Version 2.0 · Effective from August 1, 2026
This Policy describes what personal data the UzmiTermin service processes, on what legal basis, how long it is retained, and what rights you have as a data subject.
This Policy has been drawn up in accordance with the Law on Personal Data Protection of the Republic of Serbia ("Official Gazette of RS", No. 87/2018, hereinafter referred to as the ZZPL).
Language of the document. This text is a translation. The original is the version in the Serbian language. In the event of discrepancies, the Serbian text shall prevail.
In this Policy we use the term "Service" or "we".
The Service works with two groups of individuals, and the roles with respect to their data are fundamentally different.
2.1. Service Providers - entrepreneurs and companies that use the Service to manage bookings (salons, workshops, studios, independent professionals).
With respect to their data, the Service acts as the Data Controller (rukovalac). We independently determine the purposes and means of processing such data and bear responsibility for it.
2.2. End Users - individuals who book services through a specific Service Provider's page.
With respect to their data, the Data Controller is the Service Provider, and the Service acts as the Data Processor (obrađivač) - meaning it processes data exclusively on behalf of the Service Provider and within the scope established by the Data Processing Agreement.
In practical terms this means the following. If you have booked a service and wish to find out how your data is used, or to request its deletion, you should first contact the Service Provider with whom you made the booking: it is they who determine the purpose and duration of storing your history. We will provide them with technical assistance in this regard.
2.3. Separately, the Service acts as the Data Controller with respect to the technical data of all visitors to the uzmitermin.rs website (Section 7).
The legal basis for processing is a mandatory element established by Article 23 of the ZZPL. All categories are set out below.
| Category | Composition | Legal basis |
|---|---|---|
| Registration data | First and last name, email address, phone number, password hash | Performance of a contract - Art. 12(1)(2) ZZPL |
| Profile data | Name and address of the place of service provision, list of services, prices, working hours | Performance of a contract |
| Payment data | Fact, amount and date of payment, pricing plan, transaction identifier. We do not receive or store full bank card details | Performance of a contract; compliance with tax and accounting obligations - Art. 12(1)(3) ZZPL |
| Technical account data | IP address, login time, device and browser type, system activity logs | Legitimate interest - Art. 12(1)(6) ZZPL: ensuring security, incident investigation, prevention of abuse |
| Support requests | Content of correspondence, attached files | Performance of a contract; legitimate interest - ensuring quality of support |
| Marketing communications | Email address, fact and date of consent | Consent - Art. 12(1)(1) ZZPL |
Processed by us on behalf of the Service Provider (see Section 2.2).
| Category | Composition | Legal basis (determined by the Service Provider) |
|---|---|---|
| Booking data | Name, phone number, selected service, date and time | Performance of a contract between the End User and the Service Provider |
| Visit history | List of past bookings, status (completed, cancelled, no-show) | Legitimate interest of the Service Provider; performance of a contract |
| Notifications | Phone number or email address for sending confirmation and reminders | Performance of a contract |
| Booking comment | Free-form text added by the End User or the Service Provider | Performance of a contract |
Special categories of data. The Service is not intended for the processing of health data or other special categories of data listed in Article 17 of the ZZPL. Service Providers should not enter such information in free-text fields. If a Service Provider nevertheless processes such data, it does so as the Data Controller, under its own responsibility, and must independently ensure the existence of a lawful basis, including the explicit consent of the End User.
See Section 7 (cookies).
We do not sell personal data and do not disclose it to third parties for their own purposes.
To operate the Service we engage data processors - service providers that process data exclusively on our instructions, on the basis of written agreements containing obligations of confidentiality and data protection.
| Recipient category | Purpose | Location |
|---|---|---|
| Cloud infrastructure provider | Hosting of the application and databases | Germany (European Union) |
| Messaging provider | Sending notifications via messengers and SMS | Switzerland |
| Email provider | Sending transactional emails | European Union |
| Payment provider | Accepting payment for pricing plans | Republic of Serbia |
| Error monitoring and analytics services | Ensuring operability and usage statistics | European Union |
The current list of specific data processors is provided to Service Providers upon request, in accordance with the procedure established by the Data Processing Agreement.
In addition, data may be disclosed to public authorities - courts, police, tax authorities - where there is a lawful and substantiated request.
The Service's infrastructure is hosted in data centres located in Germany, and message delivery is carried out by a provider located in Switzerland.
Both countries are included in the list of states and international organisations ensuring an adequate level of personal data protection, approved by the Decision of the Government of the Republic of Serbia ("Official Gazette of RS", No. 55/2019).
This means that for data transfers to these countries no additional authorisation from the Commissioner for Personal Data Protection (Poverenik) is required, and standard contractual clauses need not be applied - the transfer is carried out under the same conditions as a transfer within the Republic of Serbia (Art. 64 ZZPL).
We do not transfer personal data to countries that do not ensure an adequate level of protection. If such a transfer becomes necessary in the future, we will give prior notice and apply the safeguards provided for by law.
We retain personal data no longer than is necessary to achieve the purposes of processing.
| Data category | Retention period |
|---|---|
| Service Provider account and profile | For the duration of the account and 30 days after its deletion (a technical period allowing recovery in the event of accidental deletion) |
| Bookings and End User data | Determined by the Service Provider. By default - 24 months from the date of the booking, after which the data is anonymised |
| Access logs and technical logs | 12 months |
| Support requests | 24 months from the date the request is closed |
| Accounting and tax documents (invoices, payment confirmations) | The period established by the legislation of the Republic of Serbia on accounting and taxation - no less than 10 years |
| Consent to marketing communications and record of withdrawal of consent | Until withdrawal of consent and 3 years thereafter - as evidence of the lawfulness of prior processing |
| Backups | 30 days from the date the backup is created |
Upon expiry of the stated periods, data is irreversibly deleted or anonymised in such a way that identification of the individual becomes impossible.
Deletion of data from active databases is carried out immediately upon expiry of the relevant period; complete deletion from backups is completed within the backup rotation cycle.
The website uses cookies and similar technologies. They are managed through a consent banner displayed upon the first visit.
| Category | Purpose | Basis |
|---|---|---|
| Necessary | Authentication, session security, saving language preferences and consent settings | Legitimate interest - without these the Service cannot function. Consent is not requested |
| Analytical | Anonymised traffic and feature usage statistics | Consent |
| Marketing | Measuring advertising effectiveness, retargeting | Consent |
Analytical and marketing cookies are not set until your consent is obtained. The corresponding scripts are not loaded until you make your choice.
You may change or withdraw your consent at any time via the "Cookie settings" link at the bottom of the website. Withdrawal of consent does not affect the lawfulness of processing carried out prior to such withdrawal.
Disabling analytical and marketing cookies does not restrict access to the features of the Service.
We apply technical, organisational and personnel measures appropriate to the nature and volume of processing, in accordance with Articles 42 and 50 of the ZZPL:
No system of data transmission and storage can guarantee absolute security. In the event of a personal data breach posing a high risk to the rights and freedoms of data subjects, we shall notify the Commissioner within 72 hours and inform the affected individuals in accordance with Articles 52 and 53 of the ZZPL.
In accordance with the ZZPL you have the following rights.
9.1. Right of access (Art. 26) - to obtain confirmation as to whether your data is being processed, and a copy of such data.
9.2. Right to rectification and supplementation (Art. 29) - to request the correction of inaccurate data and the supplementation of incomplete data.
9.3. Right to erasure (Art. 30) - to request the deletion of data, in particular where it is no longer necessary for the purposes of processing or where consent on which processing was based has been withdrawn.
9.4. Right to restriction of processing (Art. 31) - to request a temporary suspension of processing, for example during a period of verification of data accuracy or consideration of your objection.
9.5. Right to data portability (Art. 36) - to receive your data in a structured, commonly used, machine-readable format.
9.6. Right to object (Art. 37) - to object to processing based on legitimate interest. In the case of processing for the purposes of direct marketing, the objection shall be complied with unconditionally and without delay.
9.7. Right to withdraw consent (Art. 15(3)) - where processing is based on consent, you have the right to withdraw it at any time, as easily as it was given. Withdrawal does not affect the lawfulness of processing carried out prior to it.
Please note: the processing of Service Provider data for the purpose of providing the Service is based on performance of a contract, not on consent. Withdrawal of consent in respect of such processing is not possible; cessation of processing in this case is effected by terminating the contract and deleting the account.
9.8. Right not to be subject to automated decision-making (Art. 38). The Service does not make decisions producing legal effects based solely on automated processing, including profiling.
9.9. Right to lodge a complaint. You have the right to lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti):
Bulevar kralja Aleksandra 15, 11120 Belgrade, Republic of Serbia www.poverenik.rs · office@poverenik.rs · +381 11 3408 900
Contacting us is not a prerequisite for lodging a complaint.
Requests should be sent to info@uzmitermin.rs or by post to the address specified in Section 1.
We shall respond within no more than 30 days from the date of receipt of the request. If the request is complex, the period may be extended by a further 30 days, of which we shall notify you with an indication of the reasons.
The exercise of rights is free of charge. In the case of manifestly unfounded or excessive requests, in particular repetitive requests, we may charge a reasonable fee or refuse to comply, providing reasons for the refusal.
To protect your data, we may request additional information necessary to verify your identity.
If you are an End User and your request concerns data entered when booking with a specific Service Provider, please direct it to that Service Provider - they are the Data Controller. If you are unable to contact them, write to us and we will assist.
The Service is not intended for independent use by persons under the age of 15.
In accordance with Article 16 of the ZZPL, where processing is based on consent and relates to information society services, the consent of a person under 15 is valid only with the authorisation of a parent or other legal representative.
We do not knowingly collect data of minors. If you become aware that a child has provided us with their data without appropriate authorisation, please notify us at info@uzmitermin.rs and we will delete it.
The booking of a service for a minor by a Service Provider is carried out under the responsibility of the Service Provider and their legal representative.
We may amend this Policy in connection with the development of the Service or changes in legislation.
The current version is always available on this page, indicating the version number and the date of the last update. We shall notify Service Providers of material changes via the email address provided at registration no less than 15 days before the changes take effect.
Previous versions are provided upon request.
Version 2.0 of July 30, 2026
© 2026 UzmiTermin · 11191 Belgrade, Republic of Serbia