Last Updated: July 21, 2026
PROTEKKT SOFTWARE d.o.o. ("we," "us," or "Company"), a corporate entity incorporated under the laws of the Republic of Croatia, registered with the court registry of the Commercial Court under MBS: 081707259, OIB: 28968924128, having its registered corporate office at Lomošćanska cesta 34D, 47300 Ogulin, Croatia, acts as the Data Controller under the General Data Protection Regulation (EU) 2016/679 ("GDPR").
This Privacy Policy explains how we collect, process, and protect your data when you visit our website located at https://protekkt.io (the "Website") and when your locally installed software client interacts with our remote licensing infrastructure hosted via https://api.protekkt.io (the "Service").
1. WEBSITE VISITOR TELEMETRY & LIVE CHAT STORAGE
To respect your privacy while optimizing our web infrastructure, the digital interface at https://protekkt.io balances data minimization with essential user support tools:
-
Web Analytics and Cookie Consent: We use Google Analytics to help us understand how visitors interact with our website and to improve your user experience. We use Cookiebot to manage your privacy preferences. Google Analytics will only place cookies on your device and use persistent identifiers if you provide explicit consent by accepting analytics cookies through our consent banner. When you opt in, these cookies collect information about your website activity to help us analyze traffic patterns. If you decline or have not yet made a preference selection, no analytics cookies will be stored on your device. To further safeguard your data, your IP address is anonymized before any analytics processing occurs.
-
First-Party Live Chat Support Cookies: To provide real-time customer support messaging, this Website integrates Intercom live chat. When you voluntarily interact with the support widget, Intercom drops localized first-party session cookies (including
intercom-idandintercom-session) onto your browser. These cookies are used strictly to maintain thread persistence across pages and protect your access to active conversations. They do not track your behavior across external domains.
2. PAID CUSTOMER DATA RECIPIENTS & RETENTION (B2B & B2C)
Whether you purchase a license as an individual consumer (B2C) or on behalf of a business entity (B2B), we collect and process the minimal personal and transactional information required to fulfill our contractual obligations and manage your subscription.
-
Processed Variables: This includes your full customer name (and/or primary corporate contact name), email address, company name (if applicable), tax or corporate identification numbers (such as OIB for Croatian entities or VAT numbers where applicable), physical billing address, and transaction metadata. All credit card processing occurs through isolated, whitelisted third-party payment gateways and never touches our internal server infrastructure.
-
License Validity Retention Window: To ensure strict data minimization, all active operational records and personal identifiers linking you to a specific license key are retained only during the explicit validity period of your active product license. Once your 1-year license term expires and the renewal window closes, your customer profile data is systematically scrubbed from our active software licensing databases within twelve (12) months, except where longer retention is strictly mandated by Croatian fiscal and tax accounting laws (Zakon o računovodstvu).
3. BEHIND-THE-SCENES API TELEMETRY & ABUSE PREVENTION
Our downloadable software applications rely on secure, background network communications with our remote cloud gateway at https://api.protekkt.io to validate license states and dynamically generate code-protection primitives.
-
Monitoring Scope: During execution, our remote API routing system at https://api.protekkt.io monitors isolated structural tokens and licensing metadata sent by the client application. This background telemetry is limited strictly to checking your active license key string, current software client version, and the connecting network server IP address. No hardware hashes, device identifiers, or machine fingerprints are extracted or processed.
-
Purpose of Processing: This monitoring happens strictly behind the scenes and is processed under our legitimate interests (GDPR Art. 6(1)(f)) for the explicit purpose of enforcing license compliance, validating the 1-year product term, preventing license key piracy, and ensuring no technical abuse of our server endpoints (such as high-frequency automated loop scripting or denial-of-service attacks).
4. LEGAL BASIS FOR PROCESSING
Pursuant to Article 6(1) of the GDPR, our legal foundations for data processing are:
-
Contractual Necessity (Art. 6(1)(b)): To deliver, activate, and maintain the software capabilities you paid for under our EULA and Terms via https://api.protekkt.io.
-
Legal Obligation (Art. 6(1)(c)): To comply with Croatian financial reporting, tax legislation, and mandatory corporate archiving.
-
Legitimate Interests (Art. 6(1)(f)): To protect our remote API infrastructure from technical exploitation, investigate software piracy, and detect instances where a license key is weaponized to protect malicious software payloads.
5. YOUR RIGHTS UNDER THE GDPR
As an EEA resident, you hold full statutory protections under Articles 15 through 22 of the GDPR regarding your customer data and background API log metrics:
-
Right of Access & Portability: Request a copy of the telemetry records and profile entries mapped to your license key.
-
Right to Rectification: Mandatory updating of corporate or personal billing identifiers or contact fields.
-
Right to Erasure / Objection: Request early removal of data or object to background API abuse-monitoring protocols (noting that disabling API telemetry will render the software unable to complete code compilation handshakes).
To file a formal data privacy motion, contact our compliance contact directly at privacy@protekkt.io. All legitimate inquiries will be answered within thirty (30) days.
6. JUDICIAL SUPERVISION
You have the sovereign right to lodge regulatory complaints concerning our processing behavior directly with the national data protection supervisor within the Republic of Croatia:
Agencija za zaštitu osobnih podataka (AZOP) Selska cesta 136, 10 000 Zagreb, Croatia Website: https://azop.hr | Email: azop@azop.hr