Legal
Privacy Policy
Last updated: 7 October 2026
This policy explains what personal data IMPRSHR collects through imprshr.com, why we collect it, and the choices you have. We collect as little as we need to answer you and to run the site well.
Who is responsible
The data controller is IMPRSHR, Belgrade, Serbia. For any privacy question or request, write to hello@imprshr.com or call +381 63 692 729.
We process personal data in line with the Serbian Law on Personal Data Protection and, for visitors in the European Union, the General Data Protection Regulation (GDPR).
What we collect and why
- Contact and consultation forms. Your name, email, phone number (optional) and message, so we can reply and prepare a proposal. With the form we also record the page you sent it from, your device and browser type, and an approximate country and city derived from your IP address, so we can route your enquiry to the right person. Legal basis: steps you ask us to take before a contract, and our legitimate interest in answering enquiries.
- Website assistant (chat). The questions you type are sent to an AI service provider to generate answers. If you choose to leave your name, email, phone or company in the chat, we store them so a strategist can follow up. Please do not share sensitive personal information in the chat.
- Client portal. If you register, we store your name, username, email address, a securely hashed password, and the time and IP address of your last login, to give you access and protect the account.
- Analytics. With your consent only, we use Google Analytics to understand how visitors use the site (pages viewed, approximate location, device type). If you decline, analytics cookies are not set.
- Preferences stored in your browser. Your cookie choice and your light or dark theme are saved in your browser's local storage. They never leave your device.
- Server logs and security. Our hosting provider records technical data such as IP address and time of request to keep the site secure and to prevent abuse, for example by limiting repeated form submissions.
Cookies
When you first visit, we ask whether you accept analytics cookies. Until you accept, Google Analytics runs in a restricted mode without analytics or advertising cookies. You can change your choice at any time by clearing this site's data in your browser; the banner will then appear again.
Who we share data with
We do not sell personal data. We share it only with service providers that help us run the site, and only as much as each one needs:
- our web hosting and email provider (stores the site, form messages and the client portal database);
- Google (Google Analytics, with consent; Google Fonts, which delivers the site's typefaces);
- an AI model provider that generates the website assistant's answers;
- ipapi.co, which turns an IP address into an approximate country for the phone field and form routing;
- Cloudflare cdnjs, which delivers some of the site's scripts.
Some of these providers process data outside Serbia and the EU. Where that happens, we rely on the safeguards the law requires, such as the European Commission's standard contractual clauses.
How long we keep data
We keep enquiries and chat leads for as long as we need them to respond and to manage any resulting work, and then delete them unless the law requires us to keep them longer. Client portal accounts are kept until you ask us to close them. Analytics data is kept according to the retention setting in Google Analytics.
Your rights
You can ask us to show you the personal data we hold about you, correct it, delete it, restrict or object to its use, or send it to you in a portable format. Where we rely on your consent, you can withdraw it at any time. Write to hello@imprshr.com and we will reply within 30 days.
If you believe we have handled your data unlawfully, you can complain to the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia (poverenik.rs) or, in the EU, to your local data protection authority.
Security
The site is served only over encrypted HTTPS. Portal passwords are stored as one-way hashes, forms are protected against automated abuse, and access to our systems is limited to the people who need it.
Changes
We may update this policy when our services or the law change. The date at the top shows the latest version.