?where @re you ?
МакедонскиBack to home

Legal

Privacy Policy

Last updated: 6 October 2026 · Version 1.2

Каде си? is a platform for hospitality venues (restaurants, halls) to manage events, reservations, table layouts and menus. The venue's clients (couples and other event organizers) get their own dashboard, and their guests get a digital invitation.

This policy explains which personal data is processed, why, who sees it, how long it is kept and what rights you have. It is governed by the Law on Personal Data Protection (Official Gazette of the Republic of North Macedonia No. 42/2020) and, where applicable, the General Data Protection Regulation (EU) 2016/679 (GDPR).

This document is published in Macedonian and English. In case of a difference, the Macedonian version prevails.

Contents

  1. Who we are
  2. Who is responsible for your data
  3. What data we process
  4. Notes and sensitive data
  5. Purposes and legal basis
  6. Invitations and answers through a link
  7. If you are a guest
  8. Who else processes the data
  9. Transfers outside the European Union
  10. How long we keep data
  11. Security
  12. Cookies
  13. Your rights
  14. Children
  15. Changes to this policy

1. Who we are

The platform is operated by GoDevLab Agency (godevlabagency.com) ("we"). The legal entity for the platform is being incorporated; its name, registered seat and registration number will be published here once it is registered. Until then the contact is support@kadesi.mk. Website: kadesi.mk.

For privacy questions write to support@kadesi.mk.

2. Who is responsible for your data

Three groups of people use the platform: venue staff (with their own account), the venue's clients, i.e. couples or organizers (with a username and password issued by the venue), and guests (with an invitation link, no account).

  • The venue is the controller of the data of its clients, their guests and its reservations. The venue makes the planning tools (guest list, invitation, notes, budget) available to its clients as part of its service, and the client fills them in. The venue's staff do not see the guest list or the client's notes and other planning content in their panel, but the venue can export or erase them.
  • The client keeps the guest list for its own event as a personal activity and is responsible for what it enters about other people.
  • We process the data in the first point only on the venue's behalf and on its instructions, as a processor, under the Data Processing Agreement with the venue.
  • We are the controller of the data about venue staff accounts, messages sent through the contact form, and security records (technical logs, rate-limit counters and the audit log).

If you are a client or guest of a venue, contact the venue first about your data. If you write to us, we forward the request to the venue and help it respond.

3. What data we process

Whose dataDataSource
Venue staffEmail, password (stored only as a hash), sign-up and last sign-in time, sign-in sessions, IP address and browser in the sign-in security records, venue name, version and time of acceptance of the Terms of Service.You, when signing up and using the service. The email and password are required to open an account.
Venue clients (couples, organizers)Names, date, time and type of the event, contact email and phone, total price and deposit paid (a record kept by the venue; the platform processes no payments), username and password (stored only as a hash), sign-in session, content you enter for planning (notes, agenda, locations that may include a private address, budget, to-do list), invitation text and photo, table labels.The venue and you.
GuestsFull name, phone (optional), party size, invitation answer, side (bride's or groom's), notes, time of the last change of the answer through the link and the previous answer.The couple or organizer, or the guest through the invitation link.
Reservation customersName, phone, email (optional), date and time, party size, event type, note.The venue.
People in event photosPhotos of past events that the venue uploads for its portfolio; people may be recognisable in them.The venue.
Contact-form sendersName, email, message and time sent.You.
All visitorsTechnical records at the hosting provider (IP address, page address, browser), rate-limit counters that contain only a hash of the IP address, error reports configured to exclude personal data.Automatically, when you use the platform.

The audit log of security-relevant actions (for example an answer changed through a link, a data export or erasure) contains internal identifiers, the type of action, the time and, for answers through a link, the previous and new answer and a shortened one-way hash of the IP address. It contains no names or contact details.

4. Notes and sensitive data

The notes fields (on guests, reservations and planning notes) are free text. Dietary needs, allergies or access needs may be entered there, which can reveal health data or religious beliefs (special categories of personal data). Enter them only if they are needed for the event and the person has given explicit consent (for example, the guest told you in writing and agreed that it is recorded). Prefer a neutral note such as "vegetarian menu" over a diagnosis. We do not use this data for any other purpose.

5. Purposes and legal basis

PurposeLegal basis
Venue account and providing the servicePerformance of the contract with the venue (Art. 6(1)(b) GDPR).
Data of the venue's clientsThe contract between the venue and the client (Art. 6(1)(b)). Confirmed by the venue as controller; we process the data as a processor.
Data of guests and of people named in planning contentLegitimate interest of the venue and the client in organising the event and seating the guests (Art. 6(1)(f)). Confirmed by the venue as controller.
Health or diet notesExplicit consent of the person (Art. 9(2)(a)).
Reservations at the venueThe contract, or steps before a contract, between the venue and the reservation customer (Art. 6(1)(b)).
Photos in the venue's portfolioConsent of the people shown or the venue's legitimate interest; decided by the venue as controller.
Answering contact-form messagesTaking steps at your request before entering into a contract, or our legitimate interest in answering enquiries.
Security: rate limiting, audit log, sign-in records, error reportsLegitimate interest in a secure and available service.
BackupsLegitimate interest and the duty to keep processing secure, so data can be restored after an incident.

We do not sell personal data, do not use it for advertising and make no automated decisions with legal effects on you.

6. Invitations and answers through a link

  • Anyone who has the invitation link can open the page and see the couple's names, the date and start time of the event, the venue and hall, and the invitation text and photo. The guest list is not visible through the invitation.
  • Anyone who has the link can answer the invitation. Every change of an answer through the link is recorded, and the couple sees the time of the change and the previous answer.
  • The invitation photo and the event photos in the venue's portfolio can be opened by anyone who has the file's direct address. Remove location data from a photo before uploading, because the file is stored as uploaded.
  • When an event's personal data is erased, the invitation and its photo are deleted and the link stops working.

7. If you are a guest

  • The couple or organizer may have entered about you: full name, phone, party size, whether you are coming, whose side you are on and a note (for example about diet). If you answer through the link, you enter them yourself: name, whether you are coming and party size.
  • Your data is seen by the couple or organizer. The venue can export or erase it. Other guests do not see it.
  • The data is kept for up to 12 months after the event (see "How long we keep data").
  • For access, correction or erasure contact the venue named on the invitation, or the couple. You can also write to us, and we forward the request to the venue.
  • A parent or the organizer can answer for children.

8. Who else processes the data

We use the following service providers (sub-processors). The data is stored in the European Union; the nightly backup job runs on GitHub's servers (see the table).

ProviderServiceDataLocationStatus
SupabaseDatabase, sign-in, photo storage, daily backupsAll data described in this policyEU, IrelandActive
VercelHosting of the application and server functionsAll data in transit; request records (IP address, page address, browser)EU, Dublin (Ireland) for server functionsActive
ResendSending email (account confirmation, password reset, contact-form notifications)Recipient email and message contentEUPlanned
SentryApplication error monitoringTechnical description of the error; configured not to send request content, cookies, user identity or invitation linksEU, Frankfurt (Germany)Planned, only if enabled
Cloudflare R2Off-site backupsAn encrypted copy of the database and the photosEUPlanned
GitHubRunning the nightly backup job (GitHub Actions)Temporarily, while the job runs: a copy of the database and the photos before it is encrypted and uploaded to Cloudflare R2Determined by GitHubPlanned

Account confirmation and password emails are sent by Supabase. Notifications of contact-form messages also arrive in our team's email inbox. We may also disclose data to competent authorities when the law requires it.

9. Transfers outside the European Union

The servers and storage are in the EU. The providers are companies headquartered in the United States. If their staff access data from a country outside the EU, or if the backup job runs outside the EU, the transfer relies on the safeguards in their data processing agreements, such as standard contractual clauses. Requests may pass through the nearest point of Vercel's global network.

10. How long we keep data

DataPeriod
Personal data of clients and guests of an eventBy default erased automatically 12 months after the event date, unless the venue asks for a different period, or earlier if the venue erases them. After that a record of the event without names, contact details or guest data remains (date, time, type, hall, estimated guest count, price and deposit), for the venue's accounting and calendar, for as long as the venue account exists.
Contact-form messages24 months after receipt in our system; copies in our team's email inbox are deleted within the same period.
ReservationsUntil the venue deletes them. The venue can delete a reservation at any time.
Venue account and staffUntil the venue deletes its account or the service ends. After the service ends the venue has 30 days to export its data, after which it is deleted.
Client sign-in sessionsExpire 30 days after last use, then are deleted by a daily job.
Rate-limit counters (hash of the IP address)1 day.
Photos whose record was deleted or replacedDeleted within an hour.
BackupsDaily copies at Supabase are kept for 7 days and encrypted copies in Cloudflare R2 (once enabled) for 35 days. Erased data disappears from backups after 35 days at the latest. If we ever restore a backup, we re-apply every erasure made since it was created.
Audit log (no names or contact details)For as long as the venue's account exists; needed for security and for resolving disputes
Technical records at the hosting and email providersAccording to the provider's own retention periods

11. Security

  • All traffic is encrypted (HTTPS).
  • Each venue's data is separated from other venues by access rules in the database itself.
  • Passwords are stored only as a hash and must have at least 10 characters. Client sessions are stored only as a hash. After 5 failed sign-in attempts, a client account is locked for 15 minutes.
  • Requests to public forms and sign-ins are rate-limited, and security-relevant actions are written to an audit log.
  • Daily backups, encrypted before they leave the main infrastructure, and hosting in the EU. Only a small number of authorised people can access production data.

12. Cookies

We use only cookies that are necessary for signing in and for running the platform. We have no analytics, advertising or third-party cookies, and store nothing else in your browser. That is why we do not ask for cookie consent.

CookiePurposeDuration
couple_sessionKeeps the venue's client signed in.30 days from last use.
sb-…-auth-tokenKeeps venue staff signed in.Until sign-out or until the session expires.
sb-…-auth-token-code-verifierSecurity code when resetting a password by email.A few minutes.
maintenance_bypassLets our team open the platform during maintenance. Set only for our team.Up to 12 hours.

13. Your rights

  • Access to your data and a copy of it.
  • Correction of inaccurate data.
  • Erasure.
  • Restriction of processing.
  • Data portability.
  • Withdrawal of consent, where processing is based on consent, without affecting earlier processing.

Right to object: you can object at any time to processing based on legitimate interest, on grounds relating to your particular situation. The processing then stops unless there are compelling legitimate grounds that override it.

For staff accounts and contact-form messages write to us at support@kadesi.mk. For data about an event, guests or reservations contact the venue; if you write to us, we forward the request. We answer within one month; in complex cases the period can be extended by two more months, and we will tell you.

The venue settings have tools for these requests: export of all the venue's data, erasure of the personal data of a single event, and deletion of the whole account with all its data.

You have the right to lodge a complaint with the Personal Data Protection Agency (Агенција за заштита на личните податоци, www.azlp.mk). If you live in the EU, you can also complain to the data protection authority in your country.

14. Children

The platform is not intended for children. Guest lists may contain names of children entered by the couple or organizer; they are processed like other guest data.

15. Changes to this policy

We publish each new version on this page with its date. We notify venues of material changes by email before they take effect.

Privacy PolicyTerms of ServiceData Processing Agreement
© 2026 Каде си? All rights reserved.Managed by GoDevLab Agency