Data Protection Protocol
JURISDICTION: REPUBLIC OF SLOVENIA [EU]
// 01. Introduction
This Data Protection Protocol defines the parameters under which Oriney, računalniško programiranje, Rok Slemenik s.p. ("we", "us", or "our") processes information. We operate under the strict jurisdiction of the Republic of Slovenia and adhere to the General Data Protection Regulation (GDPR).
We do not traffic in user data. We collect only the minimum telemetry required to establish communication and ensure system integrity.
// 02. Data Collection & Infrastructure
We collect data through three primary vectors:
- [VOL] Voluntary Transmission: Information you explicitly provide via our command terminal (contact form), specifically: Name, Email Address, and Project Brief.
- [SYS] System Telemetry: Technical data automatically transmitted by your browser, including IP address, User-Agent string, and connection timing.
- [INFRA] Hosting Architecture: This website is hosted on Cloudflare Pages (Cloudflare, Inc.). Additional infrastructure services are provided by Hetzner Online GmbH (Germany/Finland). Both act as our data processors, ensuring physical security and GDPR compliance for all server operations.
// 03. Operational Usage
Captured data is processed strictly for the following objectives:
Communication
Executing responses to project inquiries and consultation requests.
Security
Monitoring for malicious payloads, DDoS attempts, or unauthorized access vectors.
Data Retention Logic
Client communication data is retained for the duration of the commercial relationship plus the statutory archival period required by Slovenian tax law (typically 5-10 years for invoices). Non-converted inquiries are purged from our active systems after 12 months.
// 04. Analytics Protocol (Cookie-Free)
We utilize Umami Analytics to monitor system performance.
Compliance Note: Umami is a privacy-focused analytics engine. It does not use cookies, does not store personal data, and anonymizes IP addresses. No "Cookie Banner" is required because no user-identifiable trackers are deployed on your device.
// 05. Subject Rights (GDPR)
Under EU Law, you possess the following command privileges regarding your data:
- Right to Access: Request a dump of all data we hold on you.
- Right to Rectification: Correct erroneous system records.
- Right to Erasure: Request total deletion of your records ("The Right to be Forgotten").
- Right to Lodge a Complaint: If you believe our processing infringes data protection laws, you have the right to lodge a complaint with the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec).
// 06. Secure Channel
To exercise your rights or report a compliance breach, initiate a signal to our Data Controller.
// 07. Corporate Registry (Impressum)
In compliance with the Electronic Commerce Market Act (ZEPT), the legal entity responsible for the operation of this digital infrastructure and data controlling is:
2380 Slovenj Gradec, Slovenia
Dispute Resolution: The European Commission provides a platform for online dispute resolution (OS) accessible at https://ec.europa.eu/consumers/odr.