Privacy Policy

Last updated: October 2025

1. Introduction

M Consulting (“we”, “our”, “us”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect your information when you visit our website or contact us through our online forms.

We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Croatian data protection laws.

2. Data Controller

Company name: [Company name]
Address: [Address, City, Country]
Tax ID: [to be added]
Email: [email protected]
Phone: +385 91 602 1200

3. Data We Collect

We may collect and process the following categories of data:

  • Contact details – such as your name, email address, and phone number when you contact us via form or email.

  • Business information – including your company name, position, or project details if you request a consultation.

  • Technical data – such as IP address, browser type, operating system, and access times, collected automatically through analytics tools.

  • Cookies and usage data – information about your activity on our website to improve functionality and performance.

We do not collect sensitive personal data (such as political opinions, health data, or religious beliefs).

4. How We Use Your Data

Your personal data may be used for the following purposes:

  • To respond to your inquiries or service requests.

  • To provide consulting and IT-related services.

  • To improve our website, services, and user experience.

  • To comply with legal and administrative obligations.

  • To communicate updates, offers, or news (only if you have given explicit consent).

5. Legal Basis for Processing

We process your personal data under one or more of the following legal bases:

  • Your consent (Article 6(1)(a) GDPR) – when you voluntarily provide your data via a form or email.

  • Contractual necessity (Article 6(1)(b) GDPR) – to deliver requested services.

  • Legal obligation (Article 6(1)(c) GDPR) – to meet accounting or reporting duties.

  • Legitimate interest (Article 6(1)(f) GDPR) – for website improvement and service optimization.

6. Data Retention

We retain your personal data only as long as necessary to fulfill the purposes outlined above or as required by law.

When data is no longer needed, it will be securely deleted or anonymized.

7. Data Protection and Security

We use appropriate technical and organizational measures to protect your personal data against unauthorized access, disclosure, or destruction.

All website traffic is encrypted using HTTPS (SSL/TLS).

Access to personal data is limited to authorized personnel who are bound by confidentiality.

8. Data Sharing and Transfers

Your personal data may be shared only with:

  • Trusted service providers (e.g., hosting, analytics, or email providers) under strict GDPR-compliant agreements.

  • Public authorities, if required by law.

Your data is not sold or transferred to third parties for marketing purposes.

We do not transfer data outside the European Union unless adequate safeguards are in place.

9. Cookies and Analytics

Our website may use cookies to:

  • Enable basic website functionality.

  • Analyze visitor behavior to improve our site (e.g., Google Analytics).

You can adjust cookie settings in your browser or disable non-essential cookies at any time.

10. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of access – to request a copy of your personal data.

  • Right to rectification – to correct inaccurate or incomplete data.

  • Right to erasure (“right to be forgotten”) – to request deletion of your data.

  • Right to restriction of processing – to limit data use under certain conditions.

  • Right to data portability – to receive your data in a machine-readable format.

  • Right to object – to processing based on legitimate interest.

  • Right to withdraw consent – at any time without affecting prior lawful processing.

To exercise these rights, contact us at [email protected].

You also have the right to file a complaint with the Croatian Personal Data Protection Agency (AZOP) (www.azop.hr).

11. Third-Party Links

Our website may contain links to third-party websites.

We are not responsible for their content or privacy practices. Please review their respective privacy policies before providing any personal information.

12. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal obligations.

The latest version will always be available on this page, with the “Last updated” date shown at the top.

13. Contact Us

If you have any questions about this Privacy Policy or how your data is handled, please contact us at:

M Consulting d.o.o.
Email: [email protected]
Phone: +385 91 602 1200