Version: 3.0
Last updated: 2 October 2026
Published at: /privacy
Previous version: 2.0 and its jurisdiction pages (superseded in full)
1. Definitions
1.1 Terms not defined here have the meaning given to them by the data protection law that applies to you.
| Term | Meaning |
|---|---|
| T&T, we, us, our | T&T Consulting Business, LLC and Tudor & Tudor, LLC, acting together as joint controllers (Section 2). "T&T" is the trade name of the group. |
| You | Any natural person whose personal data we process: a representative or employee of a client or prospective client, a job applicant, a visitor to the Site, a person who writes to us, or a person whose data a client provides to us. |
| Personal data | Any information relating to an identified or identifiable natural person, including "personal information", "dados pessoais", "datos personales" and equivalent terms in the laws listed in the Annex. |
| Controller and processor | The person that, alone or jointly, determines the purposes and means of the processing; and a person that processes personal data on its behalf. They include the "responsable", "controlador", "responsible party", "encargado", "operador" and "operator" of the laws in the Annex. |
| Client | A business or professional that requests or buys our services. We do not provide services to consumers. |
| Counterparty | A company or natural person with whom a client intends to transact and whom the client asks us to verify. |
| Site | tudorsgroup.com, its language versions, forms, booking pages and site assistant. |
| CRM | Our own client management system, hosted on a server operated by T&T in Croatia. |
| Local model | A language model run by us through the Ollama software on the same server as the CRM, without any connection to an external AI service. |
| GDPR | Regulation (EU) 2016/679 (General Data Protection Regulation). |
| EEA | The European Union together with Iceland, Liechtenstein and Norway. |
| AZOP | Agencija za zaštitu osobnih podataka, the Croatian Personal Data Protection Agency. |
| Special categories of data | The data listed in Article 9(1) GDPR, such as data revealing racial or ethnic origin, political opinions, religious beliefs or trade union membership, and data concerning health or sex life, together with the equivalent "sensitive data" under the laws in the Annex. |
| Annex | The Annex to this Policy, "Country-specific information". |
2. Controllers and joint controllership
2.1 Controllers. T&T Consulting Business, LLC and Tudor & Tudor, LLC, limited liability companies of the State of Florida, United States, both with their registered address at 13575 58th St N, Suite 200, Clearwater, Florida 33760, United States.
2.2 Place of activity. The activity of T&T is directed and managed from Split, Croatia, where decisions on the purposes and means of the processing are taken (Section 22.1).
2.3 Privacy contact. Dinko Anton Tudor, Managing Member, legal@tudorsgroup.com, telephone +1 813 384 8490. This is the single point of contact for every request, question or complaint about this Policy, whichever company it concerns and wherever you are.
2.4 Joint controllership (Article 26 GDPR). The two companies jointly decide why and how the personal data described here is processed, under a written arrangement between the two companies that allocates their responsibilities. Its essence (Article 26(2)) is:
2.4.1 both companies use one Site, one set of forms, one CRM and the same providers, and apply this Policy to all processing;
2.4.2 the contact point in Section 2.3 answers all requests and complaints on behalf of both companies, whichever of them holds the contract with the client, and this Policy gives the information required by Articles 13 and 14 GDPR for both;
2.4.3 both companies apply the same security measures, retention periods and processor contracts, and inform each other without delay of any personal data breach;
2.4.4 T&T Consulting Business, LLC manages the relationship with processors and the notification of breaches, with the support of Tudor & Tudor, LLC;
2.4.5 T&T Consulting Business, LLC contracts with clients, invoices and collects payment for all services, holds the Stripe account, and keeps the accounting and tax records of each engagement.
2.5 Your rights against each controller. You may exercise your rights against each of the two companies, whatever their arrangement says (Article 26(3) GDPR). Where both are involved in the same processing, each is liable for the entire damage (Article 82(4) GDPR).
2.6 Group companies that are not controllers. Tudor Adriatic d.o.o. (Split, Croatia) is not a controller of the processing described in this Policy. It is a group company that sells food and beverage products under its own terms and receives, as a recipient, the Adriatic requests that concern them (Section 9.3).
2.7 Data protection officer. We have not appointed one. Our core activities do not consist of large-scale regular and systematic monitoring of individuals, or of large-scale processing of special categories of data or of data relating to criminal convictions (Article 37(1) GDPR). We will review this if our processing changes. The functions that local laws give to a privacy officer, information officer or person in charge are performed by the privacy contact in Section 2.3.
3. Scope
3.1 This Policy applies to personal data that we process when you visit the Site; send us a form, book a consultation, pay for a service or use the Site assistant; engage or negotiate with us for any of our services (business consulting, due diligence, FDA and US regulatory services, US company and permit services, OFAC services, commodity trade and trade verification, and food and beverage trade); apply through Careers; correspond or meet with us; or when a client gives us data about you as a counterparty, or as an officer, beneficial owner or contact person of a counterparty.
3.2 Business context. Our services are offered only to businesses and professionals, not to consumers. Most of the personal data we process is the business contact data of people who act for a company.
3.3 Exclusions. This Policy does not apply to third-party websites, including those linked from the Site, or to processing that our providers carry out as independent controllers under their own notices (Section 9.2).
3.4 Countries we do not target. T&T does not actively offer its services in the United Kingdom or in Peru. If a person located in either country contacts us on their own initiative, or their data reaches us in the course of an engagement, we apply this Policy to that data and respect every right it describes, in the same way and within the same time limits as for anyone else. This statement describes our commercial activity. It is not a statement about whether the law of those countries applies to us.
4. Structure of this Policy and rule of prevalence
4.1 One policy. This Policy is the single privacy notice of T&T. It is written to the standard of the GDPR and applies to every person, wherever they are. Section 22 adds the information that is specific to our establishment in the European Union. The Annex adds, for Brazil, Colombia, Mexico, Argentina, Chile, Canada, Nigeria, South Africa and Kenya, only what the local law requires and this Policy does not already provide.
4.2 Rule of prevalence. Where this Policy and the Annex differ, or where two laws apply to you, the provision that gives you greater protection prevails: the shorter time limit, the wider right and the stricter condition for a use, disclosure or transfer. If you have links with more than one country (for example, you live in one and your company is established in another), you may rely on any of them. Nothing in this Policy limits a right that cannot be waived under the law applicable to you.
5. Principles we apply
5.1 We apply the principles of Article 5 GDPR to all processing, wherever the data subject is:
5.1.1 Lawfulness, fairness and transparency. Each activity has a legal basis (Sections 6 and 22.4), described before or at collection.
5.1.2 Purpose limitation. We do not use data for an incompatible purpose, for advertising, for marketing profiles, or to train any model.
5.1.3 Data minimisation. Forms ask only for the fields each request needs. Internal notifications carry no names or content. The visit counter records no IP address and no identifier.
5.1.4 Accuracy. We correct data when told it is inaccurate, and record the source and date of each item in a counterparty verification.
5.1.5 Storage limitation. We keep data only for the periods in Section 12.
5.1.6 Integrity and confidentiality. Section 13.
5.1.7 Accountability. We keep a record of processing activities (Article 30 GDPR), of which Section 6 is the public summary, keep records of consent, and document our decisions on each request.
6. Record of processing activities
6.1 Legal bases (Article 6(1) GDPR): (a) consent; (b) contract with you, or steps at your request before a contract; (c) legal obligation under Union or Member State law; (f) legitimate interests, explained in Section 22.4. Where the contract is with your company and not with you, the basis for processing your business contact data is the legitimate interest of both companies in performing that contract (Article 6(1)(f)). The Annex states where a local law requires a different basis, such as prior authorisation.
6.2 Table of processing activities.
| No. | Activity | Categories of data | Source | Purpose | Legal basis (GDPR) | Recipients | Retention |
|---|---|---|---|---|---|---|---|
| A1 | Get started form | First name, last name, company, email, telephone, message, consent checkbox | You | To answer your enquiry and propose a service | Art. 6(1)(b); art. 6(1)(f) where you act for a company (LIA-1) | Cloudflare (R2); CRM; Zoho; local model | 24 months from last contact if no engagement follows |
| A2 | Service request forms (due diligence, FDA, US permits, OFAC, Adriatic) | As A1, plus VAT or tax number, service, request details, attachments (company documents, mandate), up to 26 MB per submission | You | To assess the request, quote and prepare the engagement | As A1 | As A1; Tudor Adriatic d.o.o. for Adriatic requests (Section 9.3) | As A1; if an engagement follows, as A8 |
| A3 | Counterparty due diligence | Name of the counterparty; names, roles and business contact data of its officers, shareholders, beneficial owners or contacts; documents you provide; public register and public source data; sanctions screening result | You (the client); public registers and sources | To carry out the verification you ordered | Art. 6(1)(f) (LIA-2); art. 6(1)(c) where EU sanctions law requires the check (LIA-3) | CRM; Zoho; the client | As A8 |
| A4 | Commodity offers and trade verification | As A1, plus product, volume, Incoterms, origin, target price, frequency, counterparty name, transaction documents | You | To answer a product enquiry or verify a transaction proposed to you | Art. 6(1)(b); art. 6(1)(f) (LIA-2) | As A1 | As A2 |
| A5 | Consultations | Name, email, date, time, time zone, topic; data processed by Google Meet (name shown, real-time audio and video). Consultations are not recorded | You; Google | To book, hold, remind and reschedule consultations under Section C1 of our Terms | Art. 6(1)(b) | Google; Zoho (ZeptoMail); Stripe | As A8 |
| A6 | Payments | Name, email, billing address and country, amount, currency, service, payment status, Stripe reference; card brand, last four digits and expiry as shown by Stripe. We never receive the full card number or security code | You; Stripe | To collect payment, issue receipts and, on request, invoices, refund, and keep accounts | Art. 6(1)(b); art. 6(1)(c) (accounting and tax) | Stripe; professional advisers (Section 9.4) | As A8 |
| A7 | Careers | Name, email, telephone, CV and its contents, message, position | You | To assess your application | Art. 6(1)(b) | CRM; Zoho | 12 months from the close of the selection process, or longer if you agree |
| A8 | Contracts, client files and NCNDAs | Names, roles, signatures, contact and identification data of signatories; engagement content; correspondence; deliverables; invoices | You; your company | To perform the contract, document it and defend legal claims | Art. 6(1)(b), (c) and (f) (LIA-6) | CRM; Zoho; Stripe; professional advisers (Section 9.4); courts or authorities where required | Section 12.2 |
| A9 | Email correspondence | Address, name, signature, content, attachments | You | To answer and keep a record | Art. 6(1)(b) or (f) | Zoho | As the record it belongs to; otherwise 24 months from last contact |
| A10 | Site assistant | Only if you choose to send your question: your name, email, the conversation with the assistant and the page you were on | You | To answer questions the fixed answers do not cover | Art. 6(1)(f) (LIA-1) or (b) | Cloudflare; CRM; Zoho | 24 months from last contact |
| A11 | Visit counter | Daily totals per page, country, network and referring source. No cookies, no IP address, no identifier | Our server, for each page served; your browser, only if you accept "Analytics", to confirm that a person viewed the page | To know which pages are used and to separate people from automated traffic | Art. 6(1)(f) for the transient processing that produces the server totals; art. 6(1)(a) for the browser confirmation; the totals are not personal data | Cloudflare (D1) | 400 days |
| A12 | Consent records | Banner choice, date, version and categories, in your browser (tt-consent); for forms, date, time and Policy version accepted, stored with the submission | Your browser; the form | To respect and demonstrate consent (Article 7(1) GDPR and the Annex) | Art. 6(1)(c) and (f) | None | Banner: 12 months, then we ask again. Forms: with their record |
| A13 | Data subject requests | Requester identity, request, verification data, our answer | You | To answer requests and prove it | Art. 6(1)(c) | Zoho; CRM | 24 months from closing |
| A14 | Sanctions screening and OFAC records | Name, role, company, nationality where shown in an official list; list, date, result, reference; records of transactions subject to US sanctions regulations, of funds blocked or rejected and of reports to OFAC | You; your company; official lists | To avoid dealing with designated persons, perform the OFAC services and keep the records US sanctions regulations require | Art. 6(1)(c) to the extent EU restrictive measures require it; otherwise art. 6(1)(f) (LIA-3) | CRM; OFAC and other authorities where the law requires | 10 years (Section 12.3) |
6.3 Visit counter. Our own counter runs on Cloudflare D1, stores nothing on your device, and cannot recognise a returning visitor. Our server adds each page it serves to daily totals per page, country, network and referring source, without any cookie, IP address or identifier. The script that confirms that a person, and not an automated program, viewed the page runs in your browser only if you accept "Analytics". Details are in our Cookie Policy, Section 6.
6.4 The consent checkbox on our forms. Under the GDPR, the checkbox confirms that you have read this Policy and, where you include data about others, that you may share it with us. It is not the legal basis for answering your request. Where the law applicable to you requires consent or prior authorisation (Annex: Colombia, Mexico, Argentina), ticking the box is how you give it. The box is never pre-ticked, and we keep the date, time and Policy version accepted as proof.
6.5 Data we do not collect. We do not use advertising trackers, social media pixels, third-party analytics or fingerprinting, and do not buy personal data or contact lists.
6.6 Not providing data. Required fields are necessary to answer the request; without them we cannot process it. Providing data is not a statutory requirement (Article 13(2)(e) GDPR).
7. Third-party data, special categories and sanctions screening
7.1 Data you give us about others. When you send us data about another person (for example, a colleague named as contact, or the officers of a counterparty), you confirm that you may disclose it for the purpose of the request and that you have informed that person or obtained their authorisation where your own law requires it.
7.2 Counterparty data. We obtain data about a counterparty's representatives from the client and from public sources: company registers, official sanctions lists, publicly accessible court and insolvency registers, and the counterparty's own website and documents. We use it only for the report the client ordered, record the source and date of each item, and share the report only with that client, under confidentiality. Section 22.5 explains how we inform the people concerned.
7.3 Special categories of data. We do not ask for them. Please do not include them in messages, documents or CVs. If we receive them, we do not use them, and we delete them or, where they are part of a document we must keep, restrict access. If a service ever requires them, we will tell you in advance and process them only with your explicit consent or another condition of Article 9(2) GDPR and of the law applicable to you.
7.4 Sanctions screening.
7.4.1 What we do. Sanctions screening is part of our due diligence services and of our acceptance of clients (Terms, Section B7). We check the names of a client, a counterparty and their officers and beneficial owners against the sanctions lists administered by the US Office of Foreign Assets Control (the Specially Designated Nationals and Blocked Persons List and its other consolidated sanctions lists), the United Nations Security Council Consolidated List and the EU restrictive measures (the EU consolidated list of persons, groups and entities subject to financial sanctions).
7.4.2 Limits (Article 10 GDPR). We do not request criminal record certificates and do not record criminal convictions or offences in any file or report, because no Union or Croatian law authorises us, as a private company, to process them for this purpose (Article 10 GDPR). A sanctions designation is not a conviction: we record only the fact of the designation, the list, the date and the reference. A possible match is checked by a person against further identifiers, and a report states when a match is unconfirmed. No decision is taken on a screening result alone.
7.4.3 Your right to explain. If you are reported as a possible match, you may send us information showing that you are not the listed person, and we will correct our record.
8. Automated processing and the local model
8.1 What the local model does. A language model runs, through Ollama, on our own server in Croatia, which also hosts the CRM. For each new request it does two things only: it assigns a category from a closed list (for requests to buy a service: request, out of scope, spam, test or uncertain; for other messages: commercial, press, supplier, spam, other or uncertain), and writes a one-line summary for our team. For requests to buy a service it also flags, quoting the words concerned, any of seven warning signs of trade fraud defined in our own verification protocol (for example, a demand for proof of funds before any verification), each with a fixed weight set by the protocol and not by the model. When a counterparty uploads documents to a due diligence file, the model extracts the company and person names they contain so that a person can check that they match the file.
8.2 What it does not do. It does not score, rank, accept, reject or price requests, reply to you, contact anyone, search the internet, screen sanctions, evaluate personal aspects, or decide anything about you. A person reads every request in full and takes every decision.
8.3 No solely automated decisions. We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR and the equivalent provisions in the Annex). If this ever changes, we will tell you before the decision and give you the right to human review.
8.4 No external AI and no training. Your data is not sent to any external AI provider through this process and is not used to train, fine-tune or improve any model. The category and summary are stored with the request and deleted with it.
8.5 Applications. Applications received through Careers are not processed by the model. Only a person reads them.
8.6 Objection. You may object to the classification (Section 15.1.6), and we will then handle your request without the model.
8.7 Site assistant. The "Ask a question" assistant uses no AI model. It matches what you type against a fixed set of questions and answers in your browser. Nothing is sent to us unless you choose to send your question. If you do, we receive your name, email, the conversation and the page you were on.
8.8 Orchestration. The n8n software, on the same server, moves requests between storage, the CRM and the model. It sends no request data outside our infrastructure, except the emails and content-free notifications described here.
9. Recipients
9.1 Processors. Each provider acts only for the function stated, under its standard data processing terms, which meet Article 28 GDPR.
| Provider | Function | Data | Location |
|---|---|---|---|
| Cloudflare, Inc. (United States) | Site hosting (Workers); our form handler, which runs on Cloudflare Workers at a workers.dev address operated by us; storage of submissions and attachments (R2); counter totals (D1); network security | IP address and technical data of each visit (processed by Cloudflare to deliver and protect the Site; we do not receive it); form content; counter totals | Global network; submissions (R2) and counter totals (D1) are stored in Cloudflare's Eastern Europe location, which is a location hint and not a contractual guarantee of storage in the European Union |
| Zoho Corporation (United States): ZeptoMail and Zoho Mail | Transactional email and our mailbox | Name, email, messages, attachments | Zoho's United States data centre |
| Google Meet, under our Google Workspace business account and Google's Cloud Data Processing Addendum | Video consultations, not recorded | Participants' name and email, real-time audio and video, metadata | Google's global infrastructure |
| Telegram | Internal alerts that a request has arrived | No name and no content; only the fact of arrival and an internal link | Receives no requester data |
9.2 Stripe. Payments are made through Stripe. On the consultation booking page, once you choose a time, the Site loads Stripe's payment form from Stripe (js.stripe.com) so that you can pay without leaving the page; other payments are made on Stripe Checkout, a page hosted by Stripe. In both cases you enter your card details in Stripe's own fields, and they never pass through our systems. When Stripe's payment form loads, Stripe receives your IP address and data about your device and may set its own cookies to prevent fraud (Section 20.1.1). Stripe acts partly as our processor and partly as an independent controller for fraud prevention and financial regulation, under https://stripe.com/privacy. The Stripe account is held by T&T Consulting Business, LLC with Stripe, Inc. (United States).
9.3 Tudor Adriatic d.o.o. Food and beverage products are sold by Tudor Adriatic d.o.o. (Split, Croatia), a group company, under its own terms of sale. We disclose Adriatic requests to it so that it can answer you and, if you agree, sell you the products. It receives them as a recipient and processes them as a separate controller.
9.4 Other recipients. The client who ordered a report (counterparty data only); where an engagement requires activities that may only be performed by a licensed professional, the duly licensed investigator or law firm engaged for that engagement, bound by confidentiality and, where they act on our behalf, by a data processing agreement; professional advisers, such as accountants or lawyers, where we engage them, under confidentiality; courts, authorities and regulators, including OFAC, where the law requires it or for legal claims; and a buyer or successor of our business, under confidentiality, if such a transaction takes place.
9.5 Our own infrastructure. The CRM, the model and n8n run on a server owned and operated by T&T in Croatia. No hosting provider has access to it. We update this Section before a new provider starts processing personal data.
10. How a request flows through our systems
10.1 The Site, on Cloudflare Workers, receives your form and stores it with its attachments in Cloudflare R2.
10.2 The submission is copied to the CRM on our server in Croatia, reachable only from our internal network. The copy in our cloud storage is deleted at the end of the retention period that applies to the record (Section 12), by the same daily deletion process that applies to the CRM.
10.3 The local model classifies and summarises it; a person then reads it in full.
10.4 Our team receives a Telegram alert with no name and no content.
10.5 We reply from our Zoho mailbox; automatic confirmations go through ZeptoMail.
11. International transfers
11.1 Your data is processed in Croatia (our server and establishment), in the United States (seat of the controllers and of most providers) and in other countries where our providers operate (Section 9.1).
11.2 We transfer personal data out of the country of collection only on a mechanism recognised by the law that governs the transfer: adequacy, standard or model contractual clauses, a contract with you or concluded in your interest, or your consent where the law requires it. Section 22.7 covers data from the EEA. The Annex states specific local mechanisms, such as the ANPD standard clauses (Brazil) or a privacy impact assessment (Quebec).
11.3 While abroad, your data is subject to the laws of the country where it is held, including access by its courts and authorities.
11.4 You may ask for a copy of the safeguards at legal@tudorsgroup.com. We may redact commercially confidential terms.
12. Retention
12.1 Criteria. We keep data while needed for its purpose, then for any period required by law, then for the period in which legal claims may be brought, and then delete it or make it irreversibly anonymous. Where a local law requires blocking before deletion (Annex), we block it for the period that law sets.
12.2 Periods.
| Data | Period | Starting point |
|---|---|---|
| Requests that do not lead to an engagement (A1, A2, A4, A10) | 24 months | Last contact |
| Applications (A7) | 12 months, or longer if you agree | Close of the selection process |
| Client files, contracts, NCNDAs, deliverables, invoices and counterparty data in them (A3, A5, A6, A8) | The statutory accounting and tax period that applies to T&T Consulting Business, LLC or, if longer, the limitation period for contractual claims (five years for an action on a written contract under Florida law, Fla. Stat. §95.11(2)(b)) | End of the engagement or of the financial year in which it ends |
| Sanctions screening results, OFAC service files, records of transactions subject to US sanctions regulations, of funds blocked or rejected and of reports to OFAC (A14) | 10 years (31 C.F.R. §501.601) | Date of the transaction or, for blocked property, the date it is unblocked |
| Correspondence (A9) | As the record it belongs to | As that record |
| Visit counter totals (A11) | 400 days | Day counted |
| Banner choice (A12) | 12 months, then we ask again, or earlier if you change it or clear your browser | Your choice |
| Data subject requests (A13) | 24 months | Closing of the request |
12.3 OFAC records. As US companies, the controllers must keep a full and accurate record of each transaction subject to the regulations administered by the Office of Foreign Assets Control, available for examination for at least 10 years (31 C.F.R. §501.601). This is not a Union or Member State obligation, so under the GDPR we keep these records on the basis of our legitimate interest in complying with the law that governs the controllers (Article 6(1)(f); LIA-3). We keep only what that rule requires, restrict access to it and use it for no other purpose.
12.4 Providers and legal hold. Providers delete data under their data processing terms. We may keep data longer only while needed to comply with a legal obligation or an order, or for a legal claim that has arisen.
13. Security
13.1 Under Article 32 GDPR we apply measures appropriate to the risk:
13.1.1 the CRM, the model and n8n are reachable only from our internal network, not from the public internet;
13.1.2 data is encrypted in transit between your browser, the Site, our systems and our providers;
13.1.3 access is limited to the people who need it, under a duty of confidentiality;
13.1.4 card details are entered only in Stripe's payment form or on Stripe Checkout and never pass through our systems;
13.1.5 internal notifications carry no names or content, and requests are analysed only on our own server;
13.1.6 each submission is limited to 26 MB of attachments;
13.1.7 data in cloud storage is encrypted at rest by our provider; our own server is reachable only from our internal network, and access to the CRM requires an individual account and password; backups are taken daily and kept on our own server, in Croatia;
13.1.8 a daily process deletes each record when its retention period ends (Section 12), except records that the law requires us to keep longer.
13.2 No system is completely secure. For particularly confidential documents, ask us for an alternative channel before sending them.
14. Personal data breaches
14.1 We assess and record every incident that could affect personal data, its effects and the measures taken, whether or not we notify it (Article 33(5) GDPR).
14.2 Where a breach is likely to result in a risk to individuals, we notify AZOP without undue delay and, where feasible, within 72 hours (Article 33(1) GDPR), and the authority of any country in the Annex whose residents are affected, within the time its law sets if shorter.
14.3 Where the risk to you is high, we tell you without undue delay, in clear language, what happened, its likely consequences, what we have done and what you can do (Article 34 GDPR). Where a US state law applies, we meet its time limit (for Florida residents, no later than 30 days after determining the breach, under section 501.171 of the Florida Statutes).
15. Your rights
15.1 Rights available to everyone. Wherever you are, you may ask us:
15.1.1 to confirm whether we process your data and give you access and a copy, with the purposes, recipients, retention period and source (Article 15 GDPR);
15.1.2 to correct or complete your data (Article 16);
15.1.3 to erase it where there is no longer a reason to keep it (Article 17);
15.1.4 to restrict its processing, for example while a dispute about accuracy is resolved (Article 18), and to inform recipients of any correction, erasure or restriction (Article 19);
15.1.5 to receive the data you provided in a structured, commonly used, machine-readable format, or have it sent to another controller, where processing is based on consent or contract and automated (Article 20);
15.1.6 to stop processing based on our legitimate interests, including the classification by the local model, unless we show compelling legitimate grounds or need the data for legal claims (Article 21(1));
15.1.7 to stop any use of your data for direct marketing, at any time (Article 21(2) and (3));
15.1.8 to withdraw consent at any time, without affecting earlier processing (Article 7(3)), through "Cookie settings" in the footer or by writing to us;
15.1.9 to obtain human intervention and contest a decision, if one were ever based solely on automated processing (Article 22(3)).
15.2 Rights added by local law. The Annex lists them, such as information on the entities with which we shared data (Brazil), proof of authorisation (Colombia), limitation of use or disclosure (Mexico) and de-indexation (Quebec).
15.3 How to make a request. Write to legal@tudorsgroup.com stating what you are asking for. No form is required. You may write in English, Spanish, Croatian or Portuguese.
15.4 Identity verification. We verify the requester's identity with the least data possible: normally, that you write from the email address we hold or confirm details of your request. We ask for an identity document only where we cannot verify you otherwise or your law provides for it, and delete it once verified.
15.5 Representatives. You may act through a person you authorise, a legal representative, an heir where the law allows, or an authorised agent under US state law. We will ask for proof of authority and may verify your identity directly.
15.6 Time limits. For every request, wherever you are:
15.6.1 we acknowledge receipt within 7 days;
15.6.2 we give a substantive answer within the shortest period set by the law applicable to you, and never later than 30 days after receipt;
15.6.3 where a law allows an extension, we use it only if the total stays within 30 days of receipt, and tell you, with reasons, before the original period ends;
15.6.4 where we grant a request, we give effect to it with the answer or, where that is not possible, tell you the date on which it will take effect, within the period your law allows;
15.6.5 the shorter periods by country are in the Annex (for example, access in 10 days in Argentina, 15 days in Brazil and 7 days in Kenya). Where a law counts business days, we count them in the country whose law applies;
15.6.6 for residents of the United States, the time limits of our US Privacy Notice apply: acknowledgement within 10 business days (we aim for 7 days), answer within 45 days and decision on an appeal within 45 days. Where another law in this Policy also applies to the same request, the shorter period prevails (Section 4.2).
15.7 Free of charge. Exercising your rights is free. Where a request is manifestly unfounded or excessive, in particular repetitive, we may charge a reasonable fee or refuse to act, explaining why (Article 12(5) GDPR), only as far as your law allows.
15.8 Refusals and limits. If we do not act on a request, we tell you why within the time limit and that you may complain to an authority and seek a judicial remedy (Article 12(4) GDPR). Rights may be limited where we must keep data by law, such as accounting or OFAC records, or for legal claims, or where disclosure would harm the rights of others (Article 15(4)), such as the client who ordered a report.
15.9 Complaints. You may complain to us at legal@tudorsgroup.com ("Data protection complaint" in the subject), within the same time limits as requests. This is optional, except where a local law makes it a precondition (Annex: Colombia). You may also complain to the authority of the country where you live, work or where the infringement took place (Article 77 GDPR and the Annex).
16. Non-discrimination
16.1 We will not deny you a service, charge a different price, provide a different quality or otherwise treat you less favourably because you exercised a privacy right.
17. No sale and no advertising
17.1 We do not sell personal data, and have not sold it in the preceding 12 months. We do not share it for cross-context behavioural advertising or use it for targeted advertising.
17.2 If your browser sends the Global Privacy Control signal, the Site treats it as a refusal of every optional category in the consent banner.
18. Children
18.1 Our services are for businesses and professionals. We do not offer them to anyone under 18 or knowingly collect their data. If we learn that we have, we delete it unless the law requires us to keep it.
19. Commercial communications
19.1 We do not send commercial communications by electronic means without your prior consent. Confirmations, reminders, replies, invoices and service notices about a request or engagement you started are not commercial communications.
19.2 If you consent, every message will identify T&T and include a simple way to unsubscribe at no cost.
19.3 At the date of this Policy we do not operate a newsletter or mailing list.
20. Data in your browser
20.1 We do not set cookies of our own.
| Name | Type | Purpose | Category | Duration |
|---|---|---|---|---|
tt-consent | localStorage | Your choice, its date and the banner version | Strictly necessary | 12 months, then we ask again; earlier if changed or cleared |
20.1.1 Stripe. On the consultation booking page, once you choose a time, Stripe's payment form may set Stripe's own cookies (such as __stripe_mid and __stripe_sid) to prevent fraud. They are strictly necessary for the payment you request. Details are in our Cookie Policy.
20.2 Consent banner. Before any optional technology runs, including the browser confirmation of the visit counter, a banner asks for your choice. "Reject all" is as visible as "Accept all"; access does not depend on accepting; optional categories (analytics, and marketing, which is empty) are off by default; you can change your choice in "Cookie settings" in the footer; and we keep a record of your choice. Details are in our Cookie Policy, linked in the footer of every page.
21. Links to third-party sites
21.1 Third-party sites linked from the Site are governed by their own privacy notices. We are not responsible for them.
22. European Union and European Economic Area
22.1 Establishment. The activity of T&T is directed and managed from Split, Croatia, where decisions on the purposes and means of processing are taken. This is our establishment in the Union, so the GDPR applies to our processing in full under Article 3(1), wherever the data is stored, and our main establishment under Article 4(16). The Croatian Act on the Implementation of the GDPR (Narodne novine 42/2018) also applies.
22.2 Lead authority and one-stop shop. AZOP is our lead supervisory authority for cross-border processing (Article 56(1) GDPR) and cooperates with the other authorities concerned under Article 60. You may still complain to the authority of your habitual residence, place of work or place of the alleged infringement (Article 77(1)), which will handle the complaint with AZOP.
22.3 Representative. Article 27 GDPR requires a representative only from controllers not established in the Union. As we are established in Croatia, we have not designated one.
22.4 Legitimate interests (Article 13(1)(d)). Before relying on Article 6(1)(f), we assessed purpose, necessity and balance, following EDPB Guidelines 1/2024. You may request the full assessments at legal@tudorsgroup.com. In summary:
22.4.1 LIA-1: representatives of business clients. Answering and serving businesses requires the business contact data of the person who acts for them, given in a professional capacity, which that person expects us to use.
22.4.2 LIA-2: counterparty due diligence and fraud prevention. The client, and we, need to know whether a counterparty exists, who controls it and whether its signatory has authority before a transaction. Recital 47 GDPR recognises fraud prevention as a legitimate interest, and international commodity and food trade has a documented incidence of fraud, such as offers requiring advance payments (T&T never requests advance payments to open a transaction). The people concerned act in a business capacity; data comes mainly from public sources; no special category data is processed; the report goes only to the client under confidentiality; and the safeguards in Sections 7.2 and 22.5 apply.
22.4.3 LIA-3: sanctions screening and OFAC records. The interest is not making funds available to designated persons, not exposing clients, banks or ourselves to sanctions risk, and keeping the records US sanctions regulations require of the controllers. EU restrictive measures, such as Council Regulations (EU) No 269/2014 and No 833/2014, apply to our activity from Croatia, and prohibit making funds or economic resources available to designated persons; to the extent that compliance with those prohibitions requires a check, Article 6(1)(c) applies. US law is not Union or Member State law (Article 6(3)), so screening against US lists and OFAC recordkeeping rely on Article 6(1)(f). Lists are public; screening is limited to the persons relevant to the transaction; matches are reviewed by a person; records are access-restricted.
22.4.4 LIA-4: local language model. Classifying and summarising requests on our own server lets us route them promptly. The model decides nothing, a person reads every request, no data is used for training, the summary is deleted with the request, and you may object.
22.4.5 LIA-5: security. Protecting the Site and our systems against attacks and abuse (Recital 49) requires transient processing of technical data such as IP addresses, without profiling.
22.4.6 LIA-6: legal claims and records. Correspondence and files are the evidence of what was requested, agreed and delivered; access is restricted and retention follows limitation periods.
22.5 Data not obtained from you (Article 14). We give the representatives of a counterparty the information in Article 14(1) and (2) within a reasonable period and at the latest within one month, or at our first communication with them. Where informing them before a verification is completed would render impossible or seriously impair its purpose, we rely on Article 14(5)(b) GDPR, as interpreted in the Article 29 Working Party Guidelines on transparency (WP260 rev.01), endorsed by the EDPB, and record the reasons in each case. In that case we make this Policy public, limit the data to what the verification needs, record sources, restrict access, apply Section 12, and answer anyone who asks whether we hold data about them, subject only to legal restrictions.
22.6 Automated decisions (Article 22). No decision based solely on automated processing produces legal or similarly significant effects for you, so Article 22(1) does not apply (Section 8). You may still object to the classification under Article 21.
22.7 Transfers from the EEA (Chapter V).
22.7.1 Within the controllers. Access by the two US companies to data held in Croatia is processing by the same controllers to which the GDPR applies in full (Article 3(1)). We nevertheless apply to it the safeguards of Sections 22.7.2 and 22.7.3, taking into account the risks of processing outside the EEA, as EDPB Guidelines 05/2021 recommend.
22.7.2 Adequacy (Article 45). For US recipients certified under the EU-US Data Privacy Framework, we rely on Commission Implementing Decision (EU) 2023/1795 of 10 July 2023, and we check each recipient's certification on the official Data Privacy Framework list before relying on it. The General Court upheld the decision on 3 September 2025 (Case T-553/23, Latombe v Commission); an appeal against that judgment is pending before the Court of Justice (Case C-703/25 P). For a recipient that is not certified, or if the decision ceases to apply, Section 22.7.3 applies.
22.7.3 Standard contractual clauses (Article 46(2)(c)). Otherwise, we rely on the clauses of Commission Implementing Decision (EU) 2021/914, with a transfer impact assessment that considers US Executive Order 14086 and the Data Protection Review Court. Our supplementary measures are encryption in transit, minimisation, and keeping request content, the CRM and the model on our own server in Croatia.
22.7.4 Derogations (Article 49). Only for occasional transfers necessary for a contract with you or in your interest, such as sending a report to a client outside the EEA.
22.8 Storage on your device. Storing or reading information on your device, including localStorage and sessionStorage, requires prior consent unless strictly necessary for a service you requested (Article 5(3) of Directive 2002/58/EC; EDPB Guidelines 2/2023; in Croatia, Article 43(4) of the Electronic Communications Act, Narodne novine 76/2022, enforced by AZOP). Section 20 describes how we apply it.
22.9 Remedies. You have the right to a judicial remedy against an authority (Article 78) and against us or a processor (Article 79), before the courts of Croatia or of the Member State of your habitual residence; to mandate a not-for-profit body (Article 80); and to compensation for material or non-material damage (Article 82).
22.10 AZOP. Ulica Metela Ožegovića 16, 10000 Zagreb, Croatia; https://azop.hr; azop@azop.hr; +385 1 4609 000. The authorities of the other EU and EEA States are listed at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en.
23. Changes, versions and language
23.1 The version number and effective date at the top identify the version in force.
23.2 Before a change that materially affects how we process your data takes effect, we tell clients and applicants with an open matter by email; if it affects the banner categories, we ask for your choice again; and if a local law requires new consent or authorisation for a new purpose, we ask for it first.
23.3 We keep previous versions and provide them on request.
23.4 This Policy is published in English, Spanish, Portuguese (Brazil), Italian and German, and every version is intended to say the same. If you find a difference between versions, tell us: we will correct it and, meanwhile, apply the version that is more favourable to you (Section 4.2).
24. Contact and authorities
24.1 Contact. Dinko Anton Tudor, Managing Member, T&T, 13575 58th St N, Suite 200, Clearwater, Florida 33760, United States; legal@tudorsgroup.com; telephone +1 813 384 8490.
24.2 Authorities. Croatia (lead): AZOP, https://azop.hr. Other EU and EEA States: see Section 22.10. United States: Federal Trade Commission, https://www.ftc.gov; California Privacy Protection Agency (CalPrivacy), https://privacy.ca.gov; Office of the Attorney General of Florida, https://www.myfloridalegal.com. US residents: see also our US Privacy Notice. Other countries: see the Annex.
Annex: Country-specific information
This Annex adds only what each local law requires and the Policy does not already provide. Section 4.2 (prevalence) and Section 15.6 (acknowledgement in 7 days; answer in the shortest legal period and never later than 30 days) apply to every country.
Table A1. Authorities, shorter time limits and breach notification
| Country and law | Authority | Our time limit for a substantive answer | Breach notification |
|---|---|---|---|
| Brazil. Lei nº 13.709/2018 (LGPD) | Agência Nacional de Proteção de Dados (ANPD), https://www.gov.br/anpd | Confirmation or access: immediately in simplified form, or 15 days by complete statement (art. 19). Other rights (art. 18): 15 days where possible, never more than 30 | ANPD and data subjects within 3 business days of knowing the incident affected personal data, where it may cause relevant risk or damage (art. 48; Resolution CD/ANPD nº 15/2024) |
| Colombia. Ley Estatutaria 1581 de 2012; Decreto 1074 de 2015 | Superintendencia de Industria y Comercio (SIC), https://www.sic.gov.co | Consultas: 10 business days + up to 5 (art. 14). Reclamos: 15 business days + up to 8 (art. 15). Extensions capped by Section 15.6.3 | SIC, within 15 business days of detection, through the SIC's online channel (art. 17(n); Circular Única of the SIC, Title V) |
| Mexico. LFPDPPP (DOF 20 March 2025) | Secretaría Anticorrupción y Buen Gobierno, https://www.gob.mx/buengobierno | ARCO: determination in 20 days; if granted, effective within 15 days after it (art. 31) | Data subjects immediately where their property or moral rights are significantly affected (art. 19) |
| Argentina. Ley 25.326 | Agencia de Acceso a la Información Pública (AAIP), https://www.argentina.gob.ar/aaip | Access: 10 calendar days (art. 14). Rectification, updating, deletion: 5 business days (art. 16) | Internal incident record (Resolution AAIP 47/2018) |
| Chile. Ley 19.628 as amended by Ley 21.719 (in force 1 December 2026) | Agencia de Protección de Datos Personales, created by Ley 21.719, through the channels it publishes | From 1 December 2026: law allows 30 calendar days + 30; we answer within 30 (art. 11). Until 30 November 2026: 2 business days (art. 16, earlier text) | Agency without undue delay where there is a reasonable risk; data subjects where the law requires (art. 14 sexies) |
| Canada. PIPEDA; in Quebec, CQLR c. P-39.1 | Office of the Privacy Commissioner (OPC), https://www.priv.gc.ca; in Quebec, Commission d'accès à l'information (CAI), https://www.cai.gouv.qc.ca | 30 days (PIPEDA s. 8(3); Quebec Act s. 32); we do not use the s. 8(4) extension | OPC and you as soon as feasible where there is a real risk of significant harm (s. 10.1); CAI and the persons concerned promptly where there is a risk of serious injury (Quebec Act ss. 3.5 to 3.8) |
| Nigeria. Nigeria Data Protection Act 2023; GAID 2025 | Nigeria Data Protection Commission (NDPC), https://ndpc.gov.ng | 30 days | NDPC within 72 hours; you immediately where the risk is high (s. 40) |
| South Africa. POPIA (Act 4 of 2013) | Information Regulator, https://inforegulator.org.za | Within a reasonable time (s. 23), never more than 30 days | Information Regulator through its eServices portal, and you, as soon as reasonably possible (s. 22) |
| Kenya. Data Protection Act 2019; General Regulations 2021 | Office of the Data Protection Commissioner (ODPC), https://www.odpc.go.ke | Access: 7 days (reg. 9). Restriction, objection, rectification, erasure: 14 days (regs. 7, 8, 10, 12). Portability: 30 days (reg. 11) | Data Commissioner within 72 hours where there is a real risk of harm; you within a reasonable period (s. 43) |
Brazil (LGPD)
B.1 Application. The LGPD applies where we offer services to individuals in Brazil or collect data there (art. 3).
B.2 Encarregado (art. 41). We have voluntarily appointed Dinko Anton Tudor as our encarregado (Resolution CD/ANPD nº 18/2024), contactable at legal@tudorsgroup.com. You may write in Portuguese and we will answer in Portuguese.
B.3 Additional rights (art. 18). Information on the public and private entities with which we shared your data (VII) and on the possibility of not consenting and its consequences (VIII); petition to the ANPD (§1); exercise before consumer protection bodies where applicable (§8).
B.4 Legal bases (art. 7). Requests and contracts: V. Accounting and tax: II. Legal claims: VI. Counterparty verification, site assistant, local model and security: legitimate interest, IX, with a summary of the assessment on request (art. 10, §2). Visit counter: consent, I.
B.5 Transfers. Collection through the Site is international collection (Resolution CD/ANPD nº 19/2024, art. 6). Onward transfers to Croatia rely on the ANPD adequacy decision for the European Union, Resolution CD/ANPD nº 32/2026 (art. 33, I); to the United States and elsewhere, on the ANPD standard contractual clauses (Annex II of Resolution 19/2024), adopted unaltered (art. 33, II, b). On request we give the destinations, importers and purposes in Portuguese, and the text of the clauses within 15 days.
B.6 Incidents. We keep a record of every security incident for at least five years (Resolution 15/2024, art. 10).
B.7 Language. The Portuguese version is addressed to data subjects in Brazil; if it differs from the English text, the interpretation more favourable to the data subject applies.
Colombia (Ley 1581 de 2012)
C.1 Política de Tratamiento. For data subjects in Colombia, this Policy and this Annex are our Política de Tratamiento de la Información (art. 17(k), Ley 1581; art. 2.2.2.25.3.1, Decreto 1074). Telephone: +1 813 384 8490. Area responsible for consultas and reclamos: the privacy contact in Section 2.3.
C.2 Authorisation. Processing requires your prior, express and informed authorisation (art. 9), given through the form checkbox (Section 6.4), of which we keep proof (art. 17(b)). Legitimate interest is not a basis under Ley 1581. No authorisation is needed in the cases of art. 10, including data of a public nature (art. 10(b)), which covers public register and sanctions list data on counterparties; other counterparty data is processed only where the client declares that it may disclose it. Answers about sensitive data are optional (art. 12(b)).
C.3 Rights (art. 8). You may request proof of your authorisation and information on the use of your data, and revoke authorisation or request deletion where no legal or contractual duty requires us to keep the data. Access is free at least once every calendar month and whenever this Policy changes substantially.
C.4 Procedure. Write to legal@tudorsgroup.com, subject "Habeas data", with your name and identification, your request, an address for the answer and supporting documents. If a reclamo is incomplete, we ask you within 5 days to complete it; after 2 months without reply it is deemed withdrawn. Within 2 business days of a complete reclamo we mark the record "reclamo en trámite" until it is decided (art. 15).
C.5 Prior requirement. You may complain to the SIC only after completing the consulta or reclamo procedure with us (art. 16).
C.6 Transfers. The United States and Croatia are on the SIC list of adequate countries (Circular Externa 005 de 2017). Providers act under transmission contracts (art. 2.2.2.25.5.2, Decreto 1074).
Mexico (LFPDPPP 2025)
M.1 Aviso de privacidad integral. For data subjects in Mexico, this Policy and this Annex are our aviso de privacidad integral.
M.2 Purposes. Necessary purposes, which give rise to the legal relationship: activities A1 to A10, A13 and A14. Non-necessary purpose: the visit counter (A11), which you may refuse by not enabling "Analytics" or disabling it in "Cookie settings", without affecting the necessary purposes.
M.3 Consent. The checkbox gives express consent, including for financial or property data (A6). You may revoke it through the ARCO procedure, without retroactive effect, unless processing is needed for the legal relationship or a legal obligation.
M.4 ARCO. Write to legal@tudorsgroup.com, subject "Derechos ARCO", with your name, a means of reply, proof of identity or representation, the data and right concerned and, for rectification, the changes. If it is incomplete, we ask you within 5 days to complete it. Access is given by electronic copy.
M.5 Limiting use or disclosure. Write to us with the subject "Limitación de uso".
M.6 Transfers. We make no transfer that requires your consent. Transfers between the two controllers and to Tudor Adriatic d.o.o., a group company, rely on the exceptions of the LFPDPPP for companies under common control and for transfers needed for a contract concluded in your interest.
M.7 Tracking technologies. The Site uses no cookies of its own, web beacons or technologies that monitor your behaviour (Section 20).
M.8 Protection of rights. If we do not answer or you disagree, you may apply to the Secretaría Anticorrupción y Buen Gobierno within 15 days of the date on which our answer is communicated to you or of the expiry of the period to give it (art. 40).
Argentina (Ley 25.326)
AR.1 Scope. The law also protects data of legal persons; we apply this Policy to it as the law provides.
AR.2 Consent. The checkbox gives free, express and informed consent (art. 5). It is not required for data from sources of unrestricted public access or needed for a contractual or professional relationship (art. 5(2)).
AR.3 Transfers. Croatia is adequate (Disposición DNPDP 60/2016). Transfers to the United States rely on the model clauses of Disposición 60/2016 or Resolución AAIP 198/2023, or on your express consent (art. 12).
AR.4 Required statements.
El titular de los datos personales tiene la facultad de ejercer el derecho de acceso a los mismos en forma gratuita a intervalos no inferiores a seis meses, salvo que se acredite un interés legítimo al efecto conforme lo establecido en el artículo 14, inciso 3 de la Ley N° 25.326.
LA AGENCIA DE ACCESO A LA INFORMACIÓN PÚBLICA, en su carácter de Órgano de Control de la Ley N° 25.326, tiene la atribución de atender las denuncias y reclamos que interpongan quienes resulten afectados en sus derechos por incumplimiento de las normas vigentes en materia de protección de datos personales.
AR.5 Remedies. If the periods expire without a satisfactory answer, you may bring the hábeas data action (art. 33 and following) or complain to the AAIP.
Chile (Ley 21.719)
CL.1 Application. From 1 December 2026 the law applies to controllers not established in Chile whose processing aims to offer services to people in Chile (art. 1 bis).
CL.2 Rights. In addition to Section 15: temporary blocking while a request for rectification, deletion or objection is decided (art. 8 ter). Subject line: "Derechos Ley 21.719".
CL.3 Complaint. If we refuse or do not answer in time, you may complain to the Agency within 30 business days (arts. 11 and 41).
CL.4 Contact for data subjects and the Agency. As controllers without domicile in Chile, we designate legal@tudorsgroup.com as the electronic address for communications from data subjects and the Agency, and keep it operational, as Ley 19.628, as amended, requires.
Canada (PIPEDA and the Quebec Act)
CA.1 Business contact information. Although PIPEDA (s. 4.01) and the Quebec Act (s. 1) exclude business contact information used solely for professional communication, we apply this Policy to it.
CA.2 Person in charge (Quebec Act, s. 3.1). Dinko Anton Tudor, Managing Member, legal@tudorsgroup.com, as the person with the highest authority, without delegation.
CA.3 Quebec rights. Portability of computerised information you provided (s. 27); de-indexation or cessation of dissemination under s. 28.1; information and human review for automated decisions (s. 12.1), which we do not make. Fees, where allowed, cover only transcription, reproduction or transmission, and are announced in advance.
CA.4 Outside Quebec. Before communicating personal information of a person in Quebec outside Quebec, we carry out a privacy impact assessment and proceed only if it will be adequately protected, under a written agreement (s. 17).
CA.5 Records. We keep a record of every breach of security safeguards for at least 24 months (PIPEDA s. 10.3) and a register of confidentiality incidents (Quebec Act, s. 3.8).
CA.6 Language. A French version of this Policy is available for persons in Quebec (Charter of the French language, CQLR c. C-11).
Nigeria, South Africa and Kenya
N.1 Nigeria. The NDPA applies to controllers not domiciled in Nigeria that process data of data subjects in Nigeria (s. 2(2)(c)). We assess legitimate interests before relying on them, as the GAID requires. Transfers need adequate protection (s. 41) or a basis in s. 43, and we record the basis of each (s. 41(2)). Complaints to the NDPC: s. 46.
N.2 South Africa. Juristic persons are also data subjects (POPIA s. 1). The Information Officer is the person in Section 2.3 (ss. 1 and 55). Objections and requests for correction or deletion may also be made on Forms 1 and 2 of the POPIA Regulations, 2018. Transfers comply with s. 72; complaints to the Information Regulator: s. 74.
N.3 Kenya. The Act applies to controllers not established in Kenya that process data of data subjects in Kenya (s. 4(b)). Transfers comply with ss. 48 to 50 and regs. 39 to 44 of the General Regulations, and we process no data subject to localisation under s. 50. Complaints to the Data Commissioner: s. 56.