Legal information · P06
Privacy Policy and Data Processing Notice
Effective from: 24 Sept 2026, 11:48
Effective date / Datum primene: 2026-09-24
1. Controller and contact
For the processing described here, the controller is Yevt Group, To be completed after company registration., contact To be completed after company registration.. The status and contact of any data protection officer and representatives appointed where required are listed here: To be completed after company registration.. These titles do not automatically identify the same person or legal role.
This notice covers the website, accounts, purchases, programmes, support and other expressly identified features. Independent controllers involved in a transaction or service are identified in the recipient register below.
2. Data and sources
Depending on the feature you use, processing may cover identity and contact details, account information, order and payment information, agreed access and progress, support correspondence, your posts and technical information needed for security. Optional analytics and marketing have separate grounds and controls.
The complete inventory of categories actually used, sources, required information and consequences of not providing it is: To be completed after company registration.. Where data comes from another source, we identify its type and provide additional notice when legally required. We do not request every item in every category from every user.
3. Purposes and legal bases
Accounts, order processing and requested delivery rely on contract performance or steps at your request to the extent the data is necessary. Accounting, tax and other mandatory records rely on the relevant legal obligation. System protection and dispute handling may rely on legitimate interests only after appropriate assessment and with objection rights preserved.
Marketing and optional technologies requiring consent rely on appropriate separate consent. The basis for each processing operation, including particular local requirements, is shown in the section 2 inventory. We do not switch legal bases merely to bypass a withdrawal of consent or statutory restriction.
4. Private exercises and sensitive data
Do not send health information, other sensitive details or information about third parties unless needed for an expressly explained feature. Private notes and answers are stored as follows: To be completed after company registration.. Data remaining solely on your device must not be described as collected by our server, or vice versa.
If a feature requests special categories of data, we disclose its specific purpose, legal condition, choices and safeguards before processing starts. Purchasing a programme is not blanket consent to processing private journals, publishing answers or sending them to an AI provider.
5. Recipients and service providers
We disclose data only for a justified purpose and to the extent necessary. Hosting, payment, email, video and other providers may hold different roles. Actual recipients or sufficiently specific recipient categories, roles, purposes and processing countries are listed here: To be completed after company registration..
Processing by processors is governed by appropriate agreements. Where disclosure to authorities is legally required or information is used for a legal claim, we check its basis and scope. Your private correspondence does not become a public endorsement or marketing material without a separate appropriate basis.
6. International transfers
The company’s country of registration does not completely describe where data is processed. Relevant transfers, countries, mechanisms and ways to obtain safeguard information are: To be completed after company registration..
The mechanism is determined under the law governing each transfer. We do not assume that a single agreement or EU standard clauses automatically satisfy every Serbian, UK or other obligation. We do not claim that all data remains in one country without verifying actual providers and access.
7. Retention
The retention period or sufficiently specific criterion for each relevant category and purpose is: To be completed after company registration.. Where relevant, it covers accounts, purchases, statutory records, support, consent records, security logs and backups.
Deleting an account does not automatically erase information we must retain by law or for legal claims. Such information is separated and used only for its remaining justified purpose. We do not retain all information indefinitely on a general assertion that it might be useful later.
8. Your rights
Depending on applicable law and the conditions of each right, you may request information, access, a copy, correction, erasure, restriction or portability, object to processing and withdraw consent. Withdrawal does not affect the lawfulness of earlier processing based on that consent. Particular market rights are described in the Regional Addendum and Privacy Choices page.
Send requests to To be completed after company registration. or use To be completed after company registration.. You do not need to create a new account. For requests revealing personal information or changing access, we may proportionately verify identity. We do not routinely require an identity-document copy where a reliable, less intrusive method is available.
9. Response periods and complaints
For requests under Serbian law we follow its period, generally no later than 30 days; under GDPR or relevant UK rules, generally one month. Those periods are not necessarily equivalent. Extensions are used only as the law permits, with timely notice. Other regimes have their own deadlines.
Where required, we explain a refusal or limitation and available remedies. You may complain to a competent authority. Relevant authorities and procedures are: To be completed after company registration.. Contacting us does not remove your right to use available statutory remedies directly.
10. Security and automation
We use measures proportionate to risk and restrict access by role. We do not promise absolute security. If a personal-data breach occurs, we assess the risk and notify authorities and individuals where legally required.
Actual profiling and automated decisions with legal or similarly significant effects, meaningful information about their logic where required, significance and available safeguards are described here: To be completed after company registration.. Routine automated confirmations must not be confused with decisions requiring additional rights and controls.
11. Minors, cookies and marketing
Programme eligibility and additional safeguards for minors are described in a separate notice. The age for consenting to particular processing is not necessarily the age for independently entering a purchase contract. The Cookie Policy explains storing or accessing information on devices. Marketing choices are separate from messages necessary for the contract and security.
12. Changes
We publish the notice date and version. Significant changes are communicated appropriately, and new consent is obtained before new processing where required. Editing a notice does not legitimise earlier unlawful processing or expand old consents without a legal basis.