Privacy Policy
Last updated: March 13, 2026
1. Data Controller and Data Protection Officer
The data controller is JIK family s. r. o., with registered office at Voderadská 5031/4, 919 35 Hrnčiarovce nad Parnou, Slovak Republic, Company ID: 54402395, Tax ID: 2121653127, VAT ID: SK2121653127, registered in the Commercial Register of the District Court Trnava, Section: Sro, File No.: 50875/T (hereinafter "Wismeo" or the "Controller").
Data Protection Officer (DPO): For any questions regarding personal data protection, please contact us at dpo@wismeo.com. You may also direct all requests for exercising data subject rights (Section 8) to this address.
2. What personal data we process
The scope of processed data depends on how you use the service:
- Identification and contact data — name, surname and email address provided via your Google account during sign-in.
- Account and settings data — language, currency, system role, subscription status, referral code.
- Property data — name, address, purchase price, current value, mortgage details (amount, interest rate, balance, payment), monthly rent, expenses, insurance, taxes, tenant contracts.
- Portfolio financial data — forecasts, ROI, cash flow, capitalization rate, LTV; these are calculated locally from data you enter.
- Banking data (optional) — if you choose to connect a bank account via Enable Banking, we process transaction and balance data.
- Co-applicant data — name, personal ID, income and employer of co-applicants, if you voluntarily enter them in your profile.
- Technical and operational data — IP address, browser type, operating system, access logs, diagnostic records, device identifier.
- Cookies and analytics data — details in Section 7.
3. Legal basis and purpose of processing
We process personal data based on the following legal grounds under Art. 6(1) of Regulation (EU) 2016/679 (GDPR):
- Performance of a contract (Art. 6(1)(b) GDPR) — creating and managing user accounts, providing platform features (property records, financial calculations, forecasts, portfolio management), technical support, subscription processing.
- Consent (Art. 6(1)(a) GDPR) — analytics cookies (Google Analytics), connecting a bank account via Enable Banking, processing co-applicant data. You may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
- Legitimate interest of the Controller (Art. 6(1)(f) GDPR) — protecting systems against abuse, fraud and unauthorized access, security logging, bot prevention (reCAPTCHA), rate limiting, diagnostics and operational logs.
- Legal obligation (Art. 6(1)(c) GDPR) — fulfilling obligations under tax, accounting and other Slovak legal regulations.
4. Data recipients
Your personal data may be disclosed to the following categories of recipients, strictly to the extent necessary for service provision:
- Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) — authentication (Google Sign-In), cloud hosting and database (Firebase/Firestore), file storage (Firebase Storage), analytics (Google Analytics, consent-only), bot protection (reCAPTCHA v3).
- Stripe Technology Europe, Limited (1 Grand Canal Street Lower, Dublin 2, Ireland) — subscription payment processing.
- Enable Banking Oy (Finland) — bank account access intermediation (only if you choose to connect your bank account).
- Ambassadors and brokers — if you assign an ambassador or broker in the application, they have read access to selected portfolio and profile data. Assignment is voluntary and can be revoked at any time in profile settings.
- Public authorities — if required by law or a legally binding decision of a court or other authority.
5. International data transfers
Wismeo uses Google Cloud (Firebase) infrastructure. Firestore and Firebase Storage data is primarily stored in the europe-west (EU) region. Some Google support services (e.g. Google Analytics, Google Sign-In) may involve data transfers to the United States.
For transfers to the US, we rely on the European Commission adequacy decision under the EU-U.S. Data Privacy Framework (decision of July 10, 2023, C(2023) 4745). Google LLC is a certified participant of this framework.
Stripe and Enable Banking process data within the EU/EEA. If any transfer outside the EU/EEA occurs, it is safeguarded by Standard Contractual Clauses (SCCs) pursuant to Commission Decision (EU) 2021/914.
You may request a copy of the relevant transfer safeguards at dpo@wismeo.com.
6. Data retention periods
We retain personal data only for as long as necessary to fulfill the purpose for which it was collected:
- Account and portfolio data — for the duration of your account. After account deletion, data is erased within 30 days, except data we are legally required to retain.
- Billing and payment data — 10 years from the end of the year in which the transaction was made (Act No. 431/2002 Coll. on Accounting).
- Security logs and diagnostic records — maximum 12 months.
- Data processed based on consent — until consent is withdrawn. After withdrawal, data is erased without undue delay, within 30 days at the latest.
- Backups — automatic Firebase backups are retained for a maximum of 30 days after primary data deletion.
- Analytics data (Google Analytics) — retention period is set to 14 months; data is aggregated and IP addresses are anonymized.
7. Cookies and analytics
The Wismeo application uses the following categories of cookies and local storage:
- Essential (technical) — without consent: Firebase authentication session cookie, localStorage for language settings, currency, cookie banner state (gdpr_cookie_ack_v1). These are required for basic application functionality.
- Analytics — consent-only: Google Analytics (cookies _ga, _ga_*, validity 14 months) for measuring traffic and improving the service. IP addresses are anonymized. Analytics are activated only after explicit consent via the cookie banner.
- Security — without consent: reCAPTCHA v3 token for protection against automated attacks (legitimate interest of the Controller).
8. Your rights as a data subject
Under the GDPR and Act No. 18/2018 Coll. you have the following rights:
- Right of access (Art. 15 GDPR) — you have the right to obtain confirmation of whether your personal data is being processed and, if so, access to it.
- Right to rectification (Art. 16 GDPR) — you have the right to have inaccurate data corrected and incomplete data completed.
- Right to erasure (Art. 17 GDPR) — you have the right to have your data erased when the purpose of processing has ended, you withdraw consent or other conditions are met.
- Right to restriction (Art. 18 GDPR) — you have the right to request restriction of processing in legally defined cases.
- Right to data portability (Art. 20 GDPR) — you have the right to receive your data in a structured, commonly used and machine-readable format (JSON) and to transmit it to another controller.
- Right to object (Art. 21 GDPR) — you have the right to object to processing based on legitimate interest.
- Right to withdraw consent — if processing is based on consent, you have the right to withdraw it at any time.
- Right to lodge a complaint — you have the right to lodge a complaint with the supervisory authority: Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava, www.dataprotection.gov.sk.
9. How to exercise your rights
You may submit a request to exercise any of the above rights:
- by email to: dpo@wismeo.com,
- in writing to the Controller's registered office: JIK family s. r. o., Voderadská 5031/4, 919 35 Hrnčiarovce nad Parnou.
We will process your request without undue delay, within 30 days of receipt at the latest. In justified cases (complexity or number of requests) the deadline may be extended by a further 60 days, of which we will inform you. Exercising your rights is free of charge. In case of manifestly unfounded or repetitive requests we reserve the right to charge a reasonable fee or refuse the request.
10. Automated decision-making and profiling
The Wismeo application performs financial calculations (ROI, cash flow, forecasts, creditworthiness) solely as supporting information for your own decision-making. These calculations do not constitute automated decision-making with legal effects within the meaning of Art. 22 GDPR. Wismeo does not provide financial advice and does not make any decisions on your behalf.
11. Data security
We apply appropriate technical and organizational measures to protect your personal data pursuant to Art. 32 GDPR:
- encryption in transit (TLS/SSL) and at rest (AES-256, secured by Google Cloud infrastructure),
- authentication via Google Sign-In with Firebase Auth,
- Firestore Security Rules ensuring each user can only access their own data,
- protection against automated attacks via Firebase App Check and reCAPTCHA v3,
- rate limiting at the Cloud Functions level,
- regular security updates of dependencies.
12. Final provisions
The Controller reserves the right to update this document, especially in case of feature, legal or technical changes. Registered users will be notified of material changes via email or in-app notification at least 14 days before the change takes effect.
This document has been prepared in accordance with Regulation (EU) 2016/679 (GDPR), Act No. 18/2018 Coll. on Personal Data Protection, Act No. 351/2011 Coll. on Electronic Communications and Act No. 22/2004 Coll. on Electronic Commerce.