1. Controller
Dino VrgocKemptener Straße 20
89250 Senden
Germany
Email: contact@smartcroatiatravel.com. Further provider information is in the Impressum.
2. Scope
This Policy applies to the public Get FixFault website, its diagnosis and calculator tools, error-code directory, repair feedback and protected administration interface. Third-party websites linked from Get FixFault apply their own privacy notices.
3. Hosting, delivery and security logs
When a page or API endpoint is requested, hosting and security systems may process the IP address, time, requested URL, HTTP method and status, referrer, browser or device information, request identifiers and security signals. This is necessary to deliver the page, prevent abuse, diagnose faults, maintain availability and defend legal claims.
The legal basis is Article 6(1)(f) GDPR: our legitimate interests in providing a secure, reliable and technically functional service. Where processing is required by law, Article 6(1)(c) GDPR also applies. Security and server logs are retained only for the period reasonably necessary for those purposes, taking account of incident investigation, provider settings and applicable legal duties, and are then deleted or anonymized.
4. Search and abuse prevention
Public data APIs use short fixed-window rate limits. Cacheable catalogue reads keep a secret-salted hash derived from the client network address and endpoint scope only in short-lived Worker memory, while state-changing demand requests store that pseudonymous key with a request count and expiry marker in the rate-limit table. The service uses these controls to prevent one client from exhausting shared resources. The application does not store the raw IP address in the rate-limit table. Entries are designed to expire after a short abuse-prevention window; database cleanup may occur asynchronously.
The legal basis is Article 6(1)(f) GDPR, based on the legitimate interests described above. The data is not used to advertise to you or make decisions with legal or similarly significant effects.
5. Repair-outcome feedback
If you answer whether a guide worked and, where applicable, what fixed the appliance, we process the guide identifier, yes/no outcome, selected fix category, submission time and a secret-salted hash derived from the network address. The raw IP address is not stored in the feedback table. The hash prevents repeated votes for the same guide and lets a visitor correct the existing response from the same network identifier.
The legal basis is Article 6(1)(f) GDPR: our legitimate interest in improving guidance, preventing manipulation and publishing useful aggregate repair outcomes. Public statistics unlock only after a minimum response threshold and do not display the hash or an individual response. Feedback records are retained while they remain useful for those purposes, and may be deleted when the guide or dataset is withdrawn, a valid objection is upheld, or continued storage is no longer necessary.
6. Anonymous demand signals
When a public, proof-gated guide is opened, Get FixFault may increment an anonymous daily counter for that guide. The demand table stores only the public guide key, the UTC day, an aggregate count and the latest view timestamp. It does not store a raw IP address, account identifier, device fingerprint or analytics cookie. Automated and abusive traffic is filtered or rate-limited. These aggregates are used to show “most viewed” and “recently viewed” guide cards and to improve the service; they are retained as rolling demand data rather than a person-level history.
7. Consent preference and optional Google Analytics
The browser stores your analytics choice locally for up to 12 months so the site can respect it. This preference is necessary to provide the privacy setting you requested. Optional Google Analytics 4, measurement ID G-TXCQH77G6C, is not loaded unless you choose “Accept analytics.”
After consent, Google Analytics may process online identifiers, first-party analytics cookies, approximate location derived from the IP address, device and browser attributes, referring pages, visited pages and interaction data. Google signals, advertising storage, ad-user data and ad personalization are disabled in the site configuration. The purpose is audience measurement and service improvement. The legal basis is your consent under Article 6(1)(a) GDPR and, for device storage or access, § 25(1) TDDDG.
You can withdraw consent at any time using Cookie settings in the footer, with effect for the future. Withdrawal disables further measurement and attempts to remove accessible Get FixFault analytics cookies. It does not affect processing that was lawful before withdrawal. User-level and event-level Analytics data is retained according to the configured Google Analytics retention period, no longer than the options available for the standard property; aggregated reports may remain longer without identifying an individual visitor.
8. Protected administration and authentication
The administration area is restricted to approved accounts. Authentication and platform-security providers may process account identity, session, access-control and audit information for authorized administrators. Public visitors do not need an account. The legal basis is Article 6(1)(f) GDPR: protecting the editorial system and limiting administrative access.
9. Contact by email
If you contact us, we process the address, message, attachments and related correspondence needed to answer. Do not send unnecessary sensitive data. The legal basis is Article 6(1)(f) GDPR for ordinary inquiries, Article 6(1)(b) GDPR where the request concerns pre-contractual steps, and Article 6(1)(c) GDPR where retention is legally required. Correspondence is deleted when the inquiry and relevant retention or limitation periods no longer require it.
10. Service providers and recipients
Data may be received by providers used to operate, secure and administer the service, only to the extent necessary for their role. These may include:
- Cloudflare, Inc. and related entities for network delivery, security, Worker execution and database or storage infrastructure;
- OpenAI service infrastructure used to deploy and administer the hosted Site;
- Google Ireland Limited / Google LLC for Google Analytics only after consent;
- professional advisers, courts, regulators or public authorities where disclosure is necessary to comply with law or establish, exercise or defend legal claims.
We do not sell personal data. AdSense verification code is blocked until optional-services consent and the site currently requests no advertising units or affiliate tracking.
11. International transfers
Some providers operate globally, including in the United States. Where personal data is transferred outside the EEA, the transfer must rely on an applicable adequacy decision, the EU–US Data Privacy Framework where valid and applicable, European Commission standard contractual clauses, or another lawful safeguard. Provider privacy and transfer information is available from Cloudflare and Google.
12. Your GDPR rights
Subject to the legal conditions and exceptions, you may request access, rectification, erasure, restriction, data portability and information about recipients. You may withdraw consent at any time. You may object to processing based on Article 6(1)(f) GDPR for reasons arising from your particular situation. If processing were used for direct marketing, you could object at any time; Get FixFault does not currently use public visitor data for direct marketing.
Send a request to contact@smartcroatiatravel.com. We may request proportionate information to verify identity and protect others. Because repair feedback is intentionally pseudonymous, we may need the affected guide and approximate submission time to locate a record, and in some cases may not be able to connect a hash to an identifiable person without collecting additional data.
You also have the right to complain to a supervisory authority. The authority responsible for many private-sector controllers established in Bavaria is the Bavarian State Office for Data Protection Supervision (BayLDA). You may also contact the authority available under Article 77 GDPR.
13. Automated decisions, children and data requirement
Get FixFault does not use personal data for solely automated decisions that produce legal or similarly significant effects. The site is not directed to children under 16 and does not knowingly request a child’s personal data. No personal data is contractually required to read public content. Technical request processing is necessary to deliver and secure the service; optional analytics is not required.
14. Security and policy changes
We use access controls, restrictive browser security headers, limited public interfaces, pseudonymous abuse controls and data minimization. No internet service can guarantee absolute security. This Policy may be updated when services, providers or law change. The review date identifies the current version.