Privacy policy
Last updated: 15 June 2026
1. Data controller
The controller of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
STU DEVELOPMENT, obrt za usluge
Owner: Jurica Stublić
Address: Oreškovićeva ulica 8 F, 10000 Zagreb, Hrvatska
Company ID (OIB): 46839323933
Email: jurica@webica.hr
For any question about the processing of your data, write to the address above.
2. What personal data is collected
Most data is collected directly from you through forms on the site, alongside the basic technical data needed to run the service. For B2B prospecting, publicly available business data from official registers and public sources may also be processed (see 2.5).
2.1. Contact form
- First and last name
- Email address
- Company name (optional)
- Message content
2.2. AI analysis
- Email address (when you request the report)
- Industry and team size
- Description of the business process
- The tools you use
2.3. Free webshop compliance check
- Webshop URL (to run the analysis)
- Email address (to send the analysis)
- Company name (optional)
- Consent to marketing messages (optional, a separate field)
The analysis is sent to you on the basis of your own request (Article 6(1)(b) GDPR); it is not a marketing message. Occasional advice and offers are sent only if you ticked the separate, optional consent (Article 6(1)(a) GDPR), which you can withdraw with a single click (the “Unsubscribe” link in every message) or by email on request. The text of the consent and the time it was given are recorded.
Every check that is started is logged (the webshop URL entered, the time, and a pseudonymous marker derived from the IP address as a salted cryptographic hash), including before you leave an email address, in order to measure use of the tool, prevent abuse and offer relevant services. The legal basis is legitimate interest (Article 6(1)(f) GDPR). The IP address is not stored in its original form, only as a salted cryptographic hash (pseudonymised). You have the right to object to this processing at any time.
2.4. Technical data
- IP address (for security and rate limiting)
- Browser and device type
- Date and time of access
2.5. Business data from public sources (B2B prospecting)
In order to offer services to relevant companies, publicly available business data is processed from official registers and public sources: the sudski registar (Croatian court register), the obrtni registar (Croatian crafts register), the Hrvatska gospodarska komora (Croatian Chamber of Economy), professional chambers, and publicly published business contact pages.
- Name, company ID, legal form, registered seat and activity
- Publicly published business contact (telephone first, email secondarily)
- Source and date of collection (for transparency)
The legal basis is legitimate interest (Article 6(1)(f) GDPR) for B2B outreach. The data is used moderately: contact is made primarily by telephone on the publicly published business number, and no unsolicited bulk marketing email is sent. The first contact states who is calling, where the contact came from and how you can object. You have the right to object to this processing at any time, after which you are permanently removed from further contact. Prospect data without an engagement is deleted after 12 months.
3. Purposes and legal bases of processing
- Answering your enquiry: processing on the basis of steps taken prior to entering into a contract (Article 6(1)(b) GDPR).
- Sending the AI report to your email: processing on the basis of your consent (Article 6(1)(a) GDPR), which you may withdraw at any time.
- Sending the webshop compliance analysis at your request: processing in order to fulfil your request (Article 6(1)(b) GDPR); this is not marketing processing.
- Marketing and educational messages (newsletter): processing on the basis of your separate consent (Article 6(1)(a) GDPR), which you may withdraw at any time with a single click.
- Site security and abuse prevention: processing on the basis of legitimate interest (Article 6(1)(f) GDPR).
- Analytics and improving the tools (measuring use of the free tools, including the URL entered and a pseudonymous marker derived from the IP address): processing on the basis of legitimate interest (Article 6(1)(f) GDPR), with a right to object.
4. Third parties that process data
Established technical partners are used to provide the service. A data processing agreement (DPA) is in place with each of them:
- Resend (USA, EU-US Data Privacy Framework): sending transactional email.
- Vercel (USA, EU-US Data Privacy Framework): hosting and CDN.
- Google (Gemini API): generating the AI analysis; the data is neither stored nor used to train models.
- Calendly (USA, EU-US Data Privacy Framework): booking calls (only if you click the link).
5. Retention periods
- Contact enquiries: 12 months from the last communication.
- AI analyses: up to 30 days, then deleted.
- Webshop compliance check (email): at most 24 months from the last contact.
- Unsubscribed contacts (suppression list): kept permanently, as evidence of your decision not to receive marketing messages.
- Tool usage records (URL entered plus the pseudonymous marker from the IP address): up to 24 months, then deleted.
- Rate-limiting records: up to 40 days.
- Technical logs: 90 days.
After those periods the data is permanently deleted, unless the law requires longer retention.
6. Your rights
Under the GDPR you have the following rights in relation to your personal data:
- Right of access (Article 15)
- Right to rectification of inaccurate data (Article 16)
- Right to erasure, the “right to be forgotten” (Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object to processing (Article 21)
- Right to withdraw consent at any time
To exercise any of these rights, write to jurica@webica.hr.
Unsubscribing from marketing messages: every marketing message contains a one-click unsubscribe link. Unsubscribing is immediate and free, and permanently excludes you from further marketing messages (transactional messages, such as an analysis you requested or a reply to your enquiry, may still arrive).
Erasure (right to be forgotten): send an erasure request by email to jurica@webica.hr from the address you used. The request is handled without undue delay and within one month at the latest, and the erasure is confirmed to you. Erasure is free; exceptionally, only data that must be kept by law (for example under accounting and tax rules) may be retained.
You also have the right to lodge a complaint with the supervisory authority: Agencija za zaštitu osobnih podataka (AZOP, the Croatian Personal Data Protection Agency), Selska cesta 136, 10000 Zagreb, azop.hr.
7. Cookies
Only essential cookies needed to run the site (session, security) are used. No analytics or marketing cookies are used, and user behaviour is not tracked between sessions.
If analytics tools are introduced in future, your consent will be requested explicitly through the cookie banner before any processing.
8. Changes to this privacy policy
This policy may be updated from time to time to keep it in line with the law or with changes in how the service works. The current version is always available on this page, and the date of the last change is given at the top of the document.
Read the terms of use as well.
This is a translation provided for convenience. The Croatian version of this privacy policy is the authoritative one: the business is registered in Croatia and the policy is interpreted under Croatian law. In case of any discrepancy, the Croatian text prevails.