Privacy Policy
This Privacy Policy explains how MLM Engineering, operating under the brand Code Flow ("Code Flow", "we", "us"), processes personal data when you visit this website or contact us. It is drawn up in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation — "GDPR"), the Slovenian Personal Data Protection Act (ZVOP-2, Official Gazette of the Republic of Slovenia No. 163/22), the Electronic Communications Act (ZEKom-2) and other applicable legislation of the Republic of Slovenia and the European Union.
1. Data controller
The controller of personal data collected through this website is:
- MLM Engineering [pravna oblika — s.p. / d.o.o.] (brand: Code Flow)
- Registered office: Cesta pod Rifnikom 23, 3230 Šentjur, Slovenia
- Registration number (matična št.): [xxxxxxxxxx]
- VAT ID (ID za DDV): [SIxxxxxxxx]
- E-mail: info@code-flow.app
We have not appointed a data protection officer, as we are not required to do so under Article 37 GDPR; all privacy-related enquiries are handled through the contact above.
2. What personal data we process, why, and on what legal basis
a) Contact and project enquiries. When you write to us by e-mail or book a
call, we process the data you provide: name and surname, e-mail address, telephone number
(if given), your organisation and the content of your message.
Purpose: responding to your enquiry, preparing an offer and negotiating a contract.
Legal basis: Article 6(1)(b) GDPR (steps at the request of the data subject prior to
entering into a contract) and Article 6(1)(f) GDPR (our legitimate interest in business
communication).
b) Contractual and billing data. If we enter into a contract, we process the
data required for its performance and for invoicing (contact details, billing details, VAT ID).
Purpose: performance of the contract, issuing invoices, accounting and tax obligations.
Legal basis: Article 6(1)(b) GDPR and Article 6(1)(c) GDPR (legal obligations under
Slovenian tax and accounting legislation, in particular ZDDV-1 and ZGD-1).
c) Server logs. Our hosting provider automatically records technical data
when the website is accessed: IP address, date and time of the request, requested URL,
HTTP status, browser and operating system identification.
Purpose: ensuring network and information security, detecting and preventing abuse,
diagnosing technical problems.
Legal basis: Article 6(1)(f) GDPR (our legitimate interest in the security and
availability of the website).
d) Web analytics. Analytics that would use cookies or similar identifiers is only activated on the basis of your prior consent given via the cookie notice (Article 6(1)(a) GDPR and Article 225 of ZEKom-2). See the Cookie Policy. At present the website operates without analytics cookies.
e) Direct marketing. We do not send newsletters or other direct marketing messages. Should we introduce them, they will be sent only in accordance with Article 226 of ZEKom-2 and Article 6(1)(a) GDPR (consent), or to existing customers under the conditions of the "similar services" exception, always with a simple opt-out.
3. Provision of data
You are not legally required to provide us with any personal data. However, without your contact details we cannot respond to your enquiry or conclude and perform a contract.
4. Recipients of personal data
We do not sell or rent personal data. Data may be disclosed to the following categories of recipients, strictly to the extent necessary:
- IT service providers acting as our processors under Article 28 GDPR (website hosting, e-mail services, backup), bound by data processing agreements;
- our accounting service provider, for invoicing and statutory bookkeeping;
- state authorities and other bodies, where disclosure is required by law.
5. Transfers to third countries
We primarily use service providers with data centres in the EU/EEA. Where a provider processes data outside the EU/EEA (for example certain e-mail or cloud services), the transfer takes place only under the safeguards of Chapter V GDPR: an adequacy decision of the European Commission (including the EU–US Data Privacy Framework for certified US providers) or the European Commission's Standard Contractual Clauses, with supplementary measures where required.
6. Retention periods
- Enquiries that do not lead to a contract: up to 2 years after our last communication, after which they are deleted or anonymised.
- Contractual documentation: for the duration of the contract and until the expiry of statutory limitation periods (as a rule 5 years after termination).
- Issued invoices and accounting records: 10 years, as required by the Slovenian Value Added Tax Act (ZDDV-1).
- Server logs: up to 90 days, unless a longer retention is necessary for the investigation of a specific security incident.
- Data processed on the basis of consent: until you withdraw consent.
7. Your rights
Subject to the conditions of the GDPR, you have the right to:
- access your personal data (Article 15),
- rectification of inaccurate data (Article 16),
- erasure ("right to be forgotten", Article 17),
- restriction of processing (Article 18),
- data portability (Article 20),
- object to processing based on legitimate interest, including profiling (Article 21), and to object at any time to direct marketing,
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3)).
Requests can be sent to info@code-flow.app. We will respond without undue delay and at the latest within one month of receipt of the request; this period may be extended by two further months for complex requests, of which you will be informed. We may ask you for additional information to confirm your identity. Exercising these rights is free of charge, unless requests are manifestly unfounded or excessive.
8. Right to lodge a complaint
If you believe that our processing of your personal data infringes the GDPR or ZVOP-2, you have the right to lodge a complaint with the supervisory authority in Slovenia:
Informacijski pooblaščenec Republike Slovenije
Dunajska cesta 22, 1000 Ljubljana, Slovenia
Telephone: +386 1 230 97 30
E-mail: gp.ip@ip-rs.si · Web: www.ip-rs.si
9. Automated decision-making and profiling
We do not carry out automated decision-making or profiling within the meaning of Article 22 GDPR.
10. Data security
In accordance with Article 32 GDPR and ZVOP-2 we implement appropriate technical and organisational measures, including: encrypted transmission (HTTPS/TLS), access control and the principle of least privilege, regular software updates, backups, and contractual confidentiality obligations for any person processing data on our behalf. In the unlikely event of a personal data breach that is likely to result in a high risk to your rights, we will notify you and the supervisory authority in accordance with Articles 33 and 34 GDPR.
11. Children
This website is intended for business users and is not directed at children. We do not knowingly process personal data of children under 15 years of age (the age limit set by ZVOP-2 for information society services).
12. Changes to this policy
We may amend this Privacy Policy from time to time. The applicable version is always published on this page, with the date of the last update indicated at the top. In the event of substantial changes we will inform data subjects with whom we are in active contact.