gazda.mk

Privacy Policy

Last updated: 2026-10-05

This policy explains what personal data Gazda.mk collects, why, who can see it, how long we keep it and what your rights are. It applies to the website gazda.mk and the Gazda.mk application (together "the Service").

1. Who we are

The Service is operated by Kiril Trenchev, a natural person based in the Republic of North Macedonia ("we", "us"). For the purposes of the Law on Personal Data Protection ("LPDP", Official Gazette of the Republic of North Macedonia no. 42/2020) we are the controller of the personal data described in section 3, except where section 2 says otherwise.

Contact for anything about personal data: [email protected].

2. Two kinds of data: your data and your guests’ data

Two kinds of personal data pass through the Service, and our role is different for each:

  • Your data — your email address, sign-in details and organization membership. For this data we are the controller and this policy applies in full.
  • Your guests’ data — the names, phone numbers, stay dates, amounts and notes that you, as the owner or manager of a property, enter about the people who stay there. For this data you are the controller and we are the processor: we store and display it only so that you can use the Service, only on your instructions, and never for our own purposes. The data-processing terms in section 5 of the Terms of Service govern this.

If you are a guest of a property managed with Gazda.mk and want to exercise your rights, please contact the property owner; we will help them respond.

3. What we collect and why

Account data — your email address; a password stored only as a salted hash (we never see the password itself); if you sign in with Google or Apple, the stable identifier they give us for your account; if you turn on two-factor authentication, the secret of your authenticator app and your recovery codes. Purpose: to create your account, sign you in and keep the account secure. Legal basis: performance of the contract (the Terms of Service).

Organization data — the name of your organization, which accounts belong to it and their roles, and the email addresses of the people you invite. Purpose: letting a team work on the same properties. Legal basis: performance of the contract.

Data you enter about your properties and business — property names and places, photos, uploaded documents, bookings, prices, currencies and expenses. Purpose: the Service itself. Legal basis: performance of the contract. Where this includes your guests’ personal data, we act as your processor (section 2).

Calendar connections — the iCal links you paste from Airbnb or Booking.com and the dates they contain. We fetch only the dates and the platform’s reservation identifier; no guest names or contact details reach us from those platforms. Our own export link publishes only "Reserved" dates, never guest data. Legal basis: performance of the contract.

Emails we send — verification, invitations, password reset and important notices about the Service. Legal basis: performance of the contract; for security notices, our legitimate interest in keeping accounts safe.

Technical data — when you use the Service, our server and our network provider record your IP address, browser type and the time and address of each request in server logs, and use the IP address to limit abusive traffic. Legal basis: our legitimate interest in keeping the Service secure and working. Kept for up to 30 days.

Visit statistics — Cloudflare Web Analytics counts visits to our pages for us: which pages are viewed, the website a visit came from, the country, the type of browser and device, and how fast pages load. It uses no cookies and stores nothing in your browser, does not follow you to other websites, and shows us only totals — never a record of you. Legal basis: our legitimate interest in knowing how the Service is used and improving it.

How you found us — when you create an account, we note what brought you to it, if anything: the campaign name in one of our own ad links, or the website you came from (for example google.com or facebook.com). It is read from the address of the page you arrived on, is not stored in your browser, and is used only to learn which of our announcements work. Legal basis: our legitimate interest in promoting the Service. Kept for as long as the account exists.

Account activity — when your account was created and when you last used the Service, to the hour. We see these, with the counts and account details listed above, only in an internal read-only overview for running the Service — how many accounts are in use and whether new ones get started. It never shows your guests’ data or your amounts, and nobody else can see it. Legal basis: our legitimate interest in running and improving the Service. Kept for as long as the account exists.

Error reports — when something breaks, in your browser or on our server, we record the error message, technical details of where it happened, the page address (without anything after its "?"), the type of browser and the time, so that we can find and fix the problem. Email addresses and access tokens are removed before a report leaves our server. Legal basis: our legitimate interest in keeping the Service working.

Support — if you write to us, we keep the correspondence so that we can answer you. Legal basis: our legitimate interest in providing support.

What we do not do: no advertising, no tracking across other websites, no advertising or social-media pixels, no profiling, no automated decisions with legal effects on you, and no selling or renting of data to anyone. We do not collect data about your guests from any other source.

4. Local storage, not cookies

The Service does not use cookies to track you. It keeps a few values in your browser’s local storage, strictly so that the application works:

  • kula_token — your session, so that you stay signed in;
  • kula_email — the address of the signed-in account, shown in the interface;
  • kula_lang — your chosen language;
  • kula_currency — the currency you chose for totals.

These values are technically necessary, are never sent to third parties and are removed when you sign out or clear your browser data. Because they are strictly necessary, no consent banner is required for them.

On the sign-in page, if sign-in with Google or Apple is enabled, a script from Google or Apple is loaded to show their button. Their own privacy policies govern what those scripts do.

Cloudflare Web Analytics (section 3) runs a small script on our pages that sets no cookies and stores nothing in your browser.

5. Who else receives data

We use a small number of service providers (processors) to run the Service. They may only process data on our instructions and are bound by data-processing terms:

  • Hosting — the Service and its database run on a rented server operated by ColoCrossing / HostPapa in Buffalo, New York, USA. All data described in section 3 is stored there.
  • Cloudflare, Inc. (USA, with EU and worldwide infrastructure) — a network proxy in front of our server that routes and protects traffic. It processes IP addresses and request metadata, and provides the visit statistics described in section 3 (Cloudflare Web Analytics).
  • Brevo (Sendinblue SAS, France) — sends our transactional emails. It processes your email address and the content of those emails.
  • Sentry (Functional Software, Inc., USA; data stored in the European Union) — receives the error reports described in section 3.
  • Google LLC and Apple Inc. — only if you choose to sign in with Google or Apple. They confirm your identity to us and share your email address and a stable identifier. Their own privacy policies govern their side of the sign-in.
  • Airbnb and Booking.com — only if you connect a calendar. We fetch the link you gave us; those platforms see our server’s requests.

We disclose data to public authorities only where the law requires it. We do not share data with anyone else and we do not sell it.

6. Transfers outside North Macedonia

Our server is in the United States, and Cloudflare, Brevo and Sentry may process data in the European Union and in the United States. Such transfers are made under the conditions of the LPDP’s chapter on transfers to other countries: with providers that are contractually bound to protect the data, with encryption in transit, and with the security measures described in section 9.

You can ask us at [email protected] for more information about these safeguards. If we change where the Service is hosted, we will update this policy.

7. How long we keep data

  • Account and business data — for as long as your account exists. When you ask us to delete your account, we delete it within 30 days.
  • Your guests’ data — for as long as you keep it in the Service. You can edit or delete guests and bookings yourself at any time; everything is deleted together with your account.
  • Uploaded documents and photos — until you delete them or your account.
  • Server logs — up to 30 days.
  • Error reports — up to 90 days.
  • Backups — database backups may contain deleted data for up to 90 days after deletion, after which they are overwritten.
  • Support correspondence — until the matter is resolved and up to 12 months after.

Where the law requires us to keep certain records for longer (for example accounting records once the Service is paid), we keep only what the law requires, for only as long as it requires.

8. Your rights

Under the LPDP you have the right to:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate data corrected and incomplete data completed;
  • have your data erased ("right to be forgotten");
  • restrict processing in the cases the law provides;
  • receive the data you gave us in a structured, machine-readable format and have it transferred to another controller (portability);
  • object to processing based on our legitimate interest;
  • withdraw consent at any time, where processing is based on consent, without affecting processing that happened before.

To exercise a right, email [email protected] from the address of your account. We answer within one month; for complex requests the law allows us to extend this by two more months, and we will tell you if that is the case. We may ask you to confirm your identity. Requests are free of charge unless they are manifestly unfounded or excessive.

If you believe we process your data unlawfully, you have the right to lodge a complaint with the supervisory authority: the Agency for Personal Data Protection (Агенција за заштита на личните податоци), bul. "Goce Delchev" no. 18, 1000 Skopje, [email protected], azlp.mk.

Guests of properties managed with the Service should address their requests to the property owner (the controller of their data); we assist owners in responding.

9. Security

We protect personal data with technical and organisational measures appropriate to the risk, including: encryption in transit (HTTPS/TLS) for all traffic; passwords stored only as salted hashes; optional two-factor authentication; strict separation of each organization’s data; server access limited to the operator using cryptographic keys; a firewall that exposes only the web ports; and rate limiting against brute-force and abusive traffic.

No system is perfectly secure. If a breach of personal data is likely to put your rights at risk, we will notify the Agency for Personal Data Protection within 72 hours and you without undue delay, as the LPDP requires. Property owners will be informed of any breach that affects their guests’ data so that they can fulfil their own obligations.

10. Children

The Service is intended for adults who manage rental properties. We do not knowingly collect personal data from persons under 18. If you believe a minor has created an account, contact us and we will delete it.

11. Changes to this policy

We may update this policy when the Service or the law changes. The date at the top shows the current version. For material changes we will notify you by email or inside the application before they take effect. The current version is always available at gazda.mk/privacy.

This policy is available in Macedonian and English. In case of any discrepancy between the two versions, the Macedonian version prevails.

See also: Terms of Service