🇪🇺 GDPR

GDPR & Zaštita podataka

napravi.site

📅 Ažurirano: 07. april 2026. 📜 Uredba (EU) 2016/679 📋 Zakon RS br. 87/2018
Naša GDPR obaveza

Platforma napravi.site obrađuje lične podatke u skladu sa GDPR (Uredba EU 2016/679) i Zakonom o zaštiti podataka o ličnosti RS (Sl. glasnik RS br. 87/2018). Privatnost je za nas osnovno pravo, ne prateća obaveza.

1

Pravni okvir

  • GDPR — Uredba (EU) 2016/679 od 27. aprila 2016.
  • Zakon RS — Zakon o zaštiti podataka o ličnosti (Sl. glasnik RS br. 87/2018)
  • ePrivacy — Direktiva 2002/58/EZ o privatnosti i elektronskim komunikacijama
  • NIS2 Direktiva — Direktiva (EU) 2022/2555 o bezbednosti mrežnih i informacionih sistema
2

Uloge rukovalaca podataka

UlogaKoZa koje podatkeOdgovornost
Rukovalac (Controller)Operator napravi.sitePodaci o Tenant nalogu, pretplati, logoviPuna GDPR odgovornost
Obrađivač (Processor)Operator napravi.sitePodaci krajnjih korisnika Tenantovih sajtovaObrada po uputstvima Tenanta
Rukovalac (Controller)Tenant (korisnik platforme)Podaci sopstvenih krajnjih korisnika/kupacaPuna GDPR odgovornost prema krajnjim korisnicima
⚠️
Obaveze Tenanta

Korisnici platforme (Tenanti) koji prikupljaju podatke svojih kupaca sami su odgovorni za GDPR usklađenost. Tenanti koji zahtevaju formalni DPA dokument mogu nas kontaktirati na privacy@napravi.site.

3

Pravni osnov obrade (GDPR čl. 6)

Pravni osnovGDPR članPrimenjen na
Izvršenje ugovoračl. 6(1)(b)Registracija, upravljanje nalogom, naplata, pružanje usluge
Legitimni interesčl. 6(1)(f)Bezbednost, prevencija prevara, server logovi, support
Zakonska obavezačl. 6(1)(c)Računovodstvena dokumentacija, zahtevi organa vlasti
Saglasnostčl. 6(1)(a)Marketing emailovi, newsletter (opoziv uvek moguć)
4

Registar delatnosti obrade (RoPA)

DelatnostKategorije podatakaPrimiciRok čuvanja
Upravljanje korisničkim nalozimaIdentifikacioni, kontaktInterni sistemiTrajanje naloga + 30 dana
Procesiranje pretplataFinansijski, Stripe IDStripe10 godina
Pružanje CMS funkcijaKorisnički sadržajCloudinary, bazaTrajanje naloga
Bezbednosni logoviIP, session, timestampServer log sistem90 dana
SMS notifikacijeBroj telefona, tekstBulkGate30 dana (log)
AI prevodi sadržajaTekstualni sadržajOpenAI APINije trajno čuvano
5

Prenos podataka van EU/EEA

PružalacZemljaMehanizam zaštite
Stripe, Inc.SADStandardne ugovorne klauzule (SCCs)
Cloudinary Ltd.SAD/EUSCCs + EU Data Center opcija
OpenAI, Inc.SADStandardne ugovorne klauzule (SCCs)
Meta (Instagram)SADSCCs (za EU korisnike)
LinkedIn Corp.SADSCCs (za EU korisnike)
📋
Standardne ugovorne klauzule

Koristimo najnovije SCCs usvojene od Evropske komisije (Odluka 2021/914) za sve transfere podataka van EU.

6

Lice za zaštitu podataka (DPO)

Imenovanje DPO trenutno nije zakonski obavezno s obzirom na obim obrade. Operator je ipak odredio kontakt za zaštitu podataka:

  • 📧 privacy@napravi.site — predmet: „DPO / Zaštita podataka"
🔄
Buduća obaveza

Ako platforma pređe pragove po GDPR čl. 37(1), Operator će bez odlaganja imenovati DPO i objaviti mu kontakt podatke.

7

Prava ispitanika (GDPR čl. 15-22)

📋

Pristup (čl. 15)

Kopija svih ličnih podataka koje čuvamo o vama, sa informacijama o svrsi i osnovu obrade.

✏️

Ispravka (čl. 16)

Ispravka netačnih ili nepotpunih podataka u najkraćem mogućem roku.

🗑️

Brisanje (čl. 17)

„Pravo na zaborav" — kada podaci više nisu potrebni ili je saglasnost povučena.

⏸️

Ograničenje (čl. 18)

Privremeno zaustavljanje obrade dok se rešava prigovor ili provera tačnosti.

📦

Prenosivost (čl. 20)

Vaši podaci u strukturiranom, mašinski čitljivom formatu (JSON/CSV).

🚫

Prigovor (čl. 21)

Prigovor na obradu zasnovanu na legitimnom interesu — uvek bez obrazloženja.

🤖

Autom. odluke (čl. 22)

Pravo da ne budete podvrgnuti odlukama zasnovanim isključivo na automatizovanoj obradi.

↩️

Opoziv saglasnosti (čl. 7(3))

Povlačenje saglasnosti u svakom trenutku, bez uticaja na prethodnu zakonitu obradu.

8

Kako podneti zahtev za ostvarivanje prava

  1. Pošaljite email na privacy@napravi.site sa jasnim opisom zahteva
  2. Predmet: „GDPR Zahtev — [vrsta prava]" (npr. „GDPR Zahtev — Pristup podacima")
  3. Priložite dokaz identiteta (kopija lične karte sa zaštićenim osetljivim podacima)
  4. Operator potvrđuje prijem u roku od 48 sati
  5. Odgovor se dostavlja u roku od 30 dana (produžetak na 90 dana za složene zahteve)
  6. Usluga je besplatna za prvu kopiju podataka
🚫
Odbijanje zahteva

Operator može odbiti zahtev ako je: očigledno neosnovan, ponavljajući, ili bi ugrozio prava trećih lica. O odbijanju ćemo vas obavestiti sa obrazloženjem i uputiti na pravo na pritužbu.

9

Postupanje u slučaju povrede podataka

Vremenski okvirRadnjaKo
0-24 sataIdentifikacija, sadržavanje i procena povredeTehnički tim Operatora
24-72 sataPrijava Povereniku RS (ako rizik postoji)Operator (zakonska obaveza)
72 sataObaveštenje pogođenih ispitanika (ako visok rizik)Operator → Korisnici
Po sanacijiIzveštaj o povredi, korektivne mere, revizijaOperator
📨
Prijavite sumnju na incident

Kontaktirajte nas odmah na security@napravi.site ili privacy@napravi.site.

10

Posebne kategorije podataka (čl. 9)

Platforma napravi.site ne prikuplja, ne obrađuje niti zahteva posebne kategorije podataka: rasno/etničko poreklo, politička mišljenja, verska uverenja, genetske/biometrijske podatke, zdravstvene podatke, podatke o seksualnoj orijentaciji.

🚫
Zabrana za Tenante

Tenantima je izričito zabranjeno da putem platforme prikupljaju posebne kategorije podataka bez eksplicitne saglasnosti i odgovarajuće pravne osnove po GDPR čl. 9(2).

11

Automatizovano donošenje odluka i profilisanje

Platforma ne vrši automatizovano donošenje odluka koje bi proizvelo pravne efekte (GDPR čl. 22). Jedina automatizovana obrada:

  • Upravljanje pretplatom — promena stanja naloga po isteku (nije odluka o pravima)
  • Rate limiting — privremeno blokiranje IP zbog previše zahteva (bezbednost)
  • Cron podsetnici — slanje SMS-a po zakazanim terminima (na osnovu podataka korisnika)
12

Pitanja, pritužbe i nadzorni organ

📧 privacy@napravi.site — rok: 48h (potvrda) / 30 dana (rešenje)

Nadzorni organJurisdikcijaKontakt
Poverenik za informacije od javnog značaja i zaštitu podataka RSRepublika Srbijapoverenik.rs
DPA nadležnog EU članaEU/EEAedpb.europa.eu/about-edpb/board/members

🛡️ Vaša privatnost je naš prioritet

Kontaktirajte tim za zaštitu podataka za bilo kakva pitanja ili zahteve.

Our GDPR Commitment

napravi.site processes personal data in compliance with GDPR (EU Regulation 2016/679) and the Serbian Personal Data Protection Act (Official Gazette RS No. 87/2018). Privacy is a fundamental right for us, not a compliance afterthought.

1

Legal Framework

  • GDPR — Regulation (EU) 2016/679 of 27 April 2016
  • Serbian Law — Personal Data Protection Act (Official Gazette RS No. 87/2018)
  • ePrivacy — Directive 2002/58/EC on privacy and electronic communications
  • NIS2 Directive — Directive (EU) 2022/2555 on security of network and information systems
2

Data Controller Roles

RoleWhoFor Which DataResponsibility
Controllernapravi.site OperatorTenant account data, subscriptions, logsFull GDPR responsibility
Processornapravi.site OperatorEnd-user data of Tenant sitesProcessing per Tenant instructions
ControllerTenant (platform user)Their own end-users' / customers' dataFull GDPR responsibility toward end users
⚠️
Tenant Obligations as Controllers

Platform users (Tenants) who collect personal data from their own customers are independently responsible for GDPR compliance. Tenants requiring a formal Data Processing Agreement (DPA) document may contact us at privacy@napravi.site.

3

Legal Basis for Processing (GDPR Art. 6)

Legal BasisGDPR ArticleApplied To
Performance of contractArt. 6(1)(b)Registration, account management, billing, service provision
Legitimate interestsArt. 6(1)(f)Security, fraud prevention, server logs, support
Legal obligationArt. 6(1)(c)Accounting records, law enforcement requests
ConsentArt. 6(1)(a)Marketing emails, newsletter (always revocable)
4

Record of Processing Activities (RoPA)

Processing ActivityData CategoriesRecipientsRetention
User account managementIdentity, contactInternal systemsAccount lifetime + 30 days
Subscription processingFinancial, Stripe IDStripe10 years (legal obligation)
CMS service provisionUser contentCloudinary, databaseAccount lifetime
Security logsIP, session, timestampServer log system90 days
SMS notificationsPhone number, textBulkGate30 days (log)
AI content translationsText contentOpenAI APINot persistently stored
5

Data Transfers Outside the EU/EEA

ProviderCountryTransfer Mechanism
Stripe, Inc.USAStandard Contractual Clauses (SCCs)
Cloudinary Ltd.USA/EUSCCs + EU Data Center option
OpenAI, Inc.USAStandard Contractual Clauses (SCCs)
Meta (Instagram)USASCCs (for EU users)
LinkedIn Corp.USASCCs (for EU users)
📋
Standard Contractual Clauses

We use the latest SCCs adopted by the European Commission (Decision 2021/914) for all data transfers to the USA and other third countries without an adequate level of protection.

6

Data Protection Officer (DPO)

Pursuant to GDPR Art. 37, a formal DPO appointment is currently not legally required given the scale of processing. However, the Operator has designated a Data Protection Contact:

  • 📧 privacy@napravi.site — Subject: "DPO / Data Protection"
🔄
Future DPO Obligation

If the platform scales to meet the thresholds under GDPR Art. 37(1)(b) or (c), the Operator will appoint a DPO without delay and publish their contact details.

7

Data Subject Rights (GDPR Art. 15-22)

📋

Right of Access (Art. 15)

Obtain a copy of all personal data we process about you, along with information on purpose and legal basis.

✏️

Right to Rectification (Art. 16)

Request correction of inaccurate or incomplete personal data without undue delay.

🗑️

Right to Erasure (Art. 17)

"Right to be forgotten" — when data is no longer necessary or consent has been withdrawn.

⏸️

Right to Restriction (Art. 18)

Request temporary suspension of processing while a dispute or accuracy check is resolved.

📦

Right to Portability (Art. 20)

Receive your data in a structured, machine-readable format (JSON/CSV) for transfer to another controller.

🚫

Right to Object (Art. 21)

Object to processing based on legitimate interest or for direct marketing — always without justification.

🤖

Automated Decisions (Art. 22)

Right not to be subject to decisions based solely on automated processing that produce legal effects.

↩️

Withdrawal of Consent (Art. 7(3))

Revoke consent at any time without affecting the lawfulness of processing before withdrawal.

8

How to Submit a Request

  1. Send an email to privacy@napravi.site with a clear description of your request
  2. Subject line: "GDPR Request — [type of right]" (e.g., "GDPR Request — Data Access")
  3. Attach proof of identity (ID copy with sensitive fields redacted)
  4. The Operator confirms receipt within 48 hours
  5. A response is provided within 30 days (extendable to 90 days for complex requests)
  6. The service is free of charge for the first copy of data
🚫
When We May Refuse a Request

The Operator may refuse a request if it is: manifestly unfounded, repetitive, or would infringe the rights and freedoms of third parties. You will be informed of refusals with reasoning and your right to lodge a complaint.

9

Data Breach Response

TimeframeActionResponsible Party
0-24 hoursIdentification, containment, and breach assessmentOperator technical team
24-72 hoursReport to Serbian DPA (if risk exists)Operator (legal obligation)
72 hoursNotification of affected data subjects (if high risk)Operator → Users
Post-remediationBreach report, corrective measures, auditOperator
📨
Report a Suspected Incident

Contact us immediately at security@napravi.site or privacy@napravi.site.

10

Special Categories of Data (Art. 9)

napravi.site does not collect, process, or request special categories of personal data as defined in GDPR Art. 9: racial or ethnic origin, political opinions, religious beliefs, genetic or biometric data, health data, or data concerning sexual orientation.

🚫
Prohibition for Tenants

Tenants are strictly prohibited from collecting special categories of data through the platform without explicit consent and an appropriate legal basis under GDPR Art. 9(2).

11

Automated Decision-Making & Profiling

The platform does not perform automated decision-making that produces legal or similarly significant effects (GDPR Art. 22). The only automated processing in use:

  • Subscription management — automatic account status change upon plan expiry (not a decision affecting rights)
  • Rate limiting — temporary IP blocking for excessive requests (security measure)
  • Reminder cron jobs — sending appointment SMS reminders based on user-entered data
12

Questions, Complaints & Supervisory Authority

📧 privacy@napravi.site — Response: 48h (confirmation) / 30 days (resolution)

Supervisory AuthorityJurisdictionContact
Commissioner for Information of Public Importance and Personal Data ProtectionRepublic of Serbiapoverenik.rs
Competent EU Member State DPAEU/EEA (your country of residence)edpb.europa.eu/about-edpb/board/members
🏛️
Right to Lodge a Complaint

You may file a complaint with a supervisory authority at any time, without first contacting the Operator, although direct communication is recommended as a first step.

🛡️ Your Privacy is Our Priority

Contact our data protection team for any questions or requests.