Privacy Policy

LAST UPDATED: 20 JULY 2026 · VERSION 2.0

This Privacy Policy explains how MLM Engineering, operating under the brand Code Flow ("Code Flow", "we", "us"), processes personal data when you visit this website or contact us. It is drawn up in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation — "GDPR"), the Slovenian Personal Data Protection Act (ZVOP-2, Official Gazette of the Republic of Slovenia No. 163/22), the Electronic Communications Act (ZEKom-2) and other applicable legislation of the Republic of Slovenia and the European Union.

1. Data controller

The controller of personal data collected through this website is:

We have not appointed a data protection officer, as we are not required to do so under Article 37 GDPR; all privacy-related enquiries are handled through the contact above.

2. What personal data we process, why, and on what legal basis

a) Contact and project enquiries. When you write to us by e-mail or book a call, we process the data you provide: name and surname, e-mail address, telephone number (if given), your organisation and the content of your message.
Purpose: responding to your enquiry, preparing an offer and negotiating a contract.
Legal basis: Article 6(1)(b) GDPR (steps at the request of the data subject prior to entering into a contract) and Article 6(1)(f) GDPR (our legitimate interest in business communication).

b) Contractual and billing data. If we enter into a contract, we process the data required for its performance and for invoicing (contact details, billing details, VAT ID).
Purpose: performance of the contract, issuing invoices, accounting and tax obligations.
Legal basis: Article 6(1)(b) GDPR and Article 6(1)(c) GDPR (legal obligations under Slovenian tax and accounting legislation, in particular ZDDV-1 and ZGD-1).

c) Server logs. Our hosting provider automatically records technical data when the website is accessed: IP address, date and time of the request, requested URL, HTTP status, browser and operating system identification.
Purpose: ensuring network and information security, detecting and preventing abuse, diagnosing technical problems.
Legal basis: Article 6(1)(f) GDPR (our legitimate interest in the security and availability of the website).

d) Web analytics. Analytics that would use cookies or similar identifiers is only activated on the basis of your prior consent given via the cookie notice (Article 6(1)(a) GDPR and Article 225 of ZEKom-2). See the Cookie Policy. At present the website operates without analytics cookies.

e) Direct marketing. We do not send newsletters or other direct marketing messages. Should we introduce them, they will be sent only in accordance with Article 226 of ZEKom-2 and Article 6(1)(a) GDPR (consent), or to existing customers under the conditions of the "similar services" exception, always with a simple opt-out.

3. Provision of data

You are not legally required to provide us with any personal data. However, without your contact details we cannot respond to your enquiry or conclude and perform a contract.

4. Recipients of personal data

We do not sell or rent personal data. Data may be disclosed to the following categories of recipients, strictly to the extent necessary:

5. Transfers to third countries

We primarily use service providers with data centres in the EU/EEA. Where a provider processes data outside the EU/EEA (for example certain e-mail or cloud services), the transfer takes place only under the safeguards of Chapter V GDPR: an adequacy decision of the European Commission (including the EU–US Data Privacy Framework for certified US providers) or the European Commission's Standard Contractual Clauses, with supplementary measures where required.

6. Retention periods

7. Your rights

Subject to the conditions of the GDPR, you have the right to:

Requests can be sent to info@code-flow.app. We will respond without undue delay and at the latest within one month of receipt of the request; this period may be extended by two further months for complex requests, of which you will be informed. We may ask you for additional information to confirm your identity. Exercising these rights is free of charge, unless requests are manifestly unfounded or excessive.

8. Right to lodge a complaint

If you believe that our processing of your personal data infringes the GDPR or ZVOP-2, you have the right to lodge a complaint with the supervisory authority in Slovenia:

Informacijski pooblaščenec Republike Slovenije
Dunajska cesta 22, 1000 Ljubljana, Slovenia
Telephone: +386 1 230 97 30
E-mail: gp.ip@ip-rs.si · Web: www.ip-rs.si

9. Automated decision-making and profiling

We do not carry out automated decision-making or profiling within the meaning of Article 22 GDPR.

10. Data security

In accordance with Article 32 GDPR and ZVOP-2 we implement appropriate technical and organisational measures, including: encrypted transmission (HTTPS/TLS), access control and the principle of least privilege, regular software updates, backups, and contractual confidentiality obligations for any person processing data on our behalf. In the unlikely event of a personal data breach that is likely to result in a high risk to your rights, we will notify you and the supervisory authority in accordance with Articles 33 and 34 GDPR.

11. Children

This website is intended for business users and is not directed at children. We do not knowingly process personal data of children under 15 years of age (the age limit set by ZVOP-2 for information society services).

12. Changes to this policy

We may amend this Privacy Policy from time to time. The applicable version is always published on this page, with the date of the last update indicated at the top. In the event of substantial changes we will inform data subjects with whom we are in active contact.