Mileva Koncept
Legal

Privacy policy

Last updated: 4 August 2026

Your privacy matters to us, and we would rather explain it plainly than bury it in fine print. This policy sets out what personal data we collect through milevakoncept.rs, why we collect it, how long we keep it and what rights you have.

It is written under the Serbian Personal Data Protection Act (Zakon o zaštiti podataka o ličnosti, Official Gazette of the RS no. 87/2018), which closely follows the GDPR.

1. Who controls your data

The data controller, within the meaning of Article 4 of the Act, is:

Name
Mileva Koncept
Address
Vase Pelagića 18, 34205, Grivac, Serbia

We are not required to appoint a data protection officer (Article 56 of the Act): processing personal data is not our core activity, we carry out no systematic monitoring, and we do not process special categories of data on a large scale. Please send any question or request about your data to the e-mail address above.

2. What data we collect

We collect only what you send us through the forms on this site, plus the minimum technical data needed to run it securely.

  • Contact form - your name, e-mail address, subject (optional) and the message itself.
  • Accommodation booking request - your name, e-mail address, phone number (optional), number of guests, arrival and departure dates and any note you add.
  • Technical data - IP address, time of access and basic browser information, from the server's security logs.

We neither ask for nor want special categories of personal data - health, religion, political opinion, ethnicity or the like. Please do not enter them in the message field.

No form on this site asks for a national ID number, identity card number or payment card details.

3. Why we process it, and on what legal basis

Every processing operation is tied to a specific purpose and a legal basis under Article 12 of the Act:

  • Answering your enquiry - so we can reply to a message sent through the contact form. Basis: steps taken at your request before entering into a contract, and our legitimate interest in responding (Article 12(1)(2) and (6)).
  • Handling a booking request - so we can check availability, confirm the booking and arrange the details of your stay. Basis: performance of a contract, or steps prior to it (Article 12(1)(2)).
  • Protecting the site from abuse - we limit how many messages and requests may come from one IP address, so the forms do not become a spam channel. Basis: our legitimate interest in keeping the site working and secure (Article 12(1)(6)).
  • Meeting legal obligations - keeping the records and accounting documents required by law once a stay actually takes place. Basis: compliance with a legal obligation (Article 12(1)(3)).

We do not use your data for marketing messages without your consent, and we do not run a newsletter.

4. How long we keep it

We keep data no longer than the purpose it was collected for requires.

  • Contact form messages - at most two years from our last exchange, then deleted.
  • Booking requests that do not become bookings - at most twelve months.
  • Confirmed bookings - for the duration of the stay and afterwards for the periods required by hospitality and accounting regulations.
  • Server security logs - at most twelve months.

We will delete your data sooner than that as soon as you ask us to, unless the law requires us to keep it.

5. Who else may receive it

Access is limited to the few people on our team who need it for their work. Beyond that, data may be disclosed to:

  • our website and database hosting provider, which stores it on our behalf and on our instructions;
  • our e-mail provider, through which notifications about your messages and requests reach us;
  • competent state authorities, where the law requires it.

We do not sell, trade or hand your data to third parties for advertising.

If any of our service providers is located outside the Republic of Serbia, we transfer data only in line with Articles 63 to 69 of the Act - that is, to countries with an adequate level of protection or subject to appropriate safeguards.

6. Cookies

This site uses no cookies for analytics, profiling or advertising. There is no Google Analytics, no social media pixel, no ad network and no tracking of your movements across the web.

Your language choice is not stored in a cookie - it lives in the page address itself (/sr, /sr-latn, /en).

Only strictly necessary cookies may be set, used by the server to keep the site working and secure. Regulations do not require consent for these, since without them the service you asked for could not be delivered.

You can block third-party cookies in your browser settings at any time; it will not affect how this site works.

Read the cookies policy

7. Your rights

Under the Act, you have the right at any time to:

  • access - find out whether we process your data and obtain a copy (Article 26);
  • rectification - correct inaccurate and complete incomplete data (Article 29);
  • erasure - ask us to delete your data (Article 30);
  • restriction - have processing temporarily suspended (Article 31);
  • portability - receive your data in a machine-readable format, or have us transfer it to another controller (Article 36);
  • object - object to processing based on legitimate interest (Article 37);
  • withdraw consent - where processing rests on consent, withdraw it at any time, without affecting the lawfulness of processing before withdrawal.

Send your request to info@milevakoncept.rs. We reply as soon as we can and within 30 days of receiving it at the latest; exceptionally that period may be extended by a further 30 days, and we will tell you why.

Exercising these rights is free. We may charge only where a request is manifestly unfounded or repeated excessively.

8. Complaint to the Commissioner

If you believe our processing breaches the Act, you may lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection:

Bulevar kralja Aleksandra 15, 11120 Belgrade, Serbia · office@poverenik.rs · +381 11 3408 900 · www.poverenik.rs

You can go to the Commissioner without contacting us first, though we would appreciate the chance to put things right.

9. Keeping your data safe

The connection between your browser and this site is encrypted (HTTPS), and form data travels through our own server, so the database address is never exposed in the browser.

Only authorised people can reach the data in the admin panel, and only with a password. The forms are protected against automated submissions and rate-limited per address.

No measure is absolute, however. Should a data breach occur that is likely to pose a high risk to your rights, we will notify you in line with Articles 53 and 54 of the Act.

10. Children

This site is not aimed at children and we do not knowingly collect their data. Under Article 16 of the Act, a person under 15 may give consent only with the authorisation of a parent or legal guardian.

If you learn that a child has sent us their data, please tell us and we will delete it straight away.

11. Automated decision-making

We make no decisions based solely on automated processing and carry out no profiling within the meaning of Article 38 of the Act. Every booking and every enquiry is read by a person.

12. Changes to this policy

We may update this policy if the way we work changes or regulations require it. The version in force is always the one on this page, with the date of the last update at the top.

If the changes are significant, we will make them visible before they take effect.