Privacy and Cookie Policy
Last updated: 17 September 2026
This policy explains how UWIT handles personal data when you visit uwit.rs, contact us, or subscribe to our newsletter. It is intended to provide the information required by the Serbian Law on Personal Data Protection and, where it applies, the EU General Data Protection Regulation (GDPR).
1. Data controller
The controller responsible for the processing described in this policy is:
UWIT DOO BEOGRADMilića Rakića 5, 11050 Belgrade (Zvezdara), Serbia
Registration number (MB): 21957364
Tax identification number (PIB): 114011200
Email: [email protected]
2. Personal data we collect
Depending on how you use the website, we collect:
- Contact data: your name, email address, message, submission time, and later correspondence when you contact us.
- Newsletter data: your email address, sign-up time, and the token used to process an unsubscribe request.
- Technical and security data: IP address, request time, requested URL, browser and device information, referrer, and diagnostic or security events generated when the site is accessed. Our application also uses an IP-based rate limit to prevent form abuse.
- Analytics data: when analytics is enabled, Google Analytics may receive online identifiers, pages viewed, interaction and session data, approximate location, and browser or device information. We do not intentionally send your name, email address, or contact-form message to Google Analytics.
We obtain contact and newsletter data directly from you. Technical data is generated automatically by your browser, our server, and security or analytics providers. Please do not send sensitive personal data through the contact form unless it is necessary and we have specifically asked for it.
3. Why we use data and our legal bases
- To answer enquiries and discuss a possible project. We rely on steps taken at your request before a contract, or on our legitimate interest in handling business communications and developing our services.
- To send newsletters and promotional emails. We rely on your consent. Subscription is optional, and withdrawing consent does not affect the lawfulness of earlier processing.
- To operate, secure, and troubleshoot the website. We rely on our legitimate interests in providing a reliable website, preventing fraud and abuse, and protecting our systems and users.
- To measure use of the website. For Google Analytics and other non-essential tracking technologies, the legal basis is your prior consent.
- To meet legal obligations and protect legal claims. We rely on the relevant legal obligation or our legitimate interest in establishing, exercising, or defending claims.
The contact form requires your name, email address, and message so that we can understand and answer your enquiry. If you do not provide them, we cannot respond through the form. Newsletter subscription is entirely voluntary.
4. How long we keep data
- Contact enquiries and related correspondence are normally kept for up to 24 months after the last meaningful communication. If an enquiry becomes a client relationship or a dispute, relevant records may be kept for the applicable contractual, accounting, tax, or limitation period.
- Newsletter data is kept until you unsubscribe, withdraw consent, or we discontinue the newsletter. We may retain a minimal suppression record where needed to ensure that we respect an opt-out or demonstrate compliance.
- IP-based application rate-limit entries expire after about 15 minutes. Infrastructure and security logs are kept according to the shortest period necessary under our provider settings, and longer only when needed to investigate an incident or comply with law.
- Google Analytics user-level and event-level data is retained according to the configured Analytics property setting, for no longer than 14 months. Aggregated reports may remain available longer. Analytics cookie lifetimes are listed below.
When a retention period ends, data is deleted or anonymised unless continued storage is required or permitted by law.
5. Recipients and service providers
Access is limited to authorised UWIT personnel and contractors who need it for their work. We may also disclose data to the following categories of recipients:
- website hosting, infrastructure, database, backup, and security providers, including Cloudflare and Neon;
- our email hosting or delivery provider, which relays contact-form messages and future newsletters;
- Google, when Google Analytics is enabled;
- professional advisers, courts, regulators, law-enforcement bodies, or other authorities where disclosure is legally required or necessary to protect legal rights.
Service providers may process personal data only for contracted purposes and subject to appropriate confidentiality, security, and data-protection obligations. We do not sell personal data.
6. International transfers
Our primary form database is hosted in the European Union. Because Cloudflare, Google, and some other technology providers operate internationally, technical or analytics data may be processed in Serbia, the EEA, the United States, or another country. Where a transfer requires safeguards, we use an available lawful transfer mechanism, such as an adequacy decision or approved contractual safeguards, and supplementary measures where appropriate. You may contact us for more information about safeguards relevant to your data.
7. Cookies and similar technologies
Cookies are small files stored on your device. The public website may use the following categories:
- Strictly necessary security cookies. Cloudflare may use cookies such as
__cf_bmorcf_clearancewhen its bot protection or challenge features are triggered. They protect the site and are not used by UWIT for advertising. Their duration depends on the security feature; Cloudflare documents a 30-minute inactivity period for__cf_bmand a default 30-minute challenge passage forcf_clearance. - Google Analytics cookies. When Analytics is enabled,
_gadistinguishes users and_ga_<measurement-id>maintains session state. Google lists a default lifetime of two years for each. These cookies are optional and must not be set until you consent. - Consent record. When you make a cookie choice, we store it in a first-party cookie named
uwit_consent. It contains only your category choices, the date of your decision, and a policy version — no personal data — and is kept for six months, after which we ask again. If the purposes of optional cookies materially change, the stored version is invalidated and consent is requested anew. - Administration cookies. The separate UWIT admin area uses authentication and security cookies for authorised staff. They are necessary for the service requested by those users and are not used to track public visitors.
Refusing optional analytics must not limit access to the public site. Where analytics is offered, you must be able to reject it as easily as you accept it and later withdraw your choice. You can review or change your preferences at any time via the “Cookie settings” button in the website footer; withdrawing analytics consent also deletes the Google Analytics cookies our site can access. Browser settings can also delete or block cookies, although blocking strictly necessary cookies may affect protected or authenticated features.
8. Your rights
Subject to the conditions and limits in applicable law, you may request access to, correction, deletion, restriction, or portability of your personal data. You may object to processing based on legitimate interests and may withdraw consent at any time. You also have the right not to be subject to a decision based only on automated processing where it produces legal or similarly significant effects. UWIT does not use the website data described here for such automated decisions.
Send a request to [email protected]. We may ask for information reasonably needed to verify your identity. We normally respond within 30 days, subject to any lawful extension.
You may also lodge a complaint with the Serbian Commissioner for Information of Public Importance and Personal Data Protection at poverenik.rs, or with a competent EEA supervisory authority where the GDPR applies.
9. Security and children
We use organisational and technical safeguards designed to protect personal data, including access controls, encrypted connections, restricted CMS permissions, and abuse prevention. No internet service can guarantee absolute security.
This business website is not directed to children, and we do not knowingly request their personal data. If you believe a child has submitted personal data, contact us so that we can review and, when appropriate, delete it.
10. Third-party links
The website links to services such as LinkedIn, Instagram, WhatsApp, and the UWIT client portal. Those services process data under their own notices when you choose to visit them. This policy does not govern their independent processing.
11. Changes to this policy
We may update this policy when our processing or legal obligations change. The current version and its date will remain available on this page. If a change materially affects a processing activity based on consent, we will request new consent where required.