1. Scope and applicable law
This Policy applies to citiwell.me, booking and contact forms, communications with Citiwell, job applications and the initial organisation of services. Separate notices or consent forms may apply to a specific treatment, contraindication assessment, photography or another special operation.
The controller for the website and central contact channels is DRUŠTVO SA OGRANIČENOM ODGOVORNOŠĆU "CITIWELL AK" PODGORICA (CITIWELL AK DOO), TIN 03416968, registration number 5 - 1016234 / 005, registered address: TRG NEZAVISNOSTI 12, Podgorica, Crna Gora.
We apply the Montenegrin Personal Data Protection Law. The GDPR applies in addition where a particular processing operation falls within its territorial scope.
This Policy does not restrict rights granted by law or make optional information mandatory. Mandatory law prevails if it conflicts with this text.
2. Data we process and where it comes from
The data depends on how you interact with Citiwell.
We may receive minimal campaign or account information when you follow an advertisement or contact us through a platform. We do not buy personal-data lists.
The public booking form is not intended for medical documents, diagnoses, intimate photographs, identity documents or payment-card details. Provide such data only when an authorised specialist specifically requests it through an appropriate channel.
3. Purposes and legal bases
Each purpose is tied to a lawful basis. We do not use data for an incompatible purpose without a new basis.
Where we rely on legitimate interests, we consider necessity, reasonable expectations and impact on individual rights. You may object. Marketing is not a condition of booking and requires a separate basis.
4. Forms, requests, messengers and careers
The standard request form asks for a name, telephone number, messenger and gender to identify and answer the request and provide relevant service information. Other displayed fields are voluntary unless expressly marked otherwise.
When the form is submitted, the browser contacts ipapi.co to infer an approximate city and country from the IP address. The request, page, referrer, UTM and click IDs is then sent to Citiwell's server and delivered to a restricted Citiwell Telegram work chat. Candidate requests go to a separate work chat.
If you choose WhatsApp, Viber, Instagram or another external service, its operator receives data under its own policy and may act as an independent controller.
If you provide someone else's contact details, you confirm that you are authorised to do so and have informed that person. Do not impersonate another person and provide accurate information.
5. Special-category data and treatment safety
Health, skin, pregnancy, medication or contraindication information may be special-category data. We request it only where reasonably necessary for consultation and safe treatment.
- Do not place it in public comments or advertising posts.
- Access is limited to staff and specialists who need it.
- Where explicit consent is required, processing starts after it is obtained.
- Refusal to provide genuinely necessary information may mean that we cannot safely perform the treatment.
We do not use health data for advertising profiles.
6. Cookies, analytics and advertising technologies
The website uses essential local storage to remember privacy choices. Google Analytics 4 and Yandex Metrica load only after analytics consent; Meta Pixel loads only after separate advertising consent. Google Consent Mode v2 starts with analytics and advertising storage denied. If you select “analytics — yes, advertising — no”, ad_storage, ad_user_data, ad_personalization and Google Signals remain disabled.
Your explicit choice is stored for 180 days. Global Privacy Control and Do Not Track signals are treated as a rejection of optional technologies until you change the settings yourself.
Consent is voluntary. Reject and settings controls are presented with the accept button. You can change your choice at any time. Withdrawal prevents future loading of optional tools and removes known first-party cookies accessible to the site where technically possible. Cookies set on external domains must be removed through browser or provider settings.
GoDaddy hosting injects its own traffic and telemetry script at platform level. It may send the page URL, IP address and browser information to csp.secureserver.net and use cookies in the _tccl_* family (_tccl_visitor and _tccl_visit) as well as _scc_session for hosting performance, security and diagnostics. These technologies are not controlled by Citiwell's consent panel; their retention and subsequent processing are determined by GoDaddy and browser settings.
Provider settings determine identifier retention, generally no longer than 24 months. Providers may update their technologies; current cookies are visible in your browser.
7. Recipients and service providers
Access is limited by need. We do not sell or rent personal data.
A provider may be a processor, joint controller or independent controller depending on the operation. Where it acts on our instructions, we require confidentiality and appropriate safeguards within applicable law and contract.
8. International transfers
Some technology and communication providers may process data outside Montenegro or the EEA. Protection and the lawful mechanism depend on the country, provider and operation.
Where required, transfers must rely on an adequacy decision, standard contractual clauses, suitable contractual safeguards, explicit informed consent or another lawful mechanism. You may request information about a specific transfer at info@citiwell.me.
After you enter an external website or messenger, its operator controls its own infrastructure and policies. Citiwell remains responsible for its supplier choices and operations but cannot control all later processing by an independent platform.
9. Retention
We use a stated period or criterion rather than retaining data indefinitely.
At the end of retention, data is deleted, anonymised or remains only in restricted backups until scheduled overwrite.
10. Your rights
Depending on applicable law, you may exercise the following rights:
Email info@citiwell.me with your name, contact, request and the channel you used. We may request reasonable identity verification to prevent unauthorised disclosure.
Under Montenegrin law, written access, correction or erasure requests are generally handled within the statutory period of up to 15 days. Where GDPR applies, the standard period is one month and may be extended as it permits.
We may retain data or limit a request where law, another person's rights, accounting, misuse prevention or legal claims require it. We explain the reason unless law prevents us.
11. Security and incidents
We use proportionate technical and organisational measures, including role-based access, restricted work channels, credential protection, transport encryption where supported, system updates, backups and supplier controls.
No website, messenger or storage method is absolutely secure. Citiwell does not promise impossible “100% security”, but remains responsible for reasonable safeguards and response. We assess incidents and notify AZLP and affected people where required by law.
12. Minors and other people’s data
The website is not intended for independent booking by young children. A minor's treatment may require parent or legal-representative involvement or consent depending on age, procedure and law.
If you believe a child submitted data without appropriate involvement, contact us so we can investigate and delete or restrict data without a lawful basis.
13. Automated decisions, changes and responsibility
Citiwell does not use website data for solely automated decisions that produce legal or similarly significant effects. Analytics and advertising tools may create statistical segments, but they do not decide whether you can receive a service.
We update this Policy when the website, services, processing or law changes. Material updates appear here with a new date. Continued use does not replace active consent where law requires it.
This Policy describes processing and is not a waiver of legal responsibility. It does not create guarantees beyond mandatory law or make Citiwell responsible for independent-platform conduct outside our reasonable control.
Questions, requests and complaints
Contact us about access, correction, erasure, cookies or any other processing. You may also complain to the Montenegrin Agency for Personal Data Protection (AZLP).
AZLP: Bulevar Revolucije 11, 81000 Podgorica, +382 20 634 883 / 884, azlp@azlp.me. Contacting Citiwell does not remove your right to contact a supervisory authority or court.