Privacy Policy Kojé Marketplace
Application: kojé – local service marketplace | Last updated: August 17, 2026Overview
This Privacy Policy explains how kojé s. r. o. collects, uses, and protects your personal data when you use the kojé – local service marketplace mobile app (Android & iOS) and related platform services.
All personal data is processed in accordance with Regulation (EU) 2016/679 (GDPR) and the Slovak Act No. 18/2018 Coll. on Personal Data Protection.
1. Data Controller
The controller of your personal data is:
Company Name: kojé s. r. o.
Registered Office: Bauerova 1205/7, 040 23 Košice – Sídlisko KVP, Slovak Republic
Company ID (IČO): 57629251
Email (Support & Privacy): support@koje.sk / info@koje.sk
Website: https://koje.sk
2. What Data We Collect and Why
- Identity and Contact Data: Name, email address, phone number, and profile picture for account creation, direct customer-provider communication, and booking management.
- Billing and Invoicing Data: Company name / Full name, billing address (street, city, ZIP code), Company ID (IČO), Tax ID (DIČ / VAT ID), and IBAN bank account number for automated PDF invoice generation, Pay by Square QR code creation, and tax compliance.
- Location Data (GPS):
- Customers: Used strictly with foreground permission to discover nearby service providers and craftsmen.
- Providers: Providers who voluntarily enable "Dynamic Location" grant permission for background GPS collection (5-minute intervals). The location is obfuscated within a user-chosen privacy radius before being displayed on the map. This feature can be turned off at any time in settings.
- Photos and Camera (Storage & Media): Photos of damaged items/spaces uploaded by customers for AI problem analysis, portfolio photos of completed work, and chat attachments. Stored securely on Cloudflare R2.
- AI Content Analysis & Moderation: Request text and uploaded images are processed by Google Gemini AI to suggest appropriate service categories and to perform safety moderation (detecting explicit, offensive, or illegal content). No personal identifiers are transmitted to AI models.
- Encrypted Chat Communications: Direct chat messages and booking offers are encrypted and stored for support, order execution, and dispute resolution.
- Technical Data & Push Notifications: Device tokens, IP addresses, OS version, and Firebase Cloud Messaging (FCM) tokens to notify users about messages, bids, and order status updates.
3. Legal Bases for Processing
- Performance of Contract (Art. 6(1)(b) GDPR): Providing marketplace features, booking management, user accounts, and direct communication.
- Legal Obligation (Art. 6(1)(c) GDPR): Issuing and storing statutory invoices under the Slovak Accounting Act and reporting provider revenue under EU Directive 2021/514 (DAC7).
- Legitimate Interest (Art. 6(1)(f) GDPR): Preventing fraud, ensuring cybersecurity, and optimizing user experience.
- Consent (Art. 6(1)(a) GDPR): Background location access, camera/gallery permissions, and marketing communications (if requested). You may withdraw consent at any time.
4. Data Processors & Third-Party Services
| Partner | Purpose | Location / Safeguards |
|---|---|---|
| Google LLC (Firebase / Cloud) | Authentication, Push notifications (FCM), Database, Gemini AI safety screening. | EU / USA (SCC) |
| Cloudflare, Inc. (R2 Storage) | Encrypted cloud storage for request photos, portfolio pictures, and PDF invoices. | EU / Global (SCC) |
| WebSupport, s.r.o. | Email relay infrastructure for transaction notifications and PDF invoices. | Slovakia (EU) |
| Railway Corp. | Secure cloud infrastructure for backend APIs and database. | EU / USA (SCC) |
5. Data Retention & Account Deletion
- Profile data and active requests are retained until account deletion.
- You can delete your account and personal data instantly in the app via Profile → Settings → Delete Account or by emailing support@koje.sk.
- Accounting and tax invoices must be retained for 10 years in compliance with the Slovak Accounting Act (exemption under Art. 17(3)(b) GDPR).
6. Your Rights Under GDPR
Under the GDPR, you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and the right to object (Art. 21).
If you believe your rights have been violated, you have the right to lodge a complaint with the supervisory authority: Office for Personal Data Protection of the Slovak Republic (dataprotection.gov.sk).
7. Data Security
We take the security of your personal data very seriously. In accordance with Art. 32 GDPR, we apply appropriate technical and organizational security measures to protect your data against unauthorized access, alteration, disclosure, loss, or destruction. These measures include encrypted transmission across public networks, tiered access controls, infrastructure monitoring, and secure storage in certified data centers.
8. Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without parental consent, we take steps to promptly delete that data.