Last updated: January 6, 2026
This Privacy Policy explains how arthXcode d.o.o. ("we", "us", "our", "Company") collects, uses, shares, and protects your personal data when you use our mobile applications and related services (collectively, the "Service").
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and applicable Croatian data protection laws.
arthXcode d.o.o.
Podić 1, Brodarica
22000 Šibenik, Croatia
OIB: 07812992800
Email: support@xnow-one.com
Website: xnow-one.com
Depending on how you use the Service, we may collect:
| Purpose | Legal Basis (GDPR) |
|---|---|
| To create and manage your account | Contract performance (Art. 6(1)(b)) |
| To process and manage appointments | Contract performance (Art. 6(1)(b)) |
| To send appointment confirmations and reminders | Contract performance (Art. 6(1)(b)) |
| To send push notifications about your bookings | Consent (Art. 6(1)(a)) |
| To send email notifications (verification, password reset) | Contract performance (Art. 6(1)(b)) |
| To provide customer support | Legitimate interest (Art. 6(1)(f)) |
| To improve our services and fix bugs | Legitimate interest (Art. 6(1)(f)) |
| To comply with legal obligations | Legal obligation (Art. 6(1)(c)) |
We use the following third-party services to operate the Service:
| Service | Purpose | Location |
|---|---|---|
| MongoDB Atlas | Database hosting | EU (Ireland) / US |
| Firebase Cloud Messaging (Google) | Push notifications | EU / US |
| Cloudinary | Image storage | EU / US |
| Resend | Email delivery | US |
All service providers are bound by data processing agreements and are required to protect your data in accordance with GDPR.
When you book an appointment:
Some of our service providers are located outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place:
| Data Type | Retention Period |
|---|---|
| Account data | Until you delete your account |
| Appointment history | 3 years after the appointment date |
| Business data | Until the business account is deleted |
| Email verification tokens | 24 hours |
| Password reset tokens | 24 hours |
| Device tokens | Until you log out or uninstall the app |
As a data subject in the EU, you have the following rights:
To exercise any of these rights, contact us at support@xnow-one.com. We will respond within 30 days.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP):
Agencija za zaštitu osobnih podataka (AZOP)
Selska cesta 136, 10000 Zagreb, Croatia
Email: azop@azop.hr
Website: azop.hr
We implement appropriate technical and organizational measures to protect your data:
We use Firebase Cloud Messaging to send push notifications about:
You can disable push notifications at any time in your device settings. This will not affect other functionality of the Service.
The Service is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at support@xnow-one.com.
Our mobile applications do not use cookies. We do not use advertising trackers or analytics SDKs that track your behavior across apps.
We may update this Privacy Policy from time to time. When we make significant changes, we will:
We encourage you to review this Privacy Policy periodically.
If you have any questions about this Privacy Policy or our data practices, please contact us:
arthXcode d.o.o.
Podić 1, Brodarica
22000 Šibenik, Croatia
Email: support@xnow-one.com
Website: xnow-one.com
Data Protection Contact: For data protection inquiries, please email support@xnow-one.com with the subject line "Data Protection Request".