What we collect, and what we don't.
Kyuro is operated by one person. We collect the minimum needed to answer you, book a call, and measure whether our ads work — nothing else, and nothing about you is sold.
Who is responsible
The data controller is Kyuro, obrt za promidžbu i ostale usluge, vl. Daniel Vazdar · OIB: 65753088499 · MB: 99323605, seated at Zadarska 24, 31000 Osijek, Croatia, telephone +385 97 6124852. For any question about your data, or to exercise any of the rights below, emailhello@kyuro.tech. We have not appointed a data protection officer — our processing does not require one.
What we collect
When you email or book a call. Your name, email address, and whatever you choose to tell us about your business. We use it to reply and to run the call. It is kept for as long as we are in contact and for a reasonable period afterwards, and it is deleted on request.
When you use a form in one of our ads. If you fill in a form in an ad on Facebook or Instagram, we receive what you entered (name, contact details, answers) from Meta and handle it like any other enquiry.
Checking your company when you enquire. When you send an enquiry, we look up your company's name and line of business, and your business role, in public sources (the company website, public registers, business profiles) to prepare for our conversation. The search is run by an AI service (Anthropic) using the name, company and email from your enquiry. The result is saved with the enquiry in our CRM. We don't search private profiles and make no automated decisions about you.
When you simply read the site. Aggregate, cookieless analytics — page paths, referrer, approximate country, device type — collected via a self-hosted Umami instance we run ourselves. No cookies are set, no identifier follows you between sites, and the data is not personal in a form that identifies you.
Server logs. Our web server records requests for security and troubleshooting, with query strings stripped. These rotate and are not used to profile anyone.
Advertising: the Meta pixel
We advertise on Facebook and Instagram, and we need to know which ads bring people here. To do that we use the Meta advertising pixel. Where it is active, it sets cookies (_fbp, and _fbc when you arrive from an ad) and reports page views and enquiries to Meta Platforms Ireland Limited, which acts as a processor and, for its own purposes, as a joint or independent controller. This can involve transferring data outside the EEA under the EU–US Data Privacy Framework and standard contractual clauses.
The pixel is off by default. It loads only after you press Accept on the cookie banner. Until you do, no Meta script is fetched, no Meta cookie is written, and no event is sent. If you press Reject, none of that ever happens.
You can change your mind at any time. Use in the footer of any page. Withdrawing consent revokes the pixel and deletes the_fbp and _fbc cookies from your browser. Withdrawal does not undo processing that already, lawfully, took place.
Who else processes data for us
- Hostinger — our server, in a data centre in Frankfurt, Germany.
- Meta Platforms Ireland (Ireland) — advertising measurement, only with your consent (above), and ad forms.
- Attio Inc. (US) — the CRM where enquiries and calls are recorded.
- Anthropic PBC (US) — the AI service that looks up public company information for an enquiry.
- Telegram (UAE) — the new-enquiry notification on Daniel's phone.
- Brevo (Sendinblue GmbH) (Germany) — e-mail delivery: confirmations, reminders and survey results.
- Google (Ireland / US) — the spreadsheet survey answers are saved to.
- Cal.com (US) — call booking, when you book one.
- Proton AG (Switzerland) — our email, so anything you send us is stored there.
- Umami — visit analytics, self-hosted, cookieless.
Transfers to US providers rely on the EU–US Data Privacy Framework and standard contractual clauses; Switzerland has an EU adequacy decision. How we protect this data is on our Security page.
Legal bases
Answering your enquiry and running a booked call: our legitimate interest in responding to people who contact us, and the steps taken before entering a contract. Cookieless analytics and security logging: legitimate interest in operating a working, safe site. The Meta pixel and its cookies: your consent, and nothing else.
Your rights
Under the GDPR you may request access to your data, correction, erasure, restriction of processing, portability, and you may object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it at any time. Emailhello@kyuro.tech and we will respond within one month.
If you believe we have handled your data badly, you may complain to the Croatian supervisory authority — Agencija za zaštitu osobnih podataka (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr. We would rather you told us first.
Changes
If we add a tool that changes any of the above, we update this page before switching it on. Last updated 19 September 2026.