Last updated: 30 September 2026. This policy explains what personal data we collect through this website and through our own business development, why, who processes it for us, and the rights you have under the General Data Protection Regulation (GDPR).
Who runs this site.
Salestruct is a trading name. The business behind it is a sole trader (obrt) registered in Croatia and owned by Toni Medić.
- Operator
- Akvizicija, obrt za usluge, vl. Toni Medić
- Trading name
- Salestruct
- Legal form
- Sole trader (obrt)
- Register
- Obrtni registar, Republic of Croatia
- OIB
- 40929001016
- Owner
- Toni Medić
- Address
- Ulica hrvatskih žrtava 360, Seget Donji, Croatia
- hello@salestruct.com
Who is responsible for your data.
The controller for everything described here is Akvizicija, obrt za usluge, vl. Toni Medić, trading as Salestruct, Ulica hrvatskih žrtava 360, Seget Donji, Croatia, OIB 40929001016. Write to hello@salestruct.com about anything in this policy.
What we collect.
- Diagnostic and contact forms: your name, company, work email and what you write in the message box. With it we send the page you first landed on, the page that referred you and any campaign tags in the link (for example utm_source), so we know which channel brought you.
- Booking a call: after you send the diagnostic form, a booking calendar appears. What you enter there (name, email, chosen time and any notes) goes to the same place as the form.
- Revenue Leak Finder: if you ask for your report, the email address you enter, your company and role if you give them, your answers, the result (your pattern, a score for each area and the number of leaks), whether the address belongs to a free email provider, the referring page and campaign tags, and the time you sent it.
- Quiz step log: while you take the quiz we record which steps are reached (for example started, answered question 3, asked for the report). This log holds no email address and no other personal data.
- Server logs: our hosting provider records technical data such as IP address, browser type and requested pages while serving the site. We don’t use it to identify visitors.
- Business prospect data: for our own outreach we process professional contact details (name, role, company, work email) from public and professional sources.
We don’t use cookies, third-party analytics, advertising pixels or cross-site tracking. The quiz step log above is our only usage record: it is first-party, runs without cookies and contains no personal data. Nothing loads from a third party when you open a page. That only happens when you send a form, use the booking calendar or click a link to another site.
How the Revenue Leak Finder report is made and sent.
- Your browser sends your email, company, role, answers, result and campaign tags to our own automation server (n8n), hosted by OVHcloud in Frankfurt, Germany.
- That server sends only your seven area results to GitHub, which renders your PDF report. No email address, name, company or anything else that identifies you goes to GitHub.
- The finished PDF is stored in the file storage of our GoHighLevel (LeadConnector) account.
- Your contact record (email, company, role, the link to your report, your pattern, your scores and the number of leaks) is written into our GoHighLevel CRM, which sends you the email with your report.
- The step log described above is kept on the same n8n server in Frankfurt.
If sending fails, for example because your connection drops, your browser keeps the submission, including your email address, and tries again the next time you open the quiz. The cookie policy explains exactly what is stored and how to clear it.
Why we’re allowed to use it.
- Answering your message or booking: steps you asked for before a possible contract, Article 6(1)(b) GDPR, and our legitimate interest in replying to people who contact us, Article 6(1)(f).
- Sending the Revenue Leak Finder report you asked for, and at most one follow-up: legitimate interest, Article 6(1)(f), as stated next to the email field. You can opt out at any time.
- Outreach to business prospects: legitimate interest, Article 6(1)(f). We have carried out a Legitimate Interest Assessment for it. We contact people about matters relevant to their role, honour every opt-out and keep a suppression list so opted-out contacts aren’t contacted again.
- Running and securing the site, and the quiz step log: legitimate interest, Article 6(1)(f).
Who processes data for us.
These providers process personal data on our behalf, under our instructions:
- GoHighLevel (LeadConnector): our CRM. It receives the diagnostic and contact forms directly, runs the booking calendar, stores Revenue Leak Finder reports and contact records, and sends our emails, including your report.
- OVHcloud: hosts our n8n automation server in Frankfurt, Germany, which receives Revenue Leak Finder submissions and keeps the quiz step log.
- GitHub: renders the Revenue Leak Finder PDF from your seven area results only. It receives no personal data.
- Netlify: hosts this website and keeps its server logs.
We don’t sell personal data, and we don’t share it with anyone for their own marketing.
Transfers outside the EU.
GoHighLevel and Netlify are based in the United States, so data they process may leave the European Economic Area. Where it does, the transfer is covered by the European Commission’s Standard Contractual Clauses or another recognised transfer mechanism. Our n8n server stays in Germany. GitHub receives no personal data.
How long we keep it.
- We keep contact details and quiz results until you ask us to delete them or for up to 24 months after our last contact, whichever comes first.
- If we sign a contract, the records that belong to it are kept for the length of the contract and for as long as Croatian accounting and tax law requires after it.
- If you opt out, we keep your email address on a suppression list, only so we can keep honouring the opt-out.
- What your browser stores is listed on the cookie policy, with how long each item lasts.
Your rights.
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Have your data erased.
- Restrict processing.
- Object to processing based on legitimate interest, including direct outreach, at any time.
- Receive your data in a portable format.
- Complain to a supervisory authority. In Croatia this is AZOP, the Croatian Personal Data Protection Agency (azop.hr). You can also complain to the authority in your own EU country.
No decisions are made about you automatically.
The Revenue Leak Finder calculates your score from your answers, and that score describes your sales process, not you. Nothing with a legal or similarly significant effect on you is decided by automated processing.
How to make a request.
Email hello@salestruct.com. We reply within one month, as the GDPR requires. If you get an outreach email from us, you can also opt out by replying to it; the opt-out is recorded and kept.