Privacy Policy

This Privacy Policy explains who processes your personal data, why we use it, how long we keep it and which rights you have. “Studio keramike Bardak” is a shared brand name and is not a separate legal entity.

 

1. Who processes your personal data

 

The controller responsible for the processing is the entity to whose product, service or communication the data relates:

  • Saša Matić PR Studio keramike Bardak, Pančićeva 14, Belgrade (Stari grad), company ID 65923181, tax ID 112170797 — for the online store, sale of ceramic products, user accounts, delivery and customer support (the “Entrepreneur”).
  • Udruženje grnčara Bardak, Pančićeva 14, Belgrade, company ID 28025548, tax ID 106810377 — for courses, workshops and other educational activities, reservations, education vouchers, contract ceramic firing, studio rental and professional advice (the “Association”).

 

The Entrepreneur and the Association are separate controllers for their own products, services and records. For website-wide analytics and management of the shared brand profiles, they jointly determine limited purposes and means of processing.

 

For all questions and requests, use This email address is being protected from spambots. You need JavaScript enabled to view it.. The same authorised representative determines which entity the request concerns, while the documentation of the two entities is kept separately.

 

2. What data we use and why

 

We collect only the data needed for a specific enquiry, transaction or legal obligation.

 

Fields marked as required in a form are needed to respond, conclude or perform a contract, or comply with a legal requirement. If you do not provide them, we may not be able to provide the requested service or process your request. Other fields are voluntary.

 

Where processing is based on legitimate interest, we first assess whether your rights or reasonable expectations override our interest. You may object to such processing.

 

General enquiries

Data and purpose: Name, contact details and message content for responding and directing the enquiry

Legal basis: Pre-contractual steps or legitimate interest in communication

 

User account and online store

Data and purpose: Account, contact details, order, address, payment and delivery details for purchases, customer support and records

Legal basis: Pre-contractual steps, contract and legal obligation

 

Education, reservations and services

Data and purpose: Contact details, programme or service, preferred time, number of participants and note for offering, organising and providing the service

Legal basis: Pre-contractual steps and contract

 

Education vouchers

Data and purpose: Buyer details, voucher type, recipient details and temporary proof of payment for issuing and using the voucher

Legal basis: Pre-contractual steps, contract and legal obligation

 

Withdrawal and complaints

Data and purpose: Contact details, contract or purchase details, request, evidence and outcome

Legal basis: Legal obligation, contract and legal claims

 

Privacy-related requests

Data and purpose: Contact details, request type, minimum identity verification and outcome

Legal basis: Legal obligation

 

3. Forms, email, vouchers and social networks

 

Data submitted through a form is sent to the shared contact address. The server record and attachment are normally deleted immediately after the email is received; any omissions are removed during the monthly review. Correspondence and necessary business records are then retained by the responsible entity.

 

When a voucher buyer provides data about another person, the buyer is the source of that data. Recipient details are used only to issue and use the voucher, and the recipient is directed to this Privacy Policy at the first communication.

 

Direct messages on the shared brand profiles are classified according to their subject. The social platform processes its own copy and technical data under its own rules.

 

If we temporarily share a Story in which you have tagged the brand, the source is your post and tag. To download the content, publish it permanently on the website or use it in advertising, we will request separate permission.

 

4. Children and photographs

 

We request contact details from an adult. When a child-related detail is needed to organise an activity, an age or age group is sufficient. Please do not enter the child’s name in a free-text field.

 

The Association photographs recognisable adult participants only with prior, demonstrable consent, with separate choices for photography, internal archive, website publication, social media and paid promotion.

 

Unpublished working photographs are kept for no longer than 12 months. Only specially selected photographs may be kept in the Association’s historical archive, with appropriate consent, restricted access and periodic review of whether continued retention remains justified.

 

Photographing or publishing an identifiable minor is not covered by this procedure. Such processing would require a separate legal basis, notice and appropriate permission to be introduced first.

 

5. Technical data, cookies and external content

 

When you visit the website, the server and security systems may record your IP address, request time, requested page, browser or device type and error data. This data is used to deliver the page, diagnose problems, prevent abuse and protect the systems, based on legitimate interest and the security obligation.

 

Necessary cookies and local storage enable the session, user account, cart, security, language selection and privacy-setting memory. Without them, some requested functions cannot operate.

 

Optional scripts are activated only after the corresponding choice in the cookie panel:

  • Metricool is used for visit analytics and content management of the shared brand profiles;
  • Google tag and related Google measurement services are used to measure visits and marketing results. Google Ads campaigns and a separate conversion event are not currently active.

 

You can change your choice later through the cookie-settings control. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

 

Cloudflare Turnstile protects forms from automated abuse by assessing technical browser and network signals. It is used as a security, not an advertising, function.

 

A Google Maps map may be displayed on the Contact page. When it loads, Google may receive your IP address and technical device or browser data.

 

Details of the categories, purposes and duration of individual cookies are available in the cookie-settings panel.

 

6. Who may have access to the data

 

Only an authorised person accesses the data, to the extent necessary for the specific task. Depending on the purpose, restricted access or data may be provided to:

  • UNITED INTERNET DOO BEOGRAD (Unlimited.rs) — hosting, server logs and backups;
  • Proton AG — email service;
  • Metricool Software, S.L. — analytics and profile management;
  • Google — Google tag, measurement and Google Maps;
  • Cloudflare — Turnstile form protection;
  • a bank, accountant, courier or payment service — when needed for payment, an invoice or delivery;
  • social platforms — when you contact them, tag the brand or interact through them;
  • competent authorities — when we must act under the law or a binding request.

 

Manufacturers and support providers for Gridbox, BAForms and other Joomla extensions do not have access to data merely because their software is installed on the website. They may receive access only when we specifically authorise technical support, and then only to the extent necessary.

 

7. Processing outside Serbia

 

Some external services may process data in the European Union, Switzerland, the United States or other countries where their subcontractors operate.

 

A transfer is made only where an applicable legal mechanism or appropriate contractual, organisational and technical safeguards exist. You may request information about the mechanism used for a specific service through the contact address.

 

Policies of the main service providers:

 

8. How long we keep data

 

Data is deleted or anonymised when it is no longer needed. The basic periods are:

 

General contact and direct messages

Retention period: 6 months from the last relevant communication

 

Reservations, education and services

Retention period: 6 months after completion, cancellation or the end of communication

 

Education voucher

Retention period: 6 months after issue, final expiry or cancellation

 

Voucher recipient details

Retention period: 30 days after use or final expiry

 

Photo or scan of payment slip

Retention period: No more than 30 days after payment is confirmed; longer only while a dispute is ongoing

 

Contract withdrawal

Retention period: 24 months after the procedure is closed

 

Complaint

Retention period: At least 2 years from submission; longer while a dispute or legal obligation continues

 

Minimum record of privacy-related requests

Retention period: 24 months after closure

 

User account

Retention period: While active; after closure, only data that must be retained on another legal basis remains

 

Unpublished working photographs

Retention period: No longer than 12 months

 

Selected historical photo archive

Retention period: While the purpose and appropriate legal basis exist, with periodic review and the possibility of withdrawing consent

 

Invoices and business records

Retention period: According to tax, accounting and other applicable legal retention periods

 

Technical logs and data in analytics services are retained according to the configured or contractual cycle of the specific system, for no longer than needed for security, diagnostics or approved analytics. The choice for optional analytics can be withdrawn at any time.

 

Backups have a limited cycle of approximately 50 daily points. Data deleted from the active system may remain in a protected backup until the cycle ends and is deleted again if such a backup is restored.

 

9. Security

 

We apply access controls, separation of the two entities’ documentation, system updates and monitoring, backups and risk-appropriate deletion procedures.

 

No system is completely secure. We limit access to what is necessary and assess and handle data breaches in accordance with the law.

 

10. Your rights

 

Depending on the conditions prescribed by law, you may request:

  • information and access to data;
  • a copy of the data;
  • correction or completion;
  • erasure;
  • restriction of processing;
  • data portability;
  • to object;
  • to withdraw consent.

 

We do not make decisions producing legal or similarly significant effects based solely on automated processing.

 

Send a request to This email address is being protected from spambots. You need JavaScript enabled to view it. and state which product, service or activity it concerns. If necessary, we will request only additional data needed for a reasonable identity check.

 

We will respond without undue delay and no later than 30 days. The period may be extended by a further 60 days where required by the complexity or number of requests; we will inform you within the first 30 days.

 

If you believe that the processing is unlawful, you may lodge a complaint with:

 

Commissioner for Information of Public Importance and Personal Data Protection — Bulevar kralja Aleksandra 15, Belgrade; poverenik.rs

 

11. Changes to this Policy

 

The applicable version and effective date are published on this page. If a change materially affects your rights or the way data is processed, we will inform you in an appropriate manner before it takes effect.

 

Effective date: 01.08.2026.