Privacy Policy
This privacy notice explains how the demo site dezimal.svilenkovic.rs ("the Site") handles personal data, consistent with EU GDPR (Reg. 2016/679) and the Serbian Personal Data Protection Act (Zakon o zaštiti podataka o ličnosti, "Sl. glasnik RS" 87/2018).
Data controller
The Site is operated by D. Svilenković (Serbia). Contact: info@svilenkovic.com. Because this is a demo / portfolio site, the operator is the controller for any data submitted here.
What we collect
- Contact-form submissions: name, email, company (optional), message text, timestamp, IP address.
- Server access logs: IP, user agent, requested URL, timestamp. Retained up to 30 days for security/abuse purposes.
- Analytics: Google Analytics 4 (measurement ID G-S83SEJQ064) — only after you click "Accept" on the cookie banner. We use IP anonymisation and Google Consent Mode v2; analytics is denied by default.
- Functional cookies: a single first-party cookie (
cc_consent, 1 year) records your cookie choice. PHP session cookie is set transiently for CSRF protection on the contact form.
Lawful basis
- Form submissions: legitimate interest (Art. 6(1)(f) GDPR / čl. 12 ZZPL) — to respond to the inquiry. You may object at any time.
- Analytics & marketing cookies: explicit consent (Art. 6(1)(a) GDPR / čl. 12 ZZPL) collected via the banner.
- Server logs: legitimate interest — security and abuse prevention.
How long we keep it
- Form messages: up to 90 days from receipt, then deleted.
- Server logs: up to 30 days.
- Analytics: 14 months (GA4 default, configured maximum allowed without payment).
Who we share it with
We do not sell or rent personal data. Limited processors:
- Hosting infrastructure (Svilenković, Serbia — see svilenkovic.com).
- Google Ireland Ltd. — analytics, only after consent.
We do not transfer personal data outside the EU/EEA except via Google's standard contractual clauses (Consent Mode v2 keeps cookieless pings inside Google's GDPR posture).
Your rights
Under GDPR / ZZPL you can ask us to:
- Confirm whether we hold data about you and provide a copy (access).
- Correct inaccurate data (rectification).
- Delete your data (erasure / "right to be forgotten").
- Restrict or object to processing.
- Receive your data in a portable format.
- Withdraw consent at any time without affecting processing already performed.
Email info@svilenkovic.com. We respond within 30 days.
Complaints
If you are not satisfied, you can lodge a complaint with the Serbian DPA — Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti (poverenik.rs) — or your local EU supervisory authority.
Security
HTTPS is enforced (HSTS preload), responses use a strict CSP, contact-form posts require a CSRF token, and rate limits apply. We follow patch schedules for OS / web server / PHP and run periodic malware scans.