Skip to content

Privacy and Data Protection

Last updated: 8/28/2026

Controller

DOLINA DIGITAL D.O.O. Beograd (Mirijevski venac 47, sprat 4, stan 42 11160 Beograd (Zvezdara) Srbija, Serbia) processes personal data under the Serbian Personal Data Protection Act (ZZPL) and the principles of the EU General Data Protection Regulation (GDPR).

Contact: info@dolinadigital.com

Data we process

  • Account data (name, username, email) — creating the account and

session security

  • Order and payment records — performing the contract and statutory

retention

  • Wallet movements and receipts — verifying top-ups
  • IP address and browser data — fraud prevention and evidence in

payment disputes

  • Support correspondence — resolving requests

Card numbers are never stored in our systems; card data goes directly to the payment provider.

  • Performance of a contract — orders, delivery, refunds
  • Legal obligation — accounting and tax records
  • Legitimate interest — fraud prevention, security, service

improvement

  • Consent — marketing messages (not sent without it)

Retention

  • Orders, payments and invoices: for the period required by law
  • Support correspondence: 2 years after the request is closed
  • Session and security logs: 12 months

When an account is deleted, identifying data is anonymised; order and payment records are retained by law and are not deleted — they are anonymised.

Transfers

Data is shared only as far as necessary to run the service:

  • hosting and database provider (within the EU/EEA)
  • payment provider (once configured)
  • competent authorities — only on a lawful request

Sellers receive only what is needed to fulfil the order; the buyer's email address is not disclosed to the seller.

Your rights

Under ZZPL and GDPR you have the right to:

  • access, rectification and erasure
  • restriction of processing and objection
  • data portability
  • withdrawal of consent

Requests are made from your account or at info@dolinadigital.com and are answered within 30 days. An account deletion request is recorded in the system and the statutory deadline is shown on screen.

You may lodge a complaint with the Serbian supervisory authority.

Security

  • All traffic is encrypted with TLS
  • Delivery contents are stored encrypted in the database
  • Administrator sessions require two-factor authentication
  • Row-level security ensures each user sees only their own data