Privacy Policy
What personal data this website collects, why, on what legal basis, and what you can ask us to do with it.
Last updated: 21 August 2026
1. Introduction
DIGITAL CONTROL D.O.O. ("Digital Control", "we", "us", "our") protects the personal data of everyone who interacts with our website at https://digitalcontrol.me/ (the "Website") and with our services.
This Privacy Policy describes what personal data we collect, how we use it, on what legal basis, and what rights you have in relation to your data.
It applies to data collected through the Website and to any business communication started through it. Read it together with our GDPR and Data Protection Statement and our Cookie Policy.
2. Information we collect
We may collect the following categories of personal data:
- Contact information: name, email address, phone number, company name and job title, provided when you contact us or submit a form.
- Communication data: the messages and inquiries you submit through our contact or process discovery forms.
- Newsletter subscription data: email address and the record of your consent when you subscribe.
- Usage data: pages visited, time on site, traffic source, device and browser type, collected through analytics (see the Cookie Policy).
- Technical data: IP address, anonymized where possible, browser type and operating system.
We do not intentionally collect special categories of personal data, such as health, financial or biometric data, through the Website.
3. How we use your information
We use the personal data we collect in order to:
- respond to business inquiries and communication;
- produce preliminary process documentation through our Process Discovery tool;
- assess a possible business collaboration;
- send newsletters and business updates where you have consented;
- analyse Website performance and visitor behaviour in order to improve our services;
- meet legal obligations.
We do not use personal data for automated decision-making that produces legal or similarly significant effects.
4. Legal basis for processing
We process personal data on the following legal bases under the General Data Protection Regulation (GDPR):
- Legitimate interests: business-to-business communication, lead qualification, and answering business inquiries.
- Consent: newsletter subscriptions and optional analytics tracking.
- Contractual necessity: where a formal engagement or agreement is in place.
- Legal obligation: where applicable law requires it.
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights and freedoms, given the business-to-business nature of our activities.
5. Data sharing
We do not sell personal data to third parties.
We may share data with the following categories of recipients:
- Service providers: hosting providers, email delivery and marketing platforms, analytics providers and customer relationship systems, each operating under a data processing agreement.
- Professional advisors: legal, accounting or compliance advisors, where necessary.
- Regulatory authorities: where the law requires disclosure.
Service providers are selected on the basis of their compliance with applicable data protection law, including the GDPR requirements for international transfers where those apply.
6. Data security
We apply technical and organizational measures that protect personal data against unauthorized access, loss, destruction and alteration. They include:
- encrypted communication (HTTPS) for all Website traffic;
- role-based access control limiting who can reach personal data;
- hosting infrastructure inside the European Union;
- periodic review of the measures themselves.
No transmission over the internet and no electronic storage is completely secure. We cannot guarantee absolute security, and we do commit to responding promptly to any security incident.
7. Data retention
We keep personal data only as long as the purposes described in this policy require:
- Website inquiry data: at most 24 months from the last meaningful interaction, unless a contractual relationship is established.
- Newsletter subscription data: until consent is withdrawn.
- Data held under a legal obligation: for as long as that obligation runs.
After the applicable retention period the data is securely deleted or anonymized.
8. Your rights
Under applicable data protection law you may have the following rights in relation to your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion of your data, subject to legal retention requirements.
- Restriction: request that we limit how we use your data.
- Objection: object to processing based on legitimate interests.
- Withdrawal of consent: withdraw consent at any time where processing rests on consent.
- Portability: receive your data in a structured, machine-readable format.
- Complaint: lodge a complaint with the competent supervisory authority.
To exercise any of these rights, contact us with the details in the next section. We answer within the applicable statutory deadlines.
9. Contact
For questions, requests or concerns about this Privacy Policy or our processing practices:
DIGITAL CONTROL D.O.O.
Knjaza Danila 78A
81000 Podgorica
Montenegro
Email: info@digitalcontrol.me
For data protection requests, please use the subject line "Privacy Request".
We may update this Privacy Policy. Material changes are reflected in the date shown above, so it is worth reviewing the policy periodically.