Privacy Policy
Last updated: 24 June 2026
This policy explains what personal data Sorapis collects through this website, why, and what rights you have. It is written in plain language on purpose.
1. Who is responsible
The data controller is Anto Andrijanic, operating as Sorapis (“Sorapis”, “I”, “me”), based in Croatia (EU). You can reach me about anything in this policy at hi@sorapis.io.
2. What data I collect
- What you send me through the contact form: your name, work email and agency/company (required), and your recruitment niche, team size and message (optional).
- Collected automatically when you submit the form: your IP address and country, captured by my hosting provider for security and abuse prevention and stored alongside your enquiry.
- Website analytics: I use privacy-friendly, cookieless analytics (Cloudflare Web Analytics). It sets no cookies, does not track you across sites and does not collect personal data, so no cookie banner is needed.
I do not use advertising or cross-site tracking cookies.
3. Why I use it, and the legal basis
- To respond to your enquiry and discuss a possible project: legal basis is steps taken at your request before entering a contract (GDPR Art. 6(1)(b)) and my legitimate interest in answering business enquiries (Art. 6(1)(f)).
- Security and abuse prevention (IP / country): my legitimate interest in protecting the site and form (Art. 6(1)(f)).
4. Who it is shared with
I do not sell your data or share it for advertising. I use a small number of providers that process data on my behalf (processors):
- Cloudflare, Inc. — website hosting and the form-handling function that processes your submission.
- Resend — delivers your enquiry to my inbox by email.
5. International transfers
Some of these providers are based in or process data in the USA. Where your data leaves the EEA, it is protected by appropriate safeguards such as the EU Standard Contractual Clauses.
6. How long I keep it
I keep your enquiry for as long as needed to handle your request and our correspondence, and for a reasonable period afterwards (up to 24 months), then delete it — unless we begin a working relationship, in which case I keep it for the duration of that work plus any period required by law. You can ask me to delete it sooner.
7. Your rights
Under the GDPR you have the right to access your data, and to its rectification, erasure, restriction, objection, and portability. To exercise any of these, email hi@sorapis.io.
You also have the right to complain to the Croatian supervisory authority, the Personal Data Protection Agency (AZOP) — azop.hr.
8. Automated decisions
I do not make any decisions about you by purely automated means.
9. Changes
If this policy changes, I will update the date at the top of this page.