Effective date: 1 September 2022
Last updated: 31 January 2023
Version: 2.0
INERTIKA (“INERTIKA”, “we”, “us” or “our”) provides technology consulting, business process automation, systems integration, data engineering and related professional services.
For the processing described in this Privacy Policy, the data controller is:
INERTIKA
Kolodvorska ulica 7
1000 Ljubljana
Slovenia
Email: privacy@inertika.com
General enquiries: info@inertika.com
Telephone: +386 1 777 47 37
We have not appointed a Data Protection Officer because our current processing activities do not require the mandatory appointment of a DPO under Article 37 GDPR.
Privacy-related enquiries and requests are handled by our designated privacy contact at privacy@inertika.com.
This Privacy Policy explains how we process personal data when you:
This Policy concerns processing for which INERTIKA determines the purposes and means of processing and therefore acts as a data controller.
When we process personal data contained in a client’s systems solely on the client’s instructions—for example during CRM implementation, systems integration, data migration or workflow automation—we normally act as a data processor. Such processing is governed by the relevant client agreement and Data Processing Agreement and is not governed solely by this website Privacy Policy.
Depending on how you interact with us, we may process the following categories of personal data.
When you access our website, our systems may process:
We do not use website data to create advertising profiles or to conduct cross-site behavioural advertising.
When you contact us or submit a project enquiry, we may process:
Please do not submit special-category personal data, confidential credentials, production passwords, private encryption keys, health information or government identification documents through the website contact form.
When you subscribe to communications, we may process:
In connection with our business relationships, we may process:
We generally process information relating to individuals acting in a professional capacity. Information about a legal entity is not personal data unless it relates to an identifiable natural person.
When you apply for a role or offer professional services, we may process:
Please do not provide information about health, ethnicity, religion, political views, trade-union membership or other special-category information unless it is specifically required for a lawful purpose.
For proportionate B2B business development, we may obtain limited professional information from:
This information may include a person’s name, employer, job title, professional contact details, public professional profile and apparent area of business responsibility.
We do not purchase consumer marketing databases and do not use sensitive personal data for business-development purposes.
We process personal data only where we have a recognised legal basis.
Data: IP addresses, server logs, browser and device information, security events and necessary cookies.
Purposes:
Legal basis: our legitimate interests under Article 6(1)(f) GDPR in operating and securing our website.
Retention:
Data: identity, contact details, organisation, project information and correspondence.
Purposes:
Legal bases:
Retention:
Data: business contact information, project records, correspondence, access records and contractual information.
Purposes:
Legal bases:
Retention:
Client personal data processed on behalf of a client is retained according to the client’s documented instructions and the applicable Data Processing Agreement.
Data: contact details, contracts, purchase orders, invoices, transaction information and payment status.
Purposes:
Legal bases:
Retention: normally 10 years after the end of the relevant financial year, or for any longer period required by applicable accounting, tax, litigation-hold or regulatory requirements.
Data: name, email address, subscription record and communication preferences.
Purposes:
Legal basis: consent under Article 6(1)(a) GDPR.
You may withdraw consent at any time by using the unsubscribe link in an email or contacting privacy@inertika.com. Withdrawal does not affect processing conducted lawfully before withdrawal.
Retention:
Withdrawal of consent will stop marketing communications but may not require deletion of a minimal suppression record.
Data: name, employer, job title, professional contact details, public professional information and communication history.
Purposes:
Legal basis: our legitimate interests under Article 6(1)(f) GDPR in developing our business through proportionate, relevant professional communications.
Before relying on legitimate interests, we consider:
Retention:
You have an unconditional right to object to processing for direct-marketing purposes. Once you object, we will stop using your information for that purpose.
Data: application information, CV, interview notes and professional qualifications.
Purposes:
Legal bases:
Retention:
We may process relevant records to:
Legal bases: Article 6(1)(c) and Article 6(1)(f) GDPR.
Retention: for the applicable limitation period and until any complaint, investigation, litigation or enforcement process has been finally resolved.
You are not legally required to submit a general website enquiry or subscribe to our newsletter.
Certain information may be necessary to:
Where required information is not provided, we may be unable to respond fully, prepare a proposal, grant system access, enter into a contract or deliver the requested service.
We use cookies and similar technologies only where they are necessary for the website or where you have made an appropriate choice.
These may be used to:
Strictly necessary technologies do not require consent where they are genuinely necessary to provide a service requested by the user.
Optional analytics, embedded media, maps or other third-party technologies are activated only after consent where consent is legally required.
Optional technologies may process:
You can withdraw or change your consent at any time through the website’s Cookie Settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
We do not use advertising cookies or third-party behavioural advertising pixels.
A current list of cookies, providers, purposes and durations is displayed in the website’s Cookie Settings interface. This technical inventory takes precedence over generic descriptions where the website configuration changes.
Our contact page may display an embedded Google Maps component.
Where consent is required, the map should not load until you choose to activate it. When activated, information such as your IP address, browser information and interaction with the map may be transmitted to Google.
Google may process this information as an independent controller under its own privacy documentation. We do not control Google’s independent use of information collected through Google services.
You may use the rest of our website without activating the map.
We may use Mailchimp, provided by The Rocket Science Group LLC and its affiliates within Intuit, to manage newsletter subscriptions and email delivery.
Mailchimp processes subscriber information on our behalf as a data processor, subject to contractual data-protection terms.
Information processed through Mailchimp may be stored or accessed outside the European Economic Area. The transfer safeguards described in Section 11 apply.
We do not provide subscriber lists to unrelated third parties for their own marketing.
We may disclose personal data to the following categories of recipients where necessary:
Service providers acting as processors may process personal data only under documented instructions, for agreed purposes and subject to contractual confidentiality and security requirements.
We do not sell personal data.
We do not disclose personal data to data brokers or permit third parties to use our contact database for their independent advertising.
Where we engage a subcontractor to process client personal data, we do so in accordance with the applicable client agreement and Article 28 GDPR.
Where required, we will:
A client-specific subprocessor list is provided in the applicable Data Processing Agreement, security documentation or project documentation.
The subprocessor list for client delivery may differ from the providers used solely for operating this public website.
We aim to process and store personal data within the European Economic Area wherever commercially and technically reasonable.
Some service providers or their support personnel may process or access personal data from countries outside the EEA.
Where personal data is transferred outside the EEA, we rely on one or more lawful transfer mechanisms, as applicable:
Where a US recipient is validly covered by the EU–US Data Privacy Framework, we may rely on the applicable European Commission adequacy decision. Where that mechanism does not cover a transfer, we use another valid mechanism, such as Standard Contractual Clauses.
You may request information about the transfer mechanism relevant to your personal data and, where available, a copy of the applicable safeguards by contacting privacy@inertika.com. Commercially confidential information may be redacted where permitted, but the substance of the safeguards will remain available.
We apply technical and organisational measures proportionate to the nature of the data, the processing context and the relevant risks.
Depending on the relevant system, these measures include:
No system is completely secure. We therefore cannot guarantee absolute security, but we regularly review whether the measures used remain appropriate.
You must not send passwords, authentication tokens, private keys or unrestricted production database exports through ordinary email or the public contact form.
We maintain procedures to assess and respond to suspected personal-data breaches.
Where a breach is likely to result in a risk to individuals’ rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of it.
Where a breach is likely to result in a high risk to affected individuals, we will also communicate the breach to those individuals without undue delay, unless an applicable exception permits otherwise.
When we act as a processor for a client, we notify the client without undue delay in accordance with the applicable Data Processing Agreement.
We do not make decisions producing legal effects, or similarly significant effects, about website visitors, subscribers, prospects or applicants solely through automated processing within the meaning of Article 22 GDPR.
We do not use personal data collected through this website to train general-purpose artificial-intelligence models.
We may use ordinary software automation to:
Such automation does not independently make legally or similarly significant decisions about individuals.
Our website and ordinary business-development processes are not intended to collect:
If such information is received unexpectedly, we will assess whether it should be securely deleted, restricted or processed under an applicable legal basis and safeguard.
Client project data may contain special-category information only where the client has lawfully instructed us to process it and the processing is governed by an appropriate Data Processing Agreement and security requirements.
Our website and services are intended for business and professional audiences and are not directed at children.
We do not knowingly collect personal data directly from children through newsletter or project-enquiry functions.
If we become aware that a child has submitted personal data without an appropriate legal basis, we will take reasonable steps to delete it.
Subject to the conditions and limitations in applicable law, you have the right to:
These rights are not absolute. For example, we may retain information where necessary to comply with a legal obligation, establish or defend a legal claim, respect another person’s rights, or maintain a record of a marketing objection.
To exercise your rights, contact:
privacy@inertika.com
Please describe:
We may request limited additional information where reasonably necessary to verify identity and prevent unauthorised disclosure. We will not request more identity information than is proportionate to the risk.
We normally respond within one month after receiving a valid request. Where a request is complex or multiple requests have been submitted, this period may be extended by up to two additional months. If an extension is required, we will inform you within the initial one-month period.
Requests are normally handled free of charge. Where a request is manifestly unfounded or excessive, particularly because it is repetitive, we may charge a reasonable administrative fee or refuse to act, as permitted by law.
Where we process personal data based on legitimate interests, you may object for reasons relating to your particular situation.
We will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.
For direct marketing, your right to object is unconditional. If you object to direct marketing, we will stop processing your personal data for that purpose.
We encourage you to contact privacy@inertika.com first so that we can investigate and address your concern.
You also have the right to lodge a complaint with the Slovenian supervisory authority:
Information Commissioner of the Republic of Slovenia
Dunajska cesta 22
1000 Ljubljana
Slovenia
Telephone: +386 1 230 97 30
Email: gp.ip@ip-rs.si
You may also complain to the competent data-protection authority in the EU or EEA Member State of your habitual residence, place of work or the place of the alleged infringement.
Our website may contain links to third-party websites and professional platforms.
When you leave our website or interact directly with a third party, that third party may process personal data under its own privacy terms. We are not responsible for processing independently determined by third-party controllers.
Our presence on LinkedIn and other professional platforms does not mean that we control all processing performed by the platform.
Messages sent directly to our company account may also be processed by us for communication and relationship-management purposes.
We may update this Privacy Policy to reflect:
The current version will be published on this page with its effective date and version number.
Where a change materially affects processing based on consent, we will obtain new consent where required.
Where reasonably appropriate, we will provide additional notice of material changes through the website or direct communication.
Questions, objections and requests concerning personal data should be sent to:
privacy@inertika.com
General business enquiries may be sent to:
info@inertika.com
For security incidents involving INERTIKA systems or credentials, contact:
security@inertika.com
Please do not include passwords, private keys or unnecessary sensitive personal data in an ordinary email.