Privacy Policy
This policy explains what personal data we process when you visit meteoapi.eu or use the MeteoAPI.eu API, why, for how long, and what your rights are.
We use no analytics, no advertising or tracking cookies and no social media pixels. The website sets no cookies at all.
1. Controller
- Company
- METEO CENTAR d.o.o. za meteorološko savjetovanje i prognozu vremena
- Address
- Miroslava Krleže 11c, 23000 Zadar, Croatia
- OIB
- 20242452865
- VAT ID
- HR20242452865
- Register
- Commercial Court in Zadar (Trgovački sud u Zadru), MBS 01438638
- Contact
- support@meteoapi.eu
2. Visiting the website
Our web server keeps standard access logs: IP address, time of the request, the address requested and browser details. They serve security and fault diagnosis (legitimate interest) and are deleted after 14 days.
Almost everything is served from our own servers, with three exceptions, each of which sees your IP address:
- the interactive documentation at /docs loads its viewer (Swagger UI) from the jsDelivr content network, and its icon from fastapi.tiangolo.com;
- when you click Subscribe, the checkout is loaded from Paddle;
- links to app stores and partner sites take you to those sites, under their own policies.
During a purchase your browser keeps the Paddle transaction number in session storage, so the page can show your new API key; it stays on your device and is cleared when you close the tab.
3. Using the API
- Your API key record: the email address the key is registered to, its plan, dates of issue and revocation, any note we add, and the website addresses the key is restricted to, if any. We store only a hash of the key itself, never the key.
- Request log: for each forecast request, the coordinates asked for, the time, the key used and technical details of the response (such as whether it came from cache). It contains no IP address.
- Usage totals: monthly request counts per key, for billing and plan limits.
- Rate limiting: your client IP address is used in memory to apply rate limits and is not written to storage.
The legal basis is the performance of the contract (Article 6(1)(b) GDPR) and, for the request log and rate limiting, our legitimate interest in running and securing the service (Article 6(1)(f)).
4. Subscriptions and payment
Payments are handled by Paddle, our reseller and Merchant of Record. You give your payment details to Paddle, never to us. From Paddle we receive your email address, the identifiers of your Paddle customer record and subscription, the subscription's status and the end of the paid period, and we keep the notifications Paddle sends us about each purchase, renewal, cancellation or refund as the billing record of your subscription.
To let you manage your keys without a password, we send one-time sign-in links by email. The link is valid for 15 minutes and is not stored.
5. Email
When you write to us, or request a key or a sign-in link, we keep the correspondence on our own mail server for as long as needed to deal with it and to keep a record of what was agreed.
6. Who processes data for us
We do not sell personal data or share it for marketing. We use these processors:
| Paddle.com Market Limited / Paddle Payments Limited | sale, payment and invoicing (Merchant of Record) |
| UAB Cherry Servers (Lithuania) | primary servers and storage |
| Hetzner Online GmbH (Germany) | standby servers and storage |
| Euronodes | encrypted off-site backups |
Our servers are located in the European Union. Where a processor transfers data outside the EU/EEA, the transfer is based on the European Commission's standard contractual clauses.
7. How long we keep data
| Web server access logs | 14 days |
| API request log | 90 days |
| Monthly usage totals | as long as needed for billing and accounting |
| API key record | while the key exists; a revoked key's record is kept as an audit trail |
| Subscription and billing records | for the life of the subscription, then as long as tax and accounting law requires |
| Sign-in links | not stored; they expire after 15 minutes |
8. Your rights
You have the right to access your data, and to rectification, erasure, restriction of processing and data portability, and the right to object to processing based on legitimate interest. Send requests to support@meteoapi.eu; we reply within one month.
If you believe we process your data unlawfully, you may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr, or with the supervisory authority of your own EU country.
9. Changes to this policy
We may change this policy. The effective date is shown at the top of this page, and we will notify subscribers of significant changes by email.