Methorion

Privacy policy

In effect from 11 October 2026

Methorion is a platform for running an information security management system. This policy explains which personal data we handle, why, who else touches it and what you can ask of us. It applies to the Methorion web application and to the emails it sends.

At a glance

The same overview a record of processing activities gives: what we hold, why, and for how long.

What we hold Why How long
Your account: name, email, company, country, language, password (stored only as a secure hash) To sign you in and run your account While the account exists, then up to 30 days
Your organisation's records: assets, processes, vendors and their contacts, risks, actions, documents To provide the service; we process them on your organisation's behalf Until the contract ends, then up to 30 days
Security records: sign-ins, changes made in the app, IP addresses To keep accounts safe and keep the audit trail your ISMS needs As long as the workspace exists
Billing: company details, invoices, payments To bill for the service and meet accounting law 11 years, as Croatian law requires

1Who we are

Methorion is operated by Code Creators d.o.o., Croatia. For anything about your personal data, write to privacy@methorion.com. We answer within one month.

Company
Code Creators d.o.o.
Privacy contact
privacy@methorion.com

2Two roles, depending on the data

For your account, sign-up and billing data, we decide how the data is used. We are the controller under the GDPR.

For what your organisation records in its workspace (its assets, vendors, risks, the people named in them), your organisation is the controller and we process the data on its instructions, under the data processing terms of our contract. Questions about that data are best sent to your organisation first; we will help it answer.

3What we collect

Only what the service needs to work:

  • Account details you give us when you sign up or are invited: first and last name, email address, company name, country, preferred language and date format, and a password, which we store only as a secure hash.
  • If you sign in with Google: your name, email address and a Google account identifier. We never see your Google password.
  • Two-factor authentication settings, the governance roles you hold and when you accepted them, and your signature if you sign a role acceptance.
  • Workspace content your organisation enters: its profile, locations, processes, systems, assets, vendors and their contact persons, risks, corrective actions, assessments, uploaded files and generated reports.
  • If your organisation sends a vendor questionnaire, the recipient's name and email address and the answers they give.
  • Security and audit records: sign-ins, changes made in the app with the time and the user who made them, and the IP address of the request.
  • Billing details for paid plans: company name, address, OIB, invoices and payment status. Card payments are handled by Stripe; we never receive card numbers.

We do not use analytics, advertising or tracking tools, and we do not sell or rent personal data.

4Why we use it

Each use rests on a legal basis from Article 6 of the GDPR:

  • To create and run your account, provide the platform, send the emails the service needs (invitations, role assignments, access granted) and support you. Basis: performing our contract with you or your organisation, or steps you asked for before it.
  • When a company signs up, to review the registration, enable access and contact you with an offer. Basis: steps taken at your request before a contract.
  • To protect accounts and the platform, investigate misuse and keep audit records. Basis: our legitimate interest in a secure service, which is also what your organisation expects from an ISMS tool.
  • To issue invoices and keep accounting records. Basis: legal obligations under Croatian accounting and tax law.

5AI features

Some features use AI: suggesting risks for your assets and looking up a company from its OIB. When you use them, the relevant part of your workspace (for example an asset's description, or the OIB you entered) is sent to Microsoft Azure OpenAI in the European Union. Microsoft does not use this data to train its models, and the results are suggestions you review before anything is saved.

6Who else handles the data

We use a small number of service providers, each bound by a data processing agreement and only for the purpose listed:

  • Microsoft (Azure): hosting, database, file storage, sending email and the AI features. In the European Union.
  • Google: only if you choose to sign in with Google, to confirm who you are.
  • Stripe: card payments for paid plans.
  • The Croatian court register (Sudski registar): when you look up a company by OIB, we send that OIB to fetch the company's public registration data.
  • If your organisation is managed by a consultancy through Methorion, that consultancy's staff can see and work on your organisation's workspace, as your organisation agreed with them.
  • Authorities, only when the law requires it.

7Where the data is stored

Your data is stored and processed in Microsoft Azure data centres in the European Union. The only transfer outside the EU can happen when you sign in with Google, which may process your sign-in in the United States under the EU-US Data Privacy Framework.

8How long we keep it

  • Account data: while your account exists. When it is closed or the contract ends, we delete it within 30 days.
  • A registration that does not lead to a contract: deleted within 6 months.
  • Workspace content and its audit records: for the duration of the contract, then deleted within 30 days. Your organisation can export its reports before that.
  • Backups: overwritten automatically within 35 days.
  • Invoices and accounting records: 11 years, as Croatian law requires.

9Cookies and browser storage

We only use what the application needs to work, so there is no cookie banner. Nothing is used for analytics or advertising.

Name Purpose Kept for
.AspNetCore.Identity.Application Keeps you signed in 14 days, or until you sign out
Identity.TwoFactorRememberMe Remembers this device for two-factor sign-in, if you ask it to 14 days
Identity.External Carries your Google sign-in back to Methorion A few minutes
.AspNetCore.Antiforgery Protects forms against cross-site request forgery Until you close the browser
.AspNetCore.Culture Remembers your language 1 year
localStorage Browser storage for small interface preferences, such as guided tours you have already seen Until you clear it

10How we protect it

Connections are encrypted (HTTPS) and data is encrypted at rest. Two-factor authentication is required for every account, access inside a workspace follows the roles your organisation assigns, and changes are recorded in an audit log. The application reaches its database, storage and AI services with managed identities, so no service passwords are stored in it. If a personal data breach affects you, we will tell you and the supervisory authority as the GDPR requires.

11Your rights

Under the GDPR you can ask us to:

  • show you the personal data we hold about you and give you a copy
  • correct data that is wrong or incomplete (most of it you can change yourself in My profile)
  • delete your data, or restrict how we use it
  • give you your data in a portable format
  • stop using your data where we rely on legitimate interest

Write to privacy@methorion.com. We may ask you to confirm your identity first, and we reply within one month. If you think we have handled your data unlawfully, you can complain to the Croatian Personal Data Protection Agency (AZOP, azop.hr) or to the authority in your own EU country.

12Children

Methorion is a business tool and is not meant for anyone under 16. We do not knowingly collect their data.

13Changes to this policy

When we change this policy, we update the date at the top. If a change affects how we use your data, we tell you by email or in the application before it takes effect.

Back to Methorion