Privacy policy

In accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Croatian Act on the Implementation of the General Data Protection Regulation.

1. Data controller

The controller for the processing of personal data is Odo d.o.o., Milani 9, 47250 Milani, OIB: 68822243209. For any questions regarding the processing of personal data, you can contact us at info@croatia-victim.net.

2. What data we process

  • Staff user account data (e-mail, hashed password, role) — for administering, editing and viewing archive cases.
  • Data contained in archive cases, documents, photos and videos entered into the portal by staff (may include personal data of third parties related to the archived content).
  • Technical data necessary for the login session to function (authentication cookie) — see the Cookie policy.
  • Activity records (audit log) — who made a change to a case and when, for the transparency and security of the archive.

3. Purpose and legal basis of processing

We process data for the purpose of maintaining the archive and documentation records (the controller's legitimate interest and, where applicable, the performance of a task carried out in the public interest or a legal obligation to retain documentation), and to enable secure login and staff work in the portal administration area (performance of an employment/collaboration contract). Publicly published cases are shown to portal visitors only if the case's visibility has been explicitly set to "public" by authorized staff, anonymized where necessary.

4. Retention period

We keep data for as long as necessary for archiving purposes or as required by applicable statutory documentation retention periods. Archive content is never permanently deleted by an accidental action — deletion is always a specially protected administrator action (soft delete), and original document versions are never overwritten or removed.

5. Recipients of data and processors

We store data with providers of database hosting and file storage (Object Storage) services, who act as our processors and are contractually bound to an adequate level of data security. We do not sell or transfer data to third parties for marketing purposes.

6. Data security

Access to internal and private content is restricted to logged-in staff according to their assigned role (administrator/editor/viewer). Passwords are stored exclusively in hashed form. Data transfer is protected by encryption (HTTPS/TLS). Uploaded files undergo validation before storage.

7. Your rights

Under the GDPR, you have the right to request access to your personal data, its rectification, erasure, restriction of processing, data portability, and to object to processing. You can send a request to info@croatia-victim.net. If you believe your rights have been violated, you have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP).

8. Changes to this policy

We may update this privacy policy from time to time. The current version is always available on this page.