Legal

Privacy policy

Last updated: 6 October 2026

1. Introduction

This Privacy policy explains how NIKOLA LAZIĆ PR REPSALIO (operator of the duplo software) collects, processes, stores and protects personal data. It applies to the use of the duplo website and application, in accordance with the Serbian Personal Data Protection Act (ZZPL) and, where applicable, the General Data Protection Regulation (GDPR).

2. Roles (controller and processor)

For the data a company enters about its customers, suppliers, employees and business (lists, documents, payroll runs), the company is the controller, and NIKOLA LAZIĆ PR REPSALIO is the processor, which processes that data solely on the company’s documented instructions, for the purpose of providing the service. The relationship is governed by the Personal Data Processing Agreement (Annex 1 to the Terms of use), which the company accepts when opening an account.

For the data you enter about yourself and your company (user account, company details, subscription billing, newsletter), the controller is NIKOLA LAZIĆ PR REPSALIO.

3. What data we process

Account and company data: first and last name, email, company name, PIB (tax ID), company registration number (MB), address, bank accounts and subscription billing details.

Data the company enters (on the company’s behalf): about customers and suppliers — names, addresses, PIB and company registration number, contact details and business and financial data in documents; about employees and other income recipients, when the company uses payroll — first and last name, JMBG (personal identification number), address, bank account, length of service, salaries, deductions and business trips.

Sick leave (on the company’s behalf): when the company imports an export from the eBolovanje portal, the period, the cause (e.g. illness or injury at work) and the status of the employee’s sick leave are stored — data that may constitute health data. The diagnosis and other medical data are not read or stored, and sick leave in the application is visible only to the Super admin, Administrator and Accountant roles. duplo is not intended to process other special categories of data.

Technical data: sign-in details (time, IP address, device/browser) and a technical record kept for security and to limit the number of sign-in attempts.

Messages to support: when you write through the chat in the application (Help → Chat), we store your messages and our replies, the time they were sent and the name of the company you were working in while writing, so that we can reply to you and follow the conversation.

4. Purposes and legal basis

Providing the service — performance of a contract (Article 6(1)(b) GDPR and the corresponding provisions of the ZZPL). Billing and accounting — compliance with legal obligations (Article 6(1)(c) GDPR). Security and prevention of abuse — legitimate interest (Article 6(1)(f) GDPR).

Newsletter — solely on the basis of your consent (Article 6(1)(a) GDPR), given optionally at sign-up or by entering your address in the “News by email” field on the website. You can withdraw your consent at any time — via the unsubscribe link in the message itself or by writing to our contact address — without affecting your use of the service.

Transactional messages (the sign-in code, proforma invoices and invoices for the subscription, expiry reminders, a notification that a reply from support has arrived) are sent because they are necessary for the functioning of the service and the performance of the contract.

Support chat — performance of a contract (help with using the service you pay for or are trying out).

5. Sub-processors and third parties

We do not sell personal data. To provide the service we engage carefully selected sub-processors: hosting and application execution (Vercel, EU region — Frankfurt), the database (Neon — PostgreSQL, Frankfurt, EU), file storage (Vercel Blob, Frankfurt, EU), email delivery (Resend) and real-time notifications in the support chat (Pusher Channels, Bird B.V., the Netherlands — EU cluster in Ireland). No message content passes through Pusher, only a signal that a new message has arrived; the content is always loaded from our database. When connecting, Pusher processes the device’s IP address and the channel name, and may keep the IP address for up to 14 days if an error occurs in the operation of the service. All sub-processors are bound by data protection agreements.

6. Location and transfer of data

Data is primarily stored and processed in the European Union (Frankfurt, Germany; support chat notifications via Pusher in Ireland). Certain services (e.g. email delivery, error tracking at Pusher) may involve a transfer outside the EEA — in that case the appropriate safeguards provided for by the regulations (standard contractual clauses) apply.

7. Retention period

Business documents and company data are kept for as long as the company uses the service and are not deleted automatically — accounting regulations require issued documents to be retained. One-time sign-in codes are valid for 5 minutes; sessions expire after 30 days of inactivity. When use ends, the company is deleted by its own Super admin (Settings → Data, confirmation by a link from an email): all of the company’s data is permanently deleted immediately. We retain our own invoices issued to the company (accounting obligation, 10 years) and a deletion record in which the owner’s address is kept for one year and then deleted. A user deletes their own account on the My account page; the name and address that remain in the records of other companies (team history, documents) stay with those companies as controllers of their own records.

We keep the support chat conversation for as long as your account exists and delete it together with the account. Notifications about a new message that we sent by email (to you and to our support team) may contain the text of the message and remain in the recipients’ mailboxes.

8. Cookies and local storage

We use only technically necessary cookies and local storage: for sign-in and the session and for remembering display settings (theme, navigation). We do not use cookies for tracking, advertising or profiling and we do not share data with advertisers — which is why a cookie banner is not needed. You can delete this data in your browser settings.

9. Security

We apply appropriate technical and organisational measures: encrypted transfer (HTTPS/TLS), passwordless sign-in (a one-time code sent to email, hashed, with a limited number of attempts), strict isolation of data per company (multi-tenant), role-based access (salaries and sick leave are visible only to the Super admin, Administrator and Accountant roles), encrypted storage of access keys for government systems, private file storage and hosting in the EU.

10. Your rights

You have the right of access, rectification, erasure, restriction of processing, portability and objection, as well as the right to withdraw consent (for the newsletter). Persons whose data a company enters (the company’s customers, suppliers and employees) exercise their rights primarily through the company (the controller); we, as processor, help the company respond to those requests. A company can export its data (XML) and delete the company itself at any time, and a user can download their data (including support chat messages) and delete their account on the My account page.

If you believe your rights have been infringed, you have the right to lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs).

11. Changes to this policy

We may update this Policy from time to time. The current version is always available on this page; we will notify you of material changes.

12. Contact

For questions about privacy and to exercise your rights, write to email (enable JavaScript).

NIKOLA LAZIĆ PR REPSALIO · Mišeluk 3 11, 21208 Sremska Kamenica · email (enable JavaScript)