name (required)
  • Email address (required)
  • Phone number (optional)
  • Selected service and message (content is entirely up to you)
  • Consent record (the ticked confirmation and time of submission)
  • IP address and browser details the enquiry was sent from, in full

The IP address attached to an enquiry is recorded on the basis of legitimate interests (Art. 6(1)(f)): it evidences who sent the enquiry and helps prevent abuse of the form. Unlike analytics, it is not truncated here, but it is deleted together with the enquiry after 12 months. You may object to this processing (Art. 21 GDPR).

b) Visit data (only with your analytics consent)

  • Truncated IP address – the last octet is removed before storage (e.g. 192.168.1.0), so the address cannot be tied to an individual connection
  • Pseudonymous visit identifier – a random string stored in your browser, with no link to your identity
  • Technical data – device type, browser and operating system, derived from browser headers
  • Browsing data – page visited, language, time on page and referring page
  • Country – only if provided by network infrastructure; we do not perform IP-based geolocation

We do not collect special categories of personal data (Art. 9 GDPR): health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, or data on sex life or orientation. We neither request nor process payment card data through this website.

3. Purposes and Legal Bases

Each purpose rests on a clearly identified legal basis under Article 6 GDPR:

PurposeLegal basisNote
Replying to your enquirySteps at your request prior to entering a contract (Art. 6(1)(b))Without this data we cannot reply
Entering into and performing a service contractPerformance of a contract (Art. 6(1)(b))Applies to clients we work with
Invoicing, accounting and tax obligationsLegal obligation (Art. 6(1)(c))Statutory periods, see section 5
Measuring website trafficConsent (Art. 6(1)(a))Does not run until you agree; withdrawable at any time
Site security and preventing form abuseLegitimate interests (Art. 6(1)(f))Temporary per-IP submission limits

Providing data is not a statutory requirement. Completing the contact form is voluntary, and the only consequence of not doing so is that we cannot reply. Analytics consent is entirely free, and refusing it has no effect on the website or on our services.

4. Storage on Your Device and Consent

We do not use traditional cookies. Preferences are kept in browser localStorage which, unlike cookies, is not transmitted to the server with every request.

ItemPurposeBasisDuration
mss-themeRemembers dark or light themeStrictly necessaryUntil cleared
mss-consent-v2Remembers your analytics choiceStrictly necessaryUntil withdrawn
mss-sidPseudonymously distinguishes visits in analyticsConsentUntil withdrawn or cleared

Strictly necessary items are required for the site to work and are set without consent, under the exemption in electronic communications law. Analytics does not start until you explicitly agree and stops as soon as you withdraw.

We do not use advertising or cross-site tracking cookies, profiling, or third-party measurement tools such as Google Analytics, Meta Pixel or similar.

You can change or withdraw your consent at any time, as easily as you gave it (Art. 7(3) GDPR):

5. Retention Periods

We keep data no longer than necessary for the purpose it was collected for:

CategoryPeriod
Enquiries that did not lead to a business relationship12 months from receipt
Business relationship records5 years from the end of the relationship
Invoices and accounting records11 years (Croatian Accounting Act)
Website analytics dataMaximum 12 months, then deleted automatically

Deletion of analytics records older than 12 months is automated at system level rather than done manually, so the period does not depend on someone remembering to delete data.

6. Recipients and International Transfers

We do not sell, rent or trade your data for marketing purposes. Only the following recipients have access, and only to the minimum extent needed:

RecipientWhat they processLocation
Hosting and email provider (Hostinger)Website, database and mailbox storageServers in the EU
Accounting serviceInvoice data only, where a business relationship existsCroatia
Competent authoritiesOnly under a legal obligation or orderCroatia / EU

A data processing agreement under Article 28 GDPR is in place with every processor.

We do not transfer data outside the European Economic Area. To avoid such transfers, the website deliberately avoids external services that would cause them:

  • Fonts are self-hosted – typography is not fetched from Google Fonts, so your IP address is never sent to Google
  • No external analytics – traffic measurement runs on our own server
  • No IP geolocation – we do not send IP addresses to outside services to determine location
  • No third-party embeds – no YouTube embeds, social plugins or similar scripts

7. Your Rights

In relation to your personal data you have the following rights:

  • Access (Art. 15): confirmation of whether we process your data, and a copy of it
  • Rectification (Art. 16): correction of inaccurate data and completion of incomplete data
  • Erasure (Art. 17): deletion where data is no longer needed or where you withdraw consent
  • Restriction (Art. 18): temporary suspension while accuracy or an objection is verified
  • Portability (Art. 20): your data in a machine-readable format
  • Objection (Art. 21): objection to processing based on legitimate interests
  • Withdrawal of consent (Art. 7(3)): at any time and without detriment; withdrawal does not affect the lawfulness of processing before it

Send requests to info@mss-it.com. We respond without undue delay and within one month of receipt (Art. 12(3) GDPR). That period may be extended by two further months for complex requests, in which case we will tell you. Exercising your rights is free of charge.

To protect your data, we may ask for further information to confirm your identity before acting on a request.

If you believe we process your data unlawfully, you may lodge a complaint with the supervisory authority:
Croatian Personal Data Protection Agency (AZOP)
Selska cesta 136, 10000 Zagreb, Croatia
azop.hr · azop@azop.hr

8. Automated Decision-Making and Profiling

We do not take decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).

Website analytics measures aggregate figures only, such as how many times a page was viewed. We do not build individual profiles, score behaviour, or link visit data to the contact details you submit through the form.

9. Children's Data

Our services are aimed at businesses and adults. The website is not directed at children and we do not knowingly collect data from anyone under 16.

If we learn that such data has been collected without the authorisation of the holder of parental responsibility, we will delete it without delay. If you are a parent or guardian and believe a child has given us their data, contact us at info@mss-it.com.

10. Data Security

We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR):

  • Encrypted transmission (TLS/HTTPS) across the entire site
  • Authenticated administration, with access limited to authorised persons
  • Data minimisation, including truncating IP addresses before storage
  • Regular software updates and prompt patching of security issues
  • Backups of stored data

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify AZOP within 72 hours of becoming aware of it (Art. 33 GDPR), and you without undue delay where the risk is high (Art. 34 GDPR).

11. Changes to This Policy

We may update this Policy from time to time to reflect changes in law or in how the website works. The version in force is always published at this address, with the date of the last change.

We will announce material changes, particularly those affecting processing purposes or your rights, through a prominent notice on the site and, where appropriate, by email.

Last updated: September 2026

MSS IT | Privacy Policy