Skip to content
Start Your Website

Legal

Privacy Policy

Last updated: September 22, 2026

This policy explains what personal data TOMICZ collects through the public website at tomicz.com, why we collect it, who helps us process it, and the choices you have.

This page covers the public marketing website only. The TOMICZ CMS is a separate product with its own terms, including how it handles personal data, and is not covered here.

Who we are

For this public website, the data controller is TOMICZ Darko Tomić s.p. Mrkonjić Grad (TOMICZ, we, us), a sole proprietorship registered in the Republika Srpska, Bosnia and Herzegovina.

Controller
TOMICZ Darko Tomić s.p. Mrkonjić Grad
Address
Podorugla bb, 70260 Mrkonjić Grad, Bosnia and Herzegovina
Tax ID (JIB)
4514477510009
Website
tomicz.com

What we collect

We collect only what is needed to run the website, reply to enquiries, publish client reviews, protect the forms from abuse, and understand whether the site is working.

  • Contact form messages

    When you submit the contact form, we collect your name, email address, optional company, message, the source of the form submission, and anti-spam signals such as the hidden honeypot field and form token. The same message is sent through EmailJS and captured in our CRM lead intake on api.tomicz.com on a best-effort basis.

    Legal basis: Your request before a contract, our legitimate interest in replying to enquiries and keeping a record of business leads, and consent where required.

  • Direct email

    If you email us directly, we receive the email address, name, message content, and any other information you choose to include.

    Legal basis: Your request before a contract and our legitimate interest in business communication.

  • Client reviews

    Clients we have worked with can leave a review through a one-time link we send them. The form collects a star rating and your review, and optionally your name, your business or location, and a photo. It does not ask for your email address. The photo is re-encoded to a small image no wider than 480 pixels, with all metadata removed, including any location (GPS) tags, and the original file is never kept. Every review waits for our approval, and once approved the rating, review, name, business or location, and photo are shown publicly on tomicz.com.

    Legal basis: Your consent, which you give by sending the review for publication. You can withdraw it at any time and we will take the review down.

  • First-party website analytics

    We use a first-party analytics beacon to understand traffic, popular pages, referrers, rough country, and engagement. It sets no cookies and the backend does not store raw IP addresses or raw user agents. Visitors are counted with a salted daily hash.

    Legal basis: Our legitimate interest in measuring and improving the website without identifying individual visitors.

  • Google Analytics after opt-in

    If you accept analytics cookies, Google Analytics 4 may load and process usage data such as page views, device and browser information, approximate location, and interactions. If you decline or ignore the banner, GA4 does not load.

    Legal basis: Your consent.

  • Cloudflare Turnstile

    When Turnstile is configured, the contact form loads Cloudflare Turnstile to check whether the submission is likely to be human. It may process technical browser and challenge data and returns a token used by our backend to validate the submission.

    Legal basis: Our legitimate interest in protecting the website and contact form from spam and automated abuse.

  • Social and external links

    Links to LinkedIn, Instagram, and other external websites are ordinary links. We do not embed those platforms on the site. If you click through, their own privacy policies apply.

    Legal basis: No data is shared with those platforms by this website unless you choose to click a link.

Cookies and local storage

The consent banner stores your analytics choice in your browser so we can remember whether you accepted or declined analytics. This is a functional setting and is not used to track you across websites.

Google Analytics cookies are only used if you accept analytics. If you decline or ignore the banner, GA4 is not loaded and those cookies are not set by this website.

How we use the data

We use personal data to reply to enquiries, discuss possible work, keep a business record of messages you send us, publish the reviews clients send us, protect the forms from spam, operate the website, measure website performance, and improve the content and user experience.

We do not sell personal data. We do not use website contact messages for unrelated advertising lists.

Service providers

We use a small number of providers to run the public website and process enquiries.

  • EmailJS

    Sends contact form submissions from the browser to our email inbox.

    United States and other locationsEmailJS privacy policy

  • Google Analytics

    Processes analytics only after you accept analytics cookies.

    United States and other locationsGoogle privacy policy

  • Cloudflare

    Provides CDN, security, proxying, and Turnstile anti-spam checks when enabled.

    United States and other locationsCloudflare privacy policy

  • Namecheap

    Provides hosting infrastructure for the website.

    United States and other locationsNamecheap privacy policy

Some providers may process data outside Bosnia and Herzegovina and outside the European Economic Area. Where required, we rely on appropriate contractual or legal safeguards from those providers.

How long we keep data

Contact enquiries are kept for as long as needed to reply, manage the business relationship, handle follow-up, and meet legal or accounting obligations if work begins.

Client reviews stay on the site until you ask us to remove them or we take them down. A review link works once and stops working if it is not used in time.

Analytics data is kept only as long as it is useful for understanding website performance. First-party analytics is designed to be low-identification from the start.

Your rights

Under the Law on Personal Data Protection of Bosnia and Herzegovina (Official Gazette of BiH 12/25) and, where it applies to you, the EU General Data Protection Regulation (GDPR), you have the right to access, correct, delete, restrict, or object to the processing of your personal data. Where processing is based on consent, you can withdraw that consent at any time.

  • Ask what personal data we hold about you.
  • Ask us to correct inaccurate data.
  • Ask us to delete data when we no longer need it.
  • Object to or restrict certain processing.
  • Withdraw analytics consent by clearing the site's consent setting in your browser or using your browser privacy controls.

If you believe your rights have not been respected, you can complain to a supervisory authority: in Bosnia and Herzegovina, the Personal Data Protection Agency (Agencija za zaštitu ličnih podataka u BiH), Dubrovačka 6, 71000 Sarajevo, azlp.ba; if you are in the EU or EEA, the data protection authority in your country.

Security

We use HTTPS, security headers, anti-spam checks, limited public endpoints, and provider-level controls to protect the website and contact form. No website can guarantee perfect security, but we keep the public data surface narrow and do not ask for sensitive information through the contact form.

Changes to this policy

We may update this policy as the website, providers, company details, or law changes. When we do, we will update the date at the top of this page.

Contact

For questions about this policy or how we handle personal data on the public website, email us.

[email protected]