Philosophy Approach Council Partners Contact Get in touch
Legal

Privacy and Cookie Policy

Last updated: 7 May 2026 · Version 1.0

Centar za inovacije d.o.o., trading as Innovation Institute & Center, takes the protection of personal data seriously. This policy explains what information we collect when you visit innovation-institute.eu or correspond with us, why we collect it, how we use it, and the rights you have under EU data protection law.

The policy is written in plain language. If anything is unclear, please contact us using the details below and we will be glad to explain.

01

Who we are (data controller)

The data controller responsible for the processing of personal data described in this policy is:

Data Controller

Centar za inovacije d.o.o.

Desinićka ulica 5, 10000 Zagreb, Croatia

OIB (VAT/Tax ID): 98345295215

Email: office

Website: innovation-institute.eu

For any question about how we handle personal data, or to exercise any of the rights described below, please write to us at the email address above.

02

What data we collect and why

We only collect personal data that we need for a clearly defined purpose. The categories below describe everything we process when you interact with us through this website or by email.

A. Website analytics

When you visit innovation-institute.eu, we use Google Analytics 4 to understand how visitors find and use the site (pages viewed, approximate location, device type, referral source, time on page). This data helps us improve content and structure. Analytics tracking only runs after you give consent through our cookie banner. Until then, no analytics data is collected.

Legal basis: your consent.

B. Correspondence

When you write to us at office@innovation-institute.eu, we receive your name, email address, and the content of your message. We use this information to respond to you and, where relevant, to discuss potential collaboration or services.

Legal basis: our legitimate interest in responding to inquiries and managing client communication, or pre-contractual measures at your request where you contact us about engaging our services.

C. Client engagements

If you become a client, we process the personal data necessary to deliver the agreed services. This typically includes contact details of designated representatives, information shared during workshops, research, or consulting projects, and any data required for invoicing and accounting.

Legal basis: performance of a contract and compliance with our legal obligations under Croatian tax and accounting law.

D. Cookies and similar technologies

We use a small number of cookies to make the site work, remember your consent choices, and (with your permission) measure traffic. Full details are in section 5 below.

03

Who we share data with

We do not sell or rent personal data. We share limited data only with carefully selected service providers ("data processors") that help us operate the website and our business. Each of them is bound by a data processing agreement and is permitted to use your data only for the purposes we instruct.

Service provider Purpose Location
Netlify, Inc. Website hosting and content delivery USA (EU-US Data Privacy Framework)
Google LLC Website analytics (Google Analytics 4) USA (EU-US Data Privacy Framework)
Cybot A/S (Cookiebot) Cookie consent management Denmark (EU)

If we engage additional processors in the future (for example, a CRM system or email marketing tool), we will update this policy and, where required, ask for your consent before any new processing begins.

We may also disclose personal data to public authorities when required by law, court order, or a legitimate request from a competent authority.

04

International data transfers

Some of our service providers are based outside the European Economic Area, primarily in the United States. Where this is the case, the transfer is protected by the European Commission's adequacy decision under the EU-US Data Privacy Framework, or by Standard Contractual Clauses approved by the European Commission, together with additional safeguards required by EU data protection law.

If you would like more information about the specific transfer mechanism used for any provider, please contact us at the email address above.

05

Cookies and tracking

A cookie is a small text file stored on your device when you visit a website. We use cookies for two purposes: to make the site function properly, and (only with your consent) to understand how visitors use it.

Categories we use

  • Strictly necessary cookies are required for the site to work and to remember your cookie preferences. They cannot be switched off and do not require consent under EU law.
  • Statistics cookies are used by Google Analytics 4 to measure how visitors use the site. These are only set after you give consent.
  • Marketing cookies are not currently used. If we add advertising or retargeting tools in the future, they will be added to this category and will only run after your explicit consent.

Managing your consent

You can change or withdraw your consent at any time by clicking the cookie icon at the bottom of any page on this website. Withdrawing consent will not affect the lawfulness of any processing carried out before withdrawal.

Full list of cookies on this site

The list below is generated automatically by our consent management platform and reflects the actual cookies currently in use. It is updated as the site changes.

06

How long we keep your data

We retain personal data only for as long as we need it for the purpose it was collected for, or for as long as we are required to keep it by law.

Type of data Retention period
Email correspondence Up to 2 years from the last communication, unless we need to keep it longer to deal with a legal claim or to fulfil a contract
Analytics data (Google Analytics 4) 14 months (default GA4 retention setting)
Cookie consent records 12 months from the date consent was given or refused
Client contracts and invoices 11 years, in accordance with Croatian accounting and tax law
07

Your rights

EU data protection law gives you a set of rights with respect to your personal data. You can exercise any of them by writing to office@innovation-institute.eu. We will respond within one month.

  • Right of access: you can ask us to confirm whether we are processing your data and to receive a copy.
  • Right to rectification: you can ask us to correct inaccurate or incomplete data.
  • Right to erasure: you can ask us to delete your data when it is no longer needed for the purpose it was collected.
  • Right to restriction of processing: you can ask us to limit how we use your data in certain circumstances.
  • Right to data portability: for data you provided to us based on consent or a contract, you can ask to receive it in a structured, commonly used format.
  • Right to object: you can object to processing based on our legitimate interests.
  • Right to withdraw consent: where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of earlier processing.
  • Right not to be subject to automated decision-making: we do not make decisions about you using only automated means.
  • Right to lodge a complaint: you may also contact the competent data protection supervisory authority in your country if you believe your rights have not been respected.

We will not charge a fee for handling your request, unless it is manifestly unfounded or excessive (for example, repetitive). We may ask for proof of identity to make sure we are responding to the right person.

08

Security and integrity

We apply technical and organisational measures appropriate to the sensitivity of the data we process. These include encrypted connections (HTTPS), restricted access to systems holding personal data, contractual confidentiality with all partners and processors, and regular review of our security practices. No system is completely immune to risk, but we treat the protection of personal data as an ongoing responsibility, not a one-time compliance task.

09

Changes to this policy

We may update this policy from time to time, for example when we add new services, change a service provider, or when the law changes. The date at the top of this page indicates when the most recent update was made. For material changes that affect how your data is processed, we will provide a clear notice on the website.

10

Contact us

For any question about this policy or about how we handle personal data, please write to office.