Skip to content

PRIVACY NOTICE

ON THE RIGHTS OF NATURAL PERSONS

WITH REGARD TO THE PROCESSING OF THEIR PERSONAL DATA

INTRODUCTION

REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the “GDPR”, the “Regulation” or the “General Data Protection Regulation”) requires the Controller to take appropriate measures to provide the Data Subject with all information relating to the processing of personal data in a concise, transparent, intelligible and easily accessible form, using clear and plain language, and to facilitate the exercise of the Data Subject’s rights.

Serbia is not a Member State of the European Union; therefore, Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) does not, solely by virtue of their operation in Serbia, apply generally to the activities of controllers and processors established or having a place of business in Serbia. The processing of personal data is primarily governed by the applicable data protection legislation of the Republic of Serbia, in particular the provisions of the law governing the protection of personal data.

Nevertheless, in establishing the data processing practices set out in this Privacy Notice, we also regard the data protection principles of the European Union and the requirements of the GDPR as guiding standards. Accordingly, we voluntarily apply the data protection principles and safeguards laid down in the GDPR — in particular the principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability — as a high standard of data protection.

The purpose of this approach is to ensure that, in addition to compliance with the applicable Serbian legislation, the processing operations carried out by us are performed in accordance with European data protection standards and provide a high level of protection for the rights and freedoms of Data Subjects.

Where, in the specific circumstances of a particular processing activity, the territorial scope of the GDPR nevertheless applies, the provisions of the GDPR shall also apply directly to that processing activity.

The GDPR also requires prior information to be provided to Data Subjects; accordingly, by means of the information set out below, we also fulfil our obligations in this regard.

Why has this Privacy Notice been prepared?

In the course of its operations, the Controller processes personal data for various purposes and intends to do so in compliance with its statutory obligations and with due respect for the rights of Data Subjects. The Controller also considers it important to explain to Data Subjects the processing of personal data obtained in the course of its processing activities and the principal characteristics of such processing.

On what legal basis are the personal data of Data Subjects processed?

Personal data are processed only for specified purposes and on an appropriate legal basis. The relevant purposes and legal bases are described separately in relation to each specific processing activity.

What external assistance is used in the processing of your personal data?

Personal data are generally processed by the Controller at its own premises. However, certain processing operations require external assistance, for which the Controller engages processors. The identity of the processor may vary depending on the characteristics of the particular processing activity.

Who processes your personal data?

Information on the identity and contact details of the processors engaged by the Controller is provided in Chapter II of this Privacy Notice.

Which principles does the Controller consider important when processing your personal data?

Personal data are processed in accordance with the applicable legal framework, with particular regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the GDPR).

In the course of its activities, the Controller processes only the personal data specified for the relevant individual processing activities, and the personal data provided are protected by the appropriate and necessary technical and organisational measures. Particular attention is paid to ensuring the confidentiality, integrity and availability of personal data.

Following their provision by the Data Subject, the Controller is responsible for the authenticity and accuracy of the personal data. Terms used in this Privacy Notice are interpreted in accordance with the definitions set out in the legislation on informational self-determination and in the GDPR.

CHAPTER I

IDENTITY OF THE CONTROLLER

The issuer of this Privacy Notice and the Controller is:

COMPANY NAME: T-1 ABRAZIV” D.O.O.

REGISTERED OFFICE: SENCANSKI PUT 59/B, 24430 ADA, SERBIA

TAX NUMBER: RS106472529

REPRESENTED BY: Tóth Árpád

E-MAIL: office@t-1.rs

CONTACT: +381 24 854 585

WEBSITE: https://t-1ada.com/ (hereinafter: the “Company” or the “Controller”)

CHAPTER II

IDENTITY OF PROCESSORS

Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller (Article 4(8) of the Regulation).

The engagement of a processor does not require the Data Subject’s prior consent; however, the Data Subject must be informed thereof. Accordingly, we provide the following information:

Processor providing marketing services:

COMPANY NAME: ContentPlus Kft.

REGISTERED OFFICE: 1221 Budapest, Murányi utca 13, Building A, Hungary

COMPANY REGISTRATION NUMBER: 01-09-983692

TAX NUMBER: 23909144-2-43

WEBSITE: https://contentplus.hu

Other Recipients:

COMPANY NAME: Google LLC

REGISTERED OFFICE: 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA

WEBSITE: https://www.google.com/

(organisation listed under the DPF)

COMPANY NAME: Meta Platforms, Inc.

REGISTERED OFFICE: 1601 Willow Rd, Menlo Park, CA 94025, USA

WEBSITE: https://www.facebook.com/ and https://www.instagram.com

(organisation listed under the DPF)

COMPANY NAME: LinkedIn Corporation

REGISTERED OFFICE: 1000 W Maude Ave, Sunnyvale, CA 94085, USA

WEBSITE: https://www.linkedin.com/

(organisation listed under the DPF)

COMPANY NAME: Mozilor Limited (WebToffee)

REGISTERED OFFICE: 3 Warren Yard, Wolverton Mill, Milton Keynes, MK12 5NW, United Kingdom

COMPANY NAME: Cloudflare, Inc.

REGISTERED OFFICE: 101 Townsend St, San Francisco, CA 94107, USA

(organisation listed under the DPF)

COMPANY NAME: Microsoft Ireland Operations Limited (Microsoft Teams)

REGISTERED OFFICE: One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland

WEBSITE: https://www.microsoft.com/

COMPANY NAME: Leadinfo B.V.

REGISTERED OFFICE: Rivium Quadrant 141, 2909 LC Capelle aan den IJssel, The Netherlands

WEBSITE: https://www.leadinfo.com/

Where this Privacy Notice generally provides for the transfer of data to the Company’s processors, such reference shall also be understood to include transfers to the recipients listed above.

CHAPTER III

ENSURING THE LAWFULNESS OF PROCESSING

1. Processing based on the Data Subject’s consent

1.1. Where the Company intends to carry out processing based on consent, the Data Subject’s consent to the processing of his or her personal data shall be requested with the content and information specified in the data collection form provided for in the data processing policy.

1.2. Consent may also be given by the Data Subject ticking a relevant box when visiting the Company’s website, by selecting the appropriate technical settings when using information society services, or by any other statement or conduct which, in the relevant context, clearly indicates the Data Subject’s consent to the intended processing of his or her personal data. Silence, pre-ticked boxes or inactivity therefore do not constitute consent.

1.3. Consent shall cover all processing activities carried out for the same purpose or purposes. Where processing serves multiple purposes, consent shall be obtained for all such processing purposes.

1.4. Where the Data Subject gives consent in the context of a written declaration which also concerns other matters — for example, the conclusion of a sales or service agreement — the request for consent shall be presented in a manner clearly distinguishable from those other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such declaration containing the Data Subject’s consent which infringes the Regulation shall not be binding.

1.5. The Company shall not make the conclusion or performance of a contract conditional upon consent to the processing of personal data which are not necessary for the performance of that contract.

1.6. Withdrawal of consent shall be made as easy as giving consent. The Data Subject may withdraw consent at any time by sending an e-mail to the address specified in Chapter I (office@t-1.rs).

1.7. If the Data Subject withdraws consent, the Controller may no longer process the relevant data on that basis. Upon withdrawal of consent, the Controller shall ensure the deletion of the data unless another legal basis permits their continued processing (e.g. statutory retention requirements or necessity for the performance of a contract). Where personal data have been processed for several purposes, the Controller shall no longer use the personal data for the purpose in respect of which the Data Subject has withdrawn consent.

2. Processing necessary for compliance with a legal obligation

2.1. In the case of processing based on a legal obligation, the applicable legislation governing such processing shall determine the categories of data that may be processed, the purpose of processing, the retention period and the recipients.

2.2. Processing based on compliance with a legal obligation is independent of the Data Subject’s consent, as the processing is prescribed by law. Before processing begins, the Data Subject shall be informed that the processing is mandatory and shall be provided with clear and detailed information concerning all material aspects of the processing, including in particular its purpose and legal basis, the identity of the persons authorised to carry out the processing and any processing on behalf of the Controller, the duration of processing, the fact that the Controller processes the Data Subject’s personal data pursuant to a legal obligation applicable to it, and the persons who may have access to the data. The information shall also cover the Data Subject’s rights in connection with the processing and the available remedies. In the case of mandatory processing, the information may also be provided by making publicly available a reference to the statutory provisions containing the foregoing information.

3. Processing based on legitimate interests

3.1. The legitimate interests of the Company or of a third party may constitute a legal basis for processing, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the Data Subject. The reasonable expectations of the Data Subject based on his or her relationship with the Controller shall be taken into account; accordingly, processing personal data for contact purposes, including direct business development purposes, may also be regarded as being based on legitimate interests.

3.2. Processing based on legitimate interests requires a balancing test, in the course of which the Company shall always take into account the circumstances prevailing at the relevant time and the respective positions of the Controller and the Data Subjects. The individual balancing tests conducted in relation to processing carried out in the Company’s interests have reached the following conclusion: having regard to the conditions described for the relevant processing activity, the Company has concluded that the processing is justified subject to the appropriate safeguards set out in this policy, since otherwise the Company would be unable to operate competitively. In light of the foregoing, the emotional impact on Data Subjects and the interference with the right to privacy are considered proportionate.

4. Processing necessary to protect the vital interests of the Data Subject or another natural person

4.1. The protection of the vital interests of the Data Subject or of another natural person may also constitute a legal basis for processing, since the right to data protection is a fundamental but not an absolute right; in matters of life and death, the right to life naturally prevails over the right to the protection of personal data.

5. Processing based on contractual necessity

5.1. Processing may also be based on contractual necessity where it is necessary for the performance of a contract to which the Data Subject is a party or in order to take steps at the request of the Data Subject prior to entering into a contract.

6. Facilitating the exercise of Data Subject rights

6.1. In all of its processing activities, the Company shall ensure that Data Subjects are able to exercise their rights.

CHAPTER IV

INFORMATION ON PROCESSING CARRIED OUT BY THE COMPANY

Processing of the personal data of natural persons contracting with the Controller (including sole traders or private individuals issuing invoices)

(1) On the legal basis of performance of a contract, the Company may process, for the purposes of preparing, concluding, performing and terminating the contract, granting contractual discounts and, in summary, supporting economic processes falling within the parties’ common sphere of interest, the following personal data of natural persons having a contractual relationship with it: name, birth name, date of birth, mother’s name, residential address, personal tax identification number, tax number, registration number, registered office and business establishment address, telephone number, e-mail address, website address, bank account number, customer number (client number, order number) and online identifier (customer and supplier lists, loyalty customer lists). Such processing shall also be lawful where it is necessary in order to take steps at the request of the Data Subject prior to entering into a contract.

(2) Retention period of personal data: having regard to the Company’s long-term business relationships, 8 years following termination of the contract.

(3) Recipients of personal data: access to the personal data may be granted to those employees of the Controller who participate in the preparation, performance and storage of the contract; the Company’s executive officers, employees performing customer service functions, contact persons, the Company’s processors, in particular employees and processors carrying out sales functions; and such bodies as are authorised by law to carry out inspections.

(4) Personal data may be disclosed for processing purposes to the postal service or an appointed courier service for mailing and delivery, to the Controller’s security service provider for property protection purposes, and to the Controller’s processors.

(5) Processing shall be lawful where it is necessary in connection with a contract or an intention to enter into a contract (Recital 44), or in order to take steps at the request of the Data Subject prior to entering into a contract (Article 6(1)(b) of the GDPR). Accordingly, personal data collected in the context of contractual offers may also be processed on the basis of performance of a contract as described in this section. When making or receiving an offer, the Company shall inform the offeror or the recipient of the offer accordingly.

Processing relating to invoicing, accounting and retention of supporting documents in connection with contracts concluded by the Controller

(1) Purpose of processing: settlement of consideration for services provided and transactions performed by the Controller; issuance, recording and retention of invoices and other accounting documents; and compliance with accounting, tax and other statutory obligations applicable to the Controller.

(2) Categories of Data Subjects: natural persons having a contractual relationship with the Controller, sole traders, representatives and contact persons of contractual counterparties, and other natural persons whose details are provided in the course of invoicing or performance of the contract.

(3) Categories of personal data processed: the Data Subject’s name and billing address and, where required for the relevant transaction, residential or business address, tax identification number or tax number, together with any other personal data necessary for the issue, recording and retention of an invoice or other accounting document.

(4) Legal basis of processing: processing is necessary for compliance with legal obligations applicable to the Controller under the relevant data protection, accounting and tax provisions. The legal basis for processing is Article 6(1)(c) of the GDPR.

(5) Recipients or categories of recipients of the personal data: employees and other persons engaged by the Controller whose duties include invoicing, accounting, financial or tax-related tasks; accounting, financial, invoicing or other service providers and processors engaged by the Controller; and competent tax authorities, courts and other authorities or public bodies authorised by law.

(6) Retention period of personal data: the Controller retains the personal data until expiry of the mandatory retention period prescribed by the applicable accounting, tax and other legislation.

Processing of the personal data of natural persons acting on behalf of a legal entity contracting with the Controller and signing the contract

(1) Purpose of processing: the purpose of processing is to establish the contract, exercise the rights and perform the obligations set out therein, enforce any civil-law claims that may arise in the course of performance, and record and fulfil the obligations undertaken by the Controller.

(2) Data Subjects: natural persons signing the contract

(3) Categories of personal data that may be processed in relation to the natural person signing the contract:

  • name and position (job title)
  • e-mail address
  • telephone number
  • correspondence address
  • specimen signature

(4) Legal basis of processing: pursuit of the Controller’s legitimate interests, on the basis of the balancing test set out below [Article 6(1)(f) GDPR].

The Controller considers that the processing of the personal data of natural persons signing contracts satisfies the legitimate-interest basis under Article 6(1)(f) GDPR and that the interests or fundamental rights and freedoms of the Data Subjects are not prejudiced in a manner that would override the Controller’s legitimate interest (i.e. the specified interests or fundamental rights and freedoms of the Data Subject do not take precedence over that interest).

The legitimate interest exists The handover/acceptance of products or provision of services required for performance of the contract, and evidence thereof, constitutes an interest which is not exclusively the Controller’s interest but also the interest of the contracting party as a third party, and is in turn attributable to the performance of obligations under the contractual relationship.The Controller also has a significant interest in performing its contractual obligations properly and in accordance with the contract, thereby avoiding potential disputes. It is a legitimate business interest of the Controller to ensure the satisfaction of its contractual partners and to maintain good business relations with them.
The processing is necessary The processing is necessary because, without the personal data of the representative associated with the legal entity, the legal entities and the Controller would be unable to establish contact with one another; in the absence of the representative’s personal data, communication with contractual partners and performance of contracts would become significantly more difficult, which could impede performance of the contracts.
The processing constitutes a proportionaterestriction in relation tothe Data Subject The Controller processes the representative’s data constituting personal data only to the extent necessary to achieve the legitimate business-development purpose and/or to contact another external body.The data processed do not fall within special categories of personal data, which weighs in favour of the permissibility of the processing. The processing does not result in any disadvantage to the Data Subject representative and constitutes a proportionate restriction, as the Controller ensures the representative’s right to request deletion of the Data Subject’s personal data from the Controller’s records and to object to the processing.The Controller restricts and limits access to personal data to its own employees. It also ensures appropriate firewall and anti-virus protection for the protection of the data and thereby provides safeguards proportionate to the risks of the processing.

(5) Recipients or categories of recipients of the personal data: access may be granted to employees of the Controller who participate in the preparation, performance and storage of the contract; the Company’s executive officers, employees performing customer service functions, contact persons and employees carrying out sales functions; and such bodies as are authorised by law to carry out inspections.

(6) Retention period of personal data: 8 years following termination of the contract.

Processing of the personal data of natural persons designated in contracts as contact persons but who do not sign the contract

(1) Purpose of processing: to ensure communication in connection with the performance of the relevant contract or document, facilitation of such performance, and maintenance of the contractual relationship.

(2) Data Subjects: natural persons designated as contact persons who are not signatories

(3) Categories of personal data that may be processed in relation to the natural person acting as contact person:

  • name and position (job title)
  • e-mail address
  • telephone number
  • correspondence address

(4) Legal basis of processing: pursuit of the Controller’s legitimate interests, on the basis of the balancing test set out below [Article 6(1)(f) GDPR].

The Controller considers that the processing of contact-person data relating to external partners satisfies the legitimate-interest basis under Article 6(1)(f) GDPR and that the interests or fundamental rights and freedoms of the Data Subjects are not prejudiced in a manner that would override the Controller’s legitimate interest (i.e. the specified interests or fundamental rights and freedoms of the Data Subject do not take precedence over that interest).

The legitimate interest exists The Controller has a legitimate interest in maintaining contact in connection with contracts concluded by it, ensuring communication with contractual partners and thereby facilitating performance of those contracts.The Controller has a legitimate interest in storing the personal data of contact persons of potential business partners and/or other external organisations and using such data for future official contact and/or in connection with the possibility of entering into a contract, consistently with the Controller’s activities and business-development purposes.
The processing is necessary The processing is necessary because, in the absence of contact details, communication with contractual partners would become significantly more difficult and performance of contracts could consequently be impeded.
The processing constitutes a proportionaterestriction in relation tothe Data Subject The Controller processes the contact person’s data constituting personal data only to the extent necessary to achieve the legitimate business-development purpose and/or to contact another external body.The data processed do not fall within special categories of personal data, which weighs in favour of the permissibility of the processing. The processing does not result in any disadvantage to the Data Subject contact persons and constitutes a proportionate restriction, as the Controller ensures their right to request deletion of the Data Subject’s personal data from the Controller’s records and to object to the processing.The Controller restricts and limits access to personal data to its own employees. It also ensures appropriate firewall and anti-virus protection for the protection of the data and thereby provides safeguards proportionate to the risks of the processing.

(5) Recipients or categories of recipients of the personal data: access may be granted to employees of the Controller who participate in the preparation, performance and storage of the contract; the Company’s executive officers, employees performing customer service functions, contact persons and employees carrying out sales functions; and such bodies as are authorised by law to carry out inspections.

(6) Retention period of personal data: 8 years following termination of the contract.

Sending messages via the Company’s website

(1) A natural person sending a message through the website may give consent to the processing of his or her personal data by ticking the relevant checkbox. The checkbox must not be pre-ticked.

(2) Categories of personal data that may be processed: the natural person’s name (surname and given name), e-mail address, telephone number and message.

(3) Purpose of processing personal data:

requesting information, requesting a quotation, and using a service

(4) Legal basis of processing: the Data Subject’s voluntary consent [Article 6(1)(a) GDPR]. Voluntary consent may be withdrawn at any time. You are hereby informed that withdrawal of consent does not affect the lawfulness of processing carried out before such withdrawal. For identification purposes, please state your name and the e-mail address provided during registration in your deletion request.

(5) Recipients or categories of recipients of the personal data: employees of the Company performing customer service and marketing functions, and the Company’s processors, in particular its IT and marketing service providers.

(6) Retention period of personal data: The Controller processes the personal data for no longer than 8 years from the date on which the data were provided, or until the Data Subject withdraws consent or requests deletion, whichever occurs first. Upon withdrawal of consent or a valid request for deletion, the Controller shall delete the personal data unless another applicable legal basis permits or requires their continued retention.

Registration for an audit, webinar, e-book download and participation in research

(1) Processing and method of providing data: depending on the service selected, the Data Subject may provide personal data by completing a form made available on the Controller’s website or through a third-party platform linked by the Controller. Registration for webinars and the related webinar landing pages are provided through Microsoft Teams. Research questionnaires are conducted through Google Forms. Efficiency-audit registration and e-book downloads may be made available through the Controller’s website.

The Data Subject may consent to the processing of his or her personal data for the relevant purpose by ticking the checkbox provided for this purpose. The consent checkbox must not be pre-ticked.

Providing a telephone number is optional. If the other data marked as mandatory for registration are not provided, the relevant audit, webinar, e-book download or participation in research cannot be provided, or cannot be provided in full.

(2) Categories of personal data processed: the Data Subject’s name (surname and given name), the name of the business/company represented or specified by the Data Subject, e-mail address, country and, optionally, telephone number.

In the case of an efficiency audit, the Controller additionally processes the data and answers provided by the Data Subject during the audit concerning the business’s operations, technological processes, equipment and efficiency, insofar as such information constitutes personal data relating to the Data Subject.

Where the Data Subject participates in research, the Controller also processes the answers and information voluntarily provided by the Data Subject in the course of the research.

(3) Purpose of processing personal data: the purpose of processing is to provide the service or content selected by the Data Subject, including in particular:

  • carrying out the efficiency audit, preparing the audit result and sending it to the Data Subject;
  • managing registration for the webinar, enabling participation and sending the necessary information relating to the webinar;
  • making the requested e-book available and/or sending it to the Data Subject;
  • where the Data Subject so elects, enabling participation in the research and processing and evaluating the research responses;
  • maintaining the necessary communication with the Data Subject in connection with an audit, registration, download or research participation initiated by the Data Subject.

Where the Data Subject separately consents, the Controller may also process the contact details provided for the purposes of further contacting the Data Subject and providing information regarding the Controller’s services and optimisation opportunities.

(4) Legal basis of processing: the Data Subject’s voluntary consent [Article 6(1)(a) GDPR]. Voluntary consent may be withdrawn at any time. You are hereby informed that withdrawal of consent does not affect the lawfulness of processing carried out before such withdrawal. For identification purposes, please state your name and the e-mail address provided during registration in your deletion request.

Where the Data Subject gives separate consent to further contact for marketing, sales or service-related purposes, withdrawal of that consent does not affect the separate processing connected with the provision of the audit, webinar, e-book or research requested by the Data Subject.

(5) Recipients or categories of recipients of the personal data: the personal data may be accessed by employees and other persons engaged by the Controller who participate in the administration of audits, webinars, e-books, research, customer relations or marketing activities.

The personal data may also be transferred to processors engaged by the Controller, including in particular IT, hosting, website operation, e-mail delivery and marketing service providers, to the extent necessary for the performance of their tasks.

(6) Retention period of personal data: the Controller processes the personal data until the purpose of processing has been achieved, but in any event for no longer than 8 years from the date on which the data were provided or, where processing is based on consent, until the Data Subject withdraws consent at an earlier date.

Upon withdrawal of consent, the Controller deletes the data unless another appropriate legal basis permits their continued retention.

Processing in relation to social media (Facebook, LinkedIn, Youtube)

(1) The Company has only limited influence over the processing carried out by operators of social media platforms. Where we are able to influence or configure such processing, we use the options available to us to promote processing that is compliant with data protection requirements. In most cases, however, we cannot influence the platform operator’s activities and therefore do not have information as to exactly which data are processed.

Facebook’s privacy policy is available at: https://www.facebook.com/privacy/explanation/

LinkedIn’s privacy policy is available at: https://www.linkedin.com/legal/privacy-policy

Youtube’s privacy policy is available at:  https://policies.google.com/privacy?hl=en-US

(2) The Controller operates its own pages and profiles on Facebook, Youtube and LinkedIn. A Data Subject may follow the Controller, like or react to posts, comment on content, or contact the Controller through the functions made available by the relevant platform. To use these functions, the Data Subject must generally be logged in to the relevant platform. Facebook, Youtube and LinkedIn may request, store and process personal data for these purposes in accordance with their own privacy policies. The Controller has only limited influence over the type, scope and manner of such processing. The Controller processes personal data relating to persons who follow or otherwise interact with its Facebook, Youtube or LinkedIn page, channel or profile on the basis of their voluntary interaction with the relevant platform and the Controller. By requesting a service through the Controller’s Facebook, Youtube or LinkedIn page, channel or profile, the Data Subject declares that he or she has reached the age required for valid consent under the applicable rules. The Controller is not in a position to verify the age or authority of the person giving consent; accordingly, the Data Subject warrants that the data provided are accurate.

(3) Purpose of processing: providing information about current matters and news concerning the Controller, advertising on social media platforms, and presenting and promoting services. The Controller uses its Facebook, Youtube and LinkedIn pages and profiles for marketing purposes so that interested persons may learn about its services and contact the Controller.

(4) Legal basis of processing: the Data Subject’s voluntary consent (in accordance with the privacy policies of Facebook, Youtube and LinkedIn).

(5) Categories of personal data processed: the Data Subject’s name; Data Subjects: users of the social media platform.

(6) Duration of processing: the Data Subject may unfollow or otherwise cease interacting with the Controller’s Facebook, Youtube or LinkedIn page, channel or profile by using the functions provided by the relevant platform and may remove content where the platform makes this possible. Processing continues for the duration of the active service or until the relevant interaction or content is removed, subject to the platform operator’s own retention rules.

(7) Recipients: employees of the Controller performing customer service and marketing functions and the Company’s processors, in particular the Company’s marketing service provider.

(8) The Data Subject acknowledges that providing personal data is not a prerequisite for entering into a contract and that he or she is not obliged to provide personal data. A possible consequence of not providing the data is that the Data Subject will not receive information about current news or services relating to the Controller.

Processing of the personal data of job applicants, applications and CVs

(1) Categories of personal data that may be processed: the natural person’s name, date and place of birth, mother’s name, residential address, photograph, telephone number, e-mail address, and information relating to professional history, experience, qualifications and education.

If, following submission of the application, the Data Subject is invited to a personal interview, the Controller prepares notes of the interview, the contents of which also constitute personal data.

(2) Purposes of processing personal data:

  • identification of the Data Subject;
  • assessment by the Controller of the job application submitted by the Data Subject;
  • participation of the Data Subject in the selection procedure;
  • selection of a Data Subject having the appropriate skills and professional experience for the position advertised by the Controller;
  • contacting the Data Subject and maintaining contact throughout the selection process;
  • offering the Data Subject a future employment opportunity if the Data Subject is not selected by the Controller for the advertised position and, following completion of the selection procedure, has expressly consented to the retention of his or her application materials for this purpose.

(3) Legal basis of processing: except in relation to the possibility of offering a future employment opportunity, the Company processes the data on the basis of pursuing its legitimate interests as an employer (Article 6(1)(f) GDPR) and, where special categories of personal data are involved, concurrently on the basis of Article 9(2)(f) GDPR. In the latter case of a future employment opportunity, after completion of the recruitment procedure the applicant may declare that he or she expressly consents to the continued processing of the application materials for the purpose of possible future recruitment. In that case, the legal basis for the continued processing is the Data Subject’s voluntary consent (Article 6(1)(a) GDPR).

(4) Recipients or categories of recipients of the personal data: the manager authorised to exercise employer’s rights within the Company and employees performing employment-related administrative functions.

(5) Retention period of personal data: where the applicant is successful, the Controller retains the Data Subject’s personal data until termination of the employment relationship; otherwise, the data are retained until the job application has been assessed and are then deleted, unless the Data Subject has expressly requested retention for future employment opportunities. In that case, the Controller processes the application for 1 year from the date of consent or until the Data Subject withdraws consent, whichever occurs earlier.

(6) The Controller shall promptly delete documents submitted by the Data Subject upon the Data Subject’s request. If the Data Subject requests deletion of his or her personal data before completion of the selection process, the Data Subject will no longer be able to participate in that process.

When assessing an application, the Controller also reviews publicly available information on social media platforms (Facebook, LinkedIn, Instagram, X (Twitter), etc.). Such information is processed solely by being viewed; it is not copied, printed or otherwise recorded.

CHAPTER V

PROCESSING OF WEBSITE VISITOR DATA BY THE COMPANY — INFORMATION ON THE USE OF COOKIES

1. General information

The Company’s website uses cookies and other similar technologies, including in particular pixels, tags and other online measurement, identification and tracking technologies.

A cookie is a small data file placed by a website in the visitor’s browser or on the device used by the visitor, enabling the website or a third-party service provider to store certain information and access it again during a subsequent visit.

Cookies and similar technologies may be used, among other purposes, to ensure the proper and secure operation of the website, remember the visitor’s settings, improve the user experience, analyse website traffic and use and, subject to the Data Subject’s consent, measure the effectiveness of online marketing and advertising campaigns, create remarketing or retargeting audiences and display more relevant advertisements.

Information collected through cookies and other online identifiers may constitute personal data, in particular where such information can be linked directly or indirectly to a natural person.

The Data Subject’s consent is not required for cookies and technologies that are strictly necessary for the operation and security of the website, for remembering privacy settings selected by the visitor, or for providing a service expressly requested by the visitor.

Pursuant to Article 160 of the Republic of Serbia’s law on electronic communications, as a general rule the storage of information on terminal equipment or access to information already stored there requires prior information and consent; however, this requirement does not apply to technical storage or access that is strictly necessary for the transmission of a communication or for providing a service expressly requested by the Data Subject.

Cookies, pixels and other tracking technologies that are not strictly necessary, including in particular analytics, performance-measurement, marketing and advertising technologies, are used on the basis of the Data Subject’s prior consent.

The Data Subject is entitled to refuse the use of non-essential cookies. Refusing cookies does not require the visitor to discontinue use of the website; however, certain supplementary functions, such as third-party content, may operate only in a limited manner.

The Data Subject may at any time modify or withdraw previously given consent through the cookie and consent settings available on the website. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.

2. Purposes of processing

The purposes of processing through cookies and similar technologies include in particular:

  • ensuring the proper, continuous and secure operation of the website;
  • managing sessions;
  • detecting and preventing malicious, automated or fraudulent IT activities;
  • remembering the visitor’s cookie and privacy settings;
  • remembering the selected language and other user preferences;
  • making the website more convenient to use;
  • improving the user experience;
  • measuring website traffic;
  • preparing traffic, usage and performance statistics;
  • analysing how visitors use the website, which pages they visit and what actions they perform;
  • developing and optimising the website and its content;
  • measuring the effectiveness of online marketing and advertising campaigns;
  • measuring conversions and other relevant website events;
  • creating remarketing and retargeting audiences;
  • facilitating the display of more relevant and personalised online advertisements;
  • providing embedded third-party content, in particular YouTube videos.

3. Categories of personal data processed

During use of the website and through the application of cookies and similar technologies, the following categories of personal data may be processed in particular, depending on the technology concerned and the Data Subject’s settings:

  • IP address;
  • session identifier;
  • cookie identifiers;
  • other online and pseudonymous identifiers;
  • type and technical characteristics of the device used;
  • type, version and other characteristics of the browser;
  • User Agent data;
  • information relating to the operating system;
  • language and other browser or device settings;
  • date and time of the visit;
  • URL of the page or subpage visited;
  • information relating to the referring page (referrer);
  • actions, clicks and other interactions on the website;
  • page views;
  • data relating to sessions and frequency of visits;
  • traffic source;
  • approximate location information;
  • data relating to conversion events;
  • information relating to the viewing and use of embedded videos;
  • the visitor’s cookie and consent preferences.

4. Legal basis of processing

4.1. Strictly necessary cookies and technologies

The use of cookies that are strictly necessary for the proper and secure operation of the website, management of sessions, remembering the Data Subject’s cookie settings and ensuring IT security does not depend on the Data Subject’s consent.

The legal basis for the related processing of personal data is the Company’s legitimate interest under the relevant provisions of the Republic of Serbia’s law on the protection of personal data. The Company’s legitimate interest is to ensure the secure, reliable and proper operation of the website.

Where the GDPR also applies to the relevant processing, the legal basis is Article 6(1)(f) GDPR.

4.2. Analytics, functional, marketing and other non-essential technologies

The legal basis for the use of cookies and similar technologies that are not strictly necessary, and for the related processing of personal data, is the Data Subject’s prior, freely given, specific and informed consent.

The Serbian law on the protection of personal data defines consent as a freely given, specific, informed and unambiguous indication of the Data Subject’s wishes.

Where the GDPR also applies to the relevant processing, the legal basis is Article 6(1)(a) GDPR.

The Data Subject may modify or withdraw consent at any time through the website’s cookie settings.

5. Technologies used on the website

5.1. Strictly necessary and technical cookies

The website uses cookies and technologies that support its essential operation and security, manage sessions and remember privacy settings.

The website’s current cookie list identifies in particular the following necessary or technical cookies:

Cookie Provider/function Retention period
PHPSESSID PHP – session identification session
__cf_bm Cloudflare Bot Management, security 1 hour
wt_consent WebToffee – storage of cookie consent preferences 1 year
elementor WordPress/Elementor – technical operation of the website no specified expiry
wpEmojiSettingsSupports WordPress – detection of browser technical capabilities session

These cookies are expressly identified in the website’s current Cookie Policy.

5.2. Language and functional cookies

The website also uses functional cookies to support multilingual operation and certain supplementary functions.

The website’s current cookie list includes, among others, the following cookie:

Cookie Provider/function Retention period
wp-wpml_current_language WPML/WordPress – remembering the selected language session

The use of functional cookies — insofar as they are not strictly necessary for providing a service expressly requested by the visitor — is based on the Data Subject’s consent.

5.3. Google Tag Manager

The Company’s website uses Google Tag Manager.

Google Tag Manager is a tag-management system that can be used to manage and load other measurement, analytics and marketing technologies used on the website, such as Google Analytics or other marketing tags. According to Google’s official documentation, Google Tag Manager is used to deploy and manage tags on websites.

The use of Google Tag Manager is not in itself the same as the use of Google Analytics; the nature of the processing depends on which additional tags are activated through Tag Manager.

Analytics or marketing tags that require consent must be configured so that they operate in accordance with the Data Subject’s choices.

5.4. Google Analytics

The Company uses Google Analytics to measure traffic to and use of the website.

The website’s current cookie list identifies, among others, the _ga and _ga_* cookies as Google Analytics cookies. According to Google’s official documentation, Google Analytics uses the _ga cookie to store a client identifier that enables individual users and sessions to be distinguished.

Purposes of processing:

  • measuring website traffic;
  • determining the number of visitors and sessions;
  • measuring page views;
  • analysing traffic sources;
  • analysing use of the website;
  • preparing traffic and performance statistics;
  • developing the website and improving the user experience.

Categories of data processed include in particular:

  • Google Analytics client and cookie identifiers;
  • technical data and approximate location information derived from the IP address;
  • device and browser data;
  • pages visited;
  • page views;
  • time of visit;
  • session data;
  • traffic source;
  • referrer;
  • interactions and events on the website.

Legal basis of processing: the Data Subject’s prior consent.

Recipient of the data: Google, as provider of the Google Analytics service.

According to the website’s current cookie list:

Cookie Purpose Retention period
_ga measurement of visitors, sessions and website traffic 1 year, 1 month and 4 days
_ga_* storage of page-view and Google Analytics session data 1 year, 1 month and 4 days

5.5. LinkedIn Insight Tag (LinkedIn pixel)

The Company uses on the website the online marketing and measurement technology provided by LinkedIn known as the LinkedIn Insight Tag, also referred to as the LinkedIn pixel.

The LinkedIn Insight Tag enables, among other things, the measurement of conversions related to LinkedIn advertising campaigns, the creation of retargeting audiences from website visitors, and the preparation of audience statistics.

Purposes of processing include in particular:

  • measuring the effectiveness of LinkedIn advertisements;
  • measuring conversions;
  • analysing relevant actions performed on the website;
  • campaign and audience analysis;
  • creating target audiences consisting of website visitors;
  • remarketing and retargeting;
  • displaying more relevant online advertisements.

Categories of data processed include in particular:

  • URL of the page visited;
  • referrer;
  • IP address;
  • device and browser characteristics;
  • User Agent;
  • timestamp;
  • online and cookie identifiers;
  • data relating to certain actions and conversions performed on the website.

According to LinkedIn’s official information, the Insight Tag may collect, among other things, URL, referrer, IP address, device, browser and timestamp data.

Legal basis of processing: the Data Subject’s prior consent.

Recipient of the data: LinkedIn, as provider of the LinkedIn Insight Tag and related advertising services.

The website’s current cookie list includes the following LinkedIn-related cookies:

Cookie Purpose Retention period
li_gc LinkedIn cookie consent preferences 6 months
lidc LinkedIn data-centre selection/technical operation 1 day
bcookie browser identification, LinkedIn advertising tags 1 year

5.6. YouTube and embedded videos

The website uses embedded videos and related functions provided by YouTube.

When YouTube content is displayed, played and used, YouTube and/or Google may use cookies and other online identifiers.

Purposes of processing include in particular:

  • displaying video content;
  • enabling video playback;
  • ensuring the technical operation of the video player;
  • remembering user and privacy settings;
  • measuring video views and interactions;
  • ensuring service security;
  • in certain cases, providing personalised or advertising functions.

Categories of data processed: in particular the IP address, online and cookie identifiers, device and browser data, and data relating to viewing the video and interactions with the video.

The website’s current cookie list includes, among others, the following YouTube cookies:

Cookie Purpose Retention period
VISITOR_PRIVACY_METADATA storage of the user’s cookie/privacy status 6 months
VISITOR_INFO1_LIVE video-player and bandwidth settings 6 months
ytidb::LAST_RESULT_ENTRY_KEY remembering a previous YouTube interaction no specified expiry
YSC tracking views of embedded YouTube videos session
__Secure-YNID security/fraud-prevention function 6 months
__Secure-ROLLOUT_TOKEN management of YouTube feature rollout and testing 6 months

The website’s cookie list also records the __Secure-YEC cookie as previously detected/expired.

The use of non-essential YouTube technologies is based on the Data Subject’s prior consent.

Recipient of the data: Google/YouTube, as provider of the video-sharing and related technology services.

5.7. Cloudflare

The website uses Cloudflare services, among other purposes, to support website security and to detect automated and malicious traffic.

According to the website’s current cookie list, Cloudflare uses the __cf_bm cookie for the operation of Cloudflare Bot Management, with a current retention period of 1 hour.

Purpose of processing: ensuring the security of the website and its IT infrastructure, detecting automated and malicious traffic, and preventing cyberattacks.

Legal basis of processing: the Company’s legitimate interest in ensuring the proper and secure operation of the website.

5.8. WebToffee Cookie Consent

The website uses WebToffee Cookie Consent technology to manage and remember the visitor’s cookie consent choices.

The wt_consent cookie stores the cookie settings selected by the visitor so that the website can take them into account during subsequent visits.

According to the website’s current cookie list, the retention period of the wt_consent cookie is 1 year.

Purpose of processing: documenting and remembering the visitor’s consent and cookie preferences.

Legal basis of processing: the Company’s legitimate interest and, under the applicable electronic communications rules, the technical implementation of the privacy settings selected by the visitor.

5.9. Leadinfo

The website uses the B2B lead-generation and website analytics service provided by Leadinfo B.V. Leadinfo recognises visits from companies primarily on the basis of IP addresses and may match a visit with publicly available company information.

Purposes of processing: identifying companies that visit the website, analysing website use by business visitors, and supporting B2B marketing and business development.

Categories of data processed may include in particular the IP address, pages visited, date and time of the visit, referrer information, browser or session identifiers, and company information matched to the relevant business IP address.

Company recognition is primarily based on the IP address and does not itself require cookies. If enabled, Leadinfo may also use first-party cookies or similar technologies for additional website and session analytics.

Legal basis of processing: the Controller’s legitimate interest in B2B business development in relation to company identification, subject to the applicable balancing test. Where non-essential Leadinfo cookies or similar technologies are used, their use and the related processing are based on the Data Subject’s prior consent.

Leadinfo may use first-party cookies named _li_id.xxxx and _li_ses.xxxx for visitor and session analytics. Depending on the cookie, the retention period is the current session or up to 2 years; the website’s current cookie settings interface shall display the exact cookie names and retention periods in use.

Recipient of the data: Leadinfo B.V., as provider of the Leadinfo service. Leadinfo also provides an opt-out mechanism for future recognition of visits.

The current list of cookies used on the site is the following:

Necessary

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

Functional

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

Analytics

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

Performance

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

Advertisement

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

Others

Other cookies are those that are being identified and have not been classified into any category as yet.

6. Recipients of personal data

Personal data relating to cookies and similar technologies may be accessed by employees and other persons engaged by the Company who perform tasks relating to operation and development of the website, IT security, analytics or online marketing.

Depending on the technology used, the Data Subject’s choices and the role of the relevant service provider, personal data may in particular become accessible to the following service providers:

  • Google, in connection with Google Analytics, Google Tag Manager and YouTube services;
  • LinkedIn, in connection with the LinkedIn Insight Tag and LinkedIn-related online marketing, analytics and advertising services;
  • Leadinfo, in connection with B2B website visitor identification, analytics and lead generation;
  • Cloudflare, in connection with website security and bot protection;
  • the Company’s website, hosting and IT service providers;
  • service providers responsible for maintenance and development of the website.

Where an external service provider processes personal data outside the Republic of Serbia or transfers personal data there, the transfer shall take place subject to the conditions and appropriate safeguards prescribed by the applicable data protection rules.

7. Duration of processing

The retention period of cookies and other online identifiers depends on their purpose and type.

Certain cookies operate only for the duration of the current session and are deleted after the browser is closed. Other cookies may be stored for a period of several hours, days, months or more than one year.

The Company makes available in the website’s current cookie list and cookie settings interface the current name, purpose and retention period of each cookie used on the website.

The current cookie list includes, among others, the following retention periods:

  • PHPSESSID: session;
  • __cf_bm: 1 hour;
  • wt_consent: 1 year;
  • wpEmojiSettingsSupports: session;
  • wp-wpml_current_language: session;
  • _ga: 1 year, 1 month and 4 days;
  • _ga_*: 1 year, 1 month and 4 days;
  • li_gc: 6 months;
  • lidc: 1 day;
  • bcookie: 1 year;
  • _li_id.xxxx / _li_ses.xxxx (Leadinfo): depending on the cookie, session or up to 2 years;
  • VISITOR_PRIVACY_METADATA: 6 months;
  • VISITOR_INFO1_LIVE: 6 months;
  • YSC: session;
  • __Secure-YNID: 6 months;
  • __Secure-ROLLOUT_TOKEN: 6 months.

8. Managing cookie settings and withdrawing consent

On the visitor’s first visit to the website, the Data Subject may decide, through the cookie or consent management interface displayed, whether to permit the use of non-essential cookies and other technologies.

The Data Subject must be given the opportunity to:

  • consent to the use of non-essential cookies;
  • reject them;
  • make separate choices between individual cookie categories;
  • modify a previous choice at a later time;
  • withdraw consent at any time.

According to the website’s current Cookie Policy, the visitor may reopen the cookie settings at any time through the “Consent Preferences” function, modify his or her choices or withdraw consent.

The Data Subject is not required to provide his or her name or e-mail address in order to modify or withdraw consent.

In addition, the Data Subject may delete or restrict the use of cookies through the settings of his or her browser. Complete browser-level blocking of cookies may, however, affect the operation of certain website functions.

CHAPTER VI

INFORMATION ON THE RIGHTS OF DATA SUBJECTS

I. Summary of your rights:

You may request the following from the Controller:

  • information concerning the processing of your personal data (both prior to commencement of processing and during processing). Your right to information is ensured through the preparation and publication of this Privacy Notice;
  • access to your personal data (making your personal data available to you by the Controller);
  • rectification and completion of your personal data;
  • erasure or restriction (blocking) of your personal data, except where processing is mandatory;
  • you have the right to data portability;
  • you may object to the processing of your personal data;
  • you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you;
  • you have the right to seek legal remedy.

You may submit a written Data Subject request to the Controller in accordance with the chapter on enforcement of data protection rights and remedies. The Controller shall comply with a lawful request within no more than 30 days and shall notify you by letter sent to the contact details provided by you.

II. Your rights in detail:

Right to information (based on the Controller’s obligations laid down in Articles 13–14 GDPR)

In accordance with the chapter on enforcement of data protection rights and remedies, you may request written information from the Controller as to:

  • which of your personal data are processed;
  • the legal basis of processing;
  • the purpose for which the data are processed;
  • the source from which the data were obtained;
  • the period for which the data are processed;
  • whether the Controller uses a processor and, if so, the name and address of the processor and its activities related to the processing;
  • to whom, when and on what legal basis the Controller has granted access to which personal data, or to whom it has transferred your personal data;
  • the circumstances and effects of any personal data breach and the measures taken to remedy it.

Right of access (Article 15 GDPR)

You are entitled to obtain confirmation from the Controller as to whether or not personal data concerning you are being processed and, where such processing is taking place, to obtain access to the personal data being processed. You may request this in writing from the Controller in accordance with the chapter on enforcement of data protection rights and remedies.

The Controller shall provide you with a copy of the personal data undergoing processing, unless prevented by another legal requirement. Where you submit the request electronically, the information shall be provided in a commonly used electronic format unless you request otherwise.

Right to rectification and completion (Article 16 GDPR)

In accordance with the chapter on enforcement of data protection rights and remedies, you may request in writing that the Controller amend any of your personal data (for example, you may change your e-mail address or postal contact details at any time, or request the Controller to rectify any inaccurate personal data it processes about you).

Taking into account the purposes of processing, you are entitled to request that incomplete personal data processed by the Controller be completed as appropriate.

Right to erasure (Article 17 GDPR)

Erasure of personal data may principally be requested where our processing is based on your voluntary consent, for example where you have consented to our processing your telephone number or e-mail address. In such cases, we will delete your personal data.

You may withdraw your voluntary consent at any time. You are hereby informed that withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. For identification purposes, please state your name and e-mail address in your deletion request.

Right to restriction of processing (blocking) (Article 18 GDPR)

In accordance with the chapter on enforcement of data protection rights and remedies, you may request in writing that the Controller restrict processing of your personal data (by clearly marking the restricted nature of the processing and ensuring separate handling from other data).

The restriction shall remain in place for as long as the reason stated by you makes storage of the data necessary. You may request restriction, for example, where you consider that the Controller has processed a submission unlawfully but the submission must not be deleted because it is required for regulatory or court proceedings initiated by you.

In such a case, the Controller shall continue to store the personal data (for example, the relevant submission) until contacted by the authority or court and shall delete the data thereafter.

Right to data portability (Article 20 GDPR)

In accordance with the provisions on enforcement of data protection rights and remedies, you may request in writing to receive the personal data concerning you which you have provided to the Controller in a structured, commonly used and machine-readable format, and you have the right to transmit those data to another controller without hindrance from the Controller, where:

  • the processing is based on consent pursuant to Article 6(1)(a) GDPR or Article 9(2)(a) GDPR; or
  • the processing is based on a contract pursuant to Article 6(1)(b) GDPR; and
  • the processing is carried out by automated means.

Right to object (Article 21 GDPR)

You may object in writing, using the contact details set out in the chapter on enforcement of data protection rights and remedies, to the processing of your personal data where such processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party under Article 6(1)(f) of the General Data Protection Regulation, including profiling based on that provision.

In such a case, the Controller shall no longer process the personal data unless the Controller demonstrates compelling legitimate grounds for the processing which override the Data Subject’s interests, rights and freedoms, or grounds relating to the establishment, exercise or defence of legal claims.

Automated individual decision-making, including profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

This right shall not apply where the decision:

  1. is necessary for entering into, or performance of, a contract between you and the Controller;
  2. is authorised by Union or Member State law applicable to the Controller which also lays down suitable measures to safeguard the Data Subject’s rights and freedoms and legitimate interests; or
  3. is based on your explicit consent.

In the cases referred to in points (a) and (c) above, the Controller shall implement suitable measures to safeguard your rights, freedoms and legitimate interests, including at least the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.

CHAPTER VII

ENFORCEMENT OF DATA PROTECTION RIGHTS AND AVAILABLE REMEDIES

Contacting the Controller

Before initiating court or regulatory proceedings, we recommend that you send the Controller your enquiry or complaint concerning the processing of your personal data so that we may investigate and satisfactorily remedy the matter, and so that, where justified, we may comply with any request or claim made under the chapter concerning Data Subject rights.

Where you seek to exercise any right relating to processing under the chapter concerning Data Subject rights, request information regarding processing, or submit an objection or complaint regarding processing, the Controller shall investigate the matter without undue delay and within the period prescribed by the applicable laws, take action in relation to the request and provide you with information on the matter. Where necessary, having regard to the complexity and number of requests, this period may be extended in accordance with the applicable legislation.

Where you submit your request electronically, the information shall, where possible, be provided electronically unless you request otherwise. If the Controller does not take action on your request without undue delay, but no later than within the period prescribed by law, it shall inform you of the reasons for not taking action or refusing the request, and of your right to initiate court or regulatory proceedings as set out below.

In order to exercise your rights in connection with processing, or if you have any questions or concerns regarding personal data processed by the Controller, wish to request information, submit a complaint, or exercise any right set out in the chapter concerning Data Subject rights, you may submit a written Data Subject request by post or e-mail using the contact details of the Controller:

Controller contact details:

T-1 ABRAZIV” D.O.O. 

Registered office: Sencanski put 59/b, 24430 Ada, Serbia

Represented by: Tóth Árpád

Telephone: +381 24 854 585

E-mail: office@t-1.rs

Initiating proceedings before a supervisory authority

In Serbia, you may lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti (15 Bulevar kralja Aleksandra, 11000 Belgrade, Republic of Serbia, +381 11 3408 900, office@poverenik.rs)

Where the GDPR applies, you may also lodge a complaint with the competent supervisory authority in the EU or EEA Member State of your habitual residence, place of work or place of the alleged infringement.

You may request an investigation or the commencement of regulatory proceedings for the purpose of enforcing your rights on the grounds that an infringement has occurred, or that there is an imminent risk of an infringement, in connection with the processing of your personal data, including in particular:

  • if you consider that the Controller restricts the exercise of the Data Subject rights set out in the chapter concerning Data Subject rights or rejects a request to exercise such rights (request for an investigation); and
  • if you consider that, in processing your personal data, the Controller or a processor engaged by or acting on the instructions of the Controller infringes requirements concerning the processing of personal data laid down by law or by a binding legal act of the European Union (request for regulatory proceedings).

Initiating court proceedings

You may bring proceedings before a court if you consider that the Controller processes personal data in breach of requirements governing the processing of personal data laid down by law or by a binding legal act of the European Union.

CHAPTER VIII

DATA SECURITY

The Controller undertakes to ensure the security of the personal data it processes. Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks of varying likelihood and severity for the rights and freedoms of natural persons, the Controller implements appropriate technical and organisational measures and adopts procedural rules to ensure that collected, stored and otherwise processed data are protected and to prevent their destruction, unauthorised use and unauthorised alteration.

The Controller also undertakes to require every third party to whom data are transferred or disclosed on any legal basis to comply with data security requirements. The Controller shall ensure that unauthorised persons cannot access, disclose, transmit, alter or erase the data processed.

Processed data may be accessed only by the Controller and its employees, and by processors and recipients engaged by the Controller, in accordance with applicable access levels. The Controller shall not disclose such data to third parties who are not authorised to access them. Employees of the Controller and the Processor may access personal data only in accordance with defined roles, procedures and permission levels established by the Controller and the Processor.

For the security of its IT systems, the Controller protects those systems by means of a firewall and uses anti-virus scanning and anti-virus software to prevent external and internal data loss. The Controller has also arranged for appropriate monitoring of incoming and outgoing communications, irrespective of form, in order to prevent misuse.

The Controller and the Processor classify and handle personal data as confidential information. In order to protect data files processed electronically in different records, the Controller ensures that, except where required by law, data stored in separate records cannot be directly linked and attributed to the Data Subject.

The Controller ensures a level of security appropriate to the risk, including, where appropriate, among other measures:

  • the ability to ensure the ongoing confidentiality, integrity, availability and resilience of systems and services used for processing personal data (security of operations and development, intrusion prevention and detection, prevention of unauthorised access);
  • the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident (prevention of data leakage; vulnerability and incident management);
  • a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of processing (business continuity, protection against malicious code, secure storage, transfer and processing of data, and security training for employees).

In determining the appropriate level of security, particular account shall be taken of the risks presented by processing, especially risks arising from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed.

You are hereby informed that further detailed information concerning data security may be requested from the Controller (e-mail: office@t-1.rs).

CHAPTER IX

TRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES OR INTERNATIONAL ORGANISATIONS

1.) Transfers based on an adequacy decision (Article 45 GDPR)

Pursuant to Article 45 GDPR, personal data may be transferred to a third country or an international organisation where the European Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question ensures a level of protection equivalent to the level of data protection in the European Union. Article 45(2) GDPR sets out the general criteria to be taken into account by the Commission when assessing the adequacy of the level of protection. The Commission periodically reviews, on a regular basis, the adequacy of the level of protection in countries, territories, sectors or international organisations in respect of which it has previously adopted an adequacy decision and, if it determines that an adequate level of protection is no longer ensured, it shall repeal, amend or suspend its decision.

2.) Trans-Atlantic Data Privacy Framework

On 10 July 2023, the European Commission adopted an adequacy decision concerning the new EU–US Data Privacy Framework, finding that personal data may be transferred safely from the European Union to US companies participating in the new framework and that the United States ensures an adequate level of protection for personal data transferred from the EU to participating US companies. A prerequisite for participation in the Trans-Atlantic Data Privacy Framework is that US companies, acting as controllers, undertake to implement data protection measures compliant with the GDPR.

3.) Transfers subject to appropriate safeguards (Article 46 GDPR)

In the absence of an adequacy decision under Article 45 GDPR, a controller or processor may transfer personal data to a third country or an international organisation only where appropriate safeguards have been provided in relation to the transfer and enforceable Data Subject rights and effective legal remedies are available.

The Controller hereby informs you that, in the course of processing activities, the personal data you provide may be transferred to a third country.

CHAPTER X

MISCELLANEOUS

The Controller reserves the right to amend this Privacy Notice unilaterally with effect for the future. The Privacy Notice in force from time to time is available on the website at https://t-1ada.com/. Data Subjects will be informed of amendments through the Controller’s website.

Dated at Ada, 17 August 2026

T-1 ABRAZIV” D.O.O. 

Represented by: Tóth Árpád