Skip to content

Privacy policy

Last updated: February 12, 2026

WebDesignbyTomi ("we", "us" or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, process and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and the Croatian Act on the Implementation of the General Data Protection Regulation.

1. Data controller

WebDesignbyTomi

Email: info@webdesignbytomi.com

Web: webdesignbytomi.com

Republic of Croatia

2. What data we collect

2.1 Data you provide directly

2.2 Order and billing data

When you place an order for our services through our online ordering system, we collect the following data:

This data is processed on the basis of contractual obligation (order fulfillment) and legal obligation (maintaining business records and issuing invoices).

2.3 Automatically collected data

We do not use analytics tools and do not actively collect technical data about visitors. The only data we store:

3. Legal basis and purpose of processing

We process your data on the following legal bases:

Performance of a contract (Art. 6(1)(b) GDPR)

Processing of data necessary for providing our services, communicating about the project and fulfilling contractual obligations.

Legitimate interest (Art. 6(1)(f) GDPR)

Improving our services, website security and preventing misuse.

Consent (Art. 6(1)(a) GDPR)

When you give us explicit consent, e.g., for receiving promotional materials.

4. How long we retain data

5. Sharing data with third parties

We do not sell, rent or share your data with third parties for marketing purposes. We may only share data with:

6. Data transfers outside the EU/EEA

As a general rule, we do not transfer your data outside the European Economic Area. If this were necessary, we would ensure appropriate safeguards in accordance with the GDPR (standard contractual clauses, adequacy decisions).

7. Your rights

Under the GDPR, you have the following rights:

To exercise any of the above rights, contact us at info@webdesignbytomi.com. We will respond within 30 days.

8. Right to lodge a complaint

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the supervisory authority:

Croatian Personal Data Protection Agency (AZOP)

Selska cesta 136, 10000 Zagreb

Tel: +385 1 4609 000

Web: azop.hr

9. Data security

We implement appropriate technical and organizational measures to protect your data:

10. Personal data breach notification

In the event of a personal data breach that may pose a risk to your rights and freedoms, we will take the following steps in accordance with Art. 33 and 34 of the General Data Protection Regulation (GDPR):

11. Cookies

Our website uses exclusively technically necessary cookies required for the basic functionality of the site. We do not use:

Technically necessary cookies do not require your consent under Art. 5(3) of the ePrivacy Directive.

12. Changes to the privacy policy

We may update this Privacy Policy from time to time. All changes will be published on this page with the date of the last update. For significant changes that affect your rights, we will notify you by email (if we have your address) or by a prominent notice on the website.

13. Contact

For all questions related to this Privacy Policy or the processing of your personal data:

Email: info@webdesignbytomi.com

Subject: Personal data protection request