Legal

Privacy Policy

Last updated: 29 July 2026

This Privacy Policy explains how IRNAS Technologies d.o.o. processes personal data collected through the Testnik presentation website at testnik.irnas.eu. It is written to meet Regulation (EU) 2016/679 (GDPR) and the Slovenian Personal Data Protection Act (ZVOP-2).

1. Who is responsible

The data controller is:

  • IRNAS Technologies d.o.o.
  • Sokolska ulica 51, 2000 Maribor, Slovenia
  • VAT ID: SI78993857
  • Email: tech@irnas.eu

For any question about this policy or about your rights, write to the address above. We answer data protection enquiries within one month.

2. What we collect, why, and on what legal basis

2.1 Contact form

When you send us an enquiry we process the name, email address, organisation, subject and message you supply, together with the language version of the form, a keyed hash of your IP address and your browser's user-agent string.

  • Purpose: to read, answer and keep a record of your enquiry, and to prevent abuse of the form.
  • Legal basis: your consent, Art. 6(1)(a) GDPR, given by ticking the consent box; and our legitimate interest in the security of the service, Art. 6(1)(f) GDPR, for the abuse-prevention data.
  • Consequence of not providing it: we cannot reply to you.

We do not store your IP address in readable form. It is converted to a keyed hash that cannot be reversed to the original address, so it serves rate limiting without identifying you.

2.2 Server logs

Our web server keeps standard access and error logs. These may contain an IP address, the time of the request, the page requested and the user-agent string.

  • Purpose: operating the site securely, diagnosing faults, and detecting and investigating attacks.
  • Legal basis: legitimate interest in network and information security, Art. 6(1)(f) GDPR, recital 49.

2.3 Cookies

This website sets only cookies that are strictly necessary for it to work: a session cookie, a cross-site request forgery token, and a cookie remembering your language choice. There is no advertising, profiling or third-party analytics. Because these cookies are strictly necessary, no consent is required under Art. 225 of the Slovenian Electronic Communications Act (ZEKom-2) and Art. 5(3) of Directive 2002/58/EC. Details are in our Cookie Policy.

3. Who has access

Your data is seen by the IRNAS Technologies staff who handle enquiries. We do not sell personal data, and we do not pass it to third parties for their own marketing.

Processors acting on our instructions may have technical access:

  • our hosting provider, which operates the servers on which this site runs;
  • the operator of the mail server used to deliver enquiry notifications.

Each processor is bound by a written agreement under Art. 28 GDPR.

4. Where your data is processed

All infrastructure and all data storage for this website are located within the European Union. In normal operation there is no transfer of personal data to a third country or an international organisation.

5. How long we keep it

  • Contact enquiries: retained for the period configured by the administrator — 24 months by default — and then deleted automatically. Where an enquiry leads to a contract, the related records are kept for as long as required by accounting and tax law.
  • Administrative audit records: 12 months by default.
  • Server logs: in line with our hosting provider's standard retention, normally not more than 12 months.

6. Your rights

Under Articles 15 to 22 GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectification of inaccurate or incomplete data;
  • erasure ("the right to be forgotten") where the conditions are met;
  • restriction of processing;
  • data portability for data you provided to us, in a structured, commonly used, machine-readable format;
  • object to processing based on our legitimate interest;
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise any of these, write to tech@irnas.eu. We may ask for information to confirm your identity before acting, so that we do not disclose your data to someone else.

7. Complaints

If you believe we have processed your data unlawfully, you may lodge a complaint with the Slovenian supervisory authority:

  • Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia)
  • Dunajska cesta 22, 1000 Ljubljana, Slovenia
  • www.ip-rs.si

You may also complain to the supervisory authority of your habitual residence or place of work.

8. Automated decision-making

We do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.

9. How we protect your data

We apply technical and organisational measures appropriate to the risk, in accordance with Art. 32 GDPR and structured around the ISO/IEC 27001:2022 control set. These include TLS encryption of all traffic, encryption at rest of stored credentials, role-based access control on the principle of least privilege, two-factor authentication for administrative accounts, audit logging of administrative actions, defined retention with automatic deletion, and a documented incident response procedure. See our Security and compliance page.

10. The Testnik Cloud dashboard

This policy covers only the presentation website. The Testnik Cloud dashboard at testnik-cloud.eu is a separate service governed by its own privacy notice and by the service agreement concluded with each customer.

11. Changes

We may update this policy when the service or the legal framework changes. The current version and its date are always published on this page. Material changes affecting your rights will be communicated to you where we have a means of contacting you.