Privacy

Privacy Policy

What viborc.com processes, why it is needed, who receives it, and the choices available to you.

This policy describes how viborc.com handles personal data when you read the publication, send a message, or subscribe to the newsletter. It also explains the service providers involved and the choices available to you. Materially different analytics, advertising, or embedded services will be reviewed and described before they are activated.

1. Who is responsible

viborc.com is operated by DUX Consulting, vl. Vibor Cipan, a Croatian sole-trader business (obrt), which is the data controller for the processing described in this policy.

  • VAT ID: HR03848388891
  • MBO: 97833665
  • Registration authority: Grad Zagreb, Gradski ured za gospodarstvo, Područni odsjek Sesvete
  • Privacy and data-rights contact: privacy@viborc.com

The publication does not require a reader account. You can read the static site without giving viborc.com your name, email address, phone number, or postal address.

2. Information processed

2.1 Ordinary visits

When a website is requested, hosting and security systems ordinarily receive technical request data such as the requested path, time, IP address, browser or user-agent information, response status, and security signals. This information is used to deliver the site, diagnose faults, and protect it from abuse. Ordinary Nginx request and security logs use a rolling operational retention of up to 90 days.

2.2 Contact messages

If you use the contact form, the service processes your required reply email, selected subject and message, any name you choose to provide, and the technical and security information needed to submit and protect the form. Cloudflare Turnstile also processes browser, network, and challenge signals needed to distinguish automated abuse. The form does not ask for a phone number or postal address. Without the required fields and successful anti-abuse check, the message cannot be sent.

2.3 Newsletter subscriptions

If you ask to join the newsletter, the service processes your email address, subscription source, consent and confirmation records, and delivery information needed to operate the list. A subscription becomes active only after you follow the confirmation link and confirm the request.

Do not use either form to send passwords, private keys, health or financial records, confidential source material, or other highly sensitive information.

3. Why information is used

Personal data is processed only for the relevant purpose:

  • to deliver the site reliably and protect it from abuse;
  • to receive, route, and answer messages you choose to send;
  • to send a newsletter you explicitly request and confirm;
  • to understand readership and improve content, navigation, accessibility, and site performance through a cookieless baseline and, where enabled, enhanced returning-visitor and session measurement, using consent where prior permission is required and the operator’s legitimate interests elsewhere;
  • to keep a record of withdrawal or suppression so an unsubscribe request is respected;
  • to establish, exercise, or defend legal claims and comply with legal duties.

Site delivery, security, fault diagnosis, and ordinary correspondence rely on the operator’s legitimate interests in running and protecting the publication and answering readers. Messages concerning possible work may also be processed to take steps you request before an engagement. Privacy requests are handled to meet legal obligations. Newsletter delivery relies on consent, which you may withdraw at any time. Where the cookieless baseline or automatic enhanced mode is permitted to run, analytics relies on the operator’s legitimate interests in measuring and improving the publication. Enhanced analytics relies on consent where prior permission is required. Through Manage your analytics choices on the privacy policy page, you may object by choosing Go cookieless or Turn analytics off, and you may withdraw an enhanced-analytics choice at any time.

4. Contact form

Contact submissions pass through a same-origin service operated for viborc.com and are delivered by Resend to the publication’s Google Workspace inbox. The relay does not store message bodies in an application database or application log. Resend, Google Workspace, and the inbox process the message and its delivery metadata so it can be received and answered.

The form may be used for editorial correspondence, corrections, privacy requests, and business, collaboration, or speaking enquiries. A later business engagement, if any, is agreed separately from the website.

The form uses bounded inputs, a required hidden anti-spam field, an independent request rate limit, and Cloudflare Turnstile in managed mode. The Turnstile browser runtime loads only on the contact page and stays out of the rest of the publication. It normally remains unobtrusive and asks for interaction only when Cloudflare considers that necessary.

Loading the contact page allows Cloudflare to receive the IP address and browser, device, page, and security signals ordinarily needed to deliver and operate the challenge. The resulting token is submitted to the viborc.com relay, which sends it to Cloudflare Siteverify before contacting Resend. The relay does not separately forward your IP address in its Siteverify request. Turnstile tokens expire after five minutes and can be validated only once. The relay does not store tokens, message bodies, or provider responses in its application database or application log. Its operational observations are limited to aggregate fixed-label outcomes without names, email addresses, message text, tokens, IP addresses, or user-agent strings.

Because the anti-abuse check runs in the browser, this protected form requires JavaScript. If JavaScript is unavailable, privacy and data-rights requests may be sent to the privacy email published in section 1.

5. Newsletter

The newsletter uses double opt-in. Entering an address sends a confirmation request; it does not add the address to the active mailing list. Only confirming the request completes the subscription. Every newsletter provides a free and easy unsubscribe method.

Resend operates the subscriber list and email delivery. The form requests an email address only; it does not ask for a name or profile information. The confirmation token is encrypted, opaque, and expires after 24 hours. At launch, the website uses this service only to collect and confirm double-opt-in subscriber addresses in Resend Contacts. It does not itself create an automated email sequence or send a newsletter campaign.

6. Analytics and privacy choices

PostHog Cloud EU uses two measurement modes behind a coarse regional control. In the EEA (the EU together with Norway, Iceland, and Liechtenstein), the United Kingdom, Switzerland, Canada, Brazil, and Türkiye, a cookieless baseline starts automatically and enhanced analytics begins only after you choose Enable enhanced analytics. In other recognized locations, enhanced analytics may start automatically. A missing, malformed, Tor, timed-out, or otherwise unknown location receives the cookieless baseline and the choice panel; it never enables enhanced analytics by default. PostHog analytics remains disabled in China pending a separate legal review.

The gate uses Cloudflare’s two-letter country signal only to make that immediate decision. The gate lookup is not written to local storage or sent to a separate geolocation provider. When analytics is active, the country code is included in the analytics data described below. An active Global Privacy Control signal keeps analytics limited to the cookieless baseline and prevents enhanced analytics from activating. That baseline cap applies only where PostHog analytics is otherwise available; China remains off regardless of the signal.

Choosing Go cookieless leaves only the baseline active. Choosing Turn analytics off stops both PostHog modes; ordinary site-delivery and security processing described in section 2.1 continues. The Manage your analytics choices section on this page lets you review or change a prior choice at any time, and its buttons reflect this browser’s current state, with the mode already in effect shown as active and disabled; the choice prompt links to it directly. The prompt offers enabling enhanced analytics or continuing with current settings; the complete set of controls, including turning analytics off, is on this page. An explicit off choice is respected regardless of location, while an allow choice cannot override China or an active Global Privacy Control signal.

Both modes use the same bounded event inventory: page and referring URLs, campaign context, editorial context, navigation and reading interactions, click and heatmap coordinates, Core Web Vitals, and general browser, device, viewport, language, timezone, and country-level technical information. The cookieless baseline retains no PostHog analytics identifier in a cookie, local storage, or session storage. Enhanced analytics adds first-party cookie, local-storage, and session-storage state with pseudonymous device and session identifiers so visits can be linked for returning-reader and session measurement. viborc.com does not call PostHog’s identify() method, attach contact or newsletter names and email addresses, or create person profiles. Session replay is disabled. Form contents, copied text, passwords, authentication tokens, city, region, precise geographic coordinates, and a stored IP field are excluded. Before a page or referring URL is collected, URL fragments and recognized credential or email query parameters are removed; other path and campaign details may remain so a referral can be understood.

For the cookieless baseline, PostHog uses the request IP address, user agent, project, hostname, and a daily salt at ingestion to derive a rotating daily identifier. The IP address is then discarded before ordinary event enrichment. Analytics is not combined with contact-message or newsletter content.

This is the analytics contract approved for viborc.com. The production service is activated only through the reviewed site build and same-origin relay; its deployment and operational proofs are maintained separately from this policy.

6.1 Manage your analytics choices

Review or change analytics for this browser. Availability may depend on your region, browser privacy signals, and any saved choice.

Privacy controls are loading. If they never become available, this browser blocked the script that runs them, and PostHog analytics stays off with it.

7. Advertising, cookies, and browser storage

The current static publication build does not load advertising scripts and does not set advertising cookies. An ads.txt file may name vendors authorized to sell advertising inventory; that text file does not itself track readers or load advertising technology.

The contact and newsletter forms do not require a reader account. When you make an explicit analytics choice, viborc.com stores one host-only preference cookie named viborc_analytics_consent for up to 180 days. It contains only the versioned choice to allow enhanced analytics, keep the cookieless baseline, or turn PostHog analytics off; it is not an analytics identifier and is not sent to PostHog. The cookie uses SameSite=Lax, the Secure attribute on HTTPS, and the / path so the choice works throughout the site. An automatic regional default does not create this preference cookie. Dismissing the choice prompt or choosing Continue with current settings records the baseline choice in the preference cookie. Choosing the baseline or off may leave the preference cookie in place so the choice can be respected.

The cookieless baseline does not retain a PostHog analytics identifier in a cookie, local storage, or session storage. Enhanced analytics uses a first-party set of PostHog cookie, local-storage, and session-storage records for the pseudonymous device and session identifiers described in section 6. Those records are not used for advertising or combined with contact or newsletter details. The controls are configured to clear accessible PostHog analytics state when you step down to the baseline or turn PostHog analytics off; the preference cookie may remain to remember that choice.

8. Service providers and transfers

Cloudflare supports network delivery and security and provides the Turnstile anti-abuse check on the contact page. Hetzner hosts the site, and Resend delivers contact and newsletter email. Google Workspace receives and stores correspondence sent through the contact form. PostHog Cloud EU is used for the two-mode, regionally controlled measurement described in section 6 where that service is enabled.

Resend (Plus Five Five, Inc.) processes contact and newsletter data in the United States. Transfers rely on the EU–US Data Privacy Framework while Resend remains certified and on the European Commission’s Standard Contractual Clauses where applicable. Information about applicable safeguards may be requested through the privacy contact. PostHog Cloud EU stores project data in its EU region. PostHog and its documented subprocessors may process that data where needed to operate and support the service under the applicable contractual safeguards.

Articles may link to external websites. Following a link places you under that site’s privacy practices, which viborc.com does not control. Some future pages may include third-party media or interactive content. Where required, the provider will not be contacted until you choose to load, play, or interact with it. Once activated, that provider may receive your IP address, browser or device information, and the page URL, and may use its own technologies under its privacy policy.

9. Retention

Contact messages remain in the delivery and inbox systems while the correspondence, a related engagement, a legal duty, or a reasonable need to establish or defend a claim remains. Turnstile challenge tokens expire after five minutes, are single-use, and are not retained by the relay after verification. Newsletter confirmation tokens expire after 24 hours. Active newsletter records are kept until you unsubscribe or the service ends; a minimal suppression record may remain so the withdrawal is honoured. Ordinary Nginx request and security logs are retained on a rolling basis for up to 90 days to investigate faults, abuse, and security events. The analytics preference cookie expires after 180 days unless you replace the choice earlier. Enhanced-analytics PostHog cookie records are configured for no more than 180 days. Enhanced local-storage records have no independent browser expiry and remain until they are cleared through Manage your analytics choices or by the reader; session-storage records ordinarily end with the browser session. The operator will periodically review retained records and delete them when their purpose no longer applies.

PostHog analytics event records may be kept for up to seven years (84 months). This long horizon allows viborc.com to compare search performance, topic interest, content quality, navigation, and site performance over time. The necessity of that period is reviewed at least annually. Analytics event records are never sold or resold, used to build advertising profiles, or used for direct marketing. They are not combined with contact-message or newsletter content. Newsletter delivery remains a separate, expressly confirmed service. Session replay is disabled and therefore creates no replay-retention record.

10. Your rights

Subject to applicable law, you may ask for access, correction, deletion, restriction, portability, or information about personal data concerning you. You may object to analytics based on legitimate interests, withdraw consent for enhanced analytics, and withdraw consent for future newsletter messages at any time. The Manage your analytics choices section of the privacy policy page lets you keep only the cookieless baseline or turn PostHog analytics off. An active Global Privacy Control signal keeps analytics limited to the cookieless baseline and prevents enhanced analytics from activating. That baseline cap applies only where PostHog analytics is otherwise available; China remains off regardless of the signal. Withdrawal does not affect lawful processing that occurred before it.

Email privacy@viborc.com, or use the contact form and select Privacy or data request. Provide only enough information to identify the request. Identity may need to be verified before personal data is disclosed or changed.

You may also complain to the Croatian Personal Data Protection Agency (AZOP) or the competent data-protection authority where you live or work. AZOP explains how to lodge a complaint.

11. Security

Reasonable technical and organizational safeguards are used to limit access, reduce unnecessary collection, and protect data in transit and at rest. No internet transmission or storage system can be guaranteed completely secure.

12. Children

viborc.com is a general-audience publication and is not designed to collect personal data from children. If you believe a child has submitted personal data through a form, use the contact page so the matter can be reviewed.

13. Changes to this policy

Material changes will be published on this page with a new effective date. The current version applies from the date shown above.