This policy explains which personal data EMH collects, why, who handles it on our behalf, how long we keep it and what you can ask of us. It covers visitors to emhagency.com, anyone who contacts us, and the people we deal with at our clients and partners. We process personal data under the Serbian Personal Data Protection Act (Zakon o zaštiti podataka o ličnosti, Official Gazette of RS no. 87/2018 — “ZZPL”) and, for people in the European Economic Area where it applies, the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
Who is responsible
The data controller is EMH, Bulevar oslobođenja 127, 21000 Novi Sad, Serbia. For anything to do with this policy or your data, write to team@emhagency.com.
When you visit the site
The site is a set of static pages served by Cloudflare. To deliver a page and to keep attacks away, Cloudflare processes the technical data every web request carries: your IP address, the address of the page you asked for, the site that referred you, and your browser type and version. We keep no server logs of our own. Cloudflare keeps its request logs for a limited time for security and operations, as described in its privacy policy. Legal basis: our legitimate interest in running a secure, available website (Art. 12(1)(6) ZZPL; Art. 6(1)(f) GDPR).
We count visits with Cloudflare Web Analytics. It records which page was opened, which site referred you, an approximate country worked out from your IP address (which is not stored for this purpose) and how quickly the page loaded, and it reports all of it as aggregate numbers. It sets no cookies, stores nothing on your device, does not fingerprint your browser and does not follow you to other sites, so we cannot identify you from it. Because nothing is written to your device, there is nothing to accept or refuse. Legal basis: our legitimate interest in knowing whether the site works.
When you send the contact form
The form asks for your name, email address, company, an optional phone number, the kind of work you need and a description of the project. Sending it triggers the following, and nothing else:
- A bot check. Cloudflare Turnstile confirms in your browser that a person, not a script, is sending the form. To do so Cloudflare evaluates browser signals and your IP address; it sets no tracking cookie for this and does not follow you across sites. Without the check the form does not send.
- Delivery to our CRM. A small program running on Cloudflare's network verifies the bot check and passes your entries to HubSpot, our customer relationship system, together with the address and title of the page you sent it from and your IP address, from which HubSpot records an approximate location. The program keeps no copy; the site has no database of its own.
- Attribution, only if you allowed cookies. If you chose ‘Allow’ in the cookie banner, the HubSpot identifier stored in your browser travels with the submission, so the enquiry is linked to the pages you visited before sending it and to the site that brought you here. If you did not, the enquiry arrives without any visit history.
- A record in HubSpot. Your entries become a contact record that the EMH team uses to read your enquiry, reply and, if we go on to work together, prepare a proposal. The record is stored in HubSpot's data centre in Frankfurt, Germany.
There is no consent box on the form because none is needed: we process these details to take the steps you ask for before any contract is signed — reading the enquiry, replying and preparing an offer (Art. 12(1)(2) ZZPL; Art. 6(1)(b) GDPR). The bot check rests on our legitimate interest in keeping spam out (Art. 12(1)(6) ZZPL; Art. 6(1)(f) GDPR), and linking the enquiry to your earlier visits happens only with the consent you gave in the cookie banner. We do not use your details for marketing and we do not pass them to anyone else.
When you email us
Email to any @emhagency.com address is handled by Microsoft 365 (Exchange Online), which we buy through GoDaddy as reseller. Microsoft stores the mailboxes in its data centres in the European Union. We keep correspondence for as long as the matter it concerns is open (see How long we keep it). Replies we send from our mailbox may be logged on your HubSpot contact record so that the whole conversation is in one place. Legal basis: the steps you ask for before a contract, the contract itself once there is one, or our legitimate interest in answering and keeping a record of business correspondence.
When we work together
If your company becomes a client or a partner, we process the business details of the people we deal with: name, role, work email and phone number, the contents of the contract, invoices and payment records, and the messages and files exchanged during the project. We use them to deliver the work, to invoice and to meet accounting and tax obligations, and where needed to establish or defend legal claims. Legal bases: performance of the contract (Art. 12(1)(2) ZZPL; Art. 6(1)(b) GDPR), our legal obligations (Art. 12(1)(3) ZZPL; Art. 6(1)(c) GDPR) and our legitimate interest in managing the relationship (Art. 12(1)(6) ZZPL; Art. 6(1)(f) GDPR). If a client asks us to build or maintain a system that holds personal data of their own users, we act as a processor for that data under a written agreement with the client, and this policy does not cover it.
How our HubSpot account is set up
HubSpot is where enquiries and client contacts live. So that you know exactly what it does and does not do on this site:
- Enquiries arrive through HubSpot's Forms API from our own contact form after server-side checks. We do not embed a HubSpot form. Our contact form is excluded from HubSpot's automatic form collection, so its contents are sent only through our enquiry API.
- The HubSpot tracking script loads only after you choose “Allow” in the banner. Before permission, no HubSpot tracking code runs and no HubSpot tracking cookies are set. We use our own cookie banner.
- The account is hosted in HubSpot's European Union data centre (Frankfurt, Germany). HubSpot, Inc. (United States) and its affiliates may access it for support and operations under HubSpot's data processing agreement, which includes the EU standard contractual clauses; HubSpot is also certified under the EU–US Data Privacy Framework.
- We send no newsletters or marketing email, and we run no lead scoring, automated profiling or advertising integrations. HubSpot's intent data access is disabled. A contact record holds what you gave us, the pages behind the enquiry if you allowed cookies, and our correspondence with you.
- A contact who asks to be deleted is deleted from HubSpot, not merely unsubscribed.
Cookies and local storage
We store two preferences in your browser’s localStorage — your language (emh-lang) and your cookie choice (emh-consent). Neither value is sent to our servers. If you choose “Allow”, HubSpot’s script sets four tracking cookies on emhagency.com:
- hubspotutk — identifies your browser to HubSpot and is sent with the contact form so the enquiry can be matched to the visit. Kept for 6 months.
- __hstc — the visit history: first visit, previous visit, current visit and number of sessions. Kept for 6 months.
- __hssc — the current session and the number of pages viewed in it. Kept for 30 minutes.
- __hssrc — whether this is a new session. Deleted when you close the browser.
These cookies are linked to a person only if they later send the contact form. Choosing “Only necessary” keeps the HubSpot tracking script from loading. Global Privacy Control overrides a previous permission. You can change your choice using “Cookie settings” in the footer. Withdrawing permission stops an already loaded tracker and removes its four tracking cookies. A preference cookie (__hs_do_not_track, up to six months) may remain to prevent further tracking; allowing tracking again removes it. The bot check on the contact form (Cloudflare Turnstile) runs only on that page, sets no tracking cookie and does not follow you elsewhere. Legal basis for the HubSpot cookies: your consent (Art. 12(1)(1) ZZPL; Art. 6(1)(a) GDPR), which you may withdraw at any time without affecting what was done before.
Who we share it with
We do not sell personal data and we do not share it for anyone else's marketing. It is handled by these providers, each acting on our instructions under a written data processing agreement:
- Cloudflare, Inc. (San Francisco, USA) — hosting and delivery of the site, the Web Analytics count, the Turnstile bot check and the program that forwards the contact form. Cloudflare's network is global, so a request is served by the data centre nearest to you.
- HubSpot, Inc. (Cambridge, USA), through HubSpot's Frankfurt data centre — the CRM where enquiries and client contacts are stored.
- Microsoft Corporation (Redmond, USA), with mailboxes in EU data centres — email and calendar. GoDaddy, as reseller of our Microsoft 365 subscription, handles its billing and support.
- Our external accountant — invoices and the records the law requires us to keep.
We disclose personal data to public authorities only where a law obliges us to, and to legal advisers or courts where needed to establish, exercise or defend a claim.
Transfers outside Serbia. Cloudflare, HubSpot and Microsoft are headquartered in the United States. Transfers to them rest on the standard contractual clauses built into each provider's data processing agreement (appropriate safeguards under Art. 65 ZZPL and Art. 46 GDPR) and, for HubSpot and Microsoft, on their certification under the EU–US Data Privacy Framework. The data that HubSpot and Microsoft store in the European Union is also covered by the rule that personal data may flow without special authorisation to states party to the Council of Europe's Convention 108, which include every EU member state (Art. 64 ZZPL).
How long we keep it
We keep personal data only as long as its purpose needs it, and then delete it:
- Enquiries that do not lead to a project — deleted from HubSpot and from our mailbox 24 months after our last exchange.
- Client and partner records — for the duration of the relationship, then for as long as the law requires: documents that support accounting entries, including contracts and invoices, for 5 years and business books for 10 years after the end of the financial year they relate to (Serbian Accounting Act), and correspondence needed to establish or defend a claim until the limitation period has run out.
- HubSpot cookies — 6 months (hubspotutk, __hstc), 30 minutes (__hssc) or the end of the browser session (__hssrc). The visit history they produce stays on a contact record for as long as the record exists.
- Cloudflare request logs — a limited period set by Cloudflare's privacy policy; we have no per-visitor access to them. Web Analytics keeps only aggregate counts.
- Your language choice and cookie decision in local storage — until you clear your browser data.
How we protect it
The site is served only over HTTPS with security headers set, and your entries travel encrypted to Cloudflare, HubSpot and Microsoft. The site has no database and no server of ours that stores your data, so there is nothing of yours on our infrastructure to leak. HubSpot and Microsoft operate under independently audited security programmes (ISO 27001 and SOC 2). Access to our CRM and mailboxes is limited to the EMH team members who need it, each with their own account. If a breach ever affected your data, we would notify the Commissioner within 72 hours and inform you where the law requires it.
Your rights
Under the ZZPL, and under the GDPR where it applies, you can ask us to:
- tell you whether we process your data and give you a copy of it (access, Art. 26 ZZPL / Art. 15 GDPR);
- correct or complete inaccurate data (Art. 29 ZZPL / Art. 16 GDPR);
- delete it, for instance once the enquiry is closed (Art. 30 ZZPL / Art. 17 GDPR);
- restrict the processing while a dispute about it is settled (Art. 31 ZZPL / Art. 18 GDPR);
- hand the data you gave us to you or to another provider in a machine-readable form (portability, Art. 36 ZZPL / Art. 20 GDPR);
- stop processing that rests on our legitimate interest (objection, Art. 37 ZZPL / Art. 21 GDPR);
- withdraw consent for cookies at any time, under ‘Cookie settings’ in the footer (Art. 15 ZZPL / Art. 7 GDPR).
Write to team@emhagency.com with enough detail for us to find your data. We answer without undue delay and at the latest within 30 days; for complex or numerous requests the law lets us extend that by a further 60 days, and we tell you if we need to. Requests are free of charge unless they are manifestly unfounded or repetitive. We make no decisions about you by automated means alone.
If you think we have processed your data unlawfully, you can complain to the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti), Bulevar kralja Aleksandra 15, 11120 Belgrade, Serbia, www.poverenik.rs (Art. 82 ZZPL), or seek protection before a court (Art. 84 ZZPL). If you are in the EEA, you can also complain to your local supervisory authority. We would welcome the opportunity to resolve any concern directly first.
Other information
The site and our services are meant for businesses, and we do not knowingly collect data about children. We do not use your data for automated decisions with legal or similarly significant effects.
Changes to this policy
When this policy changes we update the date at the top. If a change affects your rights materially — a new provider, a new purpose, a longer retention period — we say so on the site before it takes effect.