Privacy policy
This policy explains how PCTR d.o.o. processes personal data when you use Fliint, in line with the EU General Data Protection Regulation (GDPR).
Controller
The data controller is PCTR d.o.o. (full registered name: PCTR INFORMACIJSKE STORITVE d.o.o.), Lokev 173, 6219 Lokev, Slovenia. Registration number (matična številka): 9966935000. Tax number (davčna številka): 78302765. Contact: privacy@fliint.co.
Data we process
We process account and organization data (names, email addresses, roles), location and QR asset data, scan-session and attribution data, review content synchronized from connected providers, billing and subscription metadata, and technical logs needed to operate and secure the service. Reviewer names and review text come from the connected review provider (for example Google Business Profile) and are processed only to provide the product to your organization. For the public reputation audit, we retain the contact and business context you submit, the Google Place ID, and independently derived scores. We do not retain the review text, reviewer names, address, or copied profile content returned by Google Places.
Purposes and legal bases
We process personal data to provide and improve Fliint (contract performance), to authenticate users and protect the service (legitimate interests and legal obligations), to bill subscriptions (contract and legal obligations), and—where required—on the basis of consent (for example certain marketing or non-essential cookies). We avoid storing full IP addresses for public scan flows and use privacy-safe hashes for duplicate protection where feasible.
How we use data
Data is used to synchronize reviews, calculate transparent attribution, deliver reports, enforce access boundaries, maintain audit history, and support customer communications. Review text and reviewer names are never sent to product analytics tools.
Processors and sharing
We use subprocessors for hosting, email delivery, payments (for example Stripe), authentication, and optional AI features. Provider integrations and public business data supplied by Google are governed by the Google Terms of Service and Google Privacy Policy. We do not sell personal data.
International transfers
If personal data is transferred outside the EEA, we rely on appropriate safeguards such as EU Standard Contractual Clauses or an adequacy decision, where required.
Retention and security
We retain data for as long as needed to provide the service and meet legal, tax, and dispute-resolution obligations. OAuth tokens are encrypted at rest. Tenant records are organization-scoped; location managers are location-scoped; sensitive administrative changes are audited.
Your rights
Under GDPR you may request access, rectification, erasure, restriction, portability, and objection to certain processing, and you may withdraw consent where processing is consent-based. Organization owners may request export, correction, or deletion of organization data by contacting privacy@fliint.co. You may lodge a complaint with the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec) or another competent supervisory authority.
Public replies
You must not include private appointment, treatment, property, vehicle, payment, or other confidential customer information in public review replies. You remain responsible for content you publish through connected providers.
Contact privacy@fliint.co · PCTR d.o.o., Lokev 173, 6219 Lokev, Slovenia