IRONVALD
POLICY / PUBLIC / VERSION 2.0

> LEGAL TRANSMISSION

PRIVACY POLICY

EFFECTIVE 27 May 2026·VERSION 2.0·CONTROLLER OD IRONVALD SARAJEVO

01Data Controller

Legal entity
OD IRONVALD Sarajevo
Registered office
Trg međunarodnog prijateljstva 10, Sarajevo, Bosnia and Herzegovina
Website
ironvald.com

For all matters relating to data protection, privacy inquiries, and the exercise of data subject rights, please contact us at info@ironvald.com.

02Scope of This Policy

This Privacy Policy applies to all personal data collected and processed by OD IRONVALD Sarajevo (hereinafter “IRONVALD”, “we”, “us”, or “our”) through our website ironvald.com, including the analytics consent banner, the contact form, and any marketing communications. It does not apply to personal data processed under separate contractual agreements with clients or partners, which are governed by dedicated data processing agreements.

03Legal Framework and Compliance

IRONVALD operates in full compliance with the following legal and regulatory frameworks:

  • Zakon o zaštiti ličnih podataka Bosne i Hercegovine, br. 12/25 (Law on Personal Data Protection of Bosnia and Herzegovina)
  • Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)
  • ISO/IEC 27001:2022 – Information Security Management System (certified)
  • Directive (EU) 2022/2555 (NIS2) – applied as a reference framework for critical infrastructure clients

Where GDPR and the BiH Law on Personal Data Protection overlap, we apply the stricter of the two standards.

04Consent Architecture Overview

IRONVALD processes personal data on the basis of freely given, specific, informed, and unambiguous consent in accordance with Article 6(1)(a) GDPR and the equivalent provisions of the BiH Law on Personal Data Protection. We operate a three-layer consent architecture:

LayerLegal BasisRetentionMechanism
Website Analytics (Google Analytics, Vercel Web Analytics, Vercel Speed Insights, Google Ads conversion)Consent — Art. 6(1)(a) GDPRPer each provider’s configured retentionConsent banner; tags fire only after acceptance
B2B Contact ProcessingConsent — Art. 6(1)(a) GDPR3 years from last interactionCheckbox 1 on contact form; unticked by default
Marketing CommunicationsConsent — Art. 6(1)(a) GDPRUntil consent is withdrawnCheckbox 2 on contact form; unticked by default; unsubscribe at any time

Each consent layer is independent. Declining one layer does not affect any other. All consents may be withdrawn at any time by contacting info@ironvald.com.

05Personal Data We Collect

5.1 Website Analytics (Consent Layer 1)

Before any analytics data is collected, visitors to ironvald.com are presented with a consent banner. None of the analytics tags fire unless and until the visitor actively accepts. If the visitor declines or ignores the banner, no analytics data is collected or transmitted.

Upon consent, the following pseudonymised data may be collected:

  • Browser type and version
  • Operating system
  • Referring URL
  • Pages visited and time spent
  • General geographic location (country/region level, derived from anonymised IP address)
  • Device type
  • Page performance metrics (Core Web Vitals, via Vercel Speed Insights)
  • Conversion attribution (via Google Ads tag, fired only after contact form submission and only with consent)

Google Analytics and Google Ads conversion data are processed by Google LLC, operating as our data processor. Vercel Web Analytics and Vercel Speed Insights are processed by Vercel Inc., operating as our data processor. IP addresses are anonymised prior to storage. We do not use any of these tools to identify individual users or combine analytics data with contact form data.

5.2 Contact Form (Consent Layer 2)

When you submit an inquiry through the contact form on ironvald.com, we collect:

  • Full name
  • Email address
  • Company name
  • Inquiry topic
  • Message content (any additional information you voluntarily include)

We additionally record a one-way cryptographic hash (HMAC-SHA256) of your IP address and your browser’s user-agent string at the moment of submission. These values are stored as part of the consent record (see §6 below) to satisfy our obligation under Article 7(1) GDPR to demonstrate that consent was given. The raw IP address is not stored.

This data is processed solely for the purpose of responding to your inquiry and managing the B2B interaction. Processing under this layer requires explicit opt-in via Checkbox 1 on the contact form, which is unticked by default. Submission of the form is not possible without ticking this checkbox.

[REQUIRED] I consent to IRONVALD processing my name and email address to handle my inquiry and manage our business interaction. — Retained for 3 years from the date of last interaction. Required to submit.

5.3 Marketing Communications (Consent Layer 3)

Where you separately and voluntarily opt in via Checkbox 2 on the contact form, IRONVALD may use your name and email address to send you:

  • Business updates and service announcements
  • Industry research and cybersecurity intelligence relevant to your sector
  • Surveys and feedback requests

This consent is entirely optional and independent of Checkbox 1. Ticking Checkbox 2 is not required to submit the contact form or to receive a response to your inquiry.

[OPTIONAL] I consent to IRONVALD contacting me with relevant business communications, updates, and surveys. — Retained until consent is withdrawn. Optional.

You may withdraw your marketing consent at any time by contacting info@ironvald.com or by using the unsubscribe mechanism included in every marketing communication. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.

5.4 Cookies and Local Storage

IRONVALD uses one strictly-necessary first-party cookie (ironvald_consent) to remember your analytics consent choice for 12 months. This cookie is exempt from consent requirements under ePrivacy / GDPR Recital 30 because it is strictly necessary to deliver a service the user has requested (the ability to record a consent preference).

We do not set tracking cookies, advertising cookies, or any other persistent browser-based tracking mechanisms unless you have accepted the analytics banner. We do not collect payment data, biometric data, or special category data as defined under GDPR Article 9 and the BiH Law on Personal Data Protection.

06Legal Basis for Processing

All personal data processing by IRONVALD is grounded in consent (Article 6(1)(a) GDPR and equivalent BiH law provisions):

  • Layer 1 — Website Analytics: consent collected via the website consent banner. Tags fire only after active acceptance.
  • Layer 2 — B2B contact processing: consent collected via Checkbox 1 on the contact form. Required for form submission; unticked by default.
  • Layer 3 — Marketing communications: consent collected via Checkbox 2 on the contact form. Optional; unticked by default; withdrawable at any time.

We do not rely on legitimate interest as a legal basis for any personal data collected through ironvald.com.

07Data Storage, Access, and Security

Contact form submissions (name, email address, company, topic, and message content) and the associated consent records (timestamp, hashed IP, consent flags, policy version, hashed user-agent) are stored in a managed MongoDB Atlas cluster controlled and administered by IRONVALD. Access to this data is restricted to authorised personnel via role-based access control. No other personnel have routine access to raw contact form data without explicit authorisation.

As an ISO/IEC 27001:2022 certified organisation, IRONVALD maintains a documented Information Security Management System (ISMS) governing all aspects of data storage, access control, incident response, and physical and logical security. Technical and organisational measures include:

  • Role-based access control (RBAC) on all data storage systems
  • Encryption at rest and in transit (TLS 1.2+)
  • HMAC-SHA256 hashing of IP addresses and user-agent strings in consent records
  • Access logging and audit trails
  • Regular security assessments and internal audits aligned with ISO/IEC 27001:2022 Annex A
  • Formal incident response procedures

Analytics data is stored by Google LLC and Vercel Inc. on infrastructure governed by their respective data processing terms and applicable Standard Contractual Clauses.

08Data Retention

  • Layer 2 — B2B contact data: retained for 3 years from the date of last interaction. Upon expiry, data is securely deleted from IRONVALD’s database. Data subjects may request early deletion at any time (see §10).
  • Layer 3 — Marketing contact data: retained until the data subject withdraws consent. Withdrawal may be exercised at any time by contacting info@ironvald.com or by using the unsubscribe link in any marketing communication. Upon withdrawal, contact details are removed from active marketing lists within 5 business days.
  • Layer 1 — Analytics data: retained in accordance with the retention periods configured in Google Analytics and Vercel. Aggregated and anonymised analytics reports may be retained beyond this period as they do not constitute personal data.
  • Consent records: retained for the lifetime of the corresponding contact data plus a reasonable audit period. These records contain only a hashed IP address, hashed user-agent, consent flags, timestamp, and policy version — no directly identifying personal data — and serve as evidence of lawful processing under Article 7(1) GDPR.

09International Data Transfers

Contact form data and consent records are stored on MongoDB Atlas, operated by MongoDB Inc. The underlying infrastructure is provided by a hyperscale cloud provider in a region selected by IRONVALD. Transfers, where applicable, are governed by MongoDB’s Data Processing Addendum and Standard Contractual Clauses pursuant to GDPR Chapter V.

Google Analytics and Google Ads conversion data are processed by Google LLC (United States). Google participates in the EU–U.S. Data Privacy Framework and processes data under Standard Contractual Clauses pursuant to GDPR Chapter V. For further information, see policies.google.com/privacy.

Vercel Web Analytics and Vercel Speed Insights are processed by Vercel Inc. (United States) under Standard Contractual Clauses pursuant to GDPR Chapter V.

IRONVALD does not otherwise transfer personal data to third countries or international organisations outside the processing described above.

10Your Rights as a Data Subject

Under the GDPR and the BiH Law on Personal Data Protection, you have the following rights:

  • Right to withdraw consent — you may withdraw any consent given at any time. Withdrawal does not affect the lawfulness of prior processing.
  • Right of access — you may request a copy of the personal data we hold about you.
  • Right to rectification — you may request correction of inaccurate or incomplete data.
  • Right to erasure — you may request deletion of your personal data. Requests are processed within 30 days.
  • Right to restriction of processing — you may request that we limit how we use your data in certain circumstances.
  • Right to object — you may object to any processing. We will cease processing upon receipt of a valid objection unless we can demonstrate compelling legitimate grounds.
  • Right to data portability — where technically feasible and legally applicable, you may request your data in a structured, machine-readable format.
  • Right to lodge a complaint — with the Agency for Personal Data Protection of Bosnia and Herzegovina (Agencija za zaštitu ličnih podataka u Bosni i Hercegovini) or, where applicable, with the supervisory authority of an EU member state.

To exercise any of the above rights, contact us at info@ironvald.com. We will respond within 30 days of receipt of a verifiable request. We may request proof of identity before processing any request.

11Third-Party Processors

  • MongoDB, Inc. — MongoDB Atlas database storage for contact form data and consent records. Governed by the MongoDB Data Processing Addendum and Standard Contractual Clauses.
  • Google LLC — Google Analytics and Google Ads conversion tracking (Consent Layer 1). Governed by Google’s Data Processing Terms and Standard Contractual Clauses.
  • Vercel Inc. — Web hosting, Vercel Web Analytics, and Vercel Speed Insights (Consent Layer 1 for analytics; hosting itself processes connection metadata as a technically necessary function). Governed by Vercel’s Data Processing Addendum and Standard Contractual Clauses.
  • Resend, Inc. — transactional email delivery for contact form notifications. Governed by Resend’s Data Processing Addendum.

We do not sell, rent, or otherwise disclose personal data to any other third parties, except as required by applicable law or pursuant to a lawful request by a competent authority.

12Data Breach Notification

In the event of a personal data breach likely to result in risk to the rights and freedoms of natural persons, IRONVALD will notify the competent supervisory authority within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33 and the BiH Law on Personal Data Protection. Where the breach is likely to result in high risk to individuals, affected data subjects will also be notified without undue delay.

13Changes to This Policy

IRONVALD reserves the right to update this Privacy Policy at any time. Material changes will be reflected in an updated Effective Date. Where changes affect active consents, we will seek renewed consent where required by law. We encourage you to review this policy periodically. Continued use of ironvald.com following an update constitutes acknowledgment of the revised policy.

14Contact

For questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data:

Entity
OD IRONVALD Sarajevo