Privacy Policy
Effective date: 2 September 2026
Version: 2.0
This Privacy Policy explains how DEXPIRY collects, processes, stores and protects personal data of users of the website dexpiry.com and the related web/mobile application (the "Service").
The Service processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the General Data Protection Regulation — GDPR) and applicable Croatian data-protection law.
1. Controller
The controller of personal data is:
Legal entity: J.P. Mrgan društvo s ograničenom odgovornošću za računalne djelatnosti
Registered office: Podbrežje X. 15, Zagreb
Company registration number (MBS) / OIB: 081630485 / 63318944858
Contact email: support@dexpiry.com
2. Data-protection principles
The controller processes personal data in accordance with the principles in Article 5 GDPR:
- Lawfulness, fairness and transparency: data are processed lawfully and in a way that is clear and understandable to the data subject.
- Purpose limitation: data are collected for specified, explicit and legitimate purposes and are not further processed in a manner incompatible with those purposes.
- Data minimisation: only data that are necessary for the purposes of processing are collected.
- Accuracy: data must be accurate and, where necessary, kept up to date.
- Storage limitation: data are kept only as long as necessary for the purposes of processing.
- Integrity and confidentiality: data are processed using technical and organisational measures that protect against unauthorised processing, loss or destruction.
3. Categories of personal data, purposes and legal bases
In providing the Service, personal data are processed on the following legal bases:
| Purpose of processing | Categories of personal data | Legal basis under Art. 6(1) GDPR |
|---|---|---|
| Registration and account management | Email address, sign-in data, registration date. | Performance of a contract (point (b)) — necessary to create an account and provide access to the Service. |
| Receipt inbox, product records and digital warranties | Receipt and purchase data, product and warranty data, and information the user enters (for example dates, notes, notification channels). | Performance of a contract (point (b)) — providing the requested record-keeping and notification service. |
| Billing and subscription management (where applicable) | Transaction data, subscription identifier, name, billing address. Payment-card data are processed directly by an authorised payment-service provider; DEXPIRY does not store them. | Performance of a contract (point (b)) and legal obligation (point (c)) — tax and accounting duties. |
| Customer support and handling enquiries | Email address, name, content of the enquiry, technical details of the issue. | Performance of a contract (point (b)) or legitimate interest (point (f)) — ensuring the Service operates and users can get support. |
| System security and prevention of abuse | IP address, device and browser data, access logs, sign-in and sign-out times. | Legitimate interest (point (f)) — protecting network and information security and preventing unauthorised access. |
| Informational messages and newsletters | Email address, first and last name. | Consent (point (a)) — the data subject may withdraw consent at any time. |
| Service analytics and improving the user experience | Statistical usage data, technical diagnostics (anonymised or pseudonymised). | Legitimate interest (point (f)) for necessary technical analytics, or consent (point (a)) for third-party analytics cookies if used. |
DEXPIRY does not collect banking credentials, investment information, medical information or health data.
4. Digital warranties and blockchain
Some warranty records may be connected to blockchain-based identifiers. The Service uses these identifiers to verify and display digital warranties.
The Service is not used for cryptocurrency trading, investment services, payments or financial advice.
5. Recipients of personal data (processors)
The controller does not sell, rent or otherwise disclose personal data to third parties without authorisation.
Data may be entrusted to trusted contractual partners acting solely as processors, under a data-processing agreement in accordance with Article 28 GDPR:
- Hosting and cloud computing providers: hosting and data-storage services (for example servers located in the EU/EEA).
- Communications and notification providers: services used to send transactional and reminder emails.
- Payment-service providers: licensed payment institutions that process payment data to their own security standards (PCI-DSS), where subscription billing is active.
- Competent public authorities: data are disclosed only where there is an express legal obligation or a binding order of a competent court or other public body.
6. International transfers of personal data
Personal data are primarily stored and processed within the European Union and the European Economic Area (EEA).
If individual processors are located in third countries outside the EEA, transfers are carried out only with appropriate safeguards under Chapter V GDPR, including:
- Transfers to countries for which the European Commission has adopted an adequacy decision (including US entities certified under the EU-US Data Privacy Framework).
- Use of Standard Contractual Clauses (SCCs) approved by the European Commission, together with a transfer impact assessment and additional encryption and technical measures.
7. Retention periods
Personal data are stored only as long as necessary for the purposes for which they were collected:
- Account data and user-entered records: kept for the lifetime of the user account. After the user requests account deletion, data are permanently deleted or irreversibly anonymised within 30 days, except data the controller is required to retain by law or to protect warranty rights.
- Financial and accounting data: kept in accordance with applicable tax and accounting rules (at least 11 years from the end of the business year to which they relate).
- Server logs: stored for up to 12 months to ensure system stability and security.
- Data processed on the basis of consent: kept until consent is withdrawn, after which processing is stopped without delay.
8. Technical and organisational security measures
In accordance with Article 32 GDPR, the controller applies appropriate technical and organisational measures to ensure a level of security appropriate to the risk:
- Encryption: TLS/HTTPS for data in transit and encryption of sensitive data at rest.
- Secure access management: cryptographic hashing of passwords or other secure authentication methods.
- Access control: personal data are accessible only to persons and contractors who need access to perform their tasks (least-privilege principle).
- Integrity and availability: regular backups and testing of system resilience.
9. Your rights
As a data subject, you have the following rights under the GDPR:
- Right of access (Art. 15 GDPR): you may obtain confirmation as to whether your personal data are processed, and access to those data, the purposes of processing, categories of data and recipients.
- Right to rectification (Art. 16 GDPR): you may obtain without undue delay the rectification of inaccurate personal data or the completion of incomplete data.
- Right to erasure ("right to be forgotten", Art. 17 GDPR): you may request deletion of personal data if they are no longer necessary for the purposes for which they were collected, if you withdraw consent on which processing is based, if you object to processing and the objection is justified, or if the data have been unlawfully processed.
- Right to restriction of processing (Art. 18 GDPR): you may request restriction where you contest the accuracy of data, where processing is unlawful and you oppose erasure, or while an objection is being considered.
- Right to data portability (Art. 20 GDPR): you may receive the personal data you provided to us in a structured, commonly used and machine-readable format and transmit them to another controller without hindrance.
- Right to object (Art. 21 GDPR): you may object at any time to processing based on the controller's legitimate interest, including profiling based on those provisions.
- Right to withdraw consent (Art. 7(3) GDPR): where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
How to exercise your rights
You may send a request to exercise any of these rights to support@dexpiry.com. The controller will examine the request and respond without undue delay, and at the latest within one month of receiving a valid request (Article 12(3) GDPR).
10. Right to lodge a complaint with a supervisory authority
If you consider that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority under Article 77 GDPR.
The competent supervisory authority in the Republic of Croatia is the Croatian Personal Data Protection Agency (AZOP), Ulica Metela Ožegovića 16, 10000 Zagreb, Croatia. Website: www.azop.hr. Email: azop@azop.hr. Phone: +385 (0)1 4609 000.
If you have your habitual residence or place of work in another EU Member State, you may also lodge a complaint with the supervisory authority in that Member State.
11. Automated individual decision-making and profiling
The DEXPIRY Service does not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects your rights and freedoms within the meaning of Article 22 GDPR.
12. Cookies and similar tracking technologies
The website dexpiry.com uses browser local storage for necessary functions, such as remembering your language choice. Details are set out in the Cookie Policy.
We do not currently use third-party analytics or marketing cookies. If we introduce them, we will ask for your explicit, voluntary and informed consent for any cookies that are not strictly necessary.
13. Children
DEXPIRY is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
14. Changes to this Privacy Policy
The controller may update this Privacy Policy from time to time to reflect changes in law, case law or the technical operation of the Service.
Users will be informed of material changes through a prominent notice on the website or via the email address provided at registration, at least 15 days before the changes take effect.