🔒 Privacy

Privacy Policy / Politika privatnosti

napravi.site

📅 Updated: April 7, 2026 ⚖️ GDPR + RS Law 87/2018
🔒
Naš pristup privatnosti

Prikupljamo samo podatke koji su neophodni za pružanje usluge. Ne prodajemo, ne iznajmljujemo niti delimo vaše lične podatke sa trećim stranama u marketinške svrhe.

1

Ko obrađuje vaše podatke (Rukovalac)

Rukovalac podataka za platformu napravi.site je Operator platforme. Kontakt: privacy@napravi.site

👥
Napomena za Tenant korisnike

Ako ste krajnji kupac sajta kreiranog na platformi napravi.site, Tenant (vlasnik sajta) je odgovoran za obradu vaših podataka. Obratite im se direktno za pitanja privatnosti.

2

Koje podatke prikupljamo

📋 Podaci o nalogu

  • Ime i prezime
  • Email adresa
  • Lozinka (bcrypt hash)
  • Naziv brenda / sajta
  • Kontakt telefon (opciono)
  • Datum registracije

💳 Podaci o pretplati

  • Plan pretplate
  • Datum isteka
  • Stripe Customer ID
  • Status pretplate
  • Istorija plaćanja

🌐 Tehnički podaci

  • IP adresa (logging)
  • Tip i verzija browser-a
  • Session ID (kolačić)
  • Datumi pristupa
  • Bandwidth potrošnja

📦 Vaš sadržaj

  • Slike (Cloudinary)
  • Tekstualni sadržaj
  • Kontakt informacije
  • Podaci o rezervacijama
  • Podaci o porudžbinama

Podaci o plaćanju (broj kartice, CVV) se nikada ne čuvaju na našim serverima — procesiraju se isključivo putem Stripe-a.

3

Svrha i pravni osnov obrade

SvrhaPravni osnov (GDPR)Podaci
Upravljanje nalogomIzvršenje ugovora (čl. 6(1)(b))Email, lozinka, ime
Naplata pretplateIzvršenje ugovora (čl. 6(1)(b))Stripe ID, plan, istorija
Transakcijski emailoviLegitimni interes (čl. 6(1)(f))Email adresa
Bezbednost i prevencija prevaraLegitimni interes (čl. 6(1)(f))IP, session, logovi
Marketing obaveštenjaSaglasnost (čl. 6(1)(a))Email adresa
Zakonske obavezeZakonska obaveza (čl. 6(1)(c))Podaci o plaćanjima
4

Kolačići (Cookies)

KolačićSvrhaTrajanjeTip
mslf_sessionAutentifikacija korisnika24 sataNeophodan
CSRF tokenZaštita od cross-site napadaTrajanje sesijeNeophodan
cart (sesija)Sadržaj korpeTrajanje sesijeFunkcionalni
Bez tracking kolačića

Ne koristimo Google Analytics, Facebook Pixel ni slične tracking alate.

5

Treće strane kojima delimo podatke

ProvajderSvrhaKoji podaciLokacija
Stripe, Inc.Procesiranje plaćanjaEmail, Stripe ID, transakcijeSAD (SCCs)
Cloudinary Ltd.Čuvanje slika i fajlovaUploadovane slike i medijiSAD/EU (SCCs)
OpenAI, Inc.AI prevodi sadržajaTekst za prevodSAD (SCCs)
BulkGate s.r.o.SMS notifikacijeBroj telefona, tekst SMS-aČeška (EU)
Meta (Instagram)Objave na InstagramuSadržaj, slike (uz dozvolu)SAD (SCCs)
LinkedIn Corp.Objave na LinkedIn-uSadržaj (uz dozvolu)SAD (SCCs)
6

Čuvanje i brisanje podataka

KategorijaPeriod čuvanjaRazlog
Podaci o naloguDo brisanja + 30 danaMogućnost obnavljanja
Podaci o plaćanjima10 godinaZakonska obaveza
Server logovi90 danaBezbednost i debugging
Session podaci24 sata (automatski)Tehničko funkcionisanje
Slike (Cloudinary)Do brisanja nalogaKorisnički sadržaj
7

Sigurnost podataka

  • Lozinke — heširane koristeći bcrypt (nikada plain text)
  • Sesije — httpOnly, secure kolačići; CSRF zaštita na svim formama
  • Komunikacija — SSL/TLS enkripcija (HTTPS)
  • Baza podataka — PostgreSQL sa izolacijom podataka po tenantu
  • Rate limiting — zaštita od brute-force i DDoS napada
  • Security headers — Helmet.js, CSP, X-Frame-Options
🚨
Povreda podataka

U slučaju povrede, Operator vas obaveštava u roku od 72 sata i prijavljuje Povereniku za zaštitu podataka, u skladu sa GDPR čl. 33-34.

8

Deca

Platforma nije namenjena licima mlađim od 16 godina. Ne prikupljamo svesno lične podatke dece. Ukoliko saznamo da smo prikupili podatke deteta bez roditeljske saglasnosti, odmah ćemo ih izbrisati. Kontakt: privacy@napravi.site

9

Vaša prava

PravoOpisRok
📋 PristupKopija podataka koje čuvamo o vama30 dana
✏️ IspravkaZahtev za ispravku netačnih podataka30 dana
🗑️ Brisanje„Pravo na zaborav"30 dana
📦 PrenosivostPodaci u mašinski čitljivom formatu (JSON)30 dana
🚫 PrigovorPrigovor na obradu zasnovanu na legitimnom interesu30 dana
↩️ Opoziv saglasnostiPovlačenje saglasnosti u bilo kom trenutkuOdmah
🏛️
Pravo na pritužbu

Možete podneti pritužbu Povereniku za informacije od javnog značaja i zaštitu podataka o ličnosti RS, ili DPA organu EU u svojoj zemlji boravka.

10

Izmene politike privatnosti

Materijalne izmene biće objavljene sa novim datumom i korisnici će biti obavešteni email-om najmanje 14 dana pre stupanja na snagu.

🔒 Pitanja o privatnosti?

Za sve zahteve ili pitanja vezana za vaše podatke.

privacy@napravi.site
🔒
Our Privacy Commitment

We only collect data strictly necessary to provide our service. We do not sell, rent, or share your personal data with third parties for marketing purposes.

1

Data Controller

The data controller for the napravi.site platform is the Platform Operator. Contact us at: privacy@napravi.site

👥
Note for End Users of Tenant Sites

If you are a customer or visitor of a website built on napravi.site, the Tenant (site owner) is the data controller for your information. Please contact them directly for privacy inquiries.

2

Data We Collect

📋 Account Data

  • Full name
  • Email address
  • Password (bcrypt hash)
  • Brand / site name
  • Phone number (optional)
  • Registration date

💳 Subscription Data

  • Subscription plan
  • Expiry date
  • Stripe Customer ID
  • Subscription status
  • Payment history

🌐 Technical Data

  • IP address (logging)
  • Browser type & version
  • Session ID (cookie)
  • Access timestamps
  • Bandwidth usage

📦 Your Published Content

  • Images (Cloudinary)
  • Text content
  • Contact information
  • Booking data
  • Order data

Payment card data (card number, CVV) is never stored on our servers — it is processed exclusively by Stripe.

3

Purpose & Legal Basis of Processing

PurposeLegal Basis (GDPR)Data Categories
Account managementPerformance of contract (Art. 6(1)(b))Email, password, name
Subscription billingPerformance of contract (Art. 6(1)(b))Stripe ID, plan, history
Transactional emailsLegitimate interest (Art. 6(1)(f))Email address
Security & fraud preventionLegitimate interest (Art. 6(1)(f))IP, session, logs
Marketing communicationsConsent (Art. 6(1)(a))Email address
Legal obligationsLegal obligation (Art. 6(1)(c))Payment records
4

Cookies

CookiePurposeDurationType
mslf_sessionUser authentication (session ID)24 hoursStrictly Necessary
CSRF tokenCross-site request forgery protectionSessionStrictly Necessary
cart (session)Shopping cart contentsSessionFunctional
No Tracking Cookies

We do not use Google Analytics, Facebook Pixel, or similar third-party tracking tools. Our cookies are strictly necessary for platform functionality.

5

Third Parties We Share Data With

ProviderPurposeData SharedLocation
Stripe, Inc.Payment processingEmail, Stripe ID, transactionsUSA (SCCs)
Cloudinary Ltd.Image & file storageUploaded images & mediaUSA/EU (SCCs)
OpenAI, Inc.AI content translationsText sent for translationUSA (SCCs)
BulkGate s.r.o.SMS notificationsPhone number, SMS textCzechia (EU)
Meta (Instagram)Instagram publishingPost content, images (with permission)USA (SCCs)
LinkedIn Corp.LinkedIn publishingPost content (with permission)USA (SCCs)

SCCs = Standard Contractual Clauses approved by the European Commission for cross-border data transfers.

6

Data Retention

Data CategoryRetention PeriodReason
Account dataUntil deletion + 30 daysAccount recovery window
Payment records10 yearsLegal obligation (accounting)
Server logs90 daysSecurity & debugging
Session data24 hours (automatic)Technical operation
Images (Cloudinary)Until account deletionUser content
7

Data Security

  • Passwords — hashed using bcrypt (never stored in plain text)
  • Sessions — httpOnly, secure cookies; CSRF protection on all forms
  • Communication — SSL/TLS encryption (HTTPS) enforced
  • Database — PostgreSQL with per-tenant data isolation
  • Rate limiting — protection against brute-force and DDoS attacks
  • Security headers — Helmet.js, CSP, X-Frame-Options, Referrer-Policy
🚨
Data Breach Response

In the event of a security breach that may compromise your personal data, the Operator will notify you within 72 hours of discovery and report to the competent Data Protection Authority, in accordance with GDPR Art. 33-34.

8

Children

The Platform is not intended for persons under 16 years of age. We do not knowingly collect personal data from children. If we discover that a child's data has been collected without parental consent, we will delete it immediately. Contact: privacy@napravi.site

9

Your Rights

RightDescriptionResponse Time
📋 AccessObtain a copy of all personal data we hold about you30 days
✏️ RectificationRequest correction of inaccurate or incomplete data30 days
🗑️ Erasure"Right to be forgotten" — deletion of your data30 days
📦 PortabilityReceive your data in a structured, machine-readable format (JSON)30 days
🚫 ObjectionObject to processing based on legitimate interest30 days
↩️ Withdraw ConsentRevoke consent at any time without affecting prior lawful processingImmediately
🏛️
Right to Lodge a Complaint

You may file a complaint with the Serbian Commissioner for Information of Public Importance and Personal Data Protection, or with the competent EU DPA in your country of residence.

10

Changes to This Policy

Material changes will be published with an updated date and users will be notified by email at least 14 days before the changes take effect. We recommend reviewing this page periodically.

🔒 Privacy Questions?

Contact our Privacy team for any data requests or inquiries.

privacy@napravi.site