Privacy Policy

Effective date: January 14, 2026

This Privacy Policy explains how MILOŠ ŽIVANOVIĆ PR RAČUNARSKO PROGRAMIRANJE OM OM CODE SMEDEREVO (“we”, “us”, “our”) collects, uses, stores, and protects personal data when you access or use redu.cloud. redu.cloud is a public cloud infrastructure service operated by OM OM CODE.

If you have questions or requests related to privacy, contact us at office@redu.cloud.

1. Data Controller

The Data Controller is:

  • Legal name: MILOŠ ŽIVANOVIĆ PR RAČUNARSKO PROGRAMIRANJE OM OM CODE SMEDEREVO
  • Legal form: Sole proprietor
  • Country: Republic of Serbia
  • Registered address: Omladinskih Brigada 5, 11300 Smederevo, Serbia
  • Business registration number (MB): 66875814
  • Tax number (PIB): 113508517
  • Business activity: 6201 – Computer programming
  • Contact: office@redu.cloud

2. Definitions

  • “Personal data” means any information relating to an identified or identifiable individual.
  • “Processing” means any operation performed on personal data (such as collection, storage, use, disclosure, or deletion).
  • “Controller” means the entity that determines the purposes and means of processing personal data (us, as identified above).
  • “Processor” means a third party that processes personal data on behalf of the Controller under instructions.
  • “Account” means your registered platform account used to access services.
  • “Business customer” means a company, organization, or a registered entrepreneur/sole proprietor using the Services in a professional capacity.

3. Scope

This Policy applies to our website, platform, and cloud services, including account registration and authentication, billing and invoicing, customer support, security monitoring, and platform usage.

4. Who This Applies To

B2B / professional use only: redu.cloud is intended for business customers (B2B), such as startups, development teams, companies, and registered entrepreneurs/sole proprietors acting in a professional capacity. We do not target the Services to consumers acting purely in a personal capacity.

Accounts may be created by users in Serbia, the EU, and other countries, subject to applicable law and any sanctions/export control restrictions described in our Terms of Service.

5. Categories of Personal Data We Collect

5.1 Account registration data

Registration and authentication are provided through an identity and access management system. Depending on your configuration and usage, we may process:

  • Username
  • Email address
  • Encrypted password (stored by the identity system)
  • Two-factor authentication (2FA) status and related security metadata
  • Account roles/permissions within your organization (if applicable)

5.2 Third-party sign-in (Google / GitHub)

We may allow you to create an account or sign in using third-party identity providers (for example, Google or GitHub). When you use third-party sign-in, we typically receive basic account information from the provider such as:

  • Your email address
  • Your display name (if provided)
  • A provider-specific user identifier
  • Profile image/avatar (if provided)

We do not receive your password for the third-party account. We use this information only to authenticate you and create/link your redu.cloud account.

5.3 Business profile & invoicing details

Because the Services are offered for business/professional use, we may request or process business profile details for invoicing, accounting, and compliance, such as:

  • Business / legal name (company or registered entrepreneur)
  • Registered address and billing address
  • Country of establishment / operation
  • Tax identifiers (e.g., PIB / VAT where applicable)
  • Company registration number (if applicable)
  • Billing contact name and billing email

5.4 Payments data (when payments are enabled)

When payment processing is enabled, payments are handled by third-party payment service providers. We do not store full card numbers. We may collect or receive billing-related data necessary for invoicing, accounting, fraud prevention, and customer support, such as:

  • Invoice records and payment history
  • Payment status (paid/failed/overdue)
  • Transaction identifiers / payment references
  • Limited card metadata provided by the payment provider (e.g., last 4 digits, expiry month/year) if made available
  • Dispute/chargeback status and related references (if applicable)

5.5 Verification, fraud prevention & compliance data (as needed)

To protect the platform, prevent abuse, and meet legal/compliance obligations (including payment risk controls), we may collect or request additional information in limited cases, such as:

  • Business verification details (e.g., business registration evidence or public registry references)
  • Proof of authority to act for a business (e.g., role/position confirmation)
  • Sanctions/export control screening signals (e.g., country, IP-based risk signals)
  • Security/fraud signals (e.g., device/browser signals, repeated failed payments, suspected card testing patterns)
  • If strictly necessary for high-risk cases: identity verification documents for an authorized representative (we will request only what is necessary, and handle it securely)

5.6 Cloud, technical, and security data

We process technical and security data to operate the platform, calculate usage, and protect the service:

  • IP address and login timestamps
  • Authentication events and audit events
  • API requests and console actions
  • Service usage metadata (compute, storage, network consumption) used to calculate billing totals
  • Security and infrastructure logs used for platform-wide protection (e.g., firewall logs, intrusion detection/prevention signals, reverse proxy logs)

5.7 Support and communications

  • Emails and communications sent to office@redu.cloud
  • Support requests and related correspondence

5.8 Website analytics and cookie data

We may process cookie identifiers, consent status, and website usage data (such as pages visited and basic device/browser information) to operate, secure, and improve our website, subject to your consent settings where required.

6. Purposes of Processing

  • Provide and operate the cloud platform
  • Create and manage user accounts and authentication
  • Secure the platform and prevent abuse or fraud
  • Measure usage and generate billing records
  • Perform invoicing, accounting, and tax compliance where applicable
  • Provide customer support and service notifications
  • Improve platform reliability and performance
  • Send product updates and marketing communications (where permitted)

7. Legal Basis for Processing

Where applicable, we process personal data under one or more of the following legal bases: performance of a contract (providing the service), legitimate interests (security, abuse prevention, platform reliability, fraud prevention), compliance with legal obligations (invoicing/accounting), and consent (for marketing communications and non-essential cookies where required).

7.1 Legal basis by processing activity (summary)

Data / activityMain purposeTypical legal basis
Account registration (username, email)Create and manage your accountContract
Third-party sign-in (Google/GitHub basic profile data)Authenticate and create/link your accountContract
Business profile (company name, billing details)Invoicing, account administrationContract / legal obligation
Authentication & security eventsSecurity, abuse prevention, auditsLegitimate interests
Usage metadata (compute/storage/network)Operate service, calculate usage and billingContract
Invoices and accounting recordsBilling, accounting, tax obligationsLegal obligation
Fraud prevention / risk controlsPrevent abuse, chargebacks, complianceLegitimate interests / legal obligation (where applicable)
Support communicationsRespond to requests, troubleshoot issuesContract / legitimate interests
Marketing emails (if enabled)Product updates, offers, newslettersConsent or legitimate interests (where permitted)
Non-essential cookies / advertisingAnalytics and marketing measurementConsent (where required)

8. Payments

Payments (once enabled) are processed by third-party payment service providers. Payment details are submitted directly to the provider and are not stored on our servers.

We may receive limited billing-related information such as payment status, transaction identifiers, dispute/chargeback references, invoice identifiers, and accounting-related data needed to operate the service and comply with legal obligations.

9. Infrastructure and Data Location

redu.cloud operates on our own private cloud infrastructure located in Smederevo, Serbia.

We maintain backups primarily on our own backup environment in the same location. We also use encrypted external backups to a cloud storage provider primarily for metadata and operational backups (for example, configuration and database backups). Customer virtual machine data is not backed up externally unless explicitly configured by the customer.

10. Cookies and Analytics

We use cookies and similar technologies to operate and secure our website and understand general usage patterns.

Where required by applicable law, we use a consent management platform (Cookiebot) to request and manage user consent for the use of non-essential cookies, including analytics and advertising cookies. You can update your preferences at any time through the cookie consent banner.

We use Google Analytics to better understand how visitors interact with our website. For more information, please review Google’s Privacy Policy and Google Analytics data collection and processing.

We partner with Microsoft Clarity and Microsoft Advertising to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay to improve and market our products/services. For more information, visit Microsoft Privacy Statement.

We may also use advertising pixels in the future where permitted and subject to your cookie consent choices.

10.1 Aggregated and anonymized data

We may create aggregated statistics and, where feasible, anonymized reports about the use of our website and services (for example, overall traffic or usage trends). These reports are used for service improvement, capacity planning, security, and analytics and are not intended to identify you.

11. Data Sharing and Recipients

We share personal data only when necessary to operate the platform, provide support, prevent fraud/abuse, or comply with legal obligations. We do not sell personal data.

11.1 Data processors and service providers

We may use third-party service providers (“processors”) to support our operations (for example: email services, analytics, payment processing, and backup storage). Processors process personal data on our behalf and under our instructions, subject to confidentiality and security obligations.

  • Payment service providers (once enabled), including dispute/chargeback handling
  • Email service providers (for support and transactional communications)
  • Website analytics and consent management providers
  • Backup storage providers (encrypted backups)
  • Accounting or invoicing providers (if used in the future)
  • Security tooling vendors (where applicable) for platform protection

We may also disclose personal data to authorities and regulators when legally required.

11.2 Subprocessors

We use a limited number of trusted third-party service providers (“subprocessors”) to help operate our website and cloud platform. Subprocessors process personal data only on our behalf and under our instructions, subject to confidentiality, security, and data protection obligations.

Our current subprocessors include:

SubprocessorPurposeCategories of dataProcessing location
Google (Gmail)Customer support communicationsEmail address, support messages, attachmentsEEA and/or other countries (including possible U.S.)
Google AnalyticsWebsite analytics and performance measurementCookie identifiers, IP address, device and usage dataEEA and/or other countries (including possible U.S.)
Microsoft ClarityWebsite analytics and session replayCookie identifiers, device and usage dataEEA and/or other countries (including possible U.S.)
CookiebotCookie consent managementConsent status, cookie identifiersEEA
Google Drive (encrypted backups)Encrypted backup storageEncrypted configuration and metadata backupsEEA and/or other countries (including possible U.S.)
Payment service provider (to be selected)Payment processing and invoicingName, email, billing address, invoice data, payment status, transaction identifiers, dispute/chargeback references (if applicable)EEA and/or other countries (depending on provider)

We may update this list from time to time as our services evolve. Any new subprocessors will be required to provide appropriate contractual and technical safeguards for the protection of personal data. Where required for international transfers, we rely on suitable safeguards such as Standard Contractual Clauses or other legally recognized transfer mechanisms.

12. International Transfers

Personal data is primarily processed in Serbia. Where we use third-party service providers, data may be processed in the EEA and/or other jurisdictions. Where required, we use appropriate safeguards (such as contractual protections and Standard Contractual Clauses) to protect personal data that is transferred internationally.

13. Data Retention

We retain personal data only for as long as necessary to provide services, comply with legal obligations, and maintain platform security. Our current retention approach is:

Data typeTypical retention
Account dataWhile the account is active (and for a limited period after deletion requests to complete closure)
Business profile & invoicing dataFor as long as needed to manage the account and comply with accounting/tax obligations
Billing records / invoicesUp to 10 years (legal/accounting obligations)
Security, authentication and audit logsUp to 24 months
Support communicationsUp to 36 months
Disputes / chargebacks (if applicable)Up to 36 months (or longer if required to resolve disputes or comply with legal obligations)
Cookie consent logsAs required to demonstrate consent and compliance

14. Account Deletion and Erasure

You may request account deletion by contacting office@redu.cloud.

Upon deletion, we intend to:

  • Deactivate the account and revoke access credentials
  • Delete or destroy cloud resources associated with the account
  • Erase personal data where legally possible

Certain data may be retained where required or justified, such as invoices (accounting law) and security logs (fraud/security purposes) for the retention periods described above.

15. Security

We implement security measures appropriate for a cloud infrastructure provider, including:

  • TLS encryption for services we operate
  • Firewalling and network security controls
  • Web application protection at HTTP/HTTPS level
  • Intrusion detection and prevention controls
  • Network isolation for tenant environments
  • Access control and 2FA support
  • Encrypted backups for critical platform databases

15.1 Personal data breach response

No system is completely secure. In the event of a personal data breach, we will take reasonable steps to contain and remediate the incident. Where required by applicable law, we will notify relevant authorities and affected individuals.

16. Marketing Communications

We may send registered users marketing emails and product updates. Where required, you can opt out at any time through an unsubscribe link or by contacting office@redu.cloud.

Transactional messages (e.g., password resets, security notices, invoices) are sent as necessary to operate the service.

17. Your Rights

Depending on your location and applicable law, you may have rights to:

  • Access your personal data
  • Correct inaccurate or incomplete data
  • Request deletion (erasure), where applicable
  • Request restriction of processing in certain cases
  • Object to processing based on legitimate interests
  • Data portability (where applicable)
  • Withdraw consent at any time (where processing is based on consent)

17.1 How to submit a request (identity verification)

To exercise your rights, contact office@redu.cloud. To protect your account and personal data, we may ask you to verify your identity before acting on your request (for example, by requesting the request be sent from the email address associated with your account, or by other reasonable verification steps).

We typically respond within 30 days, subject to applicable law and the complexity of the request.

18. Children’s Information

The platform is intended for business/professional users and is not directed to children. We do not knowingly collect personal data from children under the age of 13.

19. Supervisory Authority (Serbia)

If you believe your rights have been violated, you may lodge a complaint with the Serbian supervisory authority:

  • Authority: Commissioner for Information of Public Importance and Personal Data Protection (Poverenik)
  • Address: Bulevar kralja Aleksandra 15, 11000 Belgrade, Serbia
  • Phone: +381 11 3408 900
  • Email: office@poverenik.rs
  • Website: https://www.poverenik.rs

20. Governing Law

This Privacy Policy is governed by the laws of the Republic of Serbia, without prejudice to any mandatory rights you may have under applicable data protection laws.

21. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date.

Related documents