Privacy Policy
This document explains what personal data we collect, why and for how long we retain it, who we share it with, and your rights. The policy applies to bandur.top and related subdomains.
Data Controller
Računalničar, Sebastijan Bandur s.p., Marjeta na Dravskem polju 39, 2206 Marjeta na Dravskem polju, Slovenia. Tax no.: 68283270. Company ID: 8839883000. Owner: Sebastijan Bandur.
For data protection questions or to exercise your rights, contact: sebastijan.bandur.sp@gmail.com.
What data we process
We only process data you explicitly submit or that is necessary to operate and secure the site:
- Contact form: name, email address, phone (optional), company (optional), selected topic, message content.
- Technical data (server logs): IP address, browser and OS information, requested URL, timestamp — used for security and abuse prevention.
- Client business data in the course of service delivery (contact person details, invoicing data).
Purposes and legal bases
- Responding to inquiries and preparing offers — basis: steps prior to entering a contract (GDPR Art. 6(1)(b)).
- Performance of contracts with clients — basis: contract performance (GDPR Art. 6(1)(b)).
- Issuing invoices and fulfilling legal obligations (tax, accounting) — basis: legal obligation (GDPR Art. 6(1)(c)).
- Preventing abuse, spam, and security incidents — basis: legitimate interest (GDPR Art. 6(1)(f)).
Retention periods
- Contact form data: until the communication is concluded or a contract is entered into; otherwise up to 12 months after the last contact.
- Client data: for the duration of the contract and in line with tax law (10 years for invoices).
- Server logs: up to 30 days, except in the event of a security incident.
Processors (recipients of data)
Some services are entrusted to contractual processors who process data on our behalf under signed DPAs:
- Cloudflare, Inc. (USA) — website hosting and Workers infrastructure. Cross-border transfers are governed by the EU-US Data Privacy Framework and SCCs.
- Resend, Inc. (USA) — delivery of email from the contact form. Governed by Standard Contractual Clauses (SCC).
- Google LLC (Google Fonts) — when loading web fonts, the visitor's IP address is transmitted to Google. No cookies are set.
International transfers
Some processors (Cloudflare, Resend, Google) are based in the USA. Transfers are governed by Standard Contractual Clauses and/or EU-US Data Privacy Framework certification.
Your rights
As a data subject, you have the right to:
- access your data,
- rectify inaccurate data,
- erase your data (right to be forgotten), where not in conflict with statutory retention,
- restrict processing,
- data portability,
- object to processing,
- lodge a complaint with a supervisory authority.
How to exercise your rights
Send a request by email to sebastijan.bandur.sp@gmail.com. We respond within 30 days at the latest. We may ask for additional proof of identity to prevent disclosure of data to unauthorized persons.
Supervisory authority
Complaints may be addressed to: Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, 1000 Ljubljana, gp.ip@ip-rs.si, www.ip-rs.si.
Changes to this policy
This privacy policy may change. The updated version will be published on this page with a new update date.