Provider: Envoo d.o.o., company no. 6195407000, VAT no. SI45695539
Registered office: Cesta dolomitskega odreda 10c, 1000 Ljubljana, Slovenia
Contact: info@relayplan.com
2.1. Categories of personal data
- Account data: first and last name, email, company name, role, language, settings.
- Usage data: event logs, IP, device identifiers, browser type, access time, pages/screens.
- Transaction data: subscription and payment details (via Stripe; we do not store card numbers).
- Content data in the application: data on employees, hours, projects, warehouse and so on (to the extent entered by the Customer).
2.1a. Website enquiries
This section covers the form on the Contact page of relayplan.com and relayplan.si. What you enter there — first and last name, email, company, team size and the message itself — is used only to answer your enquiry.
- Legal basis: your consent (GDPR 6(1)(a)), given when you submit the form. Where the enquiry concerns a possible contract, 6(1)(b) also applies.
- Processor: the email is sent through Mailgun, so your message passes through their servers.
- Proof of consent: we store the date and time, your email address, the language of the page, the version of the consent wording you were shown, and your IP address. We keep this because we have to be able to demonstrate that consent was given, as GDPR 7(1) requires.
- Separate marketing consent: the checkbox for receiving content is optional. You can submit the form without it, and doing so makes no difference to whether or how we reply.
- Retention: enquiries and their consent records are kept until you withdraw consent, and in any case no longer than 24 months.
- Withdrawal: write to info@relayplan.com at any time. The same address covers marketing email.
2.2. Legal bases (GDPR 6(1))
- Performance of a contract (e.g. account management, access to the Service).
- Legitimate interest (e.g. improvements, security, abuse prevention).
- Consent (e.g. marketing email, non-essential cookies).
- Legal obligation (accounting and tax regulations).
2.3. Purposes of processing
- Providing and managing the Service, support, notifying you of changes.
- Billing and subscription management.
- Security: detecting and preventing abuse, backups, audit trails.
- Analytics and improvements (aggregated/anonymised where possible).
2.4. Recipients and sub-processors
- Stripe (payments).
- Hetzner (data hosting).
- Google/Gmail (email).
- Google (analytics).
The current list is in Annex A – List of sub-processors and is updated periodically.
2.5. Transfers to third countries
- Where a transfer from the EEA to third countries occurs (e.g. the USA via Stripe), appropriate safeguards are applied (e.g. SCCs / supplementary measures). Details are in the DPA.
2.6. Data retention
- Account data: for the duration of the contract and 12 months after termination (except where the law requires otherwise).
- Accounting data: 10 years in accordance with the law.
- Logs and technical records: 6 months, except in the case of incidents.
2.7. Rights of data subjects
- The right of access, rectification, erasure, restriction, objection and data portability.
- The right to withdraw consent (e.g. for marketing) without affecting the lawfulness of prior processing.
- The right to lodge a complaint with a supervisory authority: the Slovenian Information Commissioner or another competent authority in the EU.
2.8. Security
- Encryption of data in transit (TLS) and, where required, at rest.
- Logically separated tenants, RBAC, two-factor authentication (where enabled), audit trails.
- Regular backups and recovery procedures.
2.9. Children
- The Service is not intended for individuals under 16. If you learn that an account has been created without an appropriate basis, please notify us.
2.10. Contact
For questions: info@relayplan.com