Legal
Privacy Policy
This website is intentionally simple: static pages, no account area, no contact form, no newsletter, and no analytics or marketing cookies set by the site.
Controller
HILLS Lab d.o.o., Papandopulova 14, 21000 Split, Croatia, Croatian identification number (OIB): 48104693060 is responsible for personal data processed through this website and direct business communication.
For privacy questions or requests, contact [email protected].
This policy covers hills-lab.hr and direct business communication. Products linked from this website, including Memoato and PLAYGRND, have their own privacy notices. When we process personal data on a client's instructions, the relevant client agreement and data processing terms apply.
What we process
- Emails you send to us, including your address, message content, attachments, and related metadata.
- Basic technical request data processed by hosting, DNS, security, and email providers, such as IP address, user agent, requested URL, timestamp, and delivery logs.
- Business records needed to discuss, provide, invoice, or document a service relationship.
What we do not do
- We do not run a public account system on this website.
- We do not use a contact form on this website.
- We do not run a newsletter signup on this website.
- We do not set analytics or advertising cookies from this website.
- We do not sell personal data.
Purposes and legal bases
- Business inquiries and communication with client representatives: our legitimate interest in answering relevant requests and managing business relationships (GDPR Article 6(1)(f)).
- Steps requested before entering a contract, or performing a contract with you personally: contractual necessity (Article 6(1)(b)). This basis does not automatically apply to employees or representatives of a corporate client.
- Technical request data and security logs: our legitimate interest in keeping the website available, preventing abuse and investigating faults (Article 6(1)(f)).
- Invoices and other mandatory business records: compliance with accounting, tax and other applicable legal obligations (Article 6(1)(c)). Records needed to establish, exercise or defend legal claims may also be retained on the basis of legitimate interests (Article 6(1)(f)).
Recipients and international transfers
Recipients may include hosting, DNS and security providers, email and collaboration providers, and accounting or legal advisers, where needed for the purposes above. Competent authorities may receive records where disclosure is legally required. The website does not sell personal data.
Some providers may process data outside the European Economic Area. Any such transfer requires a valid mechanism under GDPR Chapter V, such as an applicable adequacy decision or standard contractual clauses with additional safeguards where needed. This policy does not itself authorise a transfer.
Contact [email protected] for information about the recipients and transfer safeguards relevant to your data, including how to obtain a copy of applicable safeguards.
How long we retain data
- Inquiries and correspondence: for the time needed to resolve the inquiry and any related follow-up. Where communication becomes part of a client relationship, retention also depends on the active engagement and any outstanding obligations or claims.
- Contracts, invoices and business records: for the statutory retention period applicable to the particular record, and longer only where necessary for an outstanding legal obligation or claim.
- Technical and security logs: retention depends on the relevant provider's configured logging period and the time needed to diagnose faults or investigate abuse. Records relevant to an incident may need to be retained until it is resolved or related claims are concluded.
- We determine the appropriate period by the record's purpose, applicable legal duties and whether an unresolved matter still requires it. You can request information about the retention period or criteria applicable to your data.
Your rights
Under the conditions set out in the GDPR, you can request access to your data, correction, erasure, restriction of processing or data portability. You can object to processing based on legitimate interests on grounds relating to your particular situation. These rights are not absolute; for example, statutory record-keeping duties may prevent immediate deletion.
Send requests to [email protected] or the registered address above. We respond without undue delay and normally within one month. Where the GDPR permits an extension because of complexity or the number of requests, we will explain it within that first month. We may request proportionate information to verify your identity.
You have the right to lodge a complaint with a supervisory authority, including the Croatian Personal Data Protection Agency (AZOP). You do not have to contact us before exercising that right.
Providing data and automated decisions
You can read the public website without submitting an inquiry. If you contact us, we need enough contact information and context to answer; without it, we may be unable to respond or arrange a service. Information required for a contract or by law is identified when it is requested.
This website does not make solely automated decisions about visitors that produce legal or similarly significant effects.