Privacy policy
This policy explains which personal data Inštitut za Varnost in Strateške Raziskave ("IVSR", "we") processes in operating the ivsr.si website, on what legal basis, for how long we keep it, and what rights you have. It is written to describe what this website actually does, rather than what a website might do.
In short
- We do not measure visits and set no analytics cookie without your consent.
- We carry out no profiling and no automated decision-making producing legal effects concerning you.
- We do not sell personal data and do not use it for advertising.
- The site embeds no third-party content (no videos, maps or social widgets) and loads no fonts from content delivery networks — fonts are self-hosted. The single exception is the bot-protection check on the contact form (Cloudflare Turnstile), described below.
- The security self-assessment runs entirely in your browser. Your answers are never sent to any server and are never stored.
Controller
Inštitut za Varnost in Strateške Raziskave, Brnčičeva ulica 13, 1231 Ljubljana - Črnuče, Slovenia
VAT ID: SI74460269
Email: [email protected]
For any data protection question, and to exercise your rights, write to us at the address above.
What we process and why
1. Accessing the website
As with any web server, our hosting provider processes technical connection data on each request: IP address, request time, requested URL, referrer and browser information. This data is necessary to deliver the pages and to detect attacks and abuse.
Legal basis: legitimate interest (Article 6(1)(f) GDPR) in the secure and reliable operation of the website.
2. Contact form
When you submit the form we process the data you enter: name, email address, organisation (optional) and the message, together with your explicit confirmation that you agree to the processing. The form collects nothing else.
Legal basis: steps taken at your request prior to entering into a contract, or your consent (Article 6(1)(b) and (a) GDPR).
3. Preventing abuse of the form
To stop the form becoming a spam channel, each submission is checked in two ways: a hidden field a human never fills in, and the time taken to complete the form. We also limit submissions from a single IP address to five per hour.
For that limit the IP address is held in server memory only, for at most one hour. It is not written to a database or a log, is not linked to the message content, and is used for no other purpose. Message content is never written to logs.
Legal basis: legitimate interest (Article 6(1)(f) GDPR) in protection against abuse.
4. Email delivery
A valid submission is delivered to our mailbox through an email delivery provider acting as our processor. Submissions that fail validation or the abuse checks never reach that provider at all. Where the form is unavailable we offer you the option of writing to us directly at [email protected]; in that case your message travels via your own and our email providers.
5. Visit measurement
If you consent to it, we process website usage data through Google Analytics 4 (ID G-GLWS711GQH): pages viewed, the time and order of views, approximate city-level location, device and browser type, and traffic source.
Until you consent, every consent category is set to denied: no cookie is set and your device is not recognised. What is nevertheless sent in that state is described in the Cookie policy.
Legal basis: your consent alone (Article 6(1)(a) GDPR), which you may withdraw at any time.
6. Storage in your browser
We write two entries to your browser's local storage: your cookie decision (with its date, so that valid consent can be demonstrated) and the fact that you dismissed the language suggestion. Both are necessary for the site to behave according to your own choices, and neither is transmitted to our server. The full inventory is in the Cookie policy.
7. Security self-assessment
The security self-assessment runs entirely in your browser. Your answers and the resulting score are never sent to any server, are not stored, and are not available to us. If you follow the link to an external service at the end, that service's own terms and privacy policy apply.
8. Contact-form bot protection (Cloudflare Turnstile)
The contact page runs Cloudflare Turnstile, which distinguishes real visitors from automated bots and so protects the form against abuse and spam. In doing so it processes technical data from your browser and device (such as your IP address and page-interaction signals), and it may store a short-lived technical token in your browser strictly to run the check.
Turnstile is designed to preserve privacy: it does not profile visitors, does not use data for advertising, and does not track you across sites. As a strictly necessary security function it requires no consent and is not part of the cookie banner.
Legal basis: legitimate interest (Article 6(1)(f) GDPR) in network and information security and in protecting the form against abuse.
What we do not do
- No profiling and no automated decision-making within the meaning of Article 22 GDPR.
- We do not sell, rent or trade personal data for advertising purposes.
- No advertising tag is installed on this site and we perform no cross-site tracking.
- Apart from the contact-form bot check (Cloudflare Turnstile, described below), we load no third-party scripts; fonts are self-hosted rather than loaded from a content delivery network.
- We do not use your form data to send marketing messages without your consent.
Recipients
We disclose personal data only where necessary for the purposes above:
- Hosting provider — technical operation of the website.
- Email delivery provider (Resend, Resend Inc., USA) — delivery of contact form messages.
- Cloudflare, Inc., 101 Townsend Street, San Francisco, CA, USA — verifying that the contact form is completed by a human (Cloudflare Turnstile).
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland — visit measurement, only with your consent.
Each acts as a processor on our instructions under a data processing agreement. We may also disclose data to competent authorities where required by law.
Third-country transfers
Processing through Google Analytics may involve a transfer of data to the United States. Google relies on the EU-US Data Privacy Framework and on the European Commission's standard contractual clauses. The same applies to the email delivery provider and to Cloudflare, Inc. (Cloudflare Turnstile). If you decline visit measurement, no analytics-related transfer takes place; the bot check, as a strictly necessary security function, runs regardless of your analytics consent.
Retention
- Contact messages: for as long as needed to handle your inquiry and for any business relationship arising from it, and thereafter until the expiry of limitation periods or statutory retention obligations.
- IP address for rate limiting: at most one hour, in memory only.
- Analytics data: retained by Google according to the retention setting of the Google Analytics 4 property; standard properties can be set to 2 or 14 months.
- Local storage entries: until you clear them in your browser or change your decision.
Your rights
In relation to your personal data you have the right to:
- access the data and obtain a copy of it;
- rectification of inaccurate and completion of incomplete data;
- erasure ("right to be forgotten");
- restriction of processing;
- portability of the data you provided to us;
- object to processing based on legitimate interest;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
You can withdraw consent to visit measurement through the Privacy settings link in the footer of any page. To exercise the other rights, write to [email protected]. We will respond within one month of receiving your request.
Complaint to the supervisory authority
If you believe we process your data unlawfully, you may lodge a complaint with the supervisory authority:
Information Commissioner of the Republic of Slovenia
Dunajska cesta 22, 1000 Ljubljana, Slovenia
Email: [email protected] · Phone: +386 1 230 97 30
www.ip-rs.si
Security
Traffic between your browser and the website is encrypted (HTTPS). Form data is validated on the server and not only in the browser, and message content is never written to logs. We collect only the data actually needed for each purpose.
Children
This website is aimed at business users and is not directed at children. We do not knowingly collect children's personal data. If you believe a child has provided us with their data, tell us and we will delete it.
Changes
We update this policy whenever the way we process data changes. If the purposes requiring consent change, we will ask for your consent again.
Last updated: 4 August 2026.
