Politika privatnosti

Kako editionkix.org štiti osobne podatke i prava korisnika.

Last updated: 24. September 2026.

This Privacy Policy explains how editionkix.org handles personal data when people read, search, or contact the site. It is written for the general public, including readers in Anguilla and readers in Croatia and the wider European Union. It should be read together with the Cookie Policy and Terms of Use. This notice describes the processing currently associated with the site’s reading, search, and contact functions; it does not describe advertising, sales, newsletters, user accounts, comments, or profiling because those functions are not part of the site’s stated operation.

1. Controller and how to contact us

The controller of personal data processed through https://2010.neurogena.net is the publishing platform editionkix.org. The controller decides why and how personal data is processed for the functions described in this notice.

For privacy questions, requests to exercise data-protection rights, or concerns about the handling of information, contact: [email protected]. You may also contact the controller by telephone at +441635778002 or by post at 3, Pipers Court, Thatcham RG19 4ER, Great Britain. No separate data protection officer is identified for this site in this notice.

2. Scope and people covered by this notice

This notice applies to visitors who browse investigative journalism and other editorial material, use the site search function, manage cookie preferences, or send a message through the contact form. It also applies to people whose details are included in correspondence sent to the site.

The site can be read without creating an account and does not provide a public comment function. Accordingly, it does not collect account-profile data or comment data as part of its stated functions. This notice does not govern independent websites, platforms, or publications that may be mentioned in editorial reporting; those organisations apply their own privacy practices.

3. Personal data we may process and where it comes from

The data processed depends on how a person uses the site. When a person submits the contact form, the site collects the name, email address, subject, and message supplied by that person. The message may contain additional personal data if the sender chooses to include it. Please do not send sensitive information unless it is necessary for your enquiry and you understand that it will be handled as correspondence.

The site also processes technical and security information generated by use of the site, such as information needed to operate a web request, diagnose faults, protect the contact form, and investigate misuse. Depending on the technical context, this may include device or browser information, request-related data, timestamps, and security records. Search terms entered into the site search function may also be processed to return relevant results and maintain the search feature.

Most personal data comes directly from the visitor or sender. Technical records arise from the interaction between a device and the site. We do not state that the site obtains personal data from data brokers, advertising networks, or public social-media profiles, because those sources are not part of the stated operation.

4. Why we process data and the legal bases

Where the EU General Data Protection Regulation (GDPR) applies to processing connected with people in Croatia or another EEA country, editionkix.org relies on the legal bases below. Comparable lawful grounds may apply under other applicable privacy law.

  • Reading, navigation, and search: technical data and search input are processed to deliver requested pages, return search results, maintain site functionality, and diagnose technical problems. This is necessary for the controller’s legitimate interests in operating an accessible editorial website and keeping it reliable.
  • Contact enquiries: contact-form data are processed to receive, assess, and respond to the sender’s message, and to keep an appropriate record of the correspondence. The usual basis is the controller’s legitimate interest in communicating with people who choose to contact it. Where a message concerns steps requested by the sender before entering into an arrangement, processing may instead be necessary for those requested steps.
  • Security and abuse prevention: technical security records are processed to protect the site, prevent malicious or disruptive activity, defend the contact form from misuse, investigate incidents, and preserve the integrity of editorial systems. The basis is legitimate interests in security and continuity.
  • Non-essential cookies or similar technologies: where such technologies are used, they are used only after the visitor has given the required consent through the cookie controls. Consent is the legal basis for that optional processing.
  • Legal obligations and rights: data may be retained, reviewed, or disclosed where this is necessary to meet an applicable legal obligation or to establish, exercise, or defend legal claims.

The site does not use personal data for newsletters, targeted advertising, commercial promotion, sale of personal data, or behavioural profiling.

5. Whether data must be provided

Visitors do not need to provide a name or email address to read editorial content or use ordinary site navigation. Providing the contact-form fields is voluntary. However, if a person does not provide enough information for the controller to understand and reply to an enquiry, the controller may be unable to respond. A person may choose not to use the contact form and may instead use the contact details provided in this notice.

Technical information required to deliver pages and protect the site is generated when a device communicates with the site. A visitor who blocks strictly necessary technical functions may find that parts of the site do not work correctly. Rejecting optional cookies should not prevent access to the core editorial content.

6. Cookies and similar technologies

Cookies and similar technologies can be used to remember privacy choices and support essential technical operation. The site provides a choice to accept or reject non-essential cookies. Necessary technologies may operate without consent where they are strictly required to provide a service requested by the visitor or to maintain the security and functioning of the site. Optional technologies are not activated merely because a visitor continues browsing where consent is required.

For a fuller explanation of the categories of cookies, the available controls, and how preferences can be changed, please read the Cookie Policy. The cookie approach is intended to account for applicable Croatian and EU ePrivacy-derived cookie requirements where those rules apply. The site does not state that it uses advertising cookies or technologies for profiling.

7. Processors, recipients, and legally required disclosures

Personal data may be handled by service-provider categories that are necessary to operate and secure the site, such as website infrastructure, technical maintenance, security, communications, or data-storage providers. When a provider processes personal data only on the controller’s instructions, it acts as a processor and should be subject to appropriate data-protection obligations.

Access is limited to people and providers who need it for the purposes described in this notice. Data may also be disclosed where required by applicable law, a valid legal process, or an authority with lawful powers, or where disclosure is necessary to protect rights, safety, security, or the integrity of the site. We do not describe undisclosed recipients, vendors, or data flows as if they were known facts.

8. International transfers

Use of a website can involve processing from locations outside a visitor’s country. The controller’s contact address is in Great Britain, and a visitor in Croatia or another EEA country should understand that correspondence sent to the controller may therefore be accessed or handled outside the EEA. The controller does not identify a particular hosting location or overseas provider in this notice where that detail has not been established.

If personal data subject to the GDPR is transferred to a country that is not covered by an applicable adequacy decision, the controller will use an appropriate transfer mechanism required by applicable law, such as contractual safeguards, and will apply supplementary measures where needed after assessing the transfer. Information about the safeguard relevant to a particular request may be sought through [email protected], subject to the protection of confidential information and security controls.

9. Retention and deletion

Personal data is not kept indefinitely merely because it has been collected. The controller uses retention criteria based on the purpose of the record, the nature of the enquiry, the need to maintain security, and any applicable legal or claims-related requirement. Contact messages are retained only for as long as reasonably needed to handle the enquiry and maintain an appropriate record of the communication, unless a longer period is necessary for a legal obligation or the establishment, exercise, or defence of legal claims.

Technical and security records are kept for the shortest period reasonably necessary to operate, secure, troubleshoot, and investigate misuse of the site. Cookie preference information is retained in accordance with the applicable cookie mechanism and its purpose. When the relevant retention period or criteria no longer apply, data is deleted, anonymised, or otherwise removed from active use where practicable. A person may ask for information about retention as it relates to their own correspondence.

10. Security and data minimisation

editionkix.org seeks to process only the data reasonably needed for the functions described here. Access to contact correspondence and technical records should be limited according to role and need. The controller uses organisational and technical measures appropriate to the nature of the processing, including measures intended to reduce unauthorised access, alteration, loss, and misuse.

No online system can guarantee complete security. Visitors should use care when sending information online and should avoid including unnecessary sensitive personal data in contact messages. If the controller becomes aware of a personal-data breach requiring notification under applicable law, it will assess and address the incident in accordance with those obligations.

11. Your data-protection rights

Where the GDPR applies, individuals may have the right to request access to their personal data; rectification of inaccurate or incomplete data; erasure in applicable circumstances; restriction of processing; and portability of data processed by automated means on the basis of consent or a contract. They may also object to processing based on legitimate interests where their particular situation gives grounds for objection. The controller will consider such objections and explain any lawful reason for continuing processing.

To make a request, email [email protected] and state the nature of the request and enough information to locate the relevant data. The controller may need to verify identity before acting, particularly where a request concerns correspondence or information that should not be disclosed to another person. Requests are handled within the time limits required by applicable law. Rights may be subject to legal exceptions, including exceptions protecting the rights and freedoms of others, legal claims, and applicable journalistic or freedom-of-expression protections.

12. Consent, objections, and marketing

Where processing is based on consent, including consent for non-essential cookies where required, consent can be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before it was withdrawn. Cookie choices can be changed using the site’s cookie controls. A person may also contact [email protected] about consent-related processing.

The site does not operate newsletters, direct marketing, or profiling. Consequently, it does not describe a direct-marketing opt-out process for activities it does not undertake. If this operational position changes, this notice and the relevant controls will need to be updated before the changed processing is carried out.

13. Complaints and supervisory authorities

We encourage people to contact the controller first so that a concern can be understood and addressed. Where the GDPR applies, a person also has the right to lodge a complaint with the supervisory authority in the EEA country of their habitual residence, place of work, or place of the alleged infringement. For people in Croatia, the competent supervisory authority is the Croatian Personal Data Protection Agency (AZOP). This does not limit any rights available under applicable law in Anguilla or another relevant jurisdiction.

14. Children

The site is a general-audience editorial publication and does not require account registration. It is not designed to deliberately collect personal data from children through accounts, comments, newsletters, or advertising. A child who contacts the site should provide only information necessary for the message. A parent, guardian, or child may contact [email protected] with a privacy concern or a request concerning information submitted through the contact form; identity and authority may need to be verified before action is taken.

15. Automated decisions

The stated operation of the site does not involve automated decision-making, including profiling, that produces legal effects or similarly significant effects for visitors. Search functionality may use a query to display relevant editorial results, but this is not a decision about an individual. The site does not state that it profiles readers for advertising or other behavioural purposes.

16. Changes to this policy

This policy may be updated when the site’s functions, data practices, legal requirements, or security arrangements change. Material changes will be reflected in the version published on https://2010.neurogena.net, and the date at the beginning of this page will show when the policy was last updated. Visitors should review this page periodically, especially before submitting information through the contact form.