This Privacy Policy explains how RapidApps (rapidapps.rs) collects, uses, stores, and protects your personal data when you visit our website at https://rapidapps.rs (the “Website”) or otherwise interact with us.
We process personal data in accordance with the Serbian Law on Personal Data Protection (“Zakon o zaštiti podataka o ličnosti”, Official Gazette of the Republic of Serbia No. 87/2018), which is aligned with the General Data Protection Regulation (EU) 2016/679 (“GDPR”). If you are located in the European Union or the European Economic Area, the GDPR also directly applies to our processing of your personal data.
1. Data Controller
The controller of your personal data is:
RapidApps rapidapps.rs Vizantijski bulevar 16, 18000 Niš, Republic of Serbia
Email: privacy@rapidapps.rs Data protection contact: privacy@rapidapps.rs · +381 64 2777912
For all privacy-related questions, requests, or complaints, please contact us using the details above.
2. Personal Data We Collect
We collect the following categories of personal data:
a) Information you provide directly:
- Contact form submissions: name, email address, phone number (if provided), company name, subject, and the content of your message
- Project intake and workshop forms: information about you and your project that you enter yourself (company name, contact details, description of needs and goals)
- Call scheduling: when you book a call, you provide your name, email, and chosen time slot
- Lead magnet / newsletter sign-up (when active): name, email address, and stated interest
b) Information collected automatically when you visit the Website:
- IP address, browser type and version, operating system
- Device type, screen resolution, referring URL
- Pages visited, time spent, clicks, and other usage data
- Cookie data (see Section 10)
c) Information from third-party services:
- If you interact with our social media content (e.g. LinkedIn), those platforms may share aggregated analytics with us in accordance with their own policies
We do not knowingly collect special categories of personal data (e.g., health, religion, political opinions) through our forms. If such information appears in documents you voluntarily upload, it is processed solely in the context of your request.
3. Legal Basis for Processing
We process your personal data on the following legal bases under the GDPR and applicable national law:
| Purpose | Legal basis |
|---|---|
| Responding to your inquiries (contact form) | Your consent and the steps taken prior to entering into a contract |
| Preparing a quote and delivering/maintaining the agreed solution | Contract (steps prior to entering into and performing a contract with you) |
| Sending you marketing or service-related communications | Your consent, which you may withdraw at any time |
| Improving our Website, services, and security | Our legitimate interests in operating and developing our service |
| Complying with legal obligations (tax, records retention) | Legal obligation |
You may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
4. How We Use Your Personal Data
We use your personal data to:
- Respond to your inquiries and provide information about RapidApps services
- Prepare a quote, build, and maintain the agreed website, CRM, or application solution
- Administer your relationship with us (communication, project management, support)
- Send service-related communications (updates, deadlines, changes)
- Send marketing communications, including newsletters and event invitations, only where you have given consent
- Provide and improve our Website, content, and services
- Ensure the security of our Website and prevent fraud or abuse
- Comply with applicable legal and regulatory obligations
As a web, CRM, and application development studio, we use the information from your inquiries and intake forms to assess your needs, prepare a proposal, and — if we enter into a collaboration — deliver and maintain the agreed solution.
We do not use automated decision-making (including profiling) that produces legal effects concerning you or similarly significantly affects you.
5. Sharing Your Personal Data
We share your personal data only with the following categories of recipients, and only to the extent necessary for the purposes set out above:
Our team: Authorized personnel process your inquiries and requests on a need-to-know basis.
Service providers (data processors): We use the following third parties to operate our Website and services. We have data processing agreements in place where required:
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Website hosting, content delivery, security | EU + global edge network |
| Resend, Inc. | Email delivery from forms | United States (Standard Contractual Clauses) |
| Sanity, Inc. | Editorial content management (no personal data of users) | EU + United States |
| Calendly, LLC | Call scheduling | United States (Standard Contractual Clauses) |
| Google LLC (Google Analytics 4) | Website analytics | United States (SCC + IP anonymization) |
| Meta Platforms, Inc. (Meta Pixel) | Conversion measurement and marketing | United States (Standard Contractual Clauses) |
Public authorities: Where required by law, including tax compliance, regulatory reporting, or response to lawful requests by competent authorities.
We do not sell your personal data, and we do not share it for the marketing purposes of third parties.
6. International Data Transfers
Some of our service providers process personal data outside the Republic of Serbia and the European Economic Area, including in the United States. Where this occurs, we ensure adequate safeguards through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Service providers participating in the EU-U.S. Data Privacy Framework
- Technical measures including encryption in transit and at rest
You may request a copy of the safeguards we apply by contacting us at privacy@rapidapps.rs.
7. Data Retention
We retain your personal data only as long as necessary for the purposes for which it was collected:
| Data category | Retention period |
|---|---|
| Contact form submissions (general inquiry) | 12 months from submission, or until you request deletion |
| Project intake and workshop form submissions | 24 months from submission, or until you request deletion |
| Scheduled calls (Calendly) | Duration of the engagement + 12 months |
| Marketing consent records | Until you withdraw consent + 12 months |
| Website analytics (Google Analytics 4) | 14 months (default GA4 retention) |
| Server logs and security records | 90 days |
After the retention period, your personal data is securely deleted or fully anonymized.
8. Your Rights
You have the following rights under the Serbian Law on Personal Data Protection (Official Gazette No. 87/2018) and the GDPR:
- Right of access — Obtain confirmation that we process your personal data and receive a copy
- Right to rectification — Correct inaccurate or incomplete personal data
- Right to erasure (“right to be forgotten”) — Have your personal data deleted under certain conditions
- Right to restriction of processing — Limit how we process your personal data under certain conditions
- Right to data portability — Receive your personal data in a structured, machine-readable format and transmit it to another controller
- Right to object — Object to processing based on legitimate interests, and to direct marketing at any time
- Right to withdraw consent — Withdraw consent at any time, without affecting prior lawful processing
- Right not to be subject to automated decision-making — We do not make decisions affecting you solely by automated means
To exercise any of these rights, contact us at privacy@rapidapps.rs. We will respond within one month, with a possible extension of two further months for complex requests. Identity verification may be required to protect your data.
You also have the right to lodge a complaint with the supervisory authority — see Section 13.
9. Data Security
We implement technical and organizational measures to protect your personal data, including:
- Encryption in transit (HTTPS/TLS for all Website traffic)
- Encryption at rest for stored personal data
- Access controls — access to personal data is restricted to authorized team members with named accounts and multi-factor authentication
- Form protection — anti-bot verification, rate limiting, and server-side input validation
- Regular security review — periodic audits of our infrastructure, dependencies, and access logs
- Incident response — in the event of a personal data breach, we will notify the supervisory authority within 72 hours and affected individuals where required
No method of transmission or storage is 100% secure, but we apply industry-standard practices to safeguard your data.
10. Cookies and Similar Technologies
Our Website uses cookies and similar technologies for the following purposes:
| Category | Purpose | Consent required? |
|---|---|---|
| Strictly necessary | Site functionality, security (bot protection, session cookies) | No (essential) |
| Analytics | Understand how visitors use our Website (Google Analytics 4 with IP anonymization) | Yes (your consent via cookie banner) |
| Marketing | Conversion measurement and advertising (Meta Pixel) | Yes |
| Functional | Remember your preferences (e.g., locale, accepted cookie notice) | Yes |
On your first visit, you will see a cookie consent banner allowing you to accept, reject, or customize non-essential cookies. You may change your preferences at any time by clicking “Cookie settings” in the Website footer.
You can also manage cookies through your browser settings. Note that disabling strictly necessary cookies may affect Website functionality. See our Cookie Policy for full details.
11. Children’s Data
Our services and Website are intended for business users and adults; we do not knowingly collect personal data from anyone under 18. If you believe we have collected personal data of a minor, please contact us at privacy@rapidapps.rs so we can take appropriate action.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The “Last updated” date at the top reflects the most recent version. Significant changes will be communicated through a prominent notice on our Website or, where appropriate, by email.
We encourage you to review this Privacy Policy periodically.
13. Supervisory Authority
If you believe that our processing of your personal data violates applicable law, you have the right to lodge a complaint with the supervisory authority:
Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti) Bulevar kralja Aleksandra 15, 11000 Belgrade, Republic of Serbia Web: https://www.poverenik.rs Email: office@poverenik.rs
For EU residents: You may also lodge a complaint with the supervisory authority in the EU/EEA Member State of your habitual residence, place of work, or place of the alleged infringement.
14. Contact Us
For any questions, requests, or concerns about this Privacy Policy or our processing of your personal data, please contact:
RapidApps rapidapps.rs Vizantijski bulevar 16, 18000 Niš, Republic of Serbia Email: privacy@rapidapps.rs · Phone: +381 64 2777912
We aim to respond to all privacy inquiries within one month.
This Privacy Policy is published in English. A translation may be made available for reference; in case of discrepancy between language versions, the English version prevails for international users, and the local-language (Serbian) version prevails for residents of the Republic of Serbia to the extent required by local law.