Skip to content

Legal

Privacy policy

Last updated: September 2026

In short

This website sets no cookies, embeds no analytics or tracking tools and loads no content from third-party servers. The fonts are served from our own server, so no connection to Google Fonts or a comparable service is made.

We process personal data only when you write to us via the contact form or by email.

Controller

A data protection officer is not required under Art. 37 GDPR, as we neither process special categories of data on a large scale nor carry out large-scale regular monitoring.

Company
KPJP, zagotavljanje kakovosti d.o.o.
Address
Cesta Ceneta Štuparja 137 1231 Ljubljana-Črnuče Slovenia
Represented by
Kristof Peymann, Managing Director

Visiting the website

When you access the site, the server processes technically necessary connection data: IP address, date and time, the address requested, volume of data transferred, status message and browser and system details.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and uninterrupted operation of the website. This data is not combined with other sources.

Hosting

The website is operated at Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. The servers are located in Nuremberg, Germany.

A data processing agreement under Art. 28 GDPR is in place with the provider. It processes the data solely on our instructions. Its technical and organisational measures are audited annually by TÜV Rheinland.

The provider uses sub-processors, some outside the European Union. As we selected a server location within the EU, server data is processed exclusively within the EU; support is likewise provided from within the EU.

Web server access logs are rotated daily and deleted automatically after 14 days. We evaluate them statistically to learn how many people read the site, which pages they visit and which referring sites they come from. This evaluation works without cookies, builds no profiles and does not attribute any visit to a person; requests from automated programs are filtered out. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the secure operation of the website and the maintenance of its content.

Delivery and protection by Cloudflare

The website is delivered through the network of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare receives your request, blocks attacks and automated mass access, and forwards the request to our server. In doing so, Cloudflare processes the connection data listed under “Visiting the website”, usually in the data centre geographically closest to you.

A data processing agreement under Art. 28 GDPR is in place with Cloudflare. Cloudflare is certified under the EU-US Data Privacy Framework; in addition, the EU Commission’s standard contractual clauses apply. Transfers to the USA are therefore safeguarded under Art. 45 and 46 GDPR.

If Cloudflare detects suspicious access, it may run a brief security check in the browser. Once passed, Cloudflare sets a technically necessary cookie (cf_clearance) that serves solely to remember this check and expires after a short time. Normal visits do not trigger this check. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the security and availability of the website.

Contact form and email

When you write to us, we process the details you provide in order to answer your enquiry.

  • Name, email address, company and your message
  • Time of receipt

Disclosure to third parties

Your message is transmitted via the mail server of our provider united-domains (smtps.udag.de) and stored in our mailbox there. The provider processes the data as a processor acting on our instructions.

Beyond that we do not pass your data on — in particular not for advertising purposes. Transfers outside the European Economic Area take place only as part of the technical delivery by Cloudflare (see above).

Legal bases and retention

Enquiries relating to a contract or its initiation are processed under Art. 6(1)(b) GDPR; all others under our legitimate interest in responding, Art. 6(1)(f) GDPR.

We delete your enquiry once it has been dealt with conclusively and no statutory retention periods apply. Commercial and tax obligations may require retention for up to ten years.

No cookies, no tracking

We set no cookies of our own, neither technically necessary nor analytical. The only exception is the Cloudflare security cookie described above, which is created only after a security check. Audience measurement is limited to the statistical evaluation of server logs without cookies and without profiles; there is no integration of social networks.

As no processing requiring consent takes place, this website needs no consent banner.

No automated decision-making

Automated decision-making including profiling under Art. 22 GDPR does not take place.

Your rights

You have the following rights in relation to us:

  • Access to the data processed about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)

Right to lodge a complaint

You may lodge a complaint with a supervisory authority at any time. The authority responsible for us is the Slovenian Information Commissioner:

Informacijski pooblaščenec, Dunajska cesta 22, 1000 Ljubljana, Slovenia — [email protected]

You may equally contact the supervisory authority where you habitually reside.

Changes

We update this policy whenever our processing or the legal situation changes. The version published here applies.