Privacy Policy
Last updated: September 2026
1. Introduction and Controller Identity
MSS (hereinafter "MSS", "we", "us") is a sole proprietorship registered in the Republic of Croatia providing IT services and network infrastructure. This Privacy Policy explains what personal data we collect through mss-it.com, why we collect it, on what legal basis, how long we keep it, and how you can exercise your rights.
Processing complies with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), the Croatian Act implementing the GDPR (OG 42/2018), and Croatian electronic communications law regarding storage of information on your device.
Data controller:
MSS – IT services and network infrastructure
Zadar, Republic of Croatia
Email: info@mss-it.com
We are not required to appoint a Data Protection Officer (Art. 37 GDPR), as our core activity involves neither large-scale regular monitoring of data subjects nor large-scale processing of special categories of data. For any data protection question, contact us directly at the address above.
2. What Data We Collect
We collect only what we need. The website requires no registration and you can browse it without providing any contact details.
a) Data you provide through the contact form
- Name (required)
- Email address (required)
- Phone number (optional)
- Selected service and message (content is entirely up to you)
- Consent record (the ticked confirmation and time of submission)
- IP address and browser details the enquiry was sent from, in full
The IP address attached to an enquiry is recorded on the basis of legitimate interests (Art. 6(1)(f)): it evidences who sent the enquiry and helps prevent abuse of the form. Unlike analytics, it is not truncated here, but it is deleted together with the enquiry after 12 months. You may object to this processing (Art. 21 GDPR).
b) Visit data (only with your analytics consent)
- Truncated IP address – the last octet is removed before storage (e.g. 192.168.1.0), so the address cannot be tied to an individual connection
- Pseudonymous visit identifier – a random string stored in your browser, with no link to your identity
- Technical data – device type, browser and operating system, derived from browser headers
- Browsing data – page visited, language, time on page and referring page
- Country – only if provided by network infrastructure; we do not perform IP-based geolocation
We do not collect special categories of personal data (Art. 9 GDPR): health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, or data on sex life or orientation. We neither request nor process payment card data through this website.
3. Purposes and Legal Bases
Each purpose rests on a clearly identified legal basis under Article 6 GDPR:
| Purpose | Legal basis | Note |
|---|---|---|
| Replying to your enquiry | Steps at your request prior to entering a contract (Art. 6(1)(b)) | Without this data we cannot reply |
| Entering into and performing a service contract | Performance of a contract (Art. 6(1)(b)) | Applies to clients we work with |
| Invoicing, accounting and tax obligations | Legal obligation (Art. 6(1)(c)) | Statutory periods, see section 5 |
| Measuring website traffic | Consent (Art. 6(1)(a)) | Does not run until you agree; withdrawable at any time |
| Site security and preventing form abuse | Legitimate interests (Art. 6(1)(f)) | Temporary per-IP submission limits |
Providing data is not a statutory requirement. Completing the contact form is voluntary, and the only consequence of not doing so is that we cannot reply. Analytics consent is entirely free, and refusing it has no effect on the website or on our services.
5. Retention Periods
We keep data no longer than necessary for the purpose it was collected for:
| Category | Period |
|---|---|
| Enquiries that did not lead to a business relationship | 12 months from receipt |
| Business relationship records | 5 years from the end of the relationship |
| Invoices and accounting records | 11 years (Croatian Accounting Act) |
| Website analytics data | Maximum 12 months, then deleted automatically |
Deletion of analytics records older than 12 months is automated at system level rather than done manually, so the period does not depend on someone remembering to delete data.
6. Recipients and International Transfers
We do not sell, rent or trade your data for marketing purposes. Only the following recipients have access, and only to the minimum extent needed:
| Recipient | What they process | Location |
|---|---|---|
| Hosting and email provider (Hostinger) | Website, database and mailbox storage | Servers in the EU |
| Accounting service | Invoice data only, where a business relationship exists | Croatia |
| Competent authorities | Only under a legal obligation or order | Croatia / EU |
A data processing agreement under Article 28 GDPR is in place with every processor.
We do not transfer data outside the European Economic Area. To avoid such transfers, the website deliberately avoids external services that would cause them:
- Fonts are self-hosted – typography is not fetched from Google Fonts, so your IP address is never sent to Google
- No external analytics – traffic measurement runs on our own server
- No IP geolocation – we do not send IP addresses to outside services to determine location
- No third-party embeds – no YouTube embeds, social plugins or similar scripts
7. Your Rights
In relation to your personal data you have the following rights:
- Access (Art. 15): confirmation of whether we process your data, and a copy of it
- Rectification (Art. 16): correction of inaccurate data and completion of incomplete data
- Erasure (Art. 17): deletion where data is no longer needed or where you withdraw consent
- Restriction (Art. 18): temporary suspension while accuracy or an objection is verified
- Portability (Art. 20): your data in a machine-readable format
- Objection (Art. 21): objection to processing based on legitimate interests
- Withdrawal of consent (Art. 7(3)): at any time and without detriment; withdrawal does not affect the lawfulness of processing before it
Send requests to info@mss-it.com. We respond without undue delay and within one month of receipt (Art. 12(3) GDPR). That period may be extended by two further months for complex requests, in which case we will tell you. Exercising your rights is free of charge.
To protect your data, we may ask for further information to confirm your identity before acting on a request.
If you believe we process your data unlawfully, you may lodge a complaint with the supervisory authority:
Croatian Personal Data Protection Agency (AZOP)
Selska cesta 136, 10000 Zagreb, Croatia
azop.hr · azop@azop.hr
8. Automated Decision-Making and Profiling
We do not take decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).
Website analytics measures aggregate figures only, such as how many times a page was viewed. We do not build individual profiles, score behaviour, or link visit data to the contact details you submit through the form.
9. Children's Data
Our services are aimed at businesses and adults. The website is not directed at children and we do not knowingly collect data from anyone under 16.
If we learn that such data has been collected without the authorisation of the holder of parental responsibility, we will delete it without delay. If you are a parent or guardian and believe a child has given us their data, contact us at info@mss-it.com.
10. Data Security
We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR):
- Encrypted transmission (TLS/HTTPS) across the entire site
- Authenticated administration, with access limited to authorised persons
- Data minimisation, including truncating IP addresses before storage
- Regular software updates and prompt patching of security issues
- Backups of stored data
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify AZOP within 72 hours of becoming aware of it (Art. 33 GDPR), and you without undue delay where the risk is high (Art. 34 GDPR).
11. Changes to This Policy
We may update this Policy from time to time to reflect changes in law or in how the website works. The version in force is always published at this address, with the date of the last change.
We will announce material changes, particularly those affecting processing purposes or your rights, through a prominent notice on the site and, where appropriate, by email.
Last updated: September 2026