Last updated: 9 August 2026
This policy explains which personal data we collect when you visit our websites or use the
Toscana ERP and CRM system, why we process it and what rights you have. We process personal data
in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR).
1. Who is the controller
| Company | TOSCANA systems d.o.o. |
| Registered office | Svetoklarska 26b, 10020 Zagreb, Croatia |
| VAT number | HR37847480286 |
| Company registration number | 080826705 |
| E-mail | support@toscana-systems.eu |
2. Data protection officer
Our data protection officer is Andy Džinić. For any question about the processing of
your data, and to exercise the rights listed in section 9, write to
support@toscana-systems.eu.
3. What data we collect
When you visit the website. Our server records the IP address, date and time of the
request, the requested address, browser and operating system type and the referring page.
These logs serve security and troubleshooting.
When you fill in a form. Through the contact form, the presentation request, webinar
registration or newsletter sign-up we collect your name, company name, e-mail address,
telephone number and the content of your message.
When you are our customer. To conclude and perform the contract we process company
data, contact details of the people responsible for the project, user accounts in the system and
the data needed for invoicing.
Cookies. See section 10.
4. Purposes and legal bases
| Purpose | Legal basis |
| Answering an enquiry and preparing a quotation | Steps taken at your request prior to entering into a contract (Art. 6(1)(b)) |
| Concluding and performing the contract, customer support | Performance of a contract (Art. 6(1)(b)) |
| Issuing invoices and keeping business records | Legal obligation (Art. 6(1)(c)) |
| Newsletter and product announcements | Consent (Art. 6(1)(a)), which you may withdraw at any time |
| System security and prevention of misuse | Legitimate interest (Art. 6(1)(f)) |
5. When we act as a processor
For the data our customers enter into the Toscana ERP and CRM system — data about their own clients,
suppliers and employees — the customer is the controller and we are the processor.
We process that data solely on the customer's instructions and under a data processing agreement,
to the extent required to provide the service and technical support. We do not use it for our own
purposes and do not disclose it to third parties other than as described in section 6.
6. Who else can see the data
We do not sell personal data. We share it only with those we need in order to provide the service:
- the provider hosting our servers in Germany, within the European Union;
- e-mail and newsletter delivery providers;
- our accountants and auditors, within their statutory duties;
- competent authorities, where required by law.
We have data processing agreements in place with all processors.
7. Transfers outside the European Economic Area
Data is stored and processed on servers in Germany. We do not transfer it outside the
European Economic Area. Should such a transfer ever become necessary, it would take place only under
the appropriate safeguards of Chapter V of the GDPR and you would be informed in advance.
8. How long we keep data
- Enquiries and quotations — up to 2 years from the last contact, unless a contract results from them.
- Contracts and invoices — 11 years, as required by tax legislation.
- Data in the ERP system — for the duration of the contract and no more than 90 days after it ends,
after which it is deleted or returned to the customer according to their instruction.
- Newsletter — until consent is withdrawn.
- Server logs — up to 12 months.
9. Your rights
At any time you have the right to:
- request access to your data and a copy of it;
- request rectification of inaccurate data;
- request erasure where there is no longer a basis for processing;
- request restriction of processing;
- object to processing based on legitimate interest;
- request portability of your data in a machine-readable format;
- withdraw consent, without affecting the lawfulness of processing before withdrawal.
Send your request to support@toscana-systems.eu.
We respond within one month at the latest. If you believe your rights have been infringed, you may
lodge a complaint with the Croatian Personal Data Protection Agency (AZOP),
Selska cesta 136, 10000 Zagreb, azop.hr,
or with the supervisory authority in your country of residence.
10. Cookies
We use cookies that are strictly necessary for the site and for signing in to the system, without which
the site cannot work, and analytics cookies that show us which pages are read. You can block or delete
cookies in your browser settings; if you block the necessary ones, signing in will not work.
11. Security
Traffic to our websites and to the system is protected by TLS encryption. Access to data is limited to
employees who need it for their work and who are bound by confidentiality. Backups are made every
8 hours and stored within the European Union.
12. Changes to this policy
We may amend this policy from time to time. The date of the last change is shown at the top of the page.
We will notify customers of the system by e-mail about any material change.