PRIVACY POLICY
Last updated: 24.05.2025
Applies to: web application, mobile application, and all related TUNNEL services
INTRODUCTION
This Privacy Policy explains how TUNNEL TECH DOO (hereinafter 'TUNNEL TECH'), with registered office in Serbia (Crkvena 11, Požega, Company Reg. No.: 22078097), collects, uses, protects, and processes your personal data when using the TUNNEL application and/or website (hereinafter: 'Service').
This Policy applies to all users, regardless of whether they access the service from Serbia, the EU, or other jurisdictions.
TYPES OF DATA WE COLLECT
We may process the following categories of personal data:
- Identification data: Email address, full name, username, address, phone number, password (hashed)
- Technical data: IP address, device type, operating system, browser information
- Usage data: In-application activities, access times, frequency of use
- Billing data: Transaction history, license type, subscription status
- Cookie data: Anonymized identifiers, language settings, analytics
LEGAL BASIS FOR PROCESSING
We process data based on:
- Contract performance: – For service provision following registration.
- Legitimate interests: – Enhancing system functionality and security.
- User consent: – For cookie usage or marketing communications.
- Legal obligations: – Data retention for accounting and tax compliance.
HOW WE USE DATA
We use data for the following purposes:
- Enabling registration and service access
- Managing subscriptions and invoices
- Detecting abuse and security threats
- Sending critical notices (e.g., terms updates)
- Internal analytics and system improvements
- Responding to inquiries and user support
DATA RETENTION AND PROTECTION
We implement the following security measures:
- Data is stored on secure servers within the EU.
- We employ SSL/TLS encryption, firewalls, and anti-DDoS protection.
- Only authorized personnel and external processors (under DPA agreements) access data.
- Data is retained while accounts are active or per legal requirements (e.g., 5 years for accounting purposes).
DATA SHARING
Your data will not be sold or shared with third parties except when:
- Required for payment processing (e.g., Stripe, PayPal)
- Necessary for technical infrastructure (e.g., hosting providers)
- Legally mandated by competent authorities
- Based on your explicit consent
All external partners are contractually bound to GDPR-compliant data protection.
INTERNATIONAL TRANSFERS
TUNNEL TECH uses infrastructure located within the European Union. Should data be transferred outside EU/EEA, we only use countries with adequate data protection levels (Article 45 GDPR) or implement standard contractual clauses (Article 46 GDPR).
USER RIGHTS
All users have the following rights under Articles 15–22 GDPR:
- Right to access data
- Right to rectify inaccurate data
- Right to erasure ('right to be forgotten')
- Right to restrict processing
- Right to data portability
- Right to object
- Right to withdraw consent (where applicable)
Requests may be submitted via email: tunnel-sales@smarty.rs
We will respond within 30 days per GDPR and Serbian Personal Data Protection Law requirements.
COOKIES
We use cookies to enhance functionality, perform analytics, and remember your preferences. For details, see our dedicated Cookie Policy.
You may disable them in your browser, but this may impair application functionality.
AUTOMATED DECISION-MAKING
We do not engage in user profiling or make automated decisions with legal effects.
CHILDREN'S PRIVACY
The Service is not intended for children under 16 without parental/guardian consent. If we discover processing of a child's data without authorization, such data will be immediately deleted.
POLICY UPDATES
TUNNEL TECH reserves the right to modify this Policy. All users will be notified via email or in-app at least 30 days in advance. Updated versions will be available on our website.
CONTACT
TUNNEL TECH DOO
Address: Crkvena 11, 31210 Požega, Srbija
Company Reg. No.: 22078097
Email: tunnel-sales@smarty.rs
For complaints, you may also contact:
Commissioner for Information of Public Importance and Personal Data Protection,
Bulevar kralja Aleksandra 15, 11000 Belgrade
https://www.poverenik.rs
Commissioner for Information of Public Importance and Personal Data Protection,
Bulevar kralja Aleksandra 15, 11000 Belgrade
https://www.poverenik.rs
EU users may contact their local Data Protection Authority (DPA).