Privacy Policy
What data the TVOJA integracija app processes, why we process it, and the rights you have under the GDPR.
On this page
- Introduction
- Who is the controller
- What data we collect
- Why we process data and on what legal basis
- Device permissions: location, calendar and notifications
- Analytics and crash reporting
- Consultations, messages and questionnaires
- Content from external sources
- Processors and international transfers
- How long we keep data
- Deleting your account
- Your rights
- Children and younger users
- Security and data stored on your device
- Changes to this policy
- Contact
Introduction
TVOJA integracija is a mobile app for people from Bosnia and Herzegovina, Croatia, Serbia, Montenegro, North Macedonia and Slovenia who already live in Germany or are preparing to move there. The app offers a step-by-step integration guide, calculators, a map of organisations and businesses, events, a blog, a glossary of German administrative terms, an e-book, and a way to send us your question.
This policy explains what data we process when you use the app, on what legal basis, how long we keep it, who we share it with, and how you can exercise your rights. It is written to meet the European Union General Data Protection Regulation (GDPR), because the app is used in Germany and other EU countries.
An account is required to use the app. When you register, we ask you to accept the Terms of Use and to confirm that you have read this Privacy Policy.
This policy covers the iOS and Android mobile app. The website tvoja-integracija.com has its own privacy policy, published on that site.
Who is the controller
The app is developed and operated by Atomic Solutions on behalf of the Tvoja Integracija brand. Atomic Solutions is the data controller within the meaning of Article 4(7) GDPR for all processing described in this policy.
For any question about data protection, to exercise your rights, or to object to processing, write to support@tvoja-integracija.com. We aim to reply within a few working days, and in any case within the deadlines set by the GDPR.
The full legal name, address and registration details of the operator are set out in the imprint on tvoja-integracija.com.
What data we collect
We collect only what we need to run the app and to help you. We do not buy data from third parties and we do not sell your data to anyone.
- Account data: your email address and password (stored only as a cryptographic hash), or your Apple account identifier if you sign in with Apple, plus your user ID, username, registration date and last sign-in time.
- Profile data: first name, last name, date of birth, country of origin and city of origin, and your notification and newsletter preferences. You enter these yourself and can change them at any time.
- Content you send us: your consultation question, the messages in your conversation with our team, your answers in the company formation questionnaire and, if you choose to give one, your reason for deleting your account.
- In-app activity stored with your account: your progress through the integration steps, your reading position in the e-book (chapter and position), your in-app search history, and the event reminders you have switched on.
- Device and notification data: your Expo push notification token, whether the device is signed in, the app version and the operating system.
- Usage analytics: pseudonymous events such as screens opened, articles, videos or chapters opened, buttons tapped, language selected and search terms entered, together with an app installation identifier.
- Error and crash data: device model, operating system and app version, the time of the error and a technical stack trace.
- Location, only if you allow it: the approximate or precise coordinates of your device at the moment you ask for nearby content.
Why we process data and on what legal basis
Every processing activity has a purpose and a legal basis under Article 6 GDPR:
- Creating and running your account, showing you personalised content and progress — performance of a contract, Article 6(1)(b) GDPR.
- Handling your consultation request, your conversation with our team and the company formation questionnaire — performance of a contract and steps taken at your request prior to entering into one, Article 6(1)(b) GDPR.
- Sending push notifications about your conversation, your consultation or an event you subscribed to — performance of a contract, Article 6(1)(b) GDPR.
- Sending the newsletter and promotional messages — your consent, Article 6(1)(a) GDPR, which you can withdraw at any time in the app settings.
- Accessing your location and writing an event to your device calendar — your consent, given through the system permission prompt, Article 6(1)(a) GDPR.
- Usage analytics, so we can understand which content actually helps people and keep improving the app — your consent, Article 6(1)(a) GDPR, read together with the rules on accessing information stored on your device.
- Error and crash reporting, to keep the app stable and secure — our legitimate interest in a working, secure app, Article 6(1)(f) GDPR.
- Preventing abuse, spam and unauthorised access — legitimate interest, Article 6(1)(f) GDPR.
- Meeting legal obligations, such as retaining business and accounting records — Article 6(1)(c) GDPR.
Device permissions: location, calendar and notifications
Location is entirely optional. We request it only while you are actively using the app, and only to show you organisations, businesses and events near you on the map and in lists. The coordinates are used at that moment to calculate proximity and are not stored with your profile. If you decline, the app works normally — we simply show you all content without sorting by distance.
Calendar access is requested only when you tap the button to add an event to your calendar. We then write that single event to your device calendar. We do not read your existing appointments and we do not transfer your calendar to our servers.
Push notifications are only sent after you approve the system prompt. To deliver them we store the device token issued by Expo; delivery itself runs through Apple (APNs) and Google (FCM). You can turn notifications off in the app settings or in your operating system settings; the token then stops being used and is removed when you sign out or delete your account.
Analytics and crash reporting
For analytics we use Firebase Analytics (Google). We record pseudonymous events: which screen was opened, which article, video or chapter was opened, which language was selected, which button was tapped and which term was searched. These events are sent together with an app installation identifier assigned by Firebase. We do not send Firebase your name, your email address or the content of your messages.
For error and crash reporting we use Sentry and Firebase Crashlytics. They record technical information about the device and about where in the code the failure happened, so that we can fix it. We do not intentionally send any content you entered in the app to these reports.
If you do not want us to record usage analytics, write to support@tvoja-integracija.com and we will exclude your account from analytics reporting. You can further limit device-level tracking in the privacy settings of your iOS or Android device.
Consultations, messages and questionnaires
When you send a consultation request, a conversation is opened between you and our team. Your question and every message in that conversation are stored in our database and are visible to you and to the members of our team who handle consultations. Our team receives a push notification about the new request that contains the text of your question.
If you complete the company formation questionnaire, we send your answers by email to the responsible person on our team or to the partner who handles that type of consultation. We use the Resend service to send that email.
Please do not put more information into messages and questionnaires than we need in order to understand your question. In particular, avoid special category data under Article 9 GDPR — for example data about health, religious or political beliefs — unless it is genuinely necessary. If you do send it to us voluntarily, we process it on the basis of your explicit consent in order to answer your request.
Content from external sources
Part of the content in the app — the blog, the chapters and the helpful forms — comes from our website tvoja-integracija.com, which runs on WordPress. When the app fetches that content, the website server records the usual technical access data, such as the IP address and client information.
Videos are shown through an embedded YouTube player. When you start a video, your device connects to Google servers and Google may process data about that access under its own privacy terms.
The map is rendered through the map service of your device and platform — on Android this is Google Maps. When you open a location and choose to navigate, an external maps app opens on your device.
The app contains links to external websites, to the community Facebook group and to the book order page. Once you open such a link, the operator of the destination site is responsible for that processing and its privacy terms apply.
We deliver content updates for the app through the Expo Updates service. When checking for an update, your device sends Expo the app version and platform information.
Processors and international transfers
To run the app we use carefully selected service providers who process data only on our instructions and with whom we have data processing agreements in place under Article 28 GDPR:
- Supabase — database, authentication, file storage and server functions. Our instance is hosted in the European Union.
- Google (Firebase Analytics and Firebase Crashlytics) — analytics and crash reporting.
- Sentry — error reporting and technical stability monitoring.
- Expo — delivery of push notifications and app updates.
- Apple and Google — sign-in with Apple, app distribution through the App Store and Google Play, and push delivery through APNs and FCM.
- Resend — transactional email, for example the company formation questionnaire.
- Slack — internal technical alerts about content loading errors; those messages contain technical information, not your profile content.
- The hosting provider of tvoja-integracija.com, the website the app fetches content from.
How long we keep data
We keep your account and profile data for as long as your account exists. When you request deletion, we delete it within 30 days, as described on our account deletion page.
Messages in conversations with our team remain in the conversation after your account is deleted, but they are detached from your identity — they are no longer linked to any user account. This preserves the record of the advice we gave without keeping data about you.
Error and crash data is kept by our providers within their standard retention windows, which are well under one year. Analytics events are kept for the retention period configured in our Firebase project.
Where the law requires us to keep something — for example accounting records relating to earlier subscriptions — we keep that data until the statutory period expires, and during that time we use it for that purpose only.
Database backups rotate automatically, so deleted data also disappears from the backups once the rotation cycle has passed.
Deleting your account
You can delete your account yourself, directly in the app: Profile, then Settings, then Request profile deletion. Deletion is carried out within 30 days, and you can cancel the request with the same button before that deadline passes.
If you can no longer sign in, send us a request from your registered email address to support@tvoja-integracija.com.
A detailed explanation of what gets deleted, what remains and why is on our Account and Data Deletion page.
Your rights
Under the GDPR you have the following rights in relation to your data:
- Right of access, Article 15 — to learn what data we process about you and to receive a copy of it.
- Right to rectification, Article 16 — to have inaccurate data corrected and incomplete data completed. You can change your name, date of birth and origin yourself in your profile.
- Right to erasure, Article 17 — to have your data deleted when there is no longer a basis for processing it.
- Right to restriction of processing, Article 18 — to have processing temporarily frozen, for example while we verify the accuracy of your data.
- Right to data portability, Article 20 — to receive the data you provided to us in a structured, commonly used and machine-readable format.
- Right to object, Article 21 — to object to processing that is based on our legitimate interest.
- Right to withdraw consent, Article 7(3) — you can withdraw consent for the newsletter, notifications, location, calendar or analytics at any time, without affecting the lawfulness of processing before the withdrawal.
- Right to lodge a complaint with a supervisory authority, Article 77 — you may contact the data protection authority in the country where you live or work, or where the alleged infringement took place. Users in Germany can contact the competent state data protection authority, users in Croatia the Personal Data Protection Agency (AZOP), and users in Bosnia and Herzegovina the Personal Data Protection Agency.
Children and younger users
The app is not intended for children under 16. People under 16 may use the app only with the consent and under the supervision of a parent or legal guardian, who in that case also gives consent for the processing of their data.
We do not knowingly collect data from children under 16. If we learn that an account was created by a child without guardian consent, we delete that account and the associated data. If you are a parent or guardian and believe we hold your child's data, contact us at support@tvoja-integracija.com.
Security and data stored on your device
All communication between the app and our servers runs over an encrypted connection (TLS). In the database we use row level security, so each user can read only their own data and the conversations they take part in. Only a small number of authorised people on our team have access to production data.
The app does not use cookies in the classic sense, but it does store data locally on your device: your sign-in token, the language you chose, your onboarding state, your push notification token and a cached copy of content you have already viewed, so the app is fast and works offline.
You can remove this local data by signing out of the app or by deleting the app from your device. The in-app browser and the YouTube player may, however, store their own data under Apple's, Google's and the destination site's terms.
Changes to this policy
We keep developing the app, so this policy will need updating from time to time — for example when we add a feature or change a service provider. The version published on this page is always the one that applies, and the date of the last update is shown at the top.
We will tell you in advance about significant changes that affect your rights, either in the app or by email. Where a change requires your consent, we will ask for it separately.
Contact
For any question about this policy, about how we process your data, or to exercise your rights, write to support@tvoja-integracija.com.
More about the project, and the imprint with the operator's full details, can be found at tvoja-integracija.com.