Draft for legal review
Privacy policy
This document is a working draft. The final text will be published once all subprocessors, retention periods and providers are known and after review by a qualified lawyer.
1.Controller and contact
For data of visitors to this website and users of Pleno, the controller is MonkeyMedia d.o.o. za usluge, Cetinovec 17C, 49250 Zlatar, Croatia. Contact: hello@pleno-booking.com.
2.Categories of data subjects
Website visitors, Pleno business users, their team members and clients who book an appointment with a business user.
3.Data processed
Contact details you send us, business account data, appointment and service data, and technical data required to operate the website. The detailed list is being finalised alongside the implementation.
4.Purposes and legal bases
Providing the service and performing the contract, answering your enquiry, legal obligations, and legitimate interest in security and basic site functionality. Analytics and marketing only with consent.
5.Roles for salon client data
For data of clients who book appointments, the business user (salon) is the controller and MonkeyMedia d.o.o. is the processor. The relationship is governed by a separate data processing agreement (DPA).
6.Recipients and subprocessors
We use hosting and technical infrastructure providers required to run the service. The final list of subprocessors will be published before this document is finalised.
7.International transfers
If a subprocessor processes data outside the EEA, appropriate safeguards will be applied. Details will accompany the final subprocessor list.
8.Retention
We keep data for as long as it is needed for the stated purposes or required by law. Specific periods per data category will be defined before publication.
9.Your rights
You have the right to access, rectification, erasure, restriction, objection and portability, and to withdraw consent. Send requests to hello@pleno-booking.com.
10.Complaint to a supervisory authority
You may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP).
11.Automated decision-making
We currently perform no automated decision-making with legal effect. If we introduce suggestions based on usage patterns, we will describe the logic and effects beforehand.
12.Security measures
We apply reasonable technical and organisational measures, including access control and data separation per business. No measure can guarantee absolute security.
13.Changes
We update this policy as the product develops. The version date is shown at the bottom of the page.
Contact for data questions: hello@pleno-booking.com