Privacy Policy
Last updated: February 1, 2026
Contents
1. Data Controller
The controller of your personal data is posojilo.si d.o.o., Slovenska cesta 36, 1000 Ljubljana, Slovenia. For all questions regarding personal data processing, contact us at dpo@posojilo.si.
2. Data We Collect
We collect the following categories of personal data: identification data (name, surname, date of birth, tax number), contact data (email address, phone number, address), financial data (bank account details, credit history from SISBON), identity verification data (ID document copy, selfie for KYC), platform usage data (IP address, device data, activity logs), and transaction data (investments, payments, account balances).
3. Legal Bases (Article 6 GDPR)
We process your data based on: contractual relationship (Art. 6(1)(b)) — for providing platform services, legal obligation (Art. 6(1)(c)) — for KYC/AML verification and tax reporting, legitimate interest (Art. 6(1)(f)) — for fraud prevention and service improvement, consent (Art. 6(1)(a)) — for marketing communications and non-essential cookies.
4. Third Parties and Processors
We share your data with the following third parties: SISBON (credit registry) — for creditworthiness verification, KYC provider — for identity verification, payment service provider (PSP) — for payment processing, email provider — for sending notifications. All processors are contractually bound to data protection in accordance with GDPR.
5. Data Retention
We retain personal data only as long as necessary to fulfil the processing purpose: account data — 5 years after account closure (legal requirement), transaction data — 10 years (tax legislation), KYC documentation — 5 years after the end of the business relationship (AML legislation), activity logs — 1 year, marketing consents — until withdrawal.
6. Your GDPR Rights
To exercise your rights, write to dpo@posojilo.si. We will respond to your request within 30 days.
8. Security Measures
To protect your data, we use: 256-bit SSL/TLS encryption for data transmission, encryption of data at rest, regular security audits and penetration tests, principle of least privilege for employee access, multi-factor authentication for critical systems, and regular employee training on data protection.
9. International Transfers
We primarily process and store your data within the EU/EEA. In case of data transfer outside the EU/EEA, we ensure appropriate safeguards in accordance with Chapter V of the GDPR, including standard contractual clauses.
10. Children
The posojilo.si platform is not intended for persons under 18 years of age. We do not knowingly collect personal data from minors. If we discover that we have collected data from a minor, we will delete it immediately.
11. Changes to Privacy Policy
posojilo.si reserves the right to amend this privacy policy. Users will be notified of material changes via email or platform notification at least 30 days before the changes take effect.