Website privacy

Privacy Policy

Last updated: 4 October 2026

1. Scope and controller

This policy explains how personal data is processed when you visit the Migravi website or contact us by email. It is not a complete privacy notice for the Migravi iPhone app or for Apple’s services.

The controller is REPARIS d.o.o. za trgovinu i usluge, Glagoljaška ulica 1, 32100 Vinkovci, Croatia, OIB 89597065136. Migravi is our product. For privacy enquiries and requests, email info@migravi.app. Company registration details are available in our Imprint.

2. Website visits and technical data

When your browser requests a page, the hosting infrastructure processes technical connection data needed to deliver it. Depending on its configuration, this can include your IP address, request date and time, requested URL, response status, browser/user-agent information and a referrer where your browser provides one.

We use the technical data needed for delivery, availability, troubleshooting and protection against misuse. The legal basis is our legitimate interest in operating a reliable and secure website under Article 6(1)(f) GDPR. We do not use this data for advertising profiles.

To complete before publication: verify the actual logged fields and processing locations with TOTOHOST. The retention limit for access, error/security and email logs is up to six months. Do not assume that visiting a website involves no personal-data processing simply because it has no analytics.

3. FAQ search

The FAQ search and topic filter operate within your browser. The search script we provide does not send the words you type to REPARIS servers, use cookies or save them in localStorage or sessionStorage. It filters the questions and answers already loaded on the page. Loading the FAQ page still involves the technical processing described above.

4. Contact and support emails

You may email info@migravi.app for general enquiries or support@migravi.app for app support. We receive your email address, any name you provide, your message, email metadata and any attachments you choose to send.

The support page asks for a topic and description. App version/build, iPhone model, iOS version and import-file details are optional and help us understand the problem. The page prepares a mailto link and opens your email app. Its custom code does not submit the form to a web server or upload attachments. You must review and send the email yourself. Your email provider processes the draft or message under its own terms.

We process enquiries to answer questions and resolve problems. The legal basis is Article 6(1)(b) GDPR where the enquiry relates to a contract with you or steps you request before entering one, and Article 6(1)(f) for other correspondence and our legitimate interest in providing support. Article 6(1)(c) applies where a specific legal obligation requires processing.

Contacting us is voluntary. Without a way to reply or enough information about the issue, we may be unable to answer or resolve it. Please do not send passwords, verification codes, full chat archives or unnecessary personal information about yourself or others. Redact sensitive details from screenshots. If we need additional diagnostic material, we will explain what is needed.

5. Analytics, cookies and browser storage

This static website does not use analytics, advertising pixels, cookies, localStorage, sessionStorage or visitor fingerprinting in its own code. Images, CSS and JavaScript are served from our own website. The FAQ search and support form work locally in your browser without storing their input persistently or sending it to a form server.

The visitor-facing site is static HTML, CSS and JavaScript; it does not use WordPress or visitor accounts. Hosting or security infrastructure can still add response headers or cookies, independently of our code. The live server configuration must therefore also be checked before publication.

To complete before publication: check the deployed TOTOHOST response headers and security configuration for infrastructure cookies. If any are introduced, update this notice accurately. Do not activate analytics or other non-essential tracking without reviewing consent requirements.

6. Recipients and service providers

Our website hosting and the mailboxes info@migravi.app and support@migravi.app are provided by TOTOHOST d.o.o., Croatia. The provider processes the technical and email data needed to operate these services. Its privacy statement and service terms provide further information about its own services. Those notices do not replace this policy.

Access to enquiries is limited to people who need it to handle support, administration or legal matters. Hosting, email, IT security and technical maintenance providers may process relevant data to deliver their services. Where they act as processors, their processing must be governed by appropriate data-processing arrangements. We may disclose data to competent authorities or advisers where required by law or necessary for legal claims. We do not sell contact details or use support messages for advertising.

To complete before publication: confirm TOTOHOST’s processing arrangements and any subprocessors or additional CDN/security services used for this hosting package.

7. International transfers

To complete before publication: confirm whether providers or subprocessors store data or allow access outside the European Economic Area. If transfers occur, state the relevant countries or arrangements and applicable safeguards, such as an adequacy decision or standard contractual clauses, and how a copy or further information can be obtained. We have not verified these details and do not claim that all processing stays within the EU.

8. Retention

  • Routine contact and support enquiries: kept while the matter is active and for up to 12 months after it is resolved, then deleted unless a separate justified obligation or need applies.
  • Legal obligations and disputes: relevant records may be retained for the period required by the applicable obligation or necessary to establish, exercise or defend legal claims. Such retention is limited to relevant information.
  • Technical logs: website access logs, error/security logs and email delivery logs are retained for up to six months.
  • Website and email backups: backup copies are retained for up to six months from creation. Deleting data from active systems does not immediately remove it from existing backups; it may remain until those copies expire or are rotated out. This can mean a backup copy remains after the routine enquiry retention period has ended. If data is recovered from backup, applicable deletion requirements must be reapplied.

The six-month limit for logs and backup copies is separate from the retention of routine enquiries in active mailboxes. We retain those enquiries for up to 12 months after resolution and apply the relevant deletion schedule to restored data.

9. Your data-protection rights

Subject to the conditions in the GDPR, you may request access to your personal data, correction, deletion, restriction of processing and data portability where applicable. You may object to processing based on legitimate interests on grounds relating to your particular situation. If an activity relies on consent, you may withdraw that consent without affecting the lawfulness of processing before withdrawal.

Contact info@migravi.app and describe your request. We may ask for proportionate information needed to verify your identity. We normally respond within one month; where the GDPR permits an extension because of complexity or the number of requests, we will inform you within that first month. Rights are not absolute, and a legal obligation or another applicable exception may limit deletion.

You may lodge a complaint with the Croatian supervisory authority, Agencija za zaštitu osobnih podataka (AZOP), Ulica Metela Ožegovića 16, 10000 Zagreb, Croatia, email azop@azop.hr, or with another competent supervisory authority. You do not have to contact us first to exercise that right.

10. Security and automated decisions

Personal data should be accessible only to those who need it for the purposes described here. Technical and organisational safeguards must be appropriate to the hosting and email systems we use. Email is not a suitable channel for passwords, verification codes or unnecessary sensitive information. No internet transmission can be guaranteed risk-free.

We do not use the website’s FAQ search or support form to make automated decisions producing legal or similarly significant effects about you, or to build advertising profiles.

11. External links and the app archive

When you follow links to Apple, Viber or other external sites, those services process visits under their own privacy notices. The Migravi website does not read the archive stored in your iPhone app. However, if you voluntarily send chat content to support, it becomes part of the correspondence we receive.

Migravi stores its imported archive locally and does not upload imported chat contents to Migravi servers. Device backups such as iCloud Backup can still include app data, and cloud services used to transfer an export can retain separate copies. These are distinct from the website processing covered here.

12. Changes and contact

We will update this notice when relevant website features, providers or processing practices change. The date above identifies the most recent revision. For questions about this website policy, contact info@migravi.app.