Privacy Policy


Last updated: 9 August 2026

This policy explains which personal data we collect when you visit our websites or use the Toscana ERP and CRM system, why we process it and what rights you have. We process personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR).

1. Who is the controller

CompanyTOSCANA systems d.o.o.
Registered officeSvetoklarska 26b, 10020 Zagreb, Croatia
VAT numberHR37847480286
Company registration number080826705
E-mailsupport@toscana-systems.eu

2. Data protection officer

Our data protection officer is Andy Džinić. For any question about the processing of your data, and to exercise the rights listed in section 9, write to support@toscana-systems.eu.

3. What data we collect

When you visit the website. Our server records the IP address, date and time of the request, the requested address, browser and operating system type and the referring page. These logs serve security and troubleshooting.

When you fill in a form. Through the contact form, the presentation request, webinar registration or newsletter sign-up we collect your name, company name, e-mail address, telephone number and the content of your message.

When you are our customer. To conclude and perform the contract we process company data, contact details of the people responsible for the project, user accounts in the system and the data needed for invoicing.

Cookies. See section 10.

4. Purposes and legal bases

PurposeLegal basis
Answering an enquiry and preparing a quotationSteps taken at your request prior to entering into a contract (Art. 6(1)(b))
Concluding and performing the contract, customer supportPerformance of a contract (Art. 6(1)(b))
Issuing invoices and keeping business recordsLegal obligation (Art. 6(1)(c))
Newsletter and product announcementsConsent (Art. 6(1)(a)), which you may withdraw at any time
System security and prevention of misuseLegitimate interest (Art. 6(1)(f))

5. When we act as a processor

For the data our customers enter into the Toscana ERP and CRM system — data about their own clients, suppliers and employees — the customer is the controller and we are the processor. We process that data solely on the customer's instructions and under a data processing agreement, to the extent required to provide the service and technical support. We do not use it for our own purposes and do not disclose it to third parties other than as described in section 6.

6. Who else can see the data

We do not sell personal data. We share it only with those we need in order to provide the service:

  • the provider hosting our servers in Germany, within the European Union;
  • e-mail and newsletter delivery providers;
  • our accountants and auditors, within their statutory duties;
  • competent authorities, where required by law.

We have data processing agreements in place with all processors.

7. Transfers outside the European Economic Area

Data is stored and processed on servers in Germany. We do not transfer it outside the European Economic Area. Should such a transfer ever become necessary, it would take place only under the appropriate safeguards of Chapter V of the GDPR and you would be informed in advance.

8. How long we keep data

  • Enquiries and quotations — up to 2 years from the last contact, unless a contract results from them.
  • Contracts and invoices — 11 years, as required by tax legislation.
  • Data in the ERP system — for the duration of the contract and no more than 90 days after it ends, after which it is deleted or returned to the customer according to their instruction.
  • Newsletter — until consent is withdrawn.
  • Server logs — up to 12 months.

9. Your rights

At any time you have the right to:

  • request access to your data and a copy of it;
  • request rectification of inaccurate data;
  • request erasure where there is no longer a basis for processing;
  • request restriction of processing;
  • object to processing based on legitimate interest;
  • request portability of your data in a machine-readable format;
  • withdraw consent, without affecting the lawfulness of processing before withdrawal.

Send your request to support@toscana-systems.eu. We respond within one month at the latest. If you believe your rights have been infringed, you may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr, or with the supervisory authority in your country of residence.

10. Cookies

We use cookies that are strictly necessary for the site and for signing in to the system, without which the site cannot work, and analytics cookies that show us which pages are read. You can block or delete cookies in your browser settings; if you block the necessary ones, signing in will not work.

11. Security

Traffic to our websites and to the system is protected by TLS encryption. Access to data is limited to employees who need it for their work and who are bound by confidentiality. Backups are made every 8 hours and stored within the European Union.

12. Changes to this policy

We may amend this policy from time to time. The date of the last change is shown at the top of the page. We will notify customers of the system by e-mail about any material change.