Quick overview
✓
We collect the data necessary to operate the platform
✓
Data is used for user accounts, accommodation, the QR guest app, AI reception, minibar, services, payments and security
✓
Data is deleted on request when there is no legal obligation to retain it
✓
Media and demo content are deleted or deactivated in accordance with platform rules
✓
Data processing complies with GDPR
For hosts – user and business data
First name, last name, email, phone number, business account name, account type, address and data needed to manage properties. This data is used to operate the platform, provide support, ensure security and meet legal obligations.
For payouts (Stripe Connect) – banking data
IBAN and related payout data are processed through Stripe Connect’s secure integration. Zvizz does not store the full IBAN on its own servers and does not have access to the full IBAN.
For properties and the QR guest app
Property name, unit name, location, rules, check-in/check-out information, available services, minibar products, prices, descriptions, images, QR codes and information the host enters to display to guests.
For guests
Name, email, phone number, data related to the stay, orders, requests, use of the QR guest app and communication with the host or support.
For the minibar and services
Data on ordered products and services, quantities, prices, order status, linked unit and time of the request.
For AI reception
User queries, AI system responses, host instructions for the property and context needed so AI reception can assist the guest during their stay.
Media content
Images, video, descriptions and other content users or hosts voluntarily publish or add on the platform.
Automatically collected data
IP address, device type, access time, language, basic technical information and interactions with the platform for security, stability, abuse prevention and basic analytics.
Operating the platform
We use data for user accounts, property management, the QR guest app, AI reception, minibar, services, orders, reservations where enabled, communication and technical support.
Billing model
Zvizz uses a billing model based on commission or fees according to the applicable price list. Fees may relate to repeat bookings, the minibar, services or other transactions on the platform.
Payments and payouts
Data is used to process payments and payouts through Stripe Connect. Card data and banking data are processed through Stripe.
AI reception
Data entered by the host is used so AI reception can give guests useful, practical answers relevant to the specific property.
Communication
We may send email notices about your account, property, orders, services, payments, security and important platform changes.
Security and abuse prevention
We use technical data to protect users, detect suspicious activity, prevent fraud and maintain platform stability.
We do not sell data
We do not sell your personal data to advertisers or other third parties.
Active users
Data is retained while you are a registered user and for a further 30 days after account deletion, unless a longer retention period is required by law.
Orders, payments and reservations
Data is retained in line with statutory periods, including tax and accounting obligations under applicable law in the Republic of Croatia.
Properties, services and minibar
Data is retained while the property is active on the platform or until the host deletes it, unless it is linked to legal obligations or transactions that must be retained.
AI reception
Host instructions and AI reception content are retained until the host changes or deletes them or while the property is active, unless longer retention is required for security or legal reasons.
Media content
Media content is stored while it is published or needed to display the property, unless the user deletes it or requests deletion.
Cookies
Up to 2 years, depending on the type of cookie and user settings.
IBAN (Stripe Connect)
Not stored on our servers. Stored exclusively through Stripe infrastructure, in line with Stripe’s privacy and security policies.
Encryption
We use SSL/TLS for data transmission and security measures to protect data in the system.
Passwords and authentication
Authentication and protection of user accounts are implemented through the platform’s security mechanisms and infrastructure providers.
Cards and IBAN
Stripe Connect processes payments, cards and banking data. Zvizz does not see the full card number or full IBAN.
Banking data
Banking data for payouts is processed through Stripe Connect and is not available in full form in our database.
Technical system functions
Data is processed through protected server-side processes and controlled access, applying the principle of least privilege.
Data access
Only authorized persons have access to personal data when necessary for support, security, legal obligations or operating the platform.
Third parties and processors
Database and infrastructure
Data is processed through infrastructure and database services that enable the platform to run, store data, authenticate users and maintain security.
Payment processing and IBAN
Stripe Connect processes card data, banking data and payouts. Zvizz does not see card data or the full IBAN.
Email notifications
We use a specialized email service to send email notifications.
Maps and locations
We use a maps and location service to display properties and approximate location information.
Media distribution
Images and video may be stored, processed and distributed through media services and CDN infrastructure.
AI systems
AI systems are used to process queries, structure host instructions and assist guests within AI reception.
Security and DNS
We use DNS, CDN and security services for availability, performance and protection of the platform.
Hosting and deployment
The application may be hosted and deployed on third-party infrastructure services.
Transfers to third countries
In some cases data may be processed outside the European Economic Area. In such cases we rely on appropriate safeguards, such as EU standard contractual clauses, encryption and the necessity of processing to provide the service.
Processor details
For detailed information about processors and applicable agreements, contact us at info@zvizz.com.
Legal bases for processing
Contract
Processing is necessary to provide the service: user account, QR guest app, minibar, services, orders, payments, support and property management.
Legal obligation
We must retain certain data for tax, accounting, security or other legal reasons.
Consent
Marketing communications, certain media content and optional features may be processed on the basis of your consent.
Legitimate interests
Platform security, fraud prevention, protecting users, basic analytics and improving the service are our legitimate interests.
Objection
If you disagree with certain processing, you can contact us at info@zvizz.com and lodge an objection.
How bases apply by data category
User account, orders, payments and business data are mainly processed on the basis of contract and legal obligation; security logs on the basis of legitimate interest; marketing and certain optional content on the basis of consent.
Functional cookies
Session token, security cookies, authentication and abuse protection are necessary for the platform to operate.
Technical cookies
Language, display, account and other technical settings may be stored for up to 2 years.
IP address and device
Collected automatically for security, stability, basic analytics and abuse prevention, and retained for up to 3 months.
Automated decisions and AI
What automated decisions are
Automated decisions are systems that automatically process data to help with security, recommendations, abuse detection or operating the platform.
Use in the Zvizz app
Automated systems may be used for security, fraud prevention, processing queries, structuring host instructions and operating AI reception.
AI reception
AI reception answers guests based on host instructions, property rules and available context. The AI must not independently invent property information.
Your rights
You have the right to request an explanation and human review if you believe automated processing has significantly affected you.
Impact on the user
We do not make solely automated decisions, including profiling, that produce legal effects for you or similarly significantly affect you without the possibility of human intervention.
Disagreement
If you disagree with an automated decision or an AI response, contact us at info@zvizz.com for further clarification and review.
Your rights (GDPR – Articles 15–22)
Right of access
You can request confirmation of whether we process your personal data and obtain a copy by emailing info@zvizz.com.
Right to rectification
If your data is inaccurate or incomplete, you can request correction.
Right to erasure
You can request deletion of your data, except for data we must retain due to legal obligations.
Right to data portability
You can request your data in a structured, commonly used and machine-readable format.
Right to complain
If you believe your rights are violated, you have the right to file a complaint with the Croatian Personal Data Protection Agency (AZOP).
How to exercise your rights
To exercise your rights, email info@zvizz.com with the subject line ‘GDPR request’ and a clear description of what you seek. We will respond without undue delay and no later than within 30 days.
Media content – special rules
Ownership
Content you add or publish remains your property, unless otherwise provided by specific rules or an agreement.
Control
You can remove your media content where that option is available or request removal through support.
Privacy
Content related to a property may be visible to guests, registered users or publicly, depending on the feature in which it is used.
People in content
If you publish content showing people, you are responsible for obtaining the necessary consents and rights for publication.
Prohibited content
Publishing pornographic content, violence, discriminatory content, content that infringes copyright or other laws is prohibited.
Legal responsibility
You are responsible for the content you publish and for having the right to publish it.
Protection of minor users
Minimum age
Users under 16 may use the platform only with explicit parental or guardian consent.
Minors (16–18)
Minor users may use the platform with clear information about how their data is processed and protected.
Recommendation
We recommend users under 16 use the platform under parental/guardian supervision and support.
Parental responsibility
Parents/guardians are responsible for supervising how minors use the platform.
Changes to this Privacy Policy and data breaches
Notices
We may notify you of changes to the Privacy Policy by email, push notifications or an in-app notice.
Minor changes
Minor changes are published directly on this Privacy Policy page.
Major changes
For material changes we will notify you by reasonable means before they take effect, where required.
No sale of data
We do not sell your personal data to third parties.
Data sharing
Sharing data with third parties without a valid legal basis, contract or your consent is not permitted.
Personal data breach
If you suspect a personal data breach, you can contact us at info@zvizz.com.
Contact
For all questions or requests regarding the processing of personal data, contact us at info@zvizz.com.
Complaints
You can submit complaints about the processing of personal data to info@zvizz.com.
Response time
We will respond without undue delay and no later than within 30 days of receiving a proper request.
Identity verification
To protect your data we may, where proportionate and necessary, request additional proof of identity.
Croatian Personal Data Protection Agency
If you are not satisfied with our response, you may contact the Croatian Personal Data Protection Agency (AZOP).
Legal obligation and applicable law
Applicable law
Processing of personal data is subject to Regulation (EU) 2016/679 (GDPR) and applicable law of the Republic of Croatia.
Dispute resolution
We seek to resolve disputes relating to data processing directly. This does not affect your right to initiate proceedings before a competent authority or court.
Tax and accounting rules
Data on payments, orders, reservations and transactions is retained in line with statutory periods where necessary for tax and accounting obligations.
Payments, payouts and Stripe Connect
How Stripe Connect works
Stripe Connect is used to process payments and payouts. Zvizz does not see, store or have access to full card data or a full IBAN.
Platform fees
A fee may be charged for payments, the minibar, services or other transactions on the platform according to the applicable price list.
Stripe security
Stripe is a certified payment services provider. Card and banking data are processed through Stripe.
Relationship with Stripe
For payment data, Stripe may act as a separate controller or processor depending on the specific service. We recommend that you also read Stripe’s privacy policy.
Payout of funds
Funds are paid out to the linked Stripe Connect account in line with platform rules, Stripe rules and fund availability.
Billing model
Zvizz may use a billing model based on commission or fees for transactions, without a mandatory monthly subscription, according to the price list shown to the user.
Technical details of the platform
Cookies and technical tools
We use necessary security and functional cookies, Stripe security mechanisms, and limited basic analytics and technical tools for stability and security of the service.
QR guest app
The QR guest app lets guests access information, rules, services, the minibar and AI reception for a specific property.
AI reception
AI reception uses data entered by the host and available property context to provide practical help to guests.
Important notices
We send notices necessary to perform the service, account security, payments, orders and material changes.
Email address
An email address is required for communication, your user account, confirmations, support and important notices.
Phone number
A phone number may be required for communication, account security, the host–guest relationship and support.
Banking data
Banking data is required for payouts through Stripe Connect and is processed through Stripe infrastructure.
What Zvizz is
Zvizz is a digital platform for hosts and guests that gives properties a QR guest app, AI reception, minibar, services, stay information and tools to manage the guest experience more easily.
Billing model
The platform uses a billing model based on fees or commissions for certain transactions, according to the price list shown to the user.
Contact email
For all information you can contact us at info@zvizz.com.
Your rights under GDPR
•
Right of access – know what data we process
•
Right to rectification – correct inaccurate or incomplete data
•
Right to erasure – request deletion of personal data
•
Right to restriction of processing (Art. 18) – temporarily stop processing
•
Right to data portability (Art. 20) – receive data in a machine-readable format
•
Right to object (Art. 21) – object to processing based on legitimate interests
•
Right to complain (Art. 77) – contact the Croatian Personal Data Protection Agency (AZOP)