1. Controller and contact
Nodekka Solutions, obrt za proizvodnja filmova i digitalnih solucija, vl. Šime Bilić, Savska cesta 104, Zagreb, Croatia, OIB 09152736529, is the controller for personal data processed through this website.
Privacy questions and requests can be sent to sime@xpsr.eu.
2. Information you provide
When you use the project enquiry form, XPSR receives the information you choose to provide: name, email address, company or project, requested service, timing, indicative budget and message. The source page is included so the enquiry has the right context. A hidden anti-spam field and submission timing are checked briefly to reduce automated abuse.
The information is used to review and answer your enquiry, clarify requirements, arrange a conversation and, where relevant, prepare a proposal or take other steps you request before entering into a contract. The applicable legal bases are steps taken at your request before a contract, XPSR’s legitimate interests in responding to genuine business enquiries and operating the website securely, and legal obligations where records must be retained.
Please do not submit special-category or other highly sensitive personal data unless it is genuinely necessary for the enquiry.
3. Email delivery and service providers
Form messages are sent through Resend, a transactional email provider, to XPSR’s business mailbox. Cloudflare provides website delivery, serverless form processing, security and related infrastructure. These providers process only the information needed to provide their services to XPSR.
The protected owner-only admin uses GitHub authentication. Ordinary visitors are not asked to sign in with GitHub. XPSR does not sell enquiry details or use them for unrelated mailing lists, advertising or profiling.
Some providers may process data outside the European Economic Area. Where this occurs, the transfer is handled under the provider’s applicable data-protection safeguards, such as an adequacy decision or standard contractual clauses.
4. Technical data and security
Cloudflare and related infrastructure may process basic request and security data such as IP address, requested URL, browser or user-agent information, timestamps and security events. This is used to deliver the website, maintain reliability, prevent abuse and investigate technical or security incidents.
The form applies basic automated spam checks. They are not used for profiling or decisions that produce legal or similarly significant effects.
5. Cookies, browser storage and analytics
The public website does not use analytics, advertising cookies, marketing pixels or third-party media embeds. It does not create advertising profiles, and no non-essential cookie is set during ordinary public browsing.
If you actively switch languages, the site temporarily uses session storage to remember the target language, page position and a short timestamp so the translated page can reopen at approximately the same place. This entry is removed after the switch or when the browser-tab session ends and is not used for tracking.
The protected admin sets one encrypted, Secure, HttpOnly, SameSite session cookie only after the authorised owner signs in. It expires after seven days or is removed on logout and is not part of the public browsing experience.
6. Retention
Enquiry correspondence is generally retained for no longer than 24 months after the last meaningful communication, unless a project begins, a longer follow-up is reasonably expected, or accounting, contractual, legal-claim or other statutory obligations require a longer period. Obvious spam can be discarded immediately. Technical and security logs are retained according to the relevant provider’s operational and security schedules.
7. Your rights
Subject to the conditions in applicable data-protection law, you may request access to your personal data, correction, deletion, restriction of processing or data portability, and you may object to processing based on legitimate interests. Requests can be sent to sime@xpsr.eu. XPSR may request enough information to verify your identity before acting on a request.
You also have the right to lodge a complaint with the Croatian supervisory authority, the Croatian Personal Data Protection Agency (AZOP), or with the competent authority where you live or work.
8. External links and changes
This website links to Instagram, client websites and other third-party destinations but does not embed them. Once you follow an external link, that provider’s own privacy information applies.
This policy will be updated when the website’s forms, storage, providers or processing practices materially change. The date above identifies the current version.