Privacy Policy
Last updated: 18 September 2026
This Privacy Policy explains how Reload, obrt za računalno programiranje, vl. David Ančić ("Reload", "we", "us" or "our") processes personal data in connection with www.reload-compliance.com.
Reload applies the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability under applicable data protection law.
1. Data Controller
Galdovačka 254C
44000 Sisak
Croatia
Data Protection Contact: David Ančić
Email: david@reload-compliance.com
Reload has not designated a formal Data Protection Officer (DPO) under Article 37 GDPR. Based on Reload's current processing activities, Reload does not currently fall within the mandatory DPO designation criteria under Article 37(1) GDPR. This assessment is periodically reviewed as Reload's processing activities, services and organisational structure develop.
2. Personal Data We Process
When you use our website or contact us, we may process:
- first name;
- last name;
- email address;
- requested service;
- company or website, if provided;
- the content of your message; and
- limited technical and security information necessary to operate, secure and protect the website and contact form.
We do not intentionally request special-category personal data through the contact form.
Please do not submit passwords, payment-card information, identity documents or unnecessary sensitive personal information through the contact form.
3. Purposes of Processing
We process personal data for the following purposes:
- responding to enquiries;
- communicating with prospective clients;
- providing requested information;
- preparing quotations and discussing potential services;
- taking steps at the individual's request before entering into a contract;
- providing requested services;
- operating and maintaining the website;
- protecting the website and contact form against automated abuse and malicious requests;
- maintaining technical and information security;
- complying with legal obligations; and
- establishing, exercising or defending legal claims where necessary.
Reload does not use contact-form information for behavioural advertising, targeted advertising or cross-site profiling.
4. Legal Bases
Depending on the circumstances, Reload relies on the following legal bases under Article 6 GDPR.
4.1 Article 6(1)(b) GDPR — contractual and pre-contractual processing
Where you contact Reload to request a quotation, discuss services or take steps towards entering into a contract, processing that is necessary for those pre-contractual steps may be based on Article 6(1)(b) GDPR.
4.2 Article 6(1)(f) GDPR — legitimate interests
For general business enquiries that do not constitute pre-contractual steps, and for proportionate website security, abuse prevention and technical protection, Reload may rely on its legitimate interests under Article 6(1)(f) GDPR.
These interests include operating and securing the website, protecting public-facing forms from abuse and maintaining the security and integrity of our systems.
Reload considers the interests, rights and freedoms of individuals when relying on legitimate interests.
4.3 Article 6(1)(c) GDPR — legal obligations
Where processing is necessary to comply with a legal obligation applicable to Reload, Article 6(1)(c) GDPR may apply.
5. Contact Form and Security Processing
The website contact form uses technical and organisational safeguards designed to reduce abuse and protect submitted information.
These measures include:
- server-side validation;
- a server-side honeypot mechanism;
- server-side rate limiting;
- a maximum of 20 submissions per IP-based one-hour rate-limit window;
- a one-way cryptographic hash of the originating IP address for rate-limiting purposes;
- server-side secrets and privileged credentials;
- restricted database access;
- Row Level Security (RLS);
- request-size restrictions;
- generic error responses; and
- appropriate security-related HTTP headers.
The raw IP address used for rate limiting is not stored in the contact-submission database. The rate-limit system uses a salted/peppered one-way hash for this security purpose.
The rate-limit security data is not used for advertising, behavioural profiling or cross-site tracking.
6. Hosting Performance Measurement
Our hosting infrastructure may use a first-party performance measurement script provided as part of the hosting platform.
This functionality may measure technical website-performance characteristics such as loading performance, responsiveness and layout stability.
It is used as part of the hosting infrastructure and is not used by Reload for advertising, behavioural profiling or cross-site tracking.
7. Hosting, Database, Email and Technical Service Providers
The website and its backend infrastructure use third-party technical service providers for hosting, database, security, deployment and email delivery.
The production website uses EU-hosted backend/database infrastructure for contact enquiries.
Contact-form submissions are stored in the backend database and are used to respond to the enquiry and provide the requested services.
Email infrastructure is used to deliver contact-form notifications to Reload.
Where third-party providers process personal data on Reload's behalf, Reload uses appropriate contractual and organisational safeguards as required by applicable data protection law.
8. International Transfers
Where personal data is transferred outside the European Economic Area, Reload will ensure that an appropriate legal mechanism under Chapter V GDPR applies.
Depending on the relevant provider and circumstances, this may include:
- an adequacy decision of the European Commission;
- European Commission Standard Contractual Clauses; or
- another lawful transfer mechanism under applicable data protection law.
9. Data Retention
Contact-form enquiries are automatically deleted 180 days after submission.
A longer retention period may apply where necessary because of:
- an ongoing contractual relationship;
- a legal obligation;
- an ongoing dispute;
- establishment, exercise or defence of legal claims; or
- another lawful basis requiring continued retention.
Security-related rate-limiting information is retained only for the period reasonably necessary for security and abuse-prevention purposes.
10. Cookies and Similar Technologies
Reload's website is designed to use only technically necessary cookies and similar technologies.
The website does not intentionally use:
- Google Analytics;
- Google Tag Manager for behavioural analytics;
- Meta Pixel;
- LinkedIn Insight Tag;
- TikTok Pixel;
- Hotjar;
- Microsoft Clarity;
- session-replay technologies;
- advertising pixels;
- retargeting technologies; or
- behavioural advertising technologies.
For more information, see our Cookie Policy.
11. Data Subject Rights
Subject to the conditions and limitations provided by the GDPR, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete personal data;
- request erasure of your personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive personal data in a portable format where the requirements of Article 20 GDPR are met; and
- lodge a complaint with a competent supervisory authority.
Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
To exercise your rights, contact:
david@reload-compliance.com
We may take reasonable steps to verify the identity of a requester where necessary to protect personal data from unauthorised disclosure.
12. Supervisory Authority
You have the right to lodge a complaint with a competent supervisory authority.
For Reload's establishment in Croatia, the relevant supervisory authority is:
Agencija za zaštitu osobnih podataka (AZOP)Ulica Metela Ožegovića 16
10000 Zagreb
Croatia
13. Automated Decision-Making and Profiling
Reload does not use personal data collected through this website for automated decision-making that produces legal effects or similarly significant effects on individuals.
Reload does not use website visitor information for behavioural advertising profiling.
14. Children's Data
The website is intended for a general business audience and is not specifically directed at children.
Reload does not knowingly collect children's personal data through the website for purposes unrelated to responding to an enquiry or providing a requested service.
15. Data Security
Reload implements appropriate technical and organisational measures designed to provide a level of security appropriate to the risks associated with its processing activities.
These measures include server-side validation, rate limiting, restricted database access, Row Level Security, secure server-side handling of credentials, request-size restrictions and security-related HTTP controls.
No internet-connected system can be guaranteed to be completely secure.
16. Third-Party Websites
Our website may contain links to websites operated by third parties.
Reload is not responsible for the privacy practices, security or content of external websites. We recommend reviewing the privacy policies of third-party websites before providing personal data.
17. Changes to This Privacy Policy
Reload may update this Privacy Policy when our processing activities, technical infrastructure, services or applicable legal requirements change.
The latest version will be identified by the "Last updated" date.
18. Contact
For privacy and personal-data enquiries:
Reload, obrt za računalno programiranje, vl. David AnčićGaldovačka 254C
44000 Sisak
Croatia
Data Protection Contact: David Ančić
Email: david@reload-compliance.com
