The Karlović Villa Method
Filigrane
Privacy Notice—Serklaž, A brand of Konsiteo Ltd
Effective date: 9 July 2026
Serklaž is a brand of Konsiteo Ltd, a company registered in England and Wales, with its registered office at 71–75 Shelton Street, Covent Garden, London WC2H 9JQ (company number 9835328, VAT number GB226792289, ICO registration ZA150392, and Croatian tax identification HR99353656457). The data controller for all processing described in this notice is Konsiteo Ltd. Alen Karlović, Founder and Director, may be contacted by email at alen@konsiteo.com—OpenPGP-encrypted correspondence is encouraged, using the public key published at konsiteo.com, fingerprint 74E5 1E59 C219 E13C A611 4E4A 2966 8E19 C842 C2E3—or by end-to-end encrypted Signal communication. All client enquiries and data-related communications addressed to the controller should be directed to croatia@serklaz.com—the same encryption is welcomed for this address, using the public key published at serklaz.com, fingerprint D351 6159 4E17 A30F 9301 0157 E647 7412 9973 36EA—by voice message at +385 91 566 66 89, or by Signal communication. This notice satisfies the transparency obligations set out in Articles 12, 13, and 14 of the UK General Data Protection Regulation and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. Where personal data is transmitted to this practice by individuals located within the European Union, processing is conducted in equal compliance with Regulation (EU) 2016/679 (EU GDPR). It is written in the same spirit in which the practice itself was built: not because the law requires words, but because the Karlović family's understanding of what it means to hold something on behalf of another person—whether a client's legacy, a villa's structural record, or their personal information—runs prior to and independent of any regulatory obligation. What follows is a complete and honest account of how that understanding is applied to the data that reaches this practice.
What this website does not do
This website is hosted on servers located within the European Union in Amsterdam, The Netherlands. As is standard with all web hosting, the hosting infrastructure may generate server access logs—recording technical data such as IP addresses, timestamps, URLs of pages requested, HTTP status codes, data volumes transferred, referrer addresses, and user-agent strings (which may indicate the browser and operating system in use)—as a routine function of delivering web pages. This technical logging is an inherent function of internet infrastructure, is not used by this practice for any analytical or commercial purpose, and is governed by the hosting provider's own data processing terms. This practice does not access, analyse, or use data collected in this way for any purpose relating to individual visitors—not because it could not, but because the same discipline that governs every other decision here applies equally to what could be done and is not. This website collects no tracking data, employs no analytics platform, and sets no cookies of any kind—not functional, not analytical, not marketing, not statistical. This website does not load any third-party scripts, stylesheets, or external resources during page render. All fonts are self-hosted and served locally from our website server. No requests are made to external typography providers, content delivery networks, or any other third party as a result of visiting this site, and accordingly no technical data (such as your IP address or browser headers) is transmitted to third parties in connection with font delivery. No device fingerprinting takes place. No pixel, tag, session recorder, beacon, or link-decoration mechanism is used to observe, record, or transmit any aspect of your presence here to any party—including to Serklaž or Konsiteo Ltd. You arrive, you read, and you leave, without leaving a trace that this practice has authored, permitted, or retained. The absence of tracking is not a concession to regulation, nor a response to the inconvenience of consent management. It is what Curare aude—the third imperative of this practice—demands of anyone who holds the obligation of another person's trust: that nothing is gathered which is not genuinely needed, and that nothing is held which cannot be defended before a standard rigorous enough to matter.
What personal data is collected, and how
The only personal data processed in connection with Serklaž is information you choose to transmit directly: your name, your telephone number, your email address—together with the technical metadata inherent in the transmission, such as timestamps and mail server headers—and the substance of your communication, whether transmitted by email to croatia@serklaz.com, by voice message at +385 91 566 66 89, or by encrypted Signal message. No web form, submission engine, session token, or behavioural tracking mechanism captures visitor information. Data reaches this practice only because you sent it, through a channel you selected, with a purpose you formed independently and entirely on your own terms. Where an advisory engagement is formed, this practice additionally collects a copy of the client's valid passport or national identity document, together with a written declaration of the source of funds intended for the engagement and any supporting documentation the client provides in connection with that declaration. This category of personal data is collected once, at the outset of the engagement, for the purpose described in the following section, and is not requested, and plays no part, in any correspondence preceding that stage. End-to-end encrypted communication—whether by Signal communication or by OpenPGP-encrypted email—is not a technical option offered alongside others. It is the preferred and actively encouraged mode of all correspondence with this practice, and the natural preference of the clients for whom Serklaž was built. Email transmitted without OpenPGP encryption travels over standard SMTP infrastructure and is not end-to-end encrypted in transit; this practice therefore publishes the necessary public key, precisely because unencrypted email is not a channel worthy of the confidence this practice asks its correspondents to place in it. Voice messages left at the designated number are received through standard mobile telephony infrastructure. This channel does not provide end-to-end encryption; metadata associated with the call—including the caller's number and the time of the message—is retained by the telecommunications carrier under its own terms. The substance of the voice message itself is retained by this practice on the terms described in this notice. Signal messages, like email, constitute a deliberate transmission of personal data to this practice and are processed accordingly. These measures are not features of a privacy programme. They are the expression of a disposition: that information shared in confidence deserves to travel under conditions worthy of that confidence.
Why that data is processed and on what legal basis
Personal data transmitted to this practice is processed for one purpose: to receive and consider your communication and, where appropriate, to respond to it in accordance with the character and terms of this practice. The lawful basis for this processing is the legitimate interest of both parties in conducting a private and substantive enquiry. The legitimate interest relied upon is the mutual interest of the person writing to this practice and of Serklaž in exchanging substantive, private correspondence in connection with a potential or ongoing advisory engagement. This interest is not overridden by the data subject's rights, given the absence of any profiling or third-party sharing, the minimal scope of data involved, and the reasonable expectation of anyone who initiates direct contact that their correspondence will be read and considered—an interest that, given the nature of this practice and the deliberate choice made by anyone who writes to it, clearly outweighs any privacy intrusion. Where a formal advisory engagement follows from an initial approach—the commencement of an engagement under the terms of the Serklaž advisory relationship—the additional processing required to perform that engagement will be conducted on the basis of contractual necessity, and will be described in the engagement documentation provided at that stage. The engagement documentation will itself satisfy the transparency requirements of Article 13 of the applicable regulation in respect of that additional processing, and will stand as a complete disclosure for the purposes of the advisory relationship. Identification documents and source-of-funds information are collected and processed on the basis of legal obligation, in accordance with anti-money laundering legislation applicable to those who assist in planning or conducting a real estate transaction on a client's behalf. The advisory fee is settled exclusively by bank transfer; the payment details transmitted in that process are processed on the basis of contractual necessity and retained in accordance with applicable financial record-keeping obligations.
How long personal data is retained
Voice messages are retained only for as long as is necessary to transcribe or act upon their content, and in any event for no longer than the period applicable to the correspondence to which they relate. Correspondence transmitted to this practice is retained for as long as the relationship it documents remains active, and thereafter for such period as is necessary to protect the legitimate interests of both parties—a period not exceeding seven (7) years from the conclusion of the relevant engagement or exchange, consistent with applicable statutory and professional obligations. Where no formal advisory engagement follows from an initial approach, correspondence is retained only for as long as is reasonably necessary to conclude that exchange and, in any event, for no more than two (2) years. Identification documents and source-of-funds records are retained for the period required under applicable anti-money laundering law, being not less than five (5) years from the conclusion of the engagement to which they relate, and are not retained beyond the point at which that legal obligation ceases to apply. Identification documents, source-of-funds declarations, supporting financial documentation, and signed agreements are held in encrypted storage, accessible only to the person to whom this practice belongs, and are not stored on shared, third-party, or general-purpose systems. No personal data is retained beyond these periods without a renewed purpose that can be independently justified. The governing principle here is the same that applies to every other judgment this practice makes: nothing is held beyond the point at which holding it serves a purpose answerable to conscience.
With whom personal data is shared
Personal data transmitted to Serklaž is not shared with any third party for any purpose. It is not sold, licensed, or passed to data brokers, analytics providers, marketing platforms, or any entity engaged in the secondary use of personal information. Our advisory fee structure—fixed, non-commission-based, and settled entirely by the client—means that no incentive exists, within this practice, to share a client's information with any party whose interest is other than the client's own. Where legal or regulatory obligations compel disclosure—to a regulator, a court, a data protection authority in the jurisdiction of the client, or a financial institution in the ordinary course of compliance—such disclosure will be made to the minimum extent required and will not be treated as a matter of routine. Where Serklaž is required to conduct client due diligence or meet anti-money laundering obligations under applicable law, personal data may be processed for that purpose on the basis of legal obligation. Identification and source-of-funds records are not shared beyond what is strictly required to meet that legal obligation, and are never used for any purpose beyond it. The legal counsel and banking relationships through which Konsiteo Ltd operates are bound by confidentiality obligations that reflect the standards this practice applies at every level of its conduct. Where a client chooses to sign the advisory agreement electronically, the Qualified Trust Service Provider used to issue the signature processes the personal data necessary to verify identity and issue the signature, under its own privacy notice and as an independent controller for that purpose.
International transfers
Konsiteo Ltd's registered office is in England and Wales; the practice operates exclusively from Rijeka, Croatia, within the European Union (Konsiteo Ltd, Dobriše Cesarića 24, 51000 Rijeka, Croatia, OIB: 99353656457). Personal data may therefore move between these two jurisdictions in the ordinary course of correspondence and engagement. The United Kingdom holds an adequacy decision under EU GDPR, renewed in December 2025 and valid until December 2031, meaning that data flowing between Croatia and the UK travels under conditions recognised as providing equivalent protection—without the need for additional transfer safeguards. Where data moves beyond these two jurisdictions, such transfers are conducted in accordance with the requirements of UK GDPR Article 46 and EU GDPR Article 46, under appropriate safeguards, and subject to the same principle of necessity that governs all processing within this practice. Where correspondence is initiated by, or an advisory engagement is entered into with, an individual located outside the United Kingdom and the European Union, the personal data transmitted in the course of that relationship may involve a transfer of data to or from a jurisdiction that does not benefit from an adequacy decision. In such cases, transfers are conducted on one or both of the following bases: where a contract for advisory services is in place or is being formed, the transfer is necessary for the performance of that contract, pursuant to Article 49(1)(b) of EU GDPR and the equivalent UK GDPR provision; and where an engagement letter is issued, it incorporates appropriate transfer safeguards as required by Article 46 of EU GDPR and the ICO's International Data Transfer Agreement under UK GDPR. In all cases, the same principles of minimum data, confidentiality, and purpose limitation that govern this practice's handling of EU and UK personal data apply without modification to data relating to clients and correspondents in any jurisdiction.
Your rights
Under the UK General Data Protection Regulation, the Data Protection Act 2018, and—where applicable—Regulation (EU) 2016/679, you hold rights in relation to the personal data this practice holds about you. These include the right to be informed—which this notice fulfils—the right of access to the data held, the right to rectification of any inaccuracy, the right to erasure where the data is no longer necessary for the purpose for which it was collected, the right to restriction of processing in certain circumstances, and the right to object to processing conducted on the basis of legitimate interest. Where processing is conducted on the basis of contractual necessity—as described above in relation to advisory engagement—you also hold the right to receive the personal data you have provided to this practice in a structured, commonly used, and machine-readable format, and to transmit that data to another controller (the right to data portability). Consent is not relied upon as a lawful basis for any processing within this practice; accordingly, no right to withdraw consent arises in relation to any processing described in this notice. No automated decision-making or profiling occurs within this practice; your data is held by a person who read what you wrote, listened to what you said, and responded with the same attention with which it was received. To exercise any of these rights, or to raise a concern about the processing of your personal data, please write to croatia@serklaz.com. All data protection complaints will be acknowledged within one calendar month of receipt and investigated without undue delay, with the complainant kept informed of progress throughout. If you remain unsatisfied following the conclusion of that process, you have the right to lodge a complaint with the Information Commissioner's Office. If you are located within the European Union, you also hold the right to lodge a complaint with the data protection supervisory authority of your Member State of habitual residence—including, where that Member State is Croatia, the Croatian Personal Data Protection Agency.
Changes to this notice
This notice reflects the practice as it stands at the effective date shown above. Should the processing activities described here change in any material respect, this notice will be updated and the revised effective date shown accordingly. The governing disposition—the absence of tracking, the commitment to encrypted communication, the refusal to hold data beyond what is genuinely necessary—will not change, because it does not originate in regulation. It originates in the same place as everything else in this practice: in a formation that preceded the brand, and in the values that the brand was built to reflect.

23 Years
of Tradition