Skip to content

Draft for legal review

Privacy policy

This document is a working draft. The final text will be published once all subprocessors, retention periods and providers are known and after review by a qualified lawyer.

1.Controller and contact

For data of visitors to this website and users of Pleno, the controller is MonkeyMedia d.o.o. za usluge, Cetinovec 17C, 49250 Zlatar, Croatia. Contact: hello@pleno-booking.com.

2.Categories of data subjects

Website visitors, Pleno business users, their team members and clients who book an appointment with a business user.

3.Data processed

Contact details you send us, business account data, appointment and service data, and technical data required to operate the website. The detailed list is being finalised alongside the implementation.

4.Purposes and legal bases

Providing the service and performing the contract, answering your enquiry, legal obligations, and legitimate interest in security and basic site functionality. Analytics and marketing only with consent.

5.Roles for salon client data

For data of clients who book appointments, the business user (salon) is the controller and MonkeyMedia d.o.o. is the processor. The relationship is governed by a separate data processing agreement (DPA).

6.Recipients and subprocessors

We use hosting and technical infrastructure providers required to run the service. The final list of subprocessors will be published before this document is finalised.

7.International transfers

If a subprocessor processes data outside the EEA, appropriate safeguards will be applied. Details will accompany the final subprocessor list.

8.Retention

We keep data for as long as it is needed for the stated purposes or required by law. Specific periods per data category will be defined before publication.

9.Your rights

You have the right to access, rectification, erasure, restriction, objection and portability, and to withdraw consent. Send requests to hello@pleno-booking.com.

10.Complaint to a supervisory authority

You may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP).

11.Automated decision-making

We currently perform no automated decision-making with legal effect. If we introduce suggestions based on usage patterns, we will describe the logic and effects beforehand.

12.Security measures

We apply reasonable technical and organisational measures, including access control and data separation per business. No measure can guarantee absolute security.

13.Changes

We update this policy as the product develops. The version date is shown at the bottom of the page.

Contact for data questions: hello@pleno-booking.com