Privacy Policy
Last updated: July 26, 2026
Neviox Digital ("we," "our," or "us") operates nevioxdigital.com under a privacy-by-design architecture. This policy explains what personal data we process, why, for how long, and who we share it with — strictly within the framework of the EU GDPR and the Croatian Electronic Communications Act (ePrivacy).
1. Data Controller
Neviox Digital Address: Peričićeva 14, 21000 Split, Croatia VAT ID (OIB): 25887842376 Email: info@nevioxdigital.com For this website, Neviox Digital is the data controller. For client engagements, roles are defined separately in the service agreement.
2. Data-Minimal Architecture
In accordance with the principle of Data Minimization (Art. 5 GDPR), Neviox Digital does not maintain a local SQL or NoSQL user database.
- We do not store your personal details, passwords, or other identifying data on our own physical servers.
- Data is processed "in-flight" and is only retained by designated sub-processors for specific project-related purposes.
- Content is managed via Sanity.io, which acts as a headless content store and does not track individual site visitors.
3. Project Inquiries & Communications
When you submit a contact form or use our Project Calculator:
- Email delivery: data is transmitted via Resend (secure TLS encryption).
- AI processing: requirements are processed via OpenAI and Pinecone to generate technical estimates. We use API-tier accounts where data is not used for training public models.
4. AI Chat Assistant
Our website chat widget uses OpenAI to generate responses and Pinecone to retrieve relevant context about our services (technical embeddings, not personal profiling). The full text of your conversation is sent to OpenAI and Pinecone to generate an answer. We do not persist chat transcripts in our own systems beyond the active session; OpenAI and Pinecone process this content under their API-tier terms, which exclude your data from being used to train their public models. Avoid sharing sensitive personal data (health records, financial account numbers, government IDs) in the chat — it is not the right channel for it.
5. Interactive Map
The map on our Contact page is click-to-load: nothing is requested from our map provider, MapTiler (Frankfurt, EU), until you click "Load Map" yourself. No cookie consent is required for this, because loading it is your own direct action, not something we trigger automatically.
6. Analytics & Tracking (Strict Opt-In)
A. Vercel Analytics (Privacy-First)
Standard, cookieless site-health monitoring. No personal identifiers, no consent required.
B. PostHog EU (Consent Required)
Hosted in Frankfurt, Germany. PostHog's script only loads in your browser, and our servers only forward form-submission events to it, after you click "Accept" in our cookie banner. Business-event data we forward (e.g., "contact form submitted") is anonymous — it is never linked to your name or email address.
C. Session Recording
Once you consent to analytics, PostHog also records an anonymized replay of on-page interactions (mouse movement, clicks, scrolling, and form field focus — not the characters you type) starting a few seconds after consent, to help us find usability issues. This is more detailed than aggregate analytics, so we name it separately here. You can avoid it entirely by declining analytics consent, or stop it anytime via "Manage Cookies" in the footer.
7. Bot & Fraud Detection
We use Vercel BotID to detect automated or fraudulent form submissions before they reach our inbox. This runs on every form submission, based on our legitimate interest in keeping our contact channels free of spam and abuse (Art. 6(1)(f) GDPR). It does not build cross-site advertising profiles and does not require consent.
8. Social Media APIs & Content Automation
We use automated API integrations to streamline our digital presence across external platforms, including but not limited to Meta (Facebook/Instagram), Google Business Profile, Pinterest, and LinkedIn.
- Purpose: these integrations are used exclusively for outbound content distribution (e.g., automating post creation, scheduling, and updates).
- Data scope: our automation workflows do not ingest, scrape, or store personal data from these platforms. We do not maintain databases of your social media profiles, follower lists, or private messages.
- Orchestration: we use secure automation middleware (e.g., n8n) to facilitate these triggers. Data processed during these triggers is transient and is not retained by Neviox Digital after the content post executes.
9. Data Retention
We keep personal data only as long as the purpose it was collected for requires, or as long as the law demands. Where we cannot commit to an exact deletion date, we describe below the criteria that determine it (Art. 13(2)(a) GDPR).
| Contact, careers, audit & calculator form submissions | Kept in our mailbox for up to 24 months from your last message, unless a signed service engagement extends this (see Invoicing below). |
| Invoicing & accounting records | 11 years, per Croatian accounting law (Zakon o računovodstvu) — a legal obligation that overrides deletion requests for these specific records. |
| Newsletter subscriber list (Brevo) | Until you unsubscribe, or after 24 months without any email engagement, whichever comes first. |
| Analytics & session-replay events (PostHog EU) | Per our PostHog project's configured retention window (currently 12 months), then automatically deleted. |
| AI chat conversations (OpenAI / Pinecone) | Not stored by us beyond your active chat session; processed by OpenAI and Pinecone under their API data-handling terms, excluded from model training. |
| Security & bot-detection logs (Vercel, BotID) | Standard hosting-provider log retention (typically 30 days), used only for security and abuse prevention. |
10. International Data Transfers
Analytics (PostHog EU) and map tiles (MapTiler) stay within the EEA. Some processors — OpenAI, Pinecone, Resend — may process data in the US. We rely on Standard Contractual Clauses and verify that our US-based processors are certified under the EU-U.S. Data Privacy Framework where applicable.
11. Your Rights
Under the GDPR, you have the right to access, rectify, or erase your data, to object to processing based on our legitimate interest, and to receive a portable copy of data you provided to us. Because we do not maintain a central local database, deletion or access requests are propagated across our processors (PostHog, Brevo, Resend, and our automation logs).
Contact info@nevioxdigital.com to exercise any of these rights. You may also lodge a complaint with the Croatian Personal Data Protection Agency (AZOP, azop.hr).