Privacy policy

This policy explains what personal data we process in providing Terenska naročila, why we process it, and what rights you have in relation to it.

Last updated: 31 July 2026

1. Who the controller is

The controller is Nejc Gergič s.p., Adamičeva 52D, 2000 Maribor, Slovenia, registration number 9857125000, tax number 16853628. For any data protection question, reach us at info@terenskanarocila.si.

We have not appointed a data protection officer, as we do not meet the criteria in Article 37 of the General Data Protection Regulation (GDPR).

2. Two different roles

We act in two roles, and the distinction matters:

  • As a controller we process data about you as our customer and about your users: user accounts, sign-ins, subscription invoices, enquiries and support. That is what this policy covers.
  • As a processor we process the data you enter into the app: your customers, their contact people, orders and notes. We never use it for our own purposes; we process it solely on your instructions. That is governed by the Data Processing Agreement.

If you are a contact person at a customer of one of our subscribers and want to know why your data is in the app, please contact that company directly, as they are the controller of that data. We are glad to help you get in touch.

3. What we process as a controller

PurposeDataLegal basisRetention
User account and access to the serviceemail address, first and last name, profile picture (optional), role, organizationperformance of a contract (Art. 6(1)(b) GDPR)duration of the subscription plus 90 days
Sign-in and securityemail address, one-time sign-in codes, sign-in time, IP address and device detailsperformance of a contract and legitimate interest in preventing abuse (Art. 6(1)(b) and (f))up to 12 months
Subscription, invoicing and accountingcompany name and address, tax number, contact person, amount and date of paymentlegal obligation (Art. 6(1)(c)); Slovenian tax and companies legislation10 years from the invoice date
Answering a Custom plan enquirycompany, name, email, phone, number of reps, system in use, messagepre-contractual steps at your request (Art. 6(1)(b))12 months from last contact
User supportthe content of your messages and our correspondencelegitimate interest in providing support (Art. 6(1)(f))24 months
Website audience measurementaggregated page visit data, with no cookies and no visitor identifierlegitimate interest in understanding site usage (Art. 6(1)(f))aggregated, not linked to an individual

Providing the data is not mandatory, but without an email address and an organization name an account cannot be created and we cannot provide the service.

4. The data you enter into the app

The content you enter into the app (your customers, their contacts, orders, notes, price list and images) is yours. We use it only to run the service, keep it secure and maintain backups. We do not sell it, do not use it for advertising, and do not use it to train artificial intelligence models.

5. Who receives the data

We do not sell personal data. We share it only with the processors we need to run the service, and only to the extent necessary:

RecipientPurposeProcessing location
Supabase, Inc.database, user authentication, file storageFrankfurt, Germany (EU)
Vercel, Inc.application hosting and audience measurementFrankfurt, Germany (EU)
Resend (Plus Five Five, Inc.)sending sign-in codes and notification emailsEU and USA
Google Ireland Ltd.Google sign-in (only if you use that option)EU

We may also disclose data to our accountant for invoicing, and to public authorities where required by law.

6. Transfers outside the EU

The database and the application are in the European Union. Some of our providers are US-based companies, so access from outside the EEA may occur during support or maintenance. Where it does, the transfer relies on the European Commission's Standard Contractual Clauses or the EU-US Data Privacy Framework, together with additional technical measures such as encryption.

7. Security

  • All traffic is encrypted (HTTPS/TLS) and database data is also encrypted at rest.
  • Sign-in is passwordless, using a one-time code valid for one hour, so there is no password to steal or reuse.
  • Data is separated between organizations at the database level (row-level security); a user cannot reach another organization's data even if they try.
  • Our staff access to production data is limited to the minimum necessary.
  • Backups are created automatically and stored within the EU.

8. Automated decision-making

We do not carry out automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.

9. Your rights

In relation to your personal data you have the right to:

  • access the data and receive a copy of it,
  • have inaccurate data corrected and incomplete data completed,
  • erasure (the "right to be forgotten") where there is no longer a basis for processing,
  • restriction of processing,
  • data portability in a machine-readable format,
  • object to processing based on legitimate interest,
  • withdraw consent where processing is based on consent; withdrawal does not affect the lawfulness of processing before it.

Send your request to info@terenskanarocila.si. We respond within one month at the latest. For security we may ask you to confirm your identity.

10. Complaint to the supervisory authority

If you believe we process your data unlawfully, you may lodge a complaint with the Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, 1000 Ljubljana, email gp.ip@ip-rs.si, phone +386 1 230 97 30. We would appreciate the chance to sort it out with you first, as most things can be resolved quickly.

11. Cookies

We use strictly necessary cookies only, which is why there is no consent banner. Details are on the Cookies page.

12. Changes to this policy

We may update this policy. The current version is always published on this page, with the date of the last update at the top. We notify customers by email of material changes.