Privacy policy
Last updated: 28. 7. 2026
1. Data controller
The personal data controller for the dogodki.today portal is Zveza društev Mladinski center Postojna (the portal operates within the regional NGO hub BOREO). Contact for questions about personal data protection: dogodkinvo@mcp.si.
This policy applies to the dogodki.today portal.
2. What data is processed
- E-mail address (for event notifications)
- Phone number (optional; for SMS notifications)
- Name (optional; for personalizing notifications)
- Location (optional; for "near me" notifications — explicitly shared by the user)
- Subscription preferences (which categories/organizers you follow, how often)
- Push subscription endpoint (for browser push notifications)
- Session token (cookie "narocnik_token", to identify the logged-in user)
- Anonymized visit statistics: path, time on page, source of arrival (referrer), screen dimensions, language. No cookies, no cross-day tracking — a unique visitor is calculated with a daily salted hash (irreversible). The IP address is used only transiently as input for this hash calculation and is not stored in raw form. Raw records are kept for 30 days, aggregates permanently. Processing takes place entirely on our server, without third-party involvement.
3. Legal basis
We process data on three legal bases — which one applies depends on the type of data:
- Consent (GDPR Art. 6(1)(a)) — email address, phone number, name, location, subscription preferences, and push subscription endpoint. You provide consent by actively clicking (email confirmation via magic-link or phone via SMS PIN). You can withdraw it at any time via the "Unsubscribe" link in every message, or on the /moje page.
- Necessity for service provision — session token (cookie "narocnik_token"). Without it, the portal would not recognize you as a logged-in user when navigating between pages, making it a strictly necessary cookie under the Electronic Communications Act (ZEKom-2) and thus exempt from consent requirements.
- Legitimate interest (GDPR Art. 6(1)(f)) — anonymized visit statistics. Our interest as the data controller is the operation, security, and improvement of the portal. Individuals are not identifiable from the statistics: the visitor identifier is an irreversible hash with a daily random salt, and the data remains entirely on our server.
Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal (GDPR Art. 7(3)).
4. Purpose of processing
We use your data exclusively to send notifications about events that match your preferences (category, organizer, location, time before the event). We do not share your data with third parties for marketing or analytics purposes.
5. Event Registrations
When you register for an event through the portal, the controller of your data is the event organiser, not the portal — the portal acts as a processor, technically transmitting and storing data on behalf of the organiser. The legal basis is the performance of the registration (Art. 6(1)(b)); data is stored for up to 12 months after the event, and payment data for 10 years (accounting regulations). You exercise your rights regarding registration with the organiser, whose contact information is listed with the event; their processing notice is published alongside the registration form.
6. Third Parties
- Google Maps — on some pages we display Google Maps. The script is only loaded after your consent (by clicking "Load map"). Google may set cookies and collect IP addresses. More: policies.google.com/privacy
- Push providerji (Google FCM, Apple APNs, Mozilla autopush) — for browser push notifications. Notification content is encrypted (VAPID); the provider only sees metadata (endpoint, ID). Push providers may also process data in third countries (USA); the transfer is based on the EU-U.S. Data Privacy Framework or on standard contractual clauses.
- SMS in e-pošta — We send SMS exclusively via our own infrastructure (smstools3 and GSM modem on our own server) — without external SMS providers. Email messages are prepared and DKIM-signed by our server and delivered via Google's intermediary server (SMTP relay) — Google, as a processor, technically processes the recipient's address and message content. This processing may also take place in third countries (USA); the transfer is based on the EU-U.S. Data Privacy Framework, or subsidiarily on standard contractual clauses. More: policies.google.com/privacy
7. Your Rights
- Right of access: you can see all your data and subscriptions on /moje.
- Right to rectification: changes on /moje (name, phone, location, preferences).
- Right to erasure ("right to be forgotten"): the "Delete me" button on /moje or the "Delete all my data" link in any email/SMS.
- Right to restriction of processing: uncheck notification channels or schedules on /moje.
- Right to data portability (GDPR Art. 20): on /moje, you can export your data in a machine-readable format (JSON).
- Right to object: every email/SMS contains an "Unsubscribe" link.
8. Data Retention Period
We store your data until you cancel your subscription. After cancellation, it is immediately deleted from the production database and from backups during their regular rotation, no later than within 30 days. Access to backups is restricted; if a backup ever needs to be restored, deleted data will be re-deleted upon restoration. Unconfirmed subscribers are deleted after 7 days; inactive subscribers (more than 5 years without activity) receive a warning and are then deleted.
9. Security
- TLS (HTTPS) for all transfers between your browser and the server
- PINs and tokens are cryptographically signed (HMAC) or hashed (bcrypt)
- Cookies: HttpOnly, Secure, SameSite=Lax
- CSRF protection for all actions
10. Complaint
If you believe we are violating your rights, you can file a complaint with the Information Commissioner of the Republic of Slovenia (Dunajska 22, 1000 Ljubljana).
11. Contact
For any questions regarding personal data protection: dogodkinvo@mcp.si.