Who we are
IDDQD d.o.o. (“IDDQD”, “we”, “us”) is the data controller for the personal data described in this policy. We are a Croatian limited liability company; see our Company Information page for our full registered details.
Contact: info@iddqd.hr
We have not appointed a formal Data Protection Officer, as it is not required for a company of our size and processing activities under Art. 37 GDPR. Direct any data-protection question or request to the email address above.
What this policy covers
This policy covers two things:
- This website (iddqd.hr) — a static, informational site with no cookies, no analytics, no tracking, and no contact form.
- Every application you can sign in to with a Google, Microsoft or GitHub account through our shared sign-in service at
auth.iddqd.hr. We operate a family of business and compliance applications for Croatian organisations, such as regulatory-monitoring and compliance-management tools. Rather than list each application by name here, this policy describes the sign-in and account data that is common to all of them; an individual application may publish additional, application-specific terms alongside this policy.
Personal data we process
On this website
The website itself collects nothing from you directly. It sets no cookies and runs no analytics or advertising scripts. There is no contact form; the only way to reach us is by emailing the address above.
The site is hosted on Microsoft Azure Static Web Apps. As with any web hosting, the hosting infrastructure necessarily records standard server/access logs for every request — typically the visitor’s IP address, the date and time of the request, the page requested, and the browser’s user-agent string. We do not collect this as a separate choice; it is an unavoidable, low-level by-product of serving web pages over the internet, and we do not combine it with any other data about you. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest, and Microsoft’s, in operating, securing and troubleshooting the hosting infrastructure). Microsoft acts as our processor under its Data Protection Addendum. Static Web Apps serves pages from Microsoft’s global network, so these logs may be processed outside the European Economic Area; any such transfer is covered by the EU Standard Contractual Clauses in that addendum and by Microsoft’s certification under the EU–U.S. Data Privacy Framework.
When you sign in to an IDDQD application
When you sign in to one of our applications using Google, Microsoft or GitHub, the provider you choose shares the following with us, with your permission, at the moment you sign in:
- your name,
- your email address, and
- your profile picture (where the provider makes one available).
We use this information only to create and operate your account with the application you are signing in to — to identify you, to let you sign back in, and to show your name and picture inside the application. We do not use it for advertising, and we do not sell it.
We never receive your password from Google, Microsoft or GitHub, and we cannot see it. Sign-in is handled by our authentication service at auth.iddqd.hr; the provider you choose authenticates you and tells our service who you are, without ever sharing your credentials with us.
Depending on the specific application, it may ask you for further information once you are signed in — for example, business details needed to provide a compliance service to a particular Croatian organisation. That information is described in the application itself, not in this general policy.
Google API Services User Data Policy
Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Legal basis for processing
| Purpose | Legal basis (Art. 6(1) GDPR) |
|---|---|
| Creating and operating your account after sign-in | (b) — necessary to perform the contract for the application you sign in to |
| Server/access logs generated by hosting | (f) — legitimate interest in operating and securing the infrastructure |
| Responding to an email you send us | (b) or (f), depending on what you ask |
We do not sell or share your data
We do not sell personal data, and we do not share the data described above with third parties for their own marketing purposes. Personal data is shared only with the processors and identity providers described below, strictly to provide the service.
Who else processes data in connection with our services
| Recipient | Role | What they process |
|---|---|---|
| Microsoft (Azure Static Web Apps) | Hosting provider (processor) | Server/access logs for this website |
| Google LLC | Identity provider, and independent controller for its own sign-in service | Confirms your identity and shares your name, email and profile picture with us, if you choose to sign in with Google |
| Microsoft Corporation | Identity provider, and independent controller for its own sign-in service | Confirms your identity and shares your name, email and profile picture with us, if you choose to sign in with Microsoft |
| GitHub, Inc. | Identity provider, and independent controller for its own sign-in service | Confirms your identity and shares your name, email and profile picture with us, if you choose to sign in with GitHub |
Google, Microsoft and GitHub each act as an independent data controller for the sign-in service they provide; their own privacy policies govern what they do with your data before it reaches us.
International transfers
Google, Microsoft and GitHub are global providers, and personal data may be processed outside the European Economic Area. Where that happens, each provider relies on its own safeguards — such as an EU adequacy decision (for example, the EU-U.S. Data Privacy Framework) or the European Commission’s Standard Contractual Clauses — to protect the transfer. See each provider’s own policy for details: Google, Microsoft, GitHub.
How long we keep your data
- Account data from sign-in (name, email, profile picture): kept for as long as your account with the relevant application is active. If you do not sign in for 24 consecutive months, or if you ask us to delete your account, we delete this data within 30 days.
- Server/access logs from hosting this website: kept for a short operational period, typically no more than 30 days, and then deleted or anonymised.
- Records an individual application is legally required to keep for longer — for example, under Croatian accounting or tax law — are retained only for the period the law requires, and only within that application; this general policy does not shorten a retention period set by law.
Deleting your data
To have your account and associated personal data deleted, email info@iddqd.hr from the address associated with your account, naming the application you used. We will confirm your identity and delete the data within 30 days, except where we are legally required to keep specific records for longer (see above).
Your rights
As a data subject under the GDPR, you have the right to:
- Access the personal data we hold about you (Art. 15);
- Rectify inaccurate or incomplete data (Art. 16);
- Erasure (“the right to be forgotten”) of your data (Art. 17);
- Restrict our processing of your data in certain circumstances (Art. 18);
- Data portability — receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible (Art. 20);
- Object to processing based on our legitimate interest (Art. 21);
- Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before the withdrawal (Art. 7(3)).
To exercise any of these rights, email info@iddqd.hr. We will respond within one month, as required by Art. 12(3) GDPR.
Automated decision-making
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you (Art. 22 GDPR).
Children
Our applications are intended for business and professional use and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact info@iddqd.hr and we will delete it.
Right to complain to the supervisory authority
If you believe we have processed your personal data unlawfully, you have the right to lodge a complaint with the Croatian data protection authority:
Agencija za zaštitu osobnih podataka (AZOP) Ulica Metela Ožegovića 16, 10000 Zagreb, Croatia Email: azop@azop.hr — Website: www.azop.hr
This is without prejudice to any other administrative or judicial remedy.
Changes to this policy
We may update this policy from time to time — for example, when we add a new sign-in provider or change hosting arrangements. We will update the date at the top of this page when we do. If a change is significant, we will take reasonable steps to make it noticeable, such as a notice within the affected application.
Contact
IDDQD d.o.o. — info@iddqd.hr. Full company details: Company Information.