v2.0

GoRules Version 2 is here - redesigned, now with managed cloud.GoRules Version 2 is here!

Watch the launch videoWatch

GoRules·Legal

Privacy Policy

Last updated: 05.08.2026.

Welcome to GoRules’ Privacy Policy!

Please note that this Privacy Policy applies to personal data that is collected and processed in the course of providing a Product (as defined in Terms of Service) by GoRules Technologies d.o.o. Čačak, with registered seat at Trg narodnog ustanka 2, 32000 Čačak, Republic of Serbia, CIN: 21925713, TIN: 113787086, (hereinafter: “GoRules”, or “we”).

GoRules, as a Data Controller or Data Processor, (collects and) processes personal data relating to interactions on the Platform (as defined in the Definition Section of this Privacy Policy). This Privacy Policy describes how GoRules uses and protects any information that you share with us in relation to our Platform.

We believe in full transparency, which is why we keep our Privacy Policy simple and easy to understand.

We strongly urge you to read this Privacy Policy and make sure that you fully understand and agree with it. If you do not agree to this Privacy Policy, please do not access, or otherwise use GoRules Platform. In case there is anything that you would like to ask us regarding this Privacy Policy, please send your inquiry to [email protected].

Along with the Terms of Service, this Privacy Policy represents a contract between you and GoRules. Thus, any capitalized but undefined term in this Privacy Policy shall have the meaning given to it in the definitions section of the Terms of Service.

Content

  1. DEFINITIONS
  2. DATA CONTROLLER AND DATA PROCESSOR
  3. WHAT DATA DO WE PROCESS ABOUT YOU AND WHEN?
  4. WHAT DO WE NOT DO?
  5. PERSONAL DATA SECURITY
  6. WITH WHOM DO WE SHARE YOUR PERSONAL DATA?
  7. INTERNATIONAL TRANSFER OF YOUR PERSONAL DATA
  8. HOW LONG DO WE KEEP YOUR DATA?
  9. YOUR RIGHTS
  10. CHANGES TO PRIVACY POLICY

1. Definitions

TERMMEANING
AccountThe account assigned to the Client or User, whose purpose is to enable the Client or User to access and use the Product and manage the User/Client Content.
AI Features or GoRules AIThe artificial intelligence-powered capabilities made available by GoRules within the Product, including AI-assisted rule generation, the AI copilot, automated test case generation, and document-to-rule conversion. AI Features are powered by a third-party AI model provider that differs by deployment mode: for Demo (Legacy) Cloud, AI Features use Claude (Anthropic, Inc.); for Managed Cloud, AI Features use Claude (Anthropic, Inc.) via AWS Bedrock. For details on how personal data is processed in connection with AI Features, see Section 3.2.2.
ClientA company (legal entity) or an independent developer (natural person) represented by User(s) registered on its behalf, who enters into the Agreement with GoRules.
ConsentYour explicit consent on the processing of personal data. Persons who are 16 years of age or older may give free consent to the processing of their personal data.
CookiesCookies and other similar technologies (e.g. web beacons, LocalStorage, etc.) are small pieces of data stored on your device (computer or mobile device). This information is used to track your use of the Platform and to compile statistical reports on Platform activity.
Data ControllerAn entity that alone or jointly with others determines the purposes and means of the processing of personal data.
Data ProcessorAny natural or legal person who processes the data on behalf of the controller.
Data Protection Lawa) Law on Personal Data Protection (“Official Gazette of the RS” no. 87/2018) and / or b) General Data Protection Regulation 2016/679.
Data Subject, or youAny natural person that shares personal data with us via Platform, or in relation to Platform (e.g. via email).
Managed CloudThe fully managed, cloud-hosted deployment of the GoRules BRMS provided by GoRules as a software-as-a-service offering, hosted on Amazon Web Services (AWS) infrastructure. For details on data processing in connection with the Managed Cloud, see Sections 3.2, 5, and 7.
Platform or ProductGoRules software platform made available through any of GoRules’ deployment modes, including the Self-Hosted subscription package, the Demo (Legacy) Cloud (the existing legacy cloud-based subscription), the Managed Cloud, as well as AI Features and related products and services that we provide, individually and collectively. This definition does not encompass any open-source software developed by GoRules.
Personal data or dataAny information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, either directly or indirectly. Therefore, data about a company or any legal entity is not considered to be personal data but registering on behalf of a legal entity may include sharing personal data. For example, information about one-person companies may constitute personal data where it allows the identification of a natural person. The rules also apply to all personal data relating to natural persons in the course of professional activity, such as the employees of a company or organization, and business e-mail addresses like “[email protected]”. This Privacy Policy does not apply to information from which no individual can reasonably be identified (anonymized information).
ProcessingAny operation or set of operations that is performed on personal data or sets of personal data. This includes activities such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
UserAn individual engaged by the Client, including but not limited to Client’s employees, developers, consultants and contractors, and registered on the Platform by the Client.

2. DATA CONTROLLER AND DATA PROCESSOR

In relation to your personal data processed via the Platform, GoRules may be either a Data Controller or Data Processor.

When GoRules acts in the capacity of a Data Controller, GoRules determines the purposes and means of the processing of personal data. The purpose of data processing is the reason why we process your personal data. The table in Section 3.1 of the Privacy Policy presents the purposes and legal basis for data processing. In those cases, GoRules is responsible for your personal data.

Apart from Section 3.2, this Privacy Policy primarily contains information on processing your data in the capacity of a Data Controller. Should you have any inquiries, or you wish to exercise any of the rights of a Data Subject stipulated in Section 9, please contact us:

  • GoRules Technologies d.o.o. Čačak
  • Trg narodnog ustanka 2, 32000 Čačak, Republic of Serbia
  • Email: [email protected]

Given that GoRules strongly supports fair personal data processing, despite being only a Data Processor in the below-listed cases, we made an additional effort to explain such personal data processing via Platform - in Section 3.2 of this Privacy Policy.

The information contained therein outlines how personal data processing via GoRules’ Platform functions in general. But if you wish to send an inquiry, or exercise any of the rights which you may have under the applicable data protection law as the Data Subject, please contact the Client directly, as they hold the position of Data Controller.

Since GoRules is a company operating under the laws of the Republic of Serbia and falls under the scope of application of the Data Protection Law, GoRules as a Data Processor is obliged to sign the Data Protection Addendum to the Terms of Service ("DPA"), with the Client as a Data Controller. The DPA reflects the agreement between the Client and GoRules regarding the terms which govern the processing of personal data under GoRules' Terms of Service. Signing the DPA will be considered as an amendment to the Agreement (within the meaning of the Definitions Section of Terms of Service) and will be considered to form a part of the Agreement. Where GoRules processes personal data as a Data Processor on behalf of a Client whose assigned Managed Cloud region is within the European Union (EU1 Region), the DPA includes the applicable standard contractual clauses and technical and organizational measures required under GDPR.

3. WHAT DATA DO WE PROCESS ABOUT YOU AND WHEN?

We may collect and receive information about you in various ways:

  • Information you provide using Platform (for example, by requesting creation of an Account on Platform).
  • Information you decide to provide through getting in touch with us.
  • Information we collect using cookies and similar technologies as explained below.

Personal data we may collect automatically

Each time you use Platform we may automatically collect the following information:

  • At the time of logging in, we store the data in local storage, such as the user id, the hashtag that we generate ourselves and is created at the time of logging in, the date of logging in and the date when you will be logged out automatically. Namely, we have created the functionality that every user is automatically logged out of Platform after exactly 8 hours after being logged in.
  • when you use the Platform, we will keep a record of the details of that usage, including the date, time, location, frequency and duration of the usage;
  • technical information about your computer or mobile device for system administration and analysis, including your IP address, URL clickstreams, unique device identifiers, operating system, and network and browser type;
  • other information about your use of the Platform, including the pages you have viewed, the duration spent on the Platform and User/Client Content you have uploaded to the Platform.

Please read our Cookie Policy in order to find out more about these technologies.

3.1 GORULES AS DATA CONTROLLER

GoRules will primarily have the role of Data Processor in relation to the collection and processing of your personal data via the Platform. However, for the purpose of complete transparency, we list possible occasions in which GoRules can find itself in the role of Data Controller.

DATA WE COLLECTPURPOSELEGAL BASISRETENTION PERIOD
Client’s organization name, first and last name, business email address, Client’s website, size of the Client’s company.Creating and maintaining Client’s Account at the Platform according to the Terms of Service.Processing is necessary for the performance of the Agreement.Until the Account is deleted in accordance with the Terms of Service.
Payment information
Card holder name, Card number, Expiration date, Security code Billing Information: First name, Last name, Company, VAT ID, Contact Email, Address, Country, State, City, ZIP code
When subscribing to any of the Platform’s paid subscription packages or when changing any Platform’s paid subscription packages in accordance with the Terms of Service, this information is being collected by GoRules directly or a third-party processor.Processing is necessary for the performance of the Agreement.We keep only the last four digits of the credit card number under subscription billing info until such Agreement is terminated and for the period necessary to comply with the applicable financial and tax accounting and other statutory obligations in accordance with the applicable law (Section 13 of the Terms of Service).
Additional Data
i.e., data you decide to share with us by contacting us.
If you send us an inquiry or otherwise request support, we will collect the data you decide to share with us.Processing of personal data is either necessary to provide a Product or part thereof or the processing is based on your consent.If the processing is based on your consent, we keep the information until you withdraw your consent or for one year, whichever date comes first.
Information necessary for identification, time and date of data subject’s requestTo allow Data Subjects to exercise their rights in accordance with this Privacy Policy, as defined in Section 9.Processing is necessary for compliance with a legal obligation to which the Data Controller is subject.We keep this information for a period of one year.
Other personal dataFor the prevention and detection of fraud, money laundering or other crimes or to respond to a binding request from a public authority or court.The processing is necessary to comply with legal and regulatory obligations.In accordance with the applicable statutory deadlines.
For Managed Cloud subscribers: organization name, first and last name, business email address, country of establishment (for Data Region assignment), and subscription plan details.Creating and maintaining the Client's Managed Cloud account; assigning the appropriate Data Region; administering the Managed Cloud subscription in accordance with the Terms of Service.Processing is necessary for the performance of the Agreement.Until the Account is deleted or the Managed Cloud subscription is terminated, in accordance with the Terms of Service. Billing-related data is retained for the period necessary to comply with applicable financial, tax, and accounting obligations.
Usage and technical data, i.e., IP address, device and browser information, operating system, pages visited, session duration, click and interaction data, page load times, error logs, and general geolocation derived from IP address, collected through the Platform's website and/or application.

This data is limited to technical and usage telemetry only. GoRules does not access, monitor, or process the Content that the Client inputs into, processes through, or generates using the Product, nor does GoRules collect any other identifying information beyond what is strictly necessary for the purposes described herein. Data collection is designed and configured to be limited to what is adequate, relevant, and necessary for these purposes, in accordance with the data minimization principle.
To monitor and analyze the performance, availability, and usage of the Platform, to detect and diagnose technical errors, and to improve the functionality and user experience of the Platform.Processing is necessary for our legitimate interest in maintaining, securing, and improving the Platform.We retain this data for a period of 30 days from collection, or as otherwise configured within our analytics tooling, unless a shorter or longer period is required to comply with applicable law.

3.2 GORULES AS DATA PROCESSOR

As previously stated, concerning some of your personal data processed on the Platform, GoRules is a Data Processor, and the Client is the Data Controller. GoRules processes personal data following instructions from the Data Controller under the Terms of Service, and DPA (if any).

The purpose of such personal data processing includes but is not limited to: inviting Clients and Users to the Platform, creating Accounts for Clients and Users, adding mandatory and optional data to the Accounts, adding system user roles, adding permissions to the Accounts, sending relevant notifications in relation to the usage of the Platform. GoRules processes these data when the Platform is being used in the form of any deployment mode, including the Demo (Legacy) Cloud and the Managed Cloud, as well as when Users are registering on the Portal in order to use the Self-Hosted Product. Besides that, GoRules might process data that is required for support reasons, in accordance with the Agreement or with Clients/Users explicit permission. Also, GoRules collects telemetry necessary for the validation of the license for the use of the Self-hosted version of the Platform. In connection with AI Features, GoRules processes User inputs submitted to the AI model solely to the extent necessary to return the requested output; such inputs are not retained after delivery of the output and are not used for AI model training.

As a processor, GoRules is permitted to collect, use, disclose and/or otherwise process your personal data only in accordance with its contracts with the Client.

3.2.1 Processing when using the Product

Cloud-based Products (Demo (Legacy) Cloud and Managed Cloud)

You may gain access to the Platform in one of two ways:

  • Invitation: An existing Client invites you to the Platform by entering your work email address and, optionally, your first and last name. GoRules processes this data as a processor, on the Client's instructions, solely for the purpose of enabling your access to the Platform. You receive an invitation by email, which you accept by clicking the link contained therein.
  • Sign-up: You may register directly, without being invited by an existing Client, by providing your email address and an organization name, and confirming your registration via a one-time code sent to your email. In this case, you (or the organization on whose behalf you are registering) become the Client, and GoRules processes your data as controller, on the basis of the performance of the Agreement concluded between you and GoRules.

Regardless of the access route, to finalize your registration you will confirm your identity using one of the following methods, depending on the authentication method configured for your organization: (i) a one-time code sent to your email address, (ii) Google Sign-In, or (iii) an SSO pop-up.

Once registered, you or the Client may optionally add the following data within the Platform:

  • First name
  • Last name
Self-Hosted Product (License Portal)

You may gain access to the Self-Hosted License Portal in one of two ways:

  • Invitation: An existing Client invites you to the License Portal by entering your work email address. GoRules processes this data as a processor, on the Client's instructions, solely for the purpose of enabling your access to the Portal.
  • Sign-up: You may register directly, without being invited by an existing Client, by providing your email address, an organization name, your organization's website, and your first and last name, and confirming your registration via a one-time code sent to your email. In this case, GoRules processes your data as controller, on the basis of the performance of the Agreement concluded between you and GoRules.

After registration, you will be able to acquire a software license key to access the Self-Hosted Product. With respect to the Self-Hosted Product itself, GoRules only processes the personal data needed to register on the Self-Hosted License Portal, and does not process, access, or monitor personal data or Content that Users upload to or process through the Self-Hosted Product while using it.

3.2.2 AI Features Data Processing

When a User interacts with AI Features, GoRules acts as a Data Processor in relation to any personal data contained within those inputs.

The following applies to personal data processed through AI Features:

  1. The AI model provider differs by deployment mode. For Demo (Legacy) Cloud Users: GoRules transmits User inputs to Anthropic (United States) for processing via Claude. This transmission is governed by Anthropic's applicable data processing terms. For Managed Cloud Users: GoRules transmits User inputs to Anthropic, Inc. (United States) via Amazon Web Services Bedrock solely to generate the requested output. For EU Region Users (EU1), this transmission is processed within the European Union and data does not leave the EU. This transmission is governed by adequate data processing agreements.
  2. User inputs and AI-generated outputs are not retained by GoRules or by AI model providers beyond what is strictly necessary to deliver the response in real time. They are not used to train, fine-tune, or otherwise improve any AI model.
  3. Users should avoid submitting special categories of personal data (as defined under applicable data protection law) through AI Features unless strictly necessary and supported by an appropriate legal basis.
  4. The Client, as Data Controller, is responsible for ensuring that any personal data submitted to AI Features is processed on a valid legal basis and that data subjects have been informed accordingly.

If you have any questions about how personal data is processed through AI Features, please contact the Client or reach us at [email protected].

4. WHAT DO WE NOT DO?

GoRules will never:

  • Sell any kind of personal information or data.
  • Disclose this information to marketers or third parties not specified in Section 6 of the Privacy Policy.
  • Process your data in any way other than stated in this Privacy Policy.
  • Use personal data contained in User inputs to AI Features to train, fine-tune, benchmark, or otherwise improve any AI model, whether operated by GoRules or a third party, without your explicit prior consent.

5. PERSONAL DATA SECURITY

We take administrative, technical, organizational, and other measures to ensure the appropriate level of security of personal data we process. Upon assessing whether a measure is adequate and which level of security is appropriate, we consider the nature of the personal data we are processing and the nature of the processing operations we perform, the risks to which you are exposed by our processing activities, the costs of the implementation of security measures and other relevant matters in the particular circumstances.

Some of the measures we apply include access authorization control, protection of integrity and confidentiality, data backup, firewalls, data encryption and other appropriate measures. We equip our staff with the appropriate knowledge and understanding of the importance and confidentiality of your personal data security.

Whenever we save your personal information, it’s stored on servers and in facilities that only selected personnel and our contractors have access to. We encrypt all data that you submit through Platform during transmission using SSL in order to prevent unauthorized parties from viewing such information. Remember - all information you submit to us by email is not secure, so please do not send sensitive information in any email to GoRules. We never request that you submit sensitive or personal information over email, so please report any such requests to us by sending an email to [email protected].

We protect personal information you provide online in connection with registering an account via GoRules’ Platform. Access to your own personal information is available through an Account created by you. To protect the security of your personal information, never share your credentials with anyone. Please notify us immediately if you believe your Account has been compromised.

Managed Cloud Security. For Users accessing the Platform through the Managed Cloud, GoRules implements commercially reasonable administrative, technical, and organizational security measures to protect personal data hosted on the Managed Cloud infrastructure (Amazon Web Services). Personal data on the Managed Cloud is stored exclusively within the Data Region assigned to your organization and is not transferred outside that region except as required by law and as explained Section 7 of this Privacy Policy.

AI Features Security. User inputs submitted to AI Features are transmitted to GoRules' third-party AI model providers over encrypted connections. For Managed Cloud Users assigned to the EU Region (EU1), transmission and inference remain within the European Union and data does not leave the EU. For Demo (Legacy) Cloud Users, inputs are transmitted to Anthropic, Inc. in the United States regardless of the User's location, as there is no Data Region assignment applicable to AI Features under the Demo (Legacy) Cloud. GoRules does not store User inputs or AI-generated outputs after delivery of the response. GoRules has a data processing agreement in place with its AI model providers governing the secure handling of any data transmitted in connection with AI Features.

6. WITH WHOM DO WE SHARE YOUR PERSONAL DATA?

GoRules utilizes external processors and sub-processors for certain processing activities. We conduct information audits to identify, categorize and record all personal data that is processed outside our company, so that the information, processing activity, processor and legal basis are all recorded, reviewed and easily accessible. The list of our sub-processors is approved by the Client.

We have strict due diligence procedures and measures in place and review, assess and background check all processors prior to forming a business relationship. We obtain company documents, certifications, references and ensure that the processor is adequate, appropriate, and effective for the task we are employing them for.

We audit their processes and activities prior to contract and during the contract period to ensure compliance with the data protection regulations and review any codes of conduct that oblige them to confirm compliance.

The list of processors and sub-processors with whom we share your personal data is available at GoRules Trust Center.

Payment processing for the Self-Hosted Plan and Managed Cloud Plan

If you purchase the Self-Hosted Plan or the Managed Cloud Plan, your payment is handled by Paddle.com Market Limited ("Paddle"), which acts as our authorized reseller and merchant of record. Unlike the processors and sub-processors listed above, Paddle does not process your payment data on our behalf and on our instructions. Instead, Paddle acts as an independent data controller for the payment data it collects directly from you (such as your name, email address, billing address, and payment instrument details), and your purchase is subject to Paddle's own Privacy Policy, available at https://www.paddle.com/legal/privacy.

Paddle shares with GoRules only a limited set of data necessary to deliver the Product, provide customer support, and prevent fraud. GoRules processes that limited data as controller, in accordance with this Privacy Policy.

This does not apply to the Enterprise Plan, where GoRules directly collects and processes your payment data as controller.

We may also share your personal data with our outside accountants, legal counsels, and auditors.

Moreover, we may disclose your personal information to third parties:

  • if we are under a duty to disclose or share your personal data in order to comply with any legal obligation;
  • to prevent and detect fraud or crime;
  • in response to a subpoena, warrant, court order, or as otherwise required by law.

Please note that personal information may be disclosed or transferred as part of, or during negotiations of, a merger, consolidation, sale of our assets, as well as equity financing, acquisition, strategic alliance or in any other situation where personal information may be transferred as one of the business assets of GoRules.

We do not have a list of all third parties we share your data with. However, if you would like further information about who we have shared your data with, you can request this by contacting us at [email protected].

7. INTERNATIONAL TRANSFER OF YOUR PERSONAL DATA

We may transfer your personal data to countries other than the one you reside in. In that case, we will also apply appropriate technical and organizational measures to ensure an adequate level of security in respect of all personal data we process. If the Data Protection Law applies to you, we make sure that such transfer is made:

  • to the countries within the EEA;
  • to the countries which ensure an adequate level of protection;
  • to the countries which do not belong to those specified under item 1. and 2, but only by applying the appropriate safeguard measures (such as Standard Contractual Clauses adopted by the European Commission)

If you would like to obtain more information about these protective measures, please contact us at [email protected].

The location where your personal data is stored depends on the deployment mode you use:

  • Demo (Legacy) Cloud: Personal data is stored on servers located in the European Union (Microsoft Azure).
  • Managed Cloud: Personal data is stored and processed exclusively within the Data Region assigned to your organization at the time of subscription:
    • EU Region: AWS within the European Union.
    • US Region: AWS within United States of America.

GoRules does not transfer Managed Cloud personal data outside the assigned Data Region except as required by applicable law, with the exception of telemetry and Real User Monitoring (RUM) data, which is processed and stored in Datadog’s Europe region regardless of the Client’s assigned Data Region. For EU-Region users, data processed within the EU is subject to GDPR and GoRules relies on its data processing agreement with third party vendors as the applicable safeguard.

  • Self-Hosted Product: Personal data is stored on the Client's own servers or infrastructure. However, certain administrative data related to the Client's license (such as first name, last name, and business email address of the Client's authorized representatives) is collected and stored through GoRules' license portal, which is hosted on servers located in the European Union (Microsoft Azure), for the purpose of license activation and management in accordance with the Terms of Service.

AI Features: The AI model provider and data transfer arrangements differ by deployment mode: (i) Demo (Legacy) Cloud: User inputs submitted to AI Features are transmitted to Anthropic (United States) for processing via Claude. This transfer is governed by Anthropic's applicable data processing terms. (ii) Managed Cloud: User inputs submitted to AI Features are transmitted to Anthropic, Inc. (United States) via Amazon Web Services Bedrock for processing. For EU Region Users (EU1), AI inference is processed within the European Union and User inputs are not transferred to the United States. This transfer is governed by standard contractual clauses and the data processing agreement between GoRules and Anthropic. User inputs and AI outputs are not retained after delivery of the response.

8. HOW LONG DO WE KEEP YOUR DATA?

The period for which we store your personal data depends on a particular purpose for the processing of personal data, as explained in detail in Section 3. We retain personal data for as long as we reasonably require it for legal or business purposes. In determining data retention periods, we take into consideration the applicable law (see Terms of Service), contractual obligations, and the expectations and requirements of our Clients. When we no longer need personal information, or when you legitimately request us to delete your information, we will securely delete or destroy it.

However, as an exception to the retention periods in Section 3 the data may be processed to determine, pursue, or defend claims and counterclaims.

9. YOUR RIGHTS

Given that fairness and transparency are our cornerstone principles, we wanted to remind you of the rights that you have as a Data Subject. These rights may be exercised by Data Subject when GoRules operates as a Data Controller.

If your inquiry or exercise of any of the Data Subject's rights relates to the data processed by the Client as a Data Controller as explained in Section 3.2 of the Privacy Policy, please contact the Client (that you have linked your Account with).

In the event GoRules receives a request for exercising any of these rights directly from a Data Subject, we are obliged to notify the Client before responding to such a request.

Right of Access

You can send us a request for a copy of the personal data we hold about you.

We have ensured that appropriate measures have been taken to provide such in a concise, transparent, intelligible, and easily accessible form, using clear and plain language. Such information is provided in writing free of charge. It may be provided by other means when authorized by the Data Subject and with prior verification as to the subject's identity.

Information is provided to the Data Subject at the earliest convenience, but at a maximum of 30 days from the date the request was received. Where the provision of information is particularly complex or is subject to a valid delay, the period may be extended by two further months where necessary.

Right to Object to Processing

You have the right to object to the processing of your personal data where that processing is being undertaken based on the Data Controller’s legitimate interest. In such a case the Data Controller is required to cease processing your data unless they can demonstrate adequate grounds that override your objection.

Right to Correction of Your Personal Data

If your personal data processed by the Data Controller is incorrect, you have the right to request that we correct those data. Where notified of inaccurate data by the Data Subject, we will rectify the error within 30 days and inform any third party of the rectification if we have disclosed the personal data in question to them.

Right to Erasure

You have the right to request that your personal data is deleted in certain circumstances, such as:

  • The personal data are no longer needed for the purpose for which they were collected;
  • You withdraw your consent (where the processing was based on consent);
  • You object to the processing and no overriding legitimate grounds are justifying processing the personal data;
  • The personal data have been unlawfully processed; or
  • To comply with a legal obligation.

However, this right does not apply where, for example, the processing is necessary:

  • To comply with a legal obligation; or
  • For the establishment, exercise, or defense of legal claims.

Each User can deactivate its User Account. Please note that some data will be kept for our internal business purposes, legal, financial, and accounting purposes.

Right to Restriction of Processing

You can exercise your right to the restriction of processing in the following situations:

  • if the accuracy of the personal data is contested,
  • you consider the processing unlawful, but you do not want your personal data to be erased,
  • we no longer need the personal data, but you require it for the establishment, exercise or defense of legal claims or you have objected to the processing and verification.

Right to Data Portability

Where you have provided personal data to us, you have the right to receive such personal data back in a structured, commonly used and machine-readable format, and to have those data transmitted to a third-party without hindrance, but in each case only where:

  • The processing is carried out by automated means; and
  • The processing is based on your consent or the performance of a contract with you.

If you have provided your consent to the collection, processing, and transfer of your personal data, you have the right to fully or partly withdraw your consent. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose(s) to which you originally consented unless there is another legal ground for the processing.

Right to Lodge a Complaint

If you have any concerns or requests in relation to your personal data, please contact us at [email protected] and we will respond as soon as possible but not later than 30 days.

If you are unsatisfied with our response, you may also contact the competent supervisory authority at your country of residency or Commissioner for information of public importance and personal data protection, Bulevar kralja Aleksandra 15, 11120 Belgrade, telephone number: (+381) - 11 - 3408 900, https://www.poverenik.rs/en/home.html.

10. CHANGES TO OUR PRIVACY POLICY

Any changes we may make to our Privacy Policy will be posted on this page and where appropriate may be notified to you by email or advised to you on the next login to the Platform. If you continue with the use of the Platform after the changes were implemented, that will signify that you agree to any such changes.