Privacy policy
In effect from 11 October 2026
Methorion is a platform for running an information security management system. This policy explains which personal data we handle, why, who else touches it and what you can ask of us. It applies to the Methorion web application and to the emails it sends.
At a glance
The same overview a record of processing activities gives: what we hold, why, and for how long.
| What we hold | Why | How long |
|---|---|---|
| Your account: name, email, company, country, language, password (stored only as a secure hash) | To sign you in and run your account | While the account exists, then up to 30 days |
| Your organisation's records: assets, processes, vendors and their contacts, risks, actions, documents | To provide the service; we process them on your organisation's behalf | Until the contract ends, then up to 30 days |
| Security records: sign-ins, changes made in the app, IP addresses | To keep accounts safe and keep the audit trail your ISMS needs | As long as the workspace exists |
| Billing: company details, invoices, payments | To bill for the service and meet accounting law | 11 years, as Croatian law requires |
1Who we are
Methorion is operated by Code Creators d.o.o., Croatia. For anything about your personal data, write to privacy@methorion.com. We answer within one month.
- Company
- Code Creators d.o.o.
- Privacy contact
- privacy@methorion.com
2Two roles, depending on the data
For your account, sign-up and billing data, we decide how the data is used. We are the controller under the GDPR.
For what your organisation records in its workspace (its assets, vendors, risks, the people named in them), your organisation is the controller and we process the data on its instructions, under the data processing terms of our contract. Questions about that data are best sent to your organisation first; we will help it answer.
3What we collect
Only what the service needs to work:
- Account details you give us when you sign up or are invited: first and last name, email address, company name, country, preferred language and date format, and a password, which we store only as a secure hash.
- If you sign in with Google: your name, email address and a Google account identifier. We never see your Google password.
- Two-factor authentication settings, the governance roles you hold and when you accepted them, and your signature if you sign a role acceptance.
- Workspace content your organisation enters: its profile, locations, processes, systems, assets, vendors and their contact persons, risks, corrective actions, assessments, uploaded files and generated reports.
- If your organisation sends a vendor questionnaire, the recipient's name and email address and the answers they give.
- Security and audit records: sign-ins, changes made in the app with the time and the user who made them, and the IP address of the request.
- Billing details for paid plans: company name, address, OIB, invoices and payment status. Card payments are handled by Stripe; we never receive card numbers.
We do not use analytics, advertising or tracking tools, and we do not sell or rent personal data.
4Why we use it
Each use rests on a legal basis from Article 6 of the GDPR:
- To create and run your account, provide the platform, send the emails the service needs (invitations, role assignments, access granted) and support you. Basis: performing our contract with you or your organisation, or steps you asked for before it.
- When a company signs up, to review the registration, enable access and contact you with an offer. Basis: steps taken at your request before a contract.
- To protect accounts and the platform, investigate misuse and keep audit records. Basis: our legitimate interest in a secure service, which is also what your organisation expects from an ISMS tool.
- To issue invoices and keep accounting records. Basis: legal obligations under Croatian accounting and tax law.
5AI features
Some features use AI: suggesting risks for your assets and looking up a company from its OIB. When you use them, the relevant part of your workspace (for example an asset's description, or the OIB you entered) is sent to Microsoft Azure OpenAI in the European Union. Microsoft does not use this data to train its models, and the results are suggestions you review before anything is saved.
7Where the data is stored
Your data is stored and processed in Microsoft Azure data centres in the European Union. The only transfer outside the EU can happen when you sign in with Google, which may process your sign-in in the United States under the EU-US Data Privacy Framework.
8How long we keep it
- Account data: while your account exists. When it is closed or the contract ends, we delete it within 30 days.
- A registration that does not lead to a contract: deleted within 6 months.
- Workspace content and its audit records: for the duration of the contract, then deleted within 30 days. Your organisation can export its reports before that.
- Backups: overwritten automatically within 35 days.
- Invoices and accounting records: 11 years, as Croatian law requires.
10How we protect it
Connections are encrypted (HTTPS) and data is encrypted at rest. Two-factor authentication is required for every account, access inside a workspace follows the roles your organisation assigns, and changes are recorded in an audit log. The application reaches its database, storage and AI services with managed identities, so no service passwords are stored in it. If a personal data breach affects you, we will tell you and the supervisory authority as the GDPR requires.
11Your rights
Under the GDPR you can ask us to:
- show you the personal data we hold about you and give you a copy
- correct data that is wrong or incomplete (most of it you can change yourself in My profile)
- delete your data, or restrict how we use it
- give you your data in a portable format
- stop using your data where we rely on legitimate interest
Write to privacy@methorion.com. We may ask you to confirm your identity first, and we reply within one month. If you think we have handled your data unlawfully, you can complain to the Croatian Personal Data Protection Agency (AZOP, azop.hr) or to the authority in your own EU country.
12Children
Methorion is a business tool and is not meant for anyone under 16. We do not knowingly collect their data.
13Changes to this policy
When we change this policy, we update the date at the top. If a change affects how we use your data, we tell you by email or in the application before it takes effect.