TOPICALAUTHORITY.ORG TAO / ROOT

Privacy Policy

TOPICALAUTHORITY.ORG
LEGAL / DATA GOVERNANCE
DISCLOSURE STATE PRIVACY POLICY / ACTIVE
PRIVACY POLICY DATA PROTECTION · TRANSPARENCY · CONTROL

Privacy Policy. Your data. Clear rules.

This Privacy Policy explains how TopicalAuthority.org handles personal data, why information may be processed, which legal bases may apply, how long data may be retained, who may receive it and which rights are available to individuals.

LAST UPDATED / 05 SEPTEMBER 2026
VERSION / PP-2026.09
PRIVACY / 01 QUICK OVERVIEW

Privacy begins with knowing who processes what — and why.

TopicalAuthority.org is operated by the controller identified in the next section. Personal data is processed only where there is a defined purpose and an applicable legal basis. The categories below describe the main privacy layers relevant to ordinary website use.

CONTROLLER Identified in Section 02

The entity responsible for determining the purposes and means of the processing described in this policy.

PLATFORM TopicalAuthority.org

A research and publishing website focused on topical authority, semantic SEO, entity systems and AI search.

PRIMARY CONTACT b@bb.hr

Privacy requests and questions about personal-data processing may be sent to this address.

CORE PRINCIPLE Purpose before collection.

Data should not be processed merely because it is technically possible to collect it.

PRIVACY / 02 CONTROLLER IDENTITY

One operator. One accountable contact point.

For the processing described in this Privacy Policy, the controller is the business operating TopicalAuthority.org.

LEGAL IDENTITY BB DIGITALNA AGENCIJA, obrt za IT i usluge, vl. Goran Barišić

Registered office: Rujanska ulica 11, 10000 Zagreb, Croatia. Website: TopicalAuthority.org.

CONTROLLER / IDENTIFIED
PRIVACY CONTACT b@bb.hr

Use this address for access, rectification, erasure, restriction, objection, portability, consent withdrawal or other privacy-related requests.

CONTACT / OPEN
PRIVACY / 03 DATA MAP

Different interactions create different data footprints.

Select a data class to see what may be processed. Not every category applies to every visitor, and optional technologies should be treated separately from infrastructure needed to deliver or secure the website.

DATA CLASS SELECT

Information You Provide

SOURCE / DIRECT

PRIVACY / 04 PURPOSES & LEGAL BASES

A purpose explains the use. A legal basis permits the processing.

The applicable legal basis depends on the processing activity and context. The table below describes the principal bases that may apply under the GDPR.

PURPOSEProcessing activity
DATATypical data involved
LEGAL BASISGDPR context
WHYOperational rationale
Website delivery & security
Technical request and security data
Legitimate interests — Art. 6(1)(f)

To operate, protect, troubleshoot and defend the website against misuse, attacks and technical faults.

Responding to inquiries
Email, name if provided, message contents
Art. 6(1)(b) or Art. 6(1)(f), depending on context

To answer a request, discuss potential services or handle ordinary correspondence.

Legal / compliance records
Data required to meet legal obligations
Legal obligation — Art. 6(1)(c)

To retain or provide information where applicable law requires it.

Optional analytics / measurement
Usage and measurement data
Consent — Art. 6(1)(a), where required

To understand site usage and improve content or technical performance when optional measurement is enabled.

IMPORTANT Consent is not a universal legal basis for every processing activity.

Some processing is necessary for technical operation, legal compliance or handling a request. Where consent is used for optional processing, it can be withdrawn without affecting the lawfulness of processing carried out before withdrawal.

PRIVACY / 05 COOKIES & MEASUREMENT

Not every browser technology has the same purpose.

Cookies or similar technologies may be used for different functions. Essential technologies support website operation or security; optional measurement or embedded services may require a different legal treatment depending on the technology and jurisdiction.

CLASS / 01 Strictly Necessary

Used where technically required to provide a requested function, maintain security or preserve core website operation.

ESSENTIAL / FUNCTIONAL NECESSITY
CLASS / 02 Preferences

May remember settings or consent choices where such functionality is enabled.

PREFERENCE / CONFIGURATION-DEPENDENT
CLASS / 03 Analytics

If enabled, analytics may measure usage patterns and performance. Where consent is legally required, the optional measurement should follow the consent state.

MEASUREMENT / OPTIONAL
CLASS / 04 Embedded Content

Third-party media or tools, if embedded, may make requests to external providers and can have their own privacy behavior.

THIRD PARTY / CONTEXT-DEPENDENT
COOKIE CONTROL Your browser may also provide controls for stored cookies and site data.

Deleting or blocking certain technologies can affect website functionality. Where a dedicated consent interface is presented, use that interface to manage optional categories made available through it.

PRIVACY / 06 RECIPIENTS & PROCESSORS

Website operation can involve specialized service providers.

Personal data may be accessible to service providers only where their role requires it for the relevant purpose. The exact provider set can change as the website’s technical stack changes.

PROCESSOR CLASS / INFRASTRUCTURE Hosting & Technical Infrastructure

Providers supporting server infrastructure, website delivery, backups, reliability or technical maintenance may process data necessary for those functions.

ACCESS / SERVICE NECESSITY
PROCESSOR CLASS / COMMUNICATION Email & Communication

Communication providers may process sender, recipient, routing and message data when emails are sent or received.

ACCESS / COMMUNICATION DELIVERY
PROCESSOR CLASS / OPTIONAL Analytics, Security or Consent Tools

Where enabled, relevant providers may receive the limited data necessary to perform the configured measurement, security or preference function.

ACCESS / CONFIGURATION-DEPENDENT
RECIPIENT / PROFESSIONAL Professional Advisers

Legal, accounting or other professional advisers may receive information when necessary for advice, compliance, claims or business administration.

ACCESS / NEED-TO-KNOW
RECIPIENT / AUTHORITY Public Authorities

Information may be disclosed where required by applicable law, lawful process or a binding request from a competent authority.

DISCLOSURE / LEGAL REQUIREMENT
TRANSFER / EEA International Processing

If a provider processes personal data outside the EEA, an appropriate transfer mechanism or other lawful basis must apply where required.

TRANSFER / SAFEGUARD-DEPENDENT
PRIVACY / 07 RETENTION LOGIC

Retention should follow purpose. Not habit.

Personal data is not intended to be retained indefinitely without a purpose. The exact period may depend on technical settings, legal obligations, the nature of a request and the need to establish, exercise or defend legal claims.

01 / COLLECTION Data enters a defined process.

Collection should correspond to a technical, communication, legal or optional measurement purpose.

02 / ACTIVE USE The purpose is performed.

Data remains available while needed to operate the service, answer the request or perform the relevant function.

03 / REVIEW Need is reassessed.

The continuing purpose, legal obligations and security requirements determine whether retention remains justified.

04 / RESTRICT Access can narrow.

Some records may move from active operational use to restricted legal, security or archival handling.

05 / DELETE Data is removed when no longer needed.

Deletion is subject to technical backup cycles, statutory duties and legitimate legal requirements.

06 / EVIDENCE Required records may remain.

Specific records can be retained where necessary to demonstrate compliance or address legal claims.

RETENTION CLASS Server & Security Logs

Retained only as long as reasonably needed for security, diagnostics and infrastructure operation, subject to provider and technical settings.

CRITERIA / SECURITY NEED
RETENTION CLASS Contact Correspondence

Retained for the period needed to respond, maintain relevant business context and address follow-up or legal issues.

CRITERIA / COMMUNICATION PURPOSE
RETENTION CLASS Consent Records

May be kept where necessary to remember preferences or demonstrate the consent status that applied to optional processing.

CRITERIA / ACCOUNTABILITY
RETENTION CLASS Legal / Business Records

Retained for any period required by applicable accounting, tax, contractual or other legal obligations.

CRITERIA / LEGAL DUTY
PRIVACY / 08 DATA SUBJECT RIGHTS

Personal data creates rights. The exact right depends on context.

Subject to the conditions and limitations of applicable data-protection law, individuals may exercise the following rights in relation to their personal data.

RIGHT / 01 Access

Ask whether personal data concerning you is processed and request access to the relevant data and processing information.

RIGHT / 02 Rectification

Request correction of inaccurate personal data and completion of incomplete data where appropriate.

RIGHT / 03 Erasure

Request deletion where the applicable legal conditions are met. The right is not absolute and may be limited by other lawful requirements.

RIGHT / 04 Restriction

Request restriction of processing in circumstances provided by applicable data-protection law.

RIGHT / 05 Portability

Where the legal conditions apply, request personal data in a structured, commonly used and machine-readable format.

RIGHT / 06 Object

Object to certain processing based on legitimate interests or other grounds where the law provides that right.

RIGHT / 07 Withdraw Consent

Where processing relies on consent, withdraw it at any time without affecting the lawfulness of prior processing.

RIGHT / 08 Complain to a Supervisory Authority

You may lodge a complaint with the competent data-protection authority. In Croatia, the supervisory authority is AZOP.

REQUEST CHANNEL Privacy requests: b@bb.hr

To protect personal data, reasonable verification may be requested before acting on a rights request. A request can also be limited or refused where applicable law permits that outcome, in which case the relevant reason should be communicated.

PRIVACY / 09 SECURITY & MINIMIZATION

Privacy is not only a notice. It is an operating discipline.

Appropriate technical and organizational measures are used with the aim of reducing unauthorized access, loss, misuse or alteration. No internet-connected system can be represented as absolutely secure.

CONTROL / 01 Data Minimization

Collect and process only information reasonably connected to the relevant purpose.

LESS DATA / LESS EXPOSURE
CONTROL / 02 Access Limitation

Limit access to individuals or providers that require the information for an authorized function.

ACCESS / NEED-TO-KNOW
CONTROL / 03 Infrastructure Security

Use technical controls appropriate to the website, hosting environment and reasonably foreseeable threats.

SECURITY / RISK-BASED
CONTROL / 04 Review & Correction

Update the privacy framework when processing, technology, providers or legal obligations materially change.

POLICY / LIVING DOCUMENT
PRIVACY / 10 EXTERNAL SYSTEMS & AUTOMATION

A link can leave this policy. A data flow may cross jurisdictions.

EXTERNAL LINKS Third-Party Websites

TopicalAuthority.org may link to external websites. Their privacy practices are controlled by their respective operators and are not governed by this Privacy Policy.

BOUNDARY / EXTERNAL CONTROLLER
INTERNATIONAL TRANSFERS Processing Outside the EEA

If personal data is transferred outside the EEA, the transfer should rely on an applicable lawful mechanism or safeguard where data-protection law requires one.

TRANSFER / LEGAL SAFEGUARD
AUTOMATED DECISION-MAKING No Legal-Effect Visitor Profiling

TopicalAuthority.org does not use ordinary website visitor data to make decisions based solely on automated processing that produce legal or similarly significant effects.

AUTOMATION / NO SIGNIFICANT DECISION
PRIVACY / 11 CHILDREN & POLICY CHANGES

The policy follows the system. When processing changes, the notice should change.

CHILDREN Professional research website

TopicalAuthority.org is not directed at children. If personal data relating to a child is identified in circumstances requiring action under applicable law, the relevant information can be reviewed and handled accordingly.

AUDIENCE / PROFESSIONAL & GENERAL RESEARCH
POLICY REVISION Material changes should be reflected here.

This Privacy Policy may be updated when the website’s processing activities, technology, service providers or legal requirements change. The current revision date is displayed at the top of this page.

VERSION / PP-2026.09
PRIVACY / 12 CONTACT & SUPERVISORY AUTHORITY

Questions should have a visible destination.

For questions about this Privacy Policy or the processing of personal data, contact the controller directly. You may also contact the competent supervisory authority where applicable.

PRIVACY CONTACT

Data controller for TopicalAuthority.org.

REGISTERED OFFICE Rujanska ulica 11, 10000 Zagreb, Croatia
PRIVACY EMAIL b@bb.hr
PLATFORM TopicalAuthority.org
PRIVACY / PRINCIPLE TOPICALAUTHORITY.ORG

Collect with purpose. Explain with precision.

Privacy transparency is not a decorative legal layer. It is the public description of how personal data moves through a system, why that movement is permitted and how the individual can challenge, correct or control it where the law provides that right.

PRIVACY POLICY / VERSION PP-2026.09
DATA GOVERNANCE DISCLOSURE / TOPICALAUTHORITY.ORG
TAO / CONTACT · DIRECT TRANSMISSION Have an asset, domain or market position to investigate? ENTER CONTACT SYSTEM →
DIGITAL ASSET INTELLIGENCE + EXECUTION
EXECUTED BY
BB DIGITALNA AGENCIJA

Investigation, consulting and execution of digital assets, premium-domain strategies, information architecture, semantic systems, websites and agreed digital growth plans.

TOPICALAUTHORITY.ORG / SEMANTIC INTELLIGENCE SYSTEM BB DIGITALNA AGENCIJA / BB.HR