Last updated: 01.06.2025.
This Privacy Policy explains how Val consulting ltd. (“we”, “us”) processes personal data when you use Consolidated-Regulation.eu.
The Website is designed for professional users outside the EU, but GDPR applies because we operate from the EU.
1. Data Controller
Val consulting ltd.
Kulmerska 31, 10000 Zagreb, Croatia, EU
Email: info@consolidated-regulation.eu
2. Personal Data We Process
We process minimal data, strictly necessary for Website operation:
2.1. Server logs (legitimate interest – Article 6(1)(f) GDPR)
Automatically collected information:
- IP address,
- time of access,
- URL accessed,
- browser type and version.
Logs are stored temporarily for security and diagnostics.
2.2. Contact and complaint data (Article 6(1)(f) GDPR)
If you contact us (e.g., via email), we process:
- your email address,
- message content,
- technical metadata.
Used only to respond to inquiries or complaints.
2.3. Cookies and analytics
See Cookie Policy.
We do not:
- create accounts,
- track users across sites,
- profile users,
- process sensitive data.
2.4 Cloudflare Turnstile
This website uses Cloudflare Turnstile to protect against bots and abuse. Turnstile may process technical data such as your IP address and browser information solely for security purposes.
3. Purposes of Processing
We process data for:
- security and functioning of the Website,
- responding to user communications,
- compliance with the Digital Services Act (DSA),
- analytics and advertising (if enabled).
4. Legal Bases
- Legitimate interest for security logs, analytics, improving service.
- Legal obligation for DSA complaint handling.
- Consent for non-essential cookies (if applicable).
5. Data Sharing
We may share limited data with:
- web hosting providers,
- advertising networks (if cookies accepted),
- authorities if legally required.
We do not sell or trade personal data.
6. Data Transfers
Some third-party providers (e.g. advertising networks) may transfer data outside the EU.
Such transfers occur only with lawful safeguards (SCCs or adequacy decisions).
7. Data Retention
- Server logs: typically 14–30 days, unless needed for security.
- Communications: as long as necessary to resolve the inquiry.
- Complaint data: for the period required by the DSA.
8. Your Rights
You have rights under GDPR:
- access,
- rectification,
- erasure,
- restriction,
- objection,
- portability,
- lodge a complaint with the Croatian Data Protection Authority (AZOP).
Contact: info@consolidated-regulation.eu