Version 1.1 · Effective date: October 5, 2026 · Last updated: October 5, 2026
Privacy Policy
How Lynkora DOO Beograd collects, uses and protects personal data on this website.
General Provisions
Lynkora DOO Beograd (hereinafter "the Company", "we", "our") is the data controller for personal data collected through this website. This Policy covers the corporate website only: the contact and project brief form, the support ticket form and ticket tracker, email correspondence that continues from them, the newsletter, and the "was this helpful?" feedback controls. Our own products are covered by their own privacy policies, published on their respective websites. Lynkora DOO Beograd is registered in the Republic of Serbia (an EU candidate country) and operates in accordance with the GDPR (applied extraterritorially under Art. 3(2)), the Serbian Personal Data Protection Act ("Zakon o zaštiti podataka o ličnosti", 2018) and other applicable data protection laws.
Representative in the European Union
We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact in the European Union (Art. 27 GDPR). Our representative in the EU is Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria. You, and the EU supervisory authorities, may address the representative in addition to or instead of us on any question relating to the processing of your personal data. Prighter gives you an easy way to exercise your privacy-related rights (for example, requests to access or erase personal data): to contact us via our representative or to exercise your rights as a data subject, please visit https://app.prighter.com/portal/14550414193.
Data We Collect
We collect the following categories of data through this website:
- Project brief form: your name, work email address, company, country, telephone number where you provide it, project type, services of interest, timeline, budget range, NDA request and the description you write.
- Support ticket form: your name, email address, severity, product or system, environment, subject and the description of the issue.
- Email correspondence: the content of your replies to our emails, including any files you attach, together with the sender address and the technical headers of the message.
- Newsletter: your email address, the language of the page you subscribed from, and the record of your consent (time and the version of the text you agreed to).
- Feedback controls: your rating of a page or of an assistant answer, and the comment you optionally add. Do not include personal data in that comment.
- Technical data: IP address, request time and status recorded for security and anti-abuse purposes, including counters used for rate limiting.
- Preferences stored in your browser: interface language, light or dark theme and your cookie-banner choice. See the Cookie Policy.
- Analytics data, only if you accept analytics in the cookie banner: the pages you view, the page you came from, your approximate location (country and city, derived from your IP address), device type, browser, screen size, language, and an online identifier stored in the _ga cookies. Google Analytics 4 does not log or store IP addresses.
Purposes and Legal Bases (GDPR Art. 6)
We process your data for the following purposes, on the following legal bases:
- To answer your enquiry and prepare a possible contract — steps taken at your request prior to entering into a contract, Art. 6(1)(b) GDPR.
- To provide support to clients and to record what was requested and answered — performance of a contract, Art. 6(1)(b) GDPR; for enquiries from people who are not yet clients, our legitimate interest in answering them, Art. 6(1)(f) GDPR.
- To send the newsletter — your consent, Art. 6(1)(a) GDPR, which you may withdraw at any time.
- To keep the website secure and to prevent spam and abuse of our forms, including the anti-bot check and rate limiting — our legitimate interest in protecting our systems and our correspondents, Art. 6(1)(f) GDPR.
- To improve the content of the website on the basis of feedback ratings — our legitimate interest in an accurate and useful website, Art. 6(1)(f) GDPR.
- To measure how the website is used and improve it (Google Analytics) — your consent, Art. 6(1)(a) GDPR, which you may withdraw at any time through “Cookie settings” in the footer of every page.
- To comply with accounting, tax and other statutory duties, and to establish, exercise or defend legal claims — Art. 6(1)(c) and Art. 6(1)(f) GDPR.
What We Do Not Do
We do not sell personal data. We do not use it for advertising profiling, and we run no advertising technologies on this website; Google Analytics runs only with your consent, with Google signals and ad personalisation disabled. We take no decisions about you that are based solely on automated processing and produce legal or similarly significant effects (GDPR Art. 22): the anti-bot check and rate limits only decide whether a single request is accepted, and a rejected form can always be re-sent or the same message sent to us by email. Providing your data is not a statutory requirement; it is simply necessary if you want us to answer you.
Retention Periods
We keep your data no longer than necessary:
- Enquiries, support tickets and the correspondence attached to them — 3 years from the last activity on the request, after which the messages and attachments are deleted and the record is anonymised (reference number and dates remain). Reason: evidence in disputes about what was requested and promised (Art. 17(3)(e) GDPR) and the general three-year limitation period.
- Log of the emails sent and received in connection with a request — kept together with that request and deleted with it.
- Newsletter subscription — until you withdraw consent or unsubscribe; the record of the consent itself is kept for a further 3 years as evidence that the consent was given.
- Feedback ratings and comments — 24 months.
- Technical logs and rate-limiting counters — no longer than 90 days.
- Analytics data in Google Analytics — no longer than 14 months, after which Google deletes it automatically; the _ga cookies expire after 2 years, or are deleted as soon as you withdraw consent.
- Data that is part of a signed contract or of accounting records — for the period required by the contract and by Serbian accounting and tax law.
Sub-processors
We use the following processors to run this website. Each of them acts on our instructions under a data processing agreement. We update this list when it changes; you can also request it at privacy@lynkora.pro.
- Cloudflare, Inc. (US, with processing in the EU) — hosting of the website, the database in which requests are stored, file storage for attachments, protection against attacks and spam (Turnstile), and routing of reply emails into the request. Agreement: Cloudflare DPA, EU Standard Contractual Clauses.
- Resend (US) — delivery of the emails this website sends: confirmations, notifications to our team and our replies to you. Agreement: DPA, EU Standard Contractual Clauses (Module 3); Resend is certified under the EU-US Data Privacy Framework.
- The provider of our corporate mailbox — where our team reads and answers your messages, under a data processing agreement.
- Google Ireland Limited (Ireland), with Google LLC (US) as its sub-processor — web analytics (Google Analytics 4), only after your consent. Agreement: Google Ads Data Processing Terms, EU Standard Contractual Clauses; Google LLC is certified under the EU-US Data Privacy Framework.
International Data Transfers
Lynkora DOO Beograd is registered in Serbia, a country for which the European Commission has not issued an adequacy decision. Where an EU client transfers personal data to us, that transfer is covered by the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module 2 where we act as processor. Onward transfers to processors in the United States rely on the Standard Contractual Clauses, Module 3, and on the EU-US Data Privacy Framework where the provider is certified. In addition to the Clauses we apply supplementary technical measures: TLS encryption in transit, encryption at rest, and minimisation of the data transferred.
Security
Access to requests and correspondence is limited to the members of our team who need it, through an administration panel protected by individual accounts, and every action on a request is logged. Traffic is encrypted with TLS; stored data and attachments are encrypted at rest by our infrastructure provider. Files you attach to an email are never executed or rendered by our systems; they are stored and offered for download only. If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours and, where the breach is likely to result in a high risk to you, we will notify you as well.
Your Rights
Under the GDPR and the Serbian Personal Data Protection Act you have the right to:
- obtain access to your data and a copy of it (Art. 15 GDPR);
- have inaccurate data corrected (Art. 16 GDPR);
- have your data erased (Art. 17 GDPR);
- obtain restriction of processing (Art. 18 GDPR);
- receive your data in a machine-readable format and have it transmitted to another controller (Art. 20 GDPR);
- object to processing based on our legitimate interests (Art. 21 GDPR);
- withdraw your consent at any time, without affecting the lawfulness of processing before the withdrawal (Art. 7(3) GDPR).
How to Exercise Your Rights
Write to privacy@lynkora.pro, stating which right you wish to exercise, or send a letter to our registered address below. Every newsletter email also contains a one-click unsubscribe link. We will respond within one month; for complex or numerous requests that period may be extended by up to two further months, and we will tell you if that happens (GDPR Art. 12(3)). We will not treat you differently because you exercised your rights.
Complaints to a Supervisory Authority
If you believe your rights have been infringed you may lodge a complaint with a supervisory authority, in particular in the country of your residence, of your place of work, or of the alleged infringement (GDPR Art. 77). For our registered seat this is the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti), Bulevar kralja Aleksandra 15, 11000 Belgrade. In the EU you may address the supervisory authority of your own country: for example the CNIL in France, the AEPD in Spain, the Garante in Italy, or the authority of the competent federal state in Germany. You may also seek a judicial remedy.
Children
This website is addressed to businesses and professionals. It is not directed at children, and we do not knowingly collect data of persons under 16 years of age. If you believe a child has sent us personal data, write to privacy@lynkora.pro and we will delete it.
Changes to This Policy
We may update this Policy. When we make a material change we increase the version number shown at the top of this page and update the effective date. The current version always applies to processing carried out after its effective date; earlier versions are available on request at privacy@lynkora.pro.
Contact
For any question about this Policy or about how we process your data, write to privacy@lynkora.pro. For all other matters, use the contact details below.
Company details
- Legal name
- Lynkora DOO Beograd
- Legal form
- Društvo s ograničenom odgovornošću (d.o.o.)
- Registered address
- Kneza Miloša 15, 11000 Beograd, Serbia
- Registration number
- 22195689
- Tax ID (PIB)
- 115706177
- Principal activity
- 6201
- Director
- Andrey Kulintsev
- Registered with
- Serbian Business Registers Agency (APR)
- dev@lynkora.pro
- Data protection
- privacy@lynkora.pro
- Phone
- +381 61 293 9368
- EU representative (Art. 27 GDPR)
- Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria