Legal
Privacy Policy
Last updated: 6 September 2026
This Privacy Policy explains how Jeevision d.o.o., the company behind EasyFlow, collects and uses personal data when you visit this website or contact us through it.
We have written it to meet Regulation (EU) 2016/679 (the General Data Protection Regulation, or GDPR) and Slovenian data protection law. It is deliberately specific: it describes what this website actually does, not what a website might do.
1. Who is responsible for your data
The controller of your personal data, meaning the party that decides why and how it is processed, is:
- Company
- Jeevision d.o.o.
- Registered address
- Homec, VIII. ulica 4, 1235 Radomlje, Slovenia
- info@jeevision.com
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. For any question about your personal data, write to info@jeevision.com and your message will reach the people responsible.
2. What this policy covers
This policy covers the EasyFlow marketing website and the enquiries you send us through it. It does not cover the EasyFlow platform itself: where a client subscribes to the platform, that client is normally the controller of the data held in it and we act as a processor under a separate data processing agreement.
3. What personal data we collect
We only collect data that you hand to us deliberately, plus the minimum technical data needed to serve the website securely.
- Data you submit in the contact form
- Your name, email address, and message. Optionally your phone number and the lending product you select. Anything else you choose to write in the message field is up to you, so please do not include sensitive information there.
- Data you send us by email
- If you write to us directly, we process your email address, your name where given, and the content of your message.
- Technical server data
- Our hosting infrastructure records standard access data such as your IP address, the page requested, the time of the request, the referring page, and your browser and operating system version. This is generated automatically by the server and is used for security and for keeping the site running.
We do not collect special categories of personal data under Article 9 GDPR, and we do not buy personal data from third parties.
4. Why we use your data and on what legal basis
Under the GDPR we must have a lawful basis for every use of your personal data. Ours are as follows.
- Answering your enquiry
- To read your message, assess whether we can help, and reply to you. Legal basis: Article 6(1)(b) GDPR, because the processing is carried out at your request before entering into a contract, together with your consent under Article 6(1)(a) GDPR, which you give by ticking the box on the contact form.
- Following up on a business conversation
- To continue a discussion you started and to keep a record of what was agreed. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in pursuing and documenting business relationships that you initiated.
- Keeping the website secure and available
- To operate the server, detect abuse and automated attacks, and investigate faults. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in the integrity and availability of our own systems.
- Meeting legal obligations
- Where accounting, tax, or other statutory rules require us to retain correspondence or transaction records. Legal basis: Article 6(1)(c) GDPR.
Where we rely on legitimate interest, we have weighed that interest against your rights and freedoms and concluded that the processing is limited, expected, and not intrusive. You may object to it at any time, as described below.
6. Who else sees your data
We do not sell, rent, or trade personal data. We share it only with service providers who help us run the website and our correspondence, and only to the extent they need it. Each of them acts as a processor under a data processing agreement that meets Article 28 GDPR.
- Our hosting provider, which stores the website and generates the server access logs.
- Our email and message delivery providers, which transmit and store the enquiries you send us.
- Professional advisers such as accountants or lawyers, where they need the information to advise us.
- Public authorities, where we are legally obliged to disclose information.
7. Transfers outside the European Economic Area
We prefer providers established in the EEA. Some of the tools we use for email delivery may nevertheless process data in a third country, most commonly the United States.
Where that happens, we make the transfer lawful under Chapter V GDPR, relying on an adequacy decision of the European Commission where one applies to the provider concerned, such as the EU-US Data Privacy Framework, and otherwise on the Commission's Standard Contractual Clauses combined with additional safeguards. You may ask us for a copy of the safeguards in place at any time.
8. How long we keep your data
We keep personal data only for as long as the purpose it was collected for still exists.
- Enquiries that do not lead to a project
- Deleted no later than 24 months after our last exchange, unless you ask us to delete them sooner.
- Enquiries that lead to a business relationship
- Kept for the duration of the relationship and afterwards for as long as statutory retention periods require, which under Slovenian accounting and tax rules is generally up to 10 years for documents with accounting relevance.
- Server access logs
- Kept for a short period only, as a rule no longer than 30 days, unless a specific log is needed to investigate a security incident.
9. How we protect your data
We apply technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. These include encrypted transport of all traffic to and from this website over TLS, access to enquiry data restricted to the people who need it, and providers selected for their own security posture.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the supervisory authority as required by Articles 33 and 34 GDPR.
10. Your rights
Under the GDPR you have the following rights over your personal data.
- Access (Article 15)
- To be told whether we process data about you and to receive a copy of it.
- Rectification (Article 16)
- To have inaccurate data corrected and incomplete data completed.
- Erasure (Article 17)
- To have your data deleted where there is no longer a valid reason for us to keep it.
- Restriction (Article 18)
- To have processing paused while a dispute about accuracy or lawfulness is resolved.
- Portability (Article 20)
- To receive the data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another controller where technically feasible.
- Objection (Article 21)
- To object at any time to processing based on our legitimate interest. We will then stop unless we can show compelling legitimate grounds that override your interests.
- Withdrawal of consent (Article 7(3))
- To withdraw consent at any time. This does not affect the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, write to info@jeevision.com. We will respond within one month, as required by Article 12(3) GDPR. If your request is unusually complex we may extend that period by two further months and will tell you if we do. Exercising your rights is free of charge.
11. Complaints
If you believe we have handled your personal data unlawfully, we would like the chance to put it right, so please contact us first. You also have the right under Article 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State where you live, work, or where the alleged infringement took place.
Our lead supervisory authority is: Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia), Dunajska cesta 22, 1000 Ljubljana, Slovenia, gp.ip@ip-rs.si, www.ip-rs.si.
12. Whether you have to provide data
You are under no statutory or contractual obligation to give us any personal data. Providing your name, email address, and a message is simply what we need in order to reply to you. If you prefer not to provide them, we will not be able to respond to your enquiry, and there is no other consequence.
13. Automated decision-making and profiling
We do not use automated decision-making producing legal or similarly significant effects concerning you within the meaning of Article 22 GDPR, and we do not build profiles of website visitors. Every enquiry we receive is read by a person.
14. Children
This website addresses businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, contact us and we will delete it.
15. Changes to this policy
We may update this policy when our practices or the law change. The version published here is always the current one, and the date at the top tells you when it last changed. If a change materially affects how we use data you have already given us, we will inform you directly where we have a way of reaching you.