Privacy Policy
Last updated 12 August 2026. Read together with our Data Processing Addendum, Cookie Policy and Acceptable Use Policy.
1. Controller identity
The controller of personal data collected through the sabeemod.org website, the Sabeemod customer workspace and the customer-support channels is Sabeemod d.o.o., PIB 02845619, CRPS 4-0089321/7, ul. Vaka Đurovića 8, 81000 Podgorica, Crna Gora, represented by its director Stefan Radović. The data-protection contact is reachable at privacy@sabeemod.org and by post at the registered address, marked "Privacy Officer".
2. Categories of data subjects
This policy covers three categories of data subjects. First, visitors who browse the sabeemod.org website without opening an account. Second, workspace users, meaning the individuals who receive an access link on behalf of a Customer legal entity and who administer the modules on that Customer's behalf. Third, guests and staff of the Customer whose personal data flows through a module because the module was installed by the Customer to process data extracted from that Customer's SabeeApp account. For the third category, Sabeemod is a processor and the Customer is the controller, and processing is governed by the separate Data Processing Addendum published on the /dpa page.
3. Categories of personal data
Categories of personal data processed by Sabeemod in its capacity as controller are limited to what is strictly necessary. For website visitors: IP address, user agent, referring URL, pages viewed, timestamps, and any cookie identifiers that were set with consent. For workspace users: full name, business email address, business phone number, spoken language, role inside the Customer organisation, workspace access log entries and support ticket content. For prospects who have submitted the contact form: the details typed into the form, plus the same technical metadata as ordinary visitors. Sabeemod never asks for, and does not process, any special category of personal data (Article 9 GDPR) in its capacity as controller.
4. Purposes and legal bases
Personal data is processed for the following purposes and on the following legal bases: (a) delivering the Service and executing the contract concluded with the Customer legal entity, on the legal basis of contractual necessity (Article 6(1)(b) GDPR); (b) invoicing, tax compliance and bookkeeping, on the legal basis of legal obligation (Article 6(1)(c) GDPR), retained for the mandatory ten (10) years imposed by Montenegrin accounting law; (c) responding to support tickets and pre-sale enquiries, on the legal basis of legitimate interest in providing a quality customer relationship (Article 6(1)(f) GDPR); (d) sending occasional service-related emails such as maintenance notices or Terms updates, on the legal basis of contractual necessity; (e) sending optional product news and best-practice content, on the legal basis of consent, freely withdrawable through the unsubscribe link included in every such email; (f) protecting the Service against fraud, brute-force attacks and abuse, on the legal basis of legitimate interest in preserving the integrity of the Service.
5. Retention periods
Retention periods are aligned to the purpose. Workspace user records are kept for the duration of the contract plus three (3) years after termination, for evidence purposes. Invoicing records are kept for ten (10) years after the invoice date, in accordance with Montenegrin accounting law. Support ticket content is kept for two (2) years after the ticket is closed, so that recurring incidents can be diagnosed against a factual history. Website analytics data is kept for thirteen (13) months maximum, in aggregated form for longer. Consent logs are kept for the duration of the consent plus three (3) years, so that the lawfulness of past processing can be evidenced.
6. Recipients and processors
Personal data is disclosed only to a strictly limited set of recipients. Internal recipients are the employees and contractors of Sabeemod bound by written confidentiality obligations and by role-based access control. External processors are engaged for hosting (a certified European cloud provider, region Frankfurt or Amsterdam), transactional email delivery (a European mail service provider), invoicing and accounting (a Montenegrin chartered accountant firm), payment processing (a SEPA-authorised payment institution based in the European Economic Area) and customer relationship management (an EU-hosted service). The current list of processors and their locations is published in the Data Processing Addendum on the /dpa page and is updated whenever a processor is added or replaced, with thirty (30) days' prior notice to Customers who subscribe to that notice.
7. International transfers
Personal data is stored and processed inside the European Economic Area or in Montenegro. Any transfer outside this perimeter is protected by the standard contractual clauses adopted by the European Commission on 4 June 2021, complemented by the technical and organisational measures described in the Data Processing Addendum. Sabeemod does not authorise onward transfers of personal data to jurisdictions that do not offer an adequate level of protection within the meaning of Article 45 GDPR, unless a valid transfer tool applies and unless a case-by-case transfer impact assessment has concluded that the transfer is lawful.
8. Data subject rights
Data subjects benefit from the full set of rights granted by the GDPR: right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), objection (Article 21), and the right not to be subject to solely automated decisions producing legal effects (Article 22). These rights can be exercised by writing to privacy@sabeemod.org. Sabeemod responds within one (1) month of receipt of a valid request; the deadline may be extended by two (2) months for complex requests, in which case the data subject is informed of the extension and of its reasons within the first month.
9. Complaints
Data subjects have the right to lodge a complaint with the competent supervisory authority. In Montenegro, the competent authority is Agencija za zaštitu ličnih podataka (AZLP), registration number 05-030/24-1938, address Bulevar Svetog Petra Cetinjskog 130, 81000 Podgorica, Crna Gora, telephone +382 20 634 883, email azlp@t-com.me. Data subjects residing in a European Union member state may also lodge a complaint with the supervisory authority of their country of residence.
10. Cookies
The sabeemod.org website uses a minimal set of cookies described in detail in the Cookie Policy on the /cookies page. Strictly necessary cookies are set without consent to enable session management and to remember the cookie consent choice itself. Analytics and preference cookies are set only after affirmative opt-in through the cookie banner, and can be revoked at any time. Sabeemod does not use advertising cookies, does not sell any signal to third-party ad networks and does not participate in real-time bidding auctions.
11. Security
Sabeemod implements the technical and organisational measures required by Article 32 GDPR and detailed in the Data Processing Addendum: encryption in transit (TLS 1.2 minimum, TLS 1.3 preferred), encryption at rest (AES-256), role-based access control, mandatory multi-factor authentication for all employee accounts, quarterly access reviews, automated vulnerability scans, annual third-party penetration test, audited backup restoration drills, business continuity plan tested twice a year, and a written incident-response plan with a maximum internal notification time of two (2) hours from detection.
12. Breach notification
In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, Sabeemod notifies the competent supervisory authority within seventy-two (72) hours of becoming aware of the breach, as required by Article 33 GDPR. Where the breach is likely to result in a high risk, affected data subjects are notified without undue delay, in clear and plain language, through the communication channel most appropriate to reach them promptly.
13. Children
The Service is designed for professional use by hospitality operators and is not directed at children under the age of sixteen (16). Sabeemod does not knowingly collect personal data from children. If Sabeemod becomes aware that a child under sixteen has provided personal data through the Service, that data will be erased as soon as reasonably practicable.
14. Automated decision-making
Sabeemod does not take decisions producing legal effects, or similarly significantly affecting a data subject, based solely on automated processing. Some modules include algorithmic scoring (for example, the demand forecast in Forecast Pro or the review sentiment analysis in Review Radar), but these produce indicative outputs that must be reviewed and approved by a human operator before any operational action is taken.
15. Changes to this policy
This Privacy Policy may be updated from time to time to reflect changes in law, in processing operations or in the list of processors. Material changes are notified by email to the billing contact of each active Customer at least thirty (30) days before entry into force. The date of the last update is displayed at the top of this page, and previous versions can be requested from privacy@sabeemod.org for evidentiary purposes for three (3) years after their replacement.