Privacy policy

How stjepantafra.com handles data from contact enquiries, email, technical logs and essential cookies.

Last updated: 8 August 2026.

This policy explains how personal data is handled when you visit stjepantafra.com, submit its contact form or contact the studio by email. It applies only to this website and direct communication related to its services.

Controller and contact

The controller for the data described in this policy is Stjepan Tafra, stjepantafra.com. For privacy questions or to exercise your rights, email info@stjepantafra.com. The full business identity and postal address must be confirmed and added before this policy is published in production.

Contact form

When you submit the form, the website processes your name, email address, selected project type and project description. Approximate timing and investment range are optional. Please do not include sensitive personal data or information about other people unless it is necessary for the enquiry.

This information is used to receive and understand your enquiry, reply to it, assess whether the studio can help and, if requested, prepare next steps or a proposal. The legal bases are taking steps at your request before potentially entering into a contract (Article 6(1)(b) GDPR) and the legitimate interests of managing business communication and protecting the form from misuse (Article 6(1)(f) GDPR). Enquiry details are not used for marketing messages without a separate legal basis.

Direct email

If you contact the studio directly by email, the email address, name if provided, message content, attachments and standard email metadata are processed. The purposes and legal bases are the same as for the contact form: responding to your request, discussing a possible project and maintaining necessary business communication.

Technical logs

The web server and security tools may automatically record an IP address, date and time of a request, requested URL, browser or device type, referring page and information about errors or suspicious requests. Logs are used only as needed to operate and secure the website, prevent misuse and diagnose technical problems. The legal basis is the legitimate interest in providing a safe and reliable website. These logs are not used to build marketing profiles.

Cookies, local storage and analytics

The website may use technically essential cookies or local storage to operate correctly, protect forms, retain the selected language or remember basic settings. WordPress, WPML or the contact form plugin may set a technical record only when a requested function requires it.

Essential technologies are not used for advertising and cannot be disabled through the website settings because the relevant function may not work without them.

\n\n\n\n

Google Analytics, installed through the Google Site Kit plugin, is used to measure visits only when you consent to the Statistics category. Google Consent Mode initially sets optional storage to denied for every location. Analytics cookies such as _ga and _ga_* are not set before consent. You can change or withdraw your choice at any time in the cookie settings; withdrawal denies analytics storage again and removes this website’s analytics cookies.

\n\n\n\n

When consent is denied, the Google tag may send limited technical and consent-state signals without analytics cookies. The website does not use these signals to recognise visitors through analytics cookies. The legal basis for optional analytics storage and measurement is consent (Article 6(1)(a) GDPR and applicable electronic communications rules). Advertising services are not currently used; introducing them would require separate consent to the Marketing category and an update to this policy. More information is available in Google’s Privacy Policy.

\n\n

\n\n\n

Who may access the data

Form enquiries are delivered to the studio’s Gmail address, so the message and enquiry data are stored and processed in Google’s Gmail service. Google states that email content is stored in its data centres and that information may be processed on servers in different countries. For users in the European Economic Area, Google identifies Google Ireland Limited as the controller of its own processing. More information about that processing, transfers and controls is available in Google’s Privacy Policy.

The hosting provider and the person maintaining the website may also have access when this is necessary to deliver a message, secure the website or diagnose a technical problem. The exact production providers, their roles and the applicable transfer mechanisms must be confirmed before this policy is published. Personal data is not sold.

How long data is retained

The proposed criterion is to keep contact enquiries and emails while the enquiry is handled and afterwards only for as long as reasonably necessary for an agreed or possible collaboration, business records, the protection of legal claims or compliance with legal obligations. When there is no longer a justified need for the correspondence, it should be deleted or anonymised. Before production, the owner must confirm the actual review and deletion routine for Gmail messages. Information that becomes part of contractual or accounting records is kept for the periods required by applicable rules.

The retention period for technical logs and backups depends on the active hosting configuration. The specific log-retention period and backup replacement cycle must be confirmed before this policy is published in production.

Your rights

Depending on the circumstances, you may request access to your data, correction of inaccurate data, erasure, restriction of processing or data portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw that consent without affecting the lawfulness of earlier processing.

Send a request to info@stjepantafra.com. Reasonable proof of identity may be requested before responding so that data is not disclosed to an unauthorised person. You also have the right to complain to the Croatian Personal Data Protection Agency (azop.hr) or another competent supervisory authority.

Security and policy changes

Reasonable technical and organisational measures appropriate to this type of website and communication are used. No transmission or storage system is entirely risk-free, so please do not send information that is not needed for a project enquiry.

This policy may change when the website’s functions, service providers or applicable requirements change. The current version and its update date will always be published on this page.

New project

Your story, professionally crafted — with a personal approach.

Tell me about your project