PUBLIC RECORD / PRIVACY
Privacy and analytics.
Your visit remains your choice.
This record explains how a Work Brief is verified and delivered, and how submitted correspondence is retained. It also records the site’s current interim Analytics choice, what the standard Google tag may process and how to turn it off.
- Default
- ON
- Control
- OFF / ON
- Effective
- Controller
- Rajko Majcen
01 WORK BRIEF + EMAIL
A message, not a website database.
When you send a Work Brief, OpenLegalCore uses the details you provide to review the enquiry and, where appropriate, reply. The website does not retain a separate database copy of the submission. The message is delivered by email to the project’s sales mailbox.
- Verification
- Cloudflare Turnstile
- Email delivery
- Resend
- Mailbox
- WebiCom d.o.o.
- Website database
- none
- After last substantive contact
- up to 12 months
What the submission contains.
The form sends your selected work path and component scope, name, email address, optional organisation, message and any optional perspective, jurisdiction or timing context you add. Do not submit passwords, credentials, confidential case files, personal legal documents or information that is not needed for the enquiry.
Why and how it is processed.
A defined-outcome enquiry may be processed where necessary to take steps at your request before entering into a contract under GDPR Article 6(1)(b). Contribution, research and other enquiries are processed on the basis of OpenLegalCore’s legitimate interest under Article 6(1)(f) in receiving, assessing and responding to relevant project correspondence. This describes the project’s operating position; it is not a claim that a supervisory authority or court has certified it.
When you open the Work Brief, its Cloudflare Turnstile client is prepared so it can check the submission for automated abuse. Its client-side signals include the IP address, TLS fingerprint, user-agent header, site key and associated origin. The website sends the resulting token—and the connecting IP address when Cloudflare provides it—to Turnstile for server-side verification. The form handler does not add the token, IP address or form contents to its application logs.
After successful verification, Resend receives the message and recipient data needed to transmit one email. WebiCom d.o.o. hosts the recipient mailbox. OpenLegalCore removes the active mailbox correspondence no later than 12 months after the last substantive contact, unless longer retention is required by law or necessary for a legal claim. Delivery providers may retain operational copies under their own deletion and backup cycles.
Read Cloudflare’s Turnstile Privacy Addendum , Resend’s Data Processing Addendum and subprocessor list , and WebiCom’s company record .
02 ANALYTICS BASIS + PRACTICE
Why this choice exists.
Optional analytics is not needed to deliver OpenLegalCore. European and Slovenian law therefore treat it differently from storage that is strictly necessary to provide a service requested by the visitor. The authorities listed below support a prior-consent approach. OpenLegalCore currently applies a documented interim default-on, opt-out model instead. That is an implementation decision, not a claim that a court or supervisory authority has certified it as compliant.
European Union framework.
Article 5(3) of the EU ePrivacy Directive requires prior consent before information is stored on, or accessed from, a visitor’s device. Its narrow exceptions cover transmission of a communication and storage or access that is strictly necessary for a service expressly requested by the visitor. Optional audience measurement does not form part of the service you request when you read this website, so OpenLegalCore does not use that exception for Google Analytics.
Where analytics identifiers and associated usage data are personal data, the General Data Protection Regulation also applies. For that personal-data processing, OpenLegalCore’s current disclosed position is legitimate interests under GDPR Article 6(1)(f): understanding use of the public site and improving its operation. Visitors can object by switching Analytics off. That GDPR basis does not itself resolve the separate terminal-storage rule in Article 5(3) of the ePrivacy Directive.
Slovenian law and supervisory practice.
Article 225 of Slovenia’s Electronic Communications Act (ZEKom-2) applies the same prior-consent rule to storage in, or access to, terminal equipment. It requires clear and comprehensive prior information about the controller and purposes, retains only the transmission and strict-necessity exceptions, and places supervision with the Information Commissioner of the Republic of Slovenia. OpenLegalCore does not classify Google Analytics storage as strictly necessary.
The Slovenian Information Commissioner’s published guidance likewise states that non-essential cookies and comparable tracking technologies require valid prior consent. Its opinions are general supervisory guidance rather than a binding ruling on this particular website, but they explain how the statutory rule is applied in practice.
OFFICIAL SOURCES
The authorities behind this record.
Legal sources reviewed .
- ePrivacy Directive, Article 5(3) EU rule for storage and access on a user’s device.
- GDPR, Articles 5, 6(1)(b) and (f), 13 and 21 Principles, legitimate interests, transparency and the right to object.
- ZEKom-2, Article 225 Slovenian terminal-storage and access rule.
- CJEU, Planet49, C-673/17 Active consent and required information about cookies.
- EDPB Guidelines 2/2023, final version Technical scope of storage and access under Article 5(3).
- EDPB Cookie Banner Taskforce report Common supervisory positions on consent interfaces.
- Slovenian Information Commissioner guidance Application of Article 225 ZEKom-2 to non-essential tracking.
03 YOUR ANALYTICS CHOICE
The default remains yours to change.
On https://openlegalcore.org, Analytics starts in the ON state and the standard Google tag may load when a page opens. An OFF choice is stored in this browser and prevents the tag from loading on later pages until you turn it on again or clear site storage. Local, preview and staging origins never contact Google.
When this interim model was introduced, the former version-one consent value was retired rather than migrated. Every browser therefore entered the new version-two preference model as ON, including browsers that had previously recorded OFF.
The public site remains available either way. Local, preview and staging origins never contact Google, even when this browser records ON.
04 DATA + PURPOSE
Use depends on the Google tag and property configuration.
Analytics helps the project understand which public records are used, where visits come from and whether navigation is working. The site now uses the standard GA4 tag without repository-imposed page-view-only, URL-reduction, Google Signals or advertising-personalisation overrides. The effective collection boundary also depends on settings administered in the GA4 property.
What a measured visit may contain.
- the visited page URL and title, visit time and referring URL;
- browser, device category, language and approximate screen characteristics;
- session and first-visit identifiers stored in analytics cookies;
- automatically collected events, engagement information and other signals enabled by the Google tag or GA4 property; and
- coarse geographic information derived during processing.
Google states that GA4 does not log or store individual IP addresses. OpenLegalCore does not intentionally place names, email addresses or form content into Analytics. This repository currently defines no custom Analytics event or project user-ID call, but that does not narrow collection performed by the standard tag or property.
05 LOCAL STORAGE + COOKIES
The preference and Analytics use separate storage.
The Analytics preference is stored in this browser so the website can honour it. That preference is not sent to OpenLegalCore. The news indicator separately stores the identifiers of public records you have seen; it is not analytics.
- Preference key
- openlegalcore:analytics-preference:v2
- Allowed values
- granted / denied
- News-read key
- openlegalcore:read-news:v1
- Local duration
- until changed or site storage is cleared
- Analytics cookies
- _ga / _ga_88S2B64R66
- Cookie maximum
- 24 months
Turning Analytics off immediately requests denied analytics storage and removes accessible Google Analytics cookies for this site. If the Google tag was already active, the page reloads; subsequent documents do not request the tag while OFF.
06 RETENTION + PROCESSING
A bounded service-provider record.
- Service
- Google Analytics 4
- Property
- G-88S2B64R66
- Measurement
- standard GA4 tag
- User/event retention
- 14 months
The 14-month setting limits user- and event-level data available in GA4 explorations. Google states that the same deletion schedule does not apply to standard aggregated reports. Google processes allowed analytics information as the analytics service provider and may process it in countries outside the country where you live.
Read Google’s Privacy Policy , business data responsibility information , international data-transfer information and GA4 data-retention explanation .
07 RIGHTS + CONTACT
A direct responsibility and review path.
Rajko Majcen, Founder and maintainer of OpenLegalCore, is the controller for this website. Privacy questions and requests can be sent to hello@openlegalcore.org.
Depending on the circumstances, you may request access, correction, deletion, restriction, objection or portability. For processing based on legitimate interests, you have a right to object under GDPR Article 21. The permanent OFF controls provide an immediate technical opt-out without affecting processing that occurred earlier. You may also lodge a complaint with the Information Commissioner of the Republic of Slovenia .