This Privacy Policy explains who processes your personal data, why we use it, how long we keep it and which rights you have. “Studio keramike Bardak” is a shared brand name and is not a separate legal entity.
The controller responsible for the processing is the entity to whose product, service or communication the data relates:
The Entrepreneur and the Association are separate controllers for their own products, services and records. For website-wide analytics and management of the shared brand profiles, they jointly determine limited purposes and means of processing.
For all questions and requests, use This email address is being protected from spambots. You need JavaScript enabled to view it.. The same authorised representative determines which entity the request concerns, while the documentation of the two entities is kept separately.
We collect only the data needed for a specific enquiry, transaction or legal obligation.
Fields marked as required in a form are needed to respond, conclude or perform a contract, or comply with a legal requirement. If you do not provide them, we may not be able to provide the requested service or process your request. Other fields are voluntary.
Where processing is based on legitimate interest, we first assess whether your rights or reasonable expectations override our interest. You may object to such processing.
General enquiries
Data and purpose: Name, contact details and message content for responding and directing the enquiry
Legal basis: Pre-contractual steps or legitimate interest in communication
User account and online store
Data and purpose: Account, contact details, order, address, payment and delivery details for purchases, customer support and records
Legal basis: Pre-contractual steps, contract and legal obligation
Education, reservations and services
Data and purpose: Contact details, programme or service, preferred time, number of participants and note for offering, organising and providing the service
Legal basis: Pre-contractual steps and contract
Education vouchers
Data and purpose: Buyer details, voucher type, recipient details and temporary proof of payment for issuing and using the voucher
Legal basis: Pre-contractual steps, contract and legal obligation
Withdrawal and complaints
Data and purpose: Contact details, contract or purchase details, request, evidence and outcome
Legal basis: Legal obligation, contract and legal claims
Privacy-related requests
Data and purpose: Contact details, request type, minimum identity verification and outcome
Legal basis: Legal obligation
Data submitted through a form is sent to the shared contact address. The server record and attachment are normally deleted immediately after the email is received; any omissions are removed during the monthly review. Correspondence and necessary business records are then retained by the responsible entity.
When a voucher buyer provides data about another person, the buyer is the source of that data. Recipient details are used only to issue and use the voucher, and the recipient is directed to this Privacy Policy at the first communication.
Direct messages on the shared brand profiles are classified according to their subject. The social platform processes its own copy and technical data under its own rules.
If we temporarily share a Story in which you have tagged the brand, the source is your post and tag. To download the content, publish it permanently on the website or use it in advertising, we will request separate permission.
We request contact details from an adult. When a child-related detail is needed to organise an activity, an age or age group is sufficient. Please do not enter the child’s name in a free-text field.
The Association photographs recognisable adult participants only with prior, demonstrable consent, with separate choices for photography, internal archive, website publication, social media and paid promotion.
Unpublished working photographs are kept for no longer than 12 months. Only specially selected photographs may be kept in the Association’s historical archive, with appropriate consent, restricted access and periodic review of whether continued retention remains justified.
Photographing or publishing an identifiable minor is not covered by this procedure. Such processing would require a separate legal basis, notice and appropriate permission to be introduced first.
When you visit the website, the server and security systems may record your IP address, request time, requested page, browser or device type and error data. This data is used to deliver the page, diagnose problems, prevent abuse and protect the systems, based on legitimate interest and the security obligation.
Necessary cookies and local storage enable the session, user account, cart, security, language selection and privacy-setting memory. Without them, some requested functions cannot operate.
Optional scripts are activated only after the corresponding choice in the cookie panel:
You can change your choice later through the cookie-settings control. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
Cloudflare Turnstile protects forms from automated abuse by assessing technical browser and network signals. It is used as a security, not an advertising, function.
A Google Maps map may be displayed on the Contact page. When it loads, Google may receive your IP address and technical device or browser data.
Details of the categories, purposes and duration of individual cookies are available in the cookie-settings panel.
Only an authorised person accesses the data, to the extent necessary for the specific task. Depending on the purpose, restricted access or data may be provided to:
Manufacturers and support providers for Gridbox, BAForms and other Joomla extensions do not have access to data merely because their software is installed on the website. They may receive access only when we specifically authorise technical support, and then only to the extent necessary.
Some external services may process data in the European Union, Switzerland, the United States or other countries where their subcontractors operate.
A transfer is made only where an applicable legal mechanism or appropriate contractual, organisational and technical safeguards exist. You may request information about the mechanism used for a specific service through the contact address.
Policies of the main service providers:
Data is deleted or anonymised when it is no longer needed. The basic periods are:
General contact and direct messages
Retention period: 6 months from the last relevant communication
Reservations, education and services
Retention period: 6 months after completion, cancellation or the end of communication
Education voucher
Retention period: 6 months after issue, final expiry or cancellation
Voucher recipient details
Retention period: 30 days after use or final expiry
Photo or scan of payment slip
Retention period: No more than 30 days after payment is confirmed; longer only while a dispute is ongoing
Contract withdrawal
Retention period: 24 months after the procedure is closed
Complaint
Retention period: At least 2 years from submission; longer while a dispute or legal obligation continues
Minimum record of privacy-related requests
Retention period: 24 months after closure
User account
Retention period: While active; after closure, only data that must be retained on another legal basis remains
Unpublished working photographs
Retention period: No longer than 12 months
Selected historical photo archive
Retention period: While the purpose and appropriate legal basis exist, with periodic review and the possibility of withdrawing consent
Invoices and business records
Retention period: According to tax, accounting and other applicable legal retention periods
Technical logs and data in analytics services are retained according to the configured or contractual cycle of the specific system, for no longer than needed for security, diagnostics or approved analytics. The choice for optional analytics can be withdrawn at any time.
Backups have a limited cycle of approximately 50 daily points. Data deleted from the active system may remain in a protected backup until the cycle ends and is deleted again if such a backup is restored.
We apply access controls, separation of the two entities’ documentation, system updates and monitoring, backups and risk-appropriate deletion procedures.
No system is completely secure. We limit access to what is necessary and assess and handle data breaches in accordance with the law.
Depending on the conditions prescribed by law, you may request:
We do not make decisions producing legal or similarly significant effects based solely on automated processing.
Send a request to This email address is being protected from spambots. You need JavaScript enabled to view it. and state which product, service or activity it concerns. If necessary, we will request only additional data needed for a reasonable identity check.
We will respond without undue delay and no later than 30 days. The period may be extended by a further 60 days where required by the complexity or number of requests; we will inform you within the first 30 days.
If you believe that the processing is unlawful, you may lodge a complaint with:
Commissioner for Information of Public Importance and Personal Data Protection — Bulevar kralja Aleksandra 15, Belgrade; poverenik.rs
The applicable version and effective date are published on this page. If a change materially affects your rights or the way data is processed, we will inform you in an appropriate manner before it takes effect.
Effective date: 01.08.2026.