Privacy Policy. Your data. Clear rules.
This Privacy Policy explains how TopicalAuthority.org handles personal data, why information may be processed, which legal bases may apply, how long data may be retained, who may receive it and which rights are available to individuals.
VERSION / PP-2026.09
Privacy begins with knowing who processes what — and why.
TopicalAuthority.org is operated by the controller identified in the next section. Personal data is processed only where there is a defined purpose and an applicable legal basis. The categories below describe the main privacy layers relevant to ordinary website use.
The entity responsible for determining the purposes and means of the processing described in this policy.
A research and publishing website focused on topical authority, semantic SEO, entity systems and AI search.
Privacy requests and questions about personal-data processing may be sent to this address.
Data should not be processed merely because it is technically possible to collect it.
One operator. One accountable contact point.
For the processing described in this Privacy Policy, the controller is the business operating TopicalAuthority.org.
Registered office: Rujanska ulica 11, 10000 Zagreb, Croatia. Website: TopicalAuthority.org.
CONTROLLER / IDENTIFIED
Use this address for access, rectification, erasure, restriction, objection, portability, consent withdrawal or other privacy-related requests.
CONTACT / OPEN
Different interactions create different data footprints.
Select a data class to see what may be processed. Not every category applies to every visitor, and optional technologies should be treated separately from infrastructure needed to deliver or secure the website.
Information You Provide
SOURCE / DIRECTA purpose explains the use. A legal basis permits the processing.
The applicable legal basis depends on the processing activity and context. The table below describes the principal bases that may apply under the GDPR.
To operate, protect, troubleshoot and defend the website against misuse, attacks and technical faults.
To answer a request, discuss potential services or handle ordinary correspondence.
To retain or provide information where applicable law requires it.
To understand site usage and improve content or technical performance when optional measurement is enabled.
Some processing is necessary for technical operation, legal compliance or handling a request. Where consent is used for optional processing, it can be withdrawn without affecting the lawfulness of processing carried out before withdrawal.
Not every browser technology has the same purpose.
Cookies or similar technologies may be used for different functions. Essential technologies support website operation or security; optional measurement or embedded services may require a different legal treatment depending on the technology and jurisdiction.
Used where technically required to provide a requested function, maintain security or preserve core website operation.
ESSENTIAL / FUNCTIONAL NECESSITY
May remember settings or consent choices where such functionality is enabled.
PREFERENCE / CONFIGURATION-DEPENDENT
If enabled, analytics may measure usage patterns and performance. Where consent is legally required, the optional measurement should follow the consent state.
MEASUREMENT / OPTIONAL
Third-party media or tools, if embedded, may make requests to external providers and can have their own privacy behavior.
THIRD PARTY / CONTEXT-DEPENDENT
Deleting or blocking certain technologies can affect website functionality. Where a dedicated consent interface is presented, use that interface to manage optional categories made available through it.
Website operation can involve specialized service providers.
Personal data may be accessible to service providers only where their role requires it for the relevant purpose. The exact provider set can change as the website’s technical stack changes.
Providers supporting server infrastructure, website delivery, backups, reliability or technical maintenance may process data necessary for those functions.
ACCESS / SERVICE NECESSITY
Communication providers may process sender, recipient, routing and message data when emails are sent or received.
ACCESS / COMMUNICATION DELIVERY
Where enabled, relevant providers may receive the limited data necessary to perform the configured measurement, security or preference function.
ACCESS / CONFIGURATION-DEPENDENT
Legal, accounting or other professional advisers may receive information when necessary for advice, compliance, claims or business administration.
ACCESS / NEED-TO-KNOW
Information may be disclosed where required by applicable law, lawful process or a binding request from a competent authority.
DISCLOSURE / LEGAL REQUIREMENT
If a provider processes personal data outside the EEA, an appropriate transfer mechanism or other lawful basis must apply where required.
TRANSFER / SAFEGUARD-DEPENDENT
Retention should follow purpose. Not habit.
Personal data is not intended to be retained indefinitely without a purpose. The exact period may depend on technical settings, legal obligations, the nature of a request and the need to establish, exercise or defend legal claims.
Collection should correspond to a technical, communication, legal or optional measurement purpose.
Data remains available while needed to operate the service, answer the request or perform the relevant function.
The continuing purpose, legal obligations and security requirements determine whether retention remains justified.
Some records may move from active operational use to restricted legal, security or archival handling.
Deletion is subject to technical backup cycles, statutory duties and legitimate legal requirements.
Specific records can be retained where necessary to demonstrate compliance or address legal claims.
Retained only as long as reasonably needed for security, diagnostics and infrastructure operation, subject to provider and technical settings.
CRITERIA / SECURITY NEED
Retained for the period needed to respond, maintain relevant business context and address follow-up or legal issues.
CRITERIA / COMMUNICATION PURPOSE
May be kept where necessary to remember preferences or demonstrate the consent status that applied to optional processing.
CRITERIA / ACCOUNTABILITY
Retained for any period required by applicable accounting, tax, contractual or other legal obligations.
CRITERIA / LEGAL DUTY
Personal data creates rights. The exact right depends on context.
Subject to the conditions and limitations of applicable data-protection law, individuals may exercise the following rights in relation to their personal data.
Ask whether personal data concerning you is processed and request access to the relevant data and processing information.
Request correction of inaccurate personal data and completion of incomplete data where appropriate.
Request deletion where the applicable legal conditions are met. The right is not absolute and may be limited by other lawful requirements.
Request restriction of processing in circumstances provided by applicable data-protection law.
Where the legal conditions apply, request personal data in a structured, commonly used and machine-readable format.
Object to certain processing based on legitimate interests or other grounds where the law provides that right.
Where processing relies on consent, withdraw it at any time without affecting the lawfulness of prior processing.
You may lodge a complaint with the competent data-protection authority. In Croatia, the supervisory authority is AZOP.
To protect personal data, reasonable verification may be requested before acting on a rights request. A request can also be limited or refused where applicable law permits that outcome, in which case the relevant reason should be communicated.
Privacy is not only a notice. It is an operating discipline.
Appropriate technical and organizational measures are used with the aim of reducing unauthorized access, loss, misuse or alteration. No internet-connected system can be represented as absolutely secure.
Collect and process only information reasonably connected to the relevant purpose.
LESS DATA / LESS EXPOSURE
Limit access to individuals or providers that require the information for an authorized function.
ACCESS / NEED-TO-KNOW
Use technical controls appropriate to the website, hosting environment and reasonably foreseeable threats.
SECURITY / RISK-BASED
Update the privacy framework when processing, technology, providers or legal obligations materially change.
POLICY / LIVING DOCUMENT
A link can leave this policy. A data flow may cross jurisdictions.
TopicalAuthority.org may link to external websites. Their privacy practices are controlled by their respective operators and are not governed by this Privacy Policy.
BOUNDARY / EXTERNAL CONTROLLER
If personal data is transferred outside the EEA, the transfer should rely on an applicable lawful mechanism or safeguard where data-protection law requires one.
TRANSFER / LEGAL SAFEGUARD
TopicalAuthority.org does not use ordinary website visitor data to make decisions based solely on automated processing that produce legal or similarly significant effects.
AUTOMATION / NO SIGNIFICANT DECISION
The policy follows the system. When processing changes, the notice should change.
TopicalAuthority.org is not directed at children. If personal data relating to a child is identified in circumstances requiring action under applicable law, the relevant information can be reviewed and handled accordingly.
AUDIENCE / PROFESSIONAL & GENERAL RESEARCH
This Privacy Policy may be updated when the website’s processing activities, technology, service providers or legal requirements change. The current revision date is displayed at the top of this page.
VERSION / PP-2026.09
Questions should have a visible destination.
For questions about this Privacy Policy or the processing of personal data, contact the controller directly. You may also contact the competent supervisory authority where applicable.
PRIVACY CONTACT
Data controller for TopicalAuthority.org.
Collect with purpose. Explain with precision.
Privacy transparency is not a decorative legal layer. It is the public description of how personal data moves through a system, why that movement is permitted and how the individual can challenge, correct or control it where the law provides that right.
DATA GOVERNANCE DISCLOSURE / TOPICALAUTHORITY.ORG