Last updated: March 7, 2026
LEOVAC Digital s. r. o.
Galvaniho 19057/33A, 821 04 Bratislava, Slovakia
Data Protection Officer: [email protected]
Supervisory Authority: รrad na ochranu osobnรฝch รบdajov Slovenskej republiky, Hraniฤnรก 12, 820 07 Bratislava, Slovakia -- dataprotection.gov.sk
Zayoto as Data Controller: We control personal data of Tenant account holders (agency owners, staff), platform usage data, website visitor data, and billing/payment data.
Zayoto as Data Processor: We process End User data (your customers' reservations, contact details) strictly on your behalf and according to your instructions.
Tenant as Data Controller: Each Tenant is an independent data controller for their End Users' personal data and is responsible for providing their own privacy policy, obtaining consents, and responding to data subject requests.
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Account creation and management | Contract performance |
| Subscription billing and invoicing | Contract performance |
| Security and fraud prevention | Legitimate interest |
| Platform improvement and analytics | Legitimate interest |
| Legal compliance (tax, accounting) | Legal obligation |
| Marketing communications | Consent (opt-in) |
We may share data with the following sub-processors:
Zayoto does NOT sell, rent, or trade personal data to third parties for marketing or advertising purposes.
Each Tenant's data is logically isolated in our multi-tenant architecture. No Tenant can access another Tenant's data.
| Data Category | Retention Period |
|---|---|
| Active Tenant account data | Duration of Subscription + 30 days |
| Billing and invoice records | 11 years (tax law) |
| End User data (as processor) | As instructed by Tenant |
| Support correspondence | 3 years after resolution |
| Website visitor logs | 90 days |
| Audit logs | 7 years |
Under the GDPR, you have the following rights:
To exercise your rights: use the Platform's data export feature (Settings > GDPR Export) or email [email protected]. We will respond within 30 days.
If you are an End User (a customer of a Tenant), please direct your data requests to the Tenant that collected your data.
We implement appropriate technical and organizational measures including: encryption in transit (TLS 1.2+) and at rest, role-based access control, password hashing (bcrypt), database-level tenant isolation, audit logging, regular encrypted backups, and EU-based hosting.
In the event of a data breach, we will notify the relevant supervisory authority within 72 hours and affected data subjects without undue delay where required.
LEOVAC Digital s. r. o.
Galvaniho 19057/33A, 821 04 Bratislava, Slovakia
Loading...