Privacy Policy
Last updated: 13 September 2026
This policy explains how Инсиде Кафе ДООЕЛ, tax number 4020010509977, registered at Бул. Македонски Просветители л. 12, Охрид (the "Provider"), processes personal data in connection with the CRM service (the "Service"), in accordance with the Law on Personal Data Protection (Official Gazette of the Republic of North Macedonia No. 42/2020).
1. Our role
- As controller we process the data of people who request a trial, of the users of our customers' accounts and of billing contacts.
- As processor we process the data our customers enter into their CRM: their customers, contacts, employees and the like. The customer is the controller of that data, and processing follows the Data Processing Agreement.
2. Data we collect
- Trial request: name, company name, email, phone and the message you write.
- User account: name, email, password (stored only as a secure hash), role, language, last sign-in time and two-factor authentication data (encrypted).
- Billing: company name, tax number and address, billing email, issued invoices and payment records.
- Card payment: the transaction reference and amount returned to us by the Casys cPay payment system. Card data is processed by Casys; we neither receive nor store it.
- Technical data: IP address and time of sign-ins and failed sign-in attempts, and a log of changes in the account, for security.
3. Purposes and legal basis
| Purpose | Legal basis |
|---|---|
| Providing the Service and customer support | performance of a contract |
| Invoicing and payment records | performance of a contract and legal obligation |
| Security, abuse prevention, sign-in log | legitimate interest |
| Answering a trial request | steps taken at the person's request before entering a contract |
We do not use the data for third-party marketing and we do not sell it.
4. How long we keep it
- Account data: for the duration of the subscription and 30 days after it ends.
- Invoices and payment records: as long as accounting and tax rules require.
- Trial requests that did not become a subscription: up to 12 months.
- Backups: 14 days.
5. Who receives the data
The data is stored on servers we rent from Contabo GmbH, in a data centre in Germany (European Union). Data is disclosed only to:
- Contabo GmbH, as the server provider, for the technical operation of the Service and of email;
- Casys, to process card payments;
- public authorities, where the law requires it.
We do not transfer the data outside the European Economic Area.
6. Security
Each customer's data is kept in a separate database. Access is protected by passwords and two-factor authentication, connections are encrypted (HTTPS), passwords and keys are stored protected, and daily backups are made and also kept at a separate location.
7. Cookies
We use only cookies necessary for the Service to work: for signing in (session), for protection against forged requests (CSRF) and for the chosen language. We do not use tracking or advertising cookies.
8. Your rights
You have the right to access your data, to rectification, erasure and restriction of processing, to portability, to object, and to withdraw consent where processing is based on consent. Send your request to info@inside.com.mk. We respond within 30 days.
If you believe the processing is unlawful, you may lodge a request with the Personal Data Protection Agency (www.azlp.mk).
If your data was entered into the CRM of one of our customers, address your request to that customer as controller. We will help them respond.
9. Changes
Changes to this policy are published on this page with the date of the last update.
10. Contact
Инсиде Кафе ДООЕЛ Бул. Македонски Просветители л. 12, Охрид Email: info@inside.com.mk · Phone: 046230980 · inside.com.mk