Privacy policy

Version 2026-09

Digitalni Kustos is a digital guide for museums and heritage sites. This policy explains what data the platform processes, why, for how long and where. The platform is operated by [not set].

Who is responsible

The platform operator is [not set] ([not set]), contact: [not set].

Each institution (museum, fortress…) is responsible for its own content and for the accounts of its staff; the operator processes that data on the institution's behalf. For questions about a particular institution's content, contact that institution.

Visitors (scanning a QR code)

You do not need an account. When you open a point, we record which point was opened, when, the language of your device and your browser type (user agent). Your IP address is not stored.

The browser type is deleted after 90 days; the visit record itself (without it) is deleted after about 26 months. The institution sees only aggregated statistics. Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in knowing how the guide is used.

On your device the guide keeps your chosen language, the points you have visited and the larger-text setting, and stores visited points for offline use. This stays on your device and is not sent to us. We use no tracking or advertising cookies and no third-party analytics.

Your location is used only if you tap “Show distances”; distances are calculated on your device and your location is not sent to us.

Third parties when you use the map

The map is loaded from Microsoft Azure Maps (part of Microsoft Azure, where this application also runs), which receives your IP address, your language and the requested map area; map usage telemetry is switched off. If Azure Maps is unavailable, the map background is loaded from OpenStreetMap tile servers, which receive the same. “Take me there” opens Google Maps or Apple Maps, under their own privacy policies.

Technical errors

If a page fails, a short error report is sent (error message, page address, browser description) so that we can fix it. These reports are deleted after 90 days.

Institution staff (content editors)

For staff accounts we process the e-mail address, a password hash (Argon2id — the password itself is never stored), role, time of last sign-in and active sessions (up to 30 days). Changes made in the administration are logged for 2 years.

Signing in uses two strictly necessary cookies (the session); the interface language is kept in one more cookie. Legal basis: performance of the contract with the institution.

Where the data is stored

All data is stored on Microsoft Azure in a data centre in France (EU). Content that institutions publish (texts, photos, recordings) is public by design, because it is intended for visitors.

Your rights

You have the right of access, rectification, erasure, restriction and objection. Write to the operator contact above. You may also lodge a complaint with the Croatian Personal Data Protection Agency (AZOP, azop.hr).

Changes

When this policy changes, the new version is published on this page with a new version number.

Platform operator
[not set]
Company ID (OIB)
[not set]
Address
[not set]
Contact
[not set]
Terms of use