Privacy Policy
Personal data processing notice pursuant to Article 23 of the Law on Personal Data Protection (Official Gazette of RS, No. 87/2018) and Article 13 of the General Data Protection Regulation (GDPR, EU Regulation 2016/679).
1. Data Controller
The controller of personal data collected through the CVETNJAK website is:
- Name
- BCILITY DOO
- Address
- 1. Oktobra 12
- Registration No.
- 21870005
- PIB
- 113454392
- [email protected]
BCILITY DOO sells tickets as a distributor and technical intermediary, on behalf of and for the account of the event organizer. For data the organizer requires in order to hold the event itself, the organizer is an independent controller. Details on the intermediary status are set out in the Terms and Conditions.
We have not appointed a data protection officer as there is no legal obligation to do so. All questions and requests concerning data processing should be directed to the contact listed above.
2. What Personal Data We Process
We process only the data necessary to sell and issue tickets and to fulfil our legal obligations:
- Data you enter yourself: first name, last name, email address and (optionally) telephone number. For buyers requesting an invoice issued to a legal entity — also the tax identification number (PIB).
- Order data: order number, selected seats/tables, quantity, price, payment method, payment status and time of purchase.
- Ticket data: issued tickets with QR codes and a record of scans at the entrance (time and outcome of the ticket check).
- Communications: a log of sent emails (order confirmation, tickets, fiscal receipt, reminders) and SMS messages, serving as proof of delivery.
- Technical data: IP address, browser and device type, and a session identifier stored in a cookie, for security purposes and correct operation of seat reservation.
We do not process payment card data
The card number, expiry date and CVV are entered exclusively on the bank's secure page. That data never reaches our system nor is it stored on our servers. Only the transaction outcome (successful / unsuccessful) and a reference number are available to us.
We do not process special categories of personal data (health data, ethnic origin, political or religious beliefs, sexual life, etc.), nor do we request national identification or ID card numbers.
3. Purposes of Processing and Legal Basis
Each purpose of processing rests on a corresponding legal basis under Article 12 of the Law on Personal Data Protection (i.e. Article 6 GDPR):
Selling and issuing tickets, delivering tickets by email, entrance control at the event
Performance of a contract — Art. 12(1)(2) LPDP
Without this data we cannot issue or deliver a ticket.
Issuing the fiscal receipt and keeping business records
Compliance with legal obligations — Art. 12(1)(3) LPDP
The Law on Fiscalisation, the Accounting Act and tax legislation.
Handling complaints, processing refunds and defence in potential disputes
Legal obligation and legitimate interest — Art. 12(1)(3) and (6) LPDP
The obligation to act upon a complaint is prescribed by the Consumer Protection Act.
Notices of changes, postponement or cancellation of an event, and reservation reminders
Performance of a contract — Art. 12(1)(2) LPDP
These are service messages and cannot be opted out of while you have an active order.
Newsletter — notices about new events and offers
Consent — Art. 12(1)(1) LPDP
Only if you ticked the corresponding box. Consent may be withdrawn at any time.
Website security, prevention of abuse and fraud, administrator access logs
Legitimate interest — Art. 12(1)(6) LPDP
Our interest is protecting the system, buyers and organizers from unauthorised access and ticket forgery.
Website traffic statistics (Google Analytics)
Consent — Art. 12(1)(1) LPDP
See section 7, Cookies and Analytics.
Providing data for a purchase is not a statutory obligation but is a requirement for concluding the contract — if you do not provide it, purchasing a ticket is not possible. Giving consent for the newsletter is entirely voluntary and does not affect your ability to purchase.
4. Data Retention Periods
We retain data only for as long as necessary for the purpose for which it was collected, or until the expiry of a statutory retention period:
- order data and issued fiscal receipts — for the periods prescribed by the Accounting Act and tax legislation (at least 5 years, and for certain records up to 10 years from the end of the business year);
- customer data and purchase history — until the expiry of complaint and limitation periods, and at the longest until the accounting period above expires;
- the log of sent emails serving as proof of ticket delivery — at least 120 days from the date of delivery;
- the record of ticket scans at the entrance — until any disputes concerning entry to the event are resolved;
- the newsletter email address — until consent is withdrawn (unsubscribed);
- technical and security logs (IP addresses, administrator account access) — for the period needed to detect and investigate security incidents;
- a temporary seat hold in the cart — deleted automatically when the payment window expires.
Once these periods expire, data is deleted or permanently anonymised, unless another legal basis for further retention exists.
5. Data Recipients and Processors
We do not sell your data and do not pass it on to third parties for marketing purposes. Data is disclosed only to the following categories of recipients and only to the extent necessary for the stated purpose:
- Event organizer (ISHRANA DOO) — the list of buyers and reserved seats, for holding the event and controlling entry.
- Bank and payment processor — Raiffeisen banka a.d. Belgrade, for processing card and IPS payments and any refunds.
- Tax Administration of the Republic of Serbia — fiscal receipt data, in accordance with the Law on Fiscalisation.
- Hetzner Online GmbH, Germany — the processor providing the server and database on which the application runs (hosting).
- Microsoft Ireland Operations Ltd. — the Microsoft Outlook (Microsoft 365) service, used to send order confirmations, tickets, fiscal receipts and reminders.
- BCILITY DOO, Serbia — the processor whose SMS gateway is used to deliver SMS notifications.
- BCILITY DOO, Serbia — the platform maintainer, as a processor, to the extent necessary for technical support and system maintenance.
- Google Ireland Ltd. / Google LLC — traffic statistics (Google Analytics), based on your consent.
- Competent authorities — courts, police, tax and inspection authorities, where a legal obligation exists.
Contracts have been concluded with all processors obliging them to process data solely on our instructions, with appropriate protective measures and a duty of confidentiality.
6. Transfer of Data Outside the Republic of Serbia
The database and all accompanying files are stored on servers of Hetzner Online GmbH, in a data centre located in the Federal Republic of Germany. Data is therefore processed and stored within the European Union.
Germany is on the list of countries deemed to ensure an adequate level of personal data protection (Decision on the list of countries, parts of their territories or one or more sectors of specific activities in those countries and international organisations in which an adequate level of personal data protection is deemed to be ensured, Official Gazette of RS, No. 55/2019). Accordingly, this transfer requires no prior authorisation from the Commissioner, in line with Article 64 of the Law on Personal Data Protection.
Emails (order confirmations, tickets, fiscal receipts and reminders) are sent via the Microsoft Outlook (Microsoft 365) service, with Microsoft Ireland Operations Ltd. of Ireland as the contracting party. As a global service provider, Microsoft may also process data outside the European Economic Area, in which case the transfer is based on standard contractual clauses and additional safeguards applied by Microsoft.
Using Google Analytics may involve the transfer of certain technical data (including a truncated IP address and cookie identifier) to the United States. Such transfer takes place on the basis of standard contractual clauses and additional safeguards applied by Google, and only if you have consented to analytics cookies.
Any other transfer of data to a third country takes place only under the conditions set out in Articles 64–69 of the Law on Personal Data Protection. A copy of the safeguards applied may be requested at the contact given in section 1.
7. Cookies and Analytics
Cookies are small text records that a website stores on your device. We use them to a minimal extent:
Strictly necessary cookies
No consent required
A session identifier that temporarily holds the seats you selected, a login cookie for administrators and scanners, and form abuse protection. The site cannot function without them.
Analytics cookies (Google Analytics 4)
Consent — set only if you give it
They measure the number of visitors, pages visited and traffic source, in aggregate statistical form. We do not use them for advertising, remarketing or profiling of individual visitors.
We do not use advertising cookies, social network pixels, or tools for tracking user behaviour across different websites. You can delete or block cookies at any time in your browser settings — note that blocking strictly necessary cookies makes purchasing tickets impossible.
8. Newsletter and Promotional Notices
We send promotional messages about new events and offers exclusively to those who have given explicit consent — by ticking the box at checkout or subscribing to the newsletter.
You may withdraw consent at any time, without giving reasons and without any consequences, by clicking the unsubscribe link in every message or by sending a request to our email address. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Service messages relating to your order (purchase confirmation, tickets, fiscal receipt, notice of an event change or cancellation) are not promotional and cannot be opted out of while the order is active.
9. Technical and Organisational Safeguards
We apply safeguards appropriate to the risk, in accordance with Article 42 of the Law on Personal Data Protection:
- all traffic with the website is encrypted (HTTPS / TLS);
- access to the administrative area is protected by account and password, with roles and access rights limited per role;
- passwords are stored exclusively in cryptographically hashed form;
- a log of administrator actions on data is maintained (audit log);
- payment card data is neither entered on our website nor stored in our system;
- tickets contain a unique QR code, and the scan log prevents repeated use of the same ticket;
- regular database backups and restricted physical and logical access to servers.
Should a personal data breach occur that may result in a high risk to the rights and freedoms of individuals, we will notify the Commissioner within 72 hours and, where prescribed, the affected individuals as well.
10. Your Rights
In relation to the data we process, you have the following rights (Articles 26–39 of the Law on Personal Data Protection):
- the right of access — to be informed whether we process your data and to obtain a copy of it;
- the right to rectification and completion of inaccurate or incomplete data;
- the right to erasure ("right to be forgotten") — where data is no longer needed for the purpose, where you withdraw consent, or where processing is unlawful;
- the right to restriction of processing — for example while the accuracy of the data is being verified;
- the right to data portability — to receive your data in a structured, commonly used and machine-readable format;
- the right to object to processing based on legitimate interest, and at any time to processing for direct marketing purposes;
- the right to withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal.
A request may be sent to the email or postal address given in section 1. We will act upon the request without delay and at the latest within 30 days of receipt; that period may be extended by a further 60 days where the request is complex, of which we will notify you. Acting upon a request is free of charge.
To protect your data, we may request additional information necessary to confirm the identity of the person making the request. Please note that the right to erasure cannot be exercised to the extent that we are legally obliged to retain data (e.g. fiscal receipt data).
11. Complaint to the Commissioner
If you believe your data is being processed unlawfully, you have the right to lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection. Lodging a complaint with the Commissioner is neither a precondition for, nor does it exclude, the right to judicial protection.
- Address
- Bulevar kralja Aleksandra 15, 11120 Beograd
- Phone
- +381 11 3408 900
- [email protected]
- Website
- www.poverenik.rs
12. Automated Decision-Making and Profiling
We do not take decisions based solely on automated processing, including profiling, that produce legal effects concerning you or significantly affect your position.
13. Minors
The website is not intended for independent purchases by persons under 15 years of age, and we do not knowingly collect such data. Should we determine that a minor's data was entered without the consent of a parent or legal guardian, we will delete it without delay.
14. Changes to This Policy
We may amend this policy to align with changes in legislation or in how the website operates. The version in force is always published on this page. We will notify you on the website of changes that materially alter the processing of your data and, where prescribed, by email as well.
15. Contact
For any questions, requests to exercise your rights, or objections regarding the processing of personal data, please contact us:
- Name
- BCILITY DOO
- Address
- 1. Oktobra 12
- [email protected]
The ticket purchase terms can be read in the Terms and Conditions.