Na početnu stranicu

Privacy Policy

Last updated: January 2026

Data Protection Overview

Sandy Smajic Cybersecurity Consulting is committed to protecting your personal data and respecting your privacy rights. This privacy policy explains how we collect, use, and safeguard your information in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

Data Controller

Sandy Smajic

Maxstr. 3, 45127 Essen, Germany

Contact

info@sandysmajic.com

+49 176 70035262

What Personal Data We Collect

Contact Information

  • Full name and business title
  • Email address and phone number
  • Company name and address
  • Professional LinkedIn profile

Technical Data

  • IP address and browser information
  • Website usage analytics
  • Cookie preferences and settings
  • Device type and operating system

How We Use Your Data

Legitimate Business Purposes

  • • Responding to consultation requests and providing cybersecurity services
  • • Conducting security assessments and compliance audits
  • • Sending relevant industry updates and security alerts
  • • Maintaining client relationships and project communications

Legal Compliance

  • • Meeting regulatory requirements (NIS2, GDPR, TISAX)
  • • Maintaining records for audit and compliance purposes
  • • Fulfilling contractual obligations with clients

Your GDPR Rights

Right to Access

Request a copy of your personal data we hold

Right to Rectification

Correct inaccurate or incomplete data

Right to Erasure

Request deletion of your personal data

Right to Portability

Receive your data in a structured format

Right to Object

Object to processing for direct marketing

Right to Restrict

Limit how we process your data

To exercise your rights: Contact us at info@sandysmajic.com with "GDPR Request" in the subject line. We will respond within 30 days as required by law.

Data Security & Retention

Security Measures

As a cybersecurity professional, we implement industry-leading security measures including:

  • • End-to-end encryption for all data transmission
  • • Multi-factor authentication for system access
  • • Regular security audits and penetration testing
  • • ISO 27001 compliant data handling procedures

Data Retention

  • • Client data: Duration of engagement + 7 years (legal requirement)
  • • Marketing contacts: Until consent is withdrawn
  • • Website analytics: 26 months maximum

© 2026 Sandy Smajic Consulting. All rights reserved.