[{"data":1,"prerenderedAt":8},["ShallowReactive",2],{"legal-privacy-policy-en":3},{"html":4,"updated":5,"isFallback":6,"excerpt":7},"\u003Cp>\u003Cstrong>Padli\u003C\u002Fstrong> — padel court booking platform\nOperated by VORTEK INOVATIONS D.O.O. Skopje\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Last updated:\u003C\u002Fstrong> 16 September 2026\u003C\u002Fp>\n\u003Chr>\n\u003Ch2>1. Personal data controller\u003C\u002Fh2>\n\u003Cp>The personal data controller is \u003Cstrong>VORTEK INOVATIONS D.O.O. Skopje\u003C\u002Fstrong>, a trade and services\ncompany with its registered office at Njudehliska 6\u002F1-13, Karposh, Skopje, EMBS 7757832,\nTAX ID MK4057024570335. For questions regarding the processing of personal data, you may\ncontact our data protection officer at: \u003Cstrong>\u003Ca href=\"mailto:hey@padli.app\">hey@padli.app\u003C\u002Fa>\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>This Policy explains what personal data we collect when you use the Padli platform\n(\u003Ca href=\"http:\u002F\u002Fwww.padli.app\">www.padli.app\u003C\u002Fa> and the Padli mobile applications), why we collect it, on what legal basis,\nwith whom we share it and how long we keep it.\u003C\u002Fp>\n\u003Ch2>2. What is personal data?\u003C\u002Fh2>\n\u003Cp>In accordance with the Law on Personal Data Protection of the Republic of North Macedonia,\n&quot;personal data&quot; means any information relating to an identified natural person or a natural\nperson who can be identified (data subject), directly or indirectly, in particular by\nreference to an identifier such as a name, an identification number, location data, an\nonline identifier, or one or more factors specific to that person&#39;s physical,\nphysiological, genetic, mental, economic, cultural or social identity.\u003C\u002Fp>\n\u003Cp>Processing of personal data is any operation performed on personal data, whether automated\nor not — collection, recording, organisation, structuring, storage, adaptation, alteration,\nretrieval, consultation, use, disclosure by transmission, publication or otherwise making\navailable, alignment or combination, restriction, erasure or destruction.\u003C\u002Fp>\n\u003Ch2>3. Which types of data do we collect and process?\u003C\u002Fh2>\n\u003Ch3>3.1. Visitors browsing without registration\u003C\u002Fh3>\n\u003Cp>You can browse venues, courts, prices and free slots without an account. In doing so we\nprocess only technical data necessary for the service to work — the request data your\nbrowser or application sends (IP address, device and browser type, language) and the\nsession cookie described in section 12 if you subsequently sign in. Location is used only\nif you grant permission to your device, to sort venues by distance; it is not stored on\nour servers.\u003C\u002Fp>\n\u003Ch3>3.2. Creating a player account\u003C\u002Fh3>\n\u003Cp>A player account is created with a \u003Cstrong>phone number or an e-mail address\u003C\u002Fstrong>, confirmed by a\n\u003Cstrong>one-time code (OTP)\u003C\u002Fstrong> that we send you. Padli player accounts have no password. We\nprocess:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>First and last name\u003C\u002Fstrong> — entered by you; you are responsible for its accuracy. Visible\nto other players (section 5.2).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Phone number and\u002For e-mail address\u003C\u002Fstrong> — your identifier and the channel through which\nwe confirm your identity and send you booking messages. The one-time code is short-lived\nand single-use.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Date of birth and gender\u003C\u002Fstrong> — optional, entered by you.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Profile picture\u003C\u002Fstrong> — optional.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Language\u003C\u002Fstrong> — the language in which the Platform is displayed to you.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Verification and sign-in timestamps\u003C\u002Fstrong> — when your phone or e-mail was confirmed and\nwhen you last signed in.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>3.3. Signing in with Google or Apple\u003C\u002Fh3>\n\u003Cp>Where you sign in with Google or with Apple, we receive from the provider only basic\nprofile information — an identifier, your name, your e-mail address and, where available, a\nprofile picture. \u003Cstrong>We never receive your password with the provider.\u003C\u002Fstrong> Where the e-mail\naddress returned is already verified by the provider and matches an existing Padli account,\nwe link the two so that you reach the same account by either route. We store the provider&#39;s\nidentifier in order to recognise you on your next sign-in. Where you signed in with Apple\nand later delete your account, we ask Apple to revoke the grant you gave us.\u003C\u002Fp>\n\u003Ch3>3.4. Player profile and playing preferences\u003C\u002Fh3>\n\u003Cp>Optionally, and only if you fill them in: a short biography (up to 280 characters), your\ndominant hand, your preferred side of the court, your playing style, your preferred time of\nday to play, and a self-declared skill level. These describe how you play and are shown on\nyour profile to the players entitled to see it.\u003C\u002Fp>\n\u003Ch3>3.5. Booking data\u003C\u002Fh3>\n\u003Cp>For each booking: the venue and court, the date, start time and duration, the sport and\nformat, the price and the service fee, the status of the booking, the participants and\ntheir seats, and your check-in where the venue uses it. Booking data is visible to you, to\nthe other participants in that booking, and to the venue at which it was made.\u003C\u002Fp>\n\u003Ch3>3.6. Payment data\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Card payments.\u003C\u002Fstrong> Payments are processed by \u003Cstrong>Halk Bank AD Skopje\u003C\u002Fstrong> through their\nNESTPAY system, on a page hosted by the bank, with 3-D Secure authentication. \u003Cstrong>We have\nno insight into your card data\u003C\u002Fstrong> — the full card number, the security code and your\naccount balance never reach our systems.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Saved cards.\u003C\u002Fstrong> Where you choose to save a card, we store only the token issued by the\nbank together with the card brand, the last four digits and the expiry date, so that a\nlater booking can be charged without re-entering the card. You may delete a saved card at\nany time.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Transactions.\u003C\u002Fstrong> For each charge, refund, reservation of funds (pre-authorisation) or\ndeclined attempt we keep a record: the amount and currency, the purpose, the status, the\ntime, the bank&#39;s reference and, where the payment failed, the reason given by the bank.\nThe record also states \u003Cstrong>how the payment was funded\u003C\u002Fstrong> (a card or your credit at the venue)\nand the amount of any promo-code discount applied to it.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Expiring cards.\u003C\u002Fstrong> Where a saved card is about to expire we note that we have warned you,\nso that the reminder is sent once and not repeatedly.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>3.6.1. Receipts and billing identity\u003C\u002Fh3>\n\u003Cp>A charge produces an electronic receipt or invoice — one document where Padli is the seller\nof record, and two where the venue&#39;s company sells as principal and Padli issues in its name\n(General Terms of Use, section 4). Each contains the amount, the value added tax, your\nidentification as the payer, our own legal identity, and the legal identity of the venue that\nrendered the service. \u003Cstrong>The identities on a receipt, and the tax rate applied to it, are\nfrozen at the moment of the charge\u003C\u002Fstrong>, because an issued accounting document must not change\nafterwards. For that reason we store the applicable rate, and the arrangement the sale was\nmade under, on the booking itself.\u003C\u002Fp>\n\u003Ch3>3.7. Account balance\u003C\u002Fh3>\n\u003Cp>Where a shared booking cannot be collected in full from the participants, the shortfall is\nrecorded as an outstanding balance (a debt) on the organiser&#39;s account. We keep the balance,\nits currency and its history of movements. This is a separate matter from credit standing in\nyour favour at a venue, which is described in section 3.27.\u003C\u002Fp>\n\u003Ch3>3.8. Shared bookings and invitations\u003C\u002Fh3>\n\u003Cp>Where you invite other players to a booking we process the invitation, its status\n(pending, accepted, declined), the seat it relates to, the share of the price and of the\nservice fee attaching to that seat, and whether the seat was filled by invitation or from\na public listing. The other participants in a booking see who is in it and which seats are\npaid.\u003C\u002Fp>\n\u003Ch3>3.9. Data about guests (people who are not Padli users)\u003C\u002Fh3>\n\u003Cp>Where you name a \u003Cstrong>guest\u003C\u002Fstrong> in a booking, we process the name you entered and, where you\nprovided one, a phone number or e-mail address, in order to record who occupies the seat\nand — where you asked for it — to deliver the invitation to them.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When you enter another person&#39;s data you must have their agreement.\u003C\u002Fstrong> Guests are never\nnamed publicly on the Platform: they are visible only to the people in the same booking and\nare never shown in public results feeds or leaderboards.\u003C\u002Fp>\n\u003Cp>Where an invitation is sent to a person who has no Padli account, we record the fact that\nit was sent, so that the same person is not contacted repeatedly, and we record an opt-out\nif they ask not to be contacted again. A person who has opted out is never contacted again.\nSuch invitations are subject to a strict daily limit.\u003C\u002Fp>\n\u003Ch3>3.10. Open matches\u003C\u002Fh3>\n\u003Cp>Where you make the free seats of your booking publicly joinable, the booking becomes\nvisible in the discovery feed to other players — with the venue, the date and time, the\nprice per seat, the free seats and the players already in it, to the extent their own\nvisibility settings allow. We record when the booking was made public and how each seat was\nobtained.\u003C\u002Fp>\n\u003Ch3>3.11. Match results and live scoring\u003C\u002Fh3>\n\u003Cp>We process the scores entered for a match, who entered or proposed them, who confirmed or\ncontested them, and when. Where a result is not contested it is confirmed automatically\nafter 24 hours. Where participants score a match live while playing, we process the\nsuccessive states of the scoreboard and which participant entered each change.\u003C\u002Fp>\n\u003Cp>Where a person states that they were not in fact in a match, we record that statement\ntogether with its author, because it invalidates the result for everyone and may be\ncontested by the seat holder.\u003C\u002Fp>\n\u003Ch3>3.12. Match history and tagging\u003C\u002Fh3>\n\u003Cp>You may record who you played with. Where you tag a Padli user, the tag is a \u003Cstrong>request\u003C\u002Fstrong>:\nwe process it as pending until that person accepts or declines it, and it attaches to their\nhistory only if they accept.\u003C\u002Fp>\n\u003Ch3>3.13. Player level and rating\u003C\u002Fh3>\n\u003Cp>We calculate and store your level (a scale from 0 to 7), an indication of its reliability,\nthe history of its changes with the reason for each change, the answers to the questionnaire\nyou complete when you set your starting level, and the pairings of confirmed competitive\nresults from which the level is calculated. Section 6 explains the automated nature of this\ncalculation.\u003C\u002Fp>\n\u003Ch3>3.14. Leaderboards and ranking points\u003C\u002Fh3>\n\u003Cp>We store the points you earn at each venue and platform-wide, and the ledger of how they\nwere earned. Points accumulate over time and are not reset. Whether you appear on a venue&#39;s\nplayer lists is a setting you control.\u003C\u002Fp>\n\u003Ch3>3.15. Connections and public profile\u003C\u002Fh3>\n\u003Cp>We process who you follow and who follows you, and whether your profile is private. Your\npublic profile may show your name, profile picture, biography, level, playing preferences,\nstatistics, match history, and your followers and the accounts you follow — subject to your\nprivacy settings.\u003C\u002Fp>\n\u003Ch3>3.16. Discovery through your phone contacts\u003C\u002Fh3>\n\u003Cp>If you choose to look for people you know, the application reads the contacts you allow it\nto read on your device and sends the phone numbers and e-mail addresses in a batch to our\nserver, where they are compared against registered accounts.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>The contacts you send are used solely for that comparison and are not stored.\u003C\u002Fstrong> We keep\nneither the matched nor the unmatched contacts; the result is returned to your device and\nthe batch is discarded. We never contact a person from your contact list on our own\ninitiative. This happens only when you start it, and never automatically.\u003C\u002Fp>\n\u003Ch3>3.17. Blocking\u003C\u002Fh3>\n\u003Cp>Where you block another user, we record the block. Its effect is mutual invisibility: the\ntwo of you disappear from each other&#39;s profiles, searches, lists and suggestions, and any\nfollow between you is severed.\u003C\u002Fp>\n\u003Ch3>3.18. Invite codes\u003C\u002Fh3>\n\u003Cp>Each account carries a permanent personal invite code. Where a new user registers through\nyour code, we record the connection between the two accounts.\u003C\u002Fp>\n\u003Ch3>3.19. Favourite venues\u003C\u002Fh3>\n\u003Cp>The venues you save are stored on your account so that they follow you across devices.\u003C\u002Fp>\n\u003Ch3>3.20. Notifications and devices\u003C\u002Fh3>\n\u003Cp>To deliver notifications we store a \u003Cstrong>device token\u003C\u002Fstrong> issued by the push service, together\nwith the type of device and which of our applications it belongs to. We also store your\n\u003Cstrong>notification preferences\u003C\u002Fstrong> — a switch for each category (bookings, reminders, invitations,\npayments) on each channel (push, e-mail, SMS), all on unless you turn one off.\u003C\u002Fp>\n\u003Cp>We also keep a record of each notification sent to you: its type, what it refers to (for\nexample, a booking or an invitation) and whether you have read it. The text itself is not\nstored — it is composed on your device, in your language, from that record. A device token is\nremoved when the device stops responding or when you turn notifications off.\u003C\u002Fp>\n\u003Cp>Where an e-mail address is definitively rejected by the receiving server (it does not\nexist), we record the address so that we stop attempting delivery to it. The record is kept\nby address and may relate to a person who has no Padli account, such as a guest or an\ninvitee.\u003C\u002Fp>\n\u003Ch3>3.21. Live Activities on iOS\u003C\u002Fh3>\n\u003Cp>Where you allow it, an iOS device may show a countdown to your match and the live score on\nthe lock screen. For this we store a separate short-lived token issued by Apple for that\nspecific activity, which becomes invalid when the activity ends.\u003C\u002Fp>\n\u003Ch3>3.22. Wallet passes and calendar invitations\u003C\u002Fh3>\n\u003Cp>Where you add a booking to Apple Wallet or Google Wallet, we store the registration of that\npass so that it can be updated when the booking changes, and we remove it when the pass is\nremoved. Booking confirmation e-mails contain a calendar invitation with the details of the\nmatch, so that it can be added to your calendar.\u003C\u002Fp>\n\u003Ch3>3.23. Sessions and account security\u003C\u002Fh3>\n\u003Cp>We store your active sessions (as an expiring, encrypted-at-rest token, not as a readable\ncredential), the surface they belong to, and when they were last used. This is what keeps\nyou signed in and what allows a session to be ended.\u003C\u002Fp>\n\u003Cp>For each session we additionally record, at the moment it is created, \u003Cstrong>the network (IP)\naddress and the browser or application identification it was created from, and the device\nname and platform derived from them\u003C\u002Fstrong>, and we refresh the address when the session is next\nused. This is what lets us show you a list of the devices signed in to your account, so that\nyou can recognise one that is not yours and sign it out, and it is used to detect and\nprevent unauthorised access. It is deleted together with the session.\u003C\u002Fp>\n\u003Ch3>3.24. Venue staff and administrators\u003C\u002Fh3>\n\u003Cp>Where you are a member of a venue&#39;s staff or an administrator, we additionally process your\ne-mail address and password (stored only as a cryptographic hash, never in readable form),\nthe venue you belong to, the permissions granted to you, the invitation through which your\naccount was created, and an \u003Cstrong>activity log of every change you make\u003C\u002Fstrong> in the console — what\nwas changed, by whom and when. The log is an accountability record and is retained\nindependently of the account.\u003C\u002Fp>\n\u003Ch3>3.25. Support and correspondence\u003C\u002Fh3>\n\u003Cp>Where you contact us, we process your message and the contact details you use, in order to\nanswer you and to keep a record of the request and its resolution.\u003C\u002Fp>\n\u003Ch3>3.26. Appearance and application settings\u003C\u002Fh3>\n\u003Cp>Your chosen language, your light or dark appearance, and a small number of technical flags\n(for example, whether a one-time explanatory prompt has already been shown to you) are kept\n\u003Cstrong>on your device\u003C\u002Fstrong>, not on our servers. They are listed individually in the Cookie Policy\n(section 4); see also section 12 below.\u003C\u002Fp>\n\u003Ch3>3.27. Credit at a venue\u003C\u002Fh3>\n\u003Cp>Where you hold credit at a venue we process the \u003Cstrong>balance\u003C\u002Fstrong> and, separately, the part of it\nthat was granted as a bonus and the date on which that part expires. Beside the balance we\nkeep an \u003Cstrong>unchangeable record of every movement\u003C\u002Fstrong> into and out of it: the amount, the\nresulting balance, the reason (a top-up you paid for, a refund taken as credit, a payment\nfor a booking, a bonus granted, a bonus expired, an adjustment made by our support team, or\na forfeit on deletion of the account), the booking or transaction it relates to, and — where\na member of our staff moved it — who did so and any note they left.\u003C\u002Fp>\n\u003Cp>That record exists so that the question &quot;where did my credit go?&quot; can be answered months\nlater, and so that a balance can be shown never to have been quietly altered. A top-up is\nalso a card payment and is recorded as one under section 3.6.\u003C\u002Fp>\n\u003Ch3>3.28. Promo codes\u003C\u002Fh3>\n\u003Cp>Where you use a promo code we record \u003Cstrong>that you used it\u003C\u002Fstrong>, on which booking, the amount\ndiscounted and the moment of use. That record is what enforces the limits of the campaign\n(one use per player, a total number of uses, first booking only) and what allows a\ndiscounted charge to be explained afterwards.\u003C\u002Fp>\n\u003Ch3>3.29. Bookings a venue makes for you\u003C\u002Fh3>\n\u003Cp>Where a venue creates a booking for you at its desk, it enters the contact detail you gave\nit. Where that detail matches your account, the booking is linked to it. Where the venue asks\nthat the booking be collected through the Platform, we record \u003Cstrong>the request and your answer\nto it\u003C\u002Fstrong> — that it was made, and whether you accepted or declined — because that answer is\nwhat determines whether you may be charged at all. An unanswered request is never treated as\nan acceptance.\u003C\u002Fp>\n\u003Ch3>3.30. How the Platform is used (product analytics)\u003C\u002Fh3>\n\u003Cp>To understand how the Platform is used — and above all what does \u003Cstrong>not\u003C\u002Fstrong> work, which cannot\nbe reconstructed from bookings that were made: the venue page that was looked at and never\nbooked, the payment step where people give up, the search that returns nothing — we record a\nsmall number of \u003Cstrong>events of your use of the applications\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>What is recorded.\u003C\u002Fstrong> The name of the event from a fixed, closed list (for example: a\nvenue viewed, a search performed, a booking started, a payment step begun, a booking\ncompleted, a venue saved or removed, a share started, a notification opened), the moment\nit occurred \u003Cstrong>as stamped by our server\u003C\u002Fstrong>, the application it came from, and where relevant\nthe venue, court or booking concerned, together with a small amount of detail specific to\nthe event (for example, the step of the flow that was reached).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Who it is attached to.\u003C\u002Fstrong> Where you are signed in, the event is attached to your account\nfrom your session — never from anything the application sends. Whether you are signed in\nor not, it also carries two \u003Cstrong>opaque identifiers generated on your device\u003C\u002Fstrong>: an\ninstallation identifier, kept on the device until you clear the application or browser\ndata, and a visit identifier valid for the current visit only. They contain no data about\nyou and exist so that the steps of one visit can be counted as one visit. Both are listed\nin the \u003Cstrong>Cookie Policy\u003C\u002Fstrong> (section 4).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>What it is not.\u003C\u002Fstrong> This is our own measurement, carried out on our own systems. \u003Cstrong>We use\nno third-party analytics service, no advertising network, no advertising pixel and no\ncross-site tracking, and we do not share these events with anyone.\u003C\u002Fstrong> They are not used to\nbuild an advertising profile of you and they do not affect your level, your bookings or\nthe price you pay.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>What happens on deletion of your account.\u003C\u002Fstrong> The events are \u003Cstrong>detached from you\u003C\u002Fstrong> — they\nremain as an unattributed record of how the Platform was used, which is a venue&#39;s own\noperating record, and can no longer be linked back to you.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Objection.\u003C\u002Fstrong> You may object to this processing at any time under section 10.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>4. What your personal data is used for and the legal basis\u003C\u002Fh2>\n\u003Cp>We process personal data only for the purposes for which it was collected, on an\nappropriate legal basis:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Creating and maintaining your account\u003C\u002Fstrong> — identification, sign-in with a one-time code\nor through Google\u002FApple, and keeping you signed in. \u003Cem>Legal basis: performance of a\ncontract.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Booking courts\u003C\u002Fstrong> — creating, changing, cancelling and displaying bookings, and passing\nthe booking to the venue so that the court is actually held for you. \u003Cem>Legal basis:\nperformance of a contract.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Payments, refunds and receipts\u003C\u002Fstrong> — executing card transactions, collecting the shares\nof a shared booking, refunding cancellations, and issuing accounting documents. \u003Cem>Legal\nbasis: performance of a contract and legal obligation (tax and accounting legislation).\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Collecting outstanding amounts\u003C\u002Fstrong> — recording and collecting a debt arising from an\nuncollectable booking. \u003Cem>Legal basis: performance of a contract and legitimate interest.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Credit at a venue\u003C\u002Fstrong> — holding your balance, executing top-ups, applying credit to a\nbooking at your request, granting and expiring promotional credit, and keeping the record\nof every movement. \u003Cem>Legal basis: performance of a contract and legal obligation (tax and\naccounting legislation).\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Promo codes\u003C\u002Fstrong> — applying a discount and enforcing the limits of the campaign. \u003Cem>Legal\nbasis: performance of a contract and legitimate interest (preventing abuse of a\npromotion).\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>A booking made for you by a venue\u003C\u002Fstrong> — linking it to your account and recording your\nanswer to a request to collect it through the Platform. \u003Cem>Legal basis: performance of a\ncontract; and, for collection through the Platform, your express acceptance, without which\nno amount is charged to you.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Organising a match\u003C\u002Fstrong> — invitations, seats, guests, responses and reminders. \u003Cem>Legal\nbasis: performance of a contract.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Open matches\u003C\u002Fstrong> — publishing the free seats of a booking so that other players can join.\n\u003Cem>Legal basis: performance of a contract, at the organiser&#39;s initiative.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Transactional notifications\u003C\u002Fstrong> — confirmations, invitations, payment and refund notices,\nreminders before a match, requests to confirm a result, and security notices, delivered\nin the application, by push, by e-mail or by SMS. These are not promotional. \u003Cem>Legal basis:\nperformance of a contract.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Push notifications on your device\u003C\u002Fstrong> — delivery to a device requires your permission on\nthat device. \u003Cem>Legal basis: consent.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Delivering an invitation to a person who is not a Padli user\u003C\u002Fstrong> — a single message to the\ncontact detail provided by the person inviting them. \u003Cem>Legal basis: legitimate interest\n(delivering an invitation the recipient is expected to receive), balanced by a strict\ndaily limit and an unconditional opt-out.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Match results, history and tagging\u003C\u002Fstrong> — recording what was played and with whom, with the\nconfirmation of the people concerned. \u003Cem>Legal basis: performance of a contract.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Calculating the player level\u003C\u002Fstrong> — deriving a level and its reliability from confirmed\nresults of competitive matches. \u003Cem>Legal basis: performance of a contract and legitimate\ninterest (matching players of comparable strength).\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Leaderboards and statistics\u003C\u002Fstrong> — awarding and displaying ranking points at a venue and\nplatform-wide. \u003Cem>Legal basis: legitimate interest, subject to the visibility setting you\ncontrol.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Connections and public profiles\u003C\u002Fstrong> — displaying profiles, followers and match history to\nother users to the extent your settings allow. \u003Cem>Legal basis: performance of a contract.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Discovery through your contacts\u003C\u002Fstrong> — comparing the contacts you choose to send against\nregistered accounts. \u003Cem>Legal basis: consent, given each time you start it.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blocking and safety\u003C\u002Fstrong> — enforcing mutual invisibility between users. \u003Cem>Legal basis:\nlegitimate interest (protection of users).\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Wallet passes and calendar invitations\u003C\u002Fstrong> — issuing and keeping a pass up to date, and\nproducing a calendar entry. \u003Cem>Legal basis: performance of a contract, at your request.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security of the account and the Platform\u003C\u002Fstrong> — sessions, rate limiting on sign-in and\npayment endpoints, detection and prevention of abuse and fraud. \u003Cem>Legal basis: legitimate\ninterest and legal obligation.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Administrative accountability\u003C\u002Fstrong> — logging every change made by venue staff and\nadministrators. \u003Cem>Legal basis: legitimate interest and legal obligation.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Support\u003C\u002Fstrong> — answering your questions and resolving complaints. \u003Cem>Legal basis:\nperformance of a contract and legitimate interest.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Improving the service\u003C\u002Fstrong> — internal analysis of how the Platform is used, based on the\nevents described in section 3.30, in order to find where it fails people and to correct\nit. This measurement is our own, is not shared with anyone and is not used for\nadvertising. \u003Cem>Legal basis: legitimate interest, to which you may object under section 10.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security of your devices\u003C\u002Fstrong> — showing you the sessions signed in to your account and\ndetecting unauthorised access, using the data in section 3.23. \u003Cem>Legal basis: legitimate\ninterest and performance of a contract.\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Marketing communication\u003C\u002Fstrong> — news, offers and tips about Padli, only where you have\ngiven your consent. \u003Cem>Legal basis: consent, withdrawable at any time.\u003C\u002Fem>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>5. Sharing data\u003C\u002Fh2>\n\u003Ch3>5.1. With the venue\u003C\u002Fh3>\n\u003Cp>When you book a court, the venue receives what it needs in order to hold the court and\nprovide the service: your name, the details of the booking, the participants and their\nstatus, your check-in, and the financial data relating to that booking. Where you contact\nthe venue, it receives the contact detail you use.\u003C\u002Fp>\n\u003Cp>The venue processes this data \u003Cstrong>as an independent controller\u003C\u002Fstrong> for its own purposes (running\nits facility, its obligations towards you and its own legal obligations). Its use of your\ndata for its own purposes is governed by its own privacy notice, and questions about it\nshould be addressed to the venue.\u003C\u002Fp>\n\u003Ch3>5.2. With other users\u003C\u002Fh3>\n\u003Cp>Padli is a social platform, so part of your data is by design visible to other people:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>In a booking you share\u003C\u002Fstrong> — the other participants see your name, your profile picture,\nyour seat and whether it is paid.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>On your profile\u003C\u002Fstrong> — the data described in section 3.15, to the extent your privacy\nsettings allow.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>On leaderboards and venue player lists\u003C\u002Fstrong> — your name, picture and points, unless you\nhave switched this off.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>In a venue&#39;s public results feed\u003C\u002Fstrong> — matches played at that venue. Players whose\nsettings do not allow it are masked rather than named, and guests are never named.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>In an open match\u003C\u002Fstrong> — the players already in the booking are shown to those considering\njoining it.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>You control this through your privacy settings, the private-profile option, the venue-list\nsetting, and blocking.\u003C\u002Fp>\n\u003Ch3>5.3. Processors and third parties\u003C\u002Fh3>\n\u003Cp>To deliver the service securely we work with the following providers, who process data on\nour behalf and only for the purpose for which it was entrusted to them:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Halk Bank AD Skopje\u003C\u002Fstrong> — processing card payments through their NESTPAY system. The bank\nis certified by VISA and MasterCard and operates in accordance with PCI DSS standards. We\nhave no insight into your card data.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>DigitalOcean (DigitalOcean LLC, USA)\u003C\u002Fstrong> — hosting infrastructure and object storage for\nimages (venue and court photographs, profile pictures) delivered over their CDN.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google LLC (USA)\u003C\u002Fstrong> — Firebase Cloud Messaging for the delivery of push notifications;\nGoogle Sign-In where you use it; Google Maps for displaying venue locations and\ndirections; Google Wallet where you add a booking as a pass.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Apple Inc. (USA)\u003C\u002Fstrong> — Sign in with Apple where you use it; the Apple Push Notification\nservice for notifications and Live Activities on iOS; Apple Wallet where you add a booking\nas a pass.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>LINK Mobility (Tera Communications)\u003C\u002Fstrong> — delivery of SMS messages: sign-in\ncodes, booking invitations and the responses to them, payment reminders, a venue&#39;s request\nto collect a booking, and confirmation of a change to your telephone number.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Our e-mail provider\u003C\u002Fstrong> — delivery of transactional e-mail (confirmations, receipts,\ninvitations, reminders).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>We do not sell personal data.\u003C\u002Fstrong> We do not use advertising networks, advertising pixels or\nthird-party analytics services, and we do not share your data with them. The measurement of\nhow the Platform is used (section 3.30) is carried out entirely on our own systems and is\ndisclosed to no one.\u003C\u002Fp>\n\u003Cp>We may disclose data where we are required to do so by law, upon the request of a competent\nauthority, or where it is necessary to establish, exercise or defend legal claims.\u003C\u002Fp>\n\u003Ch2>6. Automated decision-making\u003C\u002Fh2>\n\u003Cp>The \u003Cstrong>player level\u003C\u002Fstrong> is calculated automatically from the confirmed results of matches\nmarked as competitive, from your answers to the starting questionnaire, and from the\nstrength of the players you played with and against.\u003C\u002Fp>\n\u003Cp>This calculation is not a decision producing legal effects concerning you, and it does not\nrestrict your access to the service: it determines only how you are classified for the\npurpose of matching players of comparable strength. You may lower your own level yourself,\nyou can see the history of every change and its reason, and you may contact us if you\nbelieve a change is wrong. We do not carry out profiling for advertising purposes, and we\ndo not use your data to train artificial-intelligence models.\u003C\u002Fp>\n\u003Ch2>7. International data transfers\u003C\u002Fh2>\n\u003Cp>Some of our processors (DigitalOcean, Google, Apple) are established in the United States\nof America. Transfers of data outside the Republic of North Macedonia are carried out in\naccordance with the applicable legislation, including Standard Contractual Clauses and\nother appropriate safeguards provided for by the Law on Personal Data Protection and the\nGDPR. These providers apply technical and organisational protection measures in accordance\nwith industry standards.\u003C\u002Fp>\n\u003Ch2>8. Retention periods\u003C\u002Fh2>\n\u003Cp>Personal data is retained no longer than necessary for the purposes for which it is\nprocessed:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Account data\u003C\u002Fstrong> — for as long as your account exists. Upon deletion, the data is\nanonymised or deleted within 30 days, unless a legal obligation requires longer retention.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-time codes (OTP)\u003C\u002Fstrong> — valid for a few minutes and single-use; expired codes are\nremoved.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Booking data\u003C\u002Fstrong> — for the duration of the account, and thereafter in anonymised form in\nthe venue&#39;s records and in aggregated statistics.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Financial and transaction data, and issued receipts\u003C\u002Fstrong> — retained in accordance with the\ntax and accounting legislation of the Republic of North Macedonia (as a rule 10 years).\n\u003Cstrong>These records survive the deletion of the account\u003C\u002Fstrong>, which is why deletion anonymises\nrather than erases the account.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Saved card data (token, brand, last four digits, expiry)\u003C\u002Fstrong> — until you delete the card,\nor until it expires, after which it is deactivated and no longer used.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Account balance and debts\u003C\u002Fstrong> — until settled, and thereafter as part of the financial\nrecord.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Credit at a venue and the record of its movements\u003C\u002Fstrong> — for the duration of the account;\nthe record of movements is part of the financial record and is retained accordingly, in\na form that no longer identifies you once the account is deleted.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Promo-code redemptions\u003C\u002Fstrong> — as part of the financial record of the booking they\ndiscounted.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Match results, history and ranking points\u003C\u002Fstrong> — kept as a permanent record of what was\nplayed, so that leaderboards and levels remain consistent. Upon deletion of an account,\nthe person is no longer identifiable in them.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Player level and its history\u003C\u002Fstrong> — for the duration of the account.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Contacts sent for discovery\u003C\u002Fstrong> — \u003Cstrong>not retained\u003C\u002Fstrong>; they are compared and discarded within\nthe request.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Invitations to people who are not users\u003C\u002Fstrong> — the record that an invitation was sent is\nkept in order to prevent repeated contact; an opt-out is kept permanently, precisely so\nthat it continues to be respected.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Device tokens for push notifications\u003C\u002Fstrong> — while the device is active; removed when the\ndevice stops responding or notifications are turned off.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Live Activity tokens\u003C\u002Fstrong> — for the duration of the activity, at most a few hours.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Wallet pass registrations\u003C\u002Fstrong> — until the pass is removed from the device.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sessions, and the device data recorded with them\u003C\u002Fstrong> (network address, application\nidentification, device name) — until the session expires or you sign it out, whereupon they\nare deleted together with it.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Events of use of the Platform (section 3.30)\u003C\u002Fstrong> — \u003Cstrong>400 days\u003C\u002Fstrong>, then automatically\ndeleted. Upon deletion of an account they are detached from the person immediately and can\nno longer be linked to them.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Undeliverable e-mail addresses\u003C\u002Fstrong> — kept for as long as necessary to avoid attempting\ndelivery to an address that does not exist.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Notifications\u003C\u002Fstrong> — the record of notifications sent to you is kept for the duration of\nyour account and is removed together with it.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Activity logs of venue staff and administrators\u003C\u002Fstrong> — kept for \u003Cstrong>365 days\u003C\u002Fstrong> as an\naccountability record, independently of the individual account.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Technical and diagnostic logs\u003C\u002Fstrong> — kept for \u003Cstrong>90 days\u003C\u002Fstrong>, then automatically deleted.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Outgoing e-mail queue\u003C\u002Fstrong> — records of dispatched messages are automatically deleted\nshortly after delivery.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Correspondence with support\u003C\u002Fstrong> — for as long as necessary to resolve the request and to\nkeep a record of it.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data kept on your device\u003C\u002Fstrong> (language, appearance, one-time prompts) — until you clear\nthe application data or the browser storage.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>9. Data security\u003C\u002Fh2>\n\u003Cp>We take security seriously. Data in transit is encrypted with HTTPS and Secure Socket Layer\n(SSL) technology. The session that keeps you signed in is stored in a cookie that\nJavaScript cannot read, is limited to a single subdomain, and expires; on our side it is\nstored only as a cryptographic hash and can therefore not be read out of our database. Where\nan account uses a password (venue staff and administrators), the password is stored only as\na cryptographic hash. Access to personal data is limited to authorised persons, and every\nadministrative change is logged.\u003C\u002Fp>\n\u003Cp>Card payments are executed through the NESTPAY system of Halk Bank AD Skopje. \u003Cstrong>We have no\ninsight whatsoever into your card data\u003C\u002Fstrong> (card number, security code or account balance).\u003C\u002Fp>\n\u003Cp>Despite the protection measures applied, we cannot fully guarantee that they will prevent\nthird parties from unlawfully obtaining personal data. Any security breach will be reported\nto the competent authority and to the affected users within the statutory deadlines.\u003C\u002Fp>\n\u003Ch2>10. What are your rights?\u003C\u002Fh2>\n\u003Cp>In accordance with the Law on Personal Data Protection and the General Data Protection\nRegulation (GDPR), you have:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>The right to information and access\u003C\u002Fstrong> — to be informed about the processing of your\npersonal data and to obtain access to it.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>The right to rectification\u003C\u002Fstrong> — to request correction of inaccurate data. Most of it you\ncan correct yourself in your profile settings.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>The right to erasure\u003C\u002Fstrong> — to request deletion of your data. You may delete your account\nyourself from your settings. The request is fulfilled within 30 days, subject to data we\nare legally obliged to retain (in particular financial records, which are anonymised\nrather than erased) and subject to settlement of any outstanding balance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>The right to restriction of processing\u003C\u002Fstrong> — in the circumstances provided for by law.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>The right to data portability\u003C\u002Fstrong> — to receive the data you have provided in a structured,\ncommonly used and machine-readable format.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>The right to object\u003C\u002Fstrong> — to processing based on legitimate interest, including your\nappearance on leaderboards and venue lists, and to processing for direct marketing.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>The right to withdraw consent\u003C\u002Fstrong> — at any time, free of charge and by simple means, where\nprocessing is based on consent (marketing, push notifications, contacts discovery).\nWithdrawal does not affect the lawfulness of processing carried out before it.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>The right to lodge a complaint with the supervisory authority\u003C\u002Fstrong> — with the \u003Cstrong>Agency for\nPersonal Data Protection of the Republic of North Macedonia\u003C\u002Fstrong>, if you consider that the\nprocessing of your data infringes the applicable regulations.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>To exercise these rights, contact our data protection officer at \u003Cstrong>\u003Ca href=\"mailto:hey@padli.app\">hey@padli.app\u003C\u002Fa>\u003C\u002Fstrong>, stating\nyour first and last name, the phone number or e-mail address registered on your account, the\naddress at which you wish to receive a reply, and the substance of your request. We may ask\nyou for additional confirmation of your identity before acting on a request.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>A note on data that is not only yours.\u003C\u002Fstrong> A match, a result and a shared booking concern\nseveral people at once. Where you request erasure, we remove your identification from them,\nbut we cannot delete the record of a match for the other participants, nor the financial\nrecords we are required to keep.\u003C\u002Fp>\n\u003Ch2>11. Direct marketing\u003C\u002Fh2>\n\u003Cp>We send marketing messages (news, offers and tips about Padli) only where you have given\nyour consent. \u003Cstrong>Consent is never presumed and is off for every account by default\u003C\u002Fstrong>: it is\ngiven by an affirmative act in your account settings, and we record the moment it was given.\nYou may withdraw it at any time, through your notification settings or through the\nunsubscribe link in every such message, and the record of consent is cleared when you do. Withdrawal does not stop the transactional\nmessages necessary for a booking and for the security of your account.\u003C\u002Fp>\n\u003Ch2>12. Cookies and data stored on your device\u003C\u002Fh2>\n\u003Cp>We use \u003Cstrong>one cookie\u003C\u002Fstrong> — the session cookie that keeps you signed in — and a small number of\nvalues stored locally on your device: your own settings, and the two opaque identifiers used\nto count a visit as one visit (section 3.30). \u003Cstrong>We use no analytics cookies, no advertising\ncookies, no advertising pixels and no third-party trackers.\u003C\u002Fstrong> The details, value by value,\nare set out in the \u003Cstrong>Cookie Policy\u003C\u002Fstrong> at \u003Ca href=\"http:\u002F\u002Fwww.padli.app\u002Fcookie-policy\">www.padli.app\u002Fcookie-policy\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>13. Children and minors\u003C\u002Fh2>\n\u003Cp>An account may be opened by a person \u003Cstrong>aged 18 or over\u003C\u002Fstrong>, who alone has the legal capacity\nto enter into the contract and to pay.\u003C\u002Fp>\n\u003Cp>The Law on Personal Data Protection of the Republic of North Macedonia sets \u003Cstrong>14 years\u003C\u002Fstrong> as\nthe age from which a minor may themselves consent to the processing of their personal data\nin relation to services offered online. Accordingly:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Under 14\u003C\u002Fstrong> — we do not permit accounts and do not knowingly process such data. Where we\nestablish that an account belongs to a person under 14, we will close it and delete the\ndata, save for anything we are legally obliged to retain.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>From 14 to 18\u003C\u002Fstrong> — the Platform may be used only with the consent and under the\nsupervision of a parent or legal guardian, who accepts the Terms of Use on the minor&#39;s\nbehalf, is responsible for payment, and exercises the minor&#39;s rights under section 10 on\ntheir behalf.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>We process the data of a minor for the same purposes and on the same bases as set out in\nthis Policy, and no more of it. We may request proof of age or of parental consent, and may\nrestrict or close an account where they cannot be established.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>A junior may also play without any account at all\u003C\u002Fstrong>, as a \u003Cstrong>guest\u003C\u002Fstrong> named by an adult\naccount holder. In that case we process only the name entered and, where provided, a contact\ndetail. The adult who enters them is responsible for having the agreement of the guest and,\nwhere the guest is a minor, of their parent or guardian.\u003C\u002Fp>\n\u003Cp>If you are a parent or guardian and you believe that your child holds an account without\nyour consent, write to us at \u003Cstrong>\u003Ca href=\"mailto:hey@padli.app\">hey@padli.app\u003C\u002Fa>\u003C\u002Fstrong> and we will act on it.\u003C\u002Fp>\n\u003Ch2>14. Cooperation with competent authorities\u003C\u002Fh2>\n\u003Cp>VORTEK INOVATIONS cooperates with the police and other competent authorities in reporting\nunlawful activities. The identity of a user will be disclosed only upon the request of a\ncompetent authority, in accordance with the applicable legislation.\u003C\u002Fp>\n\u003Ch2>15. Changes to this Policy\u003C\u002Fh2>\n\u003Cp>We reserve the right to amend this Privacy Policy. The changes take effect upon their\npublication on the Platform, unless otherwise stated. Where a change materially affects\nyour rights, we will notify you in advance by a reasonable means.\u003C\u002Fp>\n\u003Ch2>16. Contact information\u003C\u002Fh2>\n\u003Cp>For questions, requests or complaints regarding the protection of personal data or this\nPolicy:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Data protection officer — E-mail:\u003C\u002Fstrong> \u003Ca href=\"mailto:hey@padli.app\">hey@padli.app\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>VORTEK INOVATIONS D.O.O. Skopje, Njudehliska 6\u002F1-13, Karposh, Skopje, North Macedonia\nEMBS: 7757832 | TAX ID: MK4057024570335\u003C\u002Fp>\n","2026-09-16",false,"The personal data controller is VORTEK INOVATIONS D.O.O. Skopje, a trade and services company with its registered office at Njudehliska 6\u002F1-13, Karposh,…",1789834209506]