Red Black Tree Privacy and Cookies Policy
Last updated: 15.08.2026. Version: 2026-08-15.
We are "Red Black Tree d.o.o. Čačak", reg.no. 20857706, a software development company registered at and operating under the laws and legislation of the Republic of Serbia.
This Privacy Policy will explain how our organization uses the personal data we collect from you when you use our website (Site), or when you communicate with us using the Internet, or by other means of communication.
Scope and Applicable Law
As a legal entity established in the Republic of Serbia, Red Black Tree d.o.o. Čačak primarily collects and processes personal data in accordance with the Law on Personal Data Protection of the Republic of Serbia (Official Gazette of RS, No. 87/2018). In addition, where our services, website features, or business activities target or interact with data subjects located in the European Union / European Economic Area, the United Kingdom, or other international jurisdictions, we ensure full compliance with the EU General Data Protection Regulation (EU GDPR), the UK GDPR, and applicable local privacy standards.
All concepts, rights, and obligations set forth in this Privacy Policy are designed to satisfy both the Serbian Law on Personal Data Protection and international privacy regulations such as the EU GDPR.
Pursuantly, Red Black Tree and this Privacy Policy follows the personal data definition under the Law on Personal Data Protection of the Republic of Serbia and the General Data Protection Regulation of the European Union (GDPR): Personal data are any information which are related to an identified or identifiable natural person (Art. 4.1 of GDPR), i.e. any information that can identify an individual, either directly or when combined with other data.
However, we strive to maintain protection of personal data which is also compliant on most territories of North America (that is, USA and Canada) and United Kingdom. We believe that personal data protection established by instruments of GDPR and Serbian law should also suffice, at least in key-elements, when most other worldly legislations are concerned.
There are quite a few internationally accepted and valid definitions of personal data, although most of them share the same principal elements. For instance, the Personal Identification Data, as described in US privacy law and information security, is information that can be used on its own or with other information to identify, contact, or locate a single person, or to identify an individual in context.
The data subjects are identifiable if they can be directly or indirectly identified, especially by reference to an identifier such as a name, an identification number, location data, an online identifier or one of several special characteristics, which expresses the physical, physiological, genetic, mental, commercial, cultural or social identity of these natural persons.
In practice, these also include all data which are or can be assigned to a person in any kind of way. For example, the telephone, credit card or personnel number of a person, account data, number plate, appearance, customer number or address are all personal data, also commonly known as personal identifying data, or elsewhere as personal identifying information.
Particularly sensitive information such as health information, income, religion and cultural profiles and the like is also personal data (RBT is not collecting them). Furthermore, and crucial in the present context, data on user behavior is also personal. Cookies can track and register individual users' browsing activities, like what articles they scroll past and which ones they choose to click on.
In this regard, we are assuring you that our core-business is not based upon, dependent upon or focused on collection of any personal data. We strive to run our business, which is mostly software development, without collection and usage of your personal data.
Therefore, we may get in touch with, or in possession of, your personal data primarily while you are visiting our Site, or while you are communicating with us using email, either as a representative of our current or prospective clients, business partners or other parties interested in our software development business.
This privacy policy has been compiled to better serve those who are concerned with how their Personal Data, or "Personally Identifiable Information" (PII) is being used online when accessing our corporate website, whichever jurisdiction they are coming from as visitors of our Site, or while communicating with us using email. In any case, and whichever jurisdiction you as a visitor of our website are coming from, rest assured that, at all times, WE DO NOT COLLECT YOUR PERSONAL DATA WITHOUT YOUR EXPLICIT APPROVAL.
Please read further details of this Privacy Policy carefully to get a clear understanding of how we collect, use, protect or otherwise handle your Personal Data, i.e. your Personally Identifiable Information in accordance with our website.
Topics:
- Scope and Applicable Law
- What data do we collect?
- How do we collect your data?
- How will we use your data and Lawful Bases for Processing?
- How and where do we store your data?
- Data retention and consent records
- Marketing communications
- What are your data protection rights?
- Cookies, analytics and network logs
- Privacy policies of other websites
- Changes to our privacy policy
- How to contact us?
- How to contact the appropriate authorities?
What data do we collect?
Our Company collects the following data:
- Personal Identification information provided when you communicate with us via email, or via social networks (for instance, job candidates, internship candidates, potential clients) such as name, email address, phone number, data of your business and other data that you may present in your email signature.
- Regarding all personal data collected through our Site, self-assessment questionnaires, contact forms, job applications, and marketing communications, RBT acts in the capacity of a Data Controller.
- Data collected through our AI Governance Self-Assessment Tool and Lead Generation Forms: When you complete our AI Governance self-assessment tool on our Site, or fill out lead forms on networks such as LinkedIn, we collect your full name, business email address, company name, job position, as well as your questionnaire responses and calculated results.
- Network Security Logs: Full IP addresses and request timestamps recorded by our web delivery network for infrastructure protection and security monitoring.
How do we collect your data?
As a Data Controller, we primarily collect personal data directly from you as the data subject (in accordance with Article 13 of the EU GDPR and Article 23 of the Serbian Law on Personal Data Protection). You directly provide Our Company with most of the data we collect. We collect data and process data when you:
- Communicate with us via email, either as a visitor of our Site or in our regular communication with yourself as our business partner;
- Register via our website for job application or internship application filling out the application forms;
- Complete our online AI Governance self-assessment questionnaire on our Site to receive a detailed written report;
- Submit your contact details through our lead generation forms on our Site or social media networks (such as LinkedIn) to receive whitepapers, analysis, or business proposals;
- Confirm your email address via our double opt-in verification process.
How will we use your data and Lawful Bases for Processing?
Our Company collects your data so that we can:
- Establish and maintain our business communication with yourself, as a job applicant, internship applicant or as a representative of our client or business partner (Legal Basis: Legitimate interest / Performance of a contract - Article 12, Paragraph 1, Items 2 and 6 of the Law on Personal Data Protection / Article 6(1)(b) and (f) of the EU GDPR);
- Generate and deliver your requested AI Governance self-assessment report to your email address (Legal Basis: Taking steps at the request of the data subject prior to entering into a contract - Article 12, Paragraph 1, Item 2 of the Law on Personal Data Protection / Article 6(1)(b) of the EU GDPR);
- Contact you regarding our commercial services, products, sales proposals, and professional insights (Legal Basis: Your explicit consent - Article 12, Paragraph 1, Item 1 of the Law on Personal Data Protection / Article 6(1)(a) of the EU GDPR).
How and where do we store your data?
We store your data using secure cloud infrastructure providers.
- Website delivery is hosted on Amazon Web Services (AWS) in Germany (Frankfurt), and so are the security logs produced by our content delivery network and web application firewall;
- Analytics and questionnaire data processing systems are hosted on Amazon Web Services (AWS) in Frankfurt, Germany (EEA);
- Customer relationship records and lead contacts reside on HubSpot infrastructure located within the EEA;
- Corporate email communication is managed through Google Workspace services.
Cross-border data transfers outside the EEA or the Republic of Serbia are conducted under valid legal transfer mechanisms, including Standard Contractual Clauses (SCCs) and applicable adequacy decisions.
We protect your data by applying appropriate technical and organizational security measures in line with EU GDPR and industry best practices:
- We continuously ensure confidentiality, integrity, availability, and resilience of processing systems and services;
- We have implemented the international standard ISO 27001 - Information Security Management System;
- We have established processes for regular testing, assessing, and evaluating the effectiveness of technical and organizational measures.
Data retention and consent records
We retain different types of data for specified timeframes:
- Unconfirmed Form Submissions: If an email verification is not completed following a form submission, the confirmation link stops working after 72 hours and the temporary record expires 7 days after the submission, after which our storage provider deletes it automatically;
- Sales, Marketing, and Assessment Data: Retained for up to 3 years from the date of our last active interaction, or until you withdraw your consent;
- Consent Audit Records: Evidence of consent and consent withdrawal is retained for a period of 3 years following consent withdrawal under our Legitimate Interest to demonstrate compliance with statutory data protection obligations, after which it is permanently deleted;
- Assessment Request Logs: The request record that accompanies each self-assessment submission, which contains the full IP address, is retained for 12 months as part of the evidence that consent was given;
- Network Security Logs: Full IP address access logs produced by our content delivery network and web application firewall are automatically deleted after 30 days;
- Cookieless Analytics Logs: Aggregated analytics logs are purged after 6 months.
Marketing communications
If you have provided explicit consent, we may send you information regarding our services, industry insights, and educational materials. You have the right to opt out at any time by clicking the Unsubscribe link in any email or by contacting privacy@rbt.rs.
You have the right at any time to stop Our Company from contacting you for marketing purposes. You can easily exercise your right to withdraw consent or unsubscribe by:
- Clicking the Unsubscribe link included in any marketing email sent by us;
- Contacting us directly via email at privacy@rbt.rs or support@rbt.rs.
What are your data protection rights?
Our Company would like to make sure you are fully aware of your data protection rights. Every user is entitled to the following:
- The right to withdraw consent: You have the right to withdraw your consent for personal data processing at any time, easily and free of charge, without affecting the lawfulness of processing based on consent before its withdrawal;
- The right to access: You have the right to request RBT for copies of your personal data free of charge;
- The right to rectification: You have the right to request that RBT correct any information you believe is inaccurate. You also have the right to request RBT to complete information you believe is incomplete;
- The right to erasure: You have the right to request that we erase your personal data, under certain conditions;
- The right to restrict processing: You have the right to request that we restrict the processing of your personal data, under certain conditions;
- The right to object to processing: You have the right to object to RBT's processing of your personal data, under certain conditions;
- The right to data portability: You have the right to request that RBT transfers the data that RBT collected to another organization, or directly to you, under certain conditions.
- If you make a request, we have one month (30 days) to respond to you. If you would like to exercise any of these rights, please contact us at our email: privacy@rbt.rs or support@rbt.rs.
Privacy policies of other websites
The Our Company website contains links to other websites. Our privacy policy applies only to our website, so if you click on a link to another website, you should read their privacy policy.
Changes to our privacy policy
Our Company keeps its privacy policy under regular review and places any updates on this web page. This privacy policy was last updated on 15.08.2026.
How to contact us
If you have any questions about Our Company's privacy policy, the data we hold on you, or you would like to exercise one of your data protection rights, please do not hesitate to contact us.
Email us at: privacy@rbt.rs or support@rbt.rs.
Or write to us at: Red Black Tree d.o.o. Čačak, Zlatiborska 18, 32000 Čačak, Republic of Serbia.
Commissioner for Information of Public Importance and Personal Data Protection
15 Bulevar kralja Aleksandra street, Belgrade 11120, Republic of Serbia
Tel: +381 11 3408 900
Fax: +381 11 3343 379
Email: office@poverenik.rs