Last updated: 6 September 2026

This policy explains what Expert Web Audit collects when you visit this website or buy an audit, why, and what you can ask us to do about it. It describes what this site actually does — not a generic template.

Who is responsible

The data controller for this site is Samoglasnik, obrt, Primorska 2, HR-10000 Zagreb, Croatia.

For anything in this policy, including any request about your data, contact us at nenad@samoglasnik.com.

What we collect, and when

When you fill in a form

Our contact and enquiry forms are run with WPForms and collect what you type into them — typically your name, email address, website address and your message. Submissions are stored in the WordPress database on our hosting and sent to us by email.

We use this to answer you and, if you become a client, to deliver the work. We do not sell it, and we do not add you to a mailing list because you sent an enquiry.

Forms are protected against automated spam. Where that protection is provided by a third-party service, that service receives your IP address and basic browser information in order to judge whether the submission is automated.

When you buy an audit

Payments are processed by Stripe. Card details are entered directly into Stripe’s own payment fields and are transmitted to Stripe — we never receive or store your card number.

From Stripe we receive confirmation of payment, the amount, and the billing details you provided. We keep those records because tax law requires us to.

Stripe acts as an independent controller for the payment data it processes. Its own privacy policy is at stripe.com/privacy.

When you just read the site

Our web server keeps standard access logs: IP address, the page requested, the time, your browser’s user-agent string and the referring page. These are generated automatically by the hosting infrastructure, are used for security and troubleshooting, and are deleted on the host’s normal schedule.

This site does not currently run Google Analytics or any comparable analytics product. If that changes, this policy will be updated before it does.

Fonts and other third-party resources

Typefaces are served from our own servers rather than from a third-party font provider, so opening a page does not send your IP address to a font network.

The only third-party resource an ordinary page loads is Stripe’s payment library, and only on pages where a payment can be made. We do not embed social widgets, advertising pixels, chat tools or session recorders.

If you send us files

To carry out an audit we may need access to your website, its analytics, or its hosting. Anything you share for that purpose is used only for the audit, is not shared with anyone else, and is deleted or access is revoked when the engagement ends. Where an audit requires credentials, we ask that you create limited, temporary access rather than sharing your own.

Cookies

This site uses a small number of cookies:

We do not use advertising cookies, we do not run retargeting pixels, and we do not share visitor data with advertising networks.

You can block or delete cookies in your browser settings. Blocking the payment and spam-protection cookies will stop those features working.

How long we keep things

Who else sees your data

We do not sell personal data. It is shared only with the providers needed to run the business:

Some of these providers operate outside the European Economic Area, principally in the United States. Where that involves a transfer of personal data, it relies on the safeguards those providers offer, such as Standard Contractual Clauses or an equivalent framework.

Your rights

If you are in the EEA or the UK, you have the right to:

Write to nenad@samoglasnik.com and we will respond within one month. You will not be charged, and we will not ask for more identification than we need.

If you think we have handled your data badly, you can complain to the Croatian Personal Data Protection Agency (AZOP), or to the authority where you live.

If you are in California

You may ask what categories of personal information we have collected, request deletion, and ask us not to sell or share it. We do not sell or share personal information as those terms are defined under California law, and we will not treat you differently for exercising these rights.

Children

This site sells professional services to businesses. It is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has sent us personal data, contact us and we will delete it.

Security

The site is served over HTTPS. Access to the administration area is restricted and protected by two-factor authentication. Payment data never touches our servers.

No system is perfectly secure. If a breach ever affects your personal data and presents a risk to you, we will notify you and the relevant authority within the time the law requires.

Changes

If this policy changes, the date at the top changes with it. Material changes affecting how we use data already collected will be communicated directly to anyone affected.