Skip to main content

Privacy Notice

Last updated: Last updated: [DATE OF LAST REVIEW]

This notice explains what information we collect when you bring us a case, why we hold it, how long we keep it, and what you can ask us to do with it. It is written in plain language on purpose. If any part of it is unclear, write to us and we will explain it.

Note for the reviewer: this text is a draft

This page is a working template, not finished legal advice. It was drafted for a small technical support business operating in Serbia, with the Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti) and GDPR-aligned expectations in mind. It has not been reviewed by a lawyer.

Before this page goes live, a qualified lawyer must review it, and every field in square brackets must be completed with the registered details of the operating entity. The fields used on this page include [LEGAL ENTITY NAME], [REGISTERED ADDRESS], [COMPANY REGISTRATION NUMBER / MB], [TAX ID / PIB] and [CONTACT EMAIL], along with the retention periods listed further down.

Remove this section only once that review is complete and the placeholders are filled in.

Who is responsible for your information

The business named below decides why and how the information described in this notice is processed. In data protection language, that makes it the data controller.

Whether the business is required to appoint a formal data protection officer depends on the scale and nature of its processing, and must be confirmed during legal review.

  • Controller: [LEGAL ENTITY NAME]
  • Registered address: [REGISTERED ADDRESS]
  • Company registration number (MB): [COMPANY REGISTRATION NUMBER / MB]
  • Tax identification number (PIB): [TAX ID / PIB]
  • Email for data protection questions: [CONTACT EMAIL]
  • Person or role handling data protection questions: [DATA PROTECTION CONTACT]

What we collect

Almost everything we hold about you is something you sent us yourself, because you wanted us to look at a specific problem. The rest is technical record-keeping.

  • The case description you write. What went wrong, in your own words, plus anything you add while the case is open.
  • Business and contact details. Business name, your name, your role, email address, phone number, and where a procedure requires it, the company registration details that show the business is yours.
  • Evidence files you upload. Screenshots, error messages, invoices from a hosting company or registrar, domain records, correspondence with a platform, and similar documents you choose to send.
  • Asset identifiers. Your website address, your .rs or .срб domain name, an Instagram handle, a Facebook Page, a Google Business Profile listing, an advertising account number, and similar references needed to work the case.
  • Technical logs. IP address, browser and device type, pages opened on this site, and timestamps. We keep these to keep the service secure and to work out what happened when something breaks.
  • Consent and authorisation records. A record of what you agreed to, when you agreed to it, and exactly what you authorised us to do on your behalf.
  • Billing records. The details required to issue an invoice under Serbian accounting and tax rules. Card payments are handled by [PAYMENT PROVIDER]; we do not see or store full card numbers.

What we never ask for

There is a short list of things we do not need, will not ask for, and do not want you to send us. If a message that appears to come from us asks for any of them, it did not come from us.

We work through the official recovery and verification steps published by the platform, bank or registrar concerned. Where one of those procedures requires an identity document, you submit it to that organisation through their own form. It does not pass through us.

If you have already sent us something from this list inside a screenshot or a message, tell us. We will delete it from our systems and confirm that it is gone. This happens often and it is nothing to worry about.

  • Passwords, for any account.
  • Two-factor or one-time codes, whether they arrive by SMS, by email or from an authenticator app.
  • Backup or recovery codes.
  • Full card numbers, card expiry dates or CVV security codes.
  • Your JMBG, the Serbian personal identification number.

Why we process your information

Under Serbian data protection law every use of personal data needs a legal basis. Ours are set out below.

  • Performing our agreement with you. Running the case, contacting you about it, preparing the filings you have authorised, and invoicing the work.
  • Our legitimate interests. Keeping the service secure, preventing misuse, keeping an accurate record of what was done on a case, and improving how we work. We weigh this against your interests, and you can object.
  • Your consent. Optional measurement of how this website is used, and any newsletter or update you specifically ask for. You can withdraw consent at any time, and withdrawing it has no effect on your case.
  • Legal obligations. Accounting, tax and record-keeping duties that apply to a business registered in Serbia.

How long we keep it

We keep information for as long as we need it for the purpose it was collected for, then we delete it. The periods below are placeholders: they must be set and confirmed during legal review, and they must be short enough to be honest and long enough to satisfy Serbian accounting rules.

Deletion of evidence files runs on a schedule after a case is closed, without anyone having to remember to do it. If you would like your files deleted earlier than the schedule, ask us and we will do it, unless a specific document has to be kept for a legal reason we will name.

  • Evidence files you uploaded: deleted on a schedule after the case closes. Retention: [EVIDENCE RETENTION PERIOD].
  • The case record itself, meaning your description, our correspondence, what was filed and what the third party decided: [CASE RECORD RETENTION PERIOD].
  • Consent and authorisation records: kept while we may need to show what you authorised us to do. Retention: [AUTHORISATION RECORD RETENTION PERIOD].
  • Technical and security logs: [LOG RETENTION PERIOD].
  • Invoices and accounting records: kept for the period Serbian accounting and tax law requires. Retention: [STATUTORY ACCOUNTING RETENTION PERIOD].

Who else sees your information

Inside our business, only the people assigned to your case can open it. We do not sell information, and we do not share it so that anyone can advertise to you.

We contact a platform, a bank, a hosting company, a registrar or RNIDS only where you have authorised us in writing to act for you on a specific case, and we send only what that particular procedure asks for. You can see what we send. Those organisations then decide on their own criteria; the decision is theirs, not ours, and we cannot control what they conclude or what further evidence they request.

  • The members of our team assigned to your case.
  • The specific platform, registrar, hosting company or bank named in the authorisation you signed for that case.
  • Our professional advisers, such as an accountant or a lawyer, where they genuinely need it and are bound by confidentiality.
  • A public authority, where we receive a legally valid request and are required to respond.
  • A buyer or successor of the business, if it is ever sold or restructured, on terms that keep this notice in force.

The service providers we rely on

Like most small businesses, we do not run our own data centre. The providers below process data on our instructions and under a written data processing agreement. They are not allowed to use your information for their own purposes.

The final list of providers, their locations and their agreements must be confirmed before launch.

  • Application hosting: [HOSTING PROVIDER], in [HOSTING REGION]. Runs this website and the case system.
  • Object storage: [OBJECT STORAGE PROVIDER], in [STORAGE REGION]. Holds the evidence files you upload.
  • Email delivery: [EMAIL DELIVERY PROVIDER]. Sends case notifications and the secure links you use to open your case.
  • Error monitoring: [ERROR MONITORING PROVIDER]. Records technical faults so we can fix them.
  • Payment processing: [PAYMENT PROVIDER]. Handles card and bank payments; we receive a confirmation, not your card details.
  • Accounting: [ACCOUNTING PROVIDER]. Issues and archives invoices as Serbian law requires.

Where your information is held, and transfers abroad

Your information is stored in [PRIMARY DATA LOCATION]. Serbia sits outside the European Economic Area, so ordinary use of European hosting already involves a transfer of data across a border, in one direction or the other.

Where information leaves Serbia, we rely on the transfer routes recognised under Serbian data protection law: transfer to a country on the list of countries considered to provide adequate protection, or, where that does not apply, a contract in the standard form prescribed by the Commissioner, or another approved safeguard. You can ask for a copy of the safeguard that applies to a specific provider by writing to [CONTACT EMAIL]. The specific instruments used must be confirmed during legal review.

Separately, if you authorise us to file something with a platform such as Meta or Google, or with a registrar, that filing goes to that company and is then processed by them, under their own terms and often outside Serbia. That is unavoidable if you want the filing made, and we will tell you before we send anything.

Your rights

You have the following rights over your personal data. Using them is free, and it will not affect how we handle your case.

To use any of these rights, write to [CONTACT EMAIL]. We may need to confirm that the request really comes from you. We do that using information we already hold, or through the email address on your case. We will never ask you for a password, a one-time code or your JMBG in order to identify you. We respond within the period set by law, [STATUTORY RESPONSE PERIOD].

  • Access. Ask what we hold about you and get a copy of it.
  • Rectification. Have information corrected or completed if it is wrong.
  • Erasure. Ask us to delete information, where we have no legal reason to keep it.
  • Restriction. Ask us to pause processing while a dispute about accuracy or legal basis is sorted out.
  • Objection. Object to processing we base on our legitimate interests, including any profiling.
  • Portability. Receive the data you gave us in a structured, machine-readable file, or have it sent to another provider where that is technically possible.
  • Withdrawal of consent. Withdraw consent at any time, for anything based on consent. This does not undo processing that was lawful before you withdrew it.
  • Complaint. Complain to the supervisory authority in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti), at [COMMISSIONER CONTACT DETAILS]. You do not have to come to us first, although we would rather have the chance to put things right.

How we protect your information

No system is perfectly safe, and we will not pretend otherwise. What we can describe is what we actually do.

If something does go wrong with your data, we will tell you plainly what happened, what it affects and what we are doing about it, and we will notify the Commissioner where the law requires it.

  • Traffic between your browser and our systems is encrypted in transit.
  • Evidence files sit in private storage that is not reachable from the public internet; the site opens them through short-lived links.
  • Access is limited to the team members assigned to a case, through named accounts with defined roles.
  • Staff accounts are protected with two-factor sign-in.
  • Access to case files is logged, so we can see who opened what.
  • We do not collect passwords, one-time codes, backup codes or full card numbers, which means there is no store of them to be stolen from us.
  • We keep a written procedure for handling a suspected data breach, including who is notified and when.

Changes to this notice, and how to reach us

When we change this notice we update the date at the top of the page. If a change materially affects how we handle information on open cases, we write to the affected customers rather than quietly editing the page.

For anything about your data, write to [CONTACT EMAIL], or by post to [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. A plain email is enough; there is no form to fill in.

Privacy Notice — Reši Lokalno