Skip to content

Privacy policy

This document explains how we process personal data on pleno-booking.com and in the Pleno application.

1.Controller and contact

The controller is MonkeyMedia d.o.o. za usluge, Cetinovec 17C, 49250 Zlatar, Croatia, OIB 67894399974. Contact for all data protection questions: hello@pleno-booking.com. We have not appointed a data protection officer because the statutory conditions are not met; if that changes, we will publish the contact.

2.Roles: controller and processor

MonkeyMedia d.o.o. is the controller for website visitor data, enquiries, user accounts, subscription and invoicing data, and platform operational and security logs. For end-client data that a business user enters or collects through Pleno (bookings, client contact details, appointment history), that business user is normally the controller and MonkeyMedia d.o.o. acts as processor on its instructions. That relationship is governed by a separate data processing agreement (DPA), which is in preparation.

3.Categories of data we process

1) Website enquiries: name, email address, business name and message content. 2) Account and identity: email, password in hashed form, user name and role. 3) Business profile and team: business name, location address, services, price list, opening hours, team members. 4) Subscription and billing: selected plan, data needed to issue an invoice, and a record of payment received. 5) Service and client data entered by the business user: client name, email, optionally phone number, appointments and notes the business user writes. 6) Support, security and logs: support message content plus technical and security logs (e.g. sign-in time, IP address, errors). 7) Transactional email delivery metadata: recipient address, send time and delivery status. 8) Cookie consent record: categories, timestamp and document version, with no personal identifier.

4.Required and optional data

Email and business details are required to create an account — without them we cannot provide the service. In the current product version, a client's email address is operationally required for appointment communication (confirmation, change, cancellation). Client notes, phone number and similar fields are optional and entered by the business user at its own responsibility. Marketing messages always require a separate, voluntary opt-in.

5.Purposes and legal bases

Answering enquiries and pre-contractual steps (Art. 6(1)(b) GDPR). Entering into and performing the Pleno contract, including account management, delivering functionality and transactional email (Art. 6(1)(b)). Issuing and retaining invoices and other legal obligations (Art. 6(1)(c)). Legitimate interests (Art. 6(1)(f)) in system security, abuse prevention, troubleshooting, basic site functionality and direct product communication with business users — we assessed that this processing does not override your rights, and you may object to it. Consent (Art. 6(1)(a)) only where genuinely required: optional cookies and marketing messages. Client data belonging to a business user is processed solely on that user's instructions as a processor (Art. 28).

6.Recipients and processors

We do not sell data. Access is limited to authorised personnel of the provider and the following verified providers: Lovable Cloud / Supabase (application hosting, database, authentication and file storage) and Resend (transactional email delivery). In addition, we may disclose data to accounting and legal advisors and to competent authorities where legally required. We do not use Stripe or any other payment processor, nor any analytics or advertising platform. An up-to-date processor list is available on request.

7.International transfers

Our infrastructure and email providers may process or store data outside the European Economic Area, or provide support from outside the EEA. In such cases we rely on the providers' documentation and the standard contractual clauses they offer. The exact list of processing locations and safeguards applied is subject to our internal verification and legal review; we do not claim that every transfer is already documented in final form.

8.Retention

We retain data by criteria rather than arbitrary fixed periods: account and business data for the duration of the contractual relationship and a reasonable period afterwards to wind the relationship down; enquiry data for as long as the conversation is live plus a reasonable period; data forming part of accounting records for as long as Croatian bookkeeping legislation requires; security logs for as long as necessary to detect and investigate incidents; business users' client data according to their instructions and until they request deletion. A precise internal deletion schedule per category is still being prepared and requires approval before publication.

9.Your rights

You have the right of access, rectification, erasure, restriction, objection to processing based on legitimate interests, data portability, and withdrawal of consent at any time without affecting the lawfulness of prior processing. Send requests to hello@pleno-booking.com. We may ask for additional information to verify your identity. We respond without undue delay and within one month at the latest, with an extension possible in complex cases. Where a business user is the controller of the data you ask about, we will forward your request to that business user.

10.Complaint to a supervisory authority

You may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, or with the supervisory authority of your habitual residence.

11.Automated decision-making and profiling

We do not carry out automated decision-making producing legal or similarly significant effects on individuals, nor profiling for that purpose. If we introduce it, we will describe the logic, significance and consequences beforehand.

12.Security

We apply reasonable technical and organisational measures: encrypted connections, role-based access control, logical separation of data per business, and restricted access to production data. We do not publish architecture details that could assist an attacker. No system is absolutely secure and we make no guarantee that incidents will not occur; we do not claim to hold security certifications.

13.Minors and business audience

Pleno is intended for business users and is not directed at children. We do not open accounts for people under 18. If a business user enters data about minor clients, that user as controller is responsible for the legal basis and any parental consent.

14.Changes to this document

We update this document when the product, providers or legal framework change. The version and date are shown at the bottom of the page, and we notify business users of material changes by email or in the application.

Contact for data questions: hello@pleno-booking.com

Version 1.0 · last updated 2026-08-17