Voziko Platform Privacy Policy
Last updated: 2026-06-26
1. Who we are
This platform is operated by Polemarhi d.o.o. ("Voziko", "we"), Vojvode Mišića 46, 35250 Paraćin, Serbia, PIB 112505565. Contact: [email protected].
For the data described here, we are the data controller — this covers only the people and records of running the platform business: taxi-company account and admin users, billing, support, sales contacts, and security/technical logs.
Separately, when we process riders' data AND drivers' personal data on a taxi company's behalf, we act as that company's processor, not controller — the taxi company is the controller of both. That processing is governed by our Data Processing Agreement and described in each company's Privacy Policy and Driver Privacy Notice; it is not covered by this policy.
2. Whose data this covers, and what we collect
This policy covers the data for which Voziko is the controller:
Taxi companies (account/admin users): company legal name, address, registration/tax number, contact email and phone, and the account login.
Billing: subscription and payment records for the taxi company's use of the platform.
Support and sales: messages, tickets and contact details when a company or prospect contacts us.
Security/technical logs: technical data such as IP address and device/browser info for account users, used to run, secure and troubleshoot the service (held in logs).
Directory visitors (near-me search): if a visitor to the public directory uses "find taxis near me", the browser sends approximate coordinates to Voziko to find nearby companies; we reverse-geocode them to a city via our map provider and store only city-level information, never the precise coordinates.
Not covered here (we are only the processor): drivers' personal data and riders' data. The taxi company is the controller of both; we process them solely on the company's instructions under the Data Processing Agreement. Driver data is described in the company's Driver Privacy Notice; rider data in the company's Privacy Policy.
3. Why we use it, and our legal basis
- To provide and operate the platform for you — performance of our contract with you.
- To keep the service secure, prevent abuse, and troubleshoot — our legitimate interest.
- To meet legal and accounting obligations — legal obligation.
We do not use this data for advertising, and the platform contains no analytics or tracking.
4. Who we share it with (sub-processors)
We use these providers to run the service; they process data only on our behalf. The current list — with purpose, data received, region, and whether your browser contacts each one directly — is published on the Voziko Sub-processor List page. In summary:
- Supabase — purpose: database, accounts, real-time. Data: account/login data. Region: EU (Frankfurt). Direct browser contact: no.
- Railway — purpose: application hosting. Data: requests in transit; logs may include IP. Region: EU (Amsterdam, Netherlands). Direct browser contact: no.
- Cloudflare — purpose: DNS, security, content delivery. Data: all requests and IP. Region: global edge. Direct browser contact: yes.
- Brevo — purpose: transactional email (e.g. password resets). Data: recipient email. Region: EU (France). Direct browser contact: no.
- Geoapify — purpose: geocoding (address ↔ location). Data: search text/coordinates. Region: EU. Direct browser contact: no.
- OpenFreeMap — purpose: map tiles. Data: map area (tiles fetched by our server; IP not sent). Region: EU (Netherlands). Direct browser contact: no.
- Business transfers — if Voziko's business is involved in a merger, acquisition or sale of assets, the data covered by this policy may be transferred to the counterparty, which must continue to protect it as described here.
We disclose data to authorities only where legally required.
5. Storage location and transfers
Your data is stored in the EU (Frankfurt), and all sub-processors above process data in the EU (Cloudflare operates a global edge network and may route requests through the nearest location). Under the Serbian Personal Data Protection Act, transfers to countries with an adequate level of protection are permitted; EU countries are treated as adequate, so no transfer outside the EU/adequacy area is required for storage.
6. How long we keep it
Account data is kept while your account is active and for up to 12 months afterwards; accounting, tax and e-invoice records are kept for up to 10 years, as required by Serbian law.
7. Your rights
You can access, correct, delete, restrict, object to, or receive a copy of your data — contact [email protected]. You may also complain to your country's data-protection authority (in Serbia, the Commissioner / Poverenik, www.poverenik.rs).
8. Changes
We may update this policy; the "last updated" date shows the current version.