1. Our processing roles
This notice explains how Temelj za rast processes data on the public Butiga CRM website, during sales and support, when managing user accounts and through the Butiga service itself.
Temelj za rast is the data controller when it determines why and how data is processed about website visitors, demo contacts, contractual and billing contacts, account administrators, support users and service security.
The customer is the controller and Temelj za rast is the processor for leads, contacts, email messages, quotes, tasks, attachments and other business content the customer or its users enter, connect or synchronise in their workspace. We process that content under the customer's documented instructions, the contract and applicable law. The customer decides what data to enter, whom to authorise and how long to retain it.
If you use Butiga through your employer or another organisation, contact that organisation's administrator first with workspace-content questions. We will support their request under the data processing agreement.
2. Data we process
Data from the public website and sales relationship
- full name, business email, phone, role and organisation name;
- content of demo, contact, partnership and sales enquiries;
- quote, contract, billing, payment and business communication data;
- cookie choices and limited technical data needed for secure website operation.
Account and service usage data
- user identity, business email address, workspace membership, role and permissions;
- sign-in, device, application, event time, IP address and security-log data when needed for authentication, protection and investigation;
- support requests, diagnostic data and feedback;
- Android app version, synchronisation and error data needed to operate features and resolve faults.\n
- views of the controlled quote room and, when a recipient confirms a decision, their name, email, decision and optional note.
Customer content
Depending on usage, Butiga may process leads and contacts, companies, record owners, email messages and attachments, meetings, tasks, deadlines, pipeline stages, quotes, price lists, internal notes and handover. Customers should not enter special categories of data or other sensitive data unless genuinely necessary, lawful and agreed.
\nWhen the customer enables a controlled quote room, the recipient may open the current quote and confirm acceptance or rejection. Butiga processes the technical viewing event and the information the recipient explicitly submits with their decision. The customer determines the purpose, recipient and availability period; recipients should contact that customer about the business decision or quote content.
Data sources
We receive data directly from you, from the organisation providing your account, through integrations connected by an authorised user, from business communication with us and automatically from limited service technical logs. We do not sell personal data.
3. Purposes and legal bases
| Purpose | Typical legal basis |
|---|---|
| Responding to enquiries, demos, quotes and entering contracts | Pre-contractual steps, contractual performance and legitimate business interests |
| Account creation, feature delivery, synchronisation and support | Contractual performance; documented controller instructions for customer content |
| Billing, taxes, records and complying with authorities' requests | Legal obligations and contractual performance |
| Security, abuse prevention, audit and incident handling | Legitimate interest, contractual obligation and legal obligation where applicable |
| Improving reliability and user experience | Legitimate interest with data minimisation; consent where required |
| Optional website analytics and embedded media | Consent that you can withdraw through the cookie controls |
| Relevant updates for existing business contacts | Legitimate interest or consent, with an easy opt-out and compliance with specific direct marketing rules |
When relying on legitimate interest, we assess the purpose, necessity and impact on your rights. You may object to this processing.
4. Business email and connected integrations
Butiga supports authorised IMAP/SMTP accounts and Gmail OAuth. When an administrator or authorised user connects an account, the service may process sender and recipient addresses, subjects, message content, signatures, folders, statuses, attachments and technical data needed for synchronisation and sending.
The customer is responsible for having the right to connect the account, informing users and business contacts where required, and defining the permitted scope of access. Credentials and OAuth tokens are used only to perform the connected function, are stored in a protected form and are not used for advertising. The independent email provider's rules continue to apply to its part of the service.
5. Recipients and subprocessors
Data is accessed only by authorised members of Temelj za rast who need access for sales, service delivery, support, finance, security or legal obligations and who are subject to confidentiality duties.
We may engage vetted providers of infrastructure, hosting and storage, email delivery, reliability monitoring, support, billing or professional services. They receive only the data needed for their task and are bound by contractual protection obligations. An up-to-date list of relevant subprocessors, processing locations and functions is available to contracted customers on request. We notify customers of planned replacements or additions of subprocessors processing customer content in accordance with the DPA and allow reasonable objections based on data protection.
We may disclose data to a competent authority where legally required, to protect rights and safety, or in connection with a corporate change, subject to appropriate confidentiality safeguards and continuity of protection.
6. International transfers
Data may be processed outside your country where required by a selected integration or an engaged provider. In that case, we apply contractual and other appropriate safeguards required by applicable law, including standard contractual clauses where necessary. The customer is responsible for the lawfulness of transfers it initiates by choosing an integration or data recipient.
7. Retention periods
- Enquiry and sales data: for the duration of communication and a reasonable period afterwards to follow up on the relationship, unless you request deletion or there is a legal reason for longer retention.
- Contractual and financial data: throughout the business relationship and for periods required by tax, accounting and other regulations.
- Account and security records: while the account is active and for a limited period after termination, according to security purposes, dispute resolution and statutory time limits.
- Customer content: during the contract and the agreed period for export, return or deletion. Remaining copies in backup systems are removed through a regular, controlled cycle, unless retention is required by law.
- Marketing records: until opt-out or objection; a minimal opt-out record may be retained to honour that choice.
- Cookie choices: according to the periods stated in the Cookie Policy.
We apply criteria relating to the purpose, volume and sensitivity of data, contract duration, risks, statutory time limits and the need to establish or defend legal claims. When data is no longer needed, we delete it, anonymise it or restrict access.
8. Your rights
Depending on applicable law and our role, you may request access, a copy, correction, deletion, restriction of processing, portability, withdrawal of consent, or object. Withdrawing consent does not affect the lawfulness of earlier processing.
Send your request to contact@temelj.me. We may request reasonable verification of identity and authority. If the request concerns content in a workspace managed by our customer, we will forward it to the appropriate administrator or act on their instructions.
You have the right to lodge a complaint with Montenegro's Agency for Personal Data Protection and Free Access to Information, Bulevar Revolucije 11, Podgorica, azlp@azlp.me, or another competent authority where applicable. We would appreciate the opportunity to resolve the issue directly first.
9. Security and incidents
We use technical and organisational measures appropriate to the risk: separate workspace boundaries, memberships, roles and permissions, backend access checks, PostgreSQL Row-Level Security, protection of email credentials and OAuth tokens, auditing of sensitive actions, rate limiting, service monitoring, backups and controlled rollback procedures.
No system is entirely risk-free. We do not guarantee absolute security, but maintain a reasonable protection and response programme. If we confirm an incident affecting customer content, we notify the relevant customer without undue delay and provide information needed for their legal obligations.
10. Children, automation and changes
Butiga is a B2B service and is not intended for children. We do not knowingly seek data from people under 18 through the public website or for opening a business account.
Butiga does not make decisions producing legal or similarly significant effects solely through automated processing on behalf of Temelj za rast. The customer is responsible for decisions made using data and reports from its workspace.
We may change this notice when the service, processing practices or regulations change. Material changes will be marked with a new date and, where reasonable, active customers will be notified through their account or business contact. Earlier versions may be requested by email.
Relevant sources
Regulations of Montenegro's Personal Data Protection Agency and EU General Data Protection Regulation, where applicable.