Privacy Policy
1. Data controller
ITMATHICS DOO BEOGRAD-ZVEZDARA, Dalmatinska 115, 11120 Belgrade, registration number 21805084, Tax ID (PIB) 113115769. Data protection contact: eshop@itmathics.rs, +381 11 422 04 08. The controller has not appointed a data protection officer; any questions regarding data processing may be addressed to the email above.
2. What data we collect
- Identity and contact: name and surname, address, email, phone;
- Order and payment: ordered products, delivery address, payment method (payment card data is processed by the bank/payment service provider; we do not store it);
- Account: username, password (encrypted), order history;
- Complaints and communication;
- Technical data: IP address, device and browser data, cookies (see the Cookie Policy).
3. Purposes and legal bases of processing
- Order processing and delivery — performance of the contract;
- Issuing invoices, tax/accounting records — legal obligation;
- Handling complaints — performance of the contract / legal obligation;
- User account — performance of the contract;
- Newsletter — consent;
- Analytics and marketing cookies — consent;
- Security and prevention of abuse — legitimate interest.
4. Retention periods
- Orders and invoices: 10 years (tax and accounting regulations);
- User account: until deletion upon request;
- Complaints: at least 2 years;
- Marketing (consent): until consent is withdrawn;
- Cookies: per the periods in the Cookie Policy.
5. Recipients of data
Courier services (delivery and returns), bank and payment service provider, IT/hosting provider, analytics and marketing service providers (Google, Microsoft, Meta), the Tax Administration (fiscal receipts / e-invoices) and competent authorities where required by law. All processors process data on our instructions and under a data processing agreement.
6. International data transfers
The website and data are hosted on servers in the European Union (which is on the list of countries with an adequate level of protection). Analytics and marketing service providers (Google LLC, Microsoft Corporation, Meta Platforms) may process data outside the Republic of Serbia, including in the USA, on the basis of standard contractual clauses and appropriate safeguards, in accordance with Art. 63–65 of the Personal Data Protection Law.
7. Data subject rights
Access, rectification, erasure, restriction, objection, portability and withdrawal of consent at any time (withdrawal does not affect the lawfulness of processing before withdrawal). Requests: eshop@itmathics.rs. We respond within 30 days at the latest.
8. Right to lodge a complaint
The Commissioner for Information of Public Importance and Personal Data Protection, Bulevar kralja Aleksandra 15, 11120 Belgrade, www.poverenik.rs.
9. Cookies
This website uses cookies. Details are set out in the Cookie Policy.
10. Data security
We apply appropriate technical and organizational measures to protect data against unauthorized access, loss or misuse.
11. Changes to the Policy
This policy may be amended. The current version, with the date of the last change, is published on this page. Last updated: 19 June 2026.
