Privacy policy

Last updated: 25 July 2026.

1. Data controller

The data controller is Talia, the owner and provider of the platform. Name: Talia Address: adresa Tax ID (PIB): pib Company number: matični broj Contact: info@booktalia.com We process data in line with the Serbian Personal Data Protection Act (ZZPL). For any privacy question or to exercise your rights, write to the contact address above.

2. What data we process

Account: name, email address, password (stored only as a hash), optionally phone and language. Appointments: venue, service, time and status. Technical data: logs necessary for the operation and security of the platform.

3. Why we process it

We process data to provide the service (booking and managing appointments), to send appointment notifications (confirmation, cancellation, reminders), for platform security and legal obligations. Marketing messages are sent only with explicit consent, which you can withdraw at any time.

4. Who else sees the data

The venue you book with sees your name, your appointment history with them and your reliability score. Notes a venue keeps about clients are private to that venue and are not shared with other venues. Processing relies on trusted infrastructure providers (hosting, database, email delivery) bound by data processing agreements. With your analytics consent, visit statistics are processed by PostHog (servers in the European Union) — without your name, email address or appointment details; see the Cookie Policy for specifics.

5. How long we keep data

Account data is kept for as long as the account exists. You can delete the account yourself at any time under “My account” → “Delete account”. Deletion permanently anonymises your name, email address and phone number and sign-in is no longer possible; a linked Google account and saved venues are removed, and upcoming appointments are cancelled with a notice to the venue. Appointment history stays with the venue as its business record, but without your personal data. The record of when notification consent was given and withdrawn is kept even after deletion — ZZPL requires proof of consent. Logs are kept only as long as security requires.

6. Your rights

Under ZZPL you have the right to access, rectification, erasure, restriction of processing, data portability and objection. You can delete your account and withdraw notification consent yourself at any time under “My account”; for the other rights write to the contact address in section 1 and we will reply within 30 days at the latest. You also have the right to lodge a complaint with the Serbian Commissioner for Information of Public Importance and Personal Data Protection.