Legal
Privacy Policy
Last updated: 25 July 2026
This policy explains what personal data Nos Astra collects when you use this website, why it is collected, who it is shared with, and the rights you have over it. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR) and the Croatian Act on the Implementation of the GDPR.
1. Who is responsible for your data
The data controller is:
- Nos Astra, obrt za računalno programiranje i savjetovanje, vl. Tamara Martinović
-
Cvjetni trg 3, Njivice, Croatia
OIB: 23795034700 · MBO: 99335433
Email: hello@nosastra.co
Nos Astra is a sole proprietorship (obrt) registered in the Obrtni registar of the Republic of Croatia. There is no separate data protection officer; enquiries about this policy go directly to the email address above.
2. What data is collected
Data you give us through the contact form
When you submit the enquiry form on this site, the following is collected:
- Your name — so replies can be addressed properly.
- Your email address — so a reply can be sent.
- Your message — the description of what you would like help with.
Please do not include sensitive personal data, confidential client information, or credentials in the message field. If your enquiry needs that level of detail, say so and we will agree a secure channel first.
Technical data
Submitting the form also causes technical data to be recorded by the services that process it, including your IP address, browser user agent, and the date and time of submission. This is used to prevent spam and abuse of the form.
The web server hosting this site keeps standard access logs, which may include IP addresses and requested URLs, for security and diagnostics.
3. Why it is collected, and the legal basis
- To read and answer your enquiry
- Legal basis: steps taken at your request prior to entering into a contract (GDPR Article 6(1)(b)). You chose to make contact, and the data is used to respond.
- To keep a record of business correspondence
- Legal basis: legitimate interests (GDPR Article 6(1)(f)) — being able to refer back to what was discussed and to substantiate a business relationship.
- To keep the form free of spam and abuse
- Legal basis: legitimate interests (GDPR Article 6(1)(f)) — keeping the site functional and secure.
Your data is not used to send marketing, and it is not sold, rented, or traded.
4. Who else processes it
Personal data submitted through this site is handled by the following processors acting on Nos Astra's instructions:
- Formspree, Inc. — receives the contact form submission and forwards it by email. Formspree is based in the United States.
- The website host — serves this site and keeps the access logs described above.
- The email provider — stores the resulting email so it can be read and replied to.
No other party receives your data unless disclosure is required by law.
5. Transfers outside the EEA
Because the contact form is processed by Formspree, Inc. in the United States, submitting the form involves a transfer of personal data outside the European Economic Area. Such transfers rely on the safeguards available under Chapter V of the GDPR — an adequacy decision or the European Commission's Standard Contractual Clauses, as set out in that provider's own data processing terms.
If you would prefer that your data not be transferred outside the EEA, do not use the form: email hello@nosastra.co directly instead.
6. How long it is kept
Enquiry correspondence is kept for up to 24 months from our last exchange, after which it is deleted unless it has become part of a client relationship with its own record-keeping and statutory accounting obligations. Server and spam-prevention logs are kept for a short period only, as determined by the providers named above.
You can ask for your enquiry to be deleted sooner at any time.
7. Cookies and analytics
This website sets no cookies, and uses no analytics, tracking pixels, or advertising scripts. Web fonts are served from this site's own domain rather than a third-party font service, so viewing these pages does not report your visit to anyone else. No consent banner is needed because there is nothing to consent to.
8. Your rights
Under the GDPR you have the right to:
- request access to the personal data held about you;
- have inaccurate data corrected;
- have your data erased;
- ask that processing be restricted;
- object to processing based on legitimate interests;
- receive your data in a portable form (data portability);
- lodge a complaint with a supervisory authority.
To exercise any of these, email hello@nosastra.co. A response will follow within one month. There is no charge for a reasonable request.
The supervisory authority in Croatia is the Agencija za zaštitu osobnih podataka (AZOP), Selska cesta 136, 10000 Zagreb — azop.hr. You may complain to AZOP, or to the authority in your own EU country of residence, at any time.
9. Automated decision-making
Nos Astra does not carry out automated decision-making or profiling that produces legal effects for you. Your enquiry is read by a person.
10. Security
This site is served over HTTPS, and the form is submitted over an encrypted connection. No system is perfectly secure, so please use judgement about what you put in a first message to a stranger — see the note in section 2.
11. Changes to this policy
If this policy changes, the revised version will be published on this page with a new "last updated" date. Material changes affecting how existing enquiry data is used will be communicated directly where contact details are held.
12. Contact
Questions about this policy or about how your data is handled: hello@nosastra.co.