LEGAL
Privacy Policy
How we collect, use, store and protect data across the website, forms, GTM tools, app and related services.
Last updated: 7 August 2026.
1. Data controller
PROJECT CODES DOO, Geteova 61, 11080 Belgrade, Zemun, Republic of Serbia. Company registration no. 22038648. Tax ID 114554057. Privacy contact: office@projectcodes.rs.
2. Who this policy applies to
This policy applies to website visitors, people using business and support forms, users of the FMCG and Startup GTM tools, newsletter subscribers, Project Codes app and marketplace users, clients, partners and campaign participants.
3. Data we may process
- name, email, phone number, company, role, industry and communication content;
- business information submitted through forms, including objectives, market, category, business model and timing;
- answers, route, diagnosis, priorities and 90-day plan from the GTM tools;
- Case ID, consent version and timestamp, operational email status, CRM synchronisation and technical AI audit information;
- account, device, diamond, code and marketplace activity;
- receipt information needed to verify a qualifying purchase;
- newsletter and marketing preferences where separately provided;
- technical security information, cookie choices and website-usage data;
- support communication and optional image attachments supplied by the user.
4. Purposes and legal bases
We process data to answer enquiries, take steps before entering a contract, prepare and perform business cooperation, deliver requested GTM results, operate the app and accounts, verify purchases, allocate diamonds, issue digital codes, provide support, secure the service, prevent abuse, perform consent-based analytics, meet legal obligations and protect legal claims. Depending on the situation, the legal basis may be consent, a pre-contractual request, contract performance, legal obligation or legitimate interest.
5. GTM tools and optional AI interpretation
Both GTM tools provide a locked deterministic result without AI. Storage of answers and delivery of the full result require explicit consent inside the tool. AI interpretation is optional and requires separate consent.
When AI interpretation is requested, only limited and redacted business context and the already locked result are sent to the OpenAI API. We do not send the business email address, phone number, IP address or secure result token. The API request uses store:false. OpenAI may still process limited security and abuse-monitoring logs under its own policies.
6. HubSpot CRM and browser tracking
HubSpot is used for CRM records and business-contact history. After a requested GTM result, the server may send contact data and a limited non-sensitive summary such as Case ID, tool type, route, short diagnosis and fit information. It does not send the full questionnaire, sensitive free text, AI prompt or secure result token.
HubSpot browser tracking loads only after analytics consent.
7. Google Analytics 4
Google Analytics 4 is active on the production website and loads only after the user accepts analytics cookies. Analytics consent is separate from GTM storage consent and AI consent.
8. Cloudflare Turnstile
Cloudflare Turnstile is used as an essential security control for forms and GTM tools. It processes technical signals and issues a short-lived token to help prevent bots and abuse. It is not used for advertising profiling.
9. Hosting, email and recipients
The site is hosted by Loopia and Loopia SMTP is used for operational email. Data may be shared only as necessary with hosting and IT providers, email services, HubSpot, OpenAI where separately approved, Cloudflare for security, digital-code partners, clients or agencies involved in a specific campaign, accountants, legal advisers and competent authorities. We do not sell personal data.
10. International transfers
Some providers may process data outside Serbia. Where this occurs, we seek appropriate contractual, organisational and technical safeguards and limit the data to what is necessary for the service.
11. Retention
- saved GTM sessions, answers and results: generally up to 180 days;
- secure result link: 14 days;
- completed or failed operational email queue records: generally up to 30 days;
- business enquiries and HubSpot CRM records: generally up to 24 months after the last relevant communication;
- newsletter data: until unsubscribe or consent withdrawal;
- cookie choice: 180 days unless the notice version changes sooner;
- support communication: generally up to 24 months after closure;
- security and audit logs: generally up to 12 months;
- contractual, accounting and legal records: for the periods required by law.
12. Your rights
Subject to applicable Serbian law, you may request access, correction, deletion, restriction, objection, data portability where applicable, or withdrawal of consent. You may also lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection.
13. Contact
For privacy questions or rights requests, contact office@projectcodes.rs.