Privacy Policy
Last updated: 29 June 2026
1. Data Controller & Contact Information
The controller of your personal data is:
Zelena Biomasna Energija, elektro in toplotna energija, d.o.o. (“ZBE”, “we”, “us”, “our”)
Trg republike 3, 1000 Ljubljana, Slovenia
Registration No.: 6219543000
Tax No.: SI 29502292
Email: info@miscanthus.eu
Website: https://miscanthus.eu
If you have any questions about how we process your personal data or wish to exercise your data protection rights, please contact us using the details above.
2. Scope & Applicability
This Privacy Policy applies to all personal data collected through the website miscanthus.eu (the “Website”), including all subdomains, landing pages, and any online forms or communication channels accessible through it.
It covers all visitors, prospective clients, business partners, and any other individuals (“you”, “data subjects”) who interact with the Website, regardless of their location. Where local data protection laws impose additional requirements, we comply with those laws to the extent they apply.
This policy does not cover third-party websites or services linked from our Website. We encourage you to review the privacy policies of any external sites before providing your personal data.
This Policy is published in English, Ukrainian, German and French. In the event of any discrepancy between the language versions, the English version prevails.
3. Personal Data We Collect
We collect personal data in two categories: data you provide voluntarily, and data collected automatically when you use the Website.
3.1 Data You Provide Directly
When you interact with the Website — for example by filling in a contact form, sending an inquiry, or requesting a quote — you may provide us with:
- Full name (first and last name)
- Email address
- Phone number
- Company name and position
- Mailing or business address
- The subject and content of your message or inquiry
- Any other information you choose to include in your correspondence
We do not collect or process payment card data, bank account numbers, or any financial payment information through this Website. All commercial transactions are handled outside the Website through standard banking and invoicing procedures.
3.2 Data Collected Automatically
When you visit the Website, certain data is collected automatically through server logs, cookies, and similar technologies. Depending on the category, this may include:
- IP address (which may be anonymized or truncated depending on your cookie preferences)
- Approximate geographic location (city/region level, derived from IP address)
- Browser type, version, and language settings
- Operating system and device type
- Screen resolution and viewport size
- Referring website URL (the page that directed you to our site)
- Pages visited, time spent on each page, and navigation path
- Click patterns, scroll depth, and interaction events
- Date and time of access
Server logs are recorded by our hosting infrastructure on every request and do not depend on your cookie choices. Analytics, behaviour, and marketing data are collected only after you give the relevant consent (see Section 6).
4. How We Collect Your Data
We collect personal data through the following channels:
- Contact and inquiry forms embedded on the Website, where you voluntarily submit your name, email, phone, and message.
- Email correspondence initiated by you via links on the Website.
- Cookies and tracking scripts placed by us and by authorised third-party services, subject to your consent where required.
- Server logs automatically generated by our hosting infrastructure when your browser requests pages from our server.
We do not purchase personal data from third parties, and we do not obtain your data from data brokers or public registries for marketing purposes.
5. Purposes & Legal Bases for Processing
We process your personal data only for specific, explicit, and legitimate purposes. For each purpose we rely on one of the legal bases provided by data protection law:
| Purpose | Legal basis |
|---|---|
| Responding to your inquiries and correspondence | Taking steps at your request before entering into a contract; where no contract is in prospect, our legitimate interest in answering you |
| Providing information about our products and services | Steps taken at your request prior to a contract |
| Website analytics — understanding visitor behaviour and improving content | Your consent, given via the cookie banner before any non-essential tracking is activated |
| Session recordings and heatmaps to identify usability issues | Your consent |
| Ensuring the security and technical functionality of the Website | Our legitimate interest in maintaining a secure web presence |
| Complying with legal obligations (tax, accounting, court orders) | Compliance with a legal obligation to which we are subject |
| Establishing, exercising, or defending legal claims | Our legitimate interest |
Where we rely on legitimate interest, we have weighed our interest against your rights and freedoms to ensure ours does not override yours. You may object to processing based on legitimate interest at any time (see Section 11).
6. Cookies & Tracking Technologies
The Website uses cookies — small text files placed on your device — and similar technologies such as pixels, local storage, and JavaScript-based scripts. We group them as follows:
6.1 Strictly Necessary Cookies
Essential for the basic operation of the Website — page navigation, preserving your cookie consent choices, and session security. They do not require your consent and cannot be disabled without impairing core functionality.
6.2 Analytics Cookies
Used to understand how visitors use the Website, which pages are most popular, and where users encounter problems. They collect aggregated, pseudonymised data such as page views, session duration, bounce rate, and traffic sources. They are activated only after you give consent through the cookie banner. We use Google Analytics 4 (provided by Google Ireland Ltd / Google LLC); GA4 does not store full IP addresses.
6.3 Behaviour & Experience Cookies
Used to improve usability and design by recording interactions such as mouse movement, clicks, scroll activity, and page transitions. Sensitive input fields (such as email and phone fields) are excluded from recordings by default. Activated only with your prior consent. We use Hotjar (provided by Hotjar Ltd, based in Malta, EU).
6.4 Marketing & Remarketing Cookies
Used to deliver relevant advertising and measure campaign effectiveness, and may include tracking pixels from advertising networks. Activated only with your explicit consent. We use the Meta Pixel (Meta Platforms) and Google Ads tags for conversion measurement and remarketing; these cookies may allow us or these advertising partners to show you targeted content on other websites based on your interaction with ours.
6.5 Managing Your Cookie Preferences
On your first visit, a cookie consent banner is presented. You may accept or reject each non-essential category individually. You can change your preferences at any time via the cookie settings link in the Website footer, or by clearing cookies in your browser. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
A detailed, current list of the individual cookies used — including their names, providers, purposes, and durations — is available in the cookie preferences panel accessible from the Website. You may also configure your browser to block or delete cookies; note that disabling certain cookies may affect Website functionality.
7. Third-Party Service Providers
To operate and improve the Website, we engage trusted third-party service providers. Where they process personal data on our behalf, they act as our data processors under a data processing agreement; in some cases they act as independent controllers (for example, certain advertising platforms).
| Service category | Provider | Purpose | Data processed |
|---|---|---|---|
| Web hosting, CDN & security | Cloudflare, Inc. (Cloudflare Pages / Workers) | Hosting the Website, content delivery, DDoS protection, server logs | IP address, access logs, request metadata |
| Web analytics | Google (Google Ireland Ltd / Google LLC) — Google Analytics 4 | Visitor statistics, traffic analysis | Pseudonymised usage data, pages visited, session data, device info |
| UX analytics | Hotjar Ltd (Malta) | Session recordings, heatmaps | Anonymized interaction data, scroll/click patterns, device info |
| Advertising | Meta Platforms (Meta Pixel); Google (Google Ads) | Remarketing, conversion tracking | Cookie identifiers, browsing patterns, approximate location |
We review each provider’s data protection practices and ensure adequate safeguards are in place before sharing any data. A full list of current sub-processors is available on request.
8. Data Sharing & Disclosure
We do not sell, rent, or trade your personal data.
We may share your personal data only in the following limited cases:
- With the service providers described in Section 7, strictly for the purposes set out in this policy and under contractual data protection obligations.
- Within our own organisation, including our Croatian branch (Zelena Biomasna Energija d.o.o. — Podružnica Jablanovec). The branch is part of the same legal entity as ZBE, not a separate company; access is limited to staff who need it for legitimate business operations.
- When required by law — in response to lawful requests by public authorities, including to meet tax, regulatory, or court obligations under applicable Slovenian, Croatian, or EU law.
- To protect rights and safety — where disclosure is necessary to protect the rights, property, or safety of ZBE, its employees, business partners, or the public.
9. International Data Transfers
Your personal data is primarily processed within the European Economic Area (EEA). Some of the providers we use transfer data outside the EEA: Google (Google Analytics, Google Ads) and Cloudflare are based in the United States, and the Meta Pixel involves transfers to Meta Platforms in the United States. Hotjar is provided by Hotjar Ltd, based in Malta, and according to its documentation stores the data it collects on servers within the EEA.
Where such transfers occur, we ensure appropriate safeguards are in place, which may include:
- An adequacy decision by the European Commission for the recipient country (such as the EU–U.S. Data Privacy Framework, where applicable);
- Standard Contractual Clauses approved by the European Commission;
- Binding Corporate Rules where applicable;
- Other legally recognised transfer mechanisms.
You may request information about the specific safeguards applied to international transfers of your data by contacting us at the address in Section 1.
10. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law.
| Data category | Retention period |
|---|---|
| Contact form inquiries | Up to 24 months after the last communication, unless a contractual relationship is established |
| Pre-contractual and contractual correspondence | Duration of the business relationship plus the applicable statutory limitation period |
| Analytics and cookie data | As defined by each cookie’s lifetime, listed in the cookie preferences panel |
| Server logs | Up to 90 days for security and diagnostic purposes |
| Data contained in invoices and accounting records | For the period required by applicable Slovenian accounting and tax legislation |
On expiry of the applicable retention period, your personal data is securely deleted or irreversibly anonymised.
11. Your Rights
As a data subject, you have the following rights in relation to the personal data we hold about you:
- Access — confirmation of whether we process your data and, if so, a copy of it along with information about how it is processed.
- Rectification — correction of inaccurate data or completion of incomplete data.
- Erasure — deletion of your data where there is no compelling reason for its continued processing, subject to legal retention requirements.
- Restriction — limiting how we process your data in certain circumstances, for instance while we verify its accuracy after you contest it.
- Data portability — where processing is based on consent or a contract and carried out by automated means, receiving your data in a structured, commonly used, machine-readable format, and transmitting it to another controller.
- Objection — objecting to processing based on legitimate interest at any time; we will stop unless we demonstrate compelling legitimate grounds that override your interests. You have an absolute right to object to processing for direct marketing.
- Withdrawal of consent — where processing is based on consent, withdrawing it at any time, without affecting the lawfulness of processing carried out beforehand.
- No solely automated decision-making — not being subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. We do not currently engage in such decision-making.
How to exercise your rights. Submit a written request to info@miscanthus.eu or by post to the address in Section 1. We may need to verify your identity before acting. We will respond within one month of receipt. If the request is complex or we receive a high volume of requests, we may extend this by up to two further months and will inform you of the extension and the reasons for it.
Exercising your rights is free of charge. Where requests are manifestly unfounded or excessive — in particular because they are repetitive — we may charge a reasonable administrative fee or decline to act.
Right to lodge a complaint. If you believe our processing of your personal data infringes data protection law, you have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your residence, place of work, or the place of the alleged infringement. Our lead supervisory authority is:
Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia)
Dunajska cesta 22, 1000 Ljubljana, Slovenia
Phone: +386 1 230 97 30
Email: gp.ip@ip-rs.si
Website: www.ip-rs.si
12. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, loss, or destruction. These include, among others:
- SSL/TLS encryption for all data transmitted between your browser and our server (HTTPS)
- Access to personal data restricted on a need-to-know basis among authorised personnel
- Regular updates and security patches for the Website’s software components and dependencies
- Firewalls, intrusion detection, and DDoS mitigation provided by our hosting infrastructure
- Secure configuration of administrative and deployment interfaces
- Contractual data protection obligations on all service providers with access to personal data
While we take all reasonable steps to protect your data, no method of internet transmission or electronic storage is completely secure. In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify you and the competent supervisory authority without undue delay, and within 72 hours where required.
13. Children’s Privacy
This Website is not directed at individuals under the age of 16, and we do not knowingly collect their personal data. If we become aware that we have inadvertently collected data from a child under 16, we will take prompt steps to delete it. If you believe a child has provided personal data through our Website, please contact us immediately.
14. Changes to This Policy
We may update or modify this Privacy Policy at any time to reflect changes in our data processing practices, applicable laws, or regulatory guidance. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, provide a prominent notice on the Website.
We encourage you to review this page periodically. Your continued use of the Website after any modification constitutes acceptance of the updated policy.