Privacy policy

This policy explains what personal data Ncore handles, why, and what you can do about it. It covers both this website and the application behind it.

01Two different relationships

There are two distinct roles in this service, and which one applies decides who you should contact about your data.

We are the controller
for the data of the account itself — the organization’s details, the administrator who signed up, billing, and the technical records of the service being used.
We are a processor
for everything your organization puts into the application: work orders, readings, equipment records, inspection records, photographs, and the names of the operators recorded against completed work. Your organization is the controller of that, and we act on its instructions.

So if you are an operator whose name appears against a completed step, your employer decides what happens to that record. Write to them; if you write to us, we will pass the request on rather than act on it ourselves.

The controller for the first category is Net Projekt d.o.o. za razvoj informacijskih sustava i tehnologije, Trinajstići 97, HR-51215 Kastav, Croatia, OIB 74530974731, reachable at info@ncoresystems.com.

02What we hold

Account data
the organization’s name and handle; each user’s name, username, role and language; an email address for those users who have one; the password, stored only as a bcrypt hash; the timezone and date format chosen for the account.
Content data
everything entered in the course of using the product — procedure templates, work orders and the readings and answers recorded on them, equipment records and their history, faults, inspection records, service records, and uploaded documents and photographs.
Attribution data
which user completed which step and when. This is the point of the product, and it cannot be switched off without the records ceasing to be evidence of anything.
Technical data
your IP address, handled transiently to apply rate limits and to stop sign-in and API abuse, and ordinary server logs of requests and errors.

We do not ask for and do not want special categories of personal data — health, biometrics, trade union membership, and so on. Please do not put them into free-text fields or photographs.

03Why, and on what legal basis

Performance of a contract
Art. 6(1)(b) GDPR — creating and running the account, authenticating users, delivering the service, issuing invoices.
Legitimate interests
Art. 6(1)(f) GDPR — keeping the service secure and available: rate limiting, abuse prevention, error logs, and backups. Our interest is in a service that stays up and is not broken into; we judge that this does not override your rights, because the data used for it is minimal and is not used to profile anyone.
Legal obligation
Art. 6(1)(c) GDPR — retaining invoices and accounting records for the period Croatian accounting legislation requires.

For content data your organization determines the purpose and the basis; we process it only on its instructions.

We do not profile you, we do not make automated decisions with legal effect about you, and we do not use your data for advertising.

04Cookies and what is stored on your device

One optional cookie set: Google Analytics, which counts visits to the public pages. It is loaded only if you accept it when asked, nothing is requested from Google before that, and refusing costs you nothing — the site works identically either way. The legal basis is your consent, and you can withdraw it from the "Cookie settings" link in the footer.

Nothing else is loaded from a third party. The fonts are served from this application rather than from Google.

The application also keeps a few things in your browser’s local storage: your sign-in token, which organization you are in, your answer to the analytics question, and the preferences you set yourself such as language and theme. All of it is either strictly necessary to sign you in or a setting you chose, and none of it is shared.

The full list, cookie by cookie and key by key →

05Who else sees it

We do not sell personal data and we do not share it for anyone else’s marketing. There are no advertising networks and no third-party AI providers involved in this service.

One analytics provider is involved, and only for visitors who agreed to it: Google Ireland Limited, which processes visit statistics for the public pages as our processor. It never sees anything from inside a signed-in account — no work orders, no equipment, no procedures, no customer records. The cookie policy sets out what it receives, where it goes and how to withdraw.

Transactional email — address verification, invitations and password resets — is sent from our own mail server, so no email delivery provider receives your address.

We will disclose data to a public authority only where a legally binding request requires it, and we will tell the affected organization unless we are prohibited from doing so.

06How long we keep it

Account and content data are kept for as long as the organization exists, because the point of the product is a history that outlasts the people who remember it.

After an organization is terminated the data remains available for export for a limited period, and is then deleted from the live database. Backups age out on their own rolling schedule, so a deleted record can persist in a backup for a short time after it has gone from the live system.

Invoices and accounting records are kept for the period Croatian accounting legislation requires, regardless of account deletion, because we are obliged to keep them.

07Your rights

Under the GDPR you have the right to:

  • ask what personal data we hold about you, and get a copy;
  • have inaccurate data corrected;
  • have data erased, where we have no overriding obligation or legitimate ground to keep it;
  • ask us to restrict processing, or object to processing based on legitimate interests;
  • receive data you gave us in a portable, machine-readable form;
  • complain to a supervisory authority.

To exercise any of these, write to info@ncoresystems.com. We will respond within one month. If your request concerns content data — records inside a customer’s organization — we will forward it to that organization, because it is the controller and the decision is theirs.

You may complain to Agencija za zaštitu osobnih podataka (AZOP), Selska cesta 136, 10000 Zagreb, Croatia, or to the supervisory authority where you live or work.

08How it is protected

The measures below are not aspirations; they are what the software actually does.

  • Passwords are stored as bcrypt hashes and never in clear. So are API keys, of which only a short non-secret prefix is kept readable.
  • Each organization’s rows are fenced off in the database itself by row-level security policies, so a query cannot cross tenants even if application code forgets a filter.
  • Sign-in and the integration API are rate limited per address, which is what the IP handling described above is for.
  • API keys are scoped to what an integration actually needs and can be revoked at any time.
  • The application makes no third-party requests, so no data leaks sideways through an embedded script or font.

No system is perfectly secure. If you find a vulnerability, please write to us before disclosing it publicly, and we will work with you.

09Children

The service is sold to businesses and is not directed at children. We do not knowingly create accounts for anyone under 16.

10Changes to this policy

We may update this policy as the service changes. The date at the end of this page is the date it last changed, and material changes are notified to administrators by email.

Questions about this policy, or about anything above, go to info@ncoresystems.com.

Last changed 10 August 2026