Visionect d.o.o. (hereinafter referred to as “we”, “us”, “our”, “Visionect”,) respects your privacy and is committed to protecting your personal data.

This Privacy and Cookie Policy (including any modifications, hereinafter referred to as the: “privacy policy”) will tell you how we look after and process your personal data, whether you visit our Visionect (www.visionect.com) or Joan (www.getjoan.com) website (hereinafter referred to as the “website”), regardless of where you visit it from, and/or purchase and/or use any of our products, services and/or applications. The term “products, services and/or applications” refers to all our products and services specified on the website, including but not limited to Visionect’s software and hardware products, mobile applications and services. 

About the terms of usage/sale of our products and/or services please read more in Terms of Use, Terms of Sale or other specific Terms as outlined in the footer of the website).

Because we are fully devoted to protecting our confidential and sensitive data, including in particular any personal data processed in connection with our commercial activities, this Privacy policy aims to resolve any concerns you might have in this regard when using our website and/or products and services.

Nevertheless, if after reading this privacy policy, you have any additional questions about the processing of your personal data, including any requests to exercise your legal rights, please do not hesitate to contact us at [email protected].

WHO ARE WE AND WHAT DO WE DO?

Visionect d.o.o., Tržaška cesta 118, 1000 Ljubljana, Slovenia is a B2B company founded in 2007. Visionect is the premier designer and developer of ultra-low-power digital display solutions created on electronic paper technology.

Visionect’s mission is to empower people in public spaces to make better decisions by delivering more relevant, timely information, supported by digital displays easily installed in locations impossible before. The company is known for its Joan room scheduling devices and workplace solutions and the Place & Play product line.

The purpose of this privacy policy is to provide you with information on which, why and how we collect and process your personal data, including but not limited to any data you may provide through this website, when you:

  • sign up to our newsletter (and download any resource or content from the website),
  • purchase and/or distribute a product and/or service,
  • contact us by filling up the contact form,
  • do other corresponding activities.

It is important that you read this privacy policy together with any other terms and conditions available on the website and/or any notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using it.

Visionect acts as controller for website, account, billing, marketing, security and support processing; for certain Workplace management services data processed on behalf of business customers, Visionect acts as processor under the applicable DPA, while the customer remains responsible for providing employee/visitor notices where required.

WHICH DATA OF YOURS DO WE PROCESS?

Personal data, or personal information, means any information about an individual from which that person can be identified It does not include data where the identity has been removed and by which we (or any other person) are not able to identify specific individuals (anonymous data).

We may collect, use, store and transfer different kinds of personal and/or other related data about you (hereinafter together referred to as the: “data”) which we have grouped together as follows:

  • Identity Data includes your first and last name and/or similar identifier;
  • Contact Data includes your billing address, delivery address, e-mail address, and telephone numbers;
  • Financial Data includes your bank account details; We do not collect your credit cards and/or PAYPAL information, as these services are ensured by third parties to which you provide the information voluntarily;
  • Transaction Data includes details about payments to and from you and other details of products and services you have purchased from us;
  • Technical Data includes internet protocol (IP) address, browser type, and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the website.
  • Usage Data includes information about how you use our website, products, and services.
  • Calendar User Data as specified in the following below.
  • Workplace Management Data  includes information about your use of our workplace management services, including room booking, desk booking, visitor management and related workplace actions, such as booking details, attendee or employee details, visitor details, visit information, check-in or check-out information and documents signed through the service.
  • Joan AI Input/Output Data includes the messages, prompts, instructions and other content you provide to Joan AI, together with the responses, suggestions and other content generated by Joan AI.
  • Platform Identity Data includes information that identifies your workspace, team, account or user profile on connected platforms or in your linked Joan account, such as workspace or team identifiers, user identifiers, email address, profile information and timezone.
  • Conversation Context Data includes information that helps Joan AI understand and continue a conversation, such as conversation, channel, thread or event identifiers, timestamps and relevant interaction context.
  • Authentication and Account Linking Data includes information used to authenticate you and connect your Joan account with other services, such as OAuth or linking tokens, access tokens, refresh or workspace tokens and linked account identifiers.
  • Approval and Audit Data includes records of approvals, decisions and actions taken through Joan AI or related workplace services, such as approval status, deciding user, requested action, execution result, errors and timestamps.
  • Event Receipt Data includes records showing the receipt, processing, delivery status or failure of events, requests or actions within the service, such as event identifiers, processing status, timestamps and error messages.
  • Long-term User Memory Data includes preferences, facts and contextual details derived from your interactions with Joan AI and retained to provide more personalized and continuous responses in future interactions.
  • Security and Logging Data includes technical logs, metadata and service records used for security, troubleshooting, audit, logging and maintaining the integrity and reliability of the service.

In order to maximize your user experience, we also collect, process, and use Aggregated Data that may be derived from your personal data but is, according to the law, not considered to be personal data as it does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. We also measure website tracking (traffic information, for example). However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will is then used in accordance with this privacy policy.

We do not collect or otherwise process any so-called “special categories of personal data”, which include details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data, except as described in the Joan AI section. Nor do we collect any information about criminal convictions and offenses.

Also, the website is not intended to be used by children or minors (person under 18) and we do not knowingly collect data relating to children or minors.

HOW IS YOUR DATA COLLECTED?

We use different methods to collect data from and about you including through:

Direct interactions. You may provide us your Identity, Contact and Financial Data by:

  • filling-in contact forms or by contacting us and/or corresponding with us by e-mail, phone, or otherwise,
  • purchasing our products or services;
  • creating an account to use our products or services by creating a user account in the “Joan Portal”;
  • subscribing to our newsletter;
  • requesting marketing material to be sent to you;
  • entering a prize competition, promotion, referral program, or survey;

Automated technologies or interactions. As you interact with our website, we may automatically collect Technical Data and/or Aggregated Data about your equipment, browsing actions, and patterns. We collect this data by using cookies and other similar technologies as explained below in the “Cookies” section.

We may obtain data from connected third-party platforms (such as Microsoft Teams or Slack) and from the user’s linked Joan account.

IN WHICH CASES WILL WE NEED TO USE SOME OF YOUR USER CALENDAR DATA?

To facilitate the use of our room scheduling solution product called »Joan« (hereinafter referred to as “Joan”) for users of Google Workplace, Office 365, Microsoft Exchange, and iCalendar, we will require certain permissions in your calendar account:

  • Read and/or write access to the calendars you wish Joan to manage. 
  • Certain summarized calendar or event information (such as first and last name, e-mail of organizer and attendees, meeting duration, confirmation of meeting, meeting room etc.) if you are subscribed to Joan Enterprise subscription plan (those information are needed for proper function of Advanced Analytics feature – read more in Terms of Use).
  • In case you are subscribed to any other Joan subscription plan, no calendar or event information is permanently stored on the servers we are using, unless specifically stated otherwise. The Joan Portal (used for managing Joan – read more in Terms of Use) only stores the e-mail of the room’s resource, all other information is gained through an API call, parsed, and sent directly to the device.
  • Access to basic user account information and email.
  • Read-only access to your resources to enable automatic room resource scan.
  • When using the Room Booking feature, calendar data from users is synchronized and stored in accordance with the policy outlined in the section “Room Booking – Data Collection and Retention”.

Native calendar data is not shared with third parties for other purposes; however, when using Joan AI, certain data is processed through selected providers/integrations.

WORKPLACE MANAGEMENT SERVICES (INCLUDING ROOM BOOKING, DESK BOOKING, VISITOR MANAGEMENT AND JOAN AI)

To enable the functionality of Workplace management services offered through the MyJoan platform, including Room Booking, Desk Booking, Visitor Management and Joan AI, we collect and process certain user-, event- and service-related data as described below. Joan AI is a conversational interface that enables users to access and use existing Joan services through natural language interactions. Unless expressly stated otherwise, the same categories of data, purposes of processing and retention rules applicable to Workplace Management Services also apply when those services are accessed through Joan AI.

How is your data collected

You provide us with your data by interacting with Workplace management services.

Lawful basis for processing:

Performance of a contract – order.

Legitimate interest for security/audit/logging.

Types of data collected

Room Booking data:

  • Title
  • Summary
  • Start and end time
  • Status
  • Visibility
  • Conference link
  • All-day indicator

Attendee data:

  • Email address
  • Full name
  • Participation status

Desk booking data:

  • Desk identifier.
  • Desk location.
  • Reservation start and end time.
  • Employee details for whom the desk is reserved.
  • Information if the desk reservation was confirmed/checked-in.

Visitor management data:

  • Visitor details (first name, last name, e-mail, phone number).
  • Host /employee details.
  • Date, time, and location of a visit.
  • Has the visitor checked in and when.
  • Has the visitor checked-out and when.
  • Any documents that visitor signs via our solution. 

Additional data processed when using Joan AI

When users interact with Workplace management services through Joan AI, additional data is processed to enable natural language interactions and personalized responses.

Additional categories of data:

  • Workspace / Team identity
  • User identity
  • Message text and prompts
  • AI-generated responses
  • Conversation context
  • OAuth / linking tokens
  • Approval records
  • Event receipts
  • Long-term user memory

Purposes of processing

In addition to the purposes described above for Workplace management services, Joan AI processes the additional categories of data listed above in order to:

  • provide you with the conversational workplace assistant (understanding the request and generating a response).
  • For account linking and authentication (OAuth).
  • For personalisation / continuity via long-term user memory.
  • To perform workplace actions (booking/cancelling desks, rooms, assets; visitor invites; announcements) via the linked Joan account.
  • For security, audit and integrity (approval records, event receipts, logging).

Recipients and integrations for Joan AI

For list of our sub-processors, refer to DPA Annex number 2.

Data synchronization policy

Calendar events from room calendars are synchronized with our internal database for a rolling window of three months into the future. Events beyond this window are not synchronized automatically. Where a user of MyJoan services initiates a calendar action outside this timeframe, synchronization will be performed on demand at that time.

Data retention policy

  • Data processed in connection with Workplace Management Services is retained only for as long as necessary to provide the services and perform related analytics and in any event no longer than 12 months after the end of service use, unless a different retention period is required by law or expressly stated below.
  • When using Joan AI service, data is retained only for as long as necessary to provide the Joan AI service and in any case no longer than 30 days after the end of the Joan AI service use. 
  • Users can request deletion of their data, processed in connection with Workplace Management Services at any time by contacting our support team at [email protected].
  • In the future, users will be able to manage deletion directly within the MyJoan portal.
  • Once a deletion request is processed:
    • all existing room booking entries for the user will be removed from the operational database,
    • upcoming events will be re-synced according to the active synchronization policy.
  • Analytics data is not deleted automatically but can be removed manually by authorized personnel upon user request.
  • Certain Joan AI-specific data, including conversation history, long-term memory, approval records and event receipts, may be retained for the duration of the user’s use of Joan AI in order to provide continuity and personalization across sessions. Such data is deleted upon disconnection or removal of the Joan AI service, unless a longer retention period is required by law.
  • Visionect does not use Input/Output Data for automated decision-making producing legal effects or similarly significant effects on individuals.
  • Prompts, instructions, responses or other input or output data generated, submitted or otherwise processed by or on behalf of a user in connection with the Joan AI service (“Input/Output Data”) are not used for the purposes of training, improving or otherwise developing any artificial intelligence models, systems or services. Visionect shall not use the Input/Output Data for automated decision-making, profiling, scoring or similar automated assessment of users or other individuals within the meaning of applicable data protection laws.
  • Notwithstanding the foregoing, the Input/Output Data may be processed for the purpose of providing user-specific personalization through long-term memory functionality in order to generate more contextual, relevant and user-tailored responses. Such personalization may constitute profiling within the meaning of applicable data protection laws. However, such profiling is used solely to improve the relevance and continuity of user interactions and is not used to make decisions producing legal or similarly significant effects on individuals.
  • Joan AI is not intended for the collection or processing of special categories of personal data and users are requested not to submit such information. However, if users voluntarily include such information in prompts or other content submitted to Joan AI, such information may be processed solely for the purpose of providing the requested service.

WHY WILL WE USE OR OTHERWISE PROCESS YOUR DATA?

We have set out below, in a table format, a description of all the ways we plan to use your data, including personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate. Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us at [email protected] if you need more detail.

Purpose/ActivityType of dataLawful basis for processing including basis of legitimate interest
To register you as a new customer (creating an account on Joan portal) and provide supported services, including updates, etc. by e-mailIdentityContactPerformance of a contract – order (executed purchase of product/service)  concluded with you;
To process and deliver your order including:Manage payments, fees, and chargesDelivery of products and services purchased/requestedCollect and recover money owed to usIdentityContactFinancialTransactionPerformance of a contract (executed purchase of product/service) with you;Necessary for our legitimate interests (to recover debts due to us);
To manage our relationship with you which will include:To provide you with e-mail news, updates, etc. on our products and services (in case of newsletter subscription, etc.)Asking you to leave a review, let us know your customer experience, etc. after you made the purchase of products and services;To deliver you information about its own similar products or services already purchased;IdentityContactPerformance of a contract (executed purchase of product/service) with you;Necessary to comply with a legal obligation;Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services):
To administer and protect our business and this website and products and services (including troubleshooting, data analysis, testing, system maintenance, support, reporting, and hosting of data);IdentityContactTechnicalNecessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganization or group restructuring exercise)Necessary to comply with legal obligations (reporting of breaches);
To use data analytics to improve our website, products, and services, marketing, customer relationships, and experiences;TechnicalUsageNecessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business, and to inform our marketing strategy);
To provide Workplace management services, including Room booking, Desk booking and Visitor ManagementIdentity Data, Contact Data, Calendar User Data, Workplace Management Data, including room booking data, attendee data, desk booking data, visitor details, host/employee details, visit date/time/location, check-in/check-out data and documents signed through the solution.Performance of a contract.
To synchronise calendars and manage room/resource availability.Calendar User Data, including read/write calendar permissions, room/resource calendar email, basic account information and email, summarized calendar/event information such as organiser/attendee names and email addresses, meeting duration, confirmation status and meeting room.Performance of a contract.
To provide Joan AI as a conversational workplace assistant.Joan AI Input/Output Data, Platform Identity Data, Conversation Context Data, including workspace/team ID and name, source-platform user ID, email, profile information, timezone, message text/prompts, AI-generated responses, channel/thread/conversation/event IDs and timestamps.Performance of a contract.
To link and authenticate user accounts for Joan AI.Authentication and Account Linking Data, including OAuth/linking tokens, access tokens, refresh/workspace tokens, linked Joan account identifiers and source-platform user identity.Performance of a contract.
To perform workplace actions requested through Joan AI.Workplace Management Data acted on, Action Request Data, Joan Account Data, including desk/room/asset bookings, visitor invitations, announcements and relevant booking/visitor/resource data used to execute the user’s request.Performance of a contract.
To record approvals and maintain audiability of Joan AI actions.Approval and Audit Data, including exact tool name, tool arguments, requester context, approval status, deciding user, execution result/error and timestamps.Performance of a contract.
To process event receipts and maintain service integrity.Event Receipt Data, including event ID, processing status, team/channel/thread/event timestamps and error messages.Performance of a contract.
To provide personalisation and continuity through long-term user memory.Long-term User Memory Data, including derived memories from prompts and AI responses, user preferences/facts derived from interactions, and user email used to scope memory.Performance of a contract.
Legitimate interest.
To maintain security, troubleshooting, logging and service integrity.Technical Data, Usage Data, Security and Logging Data, including active thread metadata, approval records, event receipts, Google Cloud Logging data and Pub/Sub in-transit payloads where applicable.Performance of a contract.
Legitimate interest.
To analyse and improve our website, products and services.Technical Data, Usage Data, Aggregated Data, and only where actually used, personal data from interaction histories/evaluation outputs.Legitimate interest.

In order for you to use our website and products, we need to process some of your Data. Should we need to process your Data for any other purpose than offering you our services, we will always ask you for your consent in advance.

DO WE USE COOKIES?

Cookies are small text files placed on your hard drive. We use cookies or similar technologies (pixels etc.) to personalize your online experience and improve our services for you. For example, cookies will remember and process the items in your shopping cart on our website. This saves you time since you are not required to re-enter the same information each time you visit our site.

We use the following cookies:

  • Strictly necessary (essential) cookies. These cookies are required for the operation of our website. They include, for example, the use of a shopping cart or e-billing services.
  • Analytical/performance cookies. They allow us to recognize and count the number of visitors and to see how visitors move around our website when they are using it. This helps us to improve the way our website works, for example, by ensuring that users find what they are looking for easily.
  • Functionality cookies. These are used to recognize you when you return to our website. This enables us to personalize our content for you, greet you by name, and remember your preferences (for example, your choice of language or region).
  • Advertising (Targeting) cookies. These cookies record your visit to our website, the pages you have visited, and the links you have followed. We will use this information to make our website and the advertising displayed on it more relevant to your interests. We may also share this information with third parties for this purpose.

Some of the cookies we use are internal, some of the external (third-party) cookies. You can find more about the individual cookies we use here:

Necessary cookiesCategoryDescriptionCookie
HubspotThis cookie is used by the opt-in privacy policy to remember not to ask the visitor to accept cookies again.__hs_opt_out
This cookie can be set to prevent the tracking code from sending any information to HubSpot.__hs_do_not_track
This cookie is used to prevent the banner from always displaying when visitors are browsing in strict mode.__hs_initial_opt_in
This cookie is used to record the categories a visitor consented to.__hs_cookie_cat_pref
This cookie is used to consistently serve visitors the same version of an A/B test page they’ve seen before.hs_ab_test
When visiting a password-protected page, this cookie is set so future visits to the page from the same browser do not require login again.<id>_key
This cookie is used to determine and save whether the chat widget is open for future visits.hs-messages-is-open
This cookie is used to prevent the chat widget welcome message from appearing again for one day after it is dismissed.hs-messages-hide-welcome-message
This cookie is set when visitors log in to a HubSpot-hosted site.__hsmem
This cookie is used to ensure that content membership logins cannot be forged.hs-membership-csrf
This cookie is used to save the visitor’s selected language choice when viewing pages in multiple languages.hs_langswitcher_choice
This cookie is set by HubSpot’s CDN provider because of their rate-limiting policies.__cfruid
Essential cookiesCategoryDescriptionCookie
CloudflareUsed to identify individual clients behind a shared IP address and apply security settings on a per-client basis.__cfduid
VisionectUsed to display different content to users in different countries.cbc_country_name
cbc_country_code
Analytical cookiesCategoryDescriptionCookie
GoogleUsed to distinguish users across browsing sessions for Google Analytics, but cannot identify unique users across different browsers or devices. Has an expiration of 2 years._ga
Used to distinguish users and has an expiration of 24 hours._gid
Used to throttle requests and has an expiration of 10 minutes._gat
HotjarUsed to let Hotjar know whether that visitor is included in the sample which is used to generate funnels._hjIncludedInSample
LinkedInUsed for LinkedIn Ad analytics.BizoID
lang
UserMatchHistory
lidc
bcookie
bscookie
TwitterUsed for Twitter integration and sharing capabilities for social media.personalization_id
HubspotThis cookie is used for tracking visitors.__hstc
This cookie keeps track of a visitor’s identity.hubspotutk
This cookie keeps track of sessions.__hssc
This cookie is set to determine if the visitor has restarted their browser.__hssrc
Functionality cookiesCategoryDescriptionCookie
ZopimUsed to talk to customers in real-time.AWSALB
__zlcmid
SpiceworksUsed to automatically discover detailed device information to troubleshoot user issues.visid_incap_1145931
incap_ses_879_1145931
_swnid
_swauth
Advertising cookiesCategoryDescriptionCookie
FacebookUsed to track opted-out Facebook users for advertising purposes.fr

Visionect has listed them so you can decide whether you would like to opt out or not. You can set your browser to refuse all or some browser cookies or to alert you when websites set or access cookies. If you disable or refuse cookies (especially essential cookies), please note that some parts of this website may become inaccessible or not function properly.

HOW CAN YOU UPDATE, REMOVE OR EXERCISE OTHER RIGHTS WITH REGARDS TO YOUR PERSONAL DATA?

You can update, remove and/or exercise other rights related to your personal data (as specified in detail below) at any time by contacting us at [email protected] We will respond as soon as we can and will follow up on your request within 14 days at most.

Also, if you do not like to receive our newsletter or other content e-mail, including updates or marketing material e-mails, you may at any time unsubscribe any time with the “unsubscribe” link within any e-mail you receive from us. We will be sad to see you go, but we respect your privacy.

The rights you may exercise with regards to your personal data:

  • Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
  • Request correction – update of your personal data. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
  • Request erasure – deletion of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us to continue to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law.
  • Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes (as mentioned you will also get an option to stop such e-mail contacting in each e-mail we will send it to you). In some cases, we may demonstrate that we have compelling legitimate grounds to process your information, which override your rights and freedoms.
  • Request restriction of processing your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data’s accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it
  • Request transfer of your personal data. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
  • Right to lodge a complaint with a supervisory authority. If you believe that our processing of your personal data infringes applicable data protection laws, you have the right to lodge a complaint with a supervisory authority. In Slovenia, the competent supervisory authority is the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec), Dunajska cesta 22, SI-1000 Ljubljana, Slovenia, phone: +386 1 230 97 30, e-mail: [email protected], website: www.ip-rs.si. You may also lodge a complaint with another competent supervisory authority in the EU/EEA, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement. We would appreciate the opportunity to address your concerns first, and you may contact us at [email protected]; however, contacting us is not a precondition for lodging a complaint with a supervisory authority.

Please keep in mind that certain personal data:

  • we are required to process for a certain period according to applicable legislation (for example due to accounting reasons),
  • we may be required to process in order to provide you with our products and services. We will properly inform you if this is the case after we receive your request.

Any requests to exercise Your rights can be directed to us through the contact details provided in this Privacy Policy. These requests can be exercised free of charge and will be addressed by us as early as possible and always within 14 days.

HOW DO WE PROCESS YOUR PERSONAL DATA?

We would never sell, share, or otherwise unlawfully use your personal data by disclosing them to any third party controller unless you provide us with your explicit consent as required by law, or we have a legal basis and/or obligation to do so.

Your personal data (and other data as well) is processed by our highly qualified employees and internal subcontractors that are required to execute confidentiality and must at all times comply with our personal and confidential information policy. We ensure they are provided with proper data security training during the onboarding process.  Each of them receives an account (secured by a strong password) which allows them to access the corporate e-mailing system, other software systems, and selected databases.

We also use external subcontractors, third-party service providers (data processors), for processing your personal data (for example e-cloud hosting services for storage, etc.). The ones established in the EU operate in compliance with GDPR. Nevertheless, many of our external third parties’ service providers are based outside the European Economic Area (EEA) so their processing of your personal data involves a transfer of data outside the EEA. Whenever this happens, we enforce a similar degree of protection by ensuring at least one of the following safeguards is implemented:

  • your personal data is processed by third-party service providers (data processors) established and operating in countries that have been deemed to provide an adequate level of protection for personal data by the European Commission;
  • your personal data is processed by third-party service providers (data processors) with which we have specific contracts approved by the European Commission which give personal data the same protection it has in Europe.

Nevertheless, this website or web platform for use of our products and services may include links to third-party websites, plug-ins, and applications (for example, PAYPAL and/or credit card payment service providers, etc.). Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party data processing activities and are not responsible for their privacy policies.

HOW LONG WILL YOU USE OR OTHERWISE PROCESS MY PERSONAL DATA?

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data, and whether we can achieve those purposes through other means, and the applicable legal requirements.

Upon user request, the data will be deleted from the operational database even before that and the analytical data will be deleted manually if the user explicitly requests it.

HOW DO WE SECURE YOUR PERSONAL DATA?

We take the security of your personal data (and your other data) very seriously.

We store the majority of our data using e-cloud based solutions. Numerous studies have established that data stored in the cloud is less likely to be lost, deleted, or leaked than data stored on a personal computer and/or other types of personal hardware. We make sure all the data we collect and the process is fully encrypted at rest and in transit, by employing state-of-the-art firewall and backup technology.

We also make sure our business premises are located inadequately secured buildings, which conform to established security standards. Physical access is controlled and monitored with the following safety measures: transponder card controlled interior door, limited access to on-premise server rooms, surveillance systems (alarm, motion detectors, etc.), etc.

We established the security measures presented above based on our best knowledge and experience in the field of data security. Notwithstanding, in case of any legislative and/or business requirements changes, we are ready to implement additional measures as soon as possible.

ARE WE ABLE TO NOTIFY ALL THE PARTIES CONCERNED IN CASE OF ANY DATA BREACH?

Yes. Any such data reach will be notified in accordance with Article 33 of the GDPR without undue delay (where feasible, not later than 72 hours after having become aware of it) to the parties concerned as well as to the supervisory authority competent in accordance with Article 55 of the GDPR.

WHICH PERSONAL DATA REGULATION DO WE COMPLY WITH?

This privacy policy is governed in accordance with Slovenian and/or EU legislation (whichever prevails), including but not limited to GDPR provisions. If you access our website, products, and/or services from outside of the EU, you are responsible for compliance with applicable local legislation.

WHO CAN YOU CONTACT IN CASE ANY QUESTIONS OR CONCERNS ARISE WITH REGARDS TO THIS PRIVACY POLICY?

We welcome your comments or questions about this privacy policy, you can email us at [email protected]. We will try to reply as soon as possible, but we will make sure we will handle your request in 14 days after we receive it.

Last revised: July 27, 2026

Review archive of previous terms here.

© 2026 VISIONECT ALL RIGHTS RESERVED.