Privacy Policy
Last updated 2026-09-16
Padli — padel court booking platform Operated by VORTEK INOVATIONS D.O.O. Skopje
Last updated: 16 September 2026
1. Personal data controller
The personal data controller is VORTEK INOVATIONS D.O.O. Skopje, a trade and services company with its registered office at Njudehliska 6/1-13, Karposh, Skopje, EMBS 7757832, TAX ID MK4057024570335. For questions regarding the processing of personal data, you may contact our data protection officer at: hey@padli.app.
This Policy explains what personal data we collect when you use the Padli platform (www.padli.app and the Padli mobile applications), why we collect it, on what legal basis, with whom we share it and how long we keep it.
2. What is personal data?
In accordance with the Law on Personal Data Protection of the Republic of North Macedonia, "personal data" means any information relating to an identified natural person or a natural person who can be identified (data subject), directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to that person's physical, physiological, genetic, mental, economic, cultural or social identity.
Processing of personal data is any operation performed on personal data, whether automated or not — collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, publication or otherwise making available, alignment or combination, restriction, erasure or destruction.
3. Which types of data do we collect and process?
3.1. Visitors browsing without registration
You can browse venues, courts, prices and free slots without an account. In doing so we process only technical data necessary for the service to work — the request data your browser or application sends (IP address, device and browser type, language) and the session cookie described in section 12 if you subsequently sign in. Location is used only if you grant permission to your device, to sort venues by distance; it is not stored on our servers.
3.2. Creating a player account
A player account is created with a phone number or an e-mail address, confirmed by a one-time code (OTP) that we send you. Padli player accounts have no password. We process:
- First and last name — entered by you; you are responsible for its accuracy. Visible to other players (section 5.2).
- Phone number and/or e-mail address — your identifier and the channel through which we confirm your identity and send you booking messages. The one-time code is short-lived and single-use.
- Date of birth and gender — optional, entered by you.
- Profile picture — optional.
- Language — the language in which the Platform is displayed to you.
- Verification and sign-in timestamps — when your phone or e-mail was confirmed and when you last signed in.
3.3. Signing in with Google or Apple
Where you sign in with Google or with Apple, we receive from the provider only basic profile information — an identifier, your name, your e-mail address and, where available, a profile picture. We never receive your password with the provider. Where the e-mail address returned is already verified by the provider and matches an existing Padli account, we link the two so that you reach the same account by either route. We store the provider's identifier in order to recognise you on your next sign-in. Where you signed in with Apple and later delete your account, we ask Apple to revoke the grant you gave us.
3.4. Player profile and playing preferences
Optionally, and only if you fill them in: a short biography (up to 280 characters), your dominant hand, your preferred side of the court, your playing style, your preferred time of day to play, and a self-declared skill level. These describe how you play and are shown on your profile to the players entitled to see it.
3.5. Booking data
For each booking: the venue and court, the date, start time and duration, the sport and format, the price and the service fee, the status of the booking, the participants and their seats, and your check-in where the venue uses it. Booking data is visible to you, to the other participants in that booking, and to the venue at which it was made.
3.6. Payment data
- Card payments. Payments are processed by Halk Bank AD Skopje through their NESTPAY system, on a page hosted by the bank, with 3-D Secure authentication. We have no insight into your card data — the full card number, the security code and your account balance never reach our systems.
- Saved cards. Where you choose to save a card, we store only the token issued by the bank together with the card brand, the last four digits and the expiry date, so that a later booking can be charged without re-entering the card. You may delete a saved card at any time.
- Transactions. For each charge, refund, reservation of funds (pre-authorisation) or declined attempt we keep a record: the amount and currency, the purpose, the status, the time, the bank's reference and, where the payment failed, the reason given by the bank. The record also states how the payment was funded (a card or your credit at the venue) and the amount of any promo-code discount applied to it.
- Expiring cards. Where a saved card is about to expire we note that we have warned you, so that the reminder is sent once and not repeatedly.
3.6.1. Receipts and billing identity
A charge produces an electronic receipt or invoice — one document where Padli is the seller of record, and two where the venue's company sells as principal and Padli issues in its name (General Terms of Use, section 4). Each contains the amount, the value added tax, your identification as the payer, our own legal identity, and the legal identity of the venue that rendered the service. The identities on a receipt, and the tax rate applied to it, are frozen at the moment of the charge, because an issued accounting document must not change afterwards. For that reason we store the applicable rate, and the arrangement the sale was made under, on the booking itself.
3.7. Account balance
Where a shared booking cannot be collected in full from the participants, the shortfall is recorded as an outstanding balance (a debt) on the organiser's account. We keep the balance, its currency and its history of movements. This is a separate matter from credit standing in your favour at a venue, which is described in section 3.27.
3.8. Shared bookings and invitations
Where you invite other players to a booking we process the invitation, its status (pending, accepted, declined), the seat it relates to, the share of the price and of the service fee attaching to that seat, and whether the seat was filled by invitation or from a public listing. The other participants in a booking see who is in it and which seats are paid.
3.9. Data about guests (people who are not Padli users)
Where you name a guest in a booking, we process the name you entered and, where you provided one, a phone number or e-mail address, in order to record who occupies the seat and — where you asked for it — to deliver the invitation to them.
When you enter another person's data you must have their agreement. Guests are never named publicly on the Platform: they are visible only to the people in the same booking and are never shown in public results feeds or leaderboards.
Where an invitation is sent to a person who has no Padli account, we record the fact that it was sent, so that the same person is not contacted repeatedly, and we record an opt-out if they ask not to be contacted again. A person who has opted out is never contacted again. Such invitations are subject to a strict daily limit.
3.10. Open matches
Where you make the free seats of your booking publicly joinable, the booking becomes visible in the discovery feed to other players — with the venue, the date and time, the price per seat, the free seats and the players already in it, to the extent their own visibility settings allow. We record when the booking was made public and how each seat was obtained.
3.11. Match results and live scoring
We process the scores entered for a match, who entered or proposed them, who confirmed or contested them, and when. Where a result is not contested it is confirmed automatically after 24 hours. Where participants score a match live while playing, we process the successive states of the scoreboard and which participant entered each change.
Where a person states that they were not in fact in a match, we record that statement together with its author, because it invalidates the result for everyone and may be contested by the seat holder.
3.12. Match history and tagging
You may record who you played with. Where you tag a Padli user, the tag is a request: we process it as pending until that person accepts or declines it, and it attaches to their history only if they accept.
3.13. Player level and rating
We calculate and store your level (a scale from 0 to 7), an indication of its reliability, the history of its changes with the reason for each change, the answers to the questionnaire you complete when you set your starting level, and the pairings of confirmed competitive results from which the level is calculated. Section 6 explains the automated nature of this calculation.
3.14. Leaderboards and ranking points
We store the points you earn at each venue and platform-wide, and the ledger of how they were earned. Points accumulate over time and are not reset. Whether you appear on a venue's player lists is a setting you control.
3.15. Connections and public profile
We process who you follow and who follows you, and whether your profile is private. Your public profile may show your name, profile picture, biography, level, playing preferences, statistics, match history, and your followers and the accounts you follow — subject to your privacy settings.
3.16. Discovery through your phone contacts
If you choose to look for people you know, the application reads the contacts you allow it to read on your device and sends the phone numbers and e-mail addresses in a batch to our server, where they are compared against registered accounts.
The contacts you send are used solely for that comparison and are not stored. We keep neither the matched nor the unmatched contacts; the result is returned to your device and the batch is discarded. We never contact a person from your contact list on our own initiative. This happens only when you start it, and never automatically.
3.17. Blocking
Where you block another user, we record the block. Its effect is mutual invisibility: the two of you disappear from each other's profiles, searches, lists and suggestions, and any follow between you is severed.
3.18. Invite codes
Each account carries a permanent personal invite code. Where a new user registers through your code, we record the connection between the two accounts.
3.19. Favourite venues
The venues you save are stored on your account so that they follow you across devices.
3.20. Notifications and devices
To deliver notifications we store a device token issued by the push service, together with the type of device and which of our applications it belongs to. We also store your notification preferences — a switch for each category (bookings, reminders, invitations, payments) on each channel (push, e-mail, SMS), all on unless you turn one off.
We also keep a record of each notification sent to you: its type, what it refers to (for example, a booking or an invitation) and whether you have read it. The text itself is not stored — it is composed on your device, in your language, from that record. A device token is removed when the device stops responding or when you turn notifications off.
Where an e-mail address is definitively rejected by the receiving server (it does not exist), we record the address so that we stop attempting delivery to it. The record is kept by address and may relate to a person who has no Padli account, such as a guest or an invitee.
3.21. Live Activities on iOS
Where you allow it, an iOS device may show a countdown to your match and the live score on the lock screen. For this we store a separate short-lived token issued by Apple for that specific activity, which becomes invalid when the activity ends.
3.22. Wallet passes and calendar invitations
Where you add a booking to Apple Wallet or Google Wallet, we store the registration of that pass so that it can be updated when the booking changes, and we remove it when the pass is removed. Booking confirmation e-mails contain a calendar invitation with the details of the match, so that it can be added to your calendar.
3.23. Sessions and account security
We store your active sessions (as an expiring, encrypted-at-rest token, not as a readable credential), the surface they belong to, and when they were last used. This is what keeps you signed in and what allows a session to be ended.
For each session we additionally record, at the moment it is created, the network (IP) address and the browser or application identification it was created from, and the device name and platform derived from them, and we refresh the address when the session is next used. This is what lets us show you a list of the devices signed in to your account, so that you can recognise one that is not yours and sign it out, and it is used to detect and prevent unauthorised access. It is deleted together with the session.
3.24. Venue staff and administrators
Where you are a member of a venue's staff or an administrator, we additionally process your e-mail address and password (stored only as a cryptographic hash, never in readable form), the venue you belong to, the permissions granted to you, the invitation through which your account was created, and an activity log of every change you make in the console — what was changed, by whom and when. The log is an accountability record and is retained independently of the account.
3.25. Support and correspondence
Where you contact us, we process your message and the contact details you use, in order to answer you and to keep a record of the request and its resolution.
3.26. Appearance and application settings
Your chosen language, your light or dark appearance, and a small number of technical flags (for example, whether a one-time explanatory prompt has already been shown to you) are kept on your device, not on our servers. They are listed individually in the Cookie Policy (section 4); see also section 12 below.
3.27. Credit at a venue
Where you hold credit at a venue we process the balance and, separately, the part of it that was granted as a bonus and the date on which that part expires. Beside the balance we keep an unchangeable record of every movement into and out of it: the amount, the resulting balance, the reason (a top-up you paid for, a refund taken as credit, a payment for a booking, a bonus granted, a bonus expired, an adjustment made by our support team, or a forfeit on deletion of the account), the booking or transaction it relates to, and — where a member of our staff moved it — who did so and any note they left.
That record exists so that the question "where did my credit go?" can be answered months later, and so that a balance can be shown never to have been quietly altered. A top-up is also a card payment and is recorded as one under section 3.6.
3.28. Promo codes
Where you use a promo code we record that you used it, on which booking, the amount discounted and the moment of use. That record is what enforces the limits of the campaign (one use per player, a total number of uses, first booking only) and what allows a discounted charge to be explained afterwards.
3.29. Bookings a venue makes for you
Where a venue creates a booking for you at its desk, it enters the contact detail you gave it. Where that detail matches your account, the booking is linked to it. Where the venue asks that the booking be collected through the Platform, we record the request and your answer to it — that it was made, and whether you accepted or declined — because that answer is what determines whether you may be charged at all. An unanswered request is never treated as an acceptance.
3.30. How the Platform is used (product analytics)
To understand how the Platform is used — and above all what does not work, which cannot be reconstructed from bookings that were made: the venue page that was looked at and never booked, the payment step where people give up, the search that returns nothing — we record a small number of events of your use of the applications.
- What is recorded. The name of the event from a fixed, closed list (for example: a venue viewed, a search performed, a booking started, a payment step begun, a booking completed, a venue saved or removed, a share started, a notification opened), the moment it occurred as stamped by our server, the application it came from, and where relevant the venue, court or booking concerned, together with a small amount of detail specific to the event (for example, the step of the flow that was reached).
- Who it is attached to. Where you are signed in, the event is attached to your account from your session — never from anything the application sends. Whether you are signed in or not, it also carries two opaque identifiers generated on your device: an installation identifier, kept on the device until you clear the application or browser data, and a visit identifier valid for the current visit only. They contain no data about you and exist so that the steps of one visit can be counted as one visit. Both are listed in the Cookie Policy (section 4).
- What it is not. This is our own measurement, carried out on our own systems. We use no third-party analytics service, no advertising network, no advertising pixel and no cross-site tracking, and we do not share these events with anyone. They are not used to build an advertising profile of you and they do not affect your level, your bookings or the price you pay.
- What happens on deletion of your account. The events are detached from you — they remain as an unattributed record of how the Platform was used, which is a venue's own operating record, and can no longer be linked back to you.
- Objection. You may object to this processing at any time under section 10.
4. What your personal data is used for and the legal basis
We process personal data only for the purposes for which it was collected, on an appropriate legal basis:
- Creating and maintaining your account — identification, sign-in with a one-time code or through Google/Apple, and keeping you signed in. Legal basis: performance of a contract.
- Booking courts — creating, changing, cancelling and displaying bookings, and passing the booking to the venue so that the court is actually held for you. Legal basis: performance of a contract.
- Payments, refunds and receipts — executing card transactions, collecting the shares of a shared booking, refunding cancellations, and issuing accounting documents. Legal basis: performance of a contract and legal obligation (tax and accounting legislation).
- Collecting outstanding amounts — recording and collecting a debt arising from an uncollectable booking. Legal basis: performance of a contract and legitimate interest.
- Credit at a venue — holding your balance, executing top-ups, applying credit to a booking at your request, granting and expiring promotional credit, and keeping the record of every movement. Legal basis: performance of a contract and legal obligation (tax and accounting legislation).
- Promo codes — applying a discount and enforcing the limits of the campaign. Legal basis: performance of a contract and legitimate interest (preventing abuse of a promotion).
- A booking made for you by a venue — linking it to your account and recording your answer to a request to collect it through the Platform. Legal basis: performance of a contract; and, for collection through the Platform, your express acceptance, without which no amount is charged to you.
- Organising a match — invitations, seats, guests, responses and reminders. Legal basis: performance of a contract.
- Open matches — publishing the free seats of a booking so that other players can join. Legal basis: performance of a contract, at the organiser's initiative.
- Transactional notifications — confirmations, invitations, payment and refund notices, reminders before a match, requests to confirm a result, and security notices, delivered in the application, by push, by e-mail or by SMS. These are not promotional. Legal basis: performance of a contract.
- Push notifications on your device — delivery to a device requires your permission on that device. Legal basis: consent.
- Delivering an invitation to a person who is not a Padli user — a single message to the contact detail provided by the person inviting them. Legal basis: legitimate interest (delivering an invitation the recipient is expected to receive), balanced by a strict daily limit and an unconditional opt-out.
- Match results, history and tagging — recording what was played and with whom, with the confirmation of the people concerned. Legal basis: performance of a contract.
- Calculating the player level — deriving a level and its reliability from confirmed results of competitive matches. Legal basis: performance of a contract and legitimate interest (matching players of comparable strength).
- Leaderboards and statistics — awarding and displaying ranking points at a venue and platform-wide. Legal basis: legitimate interest, subject to the visibility setting you control.
- Connections and public profiles — displaying profiles, followers and match history to other users to the extent your settings allow. Legal basis: performance of a contract.
- Discovery through your contacts — comparing the contacts you choose to send against registered accounts. Legal basis: consent, given each time you start it.
- Blocking and safety — enforcing mutual invisibility between users. Legal basis: legitimate interest (protection of users).
- Wallet passes and calendar invitations — issuing and keeping a pass up to date, and producing a calendar entry. Legal basis: performance of a contract, at your request.
- Security of the account and the Platform — sessions, rate limiting on sign-in and payment endpoints, detection and prevention of abuse and fraud. Legal basis: legitimate interest and legal obligation.
- Administrative accountability — logging every change made by venue staff and administrators. Legal basis: legitimate interest and legal obligation.
- Support — answering your questions and resolving complaints. Legal basis: performance of a contract and legitimate interest.
- Improving the service — internal analysis of how the Platform is used, based on the events described in section 3.30, in order to find where it fails people and to correct it. This measurement is our own, is not shared with anyone and is not used for advertising. Legal basis: legitimate interest, to which you may object under section 10.
- Security of your devices — showing you the sessions signed in to your account and detecting unauthorised access, using the data in section 3.23. Legal basis: legitimate interest and performance of a contract.
- Marketing communication — news, offers and tips about Padli, only where you have given your consent. Legal basis: consent, withdrawable at any time.
5. Sharing data
5.1. With the venue
When you book a court, the venue receives what it needs in order to hold the court and provide the service: your name, the details of the booking, the participants and their status, your check-in, and the financial data relating to that booking. Where you contact the venue, it receives the contact detail you use.
The venue processes this data as an independent controller for its own purposes (running its facility, its obligations towards you and its own legal obligations). Its use of your data for its own purposes is governed by its own privacy notice, and questions about it should be addressed to the venue.
5.2. With other users
Padli is a social platform, so part of your data is by design visible to other people:
- In a booking you share — the other participants see your name, your profile picture, your seat and whether it is paid.
- On your profile — the data described in section 3.15, to the extent your privacy settings allow.
- On leaderboards and venue player lists — your name, picture and points, unless you have switched this off.
- In a venue's public results feed — matches played at that venue. Players whose settings do not allow it are masked rather than named, and guests are never named.
- In an open match — the players already in the booking are shown to those considering joining it.
You control this through your privacy settings, the private-profile option, the venue-list setting, and blocking.
5.3. Processors and third parties
To deliver the service securely we work with the following providers, who process data on our behalf and only for the purpose for which it was entrusted to them:
- Halk Bank AD Skopje — processing card payments through their NESTPAY system. The bank is certified by VISA and MasterCard and operates in accordance with PCI DSS standards. We have no insight into your card data.
- DigitalOcean (DigitalOcean LLC, USA) — hosting infrastructure and object storage for images (venue and court photographs, profile pictures) delivered over their CDN.
- Google LLC (USA) — Firebase Cloud Messaging for the delivery of push notifications; Google Sign-In where you use it; Google Maps for displaying venue locations and directions; Google Wallet where you add a booking as a pass.
- Apple Inc. (USA) — Sign in with Apple where you use it; the Apple Push Notification service for notifications and Live Activities on iOS; Apple Wallet where you add a booking as a pass.
- LINK Mobility (Tera Communications) — delivery of SMS messages: sign-in codes, booking invitations and the responses to them, payment reminders, a venue's request to collect a booking, and confirmation of a change to your telephone number.
- Our e-mail provider — delivery of transactional e-mail (confirmations, receipts, invitations, reminders).
We do not sell personal data. We do not use advertising networks, advertising pixels or third-party analytics services, and we do not share your data with them. The measurement of how the Platform is used (section 3.30) is carried out entirely on our own systems and is disclosed to no one.
We may disclose data where we are required to do so by law, upon the request of a competent authority, or where it is necessary to establish, exercise or defend legal claims.
6. Automated decision-making
The player level is calculated automatically from the confirmed results of matches marked as competitive, from your answers to the starting questionnaire, and from the strength of the players you played with and against.
This calculation is not a decision producing legal effects concerning you, and it does not restrict your access to the service: it determines only how you are classified for the purpose of matching players of comparable strength. You may lower your own level yourself, you can see the history of every change and its reason, and you may contact us if you believe a change is wrong. We do not carry out profiling for advertising purposes, and we do not use your data to train artificial-intelligence models.
7. International data transfers
Some of our processors (DigitalOcean, Google, Apple) are established in the United States of America. Transfers of data outside the Republic of North Macedonia are carried out in accordance with the applicable legislation, including Standard Contractual Clauses and other appropriate safeguards provided for by the Law on Personal Data Protection and the GDPR. These providers apply technical and organisational protection measures in accordance with industry standards.
8. Retention periods
Personal data is retained no longer than necessary for the purposes for which it is processed:
- Account data — for as long as your account exists. Upon deletion, the data is anonymised or deleted within 30 days, unless a legal obligation requires longer retention.
- One-time codes (OTP) — valid for a few minutes and single-use; expired codes are removed.
- Booking data — for the duration of the account, and thereafter in anonymised form in the venue's records and in aggregated statistics.
- Financial and transaction data, and issued receipts — retained in accordance with the tax and accounting legislation of the Republic of North Macedonia (as a rule 10 years). These records survive the deletion of the account, which is why deletion anonymises rather than erases the account.
- Saved card data (token, brand, last four digits, expiry) — until you delete the card, or until it expires, after which it is deactivated and no longer used.
- Account balance and debts — until settled, and thereafter as part of the financial record.
- Credit at a venue and the record of its movements — for the duration of the account; the record of movements is part of the financial record and is retained accordingly, in a form that no longer identifies you once the account is deleted.
- Promo-code redemptions — as part of the financial record of the booking they discounted.
- Match results, history and ranking points — kept as a permanent record of what was played, so that leaderboards and levels remain consistent. Upon deletion of an account, the person is no longer identifiable in them.
- Player level and its history — for the duration of the account.
- Contacts sent for discovery — not retained; they are compared and discarded within the request.
- Invitations to people who are not users — the record that an invitation was sent is kept in order to prevent repeated contact; an opt-out is kept permanently, precisely so that it continues to be respected.
- Device tokens for push notifications — while the device is active; removed when the device stops responding or notifications are turned off.
- Live Activity tokens — for the duration of the activity, at most a few hours.
- Wallet pass registrations — until the pass is removed from the device.
- Sessions, and the device data recorded with them (network address, application identification, device name) — until the session expires or you sign it out, whereupon they are deleted together with it.
- Events of use of the Platform (section 3.30) — 400 days, then automatically deleted. Upon deletion of an account they are detached from the person immediately and can no longer be linked to them.
- Undeliverable e-mail addresses — kept for as long as necessary to avoid attempting delivery to an address that does not exist.
- Notifications — the record of notifications sent to you is kept for the duration of your account and is removed together with it.
- Activity logs of venue staff and administrators — kept for 365 days as an accountability record, independently of the individual account.
- Technical and diagnostic logs — kept for 90 days, then automatically deleted.
- Outgoing e-mail queue — records of dispatched messages are automatically deleted shortly after delivery.
- Correspondence with support — for as long as necessary to resolve the request and to keep a record of it.
- Data kept on your device (language, appearance, one-time prompts) — until you clear the application data or the browser storage.
9. Data security
We take security seriously. Data in transit is encrypted with HTTPS and Secure Socket Layer (SSL) technology. The session that keeps you signed in is stored in a cookie that JavaScript cannot read, is limited to a single subdomain, and expires; on our side it is stored only as a cryptographic hash and can therefore not be read out of our database. Where an account uses a password (venue staff and administrators), the password is stored only as a cryptographic hash. Access to personal data is limited to authorised persons, and every administrative change is logged.
Card payments are executed through the NESTPAY system of Halk Bank AD Skopje. We have no insight whatsoever into your card data (card number, security code or account balance).
Despite the protection measures applied, we cannot fully guarantee that they will prevent third parties from unlawfully obtaining personal data. Any security breach will be reported to the competent authority and to the affected users within the statutory deadlines.
10. What are your rights?
In accordance with the Law on Personal Data Protection and the General Data Protection Regulation (GDPR), you have:
- The right to information and access — to be informed about the processing of your personal data and to obtain access to it.
- The right to rectification — to request correction of inaccurate data. Most of it you can correct yourself in your profile settings.
- The right to erasure — to request deletion of your data. You may delete your account yourself from your settings. The request is fulfilled within 30 days, subject to data we are legally obliged to retain (in particular financial records, which are anonymised rather than erased) and subject to settlement of any outstanding balance.
- The right to restriction of processing — in the circumstances provided for by law.
- The right to data portability — to receive the data you have provided in a structured, commonly used and machine-readable format.
- The right to object — to processing based on legitimate interest, including your appearance on leaderboards and venue lists, and to processing for direct marketing.
- The right to withdraw consent — at any time, free of charge and by simple means, where processing is based on consent (marketing, push notifications, contacts discovery). Withdrawal does not affect the lawfulness of processing carried out before it.
- The right to lodge a complaint with the supervisory authority — with the Agency for Personal Data Protection of the Republic of North Macedonia, if you consider that the processing of your data infringes the applicable regulations.
To exercise these rights, contact our data protection officer at hey@padli.app, stating your first and last name, the phone number or e-mail address registered on your account, the address at which you wish to receive a reply, and the substance of your request. We may ask you for additional confirmation of your identity before acting on a request.
A note on data that is not only yours. A match, a result and a shared booking concern several people at once. Where you request erasure, we remove your identification from them, but we cannot delete the record of a match for the other participants, nor the financial records we are required to keep.
11. Direct marketing
We send marketing messages (news, offers and tips about Padli) only where you have given your consent. Consent is never presumed and is off for every account by default: it is given by an affirmative act in your account settings, and we record the moment it was given. You may withdraw it at any time, through your notification settings or through the unsubscribe link in every such message, and the record of consent is cleared when you do. Withdrawal does not stop the transactional messages necessary for a booking and for the security of your account.
12. Cookies and data stored on your device
We use one cookie — the session cookie that keeps you signed in — and a small number of values stored locally on your device: your own settings, and the two opaque identifiers used to count a visit as one visit (section 3.30). We use no analytics cookies, no advertising cookies, no advertising pixels and no third-party trackers. The details, value by value, are set out in the Cookie Policy at www.padli.app/cookie-policy.
13. Children and minors
An account may be opened by a person aged 18 or over, who alone has the legal capacity to enter into the contract and to pay.
The Law on Personal Data Protection of the Republic of North Macedonia sets 14 years as the age from which a minor may themselves consent to the processing of their personal data in relation to services offered online. Accordingly:
- Under 14 — we do not permit accounts and do not knowingly process such data. Where we establish that an account belongs to a person under 14, we will close it and delete the data, save for anything we are legally obliged to retain.
- From 14 to 18 — the Platform may be used only with the consent and under the supervision of a parent or legal guardian, who accepts the Terms of Use on the minor's behalf, is responsible for payment, and exercises the minor's rights under section 10 on their behalf.
We process the data of a minor for the same purposes and on the same bases as set out in this Policy, and no more of it. We may request proof of age or of parental consent, and may restrict or close an account where they cannot be established.
A junior may also play without any account at all, as a guest named by an adult account holder. In that case we process only the name entered and, where provided, a contact detail. The adult who enters them is responsible for having the agreement of the guest and, where the guest is a minor, of their parent or guardian.
If you are a parent or guardian and you believe that your child holds an account without your consent, write to us at hey@padli.app and we will act on it.
14. Cooperation with competent authorities
VORTEK INOVATIONS cooperates with the police and other competent authorities in reporting unlawful activities. The identity of a user will be disclosed only upon the request of a competent authority, in accordance with the applicable legislation.
15. Changes to this Policy
We reserve the right to amend this Privacy Policy. The changes take effect upon their publication on the Platform, unless otherwise stated. Where a change materially affects your rights, we will notify you in advance by a reasonable means.
16. Contact information
For questions, requests or complaints regarding the protection of personal data or this Policy:
- Data protection officer — E-mail: hey@padli.app
VORTEK INOVATIONS D.O.O. Skopje, Njudehliska 6/1-13, Karposh, Skopje, North Macedonia EMBS: 7757832 | TAX ID: MK4057024570335