1. Privacy at A360
A360 DOO BEOGRAD (“A360”, “we”, “us” or “our”) respects the privacy of individuals who interact with our company. We process personal data responsibly, transparently and only for legitimate business, contractual, legal, security and communication purposes, in accordance with the Serbian Law on Personal Data Protection and the GDPR where applicable. This public policy explains what personal data A360 may process, how we obtain and use it, who may receive it, how we protect it and how individuals can exercise their rights. It applies to clients and prospective clients, business contacts, suppliers, partners, job candidates, website and social-media visitors, event participants and other individuals who communicate or engage with A360. More specific notices, contractual terms or data processing agreements may apply to a particular relationship.
2. Who is responsible and our processing roles
- Data controller: A360 determines why and how personal data is processed for its own business administration, client and partner relations, recruitment, legal compliance, security and corporate communications.
- Data processor: A360 may process personal data on behalf of a client and only in accordance with that client’s documented instructions, the applicable contract and data-protection law. In that case, the client remains responsible for the primary privacy notice and decisions about the processing.
3. How we collect personal data
- Directly from you: when you contact us, submit a form, exchange business cards, request information, apply for a position, attend an event or communicate with A360.
- Automatically: when you use our website or digital channels, through technical logs and, where enabled, cookies or similar technologies.
- From organisations and public sources: for example, from your employer, a business partner, professional network, public register or another lawful source relevant to our relationship.
- From clients: where A360 receives personal data under a contract and acts as a processor for a client.
4. Personal data we may collect
- Identity and business details: name, employer, role, business address, email address, telephone number and professional profile information.
- Communications and relationship data: enquiries, correspondence, meeting notes, service requests, support records, event registrations and feedback.
- Website and technical data: IP address, browser and device information, access time, pages viewed, referring page, security events and similar usage information.
- Recruitment and workforce data: information provided by candidates, employees and contractors, subject to separate notices and applicable law.
- Client-controlled data: personal data processed by A360 in connection with client implementation, maintenance, support or other contracted services.
5. Why and on what basis we process personal data
- Business communications and relationships: to respond to enquiries, arrange meetings and manage relationships with clients, partners and suppliers.
- Contracts and service delivery: to prepare proposals, manage contracts, implement software, provide maintenance and support, and document project activities.
- Recruitment and workforce administration: to assess candidates and administer employment or contractor relationships under separate notices.
- Security, fraud prevention and resilience: to protect people, premises, information, systems and software; manage access; detect incidents; and support business continuity.
- Legal, regulatory and audit obligations: to meet accounting, tax, employment, information-security, data-protection and other applicable requirements.
- Service improvement and corporate communications: to obtain feedback, improve our products and services, and provide relevant updates, events or professional opportunities.
Depending on the circumstances, A360 relies on contract or pre-contractual steps, legal obligation, legitimate interests, consent, or only where applicable, vital interests or a task in the public interest. Where we rely on legitimate interests, we consider whether the individual’s rights and freedoms override those interests. Consent may be withdrawn at any time without affecting processing already carried out lawfully.
6. Website, cookies and direct marketing
A360 may use essential technical information to operate, secure and improve its website. Where non-essential cookies or similar technologies are used, A360 will provide appropriate information and choices through a Cookie Notice or consent mechanism. Third-party websites linked from the A360 website have their own privacy practices, and A360 is not responsible for their content or processing activities. A360 may send relevant business communications where permitted by law. You may object to direct marketing or unsubscribe at any time using the method provided in the communication or by contacting A360. We will continue to send service, security or contractual messages where they are necessary and not marketing communications.
7. Data minimisation, sensitive data and children
A360 applies privacy by design and seeks to collect only data that is relevant and necessary. Access is restricted on a need-to-know basis, and measures such as minimisation, masking or pseudonymisation may be used where appropriate. A Data Protection Impact Assessment may be performed for processing likely to create a higher risk to individuals. A360 does not intentionally request special-category or other highly sensitive personal data through general website contact forms. Please do not submit such information unless it is necessary and specifically requested for a lawful purpose. A360’s corporate website and services are directed to business users and are not intended for children. If we learn that personal data has been collected from a child without an appropriate legal basis, we will take reasonable steps to delete it.
8. Who may receive personal data
- Authorised A360 personnel: employees and contractors who require access for their role and are subject to confidentiality and security obligations.
- Service providers and professional advisers: IT, hosting and infrastructure providers, consultants, legal advisers, accountants, banks and other providers supporting A360’s legitimate operations.
- Clients and project parties: where information must be exchanged to deliver, support or govern the relevant service or project.
- Public authorities and lawful recipients: where disclosure is required by law, court order, regulatory request or to protect legitimate rights, safety or security.
- Corporate transaction recipients: where relevant to a merger, acquisition, restructuring or transfer of business, subject to confidentiality and legal safeguards.
A360 requires appropriate contractual, technical and organisational protections from parties processing personal data on its behalf. A360 does not disclose personal data for an unrelated purpose without a valid legal basis.
9. International transfers
Before personal data is transferred outside the country in which it was collected, or outside the European Economic Area where GDPR rules apply, A360 assesses the transfer and uses an appropriate legal mechanism. This may include an adequacy decision, standard contractual clauses or another safeguard recognised by applicable law.
10. Retention and secure disposal
A360 keeps personal data only for as long as necessary for the original purpose, the duration of the relevant relationship and any additional period required by law, contract, limitation rules, security, dispute management or audit obligations. When data is no longer required, it is securely deleted, destroyed or irreversibly anonymised in accordance with applicable controls.
11. How we protect personal data
A360 applies risk-based technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, disclosure or destruction. Measures may include access control, authentication, encryption, logging and monitoring, secure software-development practices, backups, incident response, staff training and supplier controls. No information system can be guaranteed to be completely secure. A360 reviews and improves its controls on an ongoing basis. Where a personal data breach creates a legally reportable risk, A360 will notify the competent authority and affected individuals as required by applicable law.
12. Your data-protection rights
Subject to applicable law and the circumstances of the processing, you may have the right to:
- Be informed and obtain access: receive information about the processing and request a copy of personal data held about you.
- Request rectification: have inaccurate or incomplete personal data corrected.
- Request erasure or restriction: ask for deletion or limitation of processing where the legal conditions are met.
- Object to processing: object to processing based on legitimate interests or to direct marketing.
- Request data portability: receive eligible data in a structured, commonly used and machine-readable format where the legal conditions are met.
- Withdraw consent: withdraw consent at any time where processing is based on consent.
- Automated decisions: request information and appropriate safeguards where a legally significant decision is based solely on automated processing, where applicable.
- Lodge a complaint: contact the competent data-protection authority if you believe that your rights have not been respected.
A360 may need to verify your identity before responding. Rights are not absolute and may be limited where law requires or permits continued processing. Where A360 acts only as a processor, your request may need to be addressed to the relevant client/controller; A360 will support that client in accordance with the applicable contract.
13. Contact A360
For privacy questions, requests or complaints, contact A360 using the details below. Requests are handled confidentially and directed to the appropriate privacy or Data Protection Officer function. A360 DOO BEOGRAD Vladimira Popovića 6, sprat 5, stan A 504, 11070 Beograd, Serbia Privacy contact: privacy@a-360.net General contact: office@a-360.net Website: www.a-360.net
14. Changes to this policy
A360 reviews this public policy periodically and may update it to reflect changes in law, technology, services or business practices. Material changes will be clearly indicated where appropriate. The current version will be published on the A360 website. Last updated: 5 August 2026.