Legal
Privacy Policy
Last updated 10 September 2026
This Privacy Policy is an information notice about how personal data is processed in connection with the Project Lab website. It is not a contract and it does not ask for your agreement.
Project Lab documents personal, hobby, experimental and professional projects. Some are private, some support professional work, and a few may become products or services. This policy covers the Project Lab website only.
1. Privacy principles
- Collect as little personal data as possible.
- Use it only for the purpose it was given.
- Never sell personal data or use it for third-party advertising.
- Keep card and payment details off Project Lab entirely — support is processed by an external platform.
- Make it easy to ask a question, correct something, or have data removed.
2. Data controller
The controller responsible for this website is:
IFIX ELEKTRONIKA, obrt za usluge
Ul. Matice hrvatske 28A
21 000 Split
Hrvatska
Email: upit.ifix@gmail.com
3. What data we collect
Contact data — your email address, an optional name, and the content of any message you send us.
Support data — if you choose to add them when supporting a project: an optional public name/nickname and an optional short message, plus the amount, currency, project and date of a confirmed contribution and a payment status/reference.
Project Wall data — the optional name/nickname and message you chose to display, shown next to the amount, project and date. No email addresses appear on the Project Wall.
Technical data — standard server and CDN logs (such as IP address, request time and browser type) generated by the hosting provider.
Project Lab does not receive or store card numbers or full payment details at any point.
4. Why we collect it
- To run and secure the website.
- To reply to your messages.
- To let you provide voluntary financial support for a specific project and to record a confirmed contribution against that project.
- To show an optional supporter name/nickname and message on the Project Wall, if you ask us to.
- To keep accounting and legal records.
5. Legal bases
- Handling your message and processing a support contribution you start — to take steps at your request (GDPR Art. 6(1)(b)).
- Keeping the site available and secure and understanding which projects are supported — legitimate interests (Art. 6(1)(f)).
- Accounting and tax record-keeping — legal obligation (Art. 6(1)(c)).
- Optional publication of your details and any non-essential cookies — consent (Art. 6(1)(a)), which you can withdraw at any time.
6. Support / project data
Support is a voluntary financial contribution towards a project. It is not a purchase, and no product, service or reward is promised in return. Funding is tracked per project — your contribution counts only towards the project you chose, never a global total. Only successfully completed payments affect a project’s funding figure; failed, cancelled, pending and test payments do not.
7. Project Wall data
Showing your details on the Project Wall is optional. You may support with a public name, a nickname, or anonymously (where the payment platform allows), and a message is optional. An entry appears only after the payment is confirmed; a message may be reviewed before publication and may be edited, declined or removed. You can ask us to edit or remove your entry at any time by emailing upit.ifix@gmail.com.
8. Contact form / email data
If a contact form is used, it asks only for the minimum needed to reply (such as your email address and your message). Your message is used to respond to you and is not used for marketing.
9. External payment / support platform
Support payments are handled by Ko-fi, an external service. When you continue to Ko-fi, you leave Project Lab and are subject to Ko-fi’s own terms and privacy practices. Ko-fi and its payment providers carry out the payment, including any card details. Project Lab does not operate its own checkout and does not collect or store full payment card details; the exact transaction data shared back to Project Lab will be confirmed once the support setup is finalised. See Ko-fi’s privacy information.
10. External websites
Project Lab links to independent websites, including the separate ESP32 CAN Bus Sniffer website at esp32canbus.pages.dev, Ko-fi, Instagram and YouTube. Those sites have their own operators, payment systems and privacy policies. The ESP32 CAN Bus Sniffer website handles its own product sales, payment processing (myPOS), licensing and customer data. Project Lab does not use myPOS and does not share data with that website.
11. Data retention
- Email correspondence — kept while needed to handle your matter, then deleted.
- Project Wall entries — kept while the project is shown, or until you ask for removal.
- Support / accounting records — kept for the period required by Croatian law.
- Hosting / CDN logs — kept briefly under the hosting provider's own policy.
12. Data sharing
Personal data is shared only with the service providers needed to run the site and process support (hosting/CDN, and Ko-fi for payments), and with public authorities where the law requires it. It is never sold or shared for third-party advertising.
13. International transfers
Some providers (Ko-fi, Cloudflare, YouTube) may process data outside the European Economic Area. Where they do, they rely on safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision.
14. Cookies and local storage
Project Lab sets no analytics, marketing or tracking cookies. The only item it stores in your browser is your cookie/privacy choice (in local storage), so the notice does not reappear. Web fonts are served from this site, the Ko-fi control is a plain link with no third-party script, and the project video is not loaded until you press play. The hosting/CDN provider (Cloudflare) may set a strictly necessary cookie for security; it is not used for analytics or tracking. You can accept or reject non-essential cookies just as easily and change or withdraw your choice at any time via Cookie Settings in the footer.
15. Analytics
No analytics provider is currently installed. If one is added in future, this policy will be updated and it will load only after you give consent.
16. Security
The site is served over HTTPS from a managed hosting platform. Access to correspondence and any support records is limited to the controller. No system is perfectly secure, but data is kept to a minimum to reduce risk.
17. Your GDPR rights
You have the right to access, rectify, erase, restrict and object to processing, to data portability where applicable, and to withdraw consent at any time. To exercise any of these, email upit.ifix@gmail.com.
18. Supervisory authority (AZOP)
You can lodge a complaint with the Croatian data protection authority: Agencija za zaštitu osobnih podataka (AZOP).
19. Marketing
Project Lab does not run email marketing or newsletters and does not send promotional messages.
20. Updates to this policy
This policy may be updated as the site changes (for example, if support records are connected to a database, or a service is added or removed). The “last updated” date at the top reflects the current version.
21. Contact
For any privacy question or request: upit.ifix@gmail.com.