Privacy policy
What I collect, why, how long I keep it and what rights you have over it.
This policy explains which personal data I collect through rootofjoy.com, why I collect it, how long I keep it and what rights you have over it.
It is written as plainly as the subject allows. If anything is unclear, write to me and I will explain it.
Last updated: 20 September 2026
Who processes your data
Data controller:
- Root of Joy, Petra Pupić
- RootofJoy, sole trader (obrt za usluge), owner Petra Pupić — tax number (OIB): 20337636668
- Oboj II. odvojak 6, 10000 Zagreb, Croatia
- Email: petra@rootofjoy.com
- Phone: +385 97 794 9796
I have not appointed a data protection officer, as the General Data Protection Regulation does not require me to. For any question about your data, write to me directly at the address above.
What I collect and why
When you contact me
When you write to me by email or through the form on this site, I collect your name, email address, phone number if you leave one, and the content of your message.
I use that only to reply to you and, if we agree to work together, to carry the work out. I use it for nothing else and I sell it to no one.
Legal basis: steps taken at your request before entering into a contract, and later the performance of that contract, under Article 6(1)(b) and (f) of the GDPR.
When you book a free call
To arrange a time I need your name, a contact detail and a rough picture of the space we are talking about. Notes from the call are kept only while the work is under way, or until you decide.
If you subscribe to the newsletter
Subscribing asks only for an email address, and a name if you wish to give one. Subscription is voluntary and is confirmed by clicking a link in the first message, so that nobody can subscribe someone else's address.
The newsletter is sent through MailerLite, which records whether a message was opened and whether a link in it was clicked. I look at those figures in aggregate, to learn which subjects interest people.
Legal basis: your consent, Article 6(1)(a). You can withdraw it at any time, through the unsubscribe link at the bottom of every message or by writing to me. Withdrawing consent does not affect the lawfulness of processing before the withdrawal.
Visit statistics
To know which pages people read and how they found them, I use Google Analytics. It records data about the device, the browser, an approximate location and the pages you opened.
Analytics runs only after you accept it in the cookie banner. If you decline, no analytics cookie is set and no data is sent.
Legal basis: your consent, Article 6(1)(a). The detail is in the cookie policy.
Server logs
The site is served through Netlify, which like any server records technical data about each request, including the IP address. Those logs serve security and troubleshooting, and I do not use them to follow individuals.
Legal basis: my legitimate interest in keeping the site running and secure, Article 6(1)(f).
How long I keep data
- Enquiries that did not lead to work — up to two years from the last message, so that I remember the context if you write again.
- Client and project data — for as long as the work lasts, and after that for as long as tax and accounting rules require.
- Newsletter address — until you unsubscribe. After that the address is removed from the list.
- Visit statistics — fourteen months, the longest period Google Analytics allows for individual visit data.
- Server logs — for as long as Netlify keeps them, under their terms.
Who receives your data
I do not sell your data and give it to no one for their own purposes. It reaches only the services without which the site and the newsletter would not work, and each gets only what it needs.
With each of them I have a data processing agreement in place, as Article 28 of the GDPR requires.
Netlify — serving the site
- Company: Netlify, Inc., 101 2nd Street, San Francisco, CA 94105, United States
- What it processes: technical request data, including the IP address
- Basis for transfer to the US: the EU — US Data Privacy Framework, with the European Commission's standard contractual clauses as an additional basis
Google — statistics and fonts
- Company: for users in Europe the data is processed by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, with transfer to Google LLC in the United States
- What it processes: data about your visit, if you accepted analytics
- Basis for transfer to the US: the EU — US Data Privacy Framework
Alongside analytics, the site loads fonts from Google Fonts. For that your IP address reaches Google even when you have declined analytics, because the fonts load as the page opens. Google Fonts sets no cookies.
MailerLite — the newsletter
- Company: MailerLite, Inc., 548 Market St, PMB 98174, San Francisco, CA 94104-5401, United States
- Where the data is stored: in Google Cloud data centres inside the European Union, in Germany and the Netherlands
- Sub-processors: Google Cloud EMEA Ltd (Ireland) and Vercom S.A. (Poland)
- Basis for transfer to the US: the European Commission's standard contractual clauses
Beyond that, my accountant may receive data where invoices are concerned, and competent authorities where the law requires it.
Transfers outside the European Union
Some of the services named above are based in the United States, which means that in certain cases data is transferred outside the European Economic Area.
Such transfers are permitted because they rely on the EU — US Data Privacy Framework, for which the European Commission adopted an adequacy decision in 2023, or on the standard contractual clauses adopted by the European Commission in Decision 2021/914.
The General Court of the European Union confirmed the validity of that framework in its judgment of 3 September 2025 in Latombe v Commission.
Your rights
Over your own data you have these rights:
- Access — to learn whether I process your data and to receive a copy of it.
- Rectification — to have an inaccurate detail corrected or an incomplete one completed.
- Erasure — to have your data deleted, once there is no longer a reason to keep it.
- Restriction — to have me keep the data but stop using it for a time.
- Portability — to receive the data you gave me in a machine-readable form, or to have me send it to another controller.
- Objection — to object to processing based on my legitimate interest.
- Withdrawal of consent — where processing rests on consent, you may withdraw it at any time.
For any of them it is enough to write to petra@rootofjoy.com. I reply within one month, and if a request is complex I will tell you that I need more time.
Exercising these rights is free of charge.
Complaint to the supervisory authority
If you believe I am not handling your data properly, the quickest way to sort it out is to write to me first. You can always, however, turn to the supervisory authority:
Croatian Personal Data Protection Agency (AZOP)
- Ulica Metela Ožegovića 16, 10000 Zagreb, Croatia
- Email: azop@azop.hr
- Phone: +385 1 4609 000
- azop.hr
Security and children
The site runs only over an encrypted connection (HTTPS). Only I have access to the data, from password-protected devices, and I sign in to every service with two-factor authentication.
No transmission over the internet is absolutely secure, but the measures I take match the amount and the kind of data I handle.
The services and the content of this site are meant for adults. I do not knowingly collect children's data. If I learn that I have received any, I delete it.
Changes to this policy
I update this policy when the way I work or the tools I use change. Every change is published on this page, and the date of the last change sits at the top.
If a larger change concerns you directly, I will tell you by email, where I have your address.
See also the cookie policy.