No analytics. No tracking. No banner.
This site sets no cookies of its own, loads nothing from third parties, and measures nothing about you. That is not a policy position written after the fact — it is how the site is built, and you can verify it from your browser's network tab in about ten seconds.
Last updated 1 September 2026. Controller: RTFM d.o.o., Ulica Fortunata Pintarica 24, 48000 Koprivnica, Croatia (OIB 39175066534, VAT HR39175066534). Contact: matija@rtfm.hr.
What this site collects
No analytics, and nothing set by this site. There is no analytics package, no tag manager, no advertising or social pixel, no A/B testing, and no session recording. Every asset (CSS, images) is served from rtfm.hr itself; typography uses the fonts already on your device. This site sets no cookies of its own and stores nothing in your browser.
One caveat, stated plainly: rtfm.hr is served through Cloudflare as a reverse proxy and CDN. Cloudflare terminates TLS, which means it processes your IP address and request metadata, and it may set its own security cookie (__cf_bm, a bot-management token that expires in about 30 minutes) to distinguish humans from automated traffic. That cookie is strictly necessary for the security of the service and is not used to profile or advertise to you. See Cloudflare's privacy policy and their cookie reference.
Beyond Cloudflare, no request leaves this domain unless you click an outbound link. Open your browser's network tab and reload — every request should point at rtfm.hr. If one does not, that is a bug; please tell me.
Server logs
The web server records ordinary access logs: IP address, timestamp, requested path, HTTP status, user agent, and referrer. This is standard operation and security practice — it is how abuse, scraping, and outages get diagnosed.
- Purpose: operating and securing the site.
- Legal basis: legitimate interest (GDPR Art. 6(1)(f)) in keeping the service available and defensible.
- Retention: 30 days, then rotated out.
- Not used for: profiling, marketing, or building any picture of you across visits.
Email you send
The contact page is a plain mailto: link — there is no web form, so nothing is submitted to or stored by this site. When you email, that message and its contents live in the company mailbox.
- Purpose: answering you, and running an engagement if one follows.
- Legal basis: steps taken at your request prior to a contract (Art. 6(1)(b)), or legitimate interest in replying to correspondence (Art. 6(1)(f)).
- Retention: for the life of the enquiry or engagement, plus any period Croatian accounting and tax law requires for records relating to paid work. Enquiries that go nowhere are deleted once it is clear they have.
Please do not email credentials, secrets, or production data. If an engagement needs them, we will agree a proper channel first.
Processors
The site is served through Cloudflare, Inc. (reverse proxy, CDN, TLS termination and bot protection) and runs on a virtual server rented from Hetzner Online GmbH in Falkenstein, Germany, which processes the server logs described above as part of hosting. Email for the rtfm.hr domain is handled by Proton AG (Proton Mail) in Geneva, Switzerland.
Hetzner is in the EU. Switzerland holds a European Commission adequacy decision, so mail handled by Proton needs no additional transfer mechanism. Cloudflare is US-headquartered and operates a global edge network, so requests may be handled outside the EEA; Cloudflare relies on the EU Standard Contractual Clauses and the EU–US Data Privacy Framework for those transfers.
Nothing on this site is shared with, or sold to, anyone for advertising or marketing. There is no such data to share.
Hiring me does not mean hosting with me
The above describes this website only. Engagements are a separate matter: where your systems run, who processes what, and under which agreement is decided per engagement and written down before work starts. If an engagement involves me touching personal data, that gets its own data-processing agreement.
Outbound links
This site links to GitHub, LinkedIn, in-a-box-tools.tech, and the engineering blog. Once you follow a link you are on someone else's property under their privacy policy — GitHub and LinkedIn in particular do track you. Nothing is shared with them by this site before you click.
Your rights
Under the GDPR you may request access to, correction of, or erasure of personal data held about you; object to processing based on legitimate interest; and request restriction or portability where applicable. Email the address above and you will get a reply within 30 days.
Realistically, for most visitors there is nothing to request — no account, no profile, no cookie, no identifier. If you have never emailed, the only trace of you is an access-log line that ages out within 30 days.
If you believe your data has been mishandled, you may complain to the Croatian Personal Data Protection Agency (AZOP, azop.hr), or to the supervisory authority where you live.
Changes
If this policy changes materially, the date at the top changes with it. There is no mailing list to notify, because there is no mailing list.