AXON Cloud · EN
Privacy policy
Version 1.5 · Effective 2026-09-28
This Privacy Policy explains how AXON CLOUD, obrt za računalno programiranje, vl. Leonard Fedetov (“we”, “AXON Cloud”, “Provider”) collects, uses, stores and protects personal data on https://axoncloud.hr and in the AXON Cloud service (ERP / SaaS and related verticals).
It is drafted under the GDPR (Regulation (EU) 2016/679) and Croatian data-protection law. If you have signed a separate Master Service Agreement or DPA, those prevail for processing under a paid service.
1. Controller and contact
| Legal name | AXON CLOUD, obrt za računalno programiranje, vl. Leonard Fedetov |
| Short name | AXON CLOUD, vl. Leonard Fedetov |
| Owner | Leonard Fedetov |
| Address | Ulica Giuseppea Trombe 102, 52203 Šišan, Republika Hrvatska |
| Company ID (OIB) | 17445628019 |
| Craft register no. (MBO) | 99377527 |
| Crafts licence ID | 18010012127 |
| NACE / NKD | 62.10.9 — Ostalo računalno programiranje |
| Country | Republika Hrvatska |
| Website | https://axoncloud.hr |
| Privacy contact | [email protected] |
| Data protection contact | Leonard Fedetov · [email protected] |
| Customer support | [email protected] |
1.1 Two distinct roles
- Website / marketing / AXON’s own account administration — AXON Cloud is the controller.
- Data your company enters into ERP modules (partners, employees, guests, documents, CRM, etc.) — your company is the controller and AXON Cloud is the processor under the DPA and Art. 28 GDPR.
2. What data we collect
2.1 Website / marketing visitors
- identity and contact data from forms (name, email, phone, company, message, preferred language)
- technical data: IP address, browser / device type, timestamp, page URLs, referrer — as needed for security, diagnostics and abuse prevention
- cookies and similar technologies — see the Cookie policy
2.2 AXON Cloud users (sign-in and administration)
- username, email, phone (if provided), name, UI language
- roles, permissions, company / branch / warehouse assignments
- login and session records, IP, device, 2FA status, failed login attempts
- support: ticket / email content and attachments you send us
2.3 Commercial and contract data (B2B)
- customer company details (name, OIB, address, IBAN where needed for billing)
- contract, billing and technical-admin contacts
- offers, orders, invoices, payment records
2.4 Data we process as processor (ERP)
On the controller’s instructions, depending on modules: partners and contacts, employees and payroll, guests / members, renters / drivers, documents and attachments, CRM, accounting, warehouse, POS, etc.
We do not require special-category data (health, biometrics, religion, etc.) as a condition of use. If the controller enters such data, the controller is responsible for legal basis and notices to data subjects.
2.5 Data we do not intentionally collect
- data of children under 16 via marketing forms
- data from public social networks unless you send it to us or publicly contact AXON Cloud
3. Purposes
| Purpose | Example |
|---|---|
| Inquiries, demos, offers | contact form, email |
| Contract performance | subscription, onboarding, billing |
| Authentication and security | 2FA, sessions, audit logs |
| Customer / technical support | [email protected] |
| Legal obligations | accounting, tax, fiscalisation where applicable |
| Service improvement | aggregated / anonymised diagnostics |
| B2B marketing (where allowed) | product news with consent or legitimate interest + opt-out |
4. Legal bases (Art. 6 GDPR)
- contract (lit. b) — providing AXON Cloud, support, billing
- legal obligation (lit. c) — Croatian / EU tax and accounting rules
- legitimate interests (lit. f) — system security, abuse prevention, answering B2B inquiries, limited product communication to existing customers (with right to object)
- consent (lit. a) — non-essential cookies, newsletter where requested; you may withdraw consent at any time
We do not make solely automated decisions with legal effects about you as an individual (Art. 22), unless expressly agreed in a specific module.
5. Retention
| Category | Typical period |
|---|---|
| Marketing inquiries | up to 24 months after last contact, or shorter on request |
| User accounts | for the contract term + a reasonable wind-down (typically up to 90 days) |
| Security / audit logs | typically 6–24 months (unless law requires longer) |
| Invoices / books | per Croatian tax / accounting rules (often 11 years for books) |
| Customer ERP data | per controller instructions and the DPA; after termination — export (e.g. 30 days), then deletion / anonymisation |
| Cookie consents | for the consent lifetime + evidentiary period |
After the period ends we delete or anonymise data, unless longer retention is required for disputes or law.
6. Obligation to provide data and source
Certain identity and contact data are necessary to conclude / perform the contract and to sign in; without them the service cannot be provided. Marketing inquiries are voluntary.
We usually collect data directly from you or your company admin. When we act as processor for ERP data, the source is the controller (your company) and systems you make available (Art. 13/14 GDPR — see DPA).
7. Your rights
Access, rectification, erasure (within legal limits), restriction, portability, objection, and withdrawal of consent. Withdrawal does not affect lawfulness before withdrawal.
We may reasonably verify identity. We respond within one month (extendable by up to two further months with notice for complex or numerous requests).
- Public DSAR form: /privacy/dsar
- Email: [email protected]
- Post: Ulica Giuseppea Trombe 102, 52203 Šišan, Republika Hrvatska
For ERP data processed as processor, we will forward or handle the request with the controller (your company), unless law requires otherwise.
You may lodge a complaint with AZOP (Croatia), azop.hr.
8. Recipients
Only: authorised AXON Cloud personnel under confidentiality; sub-processors (see §9) under Art. 28 contracts; authorities when required by law; your authorised tenant users; professional advisers (lawyer, accountant) under confidentiality when needed.
We do not sell personal data or share it for third-party advertising.
9. Sub-processors (current list)
| Sub-processor | Role | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting, servers, storage, backup | European Union / EEA (Hetzner data centres) |
| Google LLC / Google Workspace (Gmail SMTP/IMAP where configured) | Transactional / support email | EEA / SCCs where applicable |
An updated list is available on request ([email protected] / [email protected]). Material sub-processor changes are announced reasonably in advance or via Security / DPA.
10. Technical and organisational measures (TOMs)
Measures proportionate to risk include multi-tenant isolation, HTTPS/TLS, access control and roles, authentication (including 2FA where enabled), password hashing, secret protection, logging, backups, breach procedures (Art. 33/34), and confidentiality obligations.
More: Security. In case of a personal-data breach posing a risk to individuals, we notify AZOP and, where required, data subjects / the controller within legal deadlines.
11. International transfers
Primary AXON Cloud SaaS hosting is in the EEA (Hetzner Online GmbH). If providers outside the EEA are used, appropriate safeguards apply (e.g. EU Commission standard contractual clauses) and the transfer is documented.
12. Cookies and similar technologies
Necessary cookies enable sign-in, security and basic operation. Analytics / marketing cookies — only with consent. Details: Cookie policy.
13. Third-party links
The website may link to external sites. AXON Cloud is not responsible for their privacy practices.
14. Changes
We may update this policy. The new version is published here with its effective date. Material changes for existing customers are announced reasonably in advance (email or in-app notice) where appropriate.
15. Contact
Leonard Fedetov · [email protected] · [email protected] · Support: [email protected] · Ulica Giuseppea Trombe 102, 52203 Šišan, Republika Hrvatska · https://axoncloud.hr/legal