1. Controller, contact and scope

Temelj za rast DOO (“Temelj”, “we”, “us”), tax/company ID 03414442 and registration number 5-1013971/002, with registered address Trg slobode 5, apt 12, 85310 Budva, Montenegro, is responsible for personal data processing for the public website libar.me, business enquiries, sales, client account administration, direct support, billing for its own services and protection of its systems. Privacy contact: contact@temelj.me and +382 67 788 339.

This policy covers the public website libar.me, contact and presentation requests, business communication and the Libar application at app.libar.me. A signed offer, SaaS service agreement, data processing agreement, SLA or specific notice may govern a particular relationship more precisely. In a conflict, the signed document takes precedence for the contracted service.

2. When Temelj acts as controller or processor

Temelj usually acts as controller when it determines the purposes and means of processing data about website visitors, prospective clients, client contacts, account users, billing contacts, support requests, security records and its own business administration.

When a hotel, aparthotel, villa, guesthouse or other client uses Libar for data about its guests, employees, suppliers or business partners, the client usually acts as controller and Temelj as processor under the client's documented instructions. The client determines the legal basis, data scope and retention periods arising from its legal obligations, provides the required information, manages permissions and decides on individuals' requests.

3. Information from the website and from business communication

When you request a presentation, we process your full name, hotel or accommodation name, business email, phone if provided, number of properties, number of accommodation units, needs description and submission time. We use this data to respond, assess the relevant plan and onboarding scope, prepare a presentation, conduct requested pre-contractual communication and protect the form against abuse.

If you contact us through another channel, we may process message content, contact details, organisational role, records of agreements, offers, contractual documentation, billing details and support history. The contact form itself does not subscribe you to a marketing list.

4. Technical and safety data

When you access the website or application, the infrastructure may process IP address, request time, requested URL, HTTP status, technical browser and device information, referrer where sent by the browser, session identifiers, sign-in attempts and other security events. This data supports content delivery, diagnostics, abuse prevention, account protection, incident investigation and evidence of service integrity.

The public website currently does not use analytic or marketing cookies and does not create advertising profiles. A detailed list of browser technologies is found in Cookie Policy.

5. Data that can be processed in Libar application

The exact scope depends on the features, plan, property configuration and integrations enabled by the client. Libar is a business tool, and the client must limit input to data needed for lawful hotel operations.

Typical data categories in Libar
CategoryExamples and Purpose
Guests and contactsName, contact, nationality, language, notes and other information necessary for booking, service and hotel records.
Guest documentIdentification document details and, where an agreed lawful workflow requires it, a copy or OCR result. Access must be restricted to authorised roles.
Reservations and staysArrival and departure date, source of reservation, room, number of guests, status, price, requirements and history of changes.
Rooms and operationsRoom status, housekeeping, inspections, faults, tasks, shift handovers, responsible persons, deadlines and notes.
Folios, invoices and paymentsItems, taxes, fees, amounts, payment status, invoice and transaction references. Libar does not need to store the full card number or security code; those details are processed by an enabled payment provider.
CommunicationConfirmations, messages and communication history related to the guest, reservation, support or operational task.
Users and SecurityBusiness contact, role, permissions, MFA and session data, IP address, user-agent, logins, audit and other security events.

6. Where do we get the data?

We receive data directly from you; from a client creating or managing a property; from authorised hotel users; from a reservation or communication initiated by a guest; from reservation channels, iCal links, booking components, email or other services approved by the client; and automatically through devices, sessions and security systems.

If you provide another person's data, you must have authority and an appropriate legal basis, provide the required information and supply only data relevant to the purpose.

7. Purposes of processing and legal basis

The legal basis depends on the relationship, data type and applicable law. When Temelj acts only as processor, the client acting as controller determines the legal basis.

Purposes and usual legal basis for processing
PurposeUsual legal basis
Answer to request, presentation and preparation of offersSteps taken at the individual's request before entering into a contract, and a legitimate interest in business communication.
Providing, configuring and supporting the Libar servicePerformance of a contract; for client content, the controller's documented instructions.
Accounts, authentication, security and abuse preventionPerformance of a contract, legitimate interests in protecting users and the system, and legal obligations where applicable.
Billing, accounting and legal recordsPerformance of a contract and compliance with tax, accounting or other legal obligations.
Diagnostics and Improvement of ReliabilityLegitimate interests in maintaining and improving the service, subject to data minimisation and proportionality.
Optional measurements or marketing, if anyConsent where required by law, with a right to withdraw without affecting the lawfulness of earlier processing.
Legal claims and dealings with authoritiesLegal obligations and legitimate interests in establishing, exercising or defending claims.

8. Mandatory and optional data

Fields marked as required are necessary to process an enquiry or perform the requested function. Without a business email and basic property information, we cannot reliably respond or prepare a relevant presentation. Optional information, such as a contact phone number, may help communication but does not have to be provided.

In the application, required data is determined by the function, client configuration and applicable hotel obligations. Withholding necessary data may prevent sign-in, a reservation, document issuance or another requested action, but we will not request data that is not reasonably necessary for the purpose.

9. Recipients, subprocessors and integrations

Access is limited to authorised Temelj team members and contracted providers that need the data for hosting and infrastructure, email, support, security, backups, accounting, development or professional advice. A provider may be a processor or an independent controller, depending on its service and statutory role.

Integrations requested by the client, such as booking platforms, iCal, email services, payment providers or accounting systems, receive only the data needed for the enabled connection and are subject to their own terms and privacy policies. Current subprocessor categories and additional contractual details are provided under the contract or on reasonable request.

We can provide data to the competent authority, court, auditor, insurer or legal adviser when required by law or reasonably necessary to protect the rights, users and integrity of the service.

10. International transfers

Individual infrastructure or integration providers may process data outside of Montenegro or the European Economic Area. When applicable legislation requires additional measures, the transfer is based on an available legal mechanism, such as the decision on adequacy, appropriate contractual clauses, processing contract or other permitted basis, with technical and organisational measures appropriate to risk.

The client is responsible for assessing and approving transfers arising from integrations or external accounts it chooses.

11. Retention periods

We retain data only as long as needed for the collection purpose, an active contract, support, security, mandatory tax and accounting records, dispute resolution or legal protection. When determining retention, we consider the data's type and sensitivity, misuse risk, scope, purpose, individuals' expectations, contractual obligations, anonymisation possibilities and statutory periods.

Business enquiries that do not lead to a contract are reviewed periodically and deleted or anonymised when no longer needed for reasonable business communication or a legal claim. Client data in Libar is retained during the contract and then exported, returned, deleted, anonymised or temporarily retained in backups according to the contract, client instructions, backup cycle and mandatory law.

Reservations, stays, invoices, taxes, guests and security records may have different retention periods. The hotel as controller must determine and document the periods applicable to its activities; this public policy does not replace its retention schedule.

12. Your Rights

Subject to applicable law and possible legal exceptions, you may request information and access to your data, correction of inaccurate or completion of incomplete data, erasure, restriction or blocking of processing, portability where applicable, and object to processing based on legitimate interests. Where consent is the basis, you may withdraw it at any time without affecting the lawfulness of earlier processing.

You can lodge a complaint with the Agency for the Protection of Personal Data and Free Access to Information of Montenegro (AZLP) or to another competent supervisory authority. Before the complaint you can contact us to try to resolve the matter, but that is not a condition for addressing the competent authority.

13. How to submit a request

Send a request to contact@temelj.me or through the contact form and state your name, contact, organisation or property, service and request type. We may seek reasonable identity verification and additional information needed to locate the record, but no more than necessary to verify and handle the request.

If the request concerns data controlled by the hotel, we will refer you to the hotel or assist it according to the contract and law. We respond without undue delay and within the period required by the law applicable to the specific request.

14. Security and incidents

We apply technical and organisational measures appropriate to risk, including access restrictions by tenant, property and role, MFA and additional verification for sensitive actions, transmission protection, session management, audit trails, backups, limits on publicly exposed services and incident response procedures.

No system can be absolutely secure. The client must assign permissions correctly, remove access no longer needed, safeguard credentials, protect devices and report suspected compromise promptly. We notify the client according to the contract and applicable law.

15. Minors and automated decision-making

The public website and Libar are business services and are not directed at children. A hotel may lawfully process a minor guest's data where necessary for a reservation, registration or stay; the hotel determines the legal basis, notice, parental or guardian authority where required, and minimum necessary scope.

Temelj does not use public website data for solely automated decisions producing legal or similarly significant effects. Libar automations support defined operational flows; the authorised hotel team remains responsible for decisions about guests, prices, refunds, registration, billing, employees and legal obligations.

16. Changes and contact

We can update the policy when the product, processing, providers or regulations are changed. The current version and date of the change are always published at this address. We will notify the client by means of a product, email or other agreed channel when necessary.

Privacy questions and requests: contact@temelj.me, +382 67 788 339, Temelj za rast DOO, tax/company ID 03414442, registration number 5-1013971/002, Trg slobode 5, apt 12, 85310 Budva, Montenegro.