Last Updated: April 08, 2025
At David Dobric (hereinafter “I,” “my,” “we,” “us,” or “our”), I am committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how I collect, use, disclose, and safeguard your data when you visit my website, interact with my services, or engage with me in any way. It also outlines your rights under applicable international privacy laws, including the General Data Protection Regulation (GDPR) in the European Union, the California Consumer Privacy Act (CCPA) in the United States, the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada, the UK GDPR in the United Kingdom, and the Privacy Act 1988 in Australia, among others.
By using my website or services, you agree to the terms of this Privacy Policy. If you do not agree, please do not use my website or services.
1. Information I Collect
I may collect the following types of information:
- Personal Information: This includes your name, email address, phone number, postal address, and any other information you provide when contacting me, filling out forms, or engaging with my services.
- Non-Personal Information: This includes data such as your IP address, browser type, device information, operating system, pages visited, time spent on my site, and referring URLs. I collect this through cookies, web beacons, and similar technologies.
- Sensitive Information: I do not intentionally collect sensitive information (e.g., racial or ethnic origins, political opinions, health data, or biometric data) unless required by law or explicitly provided by you with consent.
- Usage Data: Information about how you interact with my website, such as clicks, navigation paths, and preferences.
2. How I Collect Information
I collect information in the following ways:
- Directly from You: When you submit forms, send emails, or contact me via my website or other channels.
- Automatically: Through cookies, analytics tools (e.g., Google Analytics), and server logs as you browse my website.
- From Third Parties: I may receive information from third-party partners, such as marketing agencies or analytics providers, in compliance with applicable laws.
3. How I Use Your Information
I use your information for the following purposes:
- To Provide Services: To respond to inquiries, deliver marketing strategies, and fulfill consulting or audit requests.
- To Improve Our Website: To analyze user behavior, enhance functionality, and optimize user experience.
- To Communicate: To send updates, newsletters, or promotional materials (with your consent where required).
- For Legal Compliance: To comply with legal obligations, such as tax reporting or responding to lawful requests from authorities.
- For Security: To detect and prevent fraud, abuse, or security threats to our website and services.
- For Business Operations: To manage our business, including billing, record-keeping, and analytics.
4. Legal Basis for Processing (GDPR/UK GDPR Compliance)
For users in the EU, EEA, or UK, I process your personal data based on the following legal grounds:
- Consent: Where you have given explicit consent (e.g., for marketing emails).
- Contractual Necessity: To fulfill a contract or provide services you’ve requested.
- Legitimate Interests: For purposes like improving our website, ensuring security, or conducting analytics, where these interests do not override your rights.
- Legal Obligation: To comply with applicable laws or regulations.
5. How I Share Your Information
I do not sell, trade, or rent your personal information to third parties. I may share your data in the following circumstances:
- Service Providers: With trusted third-party vendors (e.g., hosting providers, email services, analytics tools) who assist me in operating my website and services, under strict confidentiality agreements.
- Legal Requirements: If required by law, court order, or government authority, such as to comply with a subpoena or regulatory investigation.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the new entity, with notice to you where required.
- With Your Consent: If you explicitly agree to share your data with a third party for a specific purpose.
6. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right to Access (GDPR, CCPA, PIPEDA, etc.): Request a copy of the personal data I hold about you.
- Right to Rectification (GDPR, UK GDPR): Correct inaccurate or incomplete data.
- Right to Erasure/Right to be Forgotten (GDPR, CCPA): Request deletion of your data, subject to legal exceptions.
- Right to Restrict Processing (GDPR, UK GDPR): Limit how I use your data in certain circumstances.
- Right to Data Portability (GDPR, PIPEDA): Receive your data in a structured, machine-readable format to transfer to another provider.
- Right to Object (GDPR, UK GDPR): Object to processing for direct marketing or legitimate interests.
- Right to Opt-Out of Sale (CCPA): I do not sell your data, but you can opt-out of any future sharing if applicable.
- Right to Non-Discrimination (CCPA): I will not discriminate against you for exercising your rights.
To exercise these rights, please contact me at info@daviddobric.com. I will respond within the legally required timeframe (e.g., 30 days under GDPR, 45 days under CCPA). I may need to verify your identity before processing your request.
7. Data Retention
I retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, or resolve disputes. For example:
- Contact information is retained for the duration of my business relationship and up to 5 years after, unless you request deletion.
- Analytics data is retained for up to 26 months (Google Analytics default) or as required for business insights.
- Data required for legal compliance (e.g., tax records) is retained as per local laws (e.g., 7 years in many jurisdictions).
Once data is no longer needed, it is securely deleted or anonymized.
8. Data Security
I implement industry-standard security measures to protect your data, including:
- Encryption of data in transit (e.g., SSL/TLS for website traffic).
- Secure storage of data on servers with access controls.
- Regular security audits and updates to address vulnerabilities.
- Employee training on data protection best practices.
Despite these measures, no online system is 100% secure. I cannot guarantee absolute security but will notify you promptly in the event of a data breach, as required by law (e.g., within 72 hours under GDPR).
9. International Data Transfers
As a Germany-based business, your data may be processed in the United States and in the EU/EEA. However, I may transfer data to third-party providers (e.g., Google Analytics in the US) outside your jurisdiction. I ensure compliance with international laws:
- GDPR/UK GDPR: Transfers to non-EEA countries use Standard Contractual Clauses (SCCs) or rely on adequacy decisions.
- CCPA/PIPEDA: I ensure third parties meet equivalent privacy standards.
- Australia Privacy Act: I comply with cross-border disclosure requirements under APP 8.
10. Cookies and Tracking Technologies
I use cookies and similar technologies to enhance your experience, analyze usage, and deliver personalized content. Types of cookies include:
- Essential Cookies: Necessary for website functionality (e.g., navigation, form submissions).
- Analytics Cookies: Track usage patterns (e.g., Google Analytics).
- Marketing Cookies: Used for targeted advertising (if applicable, with your consent).
You can manage cookie preferences via your browser settings or our cookie consent popup (if implemented).
11. Third-Party Links
My website may contain links to third-party sites. I am not responsible for their privacy practices. I encourage you to review their privacy policies before sharing personal information.
12. Children’s Privacy
My services are not directed to individuals under 16 (or 13 in some jurisdictions, e.g., under COPPA in the US). I do not knowingly collect data from children. If I learn that I have collected such data, I will delete it immediately. Contact me at info@daviddobric.com if you believe I have inadvertently collected data from a child.
13. Changes to This Privacy Policy
I may update this Privacy Policy to reflect changes in my practices or legal requirements. I will notify you of significant changes via email (if we have your address) or a prominent notice on my website. The updated policy will be effective as of the “Last Updated” date at the top of this page.
14. Liability Limitations (Protecting You)
To the fullest extent permitted by law, I, David Dobric shall not be liable for any indirect, incidental, or consequential damages arising from:
- Unauthorized access to or use of your data due to factors beyond our control (e.g., hacking despite reasonable security measures).
- Errors, omissions, or inaccuracies in the information provided on my website.
- Actions taken by third parties, including those linked from my site.
I am not responsible for damages resulting from your failure to secure your account or data (e.g., sharing login credentials). You agree to indemnify and hold me harmless from any claims, losses, or damages arising from your use of my services, including legal fees, to the extent permitted by law.
15. Governing Law and Dispute Resolution
This Privacy Policy is governed by the laws of Germany, without regard to conflict of law principles. Any disputes arising from this policy will be resolved through:
- Informal Resolution: Contact me first at info@daviddobric.com to resolve issues.
- Mediation: If unresolved, disputes will be submitted to mediation in Germany.
- Jurisdiction: If mediation fails, disputes will be handled by the courts of Germany.
For EU/EEA residents, you may also file a complaint with your local data protection authority (e.g., the German Federal Commissioner for Data Protection and Freedom of Information).
16. Contact Me
For any questions, complaints, or to exercise your privacy rights, please contact me at:
Email: info@daviddobric.com
Response Time: I typically respond within 24 hours, though legal requests (e.g., GDPR data access) may take up to 30 days.
You may also contact your local data protection authority if you have concerns about our data practices.