Temelj za rast Privacy Notice
This notice explains which personal data Temelj processes, why, for how long, with whom it may be shared and which rights are available.
In shortTemelj za rast DOO (“Temelj”, “we”, “us”), tax/company number 03414442 and registration number 5-1013971/002, is responsible for personal data processed for this website, sales, account administration, direct support and...1. Controller, contact and scope
1. Controller, contact and scope
Temelj za rast DOO (“Temelj”, “we”, “us”), tax/company number 03414442 and registration number 5-1013971/002, is responsible for personal data processed for this website, sales, account administration, direct support and our own business operations. Registered address and contact: Trg slobode 5, apt 12, 85310 Budva, Montenegro; ; +382 67 788 339.
This notice covers temelj.me, contact and demo requests, the website support chat, Temelj Video Center, business communication and the Temelj products GuestNesty, Libar, Aviza, Vetrina, Butiga and Šoldi. A signed proposal, service agreement, data processing agreement or a product-specific notice may provide additional details. If it identifies a different contracting entity or specific controller, that document controls for the relevant service.
In shortFor website visitors, prospects, client contacts, account users, billing contacts, security records and Temelj’s own administration, Temelj normally determines the purpose and means of processing and acts as controller...2. When Temelj is a controller and when it is a processor
2. When Temelj is a controller and when it is a processor
For website visitors, prospects, client contacts, account users, billing contacts, security records and Temelj’s own administration, Temelj normally determines the purpose and means of processing and acts as controller.
When a hotel or other client uses a Temelj product to process data about its guests, employees, suppliers or customers, that client normally acts as controller and Temelj acts as processor on the client’s documented instructions. The client is responsible for lawful collection, notices, legal bases, accuracy, permissions and responding to data-subject requests. The contract or data processing agreement defines the parties’ exact roles, instructions, security duties, subprocessors, return or deletion and audit arrangements.
In shortDepending on how you interact with us, we may process identity and contact details; company, property and role details; messages, requests and files you send; proposal, contract, invoice and payment administration data...3. Data we process
3. Data we process
Depending on how you interact with us, we may process identity and contact details; company, property and role details; messages, requests and files you send; proposal, contract, invoice and payment administration data; account, permission and activity records; support history; device and security signals; and limited website analytics when you allow measurement.
Our contact form collects name, email, optional company name, subject and message. A successful inquiry is delivered to our business mailbox and may also be recorded in Butiga, Temelj’s CRM workflow, together with the source page, referrer, consent record and submission time. The support chat can store the name and email you provide, conversation messages, an access token and hashed anti-abuse signals derived from IP address, email and user-agent data.
In shortProductTypical data and purpose GuestNestyGuest and channel identifiers, conversation content, approved property knowledge, reservation context and staff handoff information used for guest communication and routine...4. Product data by service
4. Product data by service
| Product | Typical data and purpose |
|---|---|
| GuestNesty | Guest and channel identifiers, conversation content, approved property knowledge, reservation context and staff handoff information used for guest communication and routine support workflows. |
| Libar | Guest, reservation, room, stay, task, handover, folio, invoice and operational records used for reception and property operations. |
| Aviza | Survey answers, visit or location context, optional contact details, low-score alerts, incident follow-up and reporting used for guest feedback management. |
| Vetrina | Website inquiries, booking and availability inputs, content, consent choices and permitted analytics used for hotel websites and direct-booking flows. Payment details are handled by the configured payment provider where one is used. |
| Butiga | Lead, contact, company, mailbox, sales pipeline, proposal, task, meeting and approval records used for CRM, business email and commercial workflows. |
| Šoldi | Business contacts, accounting documents, transaction references, reconciliation, approval, report and audit-history records used for financial and accounting workflows. |
| Video Center | Account, company entitlement, course progress, feedback, device, session, playback and security-event data used to provide and protect private training content. |
The exact fields depend on the enabled product, plan and integrations. Clients should not submit special-category data, payment-card data, identity documents or other sensitive data unless the agreed workflow specifically requires it and appropriate safeguards are in place.
In shortWe process personal data to answer inquiries and take pre-contract steps; provide, configure and support contracted services; authenticate users and protect systems; administer accounts, invoices and legal records...5. Purposes and legal bases
5. Purposes and legal bases
We process personal data to answer inquiries and take pre-contract steps; provide, configure and support contracted services; authenticate users and protect systems; administer accounts, invoices and legal records; improve our website and products; establish or defend legal claims; and send requested or permitted business communication.
The legal basis depends on the context and may be performance of a contract or steps requested before a contract, compliance with a legal obligation, our legitimate interests in operating and securing the business, or consent for optional measurement and marketing. Where we rely on consent, it may be withdrawn at any time without affecting earlier lawful processing. Where we process customer data as processor, the client determines the legal basis.
In shortNecessary technologies support sessions, form security, privacy choices and private Video Center access. If you allow the Measurement category, the first-party Temelj Funnel Analytics tool records an anonymous browser...6. Website measurement, local storage and communications
6. Website measurement, local storage and communications
Necessary technologies support sessions, form security, privacy choices and private Video Center access. If you allow the Measurement category, the first-party Temelj Funnel Analytics tool records an anonymous browser identifier, page and click events, scroll depth, funnel path, campaign source and broad device category. It does not store your name, email address, IP address, full user-agent or form values.
The support chat uses browser local storage for a conversation token and, if you provide them, your name and email so the conversation can continue on the same browser. It also stores a sound preference. Details and controls are described in the Cookie Policy.
We do not sell personal data. We send direct marketing only where permitted and provide a practical way to object or unsubscribe. Service, security, contractual and support messages are not marketing and may still be sent when needed to provide the service.
In shortAccess is limited to authorized Temelj personnel and service providers who need data for hosting, infrastructure, email, CRM, customer support, analytics, payments, security, backups, accounting, development or...7. Recipients, service providers and integrations
7. Recipients, service providers and integrations
Access is limited to authorized Temelj personnel and service providers who need data for hosting, infrastructure, email, CRM, customer support, analytics, payments, security, backups, accounting, development or professional advice. Providers may act as processors or independent controllers, depending on the service.
Client-selected integrations—such as messaging channels, booking platforms, payment providers, email services or accounting systems—receive the information needed for the requested connection and are also governed by their own terms and privacy notices. We may disclose data to authorities or other parties when required by law or necessary to protect rights, security and service integrity. Current subprocessors relevant to a contracted product can be provided to the client on request or as specified in the agreement.
In shortSome infrastructure or integration providers may process data outside Montenegro or the European Economic Area. Where applicable law requires safeguards, we use an available lawful mechanism such as an adequacy decision...8. International transfers
8. International transfers
Some infrastructure or integration providers may process data outside Montenegro or the European Economic Area. Where applicable law requires safeguards, we use an available lawful mechanism such as an adequacy decision, approved contractual clauses, a binding data-processing arrangement or another permitted basis, together with technical and organizational safeguards appropriate to the risk.
In shortWe keep data only for as long as reasonably needed for the stated purpose, contract, security, legal claim and mandatory accounting or tax requirements. Business inquiries and CRM records are normally reviewed for...9. Retention
9. Retention
We keep data only for as long as reasonably needed for the stated purpose, contract, security, legal claim and mandatory accounting or tax requirements. Business inquiries and CRM records are normally reviewed for deletion or anonymization no later than 24 months after the last meaningful contact, unless a contract, active opportunity, legal obligation or dispute requires longer retention.
Customer content in our products is kept for the contract term and the return, export, deletion and backup-expiry periods agreed with the client. First-party funnel analytics events are configured for up to 90 days; the optional analytics identifier lasts up to 180 days unless consent is withdrawn or cookies are cleared. Closed support-chat transcript archives are configured for three months, while a visitor who closes a conversation causes its live messages to be removed after transcript handling. Video Center security events are configured for 90 days and authentication sessions for 30 days. Revoked Video Center device records are eligible for deletion after 365 days of inactivity; active device registrations may remain while the account or service is active. Statutory business and accounting records may be kept for the longer period required by law.
In shortSubject to applicable law and any exemptions, you may request information and access, correction, deletion, restriction, data portability, or object to processing. You may withdraw consent at any time. Montenegro’s...10. Your rights and requests
10. Your rights and requests
Subject to applicable law and any exemptions, you may request information and access, correction, deletion, restriction, data portability, or object to processing. You may withdraw consent at any time. Montenegro’s data-protection law also provides rights concerning notice, access and correction, and complaints may be submitted to the Agency for Personal Data Protection and Free Access to Information (AZLP).
Send requests to and describe the data or service concerned. We may verify your identity and ask for information necessary to locate the record. If the data is controlled by one of our clients, we will normally direct the request to that client or assist it as required by our agreement. We respond within the period required by the law that applies to the request.
In shortWe use proportionate technical and organizational safeguards, including access controls, scoped permissions, secure transport, logging controls, backups and incident procedures appropriate to the service. No system can...11. Security, children and automated decisions
11. Security, children and automated decisions
We use proportionate technical and organizational safeguards, including access controls, scoped permissions, secure transport, logging controls, backups and incident procedures appropriate to the service. No system can be guaranteed completely secure. More information about our approach, including the limits of any standards claim, is available in the Trust Center.
Our website and business products are not directed to children. Hospitality clients may process data relating to minors when necessary for a lawful reservation or stay; the client is responsible for the appropriate legal basis, notice and data minimization.
Temelj does not use website or sales data to make decisions producing legal or similarly significant effects solely by automated means. Product automation supports defined workflows; clients and their authorized staff remain responsible for consequential guest, pricing, refund, employment, accounting and legal decisions.
In shortWe may update this notice when products, processing activities, providers or laws change. The page displays its latest update date. Material changes will be communicated through the website, product or direct client...12. Changes and contact
12. Changes and contact
We may update this notice when products, processing activities, providers or laws change. The page displays its latest update date. Material changes will be communicated through the website, product or direct client notice when appropriate.
Privacy questions and requests: , +382 67 788 339, Temelj za rast DOO, tax/company number 03414442, registration number 5-1013971/002, Trg slobode 5, apt 12, 85310 Budva, Montenegro.