Privacy Policy
How PERONEUS d.o.o. collects, uses, retains and protects personal data relating to visitors of physiobook.com.
1. Controller and contact details
The controller of personal data collected through the Website is:
PERONEUS d.o.o.A. G. Matoša 8, 10360 Sesvete, Croatia
OIB: 41616434132
Email: info@physiobook.com
Send privacy questions and rights requests to the email address above. A data protection officer has not been appointed because the current scale and nature of processing have not been identified as requiring one.
2. Personal data we process
- Data you provide: name, email address, telephone number, organisation and other information entered into a contact, registration, comment or subscription form.
- Communications: the contents of an enquiry, application, comment or other message and information needed to respond.
- Technical data: IP address, request time, requested URL, browser and device type, security logs and error information.
- Usage data: pages viewed, approximate location derived from an IP address, referral source and interactions, where the applicable consent or other lawful basis permits collection.
- Advertising data: online identifiers, consent choices and ad interactions, to the extent permitted by your choices and the certified consent-management platform.
Do not send medical records, diagnoses, test results or other sensitive information through public Website forms unless that information is explicitly requested and necessary for the stated purpose.
3. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Responding to an enquiry and business communication | Contact details and message content | Steps taken at your request and legitimate interests in business communication |
| Newsletter and promotional communications | Name, email and consent record | Consent, withdrawable at any time |
| Publishing and moderating comments | Name, comment, email, IP and technical data | Legitimate interests in discussion, security and abuse prevention |
| Security, fraud prevention and diagnostics | IP address, access logs and technical data | Legitimate interests in protecting the Website and users, and legal obligations |
| Optional audience analytics | Online identifiers and usage data | Consent where required |
| Personalized advertising and ad measurement | Online identifiers, consent choices and interactions | Consent collected through a certified CMP |
4. Recipients and processors
Data is disclosed only where necessary and supported by an appropriate legal basis, including to:
- hosting, maintenance, security, backup and email-delivery providers;
- form, newsletter, analytics and advertising providers according to the feature used and your consent choice;
- authorized collaborators handling enquiries within their role; and
- public authorities where disclosure is required by law or necessary to establish, exercise or defend legal claims.
If the optional GeoIP fallback in Peroneus Analytics is enabled and the applicable processing choice permits it, a visitor’s IP address is sent to ipwho.is over encrypted HTTPS solely to identify an approximate country, region and city. Peroneus Analytics stores the returned approximate location and a one-way anonymous digest, not the original IP address.
The Website uses or may use services from Google, Meta and other providers listed in the consent settings or alongside the relevant feature. Depending on the service, those providers may act as processors or independent controllers under their own notices.
5. Transfers outside the European Economic Area
Some technology providers operate globally, so personal data may be processed outside the EEA. Where required, such transfers rely on an adequacy decision, the European Commission’s standard contractual clauses or another permitted safeguard, supplemented by additional measures where appropriate. Details of a provider’s transfer mechanism are available in its privacy notice.
6. Retention periods
- enquiries and business correspondence: for as long as needed to respond and protect legal claims, generally up to five years unless a longer statutory period applies;
- newsletter data: until consent is withdrawn or the purpose ends, while a minimal suppression record may be retained to respect the opt-out;
- comments: while published and for as long as reasonably needed for moderation or evidence of abuse;
- security logs: generally up to 12 months, and longer only for a specific incident or legal claim;
- analytics records: according to the retention setting of the relevant analytics service and no longer than reasonably needed for audience statistics; and
- cookies and online identifiers: for the periods described in the Cookie Policy and current CMP settings.
7. Your data-protection rights
Depending on the circumstances, you may request access, rectification, erasure, restriction of processing and data portability; object to processing based on legitimate interests; and withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority.
Send a request to info@physiobook.com. To protect personal data, reasonable proof of identity may be requested. The controller will respond without undue delay and within the time limits prescribed by the GDPR.
8. Consent and forms
Consent is requested separately for each purpose that requires it. Marketing consent is not a condition for sending an ordinary enquiry or viewing basic Website content. Required form fields are limited to information needed for the stated purpose.
You may withdraw consent as easily as you gave it: through an unsubscribe link, the privacy and cookie settings or an email to info@physiobook.com.
10. Data security
Reasonable technical and organizational measures are used, including HTTPS, access controls, software maintenance, backups, malicious-traffic protection and incident monitoring. No transmission or system is risk-free, but safeguards are reviewed in light of the assessed risk.
11. Children
The Website is informational and is not directed at children for the independent provision of marketing consent. If the controller learns that a child’s data was collected without an appropriate basis, reasonable steps will be taken to delete it. A parent or guardian may contact info@physiobook.com.
12. Complaint to a supervisory authority
You may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, Croatia, azop.hr, or with the supervisory authority responsible for your habitual residence, place of work or the place of an alleged infringement. You are welcome to contact us first so that we can try to resolve the issue promptly.
13. Changes to this policy
This policy is updated when processing purposes, services or applicable rules change. The current effective date and version appear at the top of the document.