🔒 Politika privatnosti / Privacy Policy

Planeta računari: kako sakupljamo, koristimo i štitimo Vaše lične podatke.

📋 Verzija 1.1 📅 Stupanje na snagu 21. maj 2026. 🔄 Ažurirano 13. avgust 2026.

1 Ko smo

Ova politika privatnosti opisuje kako Planeta računari (u daljem tekstu "Planeta", "mi", "nas", "naš") sakuplja, koristi i deli Vaše lične podatke kada koristite naše proizvode i usluge.

Podaci o rukovaocu:

  • Naziv: Planeta računari, Aleksander Krsmanović PR
  • Sedište: Milice Pavlović 32/3/12, 32000 Čačak, Republika Srbija
  • Matični broj: 62397314
  • PIB: 103957267
  • Email: office@planeta-racunari.rs
  • Telefon: +381 60 722 31 00
  • Veb sajt: https://planeta-racunari.rs

Ova politika se primenjuje na:

  • Veb sajt https://planeta-racunari.rs i sve njegove pod-stranice
  • QR vCard Pro: prodajna stranica /qr-license/buy/, klijent portal, license server, i sam plug-in instaliran na sajtovima naših klijenata
  • Planeta Booking Pro: /planeta-booking-pro/ i prodajni tok koji sa te stranice vodi
  • Vizuelni dokaz, alat za analizu sajta: /testiranje-sajta/

2 Koje podatke sakupljamo

2.1 Kada kupujete licencu za neki od naših proizvoda

Kada izvršite kupovinu licence, na primer za QR vCard Pro preko /qr-license/buy/ ili za Planeta Booking Pro, sakupljamo:

  • Identifikacioni podaci: ime, prezime, naziv firme (ako ste pravno lice)
  • Kontakt podaci: email adresa, broj telefona (opciono)
  • Podaci za fakturisanje: adresa za fakturu, PIB (za pravna lica)
  • Podaci o plaćanju: broj kreditne kartice se NE čuva kod nas, obrađuje ih isključivo naš platni procesor (Stripe ili WSPay) prema njihovim sigurnosnim standardima (PCI DSS)
  • Licencni podaci: license key, datum kupovine, izabrani tier (Personal/Single/5 Sites/Unlimited/Agency)
  • Tehnički podaci: IP adresa, tip uređaja i pretraživača (za potrebe sprečavanja prevara)

2.2 Kada koristite naš license server

Kada Vaš plug-in komunicira sa našim license serverom, sakupljamo:

  • Domene aktivacije: lista domena na kojima je Vaš license key aktiviran
  • Datum i vreme aktivacije / deaktivacije
  • Provera ažuriranja: datumi automatskih provera, verzija plug-ina koju koristite
  • IP adresa servera koji se konektuje

2.3 Kada koristite klijent portal

Kada se logujete na naš klijent portal, sakupljamo:

  • Login podaci: korisničko ime, hashovana lozinka (mi NIKADA ne vidimo Vašu lozinku u čistom tekstu)
  • Sesijski podaci: vreme prijave, IP adresa sesije
  • Podaci o aktivnostima: koje QR kartice ste kreirali, kada ste ih ažurirali

2.4 Kada posetioci skeniraju QR kartice naših klijenata

VAŽNA NAPOMENA O ULOGAMA: Kada krajnji korisnik (osoba sa telefonom) skenira QR kod naših klijenata, podaci koje plug-in sakuplja pripadaju našem klijentu kao rukovaocu podataka. Planeta je u ovom slučaju obrađivač podataka (Data Processor), a naš klijent je rukovalac (Data Controller).

Podaci koji se sakupljaju:

  • Tehnički podaci o skeniranju: datum i vreme, tip uređaja, pretraživač, referer URL
  • IP adresa: podrazumevano se čuva kao SHA256+salt hash, što znači da originalna IP adresa NE MOŽE biti rekonstruisana. Ovo omogućava brojanje "jedinstvenih skenova" bez čuvanja stvarne IP adrese.
  • Geografska lokacija (opciono): ako je naš klijent uključio ovu funkciju, šaljemo IP ka servisu ip-api.com (sa sedištem u Australiji) radi dobijanja gradskog/državnog nivoa lokacije. Tačna IP adresa se ne čuva nigde.
  • Podaci putem Contact Exchange forme (opciono): ime, email, telefon, firma, poruka, sakupljaju se SAMO uz eksplicitnu saglasnost posetioca preko opt-in čekboksa, i idu direktno klijentu kao rukovaocu.

2.5 Kada posećujete naš veb sajt

  • Serverski logovi: IP adresa, tip pretraživača, posećene stranice i vreme posete, koje beleži sam veb server. Ne koristimo nijedan servis za praćenje posetilaca.
  • Kolačići: vidite Sekciju 10 ispod

2.6 Kada koristite alat za analizu sajta (Vizuelni dokaz)

Samo merenje je besplatno i ne traži nijedan Vaš podatak. Unesete adresu sajta i dobijete nalaz na ekranu. Ako se tu zaustavite, ništa se ne upisuje.

Ako zatražite izveštaj na svoju adresu, obrađujemo:

  • Kontakt podaci: ime i prezime, email adresa, i broj telefona i naziv firme ako ih unesete
  • Podaci o sajtu: adresa sajta koji ste merili i adresa sajta sa kojim ste ga poredili, ako ste je uneli
  • Rezultat merenja: ocene, izmerena vremena i nalazi koje je alat izračunao
  • Tehnički podaci: jezik i vreme merenja, i potvrda da ste dali saglasnost

Uz to nastaje i troje što ne unosite Vi:

  • Nasumičan ključ za link ka izveštaju. Izveštaj stoji na tajnoj adresi koja se ne može pogoditi i otvara se samo tim linkom.
  • Broj otvaranja izveštaja i vreme poslednjeg otvaranja. Link je trajan i može da se prosledi bilo kome, pa beležimo koliko je puta izveštaj otvoren. Ne beležimo ko ga je otvorio.
  • Otisak IP adrese, u obliku jednosmernog SHA256 heša pomešanog sa tajnim ključem sajta, iz kog se adresa ne može vratiti. Služi samo da isti posetilac ne može da pokrene neograničen broj merenja.
Bez saglasnosti nema upisa. Dok ne štiklirate saglasnost, ne upisuje se nijedan podatak i izveštaj se ne šalje. Alat ne postavlja kolačiće i ne ostavlja ništa u Vašem pretraživaču.

3 Pravni osnov za obradu

U skladu sa GDPR Članom 6, naš pravni osnov za obradu Vaših ličnih podataka je:

AktivnostPravni osnov
Obrada kupovine i aktivacija licenciIzvršenje ugovora (Član 6(1)(b))
Sakupljanje podataka o skeniranju (hashed IP)Legitimni interes našeg klijenta (Član 6(1)(f)), analitika sopstvenih QR kartica
Contact Exchange (sa opt-in saglasnošću)Eksplicitna saglasnost (Član 6(1)(a))
Geografska lokacija via ip-api.comLegitimni interes rukovaoca, uz obavezu transparentnosti
Podaci iz forme za analizu sajta (ime, email, telefon, podaci o sajtu)Saglasnost (Član 6(1)(a)), data štikliranjem pre slanja i opoziva se u svakom trenutku
Otisak IP adrese u alatu za analizu sajtaLegitimni interes (Član 6(1)(f)), zaštita servisa od automatske zloupotrebe
Broj otvaranja izveštaja o analiziLegitimni interes (Član 6(1)(f)), zaštita sopstvenog rada, jer izveštaj nije namenjen prosleđivanju trećim licima ni upotrebi u tuđim poslovnim ponudama
Marketing email-ovi (newsletter)Saglasnost (Član 6(1)(a)), uvek možete odjaviti
Računovodstveni i poreski podaciZakonska obaveza (Član 6(1)(c)), srpski Zakon o računovodstvu
Sprečavanje prevara (fraud detection)Legitimni interes (Član 6(1)(f))

4 Kako koristimo Vaše podatke

Vaše podatke koristimo isključivo za:

  • Pružanje usluge: dostava license key-a, aktivacija plug-ina, podrška
  • Izrada i slanje izveštaja o analizi sajta koji ste zatražili, i kontakt sa Vama povodom nalaza iz tog izveštaja
  • Komunikacija: transakcioni email-ovi (potvrda kupovine, dostava licence, support odgovori)
  • Sigurnost: detekcija sumnjivih aktivnosti, sprečavanje zloupotrebe
  • Pravne obaveze: izdavanje računa, čuvanje računovodstvene evidencije
  • Poboljšanje usluge: anonimizovani statistički podaci o korišćenju plug-ina

Vaše podatke NE PRODAJEMO trećim licima. NE KORISTIMO ih za behavioralni marketing. NE PROFILIŠEMO Vas.

5 Sa kim delimo Vaše podatke

Delimo Vaše podatke isključivo sa sledećim trećim licima, i to samo u meri koja je neophodna:

5.1 Platni procesori

  • Stripe, Inc. (ako koristimo Stripe), sedište: San Francisco, USA. Procesira plaćanja kreditnim karticama. Privacy Policy: https://stripe.com/privacy
  • WSPay (ako koristimo WSPay), sedište: Zagreb, Hrvatska. Procesira plaćanja za balkansko tržište. Privacy Policy: https://wspay.eu/privacy

5.2 Hosting i infrastruktura

  • United Internet d.o.o. (posluje pod brendom UNLIMITED.RS), Milutina Milankovića 1c, 11073 Beograd, Republika Srbija. PIB: 109154021, matični broj: 21133710. Hostuje naš sajt, license server i bazu u kojoj stoje podaci iz formi. Serverske lokacije ovog provajdera su Srbija i Holandija (Evropski ekonomski prostor). Pravilnik o obradi podataka o ličnosti: https://unlimited.rs/pravilnik-podaciolicnosti.pdf

5.3 Email servisi

  • Resend (pravno lice: Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, SAD). Šalje transakcione poruke, izveštaje o analizi sajta i obaveštenja korisnicima. Servis prima ime primaoca, email adresu i sadržaj poruke, i obrađuje ih isključivo po našem nalogu. Vodi evidenciju o tome da li je poruka isporučena, odbijena ili prijavljena kao neželjena, kako bismo prestali da šaljemo na adrese koje to ne žele. Servis te podatke ne koristi za sopstvene svrhe i ne prosleđuje ih trećim licima. Privacy Policy: https://resend.com/legal/privacy-policy
  • Spisak podobrađivača tog servisa je javan: https://resend.com/legal/subprocessors

5.4 Geografska lokacija (samo ako klijent uključi)

  • ip-api.com (Salesforce.com Inc., Brisbane, Australija), geografska lokacija po IP-u. Privacy Policy: https://ip-api.com/docs/legal

5.5 Merenje performansi sajta

  • Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Irska). Merenje brzine i tehničkog stanja sajta radi servis Google PageSpeed Insights. Merenje pokreće pretraživač posetioca, pa Google pri tome prima adresu sajta koji se meri, IP adresu posetioca i podatke o njegovom pretraživaču, isto kao pri svakoj drugoj poseti Google servisima. Ime, email adresu i broj telefona Google ne dobija. Privacy Policy: https://policies.google.com/privacy

5.6 Zakonska obaveza

Možemo otkriti Vaše podatke nadležnim organima ako to zakon nalaže (npr. po nalogu suda, poreske inspekcije, ili u slučaju istrage prevare).

6 Međunarodni prenos podataka

Neki od naših procesora se nalaze van Evropske ekonomske zone (EEZ) i Srbije:

  • Stripe (SAD): oslanja se na Standardne ugovorne klauzule (SCC) odobrene od strane Evropske komisije.
  • Resend (SAD): prenos se obavlja na osnovu ugovora o obradi podataka koji sadrži Standardne ugovorne klauzule (SCC) Evropske komisije. Servis je uz to sertifikovan po okviru EU-U.S. Data Privacy Framework.
  • Google Ireland Limited (Irska, EEZ): svaki dalji prenos van EEZ se obavlja po pravilima tog društva i njegovim standardnim ugovornim klauzulama.
  • ip-api.com (Australija): pruža samo opcione geografske podatke na nivou grada, bez čuvanja IP adrese.
  • Hosting (Srbija i Holandija): serverske lokacije našeg hosting provajdera su Srbija i Holandija, koja je u Evropskom ekonomskom prostoru.

Sve prenose vršimo uz odgovarajuće zaštitne mere u skladu sa članovima 44-49 GDPR-a.

7 Koliko dugo čuvamo Vaše podatke

Vrsta podatakaPeriod čuvanja
Računovodstveni podaci (fakture, plaćanja)10 godina (srpski Zakon o računovodstvu)
Aktivne licence i license key-eviDoživotno (dok licenca važi) ili dok ne zatražite brisanje
Login sesije (klijent portal)30 dana od poslednje aktivnosti
Hashovani IP-ovi sa QR skeniranja365 dana (default, naš klijent može da konfiguriše kraći period)
Contact Exchange podaciDok rukovalac (naš klijent) ne obriše ili dok subjekt ne zatraži brisanje
Kontakt i izveštaj iz analize sajta24 meseca od poslednjeg kontakta, ili odmah na Vaš zahtev
Broj otvaranja izveštaja o analiziKoliko i sam izveštaj, briše se zajedno sa njim
Email marketing podaciDo odjave ili do 24 meseca neaktivnosti
Tehnički logovi (server logs)90 dana
Backup-ovi30 dana rotirajući

Po isteku ovih perioda, podaci se brišu ili anonimiziraju.

8 Vaša prava

U skladu sa GDPR (i srpskim ZZPL gde je primenjivo), imate sledeća prava:

PravoŠta to znači
Pravo na pristupMožete tražiti kopiju svih podataka koje imamo o Vama
Pravo na ispravkuMožete tražiti ispravku netačnih podataka
Pravo na brisanje ("right to be forgotten")Možete tražiti brisanje Vaših podataka, uz neka ograničenja, npr. ne možemo da brišemo računovodstvene podatke pre isteka 10 godina
Pravo na ograničenje obradeMožete tražiti da privremeno obustavimo obradu
Pravo na prenosivost podatakaMožete tražiti svoje podatke u strukturisanom, mašinsko-čitljivom formatu (JSON, CSV)
Pravo na prigovorMožete uložiti prigovor na obradu zasnovanu na legitimnom interesu
Pravo na odjavu pristankaAko je obrada zasnovana na saglasnosti, možete je povući bilo kada
Pravo na žalbu nadzornom organuMožete podneti žalbu Povereniku za informacije od javnog značaja i zaštitu podataka o ličnosti Republike Srbije (poverenik.rs) ili nadležnom EU organu ako ste iz EU

Kako da ostvarite ova prava: Pošaljite email na office@planeta-racunari.rs sa naslovom "[GDPR ZAHTEV] [tip zahteva]". Odgovaramo u roku od 30 dana od prijema zahteva. Identitet ćemo verifikovati pre obrade osetljivih zahteva (npr. brisanja).

Odjava sa poruka: svaka poruka koju Vam pošaljemo sadrži link za odjavu. Jedan klik i više Vam ne šaljemo ništa, bez objašnjavanja i bez pitanja.

9 Bezbednost podataka

Primenjujemo sledeće tehničke i organizacione mere za zaštitu Vaših podataka:

Tehničke mere:

  • HTTPS/TLS enkripcija za sav saobraćaj
  • Lozinke se čuvaju kao bcrypt/argon2 hash-evi (nikad u čistom tekstu)
  • IP adrese se čuvaju kao SHA256+salt hash, nikada u čitljivom obliku
  • Izveštaji o analizi sajta se otvaraju linkom sa nasumičnim ključem koji se ne može pogoditi
  • Redovni backup-ovi sa enkripcijom
  • Firewall i intrusion detection na nivou hosting providera
  • Redovne sigurnosne nadogradnje WordPress core-a, plug-inova i tema
  • Restrikcija pristupa license serveru po IP listi i autentikaciji

Organizacione mere:

  • Pristup ličnim podacima imaju samo ovlašćena lica (Aleksander Krsmanović)
  • Politika lozinki sa minimalnom dužinom i kompleksnošću
  • Dvofaktorska autentikacija (2FA) za admin pristup
  • Politika "least privilege" za sve sistemske naloge

Šta NE garantujemo: Iako preduzimamo razumne mere, nijedan sistem nije 100% siguran. U slučaju data breach-a koji utiče na Vaša prava i slobode, obavestićemo Vas u roku od 72 sata od saznanja, kao i nadležni nadzorni organ.

10 Kolačići (Cookies)

Analitički i marketinški kolačići

  • Nema ih. Ovaj sajt ne koristi Google Analytics ni bilo koji drugi servis koji prati posetioce, pa nema ni kolačića koji bi Vas pratili sa strane na stranu ili sa sajta na sajt.

Tehnički kolačići

  • Kolačiće postavlja sam WordPress, i to radi prijave u administraciju i pamćenja podešavanja prijavljenog korisnika. Posetiocu koji nije prijavljen se po pravilu ne postavlja nijedan.
Alat za analizu sajta ne postavlja nijedan kolačić i ne ostavlja ništa u Vašem pretraživaču.

Izbor jezika na ovoj stranici pamti se u lokalnom skladištu Vašeg pretraživača (local storage). To nije kolačić i ne šalje se nikome.

Kolačiće u svakom trenutku možete obrisati ili unapred blokirati kroz podešavanja svog pretraživača.

11 Maloletna lica

Naše usluge nisu namenjene osobama mlađim od 16 godina. Svesno NE sakupljamo podatke od maloletnih lica. Ako ste roditelj ili staratelj i saznate da nam je Vaše dete dalo svoje podatke, kontaktirajte nas na office@planeta-racunari.rs i odmah ćemo ih izbrisati.

12 Izmene ove politike

Ovu politiku možemo povremeno menjati. Materijalne izmene ćemo komunicirati:

  • Email obaveštenjem aktivnim klijentima (najmanje 30 dana pre stupanja na snagu)
  • Banner-om na naslovnoj strani sajta
  • Datumom "Ažurirano" na vrhu ovog dokumenta

Verzioniramo politiku, pa možete videti stare verzije na zahtev.

13 Kontakt

Za sva pitanja, žalbe, ili ostvarivanje Vaših prava, kontaktirajte nas:

Planeta računari (Aleksander Krsmanović)

Nadzorni organ u Srbiji: Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti

  • Web: https://www.poverenik.rs
  • Email: office@poverenik.rs
  • Adresa: Bulevar kralja Aleksandra 15, 11120 Beograd
  • Telefon: +381 11 3408 900

Nadzorni organi u EU: Lista nadzornih organa po državama: https://edpb.europa.eu/about-edpb/about-edpb/members_en

1 Who We Are

This Privacy Policy describes how Planeta računari (hereinafter "Planeta", "we", "us", "our") collects, uses, and shares your personal data when you use our products and services.

Data Controller details:

  • Legal Name: Planeta računari, Aleksander Krsmanović PR
  • Registered Address: Milice Pavlović 32/3/12, 32000 Čačak, Serbia
  • Registration Number: 62397314
  • Tax ID: 103957267
  • Email: office@planeta-racunari.rs
  • Phone: +381 60 722 31 00
  • Website: https://planeta-racunari.rs

This policy applies to:

  • Website https://planeta-racunari.rs and all sub-pages
  • QR vCard Pro: sales page /qr-license/buy/, client portal, license server, and the plug-in itself installed on our clients' sites
  • Planeta Booking Pro: /planeta-booking-pro/ and the purchase flow it leads to
  • Vizuelni dokaz, the website analysis tool: /testiranje-sajta/

2 What Data We Collect

2.1 When You Purchase a License for One of Our Products

When you purchase a license, for example QR vCard Pro via /qr-license/buy/ or Planeta Booking Pro, we collect:

  • Identification: first name, last name, company name (if business)
  • Contact: email address, phone number (optional)
  • Billing: invoice address, Tax ID (for businesses)
  • Payment: credit card details are NOT stored by us, they are processed exclusively by our payment processor (Stripe or WSPay) under their PCI DSS standards
  • License data: license key, purchase date, selected tier (Personal/Single/5 Sites/Unlimited/Agency)
  • Technical: IP address, device and browser type (for fraud prevention)

2.2 When You Use Our License Server

When your plug-in communicates with our license server, we collect:

  • Activation domains: list of domains where your license key is activated
  • Activation/deactivation timestamps
  • Update checks: dates of automatic checks, version of plug-in in use
  • IP address of the connecting server

2.3 When You Use the Client Portal

When you log into our client portal, we collect:

  • Login data: username, hashed password (we NEVER see your password in plaintext)
  • Session data: login time, session IP address
  • Activity data: QR cards you created, when you updated them

2.4 When Visitors Scan Our Clients' QR Cards

IMPORTANT ROLE NOTICE: When an end user (someone with a phone) scans our clients' QR code, the data collected by the plug-in belongs to our client as the Data Controller. Planeta acts as a Data Processor in this case, and our client is the Controller.

Data collected:

  • Technical scan data: date and time, device type, browser, referer URL
  • IP address: stored by default as SHA256+salt hash, meaning the original IP CANNOT be reconstructed. This enables counting "unique scans" without storing actual IP addresses.
  • Geographic location (optional): if our client has enabled this feature, we send the IP to ip-api.com (Australia-based) to obtain city/country level location. The exact IP is not stored anywhere.
  • Contact Exchange form data (optional): name, email, phone, company, message, collected ONLY with the visitor's explicit consent via opt-in checkbox, and sent directly to the client as the controller.

2.5 When You Visit Our Website

  • Server logs: IP address, browser type, pages visited and visit time, recorded by the web server itself. We use no visitor tracking service.
  • Cookies: see Section 10 below

2.6 When You Use the Website Analysis Tool (Vizuelni dokaz)

The measurement itself is free and requires no personal data. You enter a website address and get the findings on screen. If you stop there, nothing is stored.

If you request the report by email, we process:

  • Contact data: first and last name, email address, and phone number and company name if you provide them
  • Website data: the address of the measured website and of the comparison website, if provided
  • Measurement result: scores, measured timings and the findings calculated by the tool
  • Technical data: language and time of the measurement, and confirmation that you gave consent

Three further items are created without your input:

  • A random key for the report link. The report sits at a secret address that cannot be guessed and opens only via that link.
  • The number of times the report was opened and the time it was last opened. The link is permanent and can be forwarded to anyone, so we record how many times the report was opened. We do not record who opened it.
  • A fingerprint of your IP address, as a one-way SHA256 hash salted with the site's secret key, from which the address cannot be recovered. It exists only so that one visitor cannot start an unlimited number of measurements.
No consent, no storage. Until you tick the consent box, nothing is stored and no report is sent. The tool sets no cookies and stores nothing in your browser.

3 Legal Basis for Processing

Pursuant to GDPR Article 6, our legal bases for processing your personal data are:

ActivityLegal Basis
Purchase processing and license activationPerformance of contract (Art. 6(1)(b))
Scan data collection (hashed IP)Legitimate interest of our client (Art. 6(1)(f))
Contact Exchange (with opt-in consent)Explicit consent (Art. 6(1)(a))
Geographic lookup via ip-api.comLegitimate interest with transparency obligation
Website analysis form data (name, email, phone, site details)Consent (Art. 6(1)(a)), given by ticking the box before submission and withdrawable at any time
IP address fingerprint in the website analysis toolLegitimate interest (Art. 6(1)(f)), protecting the service from automated abuse
Report open countLegitimate interest (Art. 6(1)(f)), protecting our own work, since the report is not intended for forwarding to third parties or for use in someone else's commercial offer
Marketing emails (newsletter)Consent (Art. 6(1)(a)), always opt-out available
Accounting and tax dataLegal obligation (Art. 6(1)(c)), Serbian Accounting Act
Fraud detectionLegitimate interest (Art. 6(1)(f))

4 How We Use Your Data

We use your data solely for:

  • Service provision: delivering license keys, plug-in activation, support
  • Producing and sending the website analysis report you requested, and contacting you regarding its findings
  • Communication: transactional emails (purchase confirmation, license delivery, support replies)
  • Security: detecting suspicious activity, preventing abuse
  • Legal obligations: issuing invoices, maintaining accounting records
  • Service improvement: anonymized statistical data on plug-in usage

We DO NOT SELL your data to third parties. We DO NOT USE it for behavioral marketing. We DO NOT PROFILE you.

5 Who We Share Your Data With

We share your data only with the following third parties, and only to the extent necessary:

5.1 Payment Processors

  • Stripe, Inc. (if used), San Francisco, USA. Processes credit card payments. Privacy Policy: https://stripe.com/privacy
  • WSPay (if used), Zagreb, Croatia. Processes payments for the Balkan market. Privacy Policy: https://wspay.eu/privacy

5.2 Hosting and Infrastructure

  • United Internet d.o.o. (trading as UNLIMITED.RS), Milutina Milankovića 1c, 11073 Belgrade, Serbia. Tax ID: 109154021, registration number: 21133710. Hosts our website, license server and the database holding form submissions. This provider's server locations are Serbia and the Netherlands (European Economic Area). Personal data processing policy: https://unlimited.rs/pravilnik-podaciolicnosti.pdf

5.3 Email Services

  • Resend (legal entity: Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA). Sends transactional emails, website analysis reports and user notifications. The service receives the recipient name, email address and message content, and processes them solely on our instructions. It records whether a message was delivered, bounced or reported as spam, so that we stop sending to addresses that do not want our mail. The service does not use this data for its own purposes and does not pass it to third parties. Privacy Policy: https://resend.com/legal/privacy-policy
  • The list of its sub-processors is public: https://resend.com/legal/subprocessors

5.4 Geographic Lookup (only if client enables)

  • ip-api.com (Brisbane, Australia), IP-based geographic lookup. Privacy Policy: https://ip-api.com/docs/legal

5.5 Website Performance Measurement

  • Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Website speed and technical measurement is performed by Google PageSpeed Insights. The measurement is initiated by the visitor's own browser, so Google receives the address of the measured website, the visitor's IP address and browser details, exactly as on any other visit to a Google service. Google does not receive the name, email address or phone number. Privacy Policy: https://policies.google.com/privacy

5.6 Legal Obligations

We may disclose your data to authorities if required by law (e.g., court order, tax inspection, fraud investigation).

6 International Data Transfers

Some of our processors are located outside the European Economic Area (EEA) and Serbia:

  • Stripe (USA): relies on Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Resend (USA): the transfer takes place under a data processing agreement incorporating the European Commission's Standard Contractual Clauses (SCCs). The service is additionally certified under the EU-U.S. Data Privacy Framework.
  • Google Ireland Limited (Ireland, EEA): any onward transfer outside the EEA takes place under that company's own rules and Standard Contractual Clauses.
  • ip-api.com (Australia): provides only optional city-level geographic data, without storing the IP address.
  • Hosting (Serbia and the Netherlands): our hosting provider's server locations are Serbia and the Netherlands, the latter within the European Economic Area.

All transfers are performed with appropriate safeguards in accordance with GDPR Articles 44-49.

7 How Long We Retain Your Data

Data TypeRetention Period
Accounting data (invoices, payments)10 years (Serbian Accounting Act)
Active licenses and license keysLifetime (while license is valid) or until you request deletion
Login sessions (client portal)30 days from last activity
Hashed IPs from QR scans365 days (default, our client may configure shorter)
Contact Exchange dataUntil controller (our client) deletes or subject requests deletion
Contact and report from website analysis24 months from last contact, or immediately on your request
Report open countSame as the report itself, deleted together with it
Email marketing dataUntil unsubscribe or 24 months inactivity
Technical logs (server logs)90 days
Backups30 days rotating

After these periods, data is deleted or anonymized.

8 Your Rights

Pursuant to GDPR (and Serbian ZZPL where applicable), you have the following rights:

RightWhat It Means
Right of AccessRequest a copy of all data we hold about you
Right to RectificationRequest correction of inaccurate data
Right to Erasure ("right to be forgotten")Request deletion of your data, with some limitations, e.g. we cannot delete accounting data before the 10-year period expires
Right to RestrictionRequest temporary suspension of processing
Right to Data PortabilityRequest your data in structured, machine-readable format (JSON, CSV)
Right to ObjectObject to processing based on legitimate interest
Right to Withdraw ConsentWhere processing is based on consent, you can withdraw it anytime
Right to Lodge a ComplaintFile a complaint with the Serbian Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs) or your EU supervisory authority

How to Exercise These Rights: Email office@planeta-racunari.rs with subject "[GDPR REQUEST] [request type]". We respond within 30 days of receiving your request. We will verify your identity before processing sensitive requests (e.g., deletion).

Unsubscribing: every message we send contains an unsubscribe link. One click and we send you nothing further, with no questions asked.

9 Data Security

We implement the following technical and organizational measures to protect your data:

Technical Measures:

  • HTTPS/TLS encryption for all traffic
  • Passwords stored as bcrypt/argon2 hashes (never plaintext)
  • IP addresses stored as SHA256+salt hash, never in readable form
  • Website analysis reports open via a link with a random key that cannot be guessed
  • Regular encrypted backups
  • Firewall and intrusion detection at hosting provider level
  • Regular security updates for WordPress core, plug-ins, and themes
  • Access restrictions on license server by IP whitelist and authentication

Organizational Measures:

  • Personal data access limited to authorized personnel only (Aleksander Krsmanović)
  • Password policy with minimum length and complexity
  • Two-factor authentication (2FA) for admin access
  • "Least privilege" policy for all system accounts

What We DO NOT Guarantee: Although we take reasonable measures, no system is 100% secure. In case of a data breach affecting your rights and freedoms, we will notify you within 72 hours of becoming aware, as well as the competent supervisory authority.

10 Cookies

Analytics and Marketing Cookies

  • None. This site uses no Google Analytics or any other visitor tracking service, so there are no cookies that would follow you from page to page or from site to site.

Technical Cookies

  • Cookies are set by WordPress itself, for logging into the administration and remembering a logged-in user's settings. A visitor who is not logged in is generally given none.
The website analysis tool sets no cookies and stores nothing in your browser.

The language choice on this page is remembered in your browser's local storage. That is not a cookie and is not sent to anyone.

You can delete or pre-emptively block cookies at any time through your browser settings.

11 Minors

Our services are not intended for persons under 16 years of age. We do not knowingly collect data from minors. If you are a parent or guardian and learn that your child has provided us with personal data, contact us at office@planeta-racunari.rs and we will delete it immediately.

12 Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via:

  • Email notification to active clients (at least 30 days before effective date)
  • Banner on the homepage
  • Updated "Updated" date at the top of this document

We version the policy, so old versions can be retrieved on request.

13 Contact

For any questions, complaints, or to exercise your rights, contact:

Planeta računari (Aleksander Krsmanović)

Supervisory Authority in Serbia: Commissioner for Information of Public Importance and Personal Data Protection

  • Web: https://www.poverenik.rs
  • Email: office@poverenik.rs
  • Address: Bulevar kralja Aleksandra 15, 11120 Belgrade, Serbia
  • Phone: +381 11 3408 900

EU Supervisory Authorities: List of national authorities: https://edpb.europa.eu/about-edpb/about-edpb/members_en