Privacy Policy
Last updated: 26 June 2026
TopStar MGMT ("we", "us", or "our") operates the website topstarmgmt.hr. This policy explains what personal data we collect, for what purpose and on what legal basis, and the rights you have under the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") and the Croatian act implementing it.
1. Data Controller
The controller of your personal data is TopStar MGMT. For any data-protection questions and to exercise your rights, you can contact us at info@topstarmgmt.com.
2. Data We Collect
We collect personal data only when you provide it yourself, or, with your consent, through analytics:
- Form data (the contact form and the application pop-up): first name, last name, email address, phone number, your Instagram and Telegram handles, and the content of the message you send us.
- Usage data (analytics): if you accept analytics cookies, we collect data such as the pages you visit, time spent on the site, your device and browser type, and approximate location (derived from your IP address). This data is processed by Google Analytics and is not loaded without your consent (see section 9 on cookies).
- Server logs: our hosting provider automatically records technical data (such as your IP address and browser information) for the security and proper functioning of the site.
We do not collect payment or financial data through this website, and we do not request special categories of personal data.
3. Purposes and Legal Basis
We process your data for the following purposes and on the following legal bases under Article 6 of the GDPR:
- Responding to enquiries and processing applications submitted through the forms, so we can reply to you and assess a possible collaboration. Legal basis: your consent and taking steps at your request prior to entering into a contract (Article 6(1)(a) and (b) GDPR).
- Analytics and site improvement, to understand how the site is used and improve it. Legal basis: your consent (Article 6(1)(a) GDPR).
- Security and operation of the site through technical logs. Legal basis: our legitimate interest in a secure and reliable website (Article 6(1)(f) GDPR).
We do not sell, rent, or share your personal data with third parties for marketing purposes.
4. Recipients and Processors
To run the site we use trusted service providers that process data on our behalf as processors:
- Formspree: processing and delivery of form submissions (a US-based service). See their privacy policy.
- Google Analytics 4 (Google): site usage analytics; involves a transfer of data to the US. See Google's privacy policy.
- Vimeo: playback of the videos embedded on the homepage; when a video loads, Vimeo may set cookies and collect data. See Vimeo's privacy policy.
- Vercel: site hosting; processes server logs. See Vercel's privacy policy.
- Google Fonts: fonts are loaded from Google's servers, which may record your IP address.
5. International Data Transfers
Some of the providers above (for example Google and Formspree) process data in the United States. In those cases, the transfer relies on appropriate safeguards such as the EU-US Data Privacy Framework and the standard contractual clauses approved by the European Commission.
6. Data Retention
We keep personal data only for as long as necessary for the purpose for which it was collected. We keep form data for as long as needed to communicate with you and assess a possible collaboration, and for no longer than two years after our last contact, unless the law requires longer retention or until you withdraw your consent. Analytics data is retained by Google Analytics in line with its configured retention period.
7. Your Rights
Under the GDPR you have the following rights regarding your personal data:
- the right of access to your data (Article 15);
- the right to rectification of inaccurate data (Article 16);
- the right to erasure ("right to be forgotten", Article 17);
- the right to restriction of processing (Article 18);
- the right to data portability (Article 20);
- the right to object to processing (Article 21);
- the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
You can exercise your rights by contacting us at info@topstarmgmt.com. We will respond to your request within the time limits set by the GDPR.
8. Right to Lodge a Complaint
If you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the supervisory authority. In the Republic of Croatia this is the Croatian Personal Data Protection Agency (AZOP), azop.hr.
9. Cookies
Cookies are small files stored on your device. We use two categories:
- Essential cookies: needed for the basic operation of the site and to remember your privacy choice. These are always on.
- Analytics cookies (Google Analytics): help us understand how the site is used. They load only if you accept them via the consent banner. If you reject them, Google Analytics is not started.
You can change your choice at any time by clicking Cookie settings.
10. Children
Our services are not directed to individuals under the age of 18, and we do not knowingly collect personal data from minors.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated date.
12. Contact
If you have any questions about this Privacy Policy, you can reach us at:
info@topstarmgmt.com