Privacy Policy

Learn how we handle your personal data in compliance with GDPR and Slovenian law

Last updated: July 2026

1. Who is Responsible

Website: valentindominko.com

Controller: Valentin Dominko

Registered seat: 1000 Ljubljana, Slovenia

Contact for privacy matters: info@valentindominko.com | +386 41 504 885

This privacy policy applies to visitors of the website, people who submit contact forms, and people who create a user account to access the site's interactive apps (see Section 11).

2. What Data is Collected

Personal data you may process through the site:

  • Identification and contact data: name, email address, phone number (optional), company name or role (if provided).
  • Communication data: messages sent via contact forms, notes about calls or coaching sessions.
  • Technical data: IP address, device/browser information, pages visited, and basic analytics cookies (details in our separate Cookie Policy).
  • Account data (if you register): email address, chosen username and display name, a securely hashed password (never the password itself), email-verification status, and session/security metadata (a hashed session token, sign-in timestamps, IP address and browser user-agent of active sessions, and a security audit log of events such as sign-in, password change, and email change).
  • User-generated content (in the site's apps): content you create while signed in — for example ideas, comments, upvotes, and sharing choices in Idea Machine — together with the visibility setting you assign to it.
  • Billing data (if applicable in future): name, address, company details, VAT ID, and payment metadata (processed by third-party payment providers).

We do not intentionally collect special categories of personal data (e.g., health, sensitive information, or data revealing political opinions, religious beliefs, or ethnic origin).

3. Why and on What Legal Basis

Main purposes and corresponding legal bases under GDPR:

  • Responding to inquiries and booking calls (contact form, email, phone): Performance of a contract or steps at the request of the data subject (GDPR Article 6(1)(b)).
  • Running the website, security, and basic statistics: Legitimate interest in maintaining a secure, functional website and understanding aggregated usage patterns (GDPR Article 6(1)(f)).
  • Fulfilling legal obligations (e.g., tax and accounting records): Legal obligation (GDPR Article 6(1)(c)).
  • Providing user accounts and the apps behind them (registration, sign-in, storing your content, sharing you initiate): Performance of a contract (GDPR Article 6(1)(b)).
  • Account security (email verification, session management, rate-limiting, and the security audit log): Legitimate interest in protecting accounts and preventing abuse (GDPR Article 6(1)(f)).

4. Processors We Use

Tools and processors we use:

  • Hosting provider: NEOSERV (Slovenian company, EU-based servers) – hosts the website, email, document storage.
  • Scheduling: Calendly – for managing call bookings.
  • Video calls: Zoom and Google Meet – for coaching sessions and calls.
  • Note-taking and client management: Obsidian, Microsoft – for storing and processing session documentation.
  • Analytics (future): When added, analytics tools will be privacy-friendly (e.g., Plausible or Matomo) and detailed in our Cookie Policy.

5. How Long Data is Stored

Retention is limited to what is necessary for each purpose:

  • Contact inquiries: Usually up to 2 years after the last communication, unless needed for legal claims.
  • Client and billing data: For the duration of the coaching relationship and as long as required by Slovenian tax law (typically 6 years).
  • Server logs and security data: Typically a few weeks to a few months, unless needed to investigate incidents.
  • Accounts and account content: Kept for as long as your account exists. When you delete your account, your account record, sign-in credentials, and the content you created in the apps are permanently deleted (email-verification and password-reset tokens are short-lived and expire automatically).

When retention periods expire, data is deleted or securely anonymized.

6. Who Receives the Data

Personal data may be shared only when necessary:

  • Service providers (processors): Hosting, scheduling (Calendly), analytics, video calls, IT support, and other vendors listed above.
  • Professional advisers: Accountants, legal advisers, or other consultants when needed to fulfill legal obligations or protect rights.
  • Public authorities: Only when required by applicable law or to protect rights, safety, and property.

Personal data is not sold or rented to third parties.

7. International Transfers

Where processors transfer personal data outside the EU/EEA, they implement appropriate safeguards including Standard Contractual Clauses (SCC) to ensure data protection equivalent to GDPR standards.

8. Data Subject Rights

Under GDPR and Slovenian law (ZVOP-2), individuals whose data we process have the following rights:

  • Right of access to their personal data.
  • Right to rectification of inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten") in certain situations.
  • Right to restriction of processing in specific circumstances.
  • Right to data portability for data processed on the basis of consent or contract.
  • Right to object to processing based on legitimate interests or direct marketing.
  • Right to withdraw consent at any time without affecting lawfulness of prior processing.

Requests can be sent to info@valentindominko.com and will be handled within GDPR time limits (typically one month).

If you have an account, you can exercise several of these rights yourself from your account page: view your account data (access), change your email or password (rectification), review and sign out active sessions, and permanently delete your account (erasure) — deletion also removes the content you created in the apps.

9. Complaints and Supervisory Authority

If someone believes their data protection rights were infringed, they can:

10. Security Measures

We apply appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Examples include:

  • Secure hosting with access control and regular updates.
  • Restricted access to our tools (strong passwords, 2FA where available).
  • Minimization of collected data and regular review of who has access.

11. User Accounts and User-Generated Content

Parts of the site (the interactive apps, such as Idea Machine) require a free user account. This section explains how accounts work.

  • Sign-in: Accounts use an email address and a password. Passwords are stored only as a salted one-way hash (argon2id) and are never stored or transmitted in readable form. We verify your email address before your first sign-in.
  • Sessions: When you sign in, an HttpOnly, Secure session cookie keeps you signed in across the site's apps. We store only a hashed session token, plus the IP address and browser user-agent of each active session so you can review and revoke them. This cookie is strictly necessary for the sign-in to function.
  • Your content and its visibility: Content you create in an app is private by default. You control its visibility (private, shared with specific people you choose, visible to signed-in members, or public) and can change it at any time. When you share with a specific person, that person's account is looked up by the exact username or email you enter.
  • What others see: On non-private content, your username is shown next to your comments, and your upvotes are counted; a full list of who upvoted is not shown to other users.
  • Deleting your account: You can permanently delete your account at any time from your account page. Deletion removes your account, sign-in credentials, and the content you created in the apps (your ideas and the comments, upvotes and shares tied to them).
  • Administration: A site administrator can manage accounts (for example verify, suspend, or delete an account, or reset access) for security and moderation. Administrative actions are recorded in the security audit log.

Account and app data are stored by our hosting provider (NEOSERV, EU-based) in a database separate from the public website content. Transactional emails (email verification, password reset) are sent over an encrypted connection.

12. Links, Cookies, and Changes

The website may contain links to other sites (e.g., LinkedIn, X/Twitter). Visitors are encouraged to read the privacy policies of those sites, as this policy applies only to valentindominko.com.

Details about cookies, including types, purposes, and consent management, will be described in a separate Cookie Policy and presented via a cookie banner in line with GDPR and ePrivacy rules.

This privacy policy may be updated occasionally; the "last updated" date at the top of the page will always show the current version.