Data Controller
Buzzlo d.o.o. za usluge (“OneDown”, “we”, “us”, “our”) is the data controller responsible for processing your personal data when you use the OneDown platform, websites, and mobile applications.
| Detail | Value |
|---|---|
| Legal entity | Buzzlo d.o.o. za usluge |
| Registered office | Zagrebačka cesta 126, 10000 Zagreb, Croatia |
| Company ID (OIB) | 62127636877 |
| Court registry (MBS) | 081532265 |
| Registry court | Commercial Court in Zagreb (Trgovački sud u Zagrebu) |
| Privacy contact | hello@buzzlo.ai |
About the Platform
OneDown is an invite-only, cloud-based inventory intelligence platform engineered for bars, restaurants, hotels, and hospitality groups. The service comprises:
- Native mobile applications (iOS and Android) for high-speed stock counting and cellar inventory
- Web management console (
app.onedown.ai) for catalog governance, reporting, user management, and variance analysis - Real-time Bluetooth Low Energy (BLE) smart scale integration for open bottle and draft keg measurement
- On-device camera barcode scanning for instant packaging identification
- Automated export connectors to Point of Sale (POS) and back-office ERP platforms (such as Remaris)
Roles & Responsibilities
Under the EU General Data Protection Regulation (GDPR), data processing responsibilities are partitioned as follows:
- Buzzlo d.o.o. as Data Controller: We act as controller for your personal account credentials, security access logs, billing information, support correspondence, and diagnostic performance metrics.
- Your Organization (the Tenant) as Data Controller: Your employer or venue operator is the data controller for all operational business data entered into OneDown, including inventory counts, session assignments, warehouse stock lists, product catalogs, and recipe definitions.
- Buzzlo d.o.o. as Data Processor: We act as a data processor on behalf of your organization when storing and synchronizing customer inventory data. If your organization requires a Data Processing Agreement (DPA) incorporating Standard Contractual Clauses, contact us at hello@buzzlo.ai.
Data We Collect
We limit personal data collection strictly to what is required to deliver, secure, and operate the platform:
| Category | Specific Data Points | Purpose & Legal Basis |
|---|---|---|
| Account & Identity | Email address, full name, hashed password (scrypt), assigned organization role (Owner, Manager, Member) | User authentication, access control, audit attribution (GDPR Art. 6(1)(b)) |
| Inventory & Counting | Item counts, session timestamps, warehouse zones, weight conversions, recorded variances, inventory export history | Core service fulfillment and statutory stocktaking records (GDPR Art. 6(1)(b) & Art. 6(1)(c)) |
| Device & Diagnostics | Operating system version, app build number, device model, anonymized crash traces, IP address, request headers | Service stability, API rate limiting, compatibility, security logging (GDPR Art. 6(1)(f)) |
| Support & Inquiries | Messages, screenshots, and account identifiers submitted through in-app chat or email | Providing customer support and troubleshooting issues (GDPR Art. 6(1)(b)) |
Device Permissions
The OneDown mobile application requests specific device permissions strictly when needed for core counting workflows:
- Camera: Used exclusively for optical barcode and QR code recognition via on-device machine learning (Apple VisionKit on iOS, Google ML Kit on Android). Camera image buffers are processed entirely in local volatile memory and are never saved, recorded, or transmitted to our servers.
- Bluetooth (BLE) & Nearby Devices: Used to establish direct wireless communication with compatible digital weighing scales (such as AiLink and MASSEC). Bluetooth data is used exclusively to stream real-time weight measurements into the active counting session.
- Location Clarification: OneDown does not access GPS, does not track geographic location, and does not log device movement. On certain mobile operating systems, Bluetooth Low Energy discovery is architecturally grouped under location permissions; we never capture, record, or store geographic coordinates.
Offline Storage & Synchronization
OneDown is built offline-first so hospitality staff can perform uninterrupted counts in concrete cellars, subterranean walk-in coolers, and areas with degraded network connectivity:
- Active counting templates, product barcodes, and pending counts are cached locally on your device in an isolated, sandboxed SQLite database (Drift).
- Authentication tokens and API secrets are stored securely within your device’s hardware-backed credential storage (iOS Keychain and Android EncryptedSharedPreferences).
- When network connectivity is re-established, pending session changes synchronize securely with our cloud servers. Signing out of the mobile app or deleting the application purges local cached data immediately.
Legal Bases for Processing
We process personal data under one or more recognized legal bases pursuant to GDPR Article 6:
- Performance of a Contract (Art. 6(1)(b)): Processing necessary to create your account, authenticate your sessions, maintain inventory workflows, and fulfill our service agreement with your organization.
- Compliance with Legal Obligations (Art. 6(1)(c)): Retaining inventory session audits, export logs, and transaction histories to comply with commercial, accounting, and tax record-keeping regulations (e.g., the Croatian Accounting Act and EU fiscal directives).
- Legitimate Interests (Art. 6(1)(f)): Ensuring platform security, mitigating malicious traffic, diagnosing fatal application crashes, and maintaining infrastructure integrity.
- Consent (Art. 6(1)(a)): For optional features such as device push notifications, which can be toggled on or off at any time in device or in-app settings.
Subprocessors
We engage vetted third-party infrastructure providers to operate the OneDown platform under strict data protection terms:
| Subprocessor | Provided Service | Entity Location & Transfer Mechanism |
|---|---|---|
| Hetzner Online GmbH | Primary cloud infrastructure, application API runtime, PostgreSQL database, job queues | Germany (European Union) |
| Cloudflare, Inc. | Content Delivery Network (CDN), DDoS mitigation, Web Application Firewall (WAF), public site hosting, object storage | European Union / Global Edge (Standard Contractual Clauses) |
| Crisp IM SARL | In-app customer support chat widget (web and mobile) | France (European Union) |
| OneSignal, Inc. | Mobile push notification delivery (session reminders, export alerts) | United States (EU-U.S. Data Privacy Framework & SCCs) |
| Amazon Web Services EMEA SARL | Transactional email delivery (SES) for invites, verifications, and export digests | Frankfurt, Germany (European Union) |
Self-Hosted Error Diagnostics
Application error reporting and crash diagnostics are processed through a self-hosted, Sentry-compatible monitoring service (Bugsink) deployed directly on our dedicated Hetzner cloud infrastructure in Germany. Telemetry traces and error contexts are kept entirely on our private EU servers and are not shared with third-party commercial crash vendors.
We never sell, rent, monetize, or broker personal data to advertisers, data brokers, or third parties.
Cookies & Tracking
- Web Application (
app.onedown.ai): Employs strictly necessary HTTP session cookies and local storage tokens required for secure authentication, cross-site request forgery (CSRF) defense, and active tenant routing. These technical cookies do not track users across third-party websites. - Marketing Website (
onedown.ai): Uses privacy-friendly product analytics hosted on European infrastructure. We do not use advertising tracking pixels, third-party behavioral cookies, or invasive cross-domain profiling.
Data Retention & Deletion
We retain personal data only for as long as necessary to fulfill the purposes set out in this policy:
- Active Accounts: Stored for the duration of your organization’s active subscription.
- Sync Event Journal: Synchronization delta events are stored server-side for approximately 90 days to maintain multi-device consistency, after which they are automatically expunged.
- Account Deletion: When an account is deleted, personal credentials and identification records are permanently removed from production databases within 30 days.
- Archived Audit Records: To preserve financial, accounting, and stocktaking integrity for the tenant organization, completed inventory counts and export receipts may be retained in anonymized form, stripped of personal contact details.
Security
We employ defense-in-depth architectural safeguards to protect your data against unauthorized access, loss, or alteration:
- Encryption in Transit: All traffic between clients, mobile apps, scales, and APIs is encrypted using modern TLS 1.3 cryptographic protocols with Strict Transport Security (HSTS).
- Encryption at Rest: Databases, automated backups, and storage volumes are encrypted at rest using AES-256.
- Authentication: Passwords are protected using high-cost scrypt hashing algorithms. Authentication sessions use time-limited cryptographic tokens.
- Isolation: Multi-tenant database queries enforce strict organizational boundary isolation at the database layer.
Your Rights
Under Articles 15–22 of the GDPR, European Union residents possess enforceable data privacy rights:
- Right of Access (Art. 15): Request confirmation and a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
- Right to Erasure (Art. 17): Request permanent deletion of your personal account and associated data (“right to be forgotten”).
- Right to Restriction of Processing (Art. 18): Request that we restrict processing of your personal data under specific statutory conditions.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format.
- Right to Object (Art. 21): Object to data processing predicated upon our legitimate interests.
To exercise any of these rights, email us directly at hello@buzzlo.ai. We will respond to your request within 30 days without undue delay.
You also have the right to lodge a complaint with your competent national supervisory authority. In Croatia, the competent authority is the Agencija za zaštitu osobnih podataka (AZOP):
- Website: azop.hr
- Address: Selska cesta 136, 10000 Zagreb, Croatia
- Email: azop@azop.hr
Changes & Contact
OneDown is a business-to-business (B2B) platform. The service is not directed at children under the age of 16, and we do not knowingly solicit or collect data from minors.
We may update this Privacy Policy periodically to reflect legal modifications, feature enhancements, or operational changes. Material revisions will be highlighted via in-app alerts, email notifications, or notice on our website prior to taking effect.
If you have questions, feedback, or concerns regarding our privacy practices, contact us at:
Buzzlo d.o.o. za usluge
Attn: Data Protection
Zagrebačka cesta 126, 10000 Zagreb, Croatia
Email: hello@buzzlo.ai