(27.10.2021)
1. About us
BLUE GRID DOO, with its seat at Mihajla Pupina Boulevard no. 10a, Belgrade-New Belgrade, registration number 21259128, e-mail office@bluegrid.io (“Blue Grid“, “Company“, “us“, “we”) is a company for computer programming and provision of various services. In performing our activities, we process personal data, either as a data controller or data processor. We process personal data in full compliance with the provisions and principles prescribed under the Law on Personal Data Protection (“Official Gazette of RS”, No. 87/2018) (“Law“), other laws and bylaws, and existing standards in the field of personal data protection. When we process personal data as a data controller, we determine the purpose and manner of processing personal data, while when we process personal data as a data processor we process personal data on behalf of a data controller, e.g. our clients, who determine purpose and manner of data processing.
We conduct some of our services through a platform which is located at https://app.metricsflare.com (“Platform”) which can be accessed through our website https://metricsflare.com (“Website”). Please note that this Privacy Notice (“Notice”) applies only to the Platform and its usage, while a privacy notice applicable for the Website may be accessed here. The primary use of the Platform is to help companies to advance and improve customer service quality by allowing their clients to leave feedback and rate for a survey a company representative created for such purpose. The Platform collects data for processing after which the company registered on the Platform will use digested statistics for evaluation of their service and plan for steps to improve customer success score.
As we are committed to the protection of personal data, we accordingly collect and process personal data in a fair and transparent manner, whereby personal data are collected and processed for specific, permitted purposes, and we are processing only personal data necessary to achieve the purpose for which they are collected and processed. We store personal data only to the extent necessary to achieve the purpose of processing and in accordance with regulations.
This Notice, in addition to fulfilling our statutory obligations, provides you with information regarding the purposes of personal data processing, the legal basis for the processing of personal data, your rights as data subjects, and other aspects of personal data protection. Please read this Notice in its entirety to learn more about the types of personal information we collect and process, the purposes for which your personal information is processed, your rights, and other information contained in this Notice.
In conducting our activities, we apply measures to ensure that personal data is accurate while ensuring the right to correct or delete inaccurate personal data. In the field of personal data protection, we implement measures to protect personal data from loss, destruction, damage, as well as from unauthorized access or illegal processing of personal data by taking all necessary measures and respecting legal obligations and existing standards in this area.
2. The processed personal data, source of personal data, purpose, legal basis, and retention period
In performing our activities on the Platform and in order to fulfill numerous legal obligations, and to satisfy the interests of users of our services, fulfill contractual obligations, we, as the data controller, process personal data of persons with whom we are in contact regarding our business, such as name, IP addresses, e-mail addresses, telephone numbers, position within the organization, passwords and alike.
The purposes for which we collect, and process personal data through the Platform are clearly defined during each collection and processing of personal data, and the same is done on the basis of prescribed grounds such as the consent of a person that can be quickly and easily withdrawn at any time, our legitimate interest, and for the purpose of concluding and executing the contract and fulfilling the legal obligations we have.
2.1. Personal data collected through the Platform and for the usage of services through the Platform
When you decide to use the services that we provide through the Platform, you need to register on the Platform and confirm registration in accordance with the procedure available on the Platform in order to create a user account. In order to complete registration on the Platform, you need to provide us with the following personal data: first name and last name, e-mail address, company name, company contact phone number, and the address of the company. When creating a user account, you will need to create a unique password for accessing the user account, which we also process.
When the user account is successfully created, you will need to create user accounts for your engaged personnel, and for this purpose, you need to provide their first name and last name, e-mail address, and passwords. You, as our client and a registered user of the Platform, are responsible for collecting consent from your personnel informing them about the use and purpose of our Platform and what information will be used for what purpose.
In addition, depending on your decision regarding usage of our services through the Platform, you may be required to provide us with information such as credit/debit card or PayPal account information for billing and billing postal code for verification. Please note that we use a third-party intermediary to manage payment processing. Therefore, we do not store, retain or use your billing information. If you do not provide your credit card or other payment information before the expiration of any free trial period, your account will be suspended until payment information and charge authorization are provided.
We need the stated personal data in order to enter into a contractual relationship with you and fulfill the obligations from such a contractual relationship regarding usage of our services through the Platform, and if you do not submit them, we will not be able to enter into a contractual relationship, as well as to fulfill our obligations arising from such a contractual relationship. We keep stated personal data as long as our contractual relationship is in force, and exceptionally longer if necessary for the purpose of fulfilling our legal obligations or for the purpose of filing, realizing, or defending a legal claim.
Aside from registered users, you may, however, visit our Platform anonymously. When doing so we do not directly identify you when using our Platform. A visit to our Platform collects the following information, which may be personal data such as IP, the type of device you use to access our Platform, the date and time of your visit to the Platform, the browser you used to access it, and the operating system of your device.
We collect and process the aforementioned data for statistical and analytical purposes in order to determine the number of visits to our Platform, as well as for the security purposes of our Platform, in order to prevent abuse and potentially identify the person responsible for abuse in cooperation with government agencies. The basis for this data processing is our legitimate interest, which consists in ensuring the functionality of our Platform, improving it, and preventing potential abuse, while this data is stored as long as necessary to achieve this purpose, and exceptionally longer if necessary for the purpose of fulfilling our legal obligations or for the purpose of filing, realizing or defending a legal claim.
Additionally, through our Platform, we may collect and process personal data that may be provided in your message when you contact us via the chat contact form available on our Platform in order to contact you. If you do not provide us with the above information via the chat contact form on our website, we will not be able to respond to you. We may need this personal information in order to respond to your message sent to us via the chat contact form and we process it based on our legitimate interest in communicating with you at your request. We store personal data collected in this way and for the stated purpose until the purpose is achieved.
Our Platform uses cookies, which you can find out more about here.
On our Platform, there is a possibility that there are links to third-party websites that have their own rules regarding the protection of personal data that you can get familiar with on third-party websites and we are not responsible for them.
2.2. Marketing activities
In order to present what we do, our products, and services, we may from time to time inform you about existing and new services, products, news in the industry in which we operate. We can notify you via email in order to achieve the stated purpose, for which we need personal data such as e-mail, name, and surname which we process for this purpose. We process the personal for this purpose solely on the basis of your consent, which is the legal basis for this processing if you are a natural person.
If you do not wish to receive notifications from us, you can revoke your consent at any time by sending an e-mail to (support@metricsflare.com). If you revoke your consent for this processing of personal data, we will stop sending you the above notice and stop processing personal data collected for this purpose within 30 days from the date of revocation of consent due to technical requirements that must be met in order for the change to take place.
Personal data collected in this manner is stored and processed until you revoke your consent, exceptionally longer if it is necessary to fulfill our legal obligations.
3. Data processing based on our legitimate interest
We may from time-to-time process personal data for the purpose of achieving our goals based on our legitimate interest and only if our legitimate interest outweighs your interests, rights, and freedoms.
We process personal data based on our legitimate interest due to:
- business improvement, upgrading, and development of new and existing services and products;
- business protection;
- prevention of fraud;
- ensuring data security;
- securing our users and preventing abuse.
4. Data Processors
As stated above in this Notice, it is important to inform you that, depending on the purpose of processing, we may act as a data processor of personal data. When our clients use the Platform, you may receive certain inquiry forms that you are asked to respond to, whereby we act as the data processors on behalf of our client who is using the Platform and determine the purpose and manner of personal data processing. For this procedure, we may process, as a data processor, personal data such as e-mail and a country where you submit your responses to our client’s inquiry forms.
In carrying out our activities, we may cooperate with third parties to whom we may provide personal data for processing. Before cooperating with the processors, we assured that these are persons who meet the requirements in terms of appropriate technical, organizational, and personnel measures so that they meet the requirements that data processing is performed in accordance with regulations, and that personal data is secure. If we hire processors, we conclude contracts with processors in accordance with the regulations, and they are obliged to act only according to our instructions, taking into account the purposes of processing that we determine.
5. Recipients
In order to achieve the purposes of processing personal data, and to meet contractual and legal obligations, personal data can be shared with different recipients, which can be:
- our employees;
- accounting agencies;
- auditors;
- lawyers;
- state bodies and organizations.
Recipients receive personal data under the conditions of prescribed organizational and technical measures and procedures, where they are obliged by agreements on confidentiality and data protection, except when such obligations arise from mandatory legal provisions.
6. Personal data transfer outside the Republic of Serbia
During the business activities conducted, personal data may be transferred to other countries. If there is a transfer of personal data to other countries, such transfer is made only to countries that have been determined to provide an appropriate level of protection in accordance with the regulations of the Republic of Serbia and the decisions of the competent authorities.
7. Your rights
In accordance with the Law, you have numerous rights when it comes to your personal data. The following of this Notice lists the rights that you have in accordance with the Law, and we will always assist you in exercising your rights in accordance with the Law.
7.1. Right to access
You have the right at any time to ask us for information on whether we process your personal data, access to that data, as well as information:
- on the purpose of the processing;
- on the types of personal data that we process;
- the recipient or types of recipients to whom personal data have been or will be disclosed, in particular to recipients in other countries or international organizations;
- on the envisaged period of keeping personal data, or if that is not possible, on the criteria for determining that period;
- the existence of the right to request from us the correction or deletion of personal data, the right to limit processing, and the right to object to processing;
- on the right to submit a complaint to the Commissioner for Information of Public Importance and Personal Data Protection (“Commissioner“);
- the source of personal data, if personal data have not been collected from you;
- on the existence of an automated decision-making procedure, including the profiling referred to in Article 38, para. 1 and 4 of the Law, and, at least in those cases, relevant information on the logic used, as well as on the significance and expected consequences of that processing.
If personal data are transferred to another state or international organization, you have the right to be informed of the appropriate protection measures related to the transfer, in accordance with Article 65 of the Law.
7.2. Right to correct
You have the right to ask us to correct your incorrect personal data without undue delay. Depending on the purpose of the processing, you can supplement your incomplete personal data, which includes giving an additional statement.
In the event of a correction, we will notify all recipients to whom personal data have been disclosed of each correction, unless this is impossible or requires an excessive expenditure of time and resources, and notify you about this, as well as on all recipients at your request.
7.3. Right of deletion
You have the right to ask us to delete your personal data, and we will delete such personal data without undue delay in the following situations:
- personal data are no longer necessary to achieve the purpose for which they were collected or otherwise processed;
- you have revoked the consent on the basis of which the processing was performed, and there is no other legal basis for processing;
- you have filed an objection to processing in accordance with:
a) Article 37, paragraph 1 of the Law, and there is no other legal basis for processing that prevails over your legitimate interest, right or freedom,
b) Article 37, paragraph 2 of the Law; - personal data have been processed illegally;
- personal data must be deleted in order to fulfil our legal obligations;
- personal data are collected in connection with the use of information society services referred to in Article 16, paragraph 1 of the Law.
If we have publicly disclosed the personal data which deletion you request, we will take all reasonable measures, including technical measures, in accordance with available technologies and taking into account the possibility of bearing the costs of their use, in order to inform other controllers that you have submitted a request for deletion in accordance with the Law of all copies of these data and references, i.e. electronic links to these data.
We will notify all recipients to whom your personal information has been disclosed of any deletion, unless this is impossible or requires an excessive expenditure of time and resources, and will notify you about this, as well as on all recipients at your request.
7.4. The right to limit processing
You have the right to require us to restrict the processing of personal data if one of the following conditions is met:
- if you dispute the accuracy of personal data, within the period that allows us to check the accuracy of personal data;
- the processing is illegal, and you oppose the deletion of personal data and instead of deleting you demand a restriction on the use of data;
- We do not need personal data to achieve the purpose of processing, but you exercise this right to limit processing in order to file, exercise or defend a legal claim;
- you have filed an objection to the processing in accordance with Article 37, paragraph 1 of the Law, and the assessment of whether the legal basis for processing by the controller outweighs your interests is in progress.
In the event of exercising this right to limit processing, we will continue to process such personal data only on the basis of your consent to the processing, unless it is stored or for the purpose of filing, exercising, or defending a legal claim or to protect the rights of other natural or legal person, legal persons or for the realization of significant public interests.
We will notify all recipients to whom personal information has been disclosed of any processing restrictions, unless this is impossible or requires an excessive expenditure of time and resources, and notify you about this, as well as on all recipients at your request.
7.5. Right to transfer
You have the right, in accordance with the Law, to receive your personal data that you have previously provided to us from us in a structured, commonly used and electronically readable form and you have the right to transfer this data to another controller without our interference, if at the same time following conditions are met:
- processing is based on consent in accordance with Article 12, paragraph 1, item 1) or Article 17, paragraph 2, item 1) of the Law or on the basis of a contract, in accordance with Article 12, paragraph 1, item 2) of the Law;
- processing is performed automatically.
Your right to transfer includes the right to have your personal data transferred directly to another controller, if technically feasible.
7.6. Right to object
If you believe that this is justified in relation to the special situation in which you find yourself (for example, in situations where you are in danger), you have the right to object to us at any time for the processing of your personal data, which is carried out in accordance with Article 12. paragraph 1 item and 6) of the Law, including profiling based on these provisions. We will discontinue the processing of data based on this complaint unless we show you that there are legal reasons for the processing that outweigh your interests, rights, or freedoms of the person or are related to the filing, realization, or defense of a legal claim.
You have the right to object at any time to the processing of your personal data processed for direct advertising purposes, including profiling, to the extent that it is related to direct advertising, and in that situation, we will not further process your personal data for those purposes.
7.7. Right to notification in case of a personal data breach
In the event of a personal data breach, we will notify you without undue delay of the violation, if the personal data breach may pose a high risk to your rights and freedoms, with such notification stating at least the name and contact details of the person for the protection of personal data in the Blue Grid or information on other means of obtaining information about the injury, a description of the possible consequences of the injury, a description of the measures we have taken or proposed to take in relation to the injury, including measures taken to mitigate harmful consequences.
7.8. Right to file a complaint
You have the right to lodge a complaint with the Commissioner in accordance with the Law.
8. Our contact details
In connection with the exercise of your rights in accordance with the Law, you can contact us in writing at the address Bulevar Mihajla Pupina 10a, 11070 New Belgrade, Republic of Serbia, via the email address (support@metricsflare.com).
9. Notice amendments
We may from time to time amend and/or supplement this Notice which can be found on our Website and/or the Platform.