Privacy Policy
This Privacy Policy ("Policy") explains how Fiveset d.o.o. ("Fiveset," "we," "us," or "our") collects, uses, processes, and protects personal data when you access and use the Treax mobile application, website, and related services (collectively, the "Service").
We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR").
By creating an account, accessing, or using the Service, you acknowledge that you have read and understood this Policy.
Table of Contents
1. Data Controller
For the purposes of the GDPR, the data controller is:
Fiveset d.o.o.
TRG SUNCA BR.4, KANCELARIJA BR.24
85310 BUDVA
MONTENEGRO
info@fiveset.io
If you have questions regarding this Policy or your personal data, you may contact us at the above address or via email at info@fiveset.io.
Top2. Categories of Personal Data Collected
We collect and process the following categories of personal data, depending on your interaction with the Service:
Identification Data: name, date of birth, username, account details.
Contact Data: email address, telephone number, postal address.
Financial Data: income, expenses, bank account details, budgets, transactions (if inputted by you).
Technical Data: device identifiers, IP address, operating system, browser type, app usage statistics, crash reports.
Subscription and Payment Data: billing address, payment method details (processed via secure third-party providers), subscription plan type, invoices.
Profile Data: preferences, saved settings, account activity.
Communications Data: messages, support requests, survey responses, and other communications with us.
Derived or Analytical Data: insights generated by TreaxAI, anonymized usage data, aggregated statistics.
We do not intentionally collect sensitive personal data (e.g., health data, political opinions) unless explicitly provided by you for purposes consistent with the Service.
Top3. Purposes and Legal Bases of Processing
We process your personal data only where there is a valid legal basis under Article 6 of the GDPR. Specifically:
Performance of Contract (Art. 6(1)(b) GDPR)
To provide access to the Service (Free Plan or Subscription Plan).
To process payments, billing, and account management.
To deliver insights, reporting, and financial management tools.
Legitimate Interests (Art. 6(1)(f) GDPR)
To improve, optimize, and secure the Service.
To prevent fraud, misuse, or unauthorized access.
To analyze anonymized usage data for product development.
To communicate important updates about the Service.
Consent (Art. 6(1)(a) GDPR)
For optional marketing communications.
For the use of cookies, analytics, and tracking technologies.
For processing sensitive or special categories of data where applicable.
Legal Obligations (Art. 6(1)(c) GDPR)
To comply with applicable laws, tax, and regulatory reporting obligations.
To respond to lawful requests from authorities.
Top4. Data Retention
We will retain your personal data only for as long as necessary to fulfill the purposes set forth in this Policy, and thereafter as required by law. Retention periods include:
Account Data: retained for the lifetime of your account, and deleted within 90 days following account closure.
Financial Data: retained for up to 10 years to comply with tax, accounting, and regulatory obligations.
Technical and Analytics Data: retained up to 24 months in anonymized or aggregated form.
Marketing Data: retained until you withdraw consent or opt out.
Top5. Disclosure of Data to Third Parties
We may share your personal data with the following categories of recipients:
Service Providers: trusted third parties who process data on our behalf (e.g., cloud hosting, payment processors, analytics providers). Such providers are bound by contractual obligations ensuring compliance with GDPR.
Professional Advisors: legal, tax, or accounting advisors where necessary for our business.
Authorities and Regulators: where required by law, regulation, or judicial order.
Business Transfers: in the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the business.
We do not sell personal data to third parties.
Top6. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), we ensure that such transfers are made in compliance with GDPR, using appropriate safeguards such as:
The European Commission's Standard Contractual Clauses (SCCs);
Adequacy decisions for certain jurisdictions;
Binding Corporate Rules (BCRs), where applicable.
Top7. Data Subject Rights
Under GDPR, you have the following rights regarding your personal data:
Right of Access (Art. 15 GDPR) - to obtain confirmation of whether we process your data and access to such data.
Right to Rectification (Art. 16 GDPR) - to correct inaccurate or incomplete data.
Right to Erasure (Art. 17 GDPR) - to request deletion of your data ("right to be forgotten").
Right to Restriction of Processing (Art. 18 GDPR) - to limit how we use your data.
Right to Data Portability (Art. 20 GDPR) - to receive your data in a structured, commonly used, and machine-readable format and transfer it to another controller.
Right to Object (Art. 21 GDPR) - to object to processing based on legitimate interests or direct marketing.
Right to Withdraw Consent (Art. 7(3) GDPR) - where processing is based on consent, you may withdraw it at any time.
Right to Lodge a Complaint (Art. 77 GDPR) - to file a complaint with your local supervisory authority, such as the Information Commissioner's Office in Slovenia or your national data protection authority.
Requests to exercise your rights may be submitted to info@fiveset.io. We will respond within the statutory deadlines set forth under GDPR.
Top8. Security of Data
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Data encryption (in transit and at rest).
Secure authentication and access controls.
Regular system monitoring, logging, and intrusion detection.
Data minimization and pseudonymization where appropriate.
However, no system is entirely secure, and we cannot guarantee absolute security against unauthorized access, alteration, or destruction of data beyond our reasonable control.
Top10. Automated Decision-Making and Profiling
TreaxAI may use automated processing and profiling to generate insights and recommendations based on the data you provide. Such processing is limited to informational and educational purposes only and does not produce legal or similarly significant effects.
You have the right to request human intervention, express your point of view, and contest such automated processing under Article 22 GDPR.
Top11. Children's Privacy
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If we learn that we have collected such data, we will delete it promptly.
Top12. Changes to this Policy
We reserve the right to amend this Policy at any time. Material changes will be communicated via the Service or by email prior to becoming effective. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
Top13. Contact Information
If you have questions, concerns, or requests relating to this Policy or your personal data, please contact:
Fiveset d.o.o.
TRG SUNCA BR.4, KANCELARIJA BR.24
85310 BUDVA
MONTENEGRO
info@fiveset.io