Skip to content
Home
Home
Last updated: September 2026
Legal

Privacy Policy

This policy explains what data OneDown collects, why we process it, and how you can exercise your rights under the General Data Protection Regulation (GDPR).
Table of contents

Data Controller

Buzzlo d.o.o. za usluge (“OneDown”, “we”, “us”, “our”) is the data controller responsible for processing your personal data when you use the OneDown platform, websites, and mobile applications.

DetailValue
Legal entityBuzzlo d.o.o. za usluge
Registered officeZagrebačka cesta 126, 10000 Zagreb, Croatia
Company ID (OIB)62127636877
Court registry (MBS)081532265
Registry courtCommercial Court in Zagreb (Trgovački sud u Zagrebu)
Privacy contacthello@buzzlo.ai

About the Platform

OneDown is an invite-only, cloud-based inventory intelligence platform engineered for bars, restaurants, hotels, and hospitality groups. The service comprises:

  • Native mobile applications (iOS and Android) for high-speed stock counting and cellar inventory
  • Web management console (app.onedown.ai) for catalog governance, reporting, user management, and variance analysis
  • Real-time Bluetooth Low Energy (BLE) smart scale integration for open bottle and draft keg measurement
  • On-device camera barcode scanning for instant packaging identification
  • Automated export connectors to Point of Sale (POS) and back-office ERP platforms (such as Remaris)

Roles & Responsibilities

Under the EU General Data Protection Regulation (GDPR), data processing responsibilities are partitioned as follows:

  • Buzzlo d.o.o. as Data Controller: We act as controller for your personal account credentials, security access logs, billing information, support correspondence, and diagnostic performance metrics.
  • Your Organization (the Tenant) as Data Controller: Your employer or venue operator is the data controller for all operational business data entered into OneDown, including inventory counts, session assignments, warehouse stock lists, product catalogs, and recipe definitions.
  • Buzzlo d.o.o. as Data Processor: We act as a data processor on behalf of your organization when storing and synchronizing customer inventory data. If your organization requires a Data Processing Agreement (DPA) incorporating Standard Contractual Clauses, contact us at hello@buzzlo.ai.

Data We Collect

We limit personal data collection strictly to what is required to deliver, secure, and operate the platform:

CategorySpecific Data PointsPurpose & Legal Basis
Account & IdentityEmail address, full name, hashed password (scrypt), assigned organization role (Owner, Manager, Member)User authentication, access control, audit attribution (GDPR Art. 6(1)(b))
Inventory & CountingItem counts, session timestamps, warehouse zones, weight conversions, recorded variances, inventory export historyCore service fulfillment and statutory stocktaking records (GDPR Art. 6(1)(b) & Art. 6(1)(c))
Device & DiagnosticsOperating system version, app build number, device model, anonymized crash traces, IP address, request headersService stability, API rate limiting, compatibility, security logging (GDPR Art. 6(1)(f))
Support & InquiriesMessages, screenshots, and account identifiers submitted through in-app chat or emailProviding customer support and troubleshooting issues (GDPR Art. 6(1)(b))

Device Permissions

The OneDown mobile application requests specific device permissions strictly when needed for core counting workflows:

  • Camera: Used exclusively for optical barcode and QR code recognition via on-device machine learning (Apple VisionKit on iOS, Google ML Kit on Android). Camera image buffers are processed entirely in local volatile memory and are never saved, recorded, or transmitted to our servers.
  • Bluetooth (BLE) & Nearby Devices: Used to establish direct wireless communication with compatible digital weighing scales (such as AiLink and MASSEC). Bluetooth data is used exclusively to stream real-time weight measurements into the active counting session.
  • Location Clarification: OneDown does not access GPS, does not track geographic location, and does not log device movement. On certain mobile operating systems, Bluetooth Low Energy discovery is architecturally grouped under location permissions; we never capture, record, or store geographic coordinates.

Offline Storage & Synchronization

OneDown is built offline-first so hospitality staff can perform uninterrupted counts in concrete cellars, subterranean walk-in coolers, and areas with degraded network connectivity:

  • Active counting templates, product barcodes, and pending counts are cached locally on your device in an isolated, sandboxed SQLite database (Drift).
  • Authentication tokens and API secrets are stored securely within your device’s hardware-backed credential storage (iOS Keychain and Android EncryptedSharedPreferences).
  • When network connectivity is re-established, pending session changes synchronize securely with our cloud servers. Signing out of the mobile app or deleting the application purges local cached data immediately.

We process personal data under one or more recognized legal bases pursuant to GDPR Article 6:

  • Performance of a Contract (Art. 6(1)(b)): Processing necessary to create your account, authenticate your sessions, maintain inventory workflows, and fulfill our service agreement with your organization.
  • Compliance with Legal Obligations (Art. 6(1)(c)): Retaining inventory session audits, export logs, and transaction histories to comply with commercial, accounting, and tax record-keeping regulations (e.g., the Croatian Accounting Act and EU fiscal directives).
  • Legitimate Interests (Art. 6(1)(f)): Ensuring platform security, mitigating malicious traffic, diagnosing fatal application crashes, and maintaining infrastructure integrity.
  • Consent (Art. 6(1)(a)): For optional features such as device push notifications, which can be toggled on or off at any time in device or in-app settings.

Subprocessors

We engage vetted third-party infrastructure providers to operate the OneDown platform under strict data protection terms:

SubprocessorProvided ServiceEntity Location & Transfer Mechanism
Hetzner Online GmbHPrimary cloud infrastructure, application API runtime, PostgreSQL database, job queuesGermany (European Union)
Cloudflare, Inc.Content Delivery Network (CDN), DDoS mitigation, Web Application Firewall (WAF), public site hosting, object storageEuropean Union / Global Edge (Standard Contractual Clauses)
Crisp IM SARLIn-app customer support chat widget (web and mobile)France (European Union)
OneSignal, Inc.Mobile push notification delivery (session reminders, export alerts)United States (EU-U.S. Data Privacy Framework & SCCs)
Amazon Web Services EMEA SARLTransactional email delivery (SES) for invites, verifications, and export digestsFrankfurt, Germany (European Union)

Self-Hosted Error Diagnostics

Application error reporting and crash diagnostics are processed through a self-hosted, Sentry-compatible monitoring service (Bugsink) deployed directly on our dedicated Hetzner cloud infrastructure in Germany. Telemetry traces and error contexts are kept entirely on our private EU servers and are not shared with third-party commercial crash vendors.

We never sell, rent, monetize, or broker personal data to advertisers, data brokers, or third parties.

Cookies & Tracking

  • Web Application (app.onedown.ai): Employs strictly necessary HTTP session cookies and local storage tokens required for secure authentication, cross-site request forgery (CSRF) defense, and active tenant routing. These technical cookies do not track users across third-party websites.
  • Marketing Website (onedown.ai): Uses privacy-friendly product analytics hosted on European infrastructure. We do not use advertising tracking pixels, third-party behavioral cookies, or invasive cross-domain profiling.

Data Retention & Deletion

We retain personal data only for as long as necessary to fulfill the purposes set out in this policy:

  • Active Accounts: Stored for the duration of your organization’s active subscription.
  • Sync Event Journal: Synchronization delta events are stored server-side for approximately 90 days to maintain multi-device consistency, after which they are automatically expunged.
  • Account Deletion: When an account is deleted, personal credentials and identification records are permanently removed from production databases within 30 days.
  • Archived Audit Records: To preserve financial, accounting, and stocktaking integrity for the tenant organization, completed inventory counts and export receipts may be retained in anonymized form, stripped of personal contact details.

Security

We employ defense-in-depth architectural safeguards to protect your data against unauthorized access, loss, or alteration:

  • Encryption in Transit: All traffic between clients, mobile apps, scales, and APIs is encrypted using modern TLS 1.3 cryptographic protocols with Strict Transport Security (HSTS).
  • Encryption at Rest: Databases, automated backups, and storage volumes are encrypted at rest using AES-256.
  • Authentication: Passwords are protected using high-cost scrypt hashing algorithms. Authentication sessions use time-limited cryptographic tokens.
  • Isolation: Multi-tenant database queries enforce strict organizational boundary isolation at the database layer.

Your Rights

Under Articles 15–22 of the GDPR, European Union residents possess enforceable data privacy rights:

  • Right of Access (Art. 15): Request confirmation and a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
  • Right to Erasure (Art. 17): Request permanent deletion of your personal account and associated data (“right to be forgotten”).
  • Right to Restriction of Processing (Art. 18): Request that we restrict processing of your personal data under specific statutory conditions.
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21): Object to data processing predicated upon our legitimate interests.

To exercise any of these rights, email us directly at hello@buzzlo.ai. We will respond to your request within 30 days without undue delay.

You also have the right to lodge a complaint with your competent national supervisory authority. In Croatia, the competent authority is the Agencija za zaštitu osobnih podataka (AZOP):

Changes & Contact

OneDown is a business-to-business (B2B) platform. The service is not directed at children under the age of 16, and we do not knowingly solicit or collect data from minors.

We may update this Privacy Policy periodically to reflect legal modifications, feature enhancements, or operational changes. Material revisions will be highlighted via in-app alerts, email notifications, or notice on our website prior to taking effect.

If you have questions, feedback, or concerns regarding our privacy practices, contact us at:

Buzzlo d.o.o. za usluge
Attn: Data Protection
Zagrebačka cesta 126, 10000 Zagreb, Croatia
Email: hello@buzzlo.ai