LEGAL

Privacy Policy

Version 2026-09-30-v2 · effective 30/09/2026

Privacy Policy Status: Draft for review — not yet published. 1. Controller The controller responsible for personal data processed through CheckOpp is OLEKSANDR KORETSKIY PR AGENCIJA ZA TEHNIČKI KONSALTING FUTOG, Preduzetnik, Dr. Milana Kostića 4A, 21410 Futog, Republic of Serbia, contact office@koretskiy.rs. This policy is intended to operate consistently with applicable data-protection law, including the Serbian Law on Personal Data Protection and, where applicable, other mandatory data-protection rules. 2. Data we process Depending on how CheckOpp is used, we may process: - email address and authentication identifiers; - account and session information; - project and Case descriptions; - files, links, images, documents and other User Materials; - messages submitted through Case Dialogue; - service selections, work orders, result versions and review history; - expert assignments and operator actions; - technical logs, timestamps, browser/network metadata, security events and abuse-prevention data; - payment and billing records if paid services are enabled; - communications and complaint records. 3. Sensitive and confidential material Users should submit only information reasonably necessary for the requested assessment. Case Materials may contain confidential business or technical information. Users should avoid uploading special-category personal data, government identifiers, medical data or unrelated personal data unless genuinely necessary and lawful to process for the Case. 4. Purposes Personal data may be processed to authenticate users; create and operate Cases; analyze User Materials; conduct research and verification; perform AI-assisted processing; route Cases for authorized human or expert review; communicate with users; maintain audit and version history; prevent fraud and unauthorized access; diagnose failures; handle billing and refunds; respond to complaints and legal requests; and meet legal obligations. 5. Legal bases Depending on the activity and applicable law, processing may be based on performance of a contract or requested pre-contract steps, compliance with legal obligations, legitimate interests such as security and quality control where appropriate, or consent where legally required. 6. Service providers and recipients CheckOpp may use service providers for hosting, authentication, database/storage, email delivery, cloud deployment, AI/model processing, document processing, support and payment processing. Current technical infrastructure may include Supabase for authentication/database/storage and Vercel for web application deployment and privacy-oriented web analytics. AI-assisted processing may involve external model providers, including OpenAI, where necessary for the requested service. Authorized experts may receive access only to Cases assigned or otherwise authorized for review. We do not sell personal data to advertisers. 7. International transfers Service providers and experts may process data in jurisdictions different from the user's location. Where applicable law requires transfer safeguards, CheckOpp will use an appropriate legal mechanism or service-provider arrangement before making the relevant transfer. Current core technical providers include Supabase (authentication, database, storage and Edge Functions; current CheckOpp Supabase project region: EU Central / Frankfurt), Vercel (web hosting, deployment and server/runtime infrastructure), OpenAI (AI/model processing used for requested analytical tasks), and Google Workspace/Gmail (business email and communications). Vercel server/runtime execution may occur outside Serbia and the EEA, including the United States, depending on deployed infrastructure. AI/model and communications providers may also process data in jurisdictions outside Serbia. Where applicable Serbian data-protection law requires safeguards for an international transfer, CheckOpp will rely on the relevant provider contractual safeguards and other lawful transfer mechanisms before or while using that provider. Payment/fiscalization providers will be added to this policy before their production processing is activated. 8. AI processing Case content may be transmitted to AI/model providers where necessary to perform requested analysis. AI outputs may be reviewed, rejected, corrected or supplemented by automated checks or authorized human reviewers. See the AI & Automated Analysis Notice. 9. Browser storage and cookies CheckOpp uses authentication/session storage and limited browser storage required for service operation. CheckOpp also uses Vercel Web Analytics to measure aggregate website usage. This analytics is privacy-oriented and does not use tracking cookies for advertising or behavioural profiling. CheckOpp does not use advertising or behavioural-marketing cookies. See the Cookie & Storage Policy. 10. Retention We retain personal data only for as long as reasonably necessary for service delivery, Case continuity, security, auditability, disputes, accounting and legal obligations. Current retention policy: account/authentication data is retained while the account is active and normally for up to 24 months after the user's last material activity unless earlier deletion is appropriate; Case descriptions, uploaded materials, generated results and provenance/audit material are normally retained for up to 3 years after the Case is closed or last materially active so that results, disputes and version history can be reconstructed; security and operational logs are normally retained for up to 24 months; support and complaint records are normally retained for up to 3 years after resolution; billing, invoice and accounting records are retained for the period required by applicable Serbian tax/accounting law. Data may be retained longer where reasonably necessary for an unresolved dispute, legal claim, security investigation or legal obligation, and may be deleted earlier where no longer necessary and deletion is lawful. 11. Security CheckOpp uses access controls, authenticated service boundaries, audit records and other safeguards designed to protect Case and account data. No internet service can guarantee absolute security. 12. User rights Subject to applicable law, individuals may have rights to request access, correction, deletion, restriction, portability, objection, or information about processing. Requests: office@koretskiy.rs. Identity verification may be required. 13. Supervisory authority Where Serbian data-protection law applies, individuals may have the right to contact the Commissioner for Information of Public Importance and Personal Data Protection. Other competent authorities may apply depending on the user and processing. 14. Children CheckOpp is intended for professional, business, technical and institutional use and is not designed as a service directed to children. Users must be at least 18 years old to create an account or order a service in their own name. A person acting for a company, institution or other organization must be authorized to act for that organization. 15. Changes This policy is versioned. Material changes may require notification or renewed consent where required by law. 16. Contact Privacy contact: office@koretskiy.rs; Dr. Milana Kostića 4A, 21410 Futog, Republic of Serbia.

Published version: 2026-09-30-v2

← All legal documents

Methodology © Oleksandr KoretskiyMethodologyGlossary