Privacy Policy

Last updated: April 1, 2026.

1. Introduction

Welcome to OliveBox, a scheduling and business management platform for salons, wellness centers, and service providers, operated by Mobi Mouse d.o.o., Stojana Protica 39, 11000 Belgrade, Serbia, PIB: 104122416 ("we", "us", or "our").

We value your privacy and are committed to protecting the personal data of our users and their clients. This Privacy Policy explains what information we collect, how we use it, and what rights you have regarding your data.

By using OliveBox.net, you agree to the terms of this Privacy Policy.

2. Who We Are

Data Controller:
Mobi Mouse d.o.o.
Stojana Protica 39, 11000 Belgrade, Serbia
PIB: 104122416
Email: support@olivebox.net
Website: www.olivebox.net

Mobi Mouse d.o.o. is responsible for processing your personal data in accordance with this Privacy Policy and applicable Serbian data protection laws (including the Law on Personal Data Protection, aligned with the General Data Protection Regulation — GDPR).

3. Data We Collect

We collect and process the following categories of data:

3.1. User (Business) Data

  • Company / salon name
  • Contact person's name and surname
  • Email address
  • Mobile phone number
  • Business address
  • Appointment history and related business data

3.2. End-Client Data (Collected by Users)

Our business users may collect limited information about their clients (e.g., salon customers), such as:

  • Client name and surname
  • Email address
  • Phone number
  • Appointment records

Business users are solely responsible for ensuring that their clients are informed about such data processing and that it complies with applicable laws.

4. Purpose and Legal Basis for Processing

We process data for the following purposes:

  • To register and manage business user accounts — Performance of contract
  • To provide and maintain the OliveBox services — Performance of contract
  • To communicate with users and provide support — Legitimate interest / Contract
  • To manage billing, subscriptions, and trial periods — Performance of contract
  • To secure, maintain, and improve our Service — Legitimate interest
  • To comply with legal obligations (e.g., tax, accounting) — Legal obligation

We do not use collected data for marketing, profiling, or advertising, and we do not share any user or client data with third parties for commercial purposes.

5. Data Storage and Security

All data is stored securely on servers hosted by Amazon Web Services (AWS) in Ireland (EU). We apply technical and organizational measures, including encryption, access control, and monitoring, to protect your data against unauthorized access, loss, or alteration.

We retain personal data only for as long as necessary to fulfill the purposes above, unless a longer retention period is required by law (e.g., accounting records).

6. Data Sharing and Third Parties

We do not share, sell, or rent any personal data with third parties.

Limited access to personal data may occur only in the following cases:

  • Service providers (e.g., AWS cloud hosting, SMS gateway) who act as data processors under our instructions and are bound by confidentiality and data protection obligations.
  • Legal obligations, if we are required by law, regulation, or court order to disclose data.

We do not transfer personal data outside the European Economic Area (EEA), except where necessary for service provision (e.g., AWS infrastructure).

7. Cookies and Analytics

Our website and applications use only essential cookies and technical logs required for proper functionality. We do not use analytics, advertising, or tracking cookies.

8. Your Rights

Under the GDPR and Serbian data protection law, you have the following rights:

  • Right to access your data
  • Right to rectification (correction)
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing
  • Right to lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection (Serbia)

To exercise your rights, contact us at support@olivebox.net.

9. Data of Minors

The Service is intended only for business users aged 18 or older. We do not knowingly collect or process data from minors.

10. Data Retention

We keep personal data:

  • For as long as your account is active
  • For 12 months after account deletion, unless otherwise required by law
  • Certain accounting records may be retained up to 10 years as required by Serbian legislation

After retention periods expire, data is securely deleted or anonymized.

11. Changes to This Policy

We may update this Privacy Policy from time to time. The latest version will always be available at www.olivebox.net/en/privacy/. If changes are significant, we will notify users via email or in-app notification.

12. Contact

For any questions, requests, or concerns regarding this Privacy Policy, please contact:

Mobi Mouse d.o.o.
Stojana Protica 39
11000 Belgrade, Serbia
PIB: 104122416
Email: support@olivebox.net
Website: www.olivebox.net