Who we are and how to contact us.
Podrelay is a business service operated from Bosnia and Herzegovina. Podrelay is the controller of personal data used to operate this website, protect the client portal, respond to enquiries and manage business relationships.
For questions or privacy requests, email hello@podrelay.io.
Scope of this policy.
This policy applies when you visit podrelay.io, contact us, book a meeting, use the demonstration client portal or communicate with us about a current or possible engagement. It does not replace a client service agreement or data processing agreement.
When Podrelay processes personal data solely on a client's documented instructions, the client is normally the controller and Podrelay is a processor. The applicable agreement defines those roles and instructions.
Personal data we collect.
We may collect:
- Contact and business data: name, business email address, company, job title, telephone number and the contents of your messages.
- Booking data: meeting time, time zone and answers submitted through our scheduling provider.
- Commercial records: proposals, correspondence, signed agreements, service records, invoices and payment status.
- Portal and security data: portal username, sign-in status, session identifiers, IP address, request time, browser information and security logs. Portal passwords are checked on the server and are not included in public website files.
- Technical data: IP address, device and browser details, requested pages, timestamps, referral information and diagnostic logs created when the website is delivered.
- Local preferences: theme, date-range or similar settings stored in your browser for the portal demonstration.
- Client-provided data: data made available under a client agreement for reporting, verification or related operations.
Please do not send passwords, API keys, payment-card details, government identifiers or sensitive personal data through ordinary email or booking forms.
How we collect data.
We receive data directly from you, from the organization you represent, from clients that authorize us to work with their systems, and automatically through hosting and security infrastructure. Scheduling and other service providers also send us the information needed to provide their requested function.
Why we use personal data and our legal bases.
We use personal data to:
- respond to enquiries, arrange meetings and prepare proposals;
- enter into and perform service agreements;
- operate, authenticate, troubleshoot and secure the website and portal;
- provide reporting, verification and related services under client instructions;
- manage billing, accounting, recordkeeping and legal claims; and
- comply with legal and regulatory obligations.
Depending on the circumstances, we rely on steps requested before a contract, performance of a contract, compliance with legal obligations, consent, or legitimate interests. Legitimate interests include responding to business enquiries, administering business relationships, preventing unauthorized access, improving reliability and protecting legal rights. Where consent is the legal basis, you may withdraw it at any time without affecting earlier lawful processing.
Cookies and browser storage.
The protected portal uses a strictly necessary authentication cookie. It is marked Secure and HttpOnly, is limited to the portal path and expires automatically after 12 hours. The portal may also store display preferences in local browser storage.
Podrelay does not currently use advertising cookies, cross-site tracking pixels or its own audience analytics cookies. If that changes, this policy and any legally required consent controls will be updated before the technology is enabled.
Service providers and disclosures.
We disclose personal data only where reasonably necessary to operate the business, provide a requested service, comply with law or protect legal rights. Recipients may include:
- Vercel, which hosts and protects the website and portal;
- Cal.com, when you choose to use the booking link;
- Google, which supplies web fonts requested by the visitor's browser;
- business email, storage, accounting and collaboration providers;
- professional advisers, authorities or courts where legally required; and
- a successor involved in a genuine sale, reorganization or transfer of the business, subject to appropriate safeguards.
Third-party services process data under their own terms and privacy notices. We do not sell personal data. We do not share personal data for cross-context behavioral advertising.
Client data.
Access to client systems and data is governed by the applicable written agreement. Where required, Podrelay and the client will enter into a data processing agreement covering instructions, confidentiality, security, subprocessors, international transfers, assistance, return or deletion and incident notification.
The public portal is a fictional demonstration. Real client data must not be placed in the public demo or other static website files.
International transfers.
Podrelay is based in Bosnia and Herzegovina. Our providers and clients may be located in Bosnia and Herzegovina, the European Economic Area, the United Kingdom, the United States or elsewhere. Where applicable law requires a transfer mechanism, we use contractual safeguards or another lawful mechanism appropriate to the transfer. You may contact us for information about safeguards relevant to your data.
Retention.
We keep personal data only for as long as reasonably necessary for the relevant purpose. Enquiry records are generally retained for up to 24 months after the last meaningful contact unless a relationship begins or there is a legal reason to retain them longer. Portal sessions expire after 12 hours. Security and hosting logs follow our provider settings and may be retained longer when needed to investigate abuse.
Client, contract, invoice and accounting records are kept for the term of the relationship and any additional period required by applicable law, the governing agreement, tax rules or legitimate legal-claim needs. Data is then deleted, anonymized or securely archived where deletion is not yet permitted.
Your privacy rights.
Depending on where you live and the law that applies, you may have rights to request access, correction, deletion, restriction, objection, portability or withdrawal of consent. You may also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Podrelay does not use website visitor data for that type of automated decision.
Residents of US states with applicable privacy laws may also have rights to know, delete or correct personal information and to opt out of certain sale, sharing, targeted advertising or profiling. Podrelay does not sell personal information or use it for cross-context behavioral advertising. We will not discriminate against you for exercising an applicable privacy right.
Send a request to hello@podrelay.io. State your country or state and the right you wish to exercise. We may verify your identity and authority before acting. Legal exceptions may apply.
You may complain to the Personal Data Protection Agency in Bosnia and Herzegovina. If EU, UK or another local privacy law applies, you may also complain to the supervisory authority where you live or work.
Security.
We use reasonable administrative, organizational and technical safeguards appropriate to the nature of the information, including access controls, protected portal sessions, encrypted network connections and provider security features. No system can be guaranteed completely secure. If you believe data or portal credentials have been compromised, contact us promptly at hello@podrelay.io.
Children.
The website and services are intended for business users aged 18 or older. We do not knowingly collect personal data from children through the website. Contact us if you believe a child has provided personal data.
Third-party websites.
The website links to services we do not control. Their privacy practices are governed by their own notices. A link does not mean Podrelay controls or endorses their privacy practices.
Changes to this policy.
We may update this policy when our practices, providers or legal obligations change. The revised version will be posted here with a new effective date. Material changes will be communicated where required by law.
