Privacy
Privacy notice
This notice explains why and how data is processed. It is not a contract you accept merely by browsing this website.
Content reviewed: 27 September 2026.
1. Who processes data
FynTwin d.o.o., Rudeška cesta 238, 10000 Zagreb, Croatia, Croatian tax ID (OIB) 48151066729, is the controller for contact information, newsletter subscriptions and its own business relationships. Privacy enquiries and data-subject requests: info@fyntwin.com.
For financial data a client enters into the application, FynTwin acts in the agreed role and under the client’s instructions. The client may be the controller and FynTwin the processor; details are governed by a data processing agreement.
2. Contact enquiries and offers
The contact form receives your name, email, optional company, area of interest and message, enquiry source and technical data needed to prevent abuse. Provide only information needed for the enquiry; do not submit financial files or sensitive personal data through this form.
Responding to your request for a demonstration or offer may be necessary for pre-contractual steps (GDPR Article 6(1)(b)). Business communication with company representatives and system protection rely on legitimate interests (Article 6(1)(f)), subject to your right to object. Contacting us does not subscribe you to marketing.
Enquiries are stored in Cloudflare D1. The database currently runs in the European EEUR region; a mandatory EU jurisdiction is not configured. Resend delivers messages. Offers also involve recipient information, delivery and acceptance statuses and supporting evidence, including timestamps and security records. These support contracting, performance of the relationship and legal claims.
3. Optional newsletter
Subscription is separate from an enquiry and relies on consent. We activate an address after its owner confirms a link sent by email. An unconfirmed request does not create an active subscription.
Withdraw consent using the unsubscribe link in a message or by emailing info@fyntwin.com. Withdrawal does not affect the lawfulness of earlier processing. Newsletter withdrawal does not stop necessary messages about a contracted service.
4. Analytics, security and browser storage
When enabled, Plausible receives public-page events and allowlisted video playback events. We do not send form contents, email addresses, tokens or URL parameters. Referral information is reduced to an external domain. Events are excluded from administration, studio and offer pages.
Analytics uses no first-party analytics cookies, but this is not a claim that technical-data processing can never involve personal data. Cloudflare processes network information to deliver and protect the website; Turnstile checks form abuse.
Public-page language is determined by the URL. Private interfaces may remember an explicitly selected language in a functional cookie. Security cookies and sessions depend on the Cloudflare service and configuration; they do not all expire when the browser closes. This website does not integrate GA4, GTM, advertising tracking or Sentry.
5. Application, AI and international transfers
The application processes account and financial information for the agreed service. AI receives limited context needed for a response; filtering structured identifiers is not complete anonymisation. AI output requires professional review.
EU storage does not mean that all processing takes place in the EEA. AI providers, email delivery or support may involve processing outside the EEA. Applicable transfer mechanisms, such as an adequacy decision or standard contractual clauses with supplementary safeguards, depend on the provider and contract. Ask our contact channel for information about applicable safeguards.
The Security page describes relevant providers and distinguishes confirmed information from planned changes. Requested EU AI processing or ZDR is not represented as approved.
6. Retention
Retention depends on purpose: enquiries while needed to respond and conduct related business communication; subscriptions until consent is withdrawn; contractual and accounting records in accordance with applicable legal duties and legal-claim periods.
Deletion requests are assessed by data category. Information needed for a legal duty or claim may be retained for that restricted purpose. Backups and records have separate retention cycles. We do not promise immediate deletion from every copy.
For the retention period or criterion applicable to your enquiry, subscription or contract, email info@fyntwin.com. This notice does not claim automatic deletion of enquiries after six months or all logs after ninety days.
7. Your rights and complaints
Subject to the conditions in the GDPR, you may request access and a copy, rectification, erasure, restriction and portability. You may object to legitimate-interest processing and withdraw consent at any time.
Send requests to info@fyntwin.com. We may request proportionate proof of identity. We respond without undue delay, normally within one month; where an extension applies, we explain the reason and timing.
You may complain to the Croatian Personal Data Protection Agency (AZOP), azop.hr, or another competent supervisory authority. For data processed on a client’s behalf, we help direct your request to the appropriate controller.
8. Changes and further information
The review date appears above. We will communicate material changes to processing appropriately. Where a new purpose requires consent, continued browsing does not provide that consent.
See Security for relevant providers, AI processing and safeguards. For commercial terms, see the Terms of Use and your agreed offer.