EnterwaitEnterwait
How it worksPlatformFeaturesPricingFAQBlog
Sign In Get started
Legal

Privacy Policy

Last updated: 10 May 2026·Enterwait d.o.o., registered in the Republic of Serbia

This Privacy Policy explains how Enterwait d.o.o. ("Enterwait", "we", "us" or "our") collects, uses, discloses and otherwise processes personal data when you visit our website at enterwait.com, when you create an Enterwait account, or when an Enterwait business customer (the "Customer") uses our Services to interact with you (an "End Customer"). It is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Serbian Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti), the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and other applicable privacy laws.

Terms of Service Privacy Policy Security Data Processing Agreement Sub-processors
On this page
  1. 1. Controller and Contact
  2. 2. Categories of Personal Data We Collect
  3. 3. Purposes and Legal Bases
  4. 4. Sharing and Sub-processors
  5. 5. International Transfers
  6. 6. Retention
  7. 7. Your Rights
  8. 8. Security
  9. 9. Children
  10. 10. Cookies and Similar Technologies
  11. 11. Changes to this Policy
Plain-language summary

The text below is the legally binding version. Where the headings or summaries we provide differ from the body of an article, the body controls. We've tried to use clear language wherever possible — if any clause confuses you, please contact us before agreeing.

1. Controller and Contact

Enterwait d.o.o., Knez Mihailova 12, 11000 Belgrade, Republic of Serbia, is the controller of personal data we collect about visitors to our website and people who sign up directly with Enterwait.

Where you are an End Customer interacting with the Services through one of our business customers (for example, you book an appointment with a salon or repair shop that uses Enterwait), that business is the controller of your personal data and Enterwait acts as a processor on its behalf. Please refer to that business's privacy notice for information about its processing.

You can reach our Data Protection Officer at dpo@enterwait.com.

↑ Back to top

2. Categories of Personal Data We Collect

We process the following categories of personal data, depending on how you interact with us:

  • Account data: name, email address, role, password (hashed), business affiliation;
  • Billing data: billing contact, VAT number, address, payment-method metadata (we do not store full card numbers — payments are processed by Lemon Squeezy);
  • Booking and queue data: appointment time, service requested, status updates, queue position, free-text notes you submit;
  • Communications: messages you send through our chat, support requests, survey responses;
  • Device and usage data: IP address, device identifiers, browser type, pages viewed, referrer, timestamps;
  • Marketing data: subscription preferences, click-through and open events for emails you receive from us;
  • Cookies and similar identifiers: as described in our Cookie section below.
↑ Back to top

3. Purposes and Legal Bases

We process personal data for the purposes and on the legal bases set out below.

  • To provide the Services, manage your account and fulfil our contract with you (Article 6(1)(b) GDPR);
  • To bill, collect payment and prevent fraud, on the basis of contractual necessity and legitimate interests (Article 6(1)(b) and 6(1)(f) GDPR);
  • To communicate with you about the Services, including security alerts, transactional emails and customer support, on the basis of contractual necessity and legitimate interests;
  • To send marketing communications, where you have consented or where permitted under soft opt-in rules (Article 6(1)(a) and 6(1)(f) GDPR);
  • To improve the Services, debug, monitor performance and develop new features, on the basis of legitimate interests;
  • To comply with legal obligations, including tax, accounting and law-enforcement requests (Article 6(1)(c) GDPR);
  • To establish, exercise or defend legal claims (Article 6(1)(f) GDPR).
↑ Back to top

4. Sharing and Sub-processors

We share personal data only as necessary to operate the Services and only with parties subject to appropriate confidentiality and data-protection obligations. The categories of recipients include:

The full list, with what each provider processes and where, is published on the Sub-processors page (/legal/subprocessors).

  • The provider that hosts the Services: Hetzner Online GmbH, on servers in Germany (EU);
  • The payment provider Lemon Squeezy, which sells the subscription as Merchant of Record, processes card payments and handles tax;
  • The email delivery service (Brevo) used to send confirmations and notifications. SMS messages to End Customers are sent from the business's own phone, not by a provider of ours;
  • Push-notification delivery (Google Firebase Cloud Messaging) and error monitoring (Sentry);
  • The chat widget on our public website (Tawk.to), only if you accept the corresponding cookies;
  • The AI provider (Anthropic) that processes a menu or price list you upload when you ask the Services to create services or forms from it;
  • Professional advisers and authorities where required by law.
↑ Back to top

5. International Transfers

Our primary infrastructure is located in the European Union. Some of our sub-processors are based in countries outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on adequacy decisions where available and on the European Commission's Standard Contractual Clauses, supplemented by appropriate additional safeguards (such as encryption and access controls) where required following a transfer impact assessment.

↑ Back to top

6. Retention

We retain personal data only for as long as necessary for the purposes described in this Policy. Account and billing data are retained for the duration of the contract and for the period required by tax and accounting laws (typically up to ten (10) years in Serbia). Booking and queue data are retained for as long as the Customer's Account is active and for a reasonable period thereafter to allow recovery and audit, after which they are deleted or anonymised in accordance with our retention schedule and the DPA.

↑ Back to top

7. Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

  • Access — to obtain confirmation of whether we process your personal data and a copy of it;
  • Rectification — to correct inaccurate or incomplete personal data;
  • Erasure — to have personal data deleted in certain circumstances;
  • Restriction — to restrict processing in certain circumstances;
  • Portability — to receive personal data in a structured, machine-readable format and to have it transmitted to another controller where technically feasible;
  • Objection — to object to processing based on legitimate interests, including profiling for direct marketing;
  • Withdrawal of consent — where processing is based on consent, you can withdraw it at any time;
  • Complaint — to lodge a complaint with the Serbian Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs) or another competent supervisory authority.

California residents have additional rights under the CCPA, including the right to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information. We do not sell personal information for monetary consideration.

↑ Back to top

8. Security

We maintain technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. A non-exhaustive description of these measures is set out in our Security page and in Annex 2 to the DPA.

↑ Back to top

9. Children

The Services are not directed to children under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.

↑ Back to top

10. Cookies and Similar Technologies

We use strictly necessary cookies to operate the Services, plus a limited set of analytics and preference cookies that you can manage through our cookie banner. We do not use advertising cookies on the Customer-facing tracking pages.

↑ Back to top

11. Changes to this Policy

We may update this Policy to reflect changes in our practices or in applicable law. The "Last updated" date at the top of this Policy reflects the date of the most recent revision. We will notify you of material changes by email or through the Services.

↑ Back to top

Questions about this document?

Our legal team is happy to help. Reach out to us if you need clarification, want to negotiate a custom agreement, or are filing a request under your data-protection rights.

  • Email:legal@enterwait.com
  • Data Protection Officer:dpo@enterwait.com
  • Postal address: Enterwait d.o.o., Knez Mihailova 12, 11000 Belgrade, Serbia
  • Registered entity: Enterwait d.o.o., registered in the Republic of Serbia
Related documents
  • Terms of Service
  • Security
  • Data Processing Agreement
  • Sub-processors
EnterwaitEnterwait

The platform that turns waiting into clarity. Built in Belgrade, made for service businesses everywhere.

Product
  • Get started
  • Sign in
  • Blog
For business
  • Dashboard
  • Form builder
  • Analytics
  • Embed widget
Company
  • Pricing
  • Blog
  • Contact
Legal
  • Terms
  • Privacy
  • Security
  • DPA
  • Sub-processors

© 2026 Enterwait d.o.o. · All rights reserved.