English
1. Controller
CTT-CRYO TRANS TECH d.o.o. is the controller for personal data described in this policy. Privacy requests and suspected website-related personal data incidents may be reported to gdpr@cryotranstech.hr.
2. Scope of this policy
This policy applies to visitors of ctt-cryotranstech.com and people who contact CTT about its products, services, procurement or corporate information. It does not describe CTT's separate internal processing of employee, job-applicant, supplier or contractual records where a dedicated notice or legal framework applies.
3. Data we process
- Website and security data: IP address, request date and time, requested page, device or browser information, security signals, page views and approximate unique-visitor statistics.
- Business enquiry data: name, company, role, email, telephone number and the technical or commercial information included in an email or project enquiry.
- Correspondence data: messages, attachments and records required to answer, manage or document a business relationship.
The Procurement Project Brief is prepared in the visitor's browser. The website does not submit or permanently store it when it is completed. If the visitor selects “Send Enquiry to CTT,” their email application opens and the visitor decides whether to send the resulting message to CTT.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Delivering, maintaining and securing the website | CTT's legitimate interest in operating a secure public business website |
| Aggregated traffic measurement and service improvement | Legitimate interest in understanding and improving website performance |
| Answering product, procurement and business enquiries | Steps requested before a contract and/or legitimate interest in business communication |
| Meeting statutory, regulatory and evidentiary obligations | Compliance with legal obligations and establishment, exercise or defence of legal claims |
CTT does not currently use website visitor data for automated decision-making, behavioural advertising or cross-site profiling.
5. Recipients and service providers
Data may be accessible to authorised CTT personnel and to service providers needed to operate the website and business communications, including OpenAI Sites hosting and related infrastructure, Cloudflare security and content-delivery services, and CTT's email and IT providers. Data may also be disclosed to professional advisers, certification or inspection participants, contractual partners, courts or public authorities when this is necessary and lawful. CTT does not sell personal data.
6. International processing
Website infrastructure and its service providers may process technical and operational data outside Croatia or the European Economic Area. Where GDPR transfer rules apply, CTT relies on an adequacy decision, contractual safeguards or another lawful transfer mechanism made available for the relevant service. Information about the applicable safeguards can be requested through the privacy contact above.
7. Retention
- Security and server data is retained according to the operational and security periods applied by the relevant infrastructure provider.
- Business enquiries are retained while they are active and afterwards only for reasonable follow-up, record-keeping and legal-claim periods.
- Records that become part of a contractual, accounting or statutory file are retained for the period required by applicable law.
- The strictly necessary Cloudflare cookie is described in the Cookie Policy and normally expires after approximately 30 minutes of inactivity.
8. Your rights
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction, data portability or object to processing based on legitimate interests. Where processing is based on consent, you may withdraw that consent without affecting earlier lawful processing. CTT may need to verify the identity of the requester and may retain data where another legal basis or obligation applies.
You may also lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, Croatia — azop.hr.
9. Security and policy updates
CTT applies organisational and technical measures appropriate to the nature of the data and the website. No internet transmission can be guaranteed as completely risk-free. This policy may be updated when the website, providers or legal requirements change; the effective date at the top identifies the current version.

