This Privacy Policy is provided in accordance with the principle of informed decision-making as required by the General Data Protection Regulation (EU) 2016/679 (GDPR). Every individual has the right to know what personal data is collected, by whom, for what purpose, and for how long — presented in a lawful, fair, and transparent manner, without concealment, misleading, or omission. Only complete and honest disclosure enables a truly informed decision, as required by GDPR Art. 5(1)(a).
| Field | Value |
|---|---|
| Company name | AA Innovations, varnostne tehnologije d.o.o. |
| Address | Kersnikova 1, 1241 Kamnik, Slovenija, EU |
| VAT number | SI23888440 |
| Registration number | 8570132000 |
| info@gdprcompliantsite.com | |
| Phone | Not specified |
| Contact person | Not specified |
The EU GDPR does not prescribe specific technical measures for verifying the identity of the website controller, nor does it require identification of the website visitor. Therefore, until the relevant regulations on identity verification obligations are supplemented, individuals must decide for themselves whether to trust the unprotected identity of the controller as presented. Furthermore, the controller cannot guarantee that consent was obtained from the specific individual who purportedly agreed to the data processing terms, as the individual does not identify themselves to the controller in a unique and verifiable manner during the confirmation process. Consequently, the controller bears no responsibility for any misuse of web forms by third parties acting in another person's name. In the event that an individual objects to the processing of their personal data on the grounds that they did not provide consent, the controller shall immediately cease processing and delete the data upon receipt of such request. The controller accepts no responsibility for any damage incurred in the period between the entry of data by a third party and the receipt of the objection.
The controller has not appointed a Data Protection Officer. For data protection inquiries, please contact the controller directly using the contact details provided in Section 1.
| Activity | Purpose | Legal basis | Retention | Third party |
|---|---|---|---|---|
| Website visit logging | Technical operation and security of the website, server log analysis | Legitimate interest (Art. 6(1)(f)) | 90 days | None |
| Security logging | Detection and prevention of security threats, fraud prevention | Legitimate interest (Art. 6(1)(f)) | 30 days | None |
| SSL/TLS encryption | Secure encrypted communication between browser and server | Legitimate interest (Art. 6(1)(f)) | N/A | None |
| Functional cookies (session management) | Core website functionality, session management via PHPSESSID cookie | Legitimate interest (Art. 6(1)(f)) | Session | None |
| Consent management | Storing visitor consent preferences via gdprcs_consent cookie | Legitimate interest (Art. 6(1)(f)) | Session | gdprcompliantsite.com (self-hosted) |
| Cloudflare security challenge (bot protection) | Bot protection and security verification | Legitimate interest (Art. 6(1)(f)) | 1 day | Cloudflare, Inc. |
| Compliance report request form | Processing email address to deliver the requested compliance report and notifications | Consent (Art. 6(1)(a)) | 2 years or until withdrawal | None |
This website processes personal data under Legitimate Interest and a single consent category. By accepting this Privacy Policy, you consent to all data processing activities described herein that require consent. You may withdraw your consent at any time by contacting the controller.
| Category | Technologies | Purpose | Required |
|---|---|---|---|
| Functional / Security | Server logs, SSL/TLS encryption, PHPSESSID session cookie, gdprcs_consent consent cookie, Cloudflare security challenge | Core website functionality, security, and encrypted communication | No — operates under Legitimate interest |
The following technical disclosure was produced using a regulatory-grade evidence collection methodology adopted by European data protection regulators and supervisory authorities. All findings are based on objective technical measurements performed on this website. This disclosure is provided in the interest of full transparency to website visitors.
| Parameter | Value |
|---|---|
| Allows HTTPS | Yes |
| HTTP redirect to HTTPS | Yes |
| Redirect location | https://gdprcompliantsite.com/ |
| Name | Domain | Category | Legal basis |
|---|---|---|---|
| PHPSESSID | gdprcompliantsite.com | Functional / Session | Legitimate interest (Art. 6(1)(f)) |
| consent.gdprcompliantsite.com | consent.gdprcompliantsite.com | Consent management | Legitimate interest (Art. 6(1)(f)) |
| challenges.cloudflare.com | challenges.cloudflare.com | Security (bot protection) | Legitimate interest (Art. 6(1)(f)) |
| Name | Domain | Category | Retention | Legal basis |
|---|---|---|---|---|
| PHPSESSID | gdprcompliantsite.com | Functional (Session) | Session | Legitimate interest (Art. 6(1)(f)) |
| gdprcs_consent | gdprcompliantsite.com | Functional (Consent management) | Session | Legitimate interest (Art. 6(1)(f)) |
No local storage entries detected.
No tracking elements or beacons detected.
| Domain | Category | Legal basis |
|---|---|---|
| consent.gdprcompliantsite.com | Consent management | Legitimate interest (Art. 6(1)(f)) |
| challenges.cloudflare.com | Security (bot protection) | Legitimate interest (Art. 6(1)(f)) |
| hagen.challenges.cloudflare.com | Security (bot protection) | Legitimate interest (Art. 6(1)(f)) |
| Provider | Domain | Purpose | Legal basis | Retention | Privacy Policy | Country |
|---|---|---|---|---|---|---|
| gdprcompliantsite.com (self-hosted) | consent.gdprcompliantsite.com | Consent management platform — storing visitor consent preferences | Legitimate interest (Art. 6(1)(f)) | Session | https://gdprcompliantsite.com/privacy-policy | Slovenia (EU) |
| Cloudflare, Inc. | challenges.cloudflare.com | Bot protection and security verification | Legitimate interest (Art. 6(1)(f)) | 1 day | https://www.cloudflare.com/privacypolicy/ | United States |
| Right | Description |
|---|---|
| Right of access (Art. 15) | You have the right to obtain confirmation as to whether personal data concerning you is being processed, and access to that data. |
| Right to rectification (Art. 16) | You have the right to have inaccurate personal data corrected without undue delay. |
| Right to erasure (Art. 17) | You have the right to obtain the deletion of your personal data under certain conditions. |
| Right to restriction of processing (Art. 18) | You have the right to restrict the processing of your personal data under certain conditions. |
| Right to data portability (Art. 20) | You have the right to receive your personal data in a structured, commonly used, and machine-readable format. |
| Right to object (Art. 21) | You have the right to object to the processing of your personal data based on legitimate interests or direct marketing. |
| Right to withdraw consent (Art. 7(3)) | You have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. |
To exercise any of these rights, please contact us at: info@gdprcompliantsite.com
| Field | Value |
|---|---|
| Authority | Information Commissioner of the Republic of Slovenia (IP RS) |
| Address | Zaloška 59, 1000 Ljubljana, Slovenia |
| Phone | +386 1 230 97 30 |
| gp.ip@ip-rs.si | |
| Website | https://www.ip-rs.si |
You have the right to lodge a complaint with the supervisory authority if you believe that the processing of your personal data infringes the GDPR (Art. 77 GDPR).
Based on the technical analysis of this website, no automated decision-making or profiling with legal or similarly significant effects (Art. 22 GDPR) has been detected. If this changes, this Privacy Policy will be updated accordingly.