GDPR and data protection
Our position on personal data: the role we hold, the bases we process on, where the data sits, and how a data subject reaches us.
Last updated: 21 August 2026
1. Our approach to data protection
At DIGITAL CONTROL D.O.O., data protection is an operational responsibility, not a checkbox.
We work in environments where process ownership, auditability and regulatory awareness decide whether a system is usable. Personal data is handled on the same principles.
We commit to:
- lawful and transparent processing;
- purpose limitation;
- data minimization;
- accuracy;
- storage limitation;
- integrity and confidentiality;
- accountability.
2. Role under the GDPR
DIGITAL CONTROL D.O.O. acts as:
- Data controller: for data collected through the Website.
- Data processor: only where a contractual engagement with a client says so explicitly.
The scope of responsibility follows the context of the processing.
3. Lawful basis for processing
We rely on one or more of the following legal bases:
- legitimate interest, for business-to-business communication and lead qualification;
- consent, for newsletter subscription;
- contractual necessity, where a formal engagement exists;
- legal obligation, where one applies.
We do not process personal data without a defined legal basis.
4. Data minimization
We collect only the data needed to:
- answer business inquiries;
- produce preliminary process documentation;
- assess a possible collaboration.
We do not intentionally collect special categories of personal data through the Website.
5. Infrastructure and data location
All primary infrastructure behind the Website sits inside the European Union, as do the automation and customer relationship systems that support it.
Where third-party providers are involved, we rely on their GDPR-compliant processing frameworks and on contractual safeguards.
6. Security measures
We apply technical and organizational measures, including:
- encrypted communication (HTTPS);
- controlled system access;
- role-based permissions;
- restricted administrative access;
- hardened server infrastructure.
The measures are reviewed periodically and adjusted to the operational risk.
7. Data retention
Website-related personal data is kept for at most 24 months from the last meaningful interaction, unless:
- a contractual relationship is established;
- a legal retention obligation applies.
Newsletter data is kept until consent is withdrawn.
8. Data subject rights
Under applicable data protection law, individuals may have the right to:
- access their personal data;
- request correction;
- request erasure;
- restrict processing;
- object to processing;
- withdraw consent;
- request data portability.
Requests can be submitted to:
Email: info@digitalcontrol.me
We answer within the applicable statutory deadlines.
9. International transfers
Where a third-party provider processes data outside the European Union, we rely on safeguards such as:
- Standard Contractual Clauses;
- adequacy decisions;
- equivalent legal mechanisms.
We do not knowingly transfer data to jurisdictions without legal safeguards.
10. Incident handling
If a personal data breach occurs, we follow a documented internal process:
- assessment of the incident;
- containment;
- documentation;
- notification where the law requires it.
Where applicable, supervisory authorities and the individuals concerned are informed in line with GDPR requirements.
11. Contact for data protection matters
DIGITAL CONTROL D.O.O.
Knjaza Danila 78A
81000 Podgorica
Montenegro
Email: info@digitalcontrol.me
For GDPR requests, please use the subject line "Data Protection Request".