Revision 1.0 · Effective from 1 August 2026
This Data Processing Agreement (hereinafter - "Agreement") is concluded in accordance with Article 45 of the Law on Personal Data Protection of the Republic of Serbia ("Službeni glasnik RS", No. 87/2018, hereinafter - ZZPL) between:
This Agreement forms an integral part of the Terms of Use and is accepted by the Data Controller simultaneously therewith, upon completion of registration in the Service. No separate signature is required: pursuant to Article 45, paragraph 3 of the ZZPL, electronic form is equivalent to written form.
Language of this document. This text is a translation. The original is the version in the Serbian language. In the event of discrepancies, the Serbian text shall prevail.
1.1. This Agreement governs the processing by the Data Processor of personal data of End Users - individuals who book appointments for the Data Controller's services through the Service.
1.2. With respect to such data:
1.3. This Agreement does not apply to the processing of personal data of the Service Provider itself - its registration, payment, and technical data. In respect of such data, the Data Processor acts as an independent Data Controller, and the processing is governed by the Privacy Policy.
1.4. The Parties acknowledge that the Data Processor does not determine the purposes of processing End Users' data and does not use such data for its own purposes, including for marketing, model training, profiling, or disclosure to third parties.
In accordance with Article 45, paragraph 2 of the ZZPL, the processing is described as follows.
2.1. Subject matter of processing. Provision to the Data Controller of software for online appointment booking, calendar management, storage of appointment history, and automated dispatch of notifications to the Data Controller's clients.
2.2. Nature of processing. Collection, recording, structuring, storage, alteration, retrieval, use, transmission of notifications, restriction, erasure, and pseudonymisation - to the extent necessary for the operation of the Service.
2.3. Purpose of processing. Organisation of appointment booking for the Data Controller's services, confirmation and reminder of appointments, maintenance of visit history, and generation of business statistics for the Data Controller.
2.4. Duration of processing. From the moment of the Data Controller's registration in the Service until the termination of the Terms of Use, subject to Section 10 of this Agreement.
2.5. Categories of data subjects. Clients of the Data Controller - natural persons booking appointments for the Data Controller's services - as well as employees of the Data Controller to whom the Data Controller has granted access to the account.
2.6. Types of personal data:
2.7. Special categories of data. The Service is not intended for the processing of data referred to in Article 17 of the ZZPL, including health data. The Data Controller undertakes not to enter such information into free-text fields and acknowledges that, in the event of a breach of this obligation, the Data Controller bears sole and full responsibility for the existence of a legal basis for such processing, including the explicit consent of the data subject.
3.1. The Data Controller warrants that it processes the personal data of its clients on a lawful basis within the meaning of Article 12 of the ZZPL, and that the transfer of such data to the Data Processor is lawful.
3.2. The Data Controller independently ensures the provision of information to data subjects to the extent required by Articles 23 and 24 of the ZZPL. The Data Processor provides the technical means for this purpose - by displaying on the booking page a notice identifying the Data Controller - however, the content and completeness of such information remains the responsibility of the Data Controller.
3.3. The Data Controller undertakes to:
3.4. The Data Controller acknowledges that the content, accuracy, and lawfulness of the data it enters are beyond the control of the Data Processor.
The Data Processor undertakes to:
4.1. Act only on instructions. Process personal data solely on the basis of documented instructions from the Data Controller. Instructions shall be deemed to include this Agreement, the Terms of Use, and the actions of the Data Controller within the Service interface.
If the Data Processor is required to carry out processing pursuant to a requirement of the law of the Republic of Serbia, it shall notify the Data Controller of this prior to commencing such processing, unless such notification is prohibited by law.
4.2. Notify of unlawful instructions. Promptly inform the Data Controller if, in the Data Processor's opinion, an instruction received violates the ZZPL or other data protection rules.
4.3. Ensure confidentiality. Grant access to personal data only to those employees and contractors who require it for the performance of obligations, and only where they are subject to a confidentiality obligation - whether contractual or imposed by law. This obligation shall survive the termination of the relationship with the Data Processor.
4.4. Implement security measures. Maintain measures as required by Article 50 of the ZZPL, appropriate to the level of risk, including:
4.5. Not alter the territory of processing without complying with Section 6 of this Agreement.
5.1. General authorisation. The Data Controller grants the Data Processor general written authorisation to engage sub-processors - data centre operators, messaging and email delivery providers, payment providers, monitoring services - for the purposes of operating the Service.
5.2. Conditions of engagement. The Data Processor shall conclude with each sub-processor an agreement imposing data protection obligations no less stringent than those established by this Agreement. The Data Processor shall be fully liable to the Data Controller for the acts of the sub-processors it engages.
5.3. Current list. A list of sub-processors, indicating their function and territory of processing, shall be provided to the Data Controller upon request sent to info@uzmitermin.rs, and is published in the Privacy Policy at the level of categories of recipients.
5.4. Notification of changes. The Data Processor shall notify the Data Controller at the email address provided during registration of the engagement of a new or replacement sub-processor at least 30 days before the new sub-processor commences processing.
5.5. Right to object. The Data Controller may, within 15 days of receiving notification, submit a reasoned objection to the engagement of a new sub-processor. The Parties shall discuss the objection in good faith. If no reasonable solution is found, the Data Controller shall be entitled to terminate the Terms of Use without penalty, with a refund of the pro-rata portion of any prepaid unused period.
Absence of an objection within the specified period shall be deemed consent.
6.1. Processing of personal data is carried out on the territory of the Republic of Serbia and countries included in the list of countries and international organisations ensuring an adequate level of personal data protection, approved by Decision of the Government of the Republic of Serbia ("Službeni glasnik RS", No. 55/2019).
6.2. As at the date of entry into force of this Agreement, the Service infrastructure is hosted in data centres located in Germany (European Union), and notification delivery is carried out by a provider located in Switzerland. Both countries are included in the aforementioned list; accordingly, the transfer is made on the basis of Article 64 of the ZZPL and does not require additional authorisation from the Commissioner.
6.3. The Data Processor shall not transfer personal data to countries that do not ensure an adequate level of protection without applying safeguards as provided for in Article 65 of the ZZPL, including the Commissioner's standard contractual clauses, and without prior notification to the Data Controller in accordance with clause 5.4.
7.1. Rights of data subjects. The Data Processor shall provide the Data Controller with technical means to independently exercise the rights of data subjects: viewing, rectification, export, and erasure of client data through the Service interface.
If a data subject contacts the Data Processor directly, the Data Processor shall not respond to such request on its merits, but shall promptly redirect it to the Data Controller, notifying the data subject accordingly.
If the exercise of a right is technically not possible through the interface, the Data Processor shall provide reasonable assistance upon request sent to info@uzmitermin.rs, within a timeframe enabling the Data Controller to comply with the statutory response deadlines.
7.2. Personal data breaches. Upon discovering a personal data breach, the Data Processor shall notify the Data Controller without undue delay and no later than 48 hours from the moment the Data Processor becomes aware of the breach.
The notification shall contain a description of the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach.
The obligation to notify the Commissioner and data subjects, as established by Articles 52 and 53 of the ZZPL, rests with the Data Controller. The Data Processor shall provide the necessary assistance in this regard.
7.3. Data protection impact assessment. Upon a reasoned request, the Data Processor shall provide the Data Controller with information necessary for conducting a data protection impact assessment (Art. 54 ZZPL) and for consultations with the Commissioner (Art. 55 ZZPL), to the extent available to the Data Processor.
7.4. Scope of assistance. Assistance shall be provided having regard to the nature of the processing and the information available to the Data Processor. The Data Processor may charge a reasonable fee for assistance that goes beyond standard support, provided that prior notice is given to the Data Controller.
8.1. The Data Processor shall provide the Data Controller, upon written request, with information necessary to demonstrate compliance with the obligations under this Agreement.
8.2. The Data Controller may, no more than once per calendar year, conduct a compliance audit. Such audit shall be conducted:
8.3. The Data Processor may fulfil its obligation under clause 8.2 by providing an up-to-date report of an independent audit or certification, provided that such report reasonably covers the subject matter of the audit.
8.4. The frequency restrictions shall not apply where an audit is conducted pursuant to a direct order of the Commissioner or following a confirmed personal data breach.
The Data Processor shall maintain records of all categories of processing activities carried out on behalf of the Data Controller, to the extent required by Article 47, paragraph 2 of the ZZPL, and shall make such records available to the Commissioner upon request.
10.1. Export. Prior to deletion of the account and within 30 days following the termination of the Terms of Use, the Data Controller may export its clients' data in a structured, machine-readable format through the Service interface or upon request.
10.2. Erasure. Upon expiry of the aforementioned period, the Data Processor shall erase End Users' data from active databases. Erasure from backup copies shall be completed within the backup rotation cycle - no more than 30 days from the date of erasure from active databases.
10.3. Exception. The Data Processor shall be entitled to retain data whose retention is required by the law of the Republic of Serbia, in particular tax and accounting legislation. The confidentiality and protection obligations established by this Agreement shall continue to apply to such data.
10.4. Upon written request, the Data Processor shall confirm the fact of erasure.
11.1. Each Party shall be liable for failure to fulfil its obligations under this Agreement in accordance with the ZZPL and the law of the Republic of Serbia.
11.2. The Data Processor shall not be liable for the absence of a legal basis for processing on the part of the Data Controller, for the Data Controller's failure to fulfil the obligation to inform data subjects, or for the content of data entered by the Data Controller or its employees.
11.3. The limitation of liability established in Section 10 of the Terms of Use shall apply to this Agreement, except where such limitation is not permitted by mandatory provisions of the law of the Republic of Serbia, or in cases of wilful misconduct or gross negligence.
12.1. The Agreement enters into force upon the Data Controller's registration in the Service and remains in force for the duration of the Terms of Use.
12.2. Provisions which by their nature are intended to survive termination of the Agreement - confidentiality, erasure of data, demonstration of compliance - shall remain in force after termination.
12.3. The Data Processor may amend this Agreement in connection with changes in legislation, the composition of sub-processors, or the technical architecture of the Service. The Data Controller shall be notified of material changes by email at least 30 days before they take effect.
In the event of disagreement, the Data Controller shall be entitled to terminate the Terms of Use prior to the date on which the amendments take effect.
12.4. In the event of a conflict between this Agreement and the Terms of Use with respect to the processing of End Users' personal data, this Agreement shall prevail.
13.1. This Agreement shall be governed by the law of the Republic of Serbia.
13.2. Disputes shall be resolved in accordance with the procedure established in Section 13 of the Terms of Use.
Data Processor: info@uzmitermin.rs Pavel Zorin pr Inweb Innovations, Borska 49, 11191 Belgrade, Republic of Serbia
Supervisory authority: Commissioner for Information of Public Importance and Personal Data Protection Bulevar kralja Aleksandra 15, 11120 Belgrade · www.poverenik.rs
Revision 1.0 of July 30, 2026
© 2026 UzmiTermin · 11191 Belgrade, Republic of Serbia