Privacy Policy

Effective date: 1 September 2022
Last updated: 31 January 2023
Version: 2.0

1. Who We Are

INERTIKA (“INERTIKA”, “we”, “us” or “our”) provides technology consulting, business process automation, systems integration, data engineering and related professional services.

For the processing described in this Privacy Policy, the data controller is:

INERTIKA
Kolodvorska ulica 7
1000 Ljubljana
Slovenia

Email: privacy@inertika.com
General enquiries: info@inertika.com
Telephone: +386 1 777 47 37

We have not appointed a Data Protection Officer because our current processing activities do not require the mandatory appointment of a DPO under Article 37 GDPR.

Privacy-related enquiries and requests are handled by our designated privacy contact at privacy@inertika.com.

2. Scope of This Privacy Policy

This Privacy Policy explains how we process personal data when you:

  • visit inertika.com;
  • contact us through our website, email, telephone or social media;
  • subscribe to our newsletter or business updates;
  • communicate with us concerning a potential project;
  • become or represent a client, supplier, partner or subcontractor;
  • attend one of our meetings, webinars or events;
  • apply for a position or submit professional information to us;
  • interact with our business development activities.

This Policy concerns processing for which INERTIKA determines the purposes and means of processing and therefore acts as a data controller.

When we process personal data contained in a client’s systems solely on the client’s instructions—for example during CRM implementation, systems integration, data migration or workflow automation—we normally act as a data processor. Such processing is governed by the relevant client agreement and Data Processing Agreement and is not governed solely by this website Privacy Policy.

3. Personal Data We Process

Depending on how you interact with us, we may process the following categories of personal data.

3.1 Website and device data

When you access our website, our systems may process:

  • IP address;
  • date and time of access;
  • requested page or resource;
  • referring page;
  • browser type and version;
  • device and operating-system information;
  • language and approximate regional settings;
  • server response status;
  • security and diagnostic information;
  • cookie and consent preferences.

We do not use website data to create advertising profiles or to conduct cross-site behavioural advertising.

3.2 Enquiry and project-discussion data

When you contact us or submit a project enquiry, we may process:

  • name;
  • professional email address;
  • telephone number;
  • employer or organisation;
  • job title or professional function;
  • country or region;
  • selected service or area of interest;
  • proposed project scope;
  • budget or timeline information voluntarily provided by you;
  • correspondence and meeting notes;
  • any other information included in your message.

Please do not submit special-category personal data, confidential credentials, production passwords, private encryption keys, health information or government identification documents through the website contact form.

3.3 Newsletter and marketing-preference data

When you subscribe to communications, we may process:

  • name;
  • email address;
  • employer or professional affiliation;
  • subscription date and source;
  • consent record;
  • email delivery status;
  • unsubscribe and suppression status;
  • limited engagement data, such as whether an email was delivered or a link was selected, where permitted and appropriately disclosed.

3.4 Client, partner and supplier data

In connection with our business relationships, we may process:

  • business contact details;
  • job title and organisational role;
  • contractual correspondence;
  • meeting records;
  • project responsibilities;
  • access-authorisation records;
  • statements of work and acceptance records;
  • billing and payment administration data;
  • professional qualifications;
  • supplier due-diligence information;
  • support and incident correspondence.

We generally process information relating to individuals acting in a professional capacity. Information about a legal entity is not personal data unless it relates to an identifiable natural person.

3.5 Recruitment data

When you apply for a role or offer professional services, we may process:

  • name and contact details;
  • CV or résumé;
  • employment and education history;
  • portfolio and professional profiles;
  • technical qualifications and certifications;
  • salary or rate expectations;
  • location and work-authorisation information;
  • interview notes;
  • references, where requested with appropriate notice;
  • communications concerning the application.

Please do not provide information about health, ethnicity, religion, political views, trade-union membership or other special-category information unless it is specifically required for a lawful purpose.

3.6 Business-development data obtained from other sources

For proportionate B2B business development, we may obtain limited professional information from:

  • company websites;
  • professional networking platforms such as LinkedIn;
  • public business directories;
  • event attendee information lawfully made available to participants;
  • referrals and business introductions;
  • an individual’s employer or professional colleagues;
  • existing business records.

This information may include a person’s name, employer, job title, professional contact details, public professional profile and apparent area of business responsibility.

We do not purchase consumer marketing databases and do not use sensitive personal data for business-development purposes.

4. Purposes, Legal Bases and Retention Periods

We process personal data only where we have a recognised legal basis.

4.1 Operating and securing the website

Data: IP addresses, server logs, browser and device information, security events and necessary cookies.

Purposes:

  • delivering website content;
  • maintaining availability and performance;
  • detecting abuse, malicious traffic and technical failures;
  • investigating security incidents;
  • recording cookie choices.

Legal basis: our legitimate interests under Article 6(1)(f) GDPR in operating and securing our website.

Retention:

  • ordinary web-server logs: up to 30 days;
  • security-event logs: up to 180 days;
  • records connected with a confirmed security incident: for the duration of the investigation and up to 5 years after closure where necessary to establish, exercise or defend legal claims;
  • cookie-consent records: up to 12 months after the relevant choice, unless renewed earlier.

4.2 Responding to enquiries

Data: identity, contact details, organisation, project information and correspondence.

Purposes:

  • responding to your request;
  • arranging meetings;
  • assessing project feasibility;
  • preparing a proposal or statement of work;
  • taking steps requested by you before entering into a contract.

Legal bases:

  • Article 6(1)(b) GDPR where processing is necessary to take steps at your request before entering into a contract;
  • Article 6(1)(f) GDPR where you represent an organisation and the prospective contract would be with that organisation.

Retention:

  • enquiries that do not result in a commercial relationship: 24 months after the last substantive communication;
  • proposals and negotiations: 36 months after the proposal is closed or abandoned;
  • records required for legal claims: up to 5 years after the relevant matter ends, or longer where required by applicable law.

4.3 Delivering services and managing client relationships

Data: business contact information, project records, correspondence, access records and contractual information.

Purposes:

  • entering into and performing contracts;
  • project planning and delivery;
  • account and relationship management;
  • support and issue resolution;
  • quality control;
  • documenting instructions, approvals and acceptance;
  • protecting our contractual and legal rights.

Legal bases:

  • Article 6(1)(b) GDPR where the individual is a party to the contract;
  • Article 6(1)(f) GDPR for contacts representing corporate clients, partners or suppliers;
  • Article 6(1)(c) GDPR where processing is required by law.

Retention:

  • active project and relationship records: for the duration of the relationship;
  • operational project records: 5 years after project completion;
  • contracts, material instructions, approvals and acceptance records: 10 years after termination or completion where needed for compliance or legal claims;
  • production credentials supplied for a project: only for as long as operationally required and deleted or returned promptly following completion of the relevant task;
  • access and audit records: normally 12 months, or longer where a security, contractual or regulatory investigation requires retention.

Client personal data processed on behalf of a client is retained according to the client’s documented instructions and the applicable Data Processing Agreement.

4.4 Financial administration and legal compliance

Data: contact details, contracts, purchase orders, invoices, transaction information and payment status.

Purposes:

  • billing and payment administration;
  • bookkeeping;
  • tax and accounting compliance;
  • fraud prevention;
  • audits;
  • responding to lawful authority requests.

Legal bases:

  • Article 6(1)(c) GDPR for legal obligations;
  • Article 6(1)(b) GDPR for contractual administration;
  • Article 6(1)(f) GDPR for fraud prevention and the establishment, exercise or defence of legal claims.

Retention: normally 10 years after the end of the relevant financial year, or for any longer period required by applicable accounting, tax, litigation-hold or regulatory requirements.

4.5 Newsletter and requested communications

Data: name, email address, subscription record and communication preferences.

Purposes:

  • sending newsletters, insights and service updates requested by you;
  • maintaining evidence of consent;
  • processing unsubscribe requests.

Legal basis: consent under Article 6(1)(a) GDPR.

You may withdraw consent at any time by using the unsubscribe link in an email or contacting privacy@inertika.com. Withdrawal does not affect processing conducted lawfully before withdrawal.

Retention:

  • active subscriber information: until consent is withdrawn or the subscription becomes permanently inactive;
  • unconfirmed subscriptions: deleted after 30 days;
  • consent evidence and unsubscribe records: up to 5 years after withdrawal or the last communication;
  • minimal suppression data: retained for as long as reasonably necessary to ensure that we respect the unsubscribe request.

Withdrawal of consent will stop marketing communications but may not require deletion of a minimal suppression record.

4.6 Proportionate B2B business development

Data: name, employer, job title, professional contact details, public professional information and communication history.

Purposes:

  • identifying organisations that may have a genuine need for our services;
  • contacting appropriate professional representatives;
  • maintaining business relationships;
  • preventing repeated or irrelevant communications;
  • recording objections.

Legal basis: our legitimate interests under Article 6(1)(f) GDPR in developing our business through proportionate, relevant professional communications.

Before relying on legitimate interests, we consider:

  • the relationship between the communication and the person’s professional role;
  • the relevance of the proposed service;
  • the source of the information;
  • the reasonable expectations of the person;
  • the frequency and intrusiveness of contact;
  • the person’s right to object.

Retention:

  • unresponsive prospect records: no longer than 12 months after collection or the last communication;
  • records of an active professional discussion: up to 24 months after the last substantive communication;
  • objection or do-not-contact records: retained for as long as reasonably necessary to respect the objection.

You have an unconditional right to object to processing for direct-marketing purposes. Once you object, we will stop using your information for that purpose.

4.7 Recruitment

Data: application information, CV, interview notes and professional qualifications.

Purposes:

  • assessing suitability;
  • arranging interviews;
  • communicating about the application;
  • verifying information where appropriate;
  • preparing an employment or contractor offer;
  • defending recruitment-related legal claims.

Legal bases:

  • Article 6(1)(b) GDPR for steps requested before entering into an employment or services contract;
  • Article 6(1)(f) GDPR for recruitment administration and legal claims;
  • Article 6(1)(a) GDPR where you separately consent to consideration for future opportunities;
  • Article 6(1)(c) GDPR where employment law requires processing.

Retention:

  • unsuccessful applications: 6 months after the recruitment decision;
  • applications retained for future opportunities with consent: up to 24 months;
  • successful candidate records: transferred to the relevant personnel or contractor record and retained under the applicable employment or services retention schedule.

4.8 Legal claims, disputes and compliance investigations

We may process relevant records to:

  • establish facts;
  • obtain professional advice;
  • enforce contractual rights;
  • respond to complaints;
  • establish, exercise or defend legal claims;
  • cooperate with competent authorities.

Legal bases: Article 6(1)(c) and Article 6(1)(f) GDPR.

Retention: for the applicable limitation period and until any complaint, investigation, litigation or enforcement process has been finally resolved.

5. Whether You Must Provide Personal Data

You are not legally required to submit a general website enquiry or subscribe to our newsletter.

Certain information may be necessary to:

  • respond to a request;
  • assess a proposed project;
  • enter into or perform a contract;
  • verify authority to access a client system;
  • comply with accounting, tax, sanctions-screening or other legal requirements.

Where required information is not provided, we may be unable to respond fully, prepare a proposal, grant system access, enter into a contract or deliver the requested service.

6. Cookies and Similar Technologies

We use cookies and similar technologies only where they are necessary for the website or where you have made an appropriate choice.

6.1 Strictly necessary technologies

These may be used to:

  • maintain website security;
  • distribute traffic;
  • operate forms;
  • prevent spam or abuse;
  • remember privacy and cookie choices.

Strictly necessary technologies do not require consent where they are genuinely necessary to provide a service requested by the user.

6.2 Optional technologies

Optional analytics, embedded media, maps or other third-party technologies are activated only after consent where consent is legally required.

Optional technologies may process:

  • IP address;
  • browser and device information;
  • page or content interaction;
  • cookie identifiers;
  • approximate location derived from the IP address.

You can withdraw or change your consent at any time through the website’s Cookie Settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

We do not use advertising cookies or third-party behavioural advertising pixels.

A current list of cookies, providers, purposes and durations is displayed in the website’s Cookie Settings interface. This technical inventory takes precedence over generic descriptions where the website configuration changes.

7. Embedded Google Maps

Our contact page may display an embedded Google Maps component.

Where consent is required, the map should not load until you choose to activate it. When activated, information such as your IP address, browser information and interaction with the map may be transmitted to Google.

Google may process this information as an independent controller under its own privacy documentation. We do not control Google’s independent use of information collected through Google services.

You may use the rest of our website without activating the map.

8. Newsletter Service Provider

We may use Mailchimp, provided by The Rocket Science Group LLC and its affiliates within Intuit, to manage newsletter subscriptions and email delivery.

Mailchimp processes subscriber information on our behalf as a data processor, subject to contractual data-protection terms.

Information processed through Mailchimp may be stored or accessed outside the European Economic Area. The transfer safeguards described in Section 11 apply.

We do not provide subscriber lists to unrelated third parties for their own marketing.

9. Recipients of Personal Data

We may disclose personal data to the following categories of recipients where necessary:

  • website-hosting and infrastructure providers;
  • email, productivity and document-management providers;
  • CRM and business-operations providers;
  • newsletter and communication providers;
  • project-management, support and collaboration providers;
  • cybersecurity, logging, backup and fraud-prevention providers;
  • professional advisers, including lawyers, accountants and auditors;
  • banks and payment-service providers;
  • subcontractors approved for a relevant client project;
  • clients where disclosure is required for project delivery;
  • public authorities, courts or regulators where legally required;
  • potential parties to a corporate transaction, subject to appropriate confidentiality safeguards.

Service providers acting as processors may process personal data only under documented instructions, for agreed purposes and subject to contractual confidentiality and security requirements.

We do not sell personal data.

We do not disclose personal data to data brokers or permit third parties to use our contact database for their independent advertising.

10. Subcontractors Used in Client Projects

Where we engage a subcontractor to process client personal data, we do so in accordance with the applicable client agreement and Article 28 GDPR.

Where required, we will:

  • obtain the client’s prior specific or general written authorisation;
  • identify the relevant subcontractor;
  • impose data-protection obligations equivalent to those applicable to us;
  • remain responsible for the subcontractor’s performance of those obligations;
  • provide notice of intended changes where general authorisation applies.

A client-specific subprocessor list is provided in the applicable Data Processing Agreement, security documentation or project documentation.

The subprocessor list for client delivery may differ from the providers used solely for operating this public website.

11. International Data Transfers

We aim to process and store personal data within the European Economic Area wherever commercially and technically reasonable.

Some service providers or their support personnel may process or access personal data from countries outside the EEA.

Where personal data is transferred outside the EEA, we rely on one or more lawful transfer mechanisms, as applicable:

  • a European Commission adequacy decision under Article 45 GDPR;
  • European Commission Standard Contractual Clauses under Article 46 GDPR;
  • supplementary technical, contractual or organisational measures where appropriate;
  • Binding Corporate Rules;
  • a specific statutory derogation under Article 49 GDPR, used only where its conditions are satisfied.

Where a US recipient is validly covered by the EU–US Data Privacy Framework, we may rely on the applicable European Commission adequacy decision. Where that mechanism does not cover a transfer, we use another valid mechanism, such as Standard Contractual Clauses.

You may request information about the transfer mechanism relevant to your personal data and, where available, a copy of the applicable safeguards by contacting privacy@inertika.com. Commercially confidential information may be redacted where permitted, but the substance of the safeguards will remain available.

12. Data Security

We apply technical and organisational measures proportionate to the nature of the data, the processing context and the relevant risks.

Depending on the relevant system, these measures include:

  • encrypted HTTPS connections;
  • access control based on business need;
  • individual user accounts;
  • multi-factor authentication for material business systems;
  • password-management requirements;
  • restricted administrative privileges;
  • confidentiality obligations;
  • secure configuration and patch management;
  • logging and monitoring;
  • encrypted or access-controlled backups;
  • vendor and subprocessor review;
  • incident-response procedures;
  • periodic access review;
  • secure deletion or return of project data;
  • staff privacy and security training.

No system is completely secure. We therefore cannot guarantee absolute security, but we regularly review whether the measures used remain appropriate.

You must not send passwords, authentication tokens, private keys or unrestricted production database exports through ordinary email or the public contact form.

13. Personal Data Breaches

We maintain procedures to assess and respond to suspected personal-data breaches.

Where a breach is likely to result in a risk to individuals’ rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of it.

Where a breach is likely to result in a high risk to affected individuals, we will also communicate the breach to those individuals without undue delay, unless an applicable exception permits otherwise.

When we act as a processor for a client, we notify the client without undue delay in accordance with the applicable Data Processing Agreement.

14. Automated Decision-Making and Profiling

We do not make decisions producing legal effects, or similarly significant effects, about website visitors, subscribers, prospects or applicants solely through automated processing within the meaning of Article 22 GDPR.

We do not use personal data collected through this website to train general-purpose artificial-intelligence models.

We may use ordinary software automation to:

  • route contact enquiries;
  • detect spam or malicious traffic;
  • schedule communications;
  • classify operational requests;
  • identify technical errors.

Such automation does not independently make legally or similarly significant decisions about individuals.

15. Special-Category and Criminal-Offence Data

Our website and ordinary business-development processes are not intended to collect:

  • health information;
  • biometric identifiers;
  • racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade-union membership;
  • information concerning sex life or sexual orientation;
  • criminal-conviction or offence data.

If such information is received unexpectedly, we will assess whether it should be securely deleted, restricted or processed under an applicable legal basis and safeguard.

Client project data may contain special-category information only where the client has lawfully instructed us to process it and the processing is governed by an appropriate Data Processing Agreement and security requirements.

16. Children

Our website and services are intended for business and professional audiences and are not directed at children.

We do not knowingly collect personal data directly from children through newsletter or project-enquiry functions.

If we become aware that a child has submitted personal data without an appropriate legal basis, we will take reasonable steps to delete it.

17. Your Rights

Subject to the conditions and limitations in applicable law, you have the right to:

  • obtain confirmation as to whether we process your personal data;
  • obtain access to your personal data;
  • correct inaccurate or incomplete personal data;
  • request erasure of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • object at any time to processing for direct-marketing purposes;
  • receive qualifying data in a structured, commonly used and machine-readable format;
  • request transmission of qualifying data to another controller where technically feasible;
  • withdraw consent at any time;
  • receive information about safeguards used for qualifying international transfers;
  • lodge a complaint with a supervisory authority;
  • obtain human intervention where a qualifying solely automated decision is used.

These rights are not absolute. For example, we may retain information where necessary to comply with a legal obligation, establish or defend a legal claim, respect another person’s rights, or maintain a record of a marketing objection.

18. Exercising Your Rights

To exercise your rights, contact:

privacy@inertika.com

Please describe:

  • the right you wish to exercise;
  • the relevant interaction or service;
  • the email address or other identifier likely to be associated with the data.

We may request limited additional information where reasonably necessary to verify identity and prevent unauthorised disclosure. We will not request more identity information than is proportionate to the risk.

We normally respond within one month after receiving a valid request. Where a request is complex or multiple requests have been submitted, this period may be extended by up to two additional months. If an extension is required, we will inform you within the initial one-month period.

Requests are normally handled free of charge. Where a request is manifestly unfounded or excessive, particularly because it is repetitive, we may charge a reasonable administrative fee or refuse to act, as permitted by law.

19. Right to Object

Where we process personal data based on legitimate interests, you may object for reasons relating to your particular situation.

We will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.

For direct marketing, your right to object is unconditional. If you object to direct marketing, we will stop processing your personal data for that purpose.

20. Complaints

We encourage you to contact privacy@inertika.com first so that we can investigate and address your concern.

You also have the right to lodge a complaint with the Slovenian supervisory authority:

Information Commissioner of the Republic of Slovenia
Dunajska cesta 22
1000 Ljubljana
Slovenia

Telephone: +386 1 230 97 30
Email: gp.ip@ip-rs.si

You may also complain to the competent data-protection authority in the EU or EEA Member State of your habitual residence, place of work or the place of the alleged infringement.

21. Third-Party Websites and Social Media

Our website may contain links to third-party websites and professional platforms.

When you leave our website or interact directly with a third party, that third party may process personal data under its own privacy terms. We are not responsible for processing independently determined by third-party controllers.

Our presence on LinkedIn and other professional platforms does not mean that we control all processing performed by the platform.

Messages sent directly to our company account may also be processed by us for communication and relationship-management purposes.

22. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • changes to our processing activities;
  • new services or providers;
  • changes in law or regulatory guidance;
  • security or operational improvements.

The current version will be published on this page with its effective date and version number.

Where a change materially affects processing based on consent, we will obtain new consent where required.

Where reasonably appropriate, we will provide additional notice of material changes through the website or direct communication.

23. Contact

Questions, objections and requests concerning personal data should be sent to:

privacy@inertika.com

General business enquiries may be sent to:

info@inertika.com

For security incidents involving INERTIKA systems or credentials, contact:

security@inertika.com

Please do not include passwords, private keys or unnecessary sensitive personal data in an ordinary email.