Legal
GDPR
Last updated: 6 October 2026
duplo operates in the Republic of Serbia and processes personal data primarily in accordance with the Personal Data Protection Act (Official Gazette of the Republic of Serbia, No. 87/2018 — ZZPL) and, where applicable, with the EU General Data Protection Regulation (GDPR) — the Serbian act is largely aligned with it, so below we refer to both. This page summarises how we process and protect data; see the Privacy policy for full details.
Roles: controller and processor
For the data a company enters about its customers, suppliers, employees and business, the company is the controller, and NIKOLA LAZIĆ PR REPSALIO (operator of the duplo software) is the processor, which processes the data solely on the company’s instructions, for the purpose of providing the service. The relationship is governed by the Personal Data Processing Agreement (Annex 1 to the Terms of use), which the company accepts when opening an account.
Data minimisation
We process only what is needed for the features the company uses: company, customer and supplier details and the content of documents, and, with payroll, employee data (JMBG — personal identification number, salaries, deductions). Of the data that may constitute special categories of data (Article 17 of the ZZPL / Article 9 of the GDPR), the application processes only sick leave that the company imports from the eBolovanje portal: the period, the cause and the status — the diagnosis and other medical data are not read or stored. Sign-in is passwordless (a one-time code sent to email), so we do not store passwords at all.
Security
We apply appropriate technical and organisational measures: encrypted transfer (HTTPS/TLS), strict isolation of data per company (multi-tenant — every query is limited to the company), one-time sign-in codes (hashed, valid for 5 minutes, limited number of attempts), role-based access (salaries and sick leave are visible only to the Super admin, Administrator and Accountant roles), encrypted storage of access keys for government systems, private file storage without public addresses and hosting in the European Union.
Cookies
We use only technically necessary cookies (sign-in and session) and functional local storage (theme, navigation). We have no cookies for tracking, advertising or profiling, so a cookie banner is not needed.
Data location and sub-processors (EU)
Data is primarily stored and processed in the European Union (Frankfurt, Germany). We engage carefully selected sub-processors, bound by data protection agreements:
- hosting and application execution — Vercel (EU region, Frankfurt);
- database — Neon, PostgreSQL (Frankfurt, EU);
- file storage — Vercel Blob (Frankfurt, EU; private access);
- email delivery (sign-in codes, documents, notifications) — Resend; any transfer outside the EEA under standard contractual clauses.
- real-time notifications in the support chat — Pusher Channels (EU cluster, Ireland); no message content or company data passes through it, only a signal that a new message has arrived.
We do not sell personal data and we do not use it for advertising.
Rights of data subjects
Users and persons whose data is processed have the right of access, rectification, erasure, restriction of processing, portability and objection. A company’s customers, suppliers and employees exercise their rights primarily through the company (the controller); duplo, as processor, helps the company respond to those requests. A company can at any time export its data itself, free of charge (XML) and permanently delete the company, and a user their own account — directly in the application.
You can lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs).
Retention period
Business documents are not deleted automatically — accounting regulations require them to be retained. One-time codes expire after 5 minutes, sessions after 30 days. A company is deleted at the request of its Super admin, permanently and immediately; only our invoices issued to the company (10 years) and the deletion record (the owner’s address for one year) are retained.
Data breach notification
In the event of a personal data security breach we act in accordance with the ZZPL/GDPR — we notify the company (the controller) without undue delay so that it can meet its obligations to notify the competent authority and, where necessary, the data subjects.
Contact
For questions about data protection, exercising your rights or a copy of the Data Processing Agreement (DPA), write to email (enable JavaScript).
This page is for information only and does not constitute legal advice.
NIKOLA LAZIĆ PR REPSALIO · Mišeluk 3 11, 21208 Sremska Kamenica · email (enable JavaScript)