SITEFETTI · 2026-09-25-processing-release-v7
Privacy and cookies
Operator and contact
FORUM TRADE, podjetje za trgovino, zastopništvo in posredniško dejavnost, Miloš Verić s.p.
Šerkova ulica 13, 1000 Ljubljana, Slovenia
Registration: 6955002000 · VAT ID: SI59777648
1. Information we use
Contact forms collect your name, email and message, and for business enquiries your company name and tax identifier. Creation requests use your description, business details, language, contact details and generated content. Accounts contain sign-in and verification records; orders contain plan, billing and payment status. Contacting Sitefetti does not subscribe you to marketing. Contacts gathered on a customer’s website are not automatically added to Sitefetti campaigns.
2. Purposes, legal bases and roles
We use account, content and order data to perform the contract with you or take steps you request before entering it (GDPR Article 6(1)(b)). Billing and tax records also meet legal obligations (Article 6(1)(c)). Security, fraud prevention and handling business representatives' enquiries rely on legitimate interests in protecting and operating the service (Article 6(1)(f)), balanced against your rights. Where we ask for consent for optional messages, it can be withdrawn without affecting earlier lawful processing; a contact enquiry is not marketing consent. Outreach requires a separate assessment for the recipient and country. FORUM TRADE is controller for these purposes. For contacts and orders collected on a customer's website, the customer determines the purpose and Sitefetti acts on documented instructions under a data-processing agreement.
3. Providers
Authorised subprocessors are Render Services, Inc. (application hosting, primary region Frankfurt); Supabase Pte. Ltd. (database and website images, primary region Ireland); OpenAI Ireland Ltd. (requested text and image generation, Global project processing); Plus Five Five, Inc., trading as Resend (email addresses and message content, United States); and Cloudflare, Inc. (encrypted R2 backups, EU bucket jurisdiction). Each receives only the data needed for its function and is bound by data-protection obligations appropriate to that processing. Sitefetti remains responsible for its subprocessors’ obligations. EU primary storage does not exclude support or further processing outside the EU. Transfers use an applicable adequacy decision or standard contractual clauses and the required supplementary safeguards. Contact hello@sitefetti.com for relevant safeguard information. Stripe Payments Europe, Limited, and where applicable Stripe Technology Europe, Limited, process payments in their applicable controller or processor roles. Better Stack, Inc. receives availability and backup-result signals and operator contact details, not customer archives. The latter services are not authorised to use customer website contacts for marketing.
5. Retention, export and deletion
Unclaimed anonymous drafts are reviewed for deletion 30 days after their last generation or saved edit; unpaid drafts in verified accounts after 90 days of inactivity; closed routine enquiries after 12 months. Active paid services are excluded. After a paid service ends, there is a 30-day export window. Support can supply supported records with customer-owned image files; an export does not include the Sitefetti software. Scheduled deletion is preceded by seven days’ warning when a verified email is available. Deletion requests are verified and handled with a record of the actual scope, provider copies and exceptions. Required accounting records remain for their statutory period; relevant dispute and security evidence remains only for the justified purpose and applicable claim period, with restricted access and review. Private encrypted backups keep the seven newest verified daily copies. Failed backups may delay rotation. Deletion restrictions are reapplied before restored data is released. Closing a message or cancelling renewal does not by itself erase data. Provider-held copies may require support-assisted deletion or restricted retention until expiry; we explain remaining exceptions in the response.
Security and incident handling
Access is restricted by account permissions. Backups are encrypted and stored separately from the running application. We review reported incidents and affected records before deciding what notifications or corrective action are required. No security measure guarantees that an incident can never occur. Do not send passwords, card details or sensitive identity documents through ordinary support forms.
6. Contact and rights
Write to hello@sitefetti.com or select “Privacy and my data” in the contact form to request access, correction, deletion, restriction or portability, or to object where the relevant right applies. We may need to verify that the request concerns your data. Do not send identity documents before a secure method is agreed. You may complain to the Slovenian Information Commissioner (ip-rs.si) or your competent supervisory authority.