Privacy policy
Last updated: 26 September 2026 (version 2026-09-26)
1. Data controller
The controller of personal data collected through the Očisti Platform is MFB Solutions, obrt za digitalne, poslovne i uslužne djelatnosti, vl. Martina Bilić (OIB: 88092973161), Jagnjić Dol, Klenovec 6, 10431 Sveta Nedelja, Hrvatska. For any questions about the processing of personal data, contact us at info@ocisti.hr.
2. What data we collect
Depending on your role on the Platform: • Customer: email at sign-up; first/last name, phone, and address only at the time of your first booking; your booking history, messages, and any reviews you leave. • Guest (booking without an account): name, email, phone, and address entered directly into the booking form. • Provider: company/trade name, tax ID (OIB), address, contact details, service and pricing information, and data needed to bill the subscription (legal name and address for the VAT invoice). Some of this data (name, tax ID, address, contact) is displayed publicly on the Provider's profile in line with the legal trader-traceability requirement (DSA Art. 30). We do not collect payment data for the cleaning/rental service itself. That payment is made directly between the Customer and the Provider, outside the Platform.
3. Legal bases for processing
We process data on the basis of: performance of a contract (account registration, processing bookings, Provider subscriptions); legitimate interest (fraud prevention, Platform security, service improvement); legal obligation (trader traceability under the DSA, accounting records); and consent (e.g. push notifications, see §9), which you may withdraw at any time.
4. Recipients and processors
We do not sell or share your data with third parties for advertising. We use the following processors to operate the Platform, all contractually bound to GDPR standards: • Supabase (database and authentication), EU region Frankfurt, Germany; data does not leave the European Union. • Stripe: processing Provider subscriptions (it does not process Customer payments for the cleaning/rental services themselves). • Resend: sending transactional emails (booking confirmations, reminders). • Cloudflare: hosting the Platform and cookieless web analytics (Cloudflare Web Analytics), with no third-party advertising cookies. • Microsoft (Microsoft 365): business email that receives your enquiries. • Google: sign-in with a Google account, if you choose it, and delivery of push notifications to Android devices (Firebase Cloud Messaging). • Apple: sign-in with an Apple account, if you choose it, and delivery of push notifications to iOS devices. • OpenStreetMap Foundation (Nominatim): converting an entered address or city into coordinates for distance search. Only the address text is sent, without name or contact details. • GitHub: storage of encrypted backups. The content is encrypted with a key held only by the controller. Some processors are established or have infrastructure outside the European Economic Area (e.g. the USA). Such transfers rely on the European Commission standard contractual clauses or an adequacy decision (EU-US Data Privacy Framework). Meta Platforms Ireland Limited: if you consent to tracking, the Meta Pixel is loaded on our pages, and when a booking is submitted we also send Meta a server-side event. This transfers your IP address, browser information and, for a booking, a cryptographic hash of your email address, phone and city, from which the original values cannot be read. The sole purpose is measuring advertising performance. Without your consent nothing is sent to Meta, and you can withdraw consent at any time via 'Cookie settings' in the footer or by clearing cookies in your browser. Google Ireland Limited (Google Analytics 4): if you consent to tracking, Google Analytics is loaded on our public pages for visit statistics (which pages are viewed, which campaign a visitor came from, how many send a booking request). This transfers your IP address (Google does not store it), browser and device information, and the page address with personal data removed: invitation links, booking numbers and search locations are stripped before sending. We do not send your name, email, phone or booking content, and Google signals and ad personalisation are switched off. Google Analytics is not loaded in the provider CRM (/app). Without your consent nothing is sent to Google for analytics, and you can withdraw consent at any time via 'Cookie settings' in the footer or by clearing cookies in your browser.
5. Cookies
Cookies strictly necessary to run the Platform (sign-in, language, session) are set without asking, because the site does not work without them. Third-party cookies — Meta Pixel and Google Analytics — are set only with your explicit consent, which you can give, decline, or withdraw at any time via 'Cookie settings' in the footer (see below). Cloudflare Web Analytics operates without cookies. The consent cookie (ocisti_privola) stores your answer to the tracking question and lasts six months. If you consent, Meta sets its own cookies (_fbp, _fbc) to measure advertising. If you decline, the Meta Pixel is never loaded and its cookies are never created. If you consent, Google Analytics sets the cookies _ga and _ga_DSGEKYGT3J (telling visitors and sessions apart), which last up to two years; if you decline or withdraw consent they are not created, or we delete them. With the same consent we also set our own cookie, ocisti_izvor, which records the campaign or site you first came from (a campaign label, no name or contact details) so we can measure which campaign brought you to us; it lasts 90 days and is never set without your consent. Cookies required for sign-in, language and basic site function are set regardless of that choice, because the site does not work without them.
6. Data retention periods
We retain Provider data (name, tax ID, address, contact) for at least 6 months after the Provider stops using the Platform, in line with the trader-traceability requirement (DSA Art. 30). We retain accounting records (issued invoices, subscription data) for the legally required period of 11 years, in accordance with accounting and tax regulations. We retain other personal data (booking history, messages, reviews) for as long as your account exists; once the account is deleted, we delete this data in accordance with §8.
7. Your rights
Under the General Data Protection Regulation (GDPR) you have the right to: access your data, correct inaccurate data, delete your data (the "right to be forgotten"), restrict processing, object to processing based on legitimate interest, and data portability. Send requests to info@ocisti.hr. We respond within the statutory period of one month at the latest. If you believe our processing of your data breaches the GDPR, you have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), azop.hr.
8. Account deletion
Deleting a user account cascades to all related personal data (profile, messages, push subscriptions), except data we are legally required to retain longer (§6, e.g. accounting records, trader traceability for Providers). We may anonymize, rather than fully delete, data from completed bookings and reviews that affect other users (e.g. a public review), where necessary to preserve the integrity of a Provider's history. Request account deletion through your account settings or at info@ocisti.hr.
9. Push notifications
We send push notifications (e.g. a new-booking alert or a reminder) only with your consent, obtained when you enable notifications in your browser or device. You may withdraw that consent at any time through your browser/device settings or within the Platform. We will then stop sending push notifications to that device.
10. View statistics, reports and restrictions
Profile views: when a signed-in User opens a Service's profile, we record which profile was viewed and when. We use this for the demand statistics we show the Service and to understand how the Platform is used (legitimate interest). Views by visitors who are not signed in are recorded without any link to a person. These records are deleted after one year. Reports by Services: a Service may report a User who did not show up for an agreed appointment, stopped responding after agreeing, or behaved inappropriately. A report is never public. Only the Platform administrator can see it, and it is not shown on any profile. Restrictions: if reports prove well-founded, we may issue the User a warning, block them from sending new bookings, or close their account (legitimate interest: Platform safety and protecting Services from harm). We notify you of any such decision by e-mail, with the reasons and instructions on how to appeal. Appeals go to info@ocisti.hr and are reviewed by a person, not an automated system. Records of reports and restrictions are kept for as long as the restriction lasts and for two years after it expires, so that repeat cases can be recognised.
11. Contact
For any questions about this Privacy Policy or the processing of your personal data, email info@ocisti.hr.