Privacy notice

Which personal data we process, for what purpose and on what legal basis, and how you can exercise your rights.

Last updated:

This page explains how Mibesis d.o.o., as controller, processes the personal data of visitors to the Oglasna-Deska.Cloud website and of users of its services. We process personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, hereinafter: GDPR) and the Zakon o varstvu osebnih podatkov (ZVOP-2; Slovenian Personal Data Protection Act).

1. Controller

NameMIBESIS, družba za razvoj in informacijske storitve, d.o.o. (short name: Mibesis d.o.o.)
AddressRazlagova ulica 4, 2000 Maribor, Slovenia
Company registration number3936422000
VAT identification numberSI 75978296
Emailinfo@oglasna-deska.si
Legal representativeMiroslav Beranič, director

We are not required to designate a data protection officer, as we do not meet the conditions laid down in Article 37 GDPR. For all questions about the protection of personal data, please write to us at the email address above.

2. Scope

This notice applies to the Oglasna-Deska.Cloud website in all its language versions and to sign-in with a single account at id.oglasna-deska.cloud once it goes live. The Oglasna-Deska.SI marketplace is covered by its own privacy notice. Websites of other publishers to which we link have their own rules; we are not responsible for how they handle data.

3. What we process today

The service is under construction. Today the website has no user accounts, forms, analytics or cookies. We process personal data only in the server logs and when you write to us by email.

Server logs

With every visit, the server automatically records the IP address, the date and time of the request, the requested address, the response code, the browser identifier (user agent) and the address of the page you came from, if your browser sends it. We use these records for the secure and reliable operation of the website: to detect attacks, abuse and errors. We do not use them to build profiles of visitors.

Email

If you write to us, we process your email address, your name if you give it, the content of your message including attachments, and the time it was sent. We need these data in order to reply to you and deal with the matter.

Launch notification

If you ask us to notify you, using the ‘Notify me at launch’ button or a message of your own, we use your email address only to let you know when the service becomes available. We do not use the address for any other messages and we do not pass it on to anyone.

What we do not process today

  • The website does not set cookies and does not use analytics tools.
  • The website does not load anything from the servers of other providers: fonts, images and scripts are on our own server, and there are no social media plug-ins.
  • Choices that you save in your browser's local storage (colour scheme, paused animation) remain in your browser, and we do not receive them. Details are given on the Cookies and local storage page.

4. Once sign-in and the apps go live

Once the functions listed below go live, we will also process the following data. Before that happens, we will supplement this notice with any further details.

  • User account data: email address, first name and surname or a display name, a hash of the password or passkey data, and optional data that you enter yourself, for example a telephone number.
  • Sign-in security records: the time of sign-in, the IP address, whether the sign-in succeeded or failed, and the account identifier, so that we can detect unauthorised access and password-guessing attempts.
  • App content: emails with attachments, calendar events, contacts, notes, notebooks, photos and files that you create, upload or receive. Photos may contain metadata, for example the time and place a photo was taken and the device model; the location is visible only to you until you share the photo. This content is private: it is seen by you and by the people you choose to share it with. We do not examine it and we do not use it for any other purpose.
  • Settings: language, layout, start screen and notifications.
  • User support: the content of your question, your email address and any attachments.

5. Purposes and legal bases

Today

PurposeDataLegal basis
Secure and reliable operation of the websiteServer logsLegitimate interest (Article 6(1)(f) GDPR): protection against attacks and abuse, and fixing errors
Replying to your messagesEmail address, name, content of the messageLegitimate interest (Article 6(1)(f)); where the message concerns entering into a contract with us, steps taken at your request prior to entering into a contract (Article 6(1)(b))
Launch notificationEmail addressConsent (Article 6(1)(a)), which you give by requesting the notification and which you may withdraw at any time
Compliance with legal obligationsData required by law or by a decision of a competent authorityLegal obligation (Article 6(1)(c))
Establishment, exercise and defence of legal claimsData needed in the individual caseLegitimate interest (Article 6(1)(f))

Once sign-in and the apps go live

PurposeDataLegal basis
Managing the user account and sign-inAccount dataPerformance of a contract (Article 6(1)(b))
Protecting accounts against unauthorised accessSign-in security recordsLegitimate interest (Article 6(1)(f))
Operation of the apps (email, calendar, contacts, notes, notebooks, photos, files)App content, settingsPerformance of a contract (Article 6(1)(b))
User supportQuestion, email address, attachmentsPerformance of a contract (Article 6(1)(b)) or legitimate interest (Article 6(1)(f))
Paid services and accountingData for issuing invoicesPerformance of a contract (Article 6(1)(b)) and legal obligation (Article 6(1)(c))

Where processing is based on consent, you may withdraw your consent at any time; the withdrawal does not affect the lawfulness of processing before it (Article 7(3) GDPR). You do not need to provide any data in order to visit the website; the logs are created automatically.

6. Recipients

  • Processors: the website and the services run on servers that we rent from the hosting provider Hetzner Online GmbH in Germany. The provider processes data only on our instructions and on the basis of a contract under Article 28 GDPR.
  • People you share content with: once the apps are working, messages will be seen by their recipients, and shared events, photos and files by the people you share them with.
  • Watches: the watch apps will receive data (your next meeting, to-dos, notifications) through your phone and the same account. The transfer between your phone and your watch is also subject to the watch manufacturer's rules.
  • Competent authorities: we disclose data to them only where required by law or by a decision of a competent authority.
  • Legal advisers: where this is necessary for the establishment, exercise or defence of legal claims; they are bound by confidentiality.

We do not sell personal data, and we do not disclose it to third parties for their marketing.

7. Transfers outside the European Economic Area

We process data in the European Economic Area. We do not carry out, and do not plan, any transfers to third countries. Should a transfer ever become necessary, we would carry it out only under the conditions laid down in Chapter V GDPR, and we would amend this notice accordingly beforehand.

8. Retention periods

DataRetention period
Server logsNo more than 12 months
Email correspondenceNo more than 2 years after the matter is closed
Email address for the launch notificationUntil the notification has been sent or until you withdraw your request; we then delete it
Choices in the browser's local storageIn your browser until you revoke the choice or delete the data; we do not receive them
User account dataUntil the account is deleted; after a request for deletion, we delete them within 30 days at the latest
Sign-in security records180 days
App contentUntil you delete it yourself or until the account is deleted
Accounting documentsUntil the end of the period laid down by law

When the period expires, we delete the data or irreversibly anonymise them. We keep them longer only where this is necessary for the establishment, exercise or defence of legal claims or where the law so requires.

9. Security

  • Traffic between your browser and our servers is encrypted with the HTTPS protocol (TLS); we instruct your browser always to open the site over an encrypted connection (HSTS).
  • The website does not load resources from other providers; a strict Content Security Policy (CSP) prevents third-party scripts from running.
  • Access to the production systems is restricted to authorised persons.
  • The sign-in service will store passwords exclusively as a salted hash, from which the password cannot be derived; the apps never see your password.
  • We follow the principles of data minimisation and of data protection by design and by default.

We notify a personal data breach to the Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia) no later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights of individuals. Where the breach is likely to result in a high risk to your rights and freedoms, we also inform you without undue delay.

10. Your rights

You have the right:

  • of access to your personal data (Article 15 GDPR);
  • to rectification of inaccurate data (Article 16);
  • to erasure (Article 17);
  • to restriction of processing (Article 18);
  • to data portability in a structured, machine-readable format, where the processing is based on a contract or on consent (Article 20);
  • to object to processing based on legitimate interest (Article 21);
  • not to be subject to a decision based solely on automated processing (Article 22);
  • to withdraw your consent at any time (Article 7(3)).

11. How to exercise your rights

Send your request to info@oglasna-deska.si. We will reply within one month of receipt at the latest. In complex cases, this period may be extended by up to two further months; we will inform you of this within the first month. Handling the request is free of charge. Where we cannot reliably establish that the request comes from you, we may ask for additional information to confirm your identity.

12. Complaint to the supervisory authority

If you believe that we are processing your data in breach of the law, you can lodge a complaint with the supervisory authority:

Informacijski pooblaščenec Republike Slovenije (Information Commissioner of the Republic of Slovenia)

Dunajska cesta 22, 1000 Ljubljana
Email: gp.ip@ip-rs.si
Telephone: +386 1 230 97 30
Website: www.ip-rs.si

You can also lodge a complaint with the supervisory authority of the Member State of the European Union in which you live or work, or in which the alleged infringement took place (Article 77 GDPR).

13. Children

The service is not intended for children under the age of 16. We will not open user accounts for persons under the age of 16. If we find that we have processed a child's data without an appropriate legal basis, we delete them without delay. If you believe that a child has provided us with personal data, please write to us at info@oglasna-deska.si.

14. Profiling and automated decision-making

  • The website does not contain third-party advertising networks and does not use advertising identifiers.
  • We do not use your data to build profiles for marketing purposes.
  • We do not take decisions based solely on automated processing that would produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).

15. Cookies and local storage

The website does not set cookies. What it stores in your browser's local storage and why is described on the Cookies and local storage page.

16. Changes to this notice

We will update this notice when new functions go live and when the law or our practice changes. The version in force is always published on this page together with the date of the last change. Once user accounts are in operation, we will also inform users of significant changes by email.