01Two different relationships
There are two distinct roles in this service, and which one applies decides who you should contact about your data.
- We are the controller
- for the data of the account itself — the organization’s details, the administrator who signed up, billing, and the technical records of the service being used.
- We are a processor
- for everything your organization puts into the application: work orders, readings, equipment records, inspection records, photographs, and the names of the operators recorded against completed work. Your organization is the controller of that, and we act on its instructions.
So if you are an operator whose name appears against a completed step, your employer decides what happens to that record. Write to them; if you write to us, we will pass the request on rather than act on it ourselves.
The controller for the first category is Net Projekt d.o.o. za razvoj informacijskih sustava i tehnologije, Trinajstići 97, HR-51215 Kastav, Croatia, OIB 74530974731, reachable at info@ncoresystems.com.
02What we hold
- Account data
- the organization’s name and handle; each user’s name, username, role and language; an email address for those users who have one; the password, stored only as a bcrypt hash; the timezone and date format chosen for the account.
- Content data
- everything entered in the course of using the product — procedure templates, work orders and the readings and answers recorded on them, equipment records and their history, faults, inspection records, service records, and uploaded documents and photographs.
- Attribution data
- which user completed which step and when. This is the point of the product, and it cannot be switched off without the records ceasing to be evidence of anything.
- Technical data
- your IP address, handled transiently to apply rate limits and to stop sign-in and API abuse, and ordinary server logs of requests and errors.
We do not ask for and do not want special categories of personal data — health, biometrics, trade union membership, and so on. Please do not put them into free-text fields or photographs.
03Why, and on what legal basis
- Performance of a contract
- Art. 6(1)(b) GDPR — creating and running the account, authenticating users, delivering the service, issuing invoices.
- Legitimate interests
- Art. 6(1)(f) GDPR — keeping the service secure and available: rate limiting, abuse prevention, error logs, and backups. Our interest is in a service that stays up and is not broken into; we judge that this does not override your rights, because the data used for it is minimal and is not used to profile anyone.
- Legal obligation
- Art. 6(1)(c) GDPR — retaining invoices and accounting records for the period Croatian accounting legislation requires.
For content data your organization determines the purpose and the basis; we process it only on its instructions.
We do not profile you, we do not make automated decisions with legal effect about you, and we do not use your data for advertising.
04Cookies and what is stored on your device
One optional cookie set: Google Analytics, which counts visits to the public pages. It is loaded only if you accept it when asked, nothing is requested from Google before that, and refusing costs you nothing — the site works identically either way. The legal basis is your consent, and you can withdraw it from the "Cookie settings" link in the footer.
Nothing else is loaded from a third party. The fonts are served from this application rather than from Google.
The application also keeps a few things in your browser’s local storage: your sign-in token, which organization you are in, your answer to the analytics question, and the preferences you set yourself such as language and theme. All of it is either strictly necessary to sign you in or a setting you chose, and none of it is shared.
06How long we keep it
Account and content data are kept for as long as the organization exists, because the point of the product is a history that outlasts the people who remember it.
After an organization is terminated the data remains available for export for a limited period, and is then deleted from the live database. Backups age out on their own rolling schedule, so a deleted record can persist in a backup for a short time after it has gone from the live system.
Invoices and accounting records are kept for the period Croatian accounting legislation requires, regardless of account deletion, because we are obliged to keep them.
07Your rights
Under the GDPR you have the right to:
- ask what personal data we hold about you, and get a copy;
- have inaccurate data corrected;
- have data erased, where we have no overriding obligation or legitimate ground to keep it;
- ask us to restrict processing, or object to processing based on legitimate interests;
- receive data you gave us in a portable, machine-readable form;
- complain to a supervisory authority.
To exercise any of these, write to info@ncoresystems.com. We will respond within one month. If your request concerns content data — records inside a customer’s organization — we will forward it to that organization, because it is the controller and the decision is theirs.
You may complain to Agencija za zaštitu osobnih podataka (AZOP), Selska cesta 136, 10000 Zagreb, Croatia, or to the supervisory authority where you live or work.
08How it is protected
The measures below are not aspirations; they are what the software actually does.
- Passwords are stored as bcrypt hashes and never in clear. So are API keys, of which only a short non-secret prefix is kept readable.
- Each organization’s rows are fenced off in the database itself by row-level security policies, so a query cannot cross tenants even if application code forgets a filter.
- Sign-in and the integration API are rate limited per address, which is what the IP handling described above is for.
- API keys are scoped to what an integration actually needs and can be revoked at any time.
- The application makes no third-party requests, so no data leaks sideways through an embedded script or font.
No system is perfectly secure. If you find a vulnerability, please write to us before disclosing it publicly, and we will work with you.
09Children
The service is sold to businesses and is not directed at children. We do not knowingly create accounts for anyone under 16.
10Changes to this policy
We may update this policy as the service changes. The date at the end of this page is the date it last changed, and material changes are notified to administrators by email.
Questions about this policy, or about anything above, go to info@ncoresystems.com.
