Privacy Policy
Last updated: July 17, 2026 · Effective immediately
This Privacy Policy describes how Acomplix ("we", "us", "our") collects, uses and protects personal data when you use the Acomplix platform at acomplix.com. We are committed to protecting your privacy and handling your data in accordance with the General Data Protection Regulation (GDPR) and applicable Croatian data protection law.
1. Who we are
Acomplix is operated from Croatia. For data protection purposes, Acomplix is the data controller for store owner account data, and acts as a data processor for personal data that store owners collect from their customers (reservations, player registrations).
Contact: privacy@acomplix.com
2. Data we collect
Store owners (our direct customers)
- Account data: Store name, store slug, username, email address, store address, city and country.
- Billing data: Legal business name, billing address, billing country, VAT number or business registration number (PIB, GST, ABN etc.), customer type (B2B or B2C). Payment is processed by Stripe — we never see or store your card details. We store your Stripe customer ID and payment status.
- Usage data: Plan type, subscription dates, feature usage, admin activity logs.
- Communication data: Emails sent between you and Acomplix support.
- Technical data: IP address at signup (for GDPR consent logging), browser type, access logs.
Players and customers of stores (indirect data subjects)
- Reservation data: Name, email address, phone number (optional), number of players, reservation date and time, notes.
- Event registration data: Name, email address, player count.
Store owners are the data controllers for this player/customer data. Acomplix processes it only on their behalf and according to their instructions.
3. How we use your data
- To provide, operate and improve the Service.
- To manage your account, subscription and billing.
- To verify your business status (B2B/B2C) for correct VAT treatment.
- To send transactional emails (welcome, payment confirmation, expiry warnings, reservation notifications).
- To comply with legal obligations including tax law and accounting requirements.
- To prevent fraud and ensure platform security.
4. Legal basis for processing (GDPR)
- Contract performance: Processing necessary to provide the Service you signed up for (account management, subscription billing, feature access).
- Legal obligation: Processing required for VAT compliance, invoicing and accounting records.
- Legitimate interests: Security monitoring, fraud prevention, service improvement, customer support.
- Consent: Cookie consent where applicable. You may withdraw consent at any time.
5. Data sharing and third parties
- Stripe: Payment processing. Stripe is PCI-DSS compliant and processes card data under their own privacy policy. We share your billing details with Stripe to process payments.
- Hetzner: Our hosting provider. Servers are located in the EU (Germany). Hetzner processes data under a Data Processing Agreement in accordance with GDPR.
- Email delivery: Transactional emails are sent via our server. We do not use third-party marketing email platforms.
We do not sell your personal data. We do not share your data with third parties for marketing purposes.
6. Data retention
- Active accounts: Data is retained for the duration of your account.
- Cancelled or deleted accounts: Store data (events, reservations, profile) is retained for 30 days after cancellation or deletion, then permanently deleted.
- Billing records: Invoices and billing history are retained for 7 years as required by Croatian accounting and tax law.
- Reservation and registration data: Deleted on the same schedule as the store account, or earlier upon store owner request.
- GDPR consent logs: Retained for 3 years as evidence of consent.
7. Your rights (GDPR)
As a data subject under GDPR you have the following rights:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate data.
- Right to erasure: Request deletion of your data, subject to legal retention requirements.
- Right to restriction: Request that we limit processing of your data in certain circumstances.
- Right to data portability: Receive your data in a machine-readable format.
- Right to object: Object to processing based on legitimate interests.
- Right to withdraw consent: Where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact privacy@acomplix.com. We will respond within 30 days. You also have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) at azop.hr.
8. Cookies
We use a single functional cookie to store your consent preferences. We do not use tracking cookies, analytics cookies or advertising cookies. The cookie does not contain personal data and is stored only in your browser.
9. Security
We implement appropriate technical and organisational measures to protect your personal data, including HTTPS encryption, hashed password storage, token-based authentication, and access controls. No method of transmission over the internet is 100% secure, but we take commercially reasonable steps to protect your data.
10. Children
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@acomplix.com.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email at least 14 days before they take effect. The current version is always available at acomplix.com/privacy.
12. Contact
For any privacy-related questions or requests: privacy@acomplix.com