Last updated: 7 August 2026.
This policy explains how GeoDigit d.o.o. processes personal data when you use geodigit.net, contact us or configure optional technologies.
1. Data controller
GeoDigit d.o.o., Promenada 13, 22000 Sremska Mitrovica, Serbia, VAT 106929803, registration number 20707950. Privacy questions and requests: office@geodigit.rs, +381 22 62 45 83.
2. Data, purposes and legal bases
For enquiries, we process your name, email, selected topic, optional telephone number, message and security-verification data so that we can reply, prepare a proposal or take steps before entering a contract. Server and security services may temporarily process IP address, request time, requested URL, browser type and error data for security, abuse prevention and reliable operation. We rely on pre-contractual steps, applicable legal duties and our legitimate interests. Google Analytics and Google Maps load only with your consent.
3. Cookies and similar technologies
Optional categories are off by default. Your selection is stored in browser local storage as geodigit_consent_v1 for up to 180 days.
| Category | Technology | Purpose and duration |
|---|---|---|
| Necessary | csrftoken, sessionid | Form protection and a server session when required; CSRF data for up to one year and a session typically for up to two weeks. |
| Necessary | Google reCAPTCHA | Protects the contact form from automated abuse; Google may set security identifiers under its own terms. |
| Analytics — optional | Google Analytics 4: _ga, _ga_* | Aggregate usage statistics; configured to expire within 180 days. |
| External content — optional | Google Maps | Interactive map loaded only after consent; Google controls its own identifiers and duration. |
You can change your choice through “Cookie settings” in the footer at any time. Withdrawal applies going forward.
4. Recipients, transfers and retention
Authorised staff and contracted hosting, email, maintenance and security providers process data only as needed. When Google services are used, Google may process data as a separate provider. Transfers outside Serbia or the EEA rely on safeguards required by applicable law and provider agreements. We retain data according to the enquiry purpose, business relationship, limitation periods and legal record-keeping duties, then delete or anonymise it.
5. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, object to processing, request portability where applicable and withdraw consent. We may verify identity to protect your data. You may complain to Serbia’s Commissioner for Information of Public Importance and Personal Data Protection at poverenik.rs.
6. Other information
We do not make solely automated decisions producing legal or similarly significant effects. The site is not directed at children. External links lead to independent controllers. We may update this policy as services or law change; the date above identifies the current version.