Privacy Policy
Last updated: March 2026
1. Data Controller
The data controller for this website is KOLAB – obrt za poslovne i ostale usluge, vl. Marko Rajković, with registered address at Benešićeva ulica 7, 10000 Zagreb, Croatia.
For any privacy-related inquiries, contact us at: info@kolab-space.eu
2. What Data We Collect
We collect the following personal data:
- Connection requests: Your name, email address, organization name, and message — submitted voluntarily when you request an introduction to a catalog entity.
- Claim requests: Your name, email address, and role — submitted when you claim an entity profile as a representative.
- Entity profiles: Contact email, city, website URL, and organizational information — submitted by entity representatives for their catalog listing.
- Authentication: Email address and password — used for account creation and login. Passwords are hashed and never stored in plaintext.
3. Purpose of Data Processing
Your data is processed for the following purposes:
- Facilitating introductions between organizations in the Croatian space ecosystem
- Managing the catalog of Croatian space sector entities
- Authenticating entity representatives for profile management
- Sending administrative notifications related to connection requests and profile changes
4. Legal Basis
- Consent (Art. 6(1)(a) GDPR): For connection request submissions, where you explicitly consent to the processing of your data before submitting the form.
- Legitimate interest (Art. 6(1)(f) GDPR): For operating the catalog platform and facilitating the Croatian space ecosystem coordination.
- Contract performance (Art. 6(1)(b) GDPR): For entity representative accounts and profile management.
5. Data Retention
- Connection request data is retained for up to 3 years.
- Account and entity profile data is retained until you request deletion.
- Authentication logs are retained for security purposes for up to 1 year.
6. Third-Party Processors
We use the following third-party services to operate this platform:
- Supabase (database and authentication) — hosted on AWS eu-central-1 (Frankfurt, Germany).
- Vercel (web hosting) — processes requests through edge locations, including EU servers.
- Resend (transactional email) — processes email data in the United States. Standard Contractual Clauses (SCCs) apply for data transfers outside the EU.
7. Your Rights
Under the GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing of your data
- Data portability — receive your data in a structured format
- Object to processing based on legitimate interest
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at info@kolab-space.eu. We will respond within 30 days.
You also have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) at azop.hr.
8. Cookies
This website uses only strictly necessary cookies for authentication session management. No analytics, advertising, or tracking cookies are used. These cookies are essential for the website to function and cannot be disabled.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit (TLS/HTTPS), encrypted storage, and role-based access controls.