Web Center

Privacy policy

UPDATED:

Veb Centar d.o.o.

Last updated: 4 August 2026.

1. Who we are and who this policy covers

Veb Centar d.o.o. („Veb Centar", „we", „us" or „our") is the controller of the personal data it collects through the site www.webcenter.me and its language versions, except where in a particular relationship we expressly act as a processor on a client’s behalf. Veb Centar provides web design and development, graphic design, internet consulting, SEO and digital marketing, CMS solutions, hosting and maintenance, and related digital services.

This policy explains how we process the data of site visitors, of people who contact us, of newsletter subscribers, of business contacts, and of candidates and collaborators when they use the form provided for that. It covers data collected online. For client data that we process solely on their instructions, the provisions of their contract and the corresponding DPA apply.

2. Controller and contact

Controller: Veb Centar d.o.o.

Tax number: 02809419

Published business address — Kotor: Dobrota 174, Montenegro

Published business address — Podgorica: City kvart, Vojvode Maša Đurovića br. 4/a, Lamela 3–4, Sprat 2, ST 11, 81000 Podgorica, Montenegro

E-mail for privacy and general enquiries: office@webcenter.me

Telephone: +382 67 235 558

If Veb Centar appoints a data protection officer, their contact details will be published here. Where an obligation under Article 27 GDPR applies to a particular processing operation, the contact details of Veb Centar’s representative in the EU/EEA will be published here:

Name: Mario Šarčević

Address: Willy-Brandt-Straße 23 (Kallmorgen Tower)

20457 Hamburg, Germany

E-mail: info@progressengineering.de

3. The rules we apply

We carry out processing in accordance with the applicable data protection legislation of Montenegro and, where it applies because of our offering of services or the monitoring of behaviour of people in the EU/EEA, with the GDPR. We apply the principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.

4. What data we collect

4.1. Site usage data

When you visit the site, our server and our technical service providers may process the IP address, the date and time of the request, the pages visited, the URL you arrived from, the device and browser type, language settings, technical logs, errors, and data about security events. Part of this data is needed to display the site, to protect it from abuse, and to fix faults.

4.2. Contact form and business correspondence data

When you send us an enquiry, we process the data you enter: your name, e-mail address, telephone number, the content of your message and, if you provide it, information about your company, the project or the budget. The data is kept in our enquiry database and may be passed to authorised employees or contractors in order to reply and prepare a quote. Please do not enter special categories of data into the form (for example health data, data about political opinions, or identification numbers) unless we expressly ask for them and there is a clear legal basis.

4.3. Newsletter subscriber data

For the newsletter we process the e-mail address, the date and evidence of sign-up, any language or interest settings we offer, the record of unsubscription, and the technical data needed to deliver the message. If we were to use open or click measurement, that would be clearly stated in advance in the sign-up notice and governed by an appropriate choice for the user.

4.4. Cookies and similar technologies

We use essential cookies and, only after your permission where one is required, analytics and marketing cookies and pixels. The details are in our Cookie Policy. The tools currently used or planned include Google Analytics 4, Google Ads conversions, Meta Pixel, Hotjar and Google reCAPTCHA.

4.5. Applications to collaborate or work with us

If you use the dedicated form for collaborators or send us an application, we may process the data from the application, the CV, the portfolio and the correspondence, to the extent needed to assess the collaboration. Do not send sensitive data that is not needed for the application.

5. Why we process data, and on what basis

We process data only where we have a legal basis for it. Depending on the situation, we rely on:

  • pre-contractual steps or performance of a contract — to answer a request for a quote, to conclude or perform a contract, to provide support and to manage the business relationship;
  • a legal obligation — where we must keep or provide data under legislation, including accounting, tax or security obligations;
  • legitimate interest — for the security of the site and the network, the prevention of fraud and abuse, keeping a record of correspondence, the defence of legal claims, and the reasonable improvement of our services, where your rights and freedoms do not override it;
  • your consent — for the newsletter and for non-essential cookies and technologies, where consent is required. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

We do not make our reply to an ordinary enquiry conditional on consent to marketing. We do not pre-tick boxes for the newsletter or for non-essential cookies.

6. Who we may disclose data to

Access to the data is limited to people who need it for their work and who are bound by confidentiality. Where necessary, we share data with:

  • our hosting and infrastructure provider (Hetzner), including backup and technical support;
  • our business e-mail and collaboration provider (Google Workspace);
  • providers of measurement, advertising and security that are activated by your choice or by the use of the form (Google, Meta and Hotjar);
  • engaged IT subcontractors, accountants, legal advisers, banks and public authorities, where this is necessary and permitted;
  • the client, where we process data solely on their instructions as a processor.

We conclude appropriate agreements with processors and require them to use the data only for the agreed purposes. For data collected through their own cookies and pixels, certain analytics and advertising providers may also act under their own rules as separate or joint controllers; their terms and policies can be reviewed through the links in the Cookie Policy.

7. Transfers outside Montenegro and the EU/EEA

Our digital services may involve processing or remote access to data outside Montenegro, and some providers have global infrastructure, including locations outside the EU/EEA. Where the GDPR applies and data is transferred from the EU/EEA to a country without an adequacy decision, we apply an appropriate transfer mechanism, such as the European Commission’s standard contractual clauses, together with a transfer assessment and additional technical and organisational measures where these are needed. You may request information about the relevant safeguards, or a copy of the applicable clauses, at office@webcenter.me, subject to the protection of trade secrets and of other people’s data.

8. How long we keep data

We do not keep data longer than is needed for the purpose it was collected for, unless the law requires longer retention. The operational periods we apply, or are to apply, are:

  • security and server logs: at most 30 days, except where longer retention is necessary to investigate an incident;
  • enquiries that did not lead to business: at most 24 months from the last meaningful contact;
  • contract and project documentation: for the duration of the contract and the period needed to protect rights and to observe mandatory legal and accounting periods;
  • newsletter: until unsubscription, or at most 24 months without activity; a limited record of the unsubscription may be kept for up to 3 years in order to honour your objection to being sent messages;
  • applications to collaborate: up to 12 months from the end of the process, unless you give separate permission for longer retention or the law requires otherwise;
  • cookie choices: up to 6 months, after which we ask for the choice again, or sooner where the purpose or technology changes materially.

Data in backups is deleted through the ordinary overwrite cycle, at the latest within 90 days, unless a copy has been preserved because of a security incident or a legal obligation. Before publication, check that these periods correspond to the actual configuration and to the mandatory local periods.

9. How we protect data

We apply measures appropriate to the risk, including access control and the principle of least privilege, individual accounts, strong passwords and multi-factor authentication where it is available, encryption in transit (TLS), regular updates, backups, logging and monitoring, contractual confidentiality obligations, and incident response procedures. No system is entirely without risk; even so, we continually adapt our measures to the nature of the data and the state of the art.

10. Your rights

Within the limits of applicable law you may request: access to your data; the correction of inaccurate data or the completion of incomplete data; erasure; the restriction of processing; data portability; an objection to processing based on legitimate interest; and the withdrawal of consent. If you receive marketing, you can unsubscribe through the link in the e-mail or through office@webcenter.me. We do not take decisions producing legal or similarly significant effects solely by automated means.

Send your request to office@webcenter.me with the subject „Data protection request". We may ask for reasonable confirmation of your identity in order to protect your data. We reply without undue delay and, where the GDPR applies, as a rule within one month. We will inform you of any extension, or of the reasons for a refusal, in accordance with the law.

You may lodge a complaint with the Agency for Personal Data Protection and Free Access to Information of Montenegro (AZLP), Bulevar Revolucije 11, Podgorica, e-mail: azlp@azlp.me, or with another competent supervisory authority, including the authority of the country of your habitual residence or place of work, or of the place of the alleged infringement, where the GDPR applies.

11. Children

The site and the services are not intended for children to contract on their own. We do not knowingly collect children’s data for marketing. If you believe a child has provided us with data without the necessary authority, please contact us so that we can assess it and erase it where appropriate.

12. Changes to this policy

We may change this policy when our processes, tools or the legislation change. We will publish a new update date on the page and, for material changes, take additional notification steps where the law requires it. Previous versions can be requested at office@webcenter.me.