Privacy Policy
Effective date: 2026-10-01
This Privacy Policy (hereinafter referred to as the "Policy") outlines the procedure for processing and protecting personal data of users provided to VMTech DOO Beograd (Tax ID: 114779614, Registration Number: 22069152), registered in Serbia.
We strictly adhere to the Personal Data Protection Act of the Republic of Serbia and the EU General Data Protection Regulation (GDPR), ensuring the security of information received from users.
1. What data do we collect?
In the course of providing our services, we may collect the following data:
- Identification data: name, surname, email address, phone number.
- Technical data: IP address, browser and device information, cookies.
- Interaction history: data on site visits, page views, and activity.
2. How do we use your data?
The collected information is used for:
- Processing orders and providing services.
- Customer feedback and support.
- Improving service performance and personalizing user experience.
- Analyzing traffic and marketing campaigns.
- Compliance with legal requirements.
3. Data transfer to third parties
We do not transfer personal data to third parties without user consent, except when necessary to fulfill our obligations to the client (e.g., transferring data to logistics or payment partners).
We only work with reliable services that comply with GDPR requirements:
- Payment systems: Stripe, PayPal, AltaBanka, Banca Intesa Beograd, Raiffeisen Bank Serbia.
- Logistics partners: DHL, DPD, Posta Srbije, AKS Express Kurir.
- Analytics systems: Google Analytics, Facebook Pixel, Yandex.Metrica.
4. Data storage and protection
We take all necessary measures to protect information from unauthorized access:
- We use SSL encryption for data transmission.
- We limit access to data for employees working with confidential information.
- We regularly update security systems.
5. User rights
According to GDPR and Serbian legislation, you have the following rights:
- Right of access – request a copy of your personal data.
- Right to rectification – change or update inaccurate data.
- Right to erasure – request data deletion (if no longer needed for processing).
- Right to restrict processing – limit the use of your data.
- Right to data portability – request data transfer to another service.
- Right to withdraw consent – opt-out of personal data processing.
6. Cookies
Our website uses cookies to enhance service performance. Users can change browser settings to disable them, but this may affect site functionality.
7. Changes to the privacy policy
We reserve the right to change the Privacy Policy. All updates will be published on the website.
8. Contact information
If you have questions about data processing, contact us.
Using our website and services implies your consent to this Privacy Policy.
Data processed for an AI callback
For an immediate callback we process the phone number, optional name, locale, public-page context, device class, technical visit identifiers and consent records. If the call takes place, we may process the recording, transcript, summary, call timestamps, tool results and security events. The purposes are mobile-number ownership verification, delivery of the requested call and consultation, abuse prevention and proof of consent.
The legal bases are the user's request and steps before entering into or providing a service, express consent for optional marketing channels, and legitimate interests in security, abuse prevention and legal-claim defence. Marketing consent is not a condition of the callback and is not created by entering an OTP or submitting the callback request.
Processors and international transfers
Processing may involve contracted processors for phone-number verification, telecommunications infrastructure, hosting and technologies required for the voice AI consultation. Data is shared only to the extent necessary and subject to contractual, technical and organisational safeguards. Where processing occurs outside Serbia or the EEA, appropriate transfer safeguards are applied.
Retention, suppression and rights
Data needed for consultation continuity — the recoverable number, optional name, recording, transcript, summary, confirmed business-need facts, opportunity status and an agreed next action — may be retained for no longer than two years from the relevant interaction. At expiry it is deleted or irreversibly anonymised; captcha, OTP and client-code data keep their substantially shorter security periods. A pseudonymised phone identifier, minimal consent and audit records and an active no-contact decision may be retained longer where necessary to prevent a repeat call, maintain security or meet legal obligations. Marketing data is processed until consent is withdrawn.
Irreversibly de-identified parts of successful and unsuccessful consultations may be used to measure quality and improve sales rules and the AI consultant. Call recordings, phone numbers, names, contact details and other direct or indirect identifiers are excluded from the learning set; a candidate undergoes controlled review before activation.
The user may request access, correction, deletion, restriction, objection, withdrawal of marketing consent or manual review of a suppression decision by writing to hello@vmtech.rs. Withdrawal does not affect the lawfulness of earlier processing.
Documentation attached to a project brief
For each selected direction, the user may optionally attach up to five documents, no more than 20 MB per file. We process the file content, safely displayed original name, size, detected type and technical checksums to review the request, assess its scope and prepare a proposal.
A file is uploaded immediately after selection to protected storage outside the public website and undergoes a local malware scan. It can be downloaded only by the authorised owner from the super-admin brief view. Files and download links are not sent by e-mail; confirmations may list only the safely displayed names of successfully stored files.
Files belonging to an unfinished brief are deleted after the 24-hour technical draft expires. Files belonging to a submitted active brief are retained for no more than 180 days, or for 30 days after closure or 7 days after being marked as spam, whichever expires first. The user may request earlier deletion by writing to hello@vmtech.rs.
Socium: Instagram communication data
Socium by VMTech processes data associated with a connected Instagram professional account: account identifiers and public profile information, message and comment events, available sender profile data, text, attachment metadata, replies, delivery receipts and limited AI consultant memory when automation is enabled. The company deciding why it communicates with its audience will generally be the controller of those conversations; VMTech processes them on the company's instructions as the Socium provider, except for data it processes for its own legal, security and business purposes. The parties' roles and obligations are set out in their agreement.
Socium redacts or removes processed event and reply content after 30 days; temporary media files are removed after approximately 24 hours; encrypted conversation summaries are removed after 90 days without updates. Technical event metadata and security/audit records may remain longer under the documented retention policy. Data already sent to a destination configured by the company, or held by Meta, is outside the Socium archive and cannot be independently erased there by VMTech.
Export, closure and individual rights
An authorised Socium user can request an export of company data still held at the time of the request. The archive is prepared in private storage, downloadable only after login, and expires after 24 hours. The sole user of a workspace can close it after confirming the current password and exact company name: access and processing stop immediately and Socium deletes data under its control. Existing system snapshots expire under the backup retention policy; if a snapshot is restored, the deletion request must be reapplied before service resumes. A minimal completion receipt without conversation content may be kept to demonstrate compliance.
A company data export does not replace an individual's right to access their own data. Instagram correspondents can ask the company they contacted for access, correction or erasure; VMTech assists that company in handling the request. Send requests addressed to VMTech and questions about Socium to hello@vmtech.rs. Requests are handled after appropriate identity and third-party-rights checks within the applicable legal period.
Socium: public-page analytics
On Socium public pages, with your prior consent to statistics, we use Google Analytics to measure visits and Yandex Metrica to measure visits and record how the public homepage is used (Session Replay / Webvisor). Recordings help us identify where the page is unclear and improve usability. The sign-in page and private dashboard are not recorded. Form-field contents are excluded from recording. Without consent, the analytics code is not loaded. You can change or withdraw your choice through Cookie settings on Socium; this stops new analytics collection in that browser. For questions about data collected before withdrawal, write to hello@vmtech.rs.

