Privacy Policy
Last updated: 5 August 2026
1. Data Controller
Denis Čurčić, s.p., Petronijeva ulica 4, 6000 Koper (trading as HUMAX Ecosystem).
Company registration number: 8104778000 · Tax number: 70680825 · Ni zavezanec za DDV na podlagi 1. odstavka 94. člena ZDDV-1.
Contact for data protection queries: info@humax.si, +386 70 824 136. Based on an assessment under Article 37 of the GDPR and Article 41 of ZVOP-2 (Slovenian Personal Data Protection Act), the controller is not required to appoint a Data Protection Officer (DPO), as its core activity does not involve large-scale processing of special categories of personal data or systematic monitoring of individuals.
Roles: HUMAX is the data controller for its digital infrastructure — the website, contact form, appointment coordination, communications and the pseudonymised linking of biometric data. Our hosting, database, e-mail and analytics providers are our contracted processors. Independent licensed professionals who carry out measurements and expert consultations are independent controllers with respect to data arising from their own activity; when they carry out purely organisationally supported tasks on our behalf, they act as processors. HUMAX does not carry out healthcare activities and does not maintain medical records.
2. What Data We Collect
Contact form: name, e-mail address, phone number (optional), selected package tier (optional), the content of your message, and the time and content of your consent.
Technical data: the requesting IP address is used solely to prevent abuse of the form (submission rate limiting) and is not stored in a database.
Analytics: with your consent, anonymised visit data (see our cookie policy).
We do not collect biometric or health data through the website. Any data on physiological parameters and measurements is processed exclusively separately, outside this website, based on a specific, explicit and written consent of the individual in accordance with Article 9(2)(a) of the GDPR and under strict pseudonymisation conditions.
3. Legal Bases and Purposes of Processing
Consent (Article 6(1)(a) GDPR) — handling your inquiry submitted via the form and analytics cookies. You may withdraw your consent at any time.
Performance of a contract (point (b)) — preparing an offer, the initial consultation and the delivery of the agreed services.
Legitimate interest (point (f)) — website security and prevention of abuse of the contact form.
Legal obligation (point (c)) — retention of accounting records.
Specific processing purposes:
- responding to contact-form inquiries and preparing an individual offer (consent, performance of a contract);
- coordinating appointments with independent professionals and providing organisational support (performance of a contract);
- handling GDPR rights requests and documenting their resolution (legal obligation, Article 12 GDPR);
- issuing and retaining invoices and other accounting obligations (legal obligation);
- preventing abuse of forms and administrative logins, security event logs (legitimate interest);
- measuring website traffic with anonymised analytics (consent);
- technical pseudonymisation and linking of measurements under a coded identifier (explicit consent, Article 9(2)(a) GDPR).
4. Recipients and Processors of Data
We do not sell, lend or share your data with advertising networks. Access is limited to our contracted processors, with whom we have data processing agreements in place (Article 28 GDPR):
- Website hosting and database provider (Supabase / Cloudflare infrastructure, EU region) — website hosting, storage of submitted forms and GDPR requests; processing within the EU.
- E-mail service provider — transmission and storage of correspondence with you; processing within the EU or under standard contractual clauses.
- Google Ireland Limited — web analytics (Google Analytics 4) with IP anonymisation, only with your consent; any transfer to the USA relies on the EU-US Data Privacy Framework.
- Members of our expert panel and cooperating specialists — solely to the extent necessary to perform the agreed service; they are independent controllers for data arising from their own professional activity.
- Accounting service provider — issuing and retaining invoices under a legal obligation.
We have a data processing agreement in place with every processor, setting out the purpose, duration, categories of data, security measures, a ban on further sub-processors without our approval, and deletion or return of data when the engagement ends. An up-to-date list of processors with exact company names is available on request by e-mail.
5. Transfers to Third Countries
Data is, as a rule, processed within the European Economic Area. Where an individual processor also processes data outside the EEA (e.g. the USA), the transfer is based on the European Commission's standard contractual clauses or the EU-US Data Privacy Framework, together with additional technical safeguards.
6. Retention Periods
- Contact form inquiries: up to 24 months from the last contact.
- Client data and contractual documentation: 5 years after the end of cooperation.
- Accounting records: 10 years, in accordance with tax legislation.
- Cookie consent record: until withdrawn or deleted in your browser (max. 12 months, after which we ask again).
- GDPR rights requests and evidence of their resolution: 3 years after the case is closed (accountability under Article 5 GDPR).
- Security event and login attempt logs: up to 12 months.
- Pseudonymised measurement records: until consent is withdrawn, and no longer than 5 years from the last measurement.
Once the retention periods expire, we permanently delete or irreversibly anonymise the data.
7. Pseudonymisation
All internal measurement records are pseudonymised. When we publish results, we display only coded identifiers (e.g. K-001, A-042). Names, dates of birth, locations and other identifiers are never disclosed without explicit consent.
8. Security Measures
We use encrypted data transmission (HTTPS/TLS), access restricted on a least-privilege basis, two-factor authentication for administrative access, regular backups, separate storage of biometric and contact data, and submission rate limiting on the contact form to prevent abuse.
9. Automated Decision-Making and Profiling
We do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.
10. Your Rights
You have the right to access your data, rectify it, erase it (the "right to be forgotten"), restrict processing, object to processing, data portability, and to withdraw your consent. Send your request to info@humax.si; we will respond within one month at the latest.
The fastest way is our data rights request form, where you select the type of request; we log every request and reply to the e-mail address you provide.
If you believe that processing violates the applicable regulations, you have the right to lodge a complaint with the supervisory authority: the Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, 1000 Ljubljana, gp.ip@ip-rs.si, +386 1 230 97 30.
11. Changes to this Policy
We may update this policy from time to time. Each version is marked with the date of its last update, and significant changes will be published on this page.