Privacy Policy
SECURE DIPLO INVITE
A proprietary digital product of ZOE MILANO d.o.o.
Last updated: 21 January 2026
Data Controller
Secure Diplo Invite is a proprietary digital invitation management and access control platform developed and owned by ZOE MILANO d.o.o.
ZOE MILANO d.o.o.
Dragiše Brašovana 20
11070 Belgrade, Serbia
Company Registration Number (MB): 21307548
Tax Identification Number (PIB): 110155135
Email: [email protected]
Privacy contact: [email protected]
ZOE MILANO d.o.o. operates internationally and develops proprietary digital platforms and software solutions.
Scope of This Privacy Policy
This Privacy Policy applies to the Secure Diplo Invite website, applications, and related services (collectively, the "Service").
This Privacy Policy explains how personal data is collected, used, stored, and protected when users:
- request information or a demonstration of the Service;
- use Secure Diplo Invite as event organizers, invitees, or security personnel;
- interact with the Service through web or mobile interfaces.
Personal Data We Collect
We collect only the personal data necessary to provide and operate the Service.
This data may include:
- first and last name;
- email address;
- organization name, if provided;
- invitation status: accepted, declined, pending, or revoked;
- access and scan logs, including the date, time, and result of each QR code scan;
- technical metadata necessary to ensure the security, integrity, and auditability of the system.
We do not intentionally collect special categories of personal data as defined under the GDPR.
Purposes of Personal Data Processing
Personal data is processed solely for the following purposes:
- creating and managing event invitations;
- delivering invitations and recording the corresponding responses;
- verifying access at event entry points;
- generating and retaining audit and security logs;
- responding to inquiries and providing support;
- protecting the security, integrity, and reliability of the system;
- complying with applicable legal and regulatory obligations.
We do not sell, rent, or otherwise disclose personal data for commercial purposes.
Legal Basis for Processing
Personal data is processed in accordance with Article 6 of the GDPR on one or more of the following legal bases:
- performance of a contract or provision of the Service;
- legitimate interests relating to security, access control, and the auditability of operations;
- the user's consent, where applicable;
- compliance with legal obligations.
Data Retention and Security
ZOE MILANO d.o.o. implements appropriate technical and organizational measures to protect personal data, including:
- secure servers and controlled environments;
- access control systems and role-based permissions;
- encrypted communications using HTTPS/TLS protocols;
- monitoring and audit mechanisms.
Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected or to comply with applicable legal obligations.
Offline Operation and Audit Logs
Secure Diplo Invite supports offline access verification. Access and scan logs generated during offline operation are stored locally and synchronized with the server once connectivity is restored.
These logs are used exclusively for access control, operational auditability, and security review purposes.
Data Sharing
Personal data may be shared exclusively with:
- trusted service providers supporting hosting, technological infrastructure, or email delivery;
- competent authorities where required by law.
All service providers are contractually required to comply with the GDPR or equivalent personal data protection standards.
International Data Transfers
As an international service provider, ZOE MILANO d.o.o. may process personal data outside the Republic of Serbia and the European Union.
In all cases, appropriate safeguards are implemented in accordance with GDPR requirements.
Data Subject Rights
Data subjects have the right to:
- access their personal data;
- request the rectification of inaccurate data;
- request the erasure of their personal data;
- withdraw consent, where applicable;
- object to processing;
- request data portability.
Requests may be submitted to: [email protected]
Changes to This Privacy Policy
This Privacy Policy may be updated periodically. Any changes will be published on this page together with the updated revision date.