Privacy policy
Last updated: 2026-07-01
1. Who we are
Secure Block d.o.o. ("SecureBlock", "we", "us") is a Croatian company registered under OIB 68170225840, with its registered office at Maglenča 133/B, 43000 Bjelovar, Croatia. This policy describes how we collect and process personal data in connection with our website, the SecureBlock platform, and our penetration testing services.
2. Data we collect
We collect the minimum personal data necessary to deliver our services. This typically includes: contact information (name, work email, company) provided when you request a quote or open a support ticket; account information (name, email, role) when you create a platform user; and usage data (log records, access timestamps, browser and IP) for security and abuse prevention.
3. Why we process it
We process personal data to provide and operate the SecureBlock platform, to deliver contracted penetration testing services, to comply with legal obligations (accounting, tax, contract retention), and to keep our systems secure. Where you have opted in, we also process contact data to send occasional product updates.
4. Legal basis
Where GDPR applies, we rely on the following legal bases: performance of a contract (delivering our services to you); legitimate interests (operating the platform, preventing abuse, product improvement); legal obligation (accounting and tax law retention); and consent (marketing communications, which you can withdraw at any time).
5. Who we share it with
We share personal data only with the sub-processors listed on our Sub-processors page, all of whom operate under a data processing agreement. We do not sell personal data. We may disclose data if compelled by a valid legal request, and we will notify you unless prohibited from doing so by law.
6. International transfers
Some sub-processors are located outside the EEA. We rely on Standard Contractual Clauses and, where required, supplementary measures to ensure a level of protection consistent with EU data protection law.
7. Retention
Contact and account data is retained for the duration of the customer relationship and up to seven years after termination as required by Croatian tax law. Engagement data (findings, evidence, reports) is retained for 90 days after the retest window closes and then deleted, unless the customer requests earlier deletion or extended retention.
8. Your rights
You may request access to, correction of, or deletion of personal data we hold about you; object to certain processing; and request data portability. To exercise any right, contact us at privacy@secureblock.io. You may also lodge a complaint with the Croatian Personal Data Protection Agency (AZOP).
9. Security
SecureBlock maintains an ISO 27001-certified information security management system. Personal data is encrypted in transit and at rest, access is restricted on a least-privilege basis, and we conduct annual independent security assessments of our platform.
10. Contact
For questions about this policy or to exercise any right, email privacy@secureblock.io or write to Secure Block d.o.o., Maglenča 133/B, 43000 Bjelovar, Croatia.
11. Changes
We may update this policy from time to time. Material changes will be announced by email or in-platform notice at least 30 days before they take effect. The current version is always available at this URL.
