Kage System ("we", "us", "our") provides workflow automation, cybersecurity, secure infrastructure, and AI integration services, primarily to small and medium businesses in Serbia. We are the data controller for personal data processed through this website (kagesystem.com). Our full provider identification is published on our Legal Notice page.
This policy does not cover data we process on behalf of clients under a signed services agreement — for that data we act as a processor, and the agreement governs. It also does not cover third-party sites we link to.
We collect the minimum needed to run this site and answer you, we do not sell data, and we do not run cross-site tracking. Where we can avoid collecting something, we do — a policy is easier to honour when there is less in it.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Contact correspondence — your name, email address, and whatever you write to us | Responding to your enquiry and any engagement that follows from it | Legitimate interest in responding to someone who contacted us (Art. 6(1)(f) GDPR); performance of pre-contractual steps at your request (Art. 6(1)(b)) where relevant | For the duration of the enquiry and any resulting relationship, then deleted. Correspondence with no follow-up is deleted within 24 months. |
| Newsletter subscription — email address, confirmation timestamp, and IP address at signup | Sending the newsletter you asked for, and evidencing that you consented | Consent (Art. 6(1)(a) GDPR), withdrawable at any time | Until you unsubscribe, plus a short suppression record so we do not re-add you. Consent evidence kept while the subscription is active and for 12 months after. |
| Analytics — page viewed, referrer, device and browser type, approximate country derived from IP | Understanding aggregate traffic so we know which articles are worth writing | Legitimate interest in measuring our own audience, using a cookieless tool that does not identify you (Art. 6(1)(f) GDPR) | Per our Umami configuration; aggregated and not linked to you. |
| Server logs — IP address, request time, user agent, requested path | Security, abuse prevention, and diagnosing faults | Legitimate interest in keeping the service secure and available (Art. 6(1)(f) GDPR) | Short-term, per our hosting configuration and provider policy. |
If we offer a newsletter and you subscribe, we ask for your email address and nothing else. Subscription is confirmed opt-in: we send one message to the address you entered, and you are added to the list only if you click the confirmation link. If you never confirm, the pending record is discarded.
We use our email delivery provider to store the list and deliver the messages. Your address is used solely to send you the newsletter — we do not sell it, rent it, or use it to build an advertising profile.
Every message carries a one-click unsubscribe link, and you can also unsubscribe by emailing us. Withdrawing consent is as easy as giving it, and does not affect the lawfulness of anything sent beforehand.
Our provider may record whether messages are opened and which links are clicked, in aggregate, to tell us whether the newsletter is worth continuing. Disabling remote images in your mail client prevents open tracking.
This site sets no cookies of its own, runs no cross-site advertising pixels, and uses no cookie-based tracking. Our analytics tool is cookieless and assigns no persistent identifier.
We carry no advertising. There is no ad network, no ad script, and no advertising cookie anywhere on this site, so no advertising company receives your data. Our Cookie Policy covers this in full.
We share personal data only with providers that help us operate this site and communicate with you, only to the extent needed, and never for their own marketing. Each acts as a processor under a written agreement.
We may disclose data where we are legally obliged to, or where it is necessary to establish, exercise, or defend legal claims. We will not hand over data on an informal request, and where we are lawfully permitted to tell you about a demand, we will.
We prefer providers that store data within the European Economic Area or Serbia. Where a provider processes data outside those areas, we rely on an adequacy decision or on Standard Contractual Clauses together with any additional safeguards the transfer requires. You can ask us which mechanism applies to a specific provider and we will tell you.
Under the GDPR and the Serbian Law on Personal Data Protection you have the right to access the data we hold about you, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time where processing is based on consent. Where we rely on legitimate interest, you can object and we will stop unless we have compelling grounds that override your interests.
Exercise any of these by emailing [email protected]. We will respond within 30 days, and will tell you if we need longer. We do not charge for this, and we will not make you justify the request.
If you are unhappy with how we handled it, you can complain to the Commissioner for Information of Public Importance and Personal Data Protection, Bulevar kralja Aleksandra 15, 11000 Belgrade (poverenik.rs), or to the supervisory authority in your EU country of residence.
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects concerning you.
This site is intended for a professional audience and is not directed at children. We do not knowingly collect data from anyone under 15, the age of digital consent under Serbian law. If you believe a child has provided us with personal data, contact us and we will delete it.
We take technical and organisational measures proportionate to the data we hold: encryption in transit, hardened and patched infrastructure, access restricted to those who need it, multi-factor authentication on administrative accounts, and collecting no more than we need — the last being the most effective control available.
No system is perfectly secure. In the event of a personal data breach likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and inform you directly where the risk is high.
We will update this policy as the site or our practices change, and revise the effective date above. Material changes — such as enabling advertising or adding a new category of processing — will be flagged on the site rather than made quietly.
Any question about this policy, or any request concerning your data: [email protected]. We have not appointed a Data Protection Officer, as we are not required to; enquiries go directly to the person responsible.