Privacy policy
Last updated: 28 September 2026
This policy explains which personal data we process when you visit terrasens.hr, sign up for the grow test results or get in touch with us, why we do it, how long we keep it and what your rights are. It follows the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Croatian Act on the Implementation of the GDPR (Official Gazette of the Republic of Croatia 42/18).
Controller
TerraSens, obrt za usluge, trgovinu i proizvodnju, Ulica Mate Kvešteka 12, 10340 Vrbovec, Croatia, OIB 34696997001.
For any privacy question, write to info@terrasens.hr or call +385 1 2791 556. We have not appointed a data protection officer, as none is required for the processing we do.
Visiting the website
The site is delivered and protected by Cloudflare (Cloudflare, Inc., San Francisco, USA) from its network of servers; a visit is usually served by the server closest to you. When you open the site, your browser sends Cloudflare technical data: your IP address, the date and time, the page you opened, the page you came from and your browser and operating system.
We need this data to deliver the site, protect it from attacks and fix faults. The legal basis is our legitimate interest in running the site securely (Art. 6(1)(f) GDPR). We do not combine the logs with other data or use them for advertising. Cloudflare keeps them only as long as needed to deliver and protect the site and then deletes them automatically; we only see totals and records of blocked attacks. Cloudflare processes the data on our behalf; the transfer to the USA relies on the EU-U.S. Data Privacy Framework, under which Cloudflare is certified, and on the EU Standard Contractual Clauses.
Fonts, images and video load from the site's own address (terrasens.hr); the site loads nothing from Google or social networks.
Visit statistics
We count visits with Cloudflare Web Analytics (Cloudflare, Inc., San Francisco, USA). It sets no cookies, stores nothing in your browser and does not recognise visitors by IP address, browser or any other data. We only see totals: how many visits there were, which pages were opened, which sites visitors came from, which countries and types of device the visits came from, and how fast the pages load.
The legal basis is our legitimate interest in knowing how much the site is read and whether it works well (Art. 6(1)(f) GDPR). You can object by writing to us or by blocking the script in your browser. Cloudflare processes this data on our behalf too, with the safeguards described above.
Signing up for the grow test results
If you sign up, we process your email address, the language of the page you signed up on and the time of sign-up and confirmation. The sign-up only takes effect once you click the link in the confirmation email (double opt-in); otherwise the address is not added to the list.
We only send you grow test results and important TerraSens news, such as the design reveal and the arrival of the first lamps. The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with the unsubscribe link in every email or by writing to us; this does not affect the lawfulness of processing before the withdrawal.
The list is kept and the emails are sent by our email service provider Brevo (Sendinblue SAS, Paris, France). Brevo records whether an email was opened and whether a link was clicked, so that we know which content is useful. If you don't want that, turn off automatic image loading in your email app.
We keep the data until you unsubscribe or we close the list. After you unsubscribe, we keep your address only on the unsubscribe list, so that we never email you again.
When you contact us
If you write to us or call us, we use your details (name, contact details and the content of your message) only to reply. The legal basis is our legitimate interest in answering enquiries and, if you ask about buying, steps prior to entering into a contract (Art. 6(1)(f) and (b) GDPR). Our email is provided by Microsoft (Microsoft Ireland Operations Ltd., Dublin, Ireland). We keep messages as long as they are needed for the reply and any follow-up, unless the law requires longer retention.
Who else sees the data
We do not sell data or use it for advertising. It is processed only by service providers that do the technical work for us, on our behalf and on our instructions: Cloudflare (delivering and protecting the site, visit statistics), Brevo (email to subscribers) and Microsoft (our email). We disclose data to public authorities only when the law requires us to.
We process data inside the EU. The exception is Cloudflare in the USA, with the safeguards described above. Where Brevo or Microsoft use subcontractors outside the EU for particular services, they do so under the EU Standard Contractual Clauses or another safeguard provided for by the GDPR.
Your rights
Under the GDPR you have the right:
- to access your data and get a copy (Art. 15)
- to have inaccurate data corrected (Art. 16)
- to have your data erased (Art. 17)
- to restrict processing (Art. 18)
- to data portability (Art. 20)
- to object to processing based on legitimate interest (Art. 21)
- to withdraw your consent at any time (Art. 7(3))
Send your request to info@terrasens.hr and we will reply within one month at the latest. If you believe we process your data unlawfully, you can lodge a complaint with the Croatian Personal Data Protection Agency (AZOP, Selska cesta 136, 10000 Zagreb, azop.hr) or with the supervisory authority in the country where you live or work.
Cookies
The site itself sets no cookies and stores nothing in your browser. One exception: if Cloudflare's protection needs to check that a visit is not automated, it may set a strictly necessary security cookie (cf_clearance), used only for protection, never for tracking. When you submit the sign-up form, your browser sends the data directly to Brevo.
Other
We make no automated decisions and do no profiling (Art. 22 GDPR). Providing data is voluntary; without an email address we cannot send you the results. The site is not intended for people under 16.
The site runs only over an encrypted connection (HTTPS), and access to the site administration and the subscriber list is protected by two-factor authentication.
We update this policy when the way we process data changes. The date of the last change is shown at the top; we will tell subscribers about significant changes by email.