CRA full compliance required 453 days left What it means for you
THZ Networks Under attack? SOS — incident response, any hour of any day

LEGAL

Privacy notice

What this website collects, why, how long it is kept and what you can ask us to do about it. Written to GDPR articles 13 and 14, and specific to this site rather than copied from a generator.

Who is responsible

ATA sistemi d.o.o. — the company trading as THZ Networks and TeraHertz CyberSecurity — is the controller for the personal data described here. Registered office: Kajuhova ulica 12, 3310 Žalec. Correspondence: Cesta v Gorice 36, 1000 Ljubljana, Slovenia. Write to info@thz.net or call +386 51 249 533.

We have not appointed a Data Protection Officer. Slovenian law requires one only for public bodies and for controllers whose core activity is large-scale monitoring or large-scale processing of special-category data; neither applies to this website. Send data-protection questions to the address above and they reach the people who can answer them.

What the enquiry form collects

If you send us an enquiry we store what you typed: your name, your email address, your organisation and phone number if you gave them, your message, the language you were reading in, the wording of the consent you agreed to, the time, and the IP address the request came from.

The IP address is stored for one reason: the form is rate-limited per address to stop it being used to send mail on someone else's behalf. It is not used to identify you and it is not looked up anywhere.

The legal basis is Article 6(1)(b) GDPR — steps taken at your request before entering into a contract — together with Article 6(1)(f), our legitimate interest in keeping the form usable and answering the people who write to us. Giving us the data is voluntary; without it we cannot reply.

How long we keep it

Enquiries are deleted automatically 24 months after they arrive, by a scheduled job rather than by anyone remembering to do it. If the enquiry turns into a contract, the contract and the records that go with it are kept for as long as tax and accounting law requires.

Web server logs, which record the requested address, the time, the response code, the browser string and the IP address, are rotated weekly and deleted after no more than three weeks. They exist to keep the service running and to investigate abuse.

Cookies and tracking

This website sets no cookies. There is no analytics, no advertising pixel, no embedded video, no web font loaded from someone else's server, no chat widget and no social plugin. Nothing on any page makes a request to a third-party domain.

That is why there is no cookie banner: under ZEKom-2 article 157 consent is required before storing anything on your device, and we store nothing. If that ever changes, the banner arrives with it.

Members of staff who sign in to administer the site get a session cookie, as any login does. That is strictly necessary for the service they asked for and exempt from the consent requirement.

Who else sees it

This site runs on infrastructure we operate ourselves in Slovenia, and the enquiry itself is stored in our own database. There is no external form service, no CRM, no marketing platform and no cloud analytics in the path.

One processor is involved and it is fair to name it: the notification email is sent from our own mail server to our info@thz.net mailbox, which is hosted for us by an external email provider in Slovenia. They process what is in that message on our instructions and for no other purpose. Beyond that, nobody outside the company sees an enquiry unless the law obliges us.

No personal data from this site is transferred outside the European Economic Area.

Your rights

You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, object to processing based on legitimate interest, and ask for it in a portable form. Where processing rests on consent you can withdraw that consent at any time, which does not affect what was lawful before you did.

Write to info@thz.net. We answer within one month. We will ask you to identify yourself only so far as is necessary to be sure we are not handing your data to somebody else.

If you think we have handled your data badly you can complain to the Slovenian supervisory authority: Informacijski pooblaščenec, Dunajska cesta 22, 1000 Ljubljana, gp.ip@ip-rs.si, +386 1 230 97 30.

No automated decision-making

Article 13(2)(f) GDPR asks us to say whether there is any. There is none. Nothing on this site profiles you, scores you or decides anything about you automatically. An enquiry is read by a person; the only automated steps in the whole path are the rate limit on the form and the job that deletes old rows.

Please do not send us sensitive data

The enquiry form is for getting in touch, not for handing over evidence. Do not put health data, personal identification numbers, credentials, log extracts or anything else you would not want sitting in an inbox into it. If you are reporting an incident, say so and we will agree a channel for the detail.

If you send us special-category data anyway, we delete it once the enquiry has been answered rather than keeping it for the usual period.

Security

The site is served over TLS only; plain HTTP redirects and HSTS is set, so a browser that has seen the site once will not try again in the clear. Administrative access is restricted and logged. This is our own trade, and the site is held to the standard we sell.

If you find a security problem with this website, our vulnerability disclosure policy says how to report it, what we will do and how quickly. It is published at /vulnerability-disclosure/ and machine-readable at /.well-known/security.txt. We would rather hear it from you than from somebody else.