Politika privatnosti / Privacy Policy

Planeta računari — kako sakupljamo, koristimo i štitimo Vaše lične podatke.
How Planeta računari collects, uses, and protects your personal data.

📋Verzija 1.0 📅Stupanje na snagu 21. maj 2026. 🔄Ažurirano 21. maj 2026.

1 Ko smo

Ova politika privatnosti opisuje kako Planeta računari (u daljem tekstu „Planeta", „mi", „nas", „naš") sakuplja, koristi i deli Vaše lične podatke kada koristite naše proizvode i usluge.

Podaci o rukovaocu

PLANETA RAČUNARI

Ova politika se primenjuje na:

  • Veb sajt https://planeta-racunari.rs i sve njegove pod-stranice
  • Prodajni portal https://planeta-racunari.rs/qr-license/buy/
  • Klijent portal https://planeta-racunari.rs/qr-portal/
  • License server https://planeta-racunari.rs/qr-license/
  • WordPress plug-in QR vCard Pro instaliran na sajtovima naših klijenata

2 Koje podatke sakupljamo

2.1 Kada kupujete licencu (klijent Planete)

Kada izvršite kupovinu preko /qr-license/buy/, sakupljamo:

  • Identifikacioni podaci: ime, prezime, naziv firme (ako ste pravno lice)
  • Kontakt podaci: email adresa, broj telefona (opciono)
  • Podaci za fakturisanje: adresa za fakturu, PIB (za pravna lica)
  • Podaci o plaćanju: broj kreditne kartice se NE čuva kod nas — obrađuje ih isključivo bančin platni procesor prema njihovim sigurnosnim standardima
  • Licencni podaci: license key, datum kupovine, izabrani tier (Personal/Single/5 Sites/Unlimited/Agency)
  • Tehnički podaci: IP adresa, tip uređaja i pretraživača (za potrebe sprečavanja prevara)

2.2 Kada koristite naš license server

Kada Vaš plug-in komunicira sa https://planeta-racunari.rs/qr-license/, sakupljamo:

  • Domene aktivacije: lista domena na kojima je Vaš license key aktiviran
  • Datum i vreme aktivacije / deaktivacije
  • Provera ažuriranja: datumi automatskih provera, verzija plug-ina koju koristite
  • IP adresa servera koji se konektuje

2.3 Kada koristite klijent portal

Kada se logujete na https://planeta-racunari.rs/qr-portal/, sakupljamo:

  • Login podaci: korisničko ime, hashovana lozinka (mi NIKADA ne vidimo Vašu lozinku u čistom tekstu)
  • Sesijski podaci: vreme prijave, IP adresa sesije
  • Podaci o aktivnostima: koje QR kartice ste kreirali, kada ste ih ažurirali

2.4 Kada posetioci skeniraju QR kartice naših klijenata

VAŽNA NAPOMENA O ULOGAMA: Kada krajnji korisnik (osoba sa telefonom) skenira QR kod naših klijenata, podaci koje plug-in sakuplja pripadaju našem klijentu kao rukovaocu podataka. Planeta je u ovom slučaju obrađivač podataka (Data Processor), a naš klijent je rukovalac (Data Controller).

Podaci koji se sakupljaju:

  • Tehnički podaci o skeniranju: datum i vreme, tip uređaja, pretraživač, referer URL
  • IP adresa: podrazumevano se čuva kao SHA256+salt hash — što znači da originalna IP adresa NE MOŽE biti rekonstruisana. Ovo omogućava brojanje „jedinstvenih skenova" bez čuvanja stvarne IP adrese.
  • Geografska lokacija (opciono): ako je naš klijent uključio ovu funkciju, šaljemo IP ka servisu ip-api.com (sa sedištem u Australiji) radi dobijanja gradskog/državnog nivoa lokacije. Tačna IP adresa se ne čuva nigde.
  • Podaci putem Contact Exchange forme (opciono): ime, email, telefon, firma, poruka — sakupljaju se SAMO uz eksplicitnu saglasnost posetioca preko opt-in čekboksa, i ide direktno klijentu kao rukovaocu.

2.5 Kada posećujete naš veb sajt

  • Standardni analitički podaci: IP adresa, tip pretraživača, posećene stranice
  • Kolačići: vidite Sekciju 10 ispod

3 Pravni osnov za obradu

U skladu sa GDPR Članom 6, naš pravni osnov za obradu Vaših ličnih podataka je:

AktivnostPravni osnov
Obrada kupovine i aktivacija licenciIzvršenje ugovora (Član 6(1)(b))
Sakupljanje podataka o skeniranju (hashed IP)Legitimni interes našeg klijenta (Član 6(1)(f)) — analitika sopstvenih QR kartica
Contact Exchange (sa opt-in saglasnošću)Eksplicitna saglasnost (Član 6(1)(a))
Geografska lokacija via ip-api.comLegitimni interes rukovaoca, uz obavezu transparentnosti
Marketing email-ovi (newsletter)Saglasnost (Član 6(1)(a)) — uvek možete odjaviti
Računovodstveni i poreski podaciZakonska obaveza (Član 6(1)(c)) — srpski Zakon o računovodstvu
Sprečavanje prevara (fraud detection)Legitimni interes (Član 6(1)(f))

4 Kako koristimo Vaše podatke

Vaše podatke koristimo isključivo za:

  • Pružanje usluge: dostava license key-a, aktivacija plug-ina, podrška
  • Komunikacija: transakcioni email-ovi (potvrda kupovine, dostava licence, support odgovori)
  • Sigurnost: detekcija sumnjivih aktivnosti, sprečavanje zloupotrebe
  • Pravne obaveze: izdavanje računa, čuvanje računovodstvene evidencije
  • Poboljšanje usluge: anonimizovani statistički podaci o korišćenju plug-ina
Vaše podatke NE PRODAJEMO trećim licima. NE KORISTIMO ih za behavioralni marketing. NE PROFILIŠEMO Vas.

5 Sa kim delimo Vaše podatke

Delimo Vaše podatke isključivo sa sledećim trećim licima, i to samo u meri koja je neophodna:

5.1 Platni procesori

5.2 Hosting i infrastruktura

  • Unlimited (United Internet d.o.o., Milutina Milankovića 1c, 11073 Beograd / Novi Beograd, Republika Srbija) hostuje naš sajt i license server.

5.3 Email servisi

  • SMTP od hosting providera šalje transakcione email-ove.

5.4 Analitika

  • Anonimizirana web analitika

5.5 Geografska lokacija (samo ako klijent uključi)

  • ip-api.com (Salesforce.com Inc., Brisbane, Australija) — geografska lokacija po IP-u. Privacy Policy: ip-api.com/legal

5.6 Zakonska obaveza

Možemo otkriti Vaše podatke nadležnim organima ako to zakon nalaže (npr. po nalogu suda, poreske inspekcije, ili u slučaju istrage prevare).

6 Međunarodni prenos podataka

Neki od naših procesora (ip-api.com) se nalaze van Evropske ekonomske zone (EEZ) i Srbije:

  • Prenos u Australiju: ip-api.com pruža samo opcione geografske podatke (city-level), bez čuvanja IP adrese.

Sve prenose vršimo uz odgovarajuće zaštitne mere u skladu sa članovima 44–49 GDPR-a.

7 Koliko dugo čuvamo Vaše podatke

Vrsta podatakaPeriod čuvanja
Računovodstveni podaci (fakture, plaćanja)10 godina (srpski Zakon o računovodstvu)
Aktivne licence i license key-eviDoživotno (dok licenca važi) ili dok ne zatražite brisanje
Login sesije (klijent portal)30 dana od poslednje aktivnosti
Hashovani IP-ovi sa QR skeniranja365 dana (default, naš klijent može da konfiguriše kraći period)
Contact Exchange podaciDok rukovalac (naš klijent) ne obriše ili dok subjekt ne zatraži brisanje
Email marketing podaciDo odjave ili do 24 meseca neaktivnosti
Tehnički logovi (server logs)30 dana
Backup-ovi30 dana rotirajući

Po isteku ovih perioda, podaci se brišu ili anonimiziraju.

8 Vaša prava

U skladu sa GDPR (i srpskim ZZPL gde je primenjivo), imate sledeća prava:

PravoŠta to znači
Pravo na pristupMožete tražiti kopiju svih podataka koje imamo o Vama
Pravo na ispravkuMožete tražiti ispravku netačnih podataka
Pravo na brisanje
(right to be forgotten)
Možete tražiti brisanje Vaših podataka (uz neka ograničenja — npr. ne možemo da brišemo računovodstvene podatke pre isteka 10 godina)
Pravo na ograničenje obradeMožete tražiti da privremeno obustavimo obradu
Pravo na prenosivost podatakaMožete tražiti svoje podatke u strukturisanom, mašinsko-čitljivom formatu (JSON, CSV)
Pravo na prigovorMožete uložiti prigovor na obradu zasnovanu na legitimnom interesu
Pravo na odjavu pristankaAko je obrada zasnovana na saglasnosti, možete je povući bilo kada
Pravo na žalbu nadzornom organuMožete podneti žalbu Povereniku za informacije od javnog značaja i zaštitu podataka o ličnosti Republike Srbije (poverenik.rs) ili nadležnom EU organu ako ste iz EU
Kako da ostvarite ova prava: Pošaljite email na office@planeta-racunari.rs sa naslovom „[GDPR ZAHTEV] [tip zahteva]". Odgovaramo u roku od 30 dana od prijema zahteva. Identitet ćemo verifikovati pre obrade osetljivih zahteva (npr. brisanja).

9 Bezbednost podataka

Primenjujemo sledeće tehničke i organizacione mere za zaštitu Vaših podataka:

Tehničke mere

  • HTTPS/TLS enkripcija za sav saobraćaj
  • Lozinke se čuvaju kao bcrypt/argon2 hash-evi (nikad u čistom tekstu)
  • IP adrese za skeniranje se čuvaju kao SHA256+salt hash
  • Redovni backup-ovi sa enkripcijom
  • Firewall i intrusion detection na nivou hosting providera
  • Redovne sigurnosne nadogradnje WordPress core-a, plug-inova i tema
  • Restrikcija pristupa license serveru po IP listi i autentikaciji

Organizacione mere

  • Pristup ličnim podacima imaju samo ovlašćena lica (Aleksander Krsmanović)
  • Politika lozinki sa minimalnom dužinom i kompleksnošću
  • Dvofaktorska autentikacija (2FA) za admin pristup
  • Trening za prepoznavanje phishing pokušaja
  • Politika „least privilege" za sve sistemske naloge
Šta NE garantujemo: Iako preduzimamo razumne mere, nijedan sistem nije 100% siguran. U slučaju data breach-a koji utiče na Vaša prava i slobode, obavestićemo Vas u roku od 72 sata od saznanja, kao i nadležni nadzorni organ.

10 Kolačići

Naš sajt koristi sledeće kolačiće:

Neophodni kolačići (uvek aktivni)

  • PHPSESSID — sesija na sajtu, briše se nakon zatvaranja pretraživača
  • woocommerce_* (ako koristimo WooCommerce) — korpa, checkout

Funkcionalni kolačići (opciono, sa Vašom saglasnošću)

  • cookie_consent — pamti Vaš izbor o kolačićima
  • language — pamti izabrani jezik

Analitički kolačići (opciono, sa Vašom saglasnošću)

  • _ga, _gid, _gat — Google Analytics (ako se koristi)
  • plausible_ignore — Plausible Analytics

Možete upravljati kolačićima preko našeg cookie banner-a koji se prikazuje prilikom prve posete, ili kroz podešavanja Vašeg pretraživača.

11 Maloletna lica

Naše usluge nisu namenjene osobama mlađim od 16 godina. Svesno NE sakupljamo podatke od maloletnih lica. Ako ste roditelj/staratelj i saznate da je Vaše dete dalo nam svoje podatke, kontaktirajte nas na office@planeta-racunari.rs — odmah ćemo ih izbrisati.

12 Izmene ove politike

Ovu politiku možemo povremeno menjati. Materijalne izmene ćemo komunicirati:

  • Email obaveštenjem aktivnim klijentima (najmanje 30 dana pre stupanja na snagu)
  • Banner-om na naslovnoj strani sajta
  • Datumom „Poslednje ažurirano" na vrhu ovog dokumenta

Verzioniramo politiku, pa možete videti stare verzije na zahtev.

13 Kontakt

Za sva pitanja, žalbe, ili ostvarivanje Vaših prava, kontaktirajte nas:

Planeta računari · Aleksander Krsmanović

Nadzorni organ u Srbiji

Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti

Nadzorni organi u EU

Lista nadzornih organa po državama: edpb.europa.eu/members

1 Who We Are

This Privacy Policy describes how Planeta računari (hereinafter "Planeta," "we," "us," or "our") collects, uses, and shares your personal data when you use our products and services.

Controller Details

PLANETA RAČUNARI

This Privacy Policy applies to:

  • The website https://planeta-racunari.rs and all its subpages
  • The sales portal https://planeta-racunari.rs/qr-license/buy/
  • The client portal https://planeta-racunari.rs/qr-portal/
  • The license server https://planeta-racunari.rs/qr-license/
  • The QR vCard Pro WordPress plug-in installed on our clients' websites

2 What Data We Collect

2.1 When You Purchase a License

When you complete a purchase through /qr-license/buy/, we collect:

  • Identification data: first name, last name, company name (if you are a business)
  • Contact data: email address, phone number (optional)
  • Billing data: invoice address, Tax ID (for businesses)
  • Payment data: credit card numbers are NOT stored by us. They are processed exclusively by our bank's payment processor in accordance with their security standards.
  • License data: license key, purchase date, selected tier (Personal/Single/5 Sites/Unlimited/Agency)
  • Technical data: IP address, device type, and browser type (for fraud prevention)

2.2 When You Use Our License Server

When your plug-in communicates with https://planeta-racunari.rs/qr-license/, we collect:

  • Activation domains: the list of domains on which your license key has been activated
  • Activation/deactivation timestamps
  • Update checks: dates of automated checks and the plug-in version you are using
  • The IP address of the connecting server

2.3 When You Use the Client Portal

When you log in to https://planeta-racunari.rs/qr-portal/, we collect:

  • Login credentials: username and a hashed password (we NEVER see your password in plain text)
  • Session data: sign-in timestamp and session IP address
  • Activity data: which QR cards you have created and when you have updated them

2.4 When Visitors Scan Our Clients' QR Cards

IMPORTANT NOTE ON ROLES: When an end user (a person with a phone) scans a QR code belonging to one of our clients, the data collected by the plug-in belongs to our client as the data controller. In this scenario, Planeta acts as the data processor, and our client is the data controller.

The data collected includes:

  • Technical scan data: date and time, device type, browser, referrer URL
  • IP address: by default, this is stored as a SHA256+salt hash, which means the original IP address CANNOT be reconstructed. This allows us to count "unique scans" without storing the actual IP address.
  • Geolocation (optional): if our client has enabled this feature, we send the IP address to the ip-api.com service (based in Australia) to obtain city/country-level location information. The exact IP address is not stored anywhere.
  • Contact Exchange form data (optional): name, email, phone, company, and message. This data is collected ONLY with the visitor's explicit consent via an opt-in checkbox and is sent directly to the client as the data controller.

2.5 When You Visit Our Website

  • Standard analytics data: IP address, browser type, pages visited
  • Cookies: see Section 10 below

3 Legal Basis for Processing

In accordance with Article 6 of the GDPR, our legal bases for processing your personal data are:

ActivityLegal Basis
Processing purchases and license activationsPerformance of a contract (Art. 6(1)(b))
Collecting scan data (hashed IP)Legitimate interest of our client (Art. 6(1)(f)) — analytics for their own QR cards
Contact Exchange (with opt-in consent)Explicit consent (Art. 6(1)(a))
Geolocation via ip-api.comController's legitimate interest, subject to transparency obligations
Marketing emails (newsletter)Consent (Art. 6(1)(a)) — you can unsubscribe at any time
Accounting and tax recordsLegal obligation (Art. 6(1)(c)) — Serbian Accounting Act
Fraud detectionLegitimate interest (Art. 6(1)(f))

4 How We Use Your Data

We use your data exclusively for:

  • Service delivery: delivering license keys, activating the plug-in, and providing support
  • Communication: transactional emails (purchase confirmations, license delivery, support responses)
  • Security: detecting suspicious activity and preventing misuse
  • Legal obligations: issuing invoices and maintaining accounting records
  • Service improvement: anonymized statistical data on plug-in usage
We DO NOT SELL your data to third parties. We DO NOT USE your data for behavioral marketing. We DO NOT PROFILE you.

5 Who We Share Your Data With

We share your data only with the following third parties, and only to the extent necessary:

5.1 Payment Processors

5.2 Hosting and Infrastructure

  • Unlimited (United Internet d.o.o., Milutina Milankovića 1c, 11073 Belgrade / New Belgrade, Republic of Serbia) hosts our website and license server.

5.3 Email Services

  • SMTP through our hosting provider sends transactional emails.

5.4 Analytics

  • Anonymized web analytics

5.5 Geolocation (only if the client enables it)

  • ip-api.com (Salesforce.com Inc., Brisbane, Australia) — IP-based geolocation. Privacy Policy: ip-api.com/legal

5.6 Legal Obligations

We may disclose your data to the competent authorities when required by law (for example, pursuant to a court order, a tax inspection, or in the course of a fraud investigation).

6 International Data Transfers

Some of our processors (such as ip-api.com) are located outside the European Economic Area (EEA) and Serbia:

  • Transfers to Australia: ip-api.com provides only optional geographic data (at the city level), without storing the IP address.

We carry out all transfers with appropriate safeguards in accordance with Articles 44–49 of the GDPR.

7 How Long We Retain Your Data

Type of DataRetention Period
Accounting data (invoices, payments)10 years (Serbian Accounting Act)
Active licenses and license keysFor the lifetime of the license, or until you request deletion
Login sessions (client portal)30 days from the last activity
Hashed IPs from QR scans365 days (default; our client may configure a shorter period)
Contact Exchange dataUntil the controller (our client) deletes it, or until the data subject requests deletion
Email marketing dataUntil unsubscription or after 24 months of inactivity
Technical logs (server logs)30 days
Backups30 days (rotating)

After these periods expire, the data is deleted or anonymized.

8 Your Rights

In accordance with the GDPR (and the Serbian Personal Data Protection Act where applicable), you have the following rights:

RightWhat It Means
Right of accessYou may request a copy of all data we hold about you.
Right to rectificationYou may request the correction of inaccurate data.
Right to erasure
("right to be forgotten")
You may request the deletion of your data (subject to certain limitations — for example, we cannot delete accounting records before the 10-year retention period has expired).
Right to restriction of processingYou may request that we temporarily suspend processing.
Right to data portabilityYou may request your data in a structured, machine-readable format (JSON, CSV).
Right to objectYou may object to processing based on legitimate interest.
Right to withdraw consentIf processing is based on consent, you may withdraw that consent at any time.
Right to lodge a complaintYou may file a complaint with the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia (poverenik.rs), or with the competent EU authority if you are in the EU.
How to exercise these rights: Send an email to office@planeta-racunari.rs with the subject line "[GDPR REQUEST] [type of request]". We respond within 30 days of receiving the request. We will verify your identity before processing sensitive requests (such as deletion).

9 Data Security

We apply the following technical and organizational measures to protect your data:

Technical Measures

  • HTTPS/TLS encryption for all traffic
  • Passwords are stored as bcrypt/argon2 hashes (never in plain text)
  • IP addresses from scans are stored as SHA256+salt hashes
  • Regular encrypted backups
  • Firewall and intrusion detection at the hosting provider level
  • Regular security updates to WordPress core, plug-ins, and themes
  • Restricted access to the license server by IP allowlist and authentication

Organizational Measures

  • Personal data is accessible only to authorized personnel (Aleksander Krsmanović)
  • A password policy with minimum length and complexity requirements
  • Two-factor authentication (2FA) for administrator access
  • Phishing-awareness training
  • A "least privilege" policy for all system accounts
What we do NOT guarantee: Although we take reasonable measures, no system is 100% secure. In the event of a data breach affecting your rights and freedoms, we will notify you within 72 hours of becoming aware of the breach, and we will also notify the competent supervisory authority.

10 Cookies

Our website uses the following cookies:

Strictly Necessary Cookies (always active)

  • PHPSESSID — site session; deleted when the browser is closed
  • woocommerce_* (if WooCommerce is used) — cart and checkout

Functional Cookies (optional, with your consent)

  • cookie_consent — remembers your cookie preferences
  • language — remembers your selected language

Analytics Cookies (optional, with your consent)

  • _ga, _gid, _gat — Google Analytics (if used)
  • plausible_ignore — Plausible Analytics

You can manage cookies through our cookie banner, which is displayed on your first visit, or through your browser settings.

11 Minors

Our services are not intended for persons under the age of 16. We do NOT knowingly collect data from minors. If you are a parent or guardian and you learn that your child has provided us with their data, please contact us at office@planeta-racunari.rs — we will delete it immediately.

12 Changes to This Policy

We may amend this Privacy Policy from time to time. We will communicate any material changes through:

  • An email notification to active customers (at least 30 days before the effective date)
  • A banner on our homepage
  • An updated "Last Updated" date at the top of this document

We version this policy, so prior versions are available upon request.

13 Contact

For any questions, complaints, or to exercise your rights, please contact us:

Planeta računari · Aleksander Krsmanović

Supervisory Authority in Serbia

Commissioner for Information of Public Importance and Personal Data Protection

Supervisory Authorities in the EU

List of national authorities by country: edpb.europa.eu/members

error: Content is protected !!