Privacy Policy
Who the controller is
The controller of your personal data is registered company name, registered address, entered in the court register under court register number (MBS) and the registry court, OIB: OIB of the operating company. The same service runs on digitalni-ugovori.eu and digital-contracts.eu. Send privacy questions and requests to exercise your rights to privacy contact email address. Data protection officer: data protection officer name and contact details, or a statement that no DPO is appointed.
One note on roles: when a creditor enters a debtor's details into a project, it is the creditor who decides the purpose of that processing, and we provide the platform — confirm whether the operator is controller or processor for debtor data entered by creditors, and whether a data-processing agreement is offered.
What we collect
We collect what the service actually needs. Self-service registration is currently closed, so accounts are opened by an administrator.
- Account: e-mail address (also the username), display name, interface language and, if you enter one, a phone number. Your role is creditor, debtor, administrator or superadministrator. - Loan project — debtor details: name, address, town, postal code, OIB (Croatian tax ID), e-mail address, IBAN, BIC and responsible person. - Contract parties: name, e-mail address, interest amount and, if entered, an additional structured record of personal data. - Consents: the consent type, whether it was granted or withdrawn, the version of the document it refers to, IP address, browser details (user agent) and the time. - Communication: messages you exchange with other users, in-app notifications and your e-mail preferences. - Signing: signer name and e-mail address, each signer's status, the IP address and user agent recorded at the moment of signing and — for eID card signatures — the subject, issuer and serial number of your certificate; that certificate contains your OIB. The signing-session tables retain only a BLAKE3 hash of each one-time token. When an invitation is sent by e-mail, the full link also passes through the outbound notification queue and mail provider and may remain there under their retention rules. - Server logs: confirm whether web-server access logs with IP addresses are kept, and for how long
Purposes and legal bases
Each purpose has one basis under Article 6 GDPR:
- Running your account, projects, contracts and calculators — performance of our contract with you, Art. 6(1)(b). - Data about debtors and other parties who are not platform users — the legitimate interest of the parties in preparing, concluding and later proving the contract, Art. 6(1)(f). - Electronic signing and the evidence record — performance of the contract, Art. 6(1)(b), and the establishment, exercise or defence of legal claims, Art. 6(1)(f), in line with the eIDAS Regulation. - The consent ledger, including IP address, user agent and timestamp — the legal obligation to be able to demonstrate consent, Art. 6(1)(c) read with Art. 7(1). - Transactional notifications (invitation to sign, completion confirmation) — performance of the contract, Art. 6(1)(b). - Optional notifications — consent, Art. 6(1)(a). - The AI assistant — consent, Art. 6(1)(a). confirm whether the ai_chat_external consent is enforced as a hard gate on the send path, or is recorded as a checkbox — and state whichever is true - Security and abuse prevention — legitimate interest, Art. 6(1)(f). - Accounting and tax records — legal obligation, Art. 6(1)(c).
Electronic signatures and the evidence record
The platform offers several tiers of signature, and they do not have the same legal effect.
- Simple electronic signature (SES): the signer draws or types a mark. We then seal the document with the platform's own certificate, so any later alteration is detectable. That certificate identifies the platform, not you. Your identity is evidenced by the audit trail — possession of the one-time link, IP address, user agent and timestamps — not by a certificate. SES is not a qualified electronic signature, it is on no EU trusted list, and it is not equivalent to a handwritten signature. - Advanced electronic signature (AES): announced, NOT yet live. No additional identity factor exists today and AES cannot be selected. - Qualified signature (QES) with an eID card: you sign with your Croatian eID card via Web eID. The private key never leaves the card. - Remote QES through a qualified trust service provider: planned, not yet live.
Every milestone in a document's life — created, sent, viewed, signed, declined, completed — is written to a hash-chained log, so a later alteration of a recorded entry is detectable on verification. The chain detects edits to what is recorded; on its own it does not prove the log was not re-chained wholesale or its end removed or replaced — that needs an external anchor, which is not yet in place.
The AI assistant and automated decisions
If you use the AI assistant, the text of your chat messages is sent to an external large language model provider. That is why we ask for a separate consent (ai_chat_external) before the feature is used. confirm whether the ai_chat_external consent is enforced as a hard gate on the send path, or is recorded as a checkbox — and state whichever is true Messages you type are sent as you wrote them — do not put anything into the chat that you do not want sent to an external provider. Data the assistant fetches from the system is masked first: OIB and IBAN are replaced before any tool result reaches the model.
The assistant does not make decisions about you. We do not carry out automated decision-making with legal effect within the meaning of Art. 22 GDPR; the interest and annuity calculators are computations you run yourself. confirm whether any project approval or scoring decision is made automatically
Who we share data with
We do not sell data and we do not use it for advertising. We share it only in these cases:
- Other parties to the same contract see your name, e-mail address and signing status. That is the point of the document. - An external large language model provider — only the content of your chat with the assistant, and only if you have consented: name and country of the large language model provider. - An external e-mail delivery provider — your e-mail address and the content of the message: name and country of the email delivery provider. - Competent authorities where the law or a court order requires it.
Two things are not data sharing, but we mention them for completeness. Signature validation runs on an EU DSS instance on our own server; it fetches the EU List of Trusted Lists and national trusted lists from public EU endpoints — none of your data is sent in the process. For timestamps we contact public time-stamping authorities (names of the time-stamping authorities used); only a cryptographic hash of the document is sent to them, never the document itself.
Transfers outside the EU/EEA
The platform runs on the operator's own servers. Two external services can mean a transfer of personal data outside the EU/EEA, and we are not going to be quiet about it.
The language model: the content of your chat with the assistant is sent to name and country of the large language model provider. If that provider processes data outside the EU/EEA, the transfer relies on: transfer safeguard for the large language model provider — adequacy decision or Standard Contractual Clauses, with a link. If you do not give the ai_chat_external consent, this transfer does not happen.
E-mail delivery: name and country of the email delivery provider, with the safeguard: transfer safeguard for the email delivery provider — adequacy decision or Standard Contractual Clauses, with a link.
How long we keep data
- Account data: for as long as the account exists, and after closure retention period for account data after the account is closed. - Messages and in-app notifications: retention period for messages and in-app notifications. - Accounting and tax records: for as long as the law requires — retention period for accounting and tax records required by Croatian law. - Signed documents and the signing evidence record: retention period for signed documents and signing evidence. These are not deleted even at your request — the reason is explained in the erasure section. - The consent ledger: kept for as long as we may need to prove a consent and the processing that relied on it. - Backups: how long backups are kept before they are overwritten. An anonymisation only reaches the backups once that cycle has passed. - Your data export file: downloadable for how long a generated data export file stays downloadable.
Your rights and how to use them here
You have the right of access, rectification, erasure, restriction of processing, objection to processing based on legitimate interest, data portability, and withdrawal of consent. Here is what that concretely means in this product.
- Access and portability: request an export in the app. The system assembles a JSON file of your data, stores it, and makes it downloadable to you alone — nobody else can reach that file. - Erasure: submit the request in the app. A 30-day grace period follows. After that, a nightly job performs the anonymisation described in the next section. - Rectification, restriction and objection: contact privacy contact email address; you can also edit your profile data yourself in settings. - Withdrawal of consent: notification and communication preferences can be changed at any time in settings. confirm whether changing them also records a withdrawal in the consent ledger, and if not, state how a recorded consent is withdrawn
We answer requests within one month, as Art. 12(3) GDPR requires.
What erasure means here — and what survives it
Erasure here means anonymisation in place, not removal of rows. After the 30-day grace period, a nightly job scrubs personal data across all tables, with the exceptions described below — e-mail addresses, names, addresses, OIB, IBAN, IP addresses and user agents — including the e-mail address recorded in the deletion request itself, and replaces your identity with a random surrogate. The surrogate replaces your identity in the live system and we cannot recover the original data from it. The replacement value itself is random, so it cannot re-identify you. One residual, stated rather than hidden: the internal identifier that ties your preserved content together is derived from your original e-mail address, so someone who can GUESS that address could confirm which records were yours. The e-mail-to-identifier mapping is deleted, but the identifier stays. This is pseudonymisation, not full anonymisation. decide whether to salt or rotate the retained key, and state the outcome here
What survives: signed documents and the signing evidence record. This is not an oversight. Those records prove a legally significant act — that a specific person signed a specific document at a specific moment — and they are hash-chained to the signatures of the other parties to the same document. Deleting them would destroy the evidence and break the chain for the other signatories, who are entitled to it. The retention rests on Art. 17(3)(b) GDPR (compliance with a legal obligation) and Art. 17(3)(e) (establishment, exercise or defence of legal claims).
Be clear about what that means in practice: the surviving record still contains your name and e-mail address, the IP address and browser details captured at the moment you signed, and — if you signed with an eID card — the subject of your certificate, which contains your OIB.
Put plainly: if you have signed a document through this platform, that document and its evidence trail will survive your erasure request. Your account and profile will not. Two things are worth saying outright, because they would otherwise surprise you: your e-mail address is removed from your messages, but the message text itself remains, because a conversation is also the other party's record; and in-app notifications are not yet scrubbed. decide whether message bodies and notifications must be anonymised too, and how to do that without destroying the other party's record
The consent ledger and withdrawing consent
Consents are kept in an append-only ledger. Each record holds the consent type, whether it was granted or withdrawn, the version of the document it refers to, the IP address, the user agent and the time. An old record is never overwritten — a withdrawal is a new record, so the history can always be reconstructed.
The consent types are: privacy policy (privacy_policy), terms of use (terms), data processing (data_processing), notifications (communication), sending your chat to an external language model (ai_chat_external), and the cookie notice (cookie_notice).
E-mail preferences have a master switch and per-category switches, and you can change them at any time. confirm whether changing a preference also appends a withdrawal record to the consent ledger; if it does not, state here how a consent is withdrawn Withdrawal does not affect the lawfulness of processing carried out before it. Messages required to perform the contract — an invitation to sign, for example — rest on the contract and not on consent: confirm whether the master email switch also stops transactional signing e-mails
Cookies
We use three cookies: a session cookie for sign-in, a locale cookie for your chosen language, and a timezone cookie. Your theme choice (light or dark) is stored by the browser in local storage, not in a cookie. The session cookie is strictly necessary; without it you cannot sign in.
We have no advertising or analytics cookies and we do not track you across other sites. Cookie lifetimes: lifetime of the session, locale and timezone cookies
Where data is processed and how it is protected
The platform runs on the operator's own servers, not on a third-party cloud application platform: self-hosted PostgreSQL, self-hosted object storage and a self-hosted secrets vault. Server location: country and data centre location of the servers; name of the hosting or colocation provider, if the servers are not owned outright.
The signing record stores a one-time link only as a BLAKE3 hash. a failed invitation e-mail can retain the full link in the notification queue's dead-letter payload — scrub it, or store a session reference instead Access to data is tied to sign-in and role. No system is perfectly secure; if a personal data breach occurs that carries a high risk to you, we will notify you and the supervisory authority as required by Arts. 33 and 34 GDPR.
Versions and changes to this policy
This policy has a version number and an effective date: policy version number and effective date, matching the version recorded in the consent ledger. When we change it materially we will ask for consent again. the consent ledger currently records a fixed version string rather than one bound to this policy's version — bind them before relying on the ledger to show which version a user agreed to Earlier versions: where previous versions of this policy can be read, if they are published
Complaints and contact
If you believe we are processing your data unlawfully, write to us first at privacy contact email address. We answer within one month.
Independently of that, you have the right to lodge a complaint with the supervisory authority: the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop@azop.hr, www.azop.hr — verify AZOP's current postal address before publishing. If you live or work in another EEA country, you may also complain to your own national supervisory authority.