All legal documents

LEGAL CENTER

Privacy policy

How Northline Digital handles personal data on its corporate website and in products that identify us as their controller.

Last updated · 30 September 2026
On this page1. Controller and scope2. Information collected and its sources3. Purposes and legal bases4. Activity statistics and publisher visibility5. Payments and payment providers6. Recipients and disclosure7. International transfers8. Retention and deletion9. Your data-protection rights10. Security and account protection11. Cookies, local storage and optional analytics12. Children and automated decisions13. External services and policy changes14. Contact and further information

01Controller and scope

NORTHLINE DIGITAL j.d.o.o., Milutina Barača 62, 51000 Rijeka, Croatia, OIB 39667300205, is responsible for the processing described here. Contact [email protected] about privacy; use [email protected] for ordinary support.

This policy covers visitors, users, applicants, publishers and business contacts interacting with our corporate website and products that name us as controller, including related interfaces and APIs where offered. Merely visiting this corporate website does not mean we collect all product data listed below. A product-specific notice provides further details where its processing differs. Independently operated destinations are covered by their own notices.

02Information collected and its sources

We receive information from you, your browser or device, payment providers, authorised business contacts and people submitting reports. Public sources may be used to verify company details or a reported rights violation, limited to what is relevant.

  • Contact and account information: email, name and profile information, correspondence, support requests and account status.
  • Authentication: sign-in verification records, sessions, public passkey identifiers and public keys, device/browser information and session activity. We do not receive a passkey’s private key or the fingerprint/face template used by your device.
  • Purchases: checkout email, plan, billing details where required, payment references, amounts, status, renewals, refunds and disputes. We do not store complete card numbers or card security codes.
  • Publisher information: application answers, identity/business and tax details, payout destination, links, programme records and earnings adjustments where relevant to the relationship.
  • Technical and activity information: IP address, approximate country derived from it, timestamps, browser, operating system, language, referrer where supplied, and product events such as a visit, checkout or subscription.

Required fields are identified when collected. Without essential contact, payment or verification information we may be unable to fulfil the relevant request or service. Optional information is not a condition of unrelated services. Please do not send sensitive personal information unless specifically needed and requested through an appropriate channel.

03Purposes and legal bases

  • Providing an individual’s contract or taking requested pre-contractual steps — GDPR Article 6(1)(b): purchases, account access, fulfilment, subscription management, support and an individual publisher’s agreement.
  • Legal obligations — Article 6(1)(c): applicable accounting, tax, consumer complaints, lawful authority requests and other mandatory records or disclosures.
  • Legitimate interests — Article 6(1)(f): operating and securing services, detecting fraud, investigating misuse, establishing or defending claims, responding to business enquiries and managing representatives of corporate customers. We consider necessity, proportionality and the effect on individuals; this is not permission for unlimited tracking.
  • Consent — Article 6(1)(a): optional marketing, non-essential cookies or similar processing where consent is required. You can refuse or withdraw it without losing an unrelated core service. Necessary transactional emails are separate from marketing.

We will explain a materially different new purpose and its basis before using data for it where required. We do not use agreement to these terms as blanket consent.

04Activity statistics and publisher visibility

Products may provide publishers with limited activity and revenue information, such as a country flag, time, pseudonymous visitor identifier, event type, masked email and attributed amounts. These help account for visits and subscriptions without exposing a customer’s full account information. We limit the information to the relevant publisher’s activity.

Pseudonymous identifiers and masked emails can still be personal data; they are not automatically anonymous. Publishers may not attempt to identify visitors, combine activity for unrelated targeting or obtain hidden contact details. Operational attribution and fraud controls rely on the basis appropriate to their purpose; any non-essential device tracking requires the relevant consent. An identifier is not a promise that a person can be recognised across every browser or device.

05Payments and payment providers

Where Stripe handles checkout, the payment details you submit are processed through Stripe’s payment infrastructure. We receive information needed to associate the transaction with the purchase, deliver the service, manage refunds or disputes and keep financial records. We do not need your complete card details in support correspondence.

Depending on the processing activity and applicable agreement, Stripe may act as our processor or as an independent controller, including for its own fraud prevention and legal obligations. Its entities and practices are described in Stripe’s privacy policy. Another provider, if offered, is identified at the point of collection. Test-mode transactions do not move real money but contact and technical information used in a test can still be personal data.

06Recipients and disclosure

Access is limited to authorised personnel and providers that need information for the relevant purpose. Depending on the product, recipients include hosting/infrastructure and security providers, email/support providers, payment providers, professional advisers and accounting providers, and publishers receiving the limited information described above. We require appropriate processing terms and confidentiality safeguards where a provider acts on our instructions.

We may disclose necessary information to a competent authority under a lawful obligation or request, or where justified to protect rights and pursue or defend claims. A lawful merger or transfer of a business may involve limited disclosure under confidentiality and continued data-protection safeguards; affected individuals are informed where required.

We do not sell personal data or share it for unrelated third-party advertising. Ask our privacy contact for details of recipients relevant to your data.

07International transfers

A provider or recipient may process information outside the European Economic Area. Before a restricted transfer, we must have a valid transfer mechanism: an applicable adequacy decision, suitable safeguards such as the European Commission’s standard contractual clauses with any necessary supplementary measures, or a strictly applicable legal exception. A provider’s worldwide presence is not itself a lawful transfer mechanism.

You may ask the privacy contact which transfer arrangement applies to your data and request information or a copy of relevant safeguards, subject to necessary redactions protecting others’ rights and legitimate confidential information.

08Retention and deletion

We retain information for the purpose for which it is needed and any justified legal retention period, rather than retaining every category indefinitely.

  • Account and service records: while needed to provide the account or complete outstanding obligations; closure triggers a review of what must be deleted or restricted.
  • Authentication and technical records: while needed for their security purpose and investigation of specific incidents. Expiry of a login link does not itself mean every associated record is immediately deleted.
  • Billing, tax and payout records: for the applicable statutory accounting and tax retention periods, even after account closure.
  • Support, complaints and content reports: for handling the issue and any applicable record-keeping or claim period; Croatian consumer complaint records are retained for at least one year where required.
  • Evidence of disputes, fraud or consent: for the relevant obligation, investigation or limitation period, with access restricted to that purpose.

We consider necessity, the nature of the record, applicable law and unresolved claims. Data no longer needed is deleted or made genuinely anonymous; residual backups are restricted from ordinary use and expire under the applicable backup cycle. Ask us for the period or criteria relevant to a particular record. Deleting an account does not require us to erase records that the law requires us to retain.

09Your data-protection rights

Subject to the conditions in law, you may request access and a copy, correction, erasure, restriction and portability of data processed by automated means on the basis of consent or contract. You may withdraw consent at any time without affecting the lawfulness of earlier processing.

You may object to processing based on legitimate interests on grounds relating to your particular situation, and object to direct marketing at any time. We stop the relevant processing unless the legal conditions for continuing apply; direct marketing stops following an objection.

Contact [email protected]. We may request proportionate identity verification, not unnecessary identity documents. We ordinarily respond within one month; a lawful extension for complexity or the number of requests is explained within that month. Requests are ordinarily free; any lawful exception must be justified.

You may complain to the Croatian Personal Data Protection Agency (AZOP) or another competent supervisory authority, including where you live or work. You need not contact us first to exercise that right.

10Security and account protection

We apply safeguards proportionate to the processing, including protected connections, access restrictions, authentication controls and measures to maintain system security. No online service can promise absolute protection. We assess incidents and notify affected individuals or authorities where the law requires it.

Keep access to your email and devices secure, review available device/session controls and report suspected compromise promptly. We do not ask for passwords, passkey private keys or card security codes by email. Security precautions do not remove our responsibility for our own processing.

11Cookies, local storage and optional analytics

The corporate website does not deploy advertising or optional analytics trackers. Technical delivery can still involve server logs. Our products may use necessary cookies or comparable storage for sessions, security and saved preferences. Browser controls can remove or block storage, but blocking a necessary session mechanism may prevent sign-in or subscription management.

Before introducing non-essential analytics, advertising cookies or comparable tracking, the relevant service must explain the purpose and providers and collect consent where required, with a way to refuse and later change the choice. Continued browsing alone is not consent. Aggregated statistics are only treated as anonymous if people can no longer reasonably be identified.

12Children and automated decisions

Our paid services and publisher programme are intended for adults aged at least 18. We do not intentionally solicit children’s accounts. If you believe a child has provided personal data improperly, contact us so we can investigate and take appropriate action, including deletion where appropriate.

Security or fraud controls can flag activity or temporarily limit access. If a decision has legal or similarly significant effects and is based solely on automated processing, it may be made only where the applicable legal conditions and safeguards are met. Contact the privacy team for an explanation, to contest a decision or request human intervention where applicable. This policy does not grant unrestricted permission for automated decision-making.

13External services and policy changes

Following an external link may disclose technical information to its operator, whose privacy notice applies to its own processing. Our responsibility for processing we perform or determine is unchanged.

We date revised policies and explain material changes through an appropriate notice. A new policy does not retrospectively create consent or authorise an incompatible purpose. Where required, we provide further information and obtain consent before the new activity begins. The contract and privacy policy serve different purposes.

14Contact and further information

Privacy, rights requests, transfer safeguards and data concerns: [email protected]. General service or billing assistance: [email protected].

Postal contact: NORTHLINE DIGITAL j.d.o.o., Milutina Barača 62, 51000 Rijeka, Croatia. Provide the product and account email if relevant, but no passwords or unnecessary sensitive data. This legal mailbox is a privacy contact and does not imply that a statutory data-protection officer has been appointed.

NORTHLINE DIGITAL j.d.o.o.

Terms of service