Carely d.o.o. Privacy Statement

Effective as of June, 28th , 2025

At Carely, trust is our value. This Privacy Statement describes how Carely collects, uses, shares or otherwise processes information relating to individuals (“Personal Data”) in its capacity as data controller and the rights associated with that processing. 

Terms of data processing in our capacity as data processor as set forth in valid data processing agreement which accompany Our Platform Engagement Platform Subscription Agreement.

1. Data Controller

Carely Digital d.o.o., Tehnološki park 21, 1000 Ljubljana (“Carely, “we”, “us”, or the “Company”) is responsible for the processing of your Personal Data as described in this Privacy Statement, unless specified otherwise, and act as the controller of such Personal Data. 

This Privacy Statement does not apply to the extent we process Personal Data in the role of a data processor or service provider on behalf of our customers.

2. Processing Activities Covered

This Privacy Statement applies to the processing of Personal Data collected by us when you:

Our websites and services may contain links to other websites, applications, platforms and services maintained by third parties. The information practices of these third parties, including the social media platforms that host our branded social media pages, are governed by their privacy statements, which you should review to better understand their privacy practices

In some circumstances, we also collect, or our partners provide us with, publicly available information which may contain Personal Data that you have published or that has been made available online. The way in which our partners collect this is detailed in their own privacy policies, available on their websites.

3. What Personal Data Do We Collect?

3.1 Personal Data We Collect Directly from You

The Personal Data we collect directly from you may include identifiers, professional or employment-related information, financial account information, commercial information, visual information, and internet activity information, among others. We may collect such information in the following situations:

SituationsCategories of Personal Data
If you express an interest in obtaining additional information about our services; request customer support; use our “Contact Us” or similar features; register to use our websites or to receive communications; sign up for an event, webinar or contest; participate in a program, training, certification or survey; use our products and services; download certain content; or are employed by a customer of our products and services where your information has been shared with usContact information, such as your name, job title, company name, address, phone number, email address, username and password, other information you have voluntarily chosen to share
If you make purchases via our websites or otherwise or register for an event or webinarContact information, financial and billing information, such as billing name and address, credit card number or bank account information
If you attend an eventAttendee badge information which may include name, title, company name, address, country, phone number and email address, image and video
If you register with us for a variety of purposes, including joining a community that we host or participating in a program, training or certificationUsername, photo, video or other biographical information, such as your occupation, location, social media profiles or usernames, company name, areas of expertise and interests
If you interact with our websites or emailsInformation about your device and your usage of our websites or emails (such as Internet Protocol (IP) addresses or other identifiers), which may qualify as Personal Data (please see Section 4 below) using cookies, web beacons, or similar technologies
If you use and interact with our products and servicesInformation about your device and your usage of our services through log files and other technologies, some of which may qualify as Personal Data (including Usage Data) (please see Section 4 below)
If you communicate with us via a phone callInformation such as your name, voice and any other Personal Data you voluntarily share
If you visit our officesName, email address, phone number, company name, time and date of arrival, image or video
If you voluntarily submit certain information to us, such as filling out a survey, responding to a questionnaire or participating in other forms of researchInformation you have provided as part of that request, which may include Personal Data and special categories of Personal Data, to the extent you voluntarily choose to provide it
If you are a supplier or service provider to Carely (or work for a supplier or service provider)Contact information, payment and billing information

If you provide us or our service providers with any Personal Data relating to other individuals, you represent that you have the authority to do so, and where required, have obtained the necessary consent, and acknowledge that it may be used in accordance with this Privacy Statement. If you believe that your Personal Data has been provided to us improperly, or want to exercise your rights relating to your Personal Data, please contact us by using the information in Section 13 below.

3.2 Personal Data We Collect from Other Sources

We also collect information about you from other sources including partners from whom we collect or purchase Personal Data or who provide us with publicly available information which may contain Personal Data. We may combine this information with Personal Data provided by you.

Advertising: The Personal Data we collect from other sources for the purposes of tailored advertising includes identifiers, professional or employment-related information, education information, commercial information, visual information, internet activity information, and inferences about preferences and behaviors. We, collect this from third party providers of business contact information, including mailing addresses, job titles, email addresses, phone numbers, intent data (or user behavior data), IP addresses, social media profiles, LinkedIn URLs and custom profiles for purposes of targeted advertising, delivering relevant email content, event promotion and profiling, determining eligibility and verifying contact information. This helps us update, expand, and analyze our records, identify new customers, and create more tailored advertising to provide services that may be of interest to you.

Additional sources: In addition to the aforementioned, we collect Personal Data from the following sources:

4. What Device and Usage Data Do We Process?

We use common information-gathering tools, such as cookies, web beacons, pixels, and similar technologies to collect information that may contain Personal Data as you navigate our websites, our services, or interact with emails we have sent to you.

4.1 Device and Usage Data

As is true of most websites, we gather certain device information when individual users visit our websites. This information may include identifiers, commercial information, and internet activity information such as IP address (or proxy server information), device and application information, identification numbers and features, location, browser type, plug-ins, integrations, Internet service provider, mobile carrier, the pages and files viewed, searches, referring website, app or ad, operating system, system configuration information, advertising and language preferences, date and time stamps associated with your usage, and frequency of visits to the websites. This information is used for the purposes set out in section 5 of this Privacy Statement below.

In addition, we gather certain information as part of your use of our products and services (“Usage Data”). This information may include: (i) identifiers, such as user ID, organization ID, username, email address and user type; (ii) commercial information; and (iii) internet activity information such as IP address (or proxy server), mobile device number, device and application identification numbers, location, language, browser type, Internet service provider or mobile carrier, user interactions such as the pages and files viewed, website and webpage interactions including searches and other actions you take, operating system type and version, system configuration information, date and time stamps associated with your usage and details of which of our products and product versions you are using. This information is used for the purposes set out in detail in section 5 of this Privacy Statement below. In addition, we may use aggregated Usage Data for other internal business purposes, such as to identify additional customer opportunities and to ensure that we are meeting the demands of our customers and their users. Please note that this Usage Data is primarily used to identify the uniqueness of each user logging on (as opposed to specific individuals), apart from where it is strictly required to identify an individual for security purposes or as required as part of our provision of the services to our customers. 

4.2 Cookies, Web Beacons and Other Tracking Technologies on Our Website and in Email Communications

We use technologies such as web beacons, pixels, tags, and JavaScript, alone or in conjunction with cookies, to gather information about the use of our websites and how people interact with our emails.

When you visit our websites, we, or an authorized third party, may place a cookie on your device that collects information, including Personal Data, about your online activities over time and across different sites. Cookies allow us to track use, infer browsing preferences, and improve and customize your browsing experience.

We use both session-based and persistent cookies on our websites. Session-based cookies exist only during a single session and disappear from your device when you close your browser or turn off the device. Persistent cookies remain on your device after you close your browser or turn your device off. To change your cookie settings and preferences for one of our websites, click the Cookie Preferences link in the footer of the page. You can also control the use of cookies on your device, but choosing to disable cookies on your device may limit your ability to use some features on our websites and services.

We also use web beacons and pixels on our websites and in emails. For example, we may place a pixel in a marketing email that notifies us when you click on a link in the email. We use these technologies to operate and improve our websites and marketing emails. For more details, please see the “Advertising Cookies” row in the table below. For instructions on how to unsubscribe from our marketing emails, please see Section 10.4 below.

The following describes how we use different categories of cookies and similar technologies and your options for managing the data collection settings of these technologies:

Type of CookiesDescriptionManaging Settings
Functional cookies
_sp_id.<unique_id>Private tracker unique user id. Generated by a new visit to the client’s websiteConsent is required
_sp_ses.<unique_id>Private tracker user session id. Generated by a new visit to the client’s websiteConsent is required
spPrivate tracker unique user id generated by the tracker backend software. Generated by the first user activity on the client’s website.Consent is required

4.3 Opt-Out from the Setting of Cookies on Your Individual Browser

In many cases you may opt-out from the collection of non-essential device data on your web browser (see Section 4.1 above) by managing your cookies at the browser or device level.

5. Purposes for Which We Process Personal Data and the Legal Bases on Which We Rely

We collect and process your Personal Data for the following purposes and relying on the following legal bases:

PurposeDescriptionLegal Basis
Providing our websites (including our social media pages)We process your Personal Data to operate and administer our websites and to provide you with the content you access and requestOur legitimate interest in providing online content to our customers and prospective customers regarding our service offering and related information
Improving our websitesWe process your Personal Data to analyze overall trends and help us improve the user experience on our websitesOur legitimate interest in providing a relevant and well-functioning website for the benefit of our website visitors
Promoting the security of our websitesWe process your Personal Data by tracking use of our websites and verifying and investigating activityOur legitimate interest in promoting the safety and security of our websites and in protecting our rights and the rights of others
Displaying personalized advertisements and contentWe process your Personal Data to conduct market research, advertise to you, provide personalized information about us on and off our websites and to provide other personalized content based upon your activities and interestsYour consent and our legitimate interest in advertising our products and services or, where necessary
Registering visitorsWe process your Personal Data, including registration information and associated non-disclosure information, for security reasonsOur legitimate interest in protecting our offices, staff, visitors and our confidential information against unauthorized access
Managing event registrations and attendanceWe process your Personal Data to plan and host events or webinars for which you have registered or that you attend, including sending related communications to you. Where you explicitly consent, we also may process your biometric Personal Data to facilitate event registration and for security reasonsPerformance of a contract or where we receive your explicit consent
Sending communicationsWe process your Personal Data to send you marketing information, product recommendations and other non-transactional communications (e.g., marketing newsletters, telemarketing calls, SMS or push notifications, information about our products, news or events) about us, our affiliates and partnersYour prior consent
Handling contact and user support requestsWe process your Personal Data, if you fill out a “Contact Me” web form or request user support, or if you contact us by other means including but not limited to via phoneNecessary for the performance of a contract or our legitimate interest in fulfilling your requests and communicating with you
Providing our servicesWe process your Personal Data to perform our contract with you for the provision of our services and to satisfy our obligations under the applicable terms of useNecessary for the performance of a contract or our legitimate interest to provide and administer our services
Managing our customer and user accountsWe process your Personal Data (including Usage Data) to manage customer and user accounts generally, such as billing, customer correspondence and customer relationship managementNecessary for the performance of a contract or our legitimate interest in the management of customer and user accounts
Managing usage and licensing complianceWe process your Personal Data (including Usage Data) to assess and manage usage and licensing compliance with the applicable terms of use of our servicesNecessary for the performance of a contract or our legitimate interest in managing the provision of our services to customers
Preparing internal reports and business modelingWe process your Personal Data (including Usage Data) for internal reporting and business modeling purposes (e.g., forecasting, revenue, capacity planning, product strategy)Our legitimate interest in the management of our business operations
Maintaining our securityWe process your Personal Data (including your Usage Data) for the purposes of maintaining Carely’s own security, including investigating, detecting and preventing suspicious activity, fraud and cybercrime that may affect Carely or its servicesOur legitimate interest in promoting the safety and security of Carely generally and to protect our rights and the rights of others
Aggregating dataWe process your Personal Data (including your Usage Data) for the purposes of aggregating this information to ensure that it is no longer identifyingOur legitimate interest in minimizing the amount of Personal Data processed as part of the noted processing activity
Managing, and participating in, webinars, contests, programs, training, certifications or promotionsWe process your Personal Data if you register for a webinar, contest, promotion, training, certification or a program. In some cases where the training or certification is through your employer, we will share your Personal Data with your employer. Some webinars, contests, programs, trainings, certifications and promotions have additional rules containing information about how we will process your Personal DataConsent, necessary for the performance of a contract or our legitimate interest in providing the webinar, contest, promotion, training, certification or promotion
Managing paymentsIf you have provided financial information to us, we process your Personal Data to verify that information and to collect payments to the extent that doing so is necessary to complete a transaction and perform our contract with youNecessary for the performance of a contract
Complying with legal obligationsWe process your Personal Data (including Usage Data) when cooperating with public and government authorities, courts or regulators in accordance with our legal obligations under applicable laws to the extent this requires the processing or disclosure of Personal Data to protect our rightsLegal obligation or our legitimate interest in protecting against misuse or abuse of our websites or services, protecting personal property or safety, pursuing remedies available to us and limiting our damages, complying with judicial proceedings, court orders or legal processes, responding to lawful requests, or for auditing purposes

If we need to collect and process Personal Data by law, or under a contract we have entered into with you, and you fail to provide the required Personal Data when requested, we may not be able to perform our contract with you.

6. Who Do We Share Personal Data With?

We may share your Personal Data as follows:

For more information on the recipients of your Personal Data, please contact us by using the information in Section 13 below.

7. International Transfer of Personal Data

Your Personal Data may be processed outside your country or jurisdiction. We ensure that the recipient of your Personal Data offers an adequate level of protection and security, for instance by entering into the appropriate back-to-back agreements and, if required, standard contractual clauses or an alternative mechanism for the transfer of data as approved by the European Commission (Art. 46 GDPR) or other applicable regulators or legislators.

8. Children

Our websites and services are not directed at children. We do not knowingly collect Personal Data from children under the age of 13. We do not knowingly collect Personal Data for children between 13-18 unless we have obtained consent from a parent or guardian or such collection is subject to a separate agreement with us or the visit by a child is unsolicited or incidental. If you believe we have mistakenly or unintentionally collected Personal Data of a minor without appropriate consent please contact us by using the information in Section 13 below and we will take steps to delete their Personal Data from our systems.

9. How Long Do We Keep Your Personal Data?

We may retain your Personal Data for a period of time consistent with the original purpose of collection (see Section 5 above) or as long as required to fulfill our legal obligations. We determine the appropriate retention period for Personal Data on the basis of the amount, nature, and sensitivity of the Personal Data being processed, the potential risk of harm from unauthorized use or disclosure of the Personal Data, whether we can achieve the purposes of the processing through other means, and on the basis of applicable legal requirements (such as applicable statutes of limitation).

After expiry of the applicable retention periods, your Personal Data will be deleted. If there is any data that we are unable, for technical reasons, to delete entirely from our systems, we will implement appropriate measures to prevent any further use of such data.

For more information on data retention periods, please contact us by using the information in the Section 13 below.

10. Your Rights Relating to Your Personal Data

10.1 Your Rights

We notify you about the following rights in connection with your personal data which you can perform so that you send an email to [email protected] and:

You also have the right to file a complaint with the supervisory authority, which is the Information Commissioner of the Republic of Slovenia, whose contact information is available at https://www.ip-rs.si.

For additional information regarding your rights in connection with your personal data, including certain limitations in force for some of these rights, see Articles 12 to 23 of the GDPR.

Please note that Automated Decision-Making currently does not take place on our websites or in our services.

10.2 How to Exercise Your Rights

To exercise your rights, please contact us by using the information in Section 13 below. Your Personal Data may be processed in responding to these rights. We try to respond to all legitimate requests within one month unless otherwise required by law, and will contact you if we need additional information from you in order to honor your request or verify your identity. Occasionally it may take us longer than a month, taking into account the complexity and number of requests we receive. If you are an employee of a Carely customer, we recommend you contact your employer’s system administrator for assistance in correcting or updating your information.

Some registered users may update their user settings, profiles, organization settings and event registrations by logging into their accounts and editing their settings or profiles.

To update your billing information, discontinue your account or request return or deletion of your Personal Data and other information associated with your account, please contact us by using the information in Section 13 below.

10.3 Your Rights Relating to Customer Data

As described above, we may also process Personal Data submitted by or for a customer to our products and services. To this end, if not stated otherwise in this Privacy Statement or in a separate disclosure, we process such Personal Data as a processor on behalf of our customer who is the controller of the Personal Data (see Section 1 above). We are not responsible for and have no control over the privacy and data security practices of our customers, which may differ from those explained in this Privacy Statement. If your data has been submitted to us in our role as a processor by or on behalf of our customer and you wish to exercise any rights you may have under applicable data protection laws, please inquire with them directly. Because we may only access a customer’s data upon their instructions, we will refer your request to that customer, and will support them as needed in responding to your request within a reasonable timeframe.

10.4 Your Preferences for Email and SMS Marketing Communications

If we process your Personal Data for the purpose of sending you marketing communications, you may manage your receipt of marketing and non-transactional communications from Carely by clicking on the “unsubscribe” link located on the bottom of our marketing emails, by replying or texting ‘STOP’ if you receive our SMS communications.

Please note that opting out of marketing communications does not opt you out of receiving important business communications related to your current relationship with us, such as communications about your subscriptions or security information.

11. How We Secure Your Personal Data

We take appropriate precautions including organizational, technical, and physical measures to help safeguard against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure of, or access to, the Personal Data we process or use.

While we follow generally accepted standards to protect Personal Data, no method of storage or transmission is 100% secure. You are solely responsible for protecting your password, limiting access to your devices and signing out of websites after your sessions. If you have any questions about the security of our websites, please contact us by using the information in Section 13 below.

12. Changes to This Privacy Statement

We will update this Privacy Statement from time to time to reflect changes in our practices, technologies, legal requirements, and other factors. If we do, we will update the “effective date” at the top. If we make a material update, we may provide you with notice prior to the update taking effect, such as by posting a notice on our website or by contacting you directly, or where required under applicable law and feasible, seek your consent to these changes.

We encourage you to periodically review this Privacy Statement to stay informed about our collection, processing and sharing of your Personal Data.

13. Contacting Us

To exercise your rights regarding your Personal Data, or if you have questions regarding this Privacy Statement or our privacy practices please contact us at [email protected]

We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy. If, however, you believe that we have not been able to assist with your complaint or concern, and you are located in the European Economic Area or the United Kingdom, you have the right to lodge a complaint with the competent supervisory authority.  If you work or reside in a country that is a member of the European Union or that is in the EEA, you may find the contact details for your appropriate data protection authority on the following website.

Ready to elevate your patient experience and drive measurable growth?

Contact us and see firsthand how easy it is to elevate patient engagement, build lasting loyalty, and make smarter, data-driven decisions.