Flatie Tech d.o.o. operates the website flatie.hr and the application app.flatie.hr together with its mobile applications (collectively: the “Platform”). This Privacy Policy explains which personal data we process, why, for how long, and how to exercise your rights under the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the Croatian Act implementing the GDPR (Official Gazette 42/2018).
1. Who we are and our dual role
1.1 Identity and contact
Controller / Processor: Flatie Tech d.o.o., Zagorska ulica 22, 10000 Zagreb, Croatia, OIB (personal identification number): 50129451233.
General inquiries: [email protected]
Data Protection Officer (DPO): [email protected]
Supervisory authority: Croatian Personal Data Protection Agency (AZOP), Ulica Metela Ožegovića 16, 10000 Zagreb, azop.hr.
1.2 Dual role
With respect to different categories of data Flatie acts in two roles defined by the GDPR:
- As a controller (Art. 4(7) GDPR): for user account data, authentication, subscription billing, marketing consents, marketing-site analytics, and Platform security logs. For this data Flatie independently determines the purpose and means of processing — see section 2.
- As a processor (Art. 4(8) GDPR): for data belonging to a Building or its Users in the context of building management (memberships, notices, votes, polls, chat, defect reports, reserve fund, documents, AI-assistant prompts). The controller is the Organization or, for self-managed Buildings, the Co-owner Representative acting on behalf of the co-owners. Processing is governed by a separately concluded Data Processing Agreement (DPA) — see section 3.
If you have a question or request regarding the data in section 3, first contact the Organization managing the Building (or the Co-owner Representative). Flatie will assist the controller as needed. For direct inquiries to Flatie acting as processor: [email protected].
2. When Flatie acts as a controller
For the following categories of data Flatie independently determines the purpose and means of processing and is responsible to the data subject under the GDPR.
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Account & authentication | name, email, password hash, mobile number, personal identification number — OIB (if entered), interface language | Performance of contract (Art. 6(1)(b)) | Until account deletion + 30-day grace period |
| Subscription billing | subscription data, status, invoices and statements | Performance of contract + legal obligation (accounting) | 11 years (General Tax Act, Accounting Act) |
| Transactional email | email, system notification content | Performance of contract (Art. 6(1)(b)) | Until account deletion |
| Marketing (newsletter) | email, consent status | Consent (Art. 6(1)(a)) | Until consent withdrawal |
| Marketing-site analytics (flatie.hr) | anonymized/pseudonymized traffic data (Google Analytics 4) | Consent (cookies) | Up to 2 years (see Cookie Policy) |
| Product analytics (web + mobile app) | pseudonymized usage events — pseudonymous user id, feature used, counts and timestamps (PostHog, EU); never names, emails or Building data content | Consent (web: cookie banner); legitimate interest (Art. 6(1)(f)) in the mobile app, with opt-out in app settings | Up to 12 months |
| Error tracking & technical logs (web + mobile app) | crash and error reports, technical logs with pseudonymous user id, device/browser model, OS version (BetterStack, EU) | Legitimate interest (Art. 6(1)(f)) — service stability and security | Up to 30 days |
| Security & Platform audit logs | IP address, user-agent, session ID, security events; audit log of actions (who performed which action, on what resource, when, on whose behalf) | Legitimate interest (Art. 6(1)(f)) — Platform and user protection | 24 months, or longer for legal claim defense |
| Push notifications | technical device identifier (push token) | Performance of contract (Art. 6(1)(b)) | Until unsubscribe or account deletion |
| One-time passwords (OTP) for Building invitations | OTP record linked to user and Building | Performance of contract (Art. 6(1)(b)) | Automatically invalidated after use or expiration |
| Contact form (visitor inquiries) | name, email, phone, subject and message body | Legitimate interest (Art. 6(1)(f)) — replying to inquiries | Until inquiry is resolved, max 12 months |
3. When Flatie acts as a processor
The following categories of data Flatie processes on behalf of the Organization (or the Co-owner Representative of a self-managed Building) as controller. The legal basis for these operations is provided by the controller; details are governed by the DPA.
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Building membership (roles & relations) | role in the Building (co-owner, representative), Apartment, ownership share (area percentage for weighted voting per Official Gazette 152/2024), relations between users (whose representative, who owns which apartment), record of a tenant (name) entered by the apartment owner for internal building-management purposes — the tenant has no Platform account or access. Note: voting is technically restricted to co-owners; ownership-share changes are possible within the powers defined by law (Official Gazette 152/2024) and the building’s internal practice. | Determined by the Organization as controller (see DPA); for weighted voting: legal obligation (Official Gazette 152/2024) | While Building subscription is active + archive per applicable law |
| Notices, votes, polls, Building chat | content of notices, votes, comments, messages; weighted-vote record per ownership share | Determined by controller | Subscription duration + statutory retention (vote minutes — Official Gazette 152/2024) |
| Defect reports & maintenance logs | report text, photos, repair status, maintenance records | Determined by controller | Subscription duration + archive per controller decision |
| Reserve fund & transaction records | record items, amounts, descriptions | Determined by controller | Per applicable law (Official Gazette 152/2024, tax regulations) |
| Building document repository | files uploaded by the controller or an authorized User (contracts, statements, financial documents, etc.) | Determined by controller | Subscription duration (except documents subject to statutory retention) |
| AI assistant (on User request) | content of prompts and relevant Building context the User sends to the assistant; available to all authenticated Users regardless of role | Legitimate interest (Art. 6(1)(f)); cross-border transfer subject to appropriate safeguards | Conversations are not stored by Flatie; the assistant is currently not enabled (see section 4) |
4. AI assistant
The Platform may offer the User an AI assistant providing context-aware responses. In accordance with Art. 50 of Regulation (EU) 2024/1689 (the AI Act) we expressly inform you that the AI assistant is not a natural person, but an artificial-intelligence system. The assistant is currently not enabled; once enabled, it will be available to all authenticated Platform Users regardless of their role.
4.1 Data processed
The content of your prompts and relevant Building context you send to the assistant.
4.2 Model providers and cross-border transfer
- Document import (in use) — when a building manager or co-owners’ representative uploads existing documents while setting up a building, their content is sent for text recognition and data extraction to Mistral AI (France, EU). The extracted data is shown as a suggestion that a person reviews and confirms before it is saved.
- AI assistant (currently not enabled) — once enabled, it will use Mistral AI (France, EU) and Cohere (knowledge-base search; Canada/USA), with Anthropic PBC (USA) as a possible alternative model under Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). We will announce the activation of each of these providers at least 30 days in advance on the sub-processors page. Assistant conversations are not stored on Flatie servers.
4.3 Automated decisions
The AI assistant provides informational responses only and does not make automated decisions producing legal or similarly significant effects on the User within the meaning of Art. 22 GDPR. All decisions concerning a User’s rights, obligations and finances are made by an authorized person.
4.4 Opt-out
Use of the AI assistant is voluntary. You may stop using it at any time; processing for this purpose then ceases. Refusing to use the AI assistant does not affect access to other Platform features.
5. Who has access to the data
5.1 Flatie employees and contractors
Access is controlled by an internal role-based access control (RBAC) system with multiple levels. Access categories:
- Platform Administrator — full operational access to all data for technical support and incident response. This access technically includes data of all Buildings on the Platform; each such access is logged in the audit log with a distinguishing marker identifying it as administrator intervention.
- Platform Moderator — content moderation, user and organization management.
- Platform Support — limited view of organizations and analytics, content moderation.
- Platform Operations — solely for viewing platform analytics.
All accesses are recorded in the audit log. Access is strictly limited to what is necessary to perform a work task.
5.2 Organizations and authorized Building Users
- Organizations (building managers) and their authorized staff — solely for the Buildings they manage, in accordance with the DPA.
- Co-owner Representatives and deputies — solely for the Building for which they are elected.
- Co-owners — for the data of their own Building to the extent defined by their role.
5.3 Processors (sub-processors)
We share data with a limited number of service providers with whom we have a Data Processing Agreement. The current list (vendor, purpose, location, transfer mechanism, DPA status) is published at flatie.hr/en/sub-processors.
All processors are contractually prohibited from processing data for purposes other than those agreed and are required to ensure an appropriate level of protection.
6. International transfers
Primary processing and storage take place in the EU/EEA. Some data is also processed outside the EU/EEA: push notifications to mobile devices are relayed by Expo (USA) and delivered by Google (Firebase Cloud Messaging) and Apple (APNs), which receive a device token and the notification title and text; all traffic passes through Cloudflare’s global network; and Google Analytics 4 on the marketing site (only with your consent) may involve a transfer to Google LLC (USA). These transfers rely on Standard Contractual Clauses 2021/914 and, for Google LLC, the EU-US Data Privacy Framework. No AI provider outside the EU receives data today (see section 4). The updated list with safeguards is published at flatie.hr/en/sub-processors.
7. Retention periods
Retention periods for specific categories are listed in sections 2 and 3. Additionally:
- Accounting records and invoices — 11 years (General Tax Act, Accounting Act).
- Vote minutes and other statutory records related to building management — per the Act on the Management and Maintenance of Buildings (Official Gazette 152/2024) and implementing regulations.
- Security and audit logs — 24 months, or longer for legal claim defense.
- Soft-deleted accounts — 30 days grace period before irreversible deletion, with the ability to cancel by signing in during that period.
- OTP records — automatically invalidated after use or expiration.
- Push tokens (device identifiers) — until notifications are unsubscribed or the account is deleted.
- AI-assistant conversations — not stored on Flatie servers; the conversation history stays in your browser or app.
After the retention periods expire, data is deleted or anonymized.
8. Your rights
Under the GDPR you have the following rights:
- Access and portability — download your data via “Settings → Privacy” or request export from the DPO at [email protected].
- Rectification — edit your profile in the app or request correction from the DPO at [email protected].
- Erasure (“right to be forgotten”) — under “Settings → Privacy → Delete account” you initiate the process with a 30-day grace period; you can cancel deletion by signing in during that period. For data where Flatie acts as processor, submit erasure requests to the controller (Organization or Co-owner Representative).
- Restriction of processing — send a request to [email protected].
- Objection — to processing based on legitimate interest; send a request to [email protected].
- Automated decisions — Flatie does not make automated decisions producing legal or similarly significant effects on the data subject (Art. 22 GDPR). No profiling for that purpose.
- Withdrawal of consent — at any time, without affecting the lawfulness of processing prior to withdrawal.
- Complaint — you may lodge a complaint with AZOP (azop.hr).
We respond to verified requests within 30 days, with a possible extension under Art. 12(3) GDPR. For technical support: [email protected].
9. Data security
We implement reasonable technical and organizational protection measures:
- Flatie Tech d.o.o. does not sell users’ personal data.
- Passwords are securely stored using cryptographic hash functions and are not available to third parties.
- Access to data is controlled by a multi-level RBAC system; every access, including administrator interventions, is logged in the audit log.
- Role changes, resource deletions and all significant actions are logged in the audit log.
- Access to infrastructure is restricted to authorized IT providers necessary for system operation.
- We support two-factor (2FA) authentication as an additional layer of account protection.
In case of a data breach we will react promptly, take the necessary measures, and notify you in accordance with Art. 33/34 GDPR.
10. Cookies
For details on cookies, types of consent and how to change your choices, see the Cookie Policy. In short:
- Strictly necessary cookies — required for site operation, do not require consent.
- Analytics and marketing cookies — used only with your consent.
11. Policy changes
Material changes affecting your rights will trigger a new consent request on your next visit or sign-in. The version label in the document header tracks the current version. The history of material changes is available on request from the DPO. The current version is always published at flatie.hr/en/privacy-policy.
12. Contact
Data Protection Officer (DPO): [email protected]
General inquiries: [email protected]
Technical support: [email protected]
Flatie Tech d.o.o., Zagorska ulica 22, 10000 Zagreb, OIB (personal identification number): 50129451233