1. Who we are
This policy explains how Innovatica [full legal name, registration number, registered seat] ("we") processes personal data when you visit innovatica.ai, contact us, or interact with solutions we run under our own name. Contact for all privacy matters: info@innovatica.ai.
Where we operate AI and data solutions on behalf of a client, the client is the controller of its end users' data and our processing is governed by the Data Processing Agreement published alongside this policy — that client's own privacy notice applies to you as its end user.
2. What we collect, why, and on what basis
| Context | Data | Purpose | Legal basis |
|---|---|---|---|
| Contact form / e-mail | The e-mail address you provide, the content of your message, and our correspondence | Responding to your inquiry; taking steps prior to a contract | Steps at your request prior to a contract; legitimate interest in responding |
| Confirmation e-mail | Your e-mail address | One confirmation of receipt, with our response-time promise | Legitimate interest |
| Website operation | Technical logs and telemetry: IP address, browser/user-agent, pages requested, timestamps, response codes and latency | Operating, securing and improving the site | Legitimate interest in running a secure service |
| Business relationship | Contact details of client representatives (name, role, e-mail, phone) | Contract performance, invoicing, communication | Contract; legal obligations |
We use no advertising trackers and no third-party analytics cookies. The site sets no cookies for tracking; a language/theme preference may be stored locally in your browser and never leaves it.
3. Where the data lives and who processes it
Our infrastructure runs on Microsoft Azure in the European Union (currently Sweden Central; some services West Europe). E-mail is delivered via Azure Communication Services. Source code and operational configuration are hosted on GitHub. Where a solution uses large-language- model inference, the relevant provider (e.g. Anthropic) processes the submitted content without training on it, under its commercial terms. The current subprocessor list, locations and transfer safeguards are stated in our Data Processing Agreement (Annex 3), published on this page.
Transfers outside the EU/Serbia occur only under appropriate safeguards (standard contractual clauses and/or an applicable adequacy framework).
4. How long we keep it
- Inquiries and correspondence: as long as needed to handle the matter and any follow-up business relationship, then deleted or archived per legal retention duties.
- Technical logs and telemetry: [30] days operational retention.
- Contract and invoicing records: statutory retention periods.
5. Your rights
Subject to the law that applies to you (the Serbian Law on Personal Data Protection — ZZPL — and/or the GDPR), you have the right to access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interest, as well as the right to withdraw consent where processing rests on it. Write to info@innovatica.ai — we respond within the statutory deadlines.
You also have the right to lodge a complaint with a supervisory authority: in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik); in the EU, your local data-protection authority.
6. Changes
We update this policy as our services evolve; the current version and its date are always shown here. Material changes are announced on this page.