Privacy policy
Effective date: 20 July 2026
1. Introduction
Gamelu d.o.o., with its registered office in the Republic of Croatia, Slavonski Brod, Naselje Slavonija I 4/1, OIB: 73976474236 (hereinafter: Gamelu, the Company or We), respects the privacy of its users, business partners and associates. The Company's business is founded on trust, responsibility and transparency.
The 2016 General Data Protection Regulation (hereinafter: the Regulation) replaced Directive 95/46/EC of 1995 and harmonised data protection rules across the European Union. Its primary purpose is to protect the rights and freedoms of individuals, particularly with regard to the processing of personal data without their knowledge or consent. The Regulation prescribes how organisations, including the Company, collect, process and store personal data. These rules apply regardless of the form in which the data is held (electronic, paper or other media). The Company ensures that personal data is processed lawfully, fairly and securely, and that it is protected against unauthorised access or disclosure.
The Regulation applies to all forms of personal data processing, whether wholly or partly automated, as well as to the processing of data in physical form where it forms part of a structured system.
In territorial terms, the Regulation applies to all entities operating within the European Union that process personal data. It also applies to entities outside the European Union if they offer goods or services to persons within the EU or monitor their behaviour.
This Policy establishes the rules and principles that the Company, its employees, partners and everyone acting on its behalf must observe when processing personal data. The aim is to ensure a high level of data protection in accordance with applicable laws.
When you visit the www.gamelu.hr website, no cookies are set and no information about your device is collected. The server's technical logs record the IP address, which is necessary for the operation and security of the website. This does not make it possible to establish your identity, and you remain anonymous.
1.1. Reasons for adopting this Policy
- Applying the standards established by this Policy ensures that the collection, processing and storage of personal data is carried out in accordance with applicable legislation and the Regulation
- It safeguards the rights of employees, service users and the Company's business partners
- It clearly and transparently defines the procedures for collecting, processing and storing personal data
- It reduces the risk of unauthorised use or unlawful disclosure of entrusted data
1.2. Key terms
Main establishment – The main establishment of a controller of personal data in the European Union is the place where the key decisions on the purposes and means of processing personal data are taken. The main establishment of a processor in the EU is its central administration. If a controller is registered outside the EU, it must appoint a representative within the EU whose authority enables them to act on its behalf, including communicating with supervisory authorities.
Personal data – Any information relating to an identified or identifiable individual (data subject). An individual can be identified directly or indirectly, for example by name, identification number, location data, an online identifier, or other characteristics relating to their physical, physiological, genetic, mental, economic, cultural or social identity.
Special categories of personal data – Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, as well as genetic and biometric data (used for unique identification), health data, and data concerning an individual's sex life or sexual orientation.
Controller – A natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means of processing are laid down by EU law or the legislation of a Member State, the criteria for designating the controller may be defined by those provisions.
Processor – A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Data subject (data owner) – Any living natural person whose personal data is processed by an organisation.
Processing – Any operation or set of operations performed on personal data, whether or not by automated means. This includes, for example, collection, recording, organisation, storage, adaptation, use, disclosure, erasure or destruction of data.
Profiling – Any form of automated processing of personal data used to evaluate certain personal aspects of an individual, in particular to analyse or predict personal characteristics such as work performance, economic situation, health, interests, behaviour, location or movements.
Personal data breach – Any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Child – Within the meaning of the Regulation, a child is any person under 16 years of age, unless the law of a Member State provides for a lower age limit (but not lower than 13). Processing a child's personal data is permitted only with the consent of a parent or guardian, and the controller must take reasonable steps to verify that consent.
Third party – A natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor, or persons authorised to process personal data under the direct authority of the controller or processor.
Filing system – Any structured set of personal data accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.
1.3. Risks
This Policy contributes to reducing and managing the security risks associated with the processing of personal data, including:
- a) Breach of confidentiality – inappropriate or unauthorised processing of personal data
- b) Restriction of data subjects' freedom of choice – individuals being unable to decide freely how the Company uses their personal data
- c) Reputational risk – damage to the Company's reputation, for example in the event of a security incident or hacking attack
2. Policy statement
2.1. Scope of the Policy
The rules established by this Policy apply to:
- a) the Company
- b) all employees of the Company
- c) all associates, clients, contractual partners and other natural and legal persons acting on behalf of the Company
These rules apply to all personal data held by the Company that relates to identifiable individuals. Such data may include:
- a) first and last name
- b) address
- c) e-mail address
- d) telephone number
- e) any other data that can be linked to a specific individual
The Company primarily processes the data users provide when creating a user account, as well as any subsequent changes to that data.
The Company also processes data relating to:
- a) User account – including information about the subscription, contacts within the Application and similar data
- b) Use of the Application – such as the date and time of access, activity within the Application and technical data (device type, operating system, IP address and cookies)
- c) Content within the Application – including documents the user uploads or creates, as well as comments and messages posted through the Application
2.2. Statement
The Company, its employees and all natural and legal persons acting on its behalf undertake to comply with all applicable European Union and Member State regulations relating to the protection of personal data, as well as to protect the rights and freedoms of individuals. Personal data is collected and processed in accordance with the General Data Protection Regulation (GDPR). Compliance with the Regulation is governed in detail by this Policy and other internal acts of the Company.
This Policy and the Regulation apply to all personal data processing activities, including the data of service users, clients, employees, suppliers and other business partners, as well as any other personal data processed by the Company from any source.
The rules defined by this Policy are binding on all employees of the Company, as well as on third parties acting for or on behalf of the Company, including external associates and contractual partners.
Where the Company acts as a processor, personal data is processed solely in accordance with the instructions of the controller or the client, in compliance with the Regulation, the applicable legislation of the Member State and this Policy.
3. Responsibilities and roles under the Regulation
3.1. Controller and processor
The Company's principal activity is other software publishing. Where the Company acts as a processor of personal data in relation to a business partner, it assumes all obligations and responsibilities arising from that role, in accordance with the General Data Protection Regulation, the legislation of the Member State and the provisions of this Policy. The Company undertakes to process personal data on behalf of a business partner (controller) solely in accordance with the partner's instructions, as defined by the relevant contractual relationship.
In addition, in certain cases the Company also acts as a controller of personal data, as defined by the Regulation. All persons performing managerial or supervisory functions within the Company are responsible for developing, implementing and promoting good information management practice.
3.2. Data protection officer
To further strengthen the security and protection of personal data, the Company may appoint a data protection officer (hereinafter: the Officer), under the conditions prescribed by the Regulation.
If appointed, the Officer reports to the Company's management and is responsible for monitoring and ensuring compliance with applicable data protection regulations.
The Officer is responsible for the day-to-day monitoring of the Company's compliance with this Policy and the Regulation, particularly as regards the processing of personal data within the Company.
As part of their duties, the Officer participates in the implementation of the relevant procedures and provides employees with the necessary information and guidance on the application of this Policy and the Regulation.
Compliance with data protection regulations is the responsibility of all employees of the Company, as well as of all natural and legal persons acting for or on behalf of the Company who take part in the processing of personal data.
Employees must ensure that their personal data is accurate and up to date and must inform the Company of any changes in good time so that records remain accurate and current.
4. The Company's data protection principles
All processing of personal data must be carried out in accordance with the data protection principles, at least to the extent prescribed by Article 5 of the Regulation. The rules and procedures governing the processing of personal data within the Company have been established to ensure compliance with the provisions of the Regulation and this Policy.
4.1. The Company as a processor of personal data
In line with its contractual obligations towards business partners, the Company may take on the role of processor of personal data. In that case, the Company and all persons acting under its supervision who have access to personal data process it solely in accordance with the business partner's instructions, unless otherwise required by European Union law or the legislation of a Member State.
By concluding the relevant contract, the Company assumes the following obligations as a processor:
4.1.1. The Company ensures the implementation of appropriate technical and organisational measures, in accordance with this and other related policies, so that the processing of personal data complies with the Regulation and the rights of data subjects are protected.
4.1.2. The Company will not engage another processor without the prior specific or general written authorisation of the business partner. In the case of general authorisation, the Company will inform the business partner in good time of any intended changes concerning the addition or replacement of processors, giving the partner the opportunity to object.
4.1.3. The processing of personal data is governed by a contract or other legal act in accordance with European Union law or the legislation of a Member State.
4.1.4. If the Company engages another processor for specific activities, the same data protection obligations as those set out in the contract between the Company and the business partner are imposed on that processor by way of an appropriate contract or legal act.
4.1.5. The contracts or other legal acts referred to in the preceding points may be concluded in written, oral or electronic form, in accordance with applicable regulations.
4.1.6. The Company maintains a record of all categories of processing activities carried out on behalf of controllers. The record contains:
- a) the name and contact details of the processor, of each controller on whose behalf it acts and, where applicable, of their representatives and data protection officers
- b) the categories of processing activities carried out on behalf of each controller
- c) information on transfers of personal data to third countries or international organisations, where applicable, including the appropriate safeguards
- d) where possible, a general description of the technical and organisational security measures applied
4.1.7. The Company does not assess the lawfulness of the processing of personal data instructed by a business partner or another controller, nor does it restrict such processing on its own initiative. However, it notifies the relevant controller of any irregularities it identifies. If the Company considers that the required processing could adversely affect its integrity, reputation or financial stability, it reserves the right to object to such processing and to inform the business partner of the possible consequences in good time.
4.2. The Company as a controller of personal data
4.2.1. Personal data may be collected only for specified, clearly defined and legitimate purposes. Data collected for one purpose must not be used for other, incompatible purposes.
4.2.2. Personal data must be:
- a) processed lawfully, fairly and transparently in relation to the data subject (“lawfulness, fairness and transparency”)
- b) collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes (“purpose limitation”), except where permitted by the Regulation
- c) adequate, relevant and limited to what is necessary (“data minimisation”)
- d) accurate and, where necessary, kept up to date, with inaccurate data rectified or erased without delay (“accuracy”)
4.2.3. A lawful legal basis must be established before any processing. Processing is permitted only if at least one of the following conditions is met:
- a) the data subject has given consent for one or more purposes
- b) processing is necessary for the performance of a contract or to take steps prior to entering into a contract
- c) processing is necessary for compliance with a legal obligation
- d) processing is necessary to protect the vital interests of the data subject or another person
- e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority
- f) processing is necessary for legitimate interests, except where these are overridden by the rights and freedoms of the data subject
4.2.4. Fair processing means that all relevant information is available to the data subject, particularly when data is collected directly from them.
4.2.5. Transparency means providing the data subject with clear and understandable information, in accordance with Articles 12, 13 and 14 of the Regulation.
4.2.6. All personal data is processed in accordance with applicable regulations and the Company's internal rules.
4.2.7. The data subject must, at a minimum, be provided with the following information:
- a) the identity and contact details of the controller
- b) the contact details of the data protection officer (if appointed)
- c) the purpose and legal basis of the processing
- d) the retention period or the criteria used to determine it
- e) the data subject's rights (access, rectification, erasure, restriction of processing, objection, portability)
- f) the right to withdraw consent
- g) the right to lodge a complaint with a supervisory authority
- h) information on whether providing the data is obligatory and the possible consequences of not providing it
- i) the existence of automated processing, including profiling
4.2.8. Data must be limited to what is necessary:
- a) the Company does not collect data that is not needed for a specific purpose
- b) data collection forms must contain a processing notice or a link to the privacy policy
- c) data collection procedures are reviewed periodically to prevent excessive collection
4.2.9. Personal data must be accurate and up to date:
- a) data is regularly reviewed and updated
- b) employees are trained on the importance of data accuracy
- c) data subjects are required to provide accurate and up-to-date data
- d) all changes to data must be recorded
- e) appropriate procedures are established to maintain data accuracy
- f) data subjects' requests are handled without delay, at the latest within 30 days (with the possibility of extension in complex cases)
4.2.10. Data is kept only for as long as necessary:
- a) once the purpose has been fulfilled, data is anonymised or erased
- b) data is stored securely
- c) any extended retention must be justified by legitimate reasons
- d) processing must be protected by appropriate security measures
4.2.11. A risk assessment of personal data processing is carried out, taking into account all relevant circumstances.
4.2.12. The risk assessment considers the possible consequences for data subjects, as well as the impact on the Company's reputation and the trust of users and partners.
4.2.13. When defining technical security measures, the following are taken into account:
- a) password management
- b) automatic locking of devices
- c) restrictions on the use of removable media
- d) antivirus protection and firewall
- e) role-based access control
- f) encryption of portable devices
- g) network security
- h) pseudonymisation and anonymisation of data
- i) continuous improvement of security standards
5. Rights of data subjects
5.1. Availability of information
The Company ensures that information is available so that data subjects are aware that their personal data is being processed and understand:
- a) how their data is used
- b) how they can exercise their rights
5.2. Rights of data subjects
Data subjects have the following rights in relation to the processing of their personal data:
- a) the right to request access to personal data concerning them
- b) the right to object to the processing of personal data, particularly where such processing could have adverse consequences for the data subject
- c) the right to object to the processing of personal data for direct marketing purposes
- d) the right to be informed of the logic, methods and algorithms involved in automated data processing
- e) the right to seek compensation before a competent court for damage caused by data processing
- f) the right to request the rectification, erasure or restriction of processing of inaccurate data or data for which consent has been withdrawn, where no other legal basis for processing exists
- g) the right to submit a request to the supervisory authority to establish a possible infringement of the Regulation
- h) the right to data portability to another controller
- i) the right to object to automated decision-making, including profiling, where no consent has been given for it
5.3. Exercising data subjects' rights
In order to exercise their rights:
- a) the data subject may submit a request for access to personal data
- b) the data subject has the right to lodge a complaint with the Company regarding the processing of their personal data or the way a request to exercise their rights has been handled
6. Consent
The Company considers consent to be any freely given, specific, informed and unambiguous statement by which the data subject agrees to the processing of their personal data, or of the data of persons they represent. Consent may be withdrawn at any time, in a manner as simple as that in which it was given.
For the Company, giving consent means that the data subject is fully informed about the intended processing of their personal data. Consent given under duress, by deception or in error is considered invalid and cannot constitute a lawful basis for processing.
Obtaining consent requires the active participation of the data subject and the controller. A lack of response or inaction on the part of the data subject cannot be regarded as consent — consent cannot be presumed. The controller must be able to demonstrate at all times that consent was lawfully obtained.
In practice, consent to the processing of personal data and special categories of data usually forms part of the standard forms and written documents signed by the data subject (a user or business partner) in accordance with the Company's internal rules. The data subject has the right to withdraw their consent to the processing of personal data at any time.
7. Data security
All employees of the Company, as well as other persons acting for and on behalf of the Company, are responsible for the protection and security of the personal data the Company collects and processes. Personal data must be kept in a way that prevents unauthorised access or disclosure to third parties, except where such disclosure is permitted and governed by an appropriate confidentiality agreement. In that case, the third party undertakes to comply with the provisions of this Policy and to meet the security requirements prescribed by the General Data Protection Regulation.
Access to personal data is restricted exclusively to persons who need it to perform their work tasks. The Company applies high data protection standards and ensures that data is stored and processed appropriately and securely.
Processing personal data outside the Company's premises may pose an increased security risk, including the possibility of loss, theft or unauthorised access to data. Such processing therefore requires the prior approval of the responsible persons within the Company.
All personal data processing activities are carried out within the European Union. The Company does not transfer personal data to third countries.
8. Disclosure of data
In certain situations, regulations permit personal data to be handed over to law enforcement agencies and state authorities without the data subject's consent. In such cases, the Company will provide the requested information. However, before handing over the data, the responsible person will verify the legitimacy of the request with the assistance of legal experts or the competent data protection authorities.
The Company is also obliged to prevent the unauthorised sharing of personal data with third parties, such as family members, friends, state institutions or, in certain circumstances, the police. All employees should be familiar with the correct course of action when asked to disclose data to third parties.
9. Data retention and handling
The Company must not retain personal data enabling the identification of an individual for longer than is necessary to fulfil the purpose for which it was collected.
However, data may be kept beyond the period prescribed by law or internal rules if it is processed for purposes in the public interest, for scientific or historical research, or for statistical purposes. In such situations, appropriate technical and organisational measures must be applied to protect the rights and freedoms of data subjects.
Personal data processed by the Company must be processed in a manner that ensures its security, thereby also protecting the rights and freedoms of individuals.
10. Transfers of data to third countries
Any transfer of personal data from the European Economic Area to third countries is considered unlawful unless an adequate level of protection of the data subject's fundamental rights is ensured.
a) The European Commission assesses third countries, their territories and/or individual sectors to determine whether they provide an adequate level of protection of individuals' rights and freedoms. If data is transferred to countries that meet these security standards, no special authorisation from the supervisory authority is required. Member States of the European Economic Area, although not necessarily members of the European Union, also meet the necessary conditions.
b) The Company may adopt its own rules for the transfer of personal data to third countries. Such rules must be notified to the competent supervisory authority, which will review them and approve or reject them.
c) If none of the above conditions is met, data may be transferred to third countries or international organisations only in specific situations, such as:
- when the data subject has given explicit consent after being informed of the possible risks of the transfer
- when the transfer is necessary for the performance of a contract between the data subject and the controller or processor, or for the implementation of pre-contractual measures taken at the data subject's request
- when the transfer is necessary for the conclusion or performance of a contract concluded in the data subject's interest between the controller/processor and a third party
- when the transfer is justified by public interest
- when the transfer is necessary for the establishment, exercise or defence of legal claims
- when the transfer is necessary to protect the vital interests of the data subject or other persons, where the data subject is unable to give consent
This Privacy Policy will be reviewed periodically and updated as necessary. All amendments take effect upon publication of the revised version. We recommend checking our website regularly to stay informed of any changes, a summary of which will be displayed alongside the updated version.
Annex 1 to the Data Protection Policy
1) Identity and contact details of the controller
The controller is Gamelu d.o.o., with its registered office in Croatia, Slavonski Brod, Naselje Slavonija I 4/1, OIB: 73976474236, contact e-mail: gamelu@gamelu.hr
2) Contact details of the data protection officer (if appointed)
At the time of adoption of this Policy, no data protection officer has been appointed.
3) Purposes of processing and legal basis for the use of personal data
Registration in the application: Personal data is processed to create and verify the user account. The legal basis is contract (the Terms of Service). If the user adds a profile picture, the processing is based on consent. In the case of an invitation, the e-mail address is processed for the purpose of sending the invitation.
Use of the application: Data is processed to provide access to the application, its features and content, and to further develop and improve the user experience. The legal basis is contract.
Analysis of application usage: Data is used to enhance functionality and improve the service.
Contacting users: Data may be used to send notifications about news or to collect feedback.
Responding to enquiries: Data is processed in order to respond to users' requests or questions, on the basis of legitimate interest or a legal obligation.
Application security: Data may be processed to detect and prevent security incidents or misuse, on the basis of the Company's legitimate interest.
4) Data retention period
Personal data is kept only for as long as necessary to fulfil the purpose of its processing, unless a longer retention period is prescribed by law.
5) Rights of data subjects
Users have the right to request information about the processing of their personal data, including access to the data, rectification, erasure, restriction of processing, objection to processing and data portability. They also have the right to know the purpose of processing, the categories of data, the recipients of the data, the retention period and the source of the data if it was not collected directly from them.
6) Right to withdraw consent
Where processing is based on consent, the user may withdraw it at any time by sending a request to gamelu@gamelu.hr or to the Company's address. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
7) Right to lodge a complaint with the supervisory authority
If users believe their rights have been violated, they may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10 000 Zagreb, e-mail: azop@azop.hr
8) Obligation to provide personal data
Providing personal data is necessary for concluding the contract and using the services. If the data is not provided, the user will not be able to use the Company's services.
9) Automated processing and profiling
Only the basic data required for the operation of the application is collected. No automated decision-making or profiling with a significant effect on the user is carried out.
10) Demo request form data
The information you submit through the demo request form (name, company, e-mail address, telephone number, number of employees and your message) is used solely to contact you regarding your enquiry. The legal basis for this processing is your consent.
Received enquiries are stored in our business e-mail mailbox located within the European Union.
We retain enquiries for 12 months from receipt, after which they are deleted. You may withdraw your consent at any time by writing to gamelu@gamelu.hr.