Privacy Policy
This Privacy Policy explains how HYDRA CONSULTING d.o.o. processes the personal data of visitors to hydra-consulting.hr, including its English and Croatian versions, and people who contact us using the details published on the website. It covers website visits, initial enquiries, discussions about a potential engagement and the exercise of data protection rights.
The website does not use cookies, analytics or visitor tracking. We do not carry out automated decision-making or profiling. We do not make international transfers of personal data in connection with the processing covered by this Policy.
This Policy is not a notice about processing carried out for clients under separately agreed advisory, DPO or representative engagements. Appropriate separate information is provided for that processing, depending on the roles of HYDRA CONSULTING and the relevant controller.
1. Controller and contact details
The controller is HYDRA CONSULTING d.o.o. (referred to as HYDRA, we, us or our). We determine why and how personal data are processed for the purposes described in this Policy.
HYDRA CONSULTING d.o.o.
Prve Poljanice 7
10040 Zagreb, Croatia
Croatian personal identification number (OIB): 82306718971
Email: info@hydra-consulting.hr
Telephone: +385 95 90 60 745
You can use these contact details for questions about the processing of your data and requests to exercise your rights. No special form is required.
Processing is governed by Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and applicable Croatian personal data protection legislation. This Policy provides information. Visiting the website or sending an enquiry does not constitute consent to processing for other purposes.
2. Where we obtain your data
We primarily obtain data from you, through the technical request your browser sends when you visit the website or the information you provide in an enquiry. If your organisation or another person provides your business contact details in connection with a specific enquiry, that organisation or person is the source. We then process only the data needed for the related communication.
If we did not obtain the data from you, we provide the required information, including its source, within the time limits in Article 14 GDPR: no later than one month, or earlier at our first communication with you or the first disclosure to another recipient. We do not repeat information you already have or provide it where another statutory exception applies.
3. Data, purposes and legal bases
3.1. Website availability and security
To display the requested content, the server processes your IP address and information about your browser request. The request may include the address of the page or file requested, information about your browser and operating system, and the referring page address if your browser sends it. The hosting infrastructure may generate access and security logs containing some of these data, the date and time of access, the response status or details of a technical error.
The purposes are to deliver content, maintain website availability, identify technical problems and detect and prevent misuse or security incidents. The legal basis is our legitimate interest in operating a functional and secure website under Article 6(1)(f) GDPR. We do not use these data for marketing analytics, monitoring interests or linking your activity across websites.
3.2. Enquiries and discussions about an engagement
When you contact us, we process the information you provide, such as your name, email address, telephone number, organisation and professional role, the content of your message and attachments, and details of the service requested. A telephone conversation may result in a note needed to respond to the enquiry or prepare a proposal.
We use the data to respond, clarify your request, prepare a proposal and discuss a potential engagement. For general enquiries and communication with people acting on behalf of an organisation, the legal basis is our legitimate interest in responding to enquiries and establishing business relationships under Article 6(1)(f) GDPR.
If we take steps at your request towards a contract to which you would personally be a party, the necessary processing is based on Article 6(1)(b) GDPR. That basis does not apply to you merely because you represent a company that would enter into the contract.
Providing data for an enquiry is voluntary, but without enough information and a means of contact we may be unable to respond or prepare a proposal. For an initial enquiry, we do not request special categories of data, such as health data, or copies of identity documents. If we receive data that are not needed for the enquiry, we limit their use and delete unnecessary content.
3.3. Rights requests and legal obligations
To handle rights requests, we process contact details, the request, any data needed to confirm identity, and a record of our handling and response. The legal basis is compliance with our obligations under Articles 12 to 22 GDPR, pursuant to Article 6(1)(c). We use the same basis to comply with binding requests from competent authorities where the obligation arises under applicable law.
3.4. Protecting rights and handling legal claims
Where necessary to establish, exercise or defend a specific legal claim, we process relevant correspondence and other related evidence. The legal basis is our legitimate interest in protecting our rights under Article 6(1)(f) GDPR. This does not mean that we automatically retain all data for potential disputes.
4. Cookies, language selection and other technologies
The website does not set cookies. It does not use analytics tools, advertising pixels, tracking identifiers or device fingerprinting. Visiting the website is not conditional on accepting cookies or this Policy.
The English and Croatian versions have separate addresses. Selecting EN or HR opens the corresponding language version. We do not use localStorage, sessionStorage or another browser entry placed by our website to remember your language choice.
The website has no contact form, user accounts or newsletter subscription. Its photographs, graphics and other resources are not loaded from external marketing services. We use fonts hosted on our own server, without calling the Google Fonts service. Ordinary browser caching and history depend on your browser and are not tracking tools placed by HYDRA.
The absence of cookies does not exclude the technical processing needed to display content, described in section 3.1. We do not use data from your enquiries to send newsletters or unsolicited marketing messages.
5. Recipients and access to personal data
Within HYDRA CONSULTING, data are accessed only by authorised people who need them to handle an enquiry, maintain the website, protect systems or comply with legal obligations. We do not sell data or provide them to others for their own marketing purposes.
Providers of website hosting, business email and related technical support may access data to the extent needed to provide their services. Where they act as our processors, they process data on our instructions and under contractual obligations in accordance with Article 28 GDPR, including confidentiality and security requirements.
We may disclose relevant data to legal advisers where needed for a specific legal claim, and to courts or other competent authorities where there is a legal obligation or another appropriate legal basis. Those recipients may act as independent controllers. Only the data needed for the particular purpose are disclosed.
6. International data transfers
For the processing covered by this Policy, we do not transfer personal data to third countries outside the European Economic Area (EEA) or to international organisations. This includes storage and access by the service providers we use for this processing. The EEA consists of the EU Member States, Iceland, Liechtenstein and Norway.
7. Data security
We apply technical and organisational measures appropriate to the nature of the data and the risks of processing. These include restricting access to authorised people, confidentiality, protecting systems and communications, and handling security incidents. If a personal data breach is likely to result in a high risk to your rights and freedoms, we will inform you in accordance with Article 34 GDPR unless a statutory exception applies.
8. Data retention and deletion
We do not retain personal data indefinitely. The retention period is determined separately for each type of data and purpose. When there is no longer an appropriate basis for retention, the data are deleted or irreversibly anonymised. The following criteria apply to the different types of processing.
8.1. Technical data and server logs
Data needed only to deliver content are processed during the corresponding browser request. If some data are stored in access or security logs, their retention is determined by the period needed to detect and verify errors, identify related security events and check that a problem has been resolved. Relevant factors include the type of log, risks to the system and the hosting provider’s review and deletion cycle. Logs are not retained to build a history of an individual visitor’s behaviour.
If a particular log entry is needed to investigate a specific incident or for legal proceedings, it may be isolated and retained under the rules for that matter. The reason for extended retention applies to relevant records, not automatically to all server logs.
8.2. Enquiries, proposals and engagement discussions
We retain correspondence until the enquiry and related discussions are closed. In determining that point, we consider whether a response has been provided, whether questions remain open, whether the scope of the service is still being discussed, and whether a proposal has been accepted, declined or has expired. After closure, we delete data that are no longer needed, except for material whose retention is justified by a specific legal obligation or legal claim.
If an engagement follows, relevant correspondence becomes part of the records for that engagement. It is then subject to the retention arrangements and additional information for the relevant contractual relationship, rather than indefinite retention merely because the first contact was made through the website.
8.3. Rights requests and legal matters
We retain a request and the record of our response while handling it and for as long as needed to demonstrate our handling in a specific objection, investigation or other related proceedings. In determining the period, we consider the conclusion of the proceedings and applicable time limits for remedies and claims. Additional data obtained solely to verify identity are deleted after verification unless there is a specific justification for retaining them.
Evidence relevant to a legal claim is retained while the claim may be brought or proceedings are ongoing, taking into account applicable limitation periods, any interruption or suspension of those periods, the final conclusion of proceedings and, where relevant, enforcement of the decision. Only records needed for that claim are retained.
8.4. Backups
If data are held in backups, they are removed through the regular backup replacement and deletion cycle. Backups are not intended for routine processing of deleted data. If restoration is necessary for system recovery, previously applied deletions and processing restrictions are reapplied.
9. Your rights
You may exercise rights in relation to your personal data, subject to the conditions and exceptions in the GDPR. Their applicability depends on the legal basis and circumstances of the particular processing.
9.1. Access (Article 15)
You can obtain confirmation of whether we process your data, access to and a copy of those data, and information about purposes, categories, recipients, retention and, where we did not obtain the data from you, their source. Providing a copy must not adversely affect other people’s rights and freedoms.
9.2. Rectification and completion (Article 16)
You can request correction of inaccurate data and completion of incomplete data, taking account of the purpose of the processing.
9.3. Erasure (Article 17)
You can request erasure, for example where data are no longer needed, processing is unlawful or your objection is upheld. We are not required to erase data to the extent retention is necessary to comply with a legal obligation or to establish, exercise or defend legal claims.
9.4. Restriction of processing (Article 18)
You can request restriction while we verify disputed data accuracy or assess an objection, where processing is unlawful but you oppose erasure, or where we no longer need the data but you need them for legal claims. We will inform you before lifting a restriction.
9.5. Data portability (Article 20)
Where processing is based on Article 6(1)(b) GDPR and carried out by automated means, you can obtain data you provided to us in a structured, commonly used and machine-readable format. You can request direct transmission to another controller where technically feasible. This right does not apply to processing based solely on legitimate interests or a legal obligation.
9.6. Objection (Article 21)
You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR. We will stop that processing unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims. You can send an objection to info@hydra-consulting.hr.
9.7. Consent and automated decision-making
We do not rely on consent for the ordinary processing described in this Policy. If we request consent for any additional processing, we will provide separate information beforehand about that processing and the ability to withdraw consent at any time without affecting the lawfulness of prior processing.
We do not carry out automated decision-making or profiling. We do not use your data for decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
10. How to exercise your rights
Send your request to info@hydra-consulting.hr or by post to the address in section 1. Provide enough information for us to understand the request and locate the relevant processing. If you act through an authorised representative, we may verify their authority. If there are reasonable doubts about your identity, we will request only the additional data necessary to confirm it.
We respond without undue delay and no later than one month after receiving the request. Where necessary because of the complexity or number of requests, this may be extended by two further months. We will inform you of the extension and reasons within the first month. If we do not act on the request, we will explain why within the same period and inform you about the possibility of a complaint and a judicial remedy.
Handling is free of charge. Only for manifestly unfounded or excessive requests may we charge a reasonable fee or refuse to act, with an explanation. Where possible, we respond electronically to an electronic request unless you ask otherwise. We notify recipients of rectification, erasure or restriction in accordance with Article 19 GDPR unless this is impossible or involves disproportionate effort. We will identify those recipients to you on request.
11. Complaints to a supervisory authority
If you consider that the processing of your data infringes the GDPR, you may lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work or the alleged infringement. In Croatia, you can contact the Croatian Personal Data Protection Agency (Agencija za zaštitu osobnih podataka, AZOP) and submit a request for a determination of an infringement of rights. This does not exclude other administrative or judicial remedies.
Croatian Personal Data Protection Agency (AZOP)
Ulica Metela Ožegovića 16, 10000 Zagreb, Croatia
Email: azop@azop.hr
Website: https://azop.hr
12. Links to other services
LinkedIn is linked through an ordinary hyperlink, without embedded posts or tracking tools. When you follow it, you move to a separate service to which your browser sends the technical data needed for access. LinkedIn’s own privacy information applies to processing it carries out for its purposes. Our statement about the absence of international transfers concerns processing for which we are responsible, not independent processing by external services you choose to use.
13. Changes to this Policy
We update this Policy when the processing described or relevant information changes. The current version, with its update date, is available on the website in Croatian and English. If we intend to use data for a new purpose, we will provide the required information and establish an appropriate legal basis before that processing begins. Continuing to use the website is not treated as consent to new processing.