Who processes your data
The data controller is PushPullCode d.o.o., a company incorporated in Croatia, company/VAT ID: HR35276425546. Skladno is a service provided by PushPullCode d.o.o.
For any data protection question, or to exercise your rights, write to info@skladno.eu. We reply within the period set by the General Data Protection Regulation (GDPR), and in any case within thirty days.
What we collect and why
Email address (list signup)
When you leave your email address for the free Declaration of Conformity template or for your readiness report, we store your email address, the site language, where you signed up from and the time of signup. We also record that this submission requested our updates, and the exact consent wording you were shown.
- Purpose: sending the document you asked for and occasional updates on PPWR and its deadlines.
- Legal basis: your consent, Art. 6(1)(a) GDPR.
- Withdrawing consent: at any time, via the unsubscribe link at the foot of any message we send, or by writing to info@skladno.eu. Withdrawal does not affect the lawfulness of processing before it.
Readiness check answers
The readiness check asks closed-choice questions only. There are no open questions and we never ask for free text. Until you press submit, your answers stay in your browser and never reach us.
When you submit, we store your answers, the roles derived from them, the version of the obligations catalogue they were evaluated against, and the time of submission, all linked to your email address. This lets us regenerate the report if delivery fails — we store no copy of the PDF anywhere.
- Purpose: producing and sending your readiness report.
- Legal basis: your consent, Art. 6(1)(a) GDPR.
Role determination is informational. It is not a legal assessment, it is not a decision producing legal effects, and it does not replace professional advice.
User account (app.skladno.eu)
When you open an account we process your email address, your password (stored only as a cryptographic hash — we cannot read your password), whether your email address has been confirmed, and the name you enter at registration. To sign you in and maintain your session we process session data: the session identifier, its expiry, and the IP address and browser details the session was opened from.
- Purpose: opening and running your account, signing in, account security (detecting unauthorised access), and rate-limiting sign-in attempts.
- Legal basis: performance of a contract, Art. 6(1)(b) GDPR; for security records, our legitimate interest in protecting the Service and your account, Art. 6(1)(f) GDPR.
The application uses strictly necessary cookies only (a session cookie, scoped to app.skladno.eu), without which signing in is technically impossible. Strictly necessary cookies need no consent. The application uses no analytics or marketing cookies.
Alongside your account we also record the version identifier of the Terms of Use you accepted and the time of acceptance, so that we can evidence what was agreed (legitimate interest, Art. 6(1)(f) GDPR).
Company or sole-trader details (workspace)
Into your workspace you enter the legal identity of your company or sole trader: name, address, OIB (Croatian personal identification number) and VAT ID. These details print on the documents you produce with the Service (for example on an EU Declaration of Conformity). Where the user is a sole trader or another self-employed natural person, the name, address and OIB are that person's personal data and we process them with the same care.
- Purpose: producing your documentation and running your workspace; and, once charging is introduced, meeting accounting and tax obligations.
- Legal basis: performance of a contract, Art. 6(1)(b) GDPR; for accounting records, compliance with a legal obligation, Art. 6(1)(c) GDPR.
The content of your documents — processed on your behalf
The content you enter into documents may include personal data of third parties (for example the name and function of the person signing a declaration). For that content you are the controller, and we process it as a processor, solely in order to provide the Service and on your instructions, subject to the Art. 28 GDPR obligations described in the Terms of Use.
Linking earlier signups to your account
If you left your email address on skladno.eu before opening an account (the list or the readiness check), we link records carrying the same email address to your account. This keeps us from treating you as two unrelated people, and lets us understand which content leads to an account being opened.
- Legal basis: our legitimate interest in keeping an orderly relationship with our users and measuring how effective our content is, Art. 6(1)(f) GDPR. You may object to this processing (see "Your rights"); your marketing consents are unaffected by it — unsubscribing from the list applies whether or not you hold an account.
Account-related messages
To your email address we send messages without which the Service does not work: confirmation of your email address, a password reset link, and notices about material changes to the Service or to the Terms. These messages are not marketing and unsubscribing from the list does not apply to them.
- Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
Technical data (public pages)
To protect the public forms on skladno.eu from abuse we process your IP address, transiently and in server memory only, to rate-limit attempts — we do not store IP addresses from the public forms in our database. (Inside the application, the session IP address is stored as described above, as a security record for your account.)
- Legal basis: our legitimate interest in protecting the service from abuse, Art. 6(1)(f) GDPR.
Analytics and cookies (public pages)
We collect basic aggregate traffic statistics without cookies and without profiling individual visitors (Vercel Analytics). This needs no consent and rests on our legitimate interest in understanding how our content is used.
We also use Google Analytics 4 and Google Ads to measure how well our content and advertising perform. These tools set cookies and process device identifiers, your IP address and the addresses of the pages you visit.
Those scripts do not run until you accept them. Until you choose, every Google consent category (ad storage, ad user data, ad personalisation, analytics storage) is set to denied, so no such cookies are set. You can change your choice at any time from the consent bar, and refusing is exactly as easy as accepting.
- Legal basis: your consent, Art. 6(1)(a) GDPR and Art. 43(4) of the Croatian Electronic Communications Act (NN 76/22).
We remember your choice locally in your browser (localStorage) so that we do not have to ask on
every visit. That entry never travels to our servers.
Payments (applies from the introduction of charging)
⚠ This section applies from the moment we open the paid plans for purchase. We will publish a new version of this policy when that happens.
Paid plans are sold by Paddle as merchant of record. The details you enter when purchasing (name, email address, billing address, payment instrument details, VAT ID) are processed by Paddle as an independent controller, under its own privacy policy made available during the purchase. We neither receive nor store payment card details. From Paddle we receive the transaction confirmation and the subscription status, which we keep as part of your workspace's records.
Who we share data with
We do not sell your data and we do not trade it for marketing purposes. We use the following processors and recipients:
| Recipient | Role | Processing location |
|---|---|---|
| Webdock.io ApS | Server and database (accounts, workspaces, documents, list signups) | Denmark, EU |
| Brevo (Sendinblue SAS) | Sending email and maintaining the recipient list | France, EU |
| Vercel Inc. | Serving the public pages and aggregate analytics | EU/US |
| Cloudflare, Inc. | DNS, TLS and abuse protection | EU/US |
| Google Ireland Ltd. | Analytics and ad measurement on the public pages — only with your consent | EU/US |
| Paddle (from the introduction of charging) | Seller and payment processing for paid plans — independent controller | United Kingdom/EU |
The database holding your account, workspace, documents and signups sits on a server in Copenhagen, Denmark, inside the European Union.
Where a recipient may process data outside the European Economic Area, the transfer relies on the European Commission's Standard Contractual Clauses, or on the EU–US Data Privacy Framework where the recipient is certified under it. For the United Kingdom, the European Commission's adequacy decision applies.
How long we keep data
| Data | Period |
|---|---|
| Email address on the list and the consent record | for as long as you are on the list; after you unsubscribe we keep the consent and unsubscribe record for a further five years, to evidence that our sending was lawful |
| Readiness check answers | attached to your signup — deleting the signup deletes the answers with it, in the same operation |
| Account and workspace data | for as long as the account is open; after closure we delete it within thirty days at the latest, allowing a period in which you can download your documents |
| Session security records (IP, browser) | until the session expires, and for twelve months at most |
| Record of the accepted version of the Terms | for as long as the account is open |
| Transaction records (from the introduction of charging) | for the periods prescribed by accounting and tax law |
| Backups | encrypted, with strictly limited access, solely for data recovery — see the note below the table |
A note on backups. Backups of our systems are encrypted, access to them is strictly limited, and they serve only recovery from failure or data loss and the durability of data; they are not available in ordinary operation and data is not used from them. We carry out deletion requests in the production systems, which are the only place data is processed. If we ever had to restore a backup, we would delete again — as part of that same restore — any data deleted in the meantime.
These periods have nothing to do with the PPWR retention periods. Those concern your own packaging conformity documentation; the documents you produced with the Service we keep for you only for as long as your account is open, and retaining them for the statutory period is your own obligation and responsibility.
Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interest, as well as the right to withdraw consent at any time.
Send your request to info@skladno.eu from the address it concerns. If you hold an account you may also send it from the account's email address; for your own protection we may ask you to confirm your identity before acting.
If you believe we process your data unlawfully, you may lodge a complaint with the supervisory authority: Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr.
Children
Skladno is intended for business users. We do not knowingly collect data from anyone under 16.
Changes to this policy
Every version of this policy carries an identifier (for example privacy-v2-2026-08) and the date from which it applies. We may change the policy as the service develops. We will notify you by email or in the application, before it takes effect, of material changes affecting the processing of data of users who hold an account; other changes we announce on this page. Earlier versions will be provided on request.
Version privacy-v2-2026-08 · In force from 3 August 2026.