Privacy Policy

Last updated: 22 July 2026

This Privacy Policy explains how [LEGAL ENTITY NAME] d.o.o. ("Bandeha", "we", "us" or "our") collects, uses, discloses and protects personal data when you use the Bandeha platform at https://bandeha.com and its related services (the "Service"). We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Serbian Law on Personal Data Protection ("Zakon o zaštiti podataka o ličnosti", "ZZPL"). Please read it together with our Terms of Service and Cookie Policy.

1. Who is the data controller

The data controller (rukovalac) responsible for your personal data is:

  • [LEGAL ENTITY NAME] d.o.o.
  • Registered seat: [Street and number], [Postal code] [City], Republic of Serbia
  • Registration number (matični broj): [MATIČNI BROJ]
  • Tax ID (PIB): [PIB]
  • Data-protection contact: [email protected]
  • General contact: [email protected]

For any question about this Policy or about how we handle your data, or to exercise any of your rights, contact us at [email protected].

2. What personal data we collect

a) Data you provide when you register and use the Service

  • Account data — email address and a password (which we never store in plain text; it is kept only as a salted cryptographic hash).
  • Player profile — first name, last name, username, and optionally your date of birth, gender, short bio, profile photo (avatar), and your country and city.
  • Club profile (for club accounts) — club name, and optionally description, logo, postal address, phone number, contact email, website and number of courts.
  • Content you create — teams you create or join, match records and set scores you submit or confirm, and news posts (for clubs and administrators).

b) Data generated automatically when you use the Service

  • Authentication & session data — sign-in tokens stored in secure, httpOnly cookies, session records used to keep you signed in and to let you sign out, and the date and time of your last sign-in.
  • Security & audit logs — for certain administrative or security-relevant actions we record the action taken and the IP address from which it was made, to protect the Service and detect abuse.
  • Technical data — standard information your browser or device sends when making requests to our servers (such as IP address and request metadata) which is processed transiently to deliver and secure the Service.

We do not intentionally collect special categories of personal data (such as health, religion, political opinions, or biometric data). Please do not include such information in free-text fields (e.g. your bio, club description or news content).

3. Why we use your data and our legal bases

We only process your personal data where we have a lawful basis under Art. 6(1) GDPR (and the corresponding provisions of the ZZPL). The table below sets out each purpose and its legal basis.

PurposeLegal basis
Create and administer your account; provide the core features (teams, matches, results confirmation, club listings, news)Performance of a contract (Art. 6(1)(b))
Send transactional emails you need to use the Service (email verification, password reset, and account/match notifications)Performance of a contract (Art. 6(1)(b))
Display your public profile information (e.g. username, name, city, avatar, and your teams and match history) to other users of the ServicePerformance of a contract (Art. 6(1)(b)) and our legitimate interest in operating a community platform (Art. 6(1)(f))
Verify club accounts and keep the club directory accurateLegitimate interest (Art. 6(1)(f)) in trust and safety
Keep the Service secure, prevent fraud and abuse, and maintain audit logsLegitimate interest (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c))
Optional profile details you choose to add (date of birth, gender, bio, photo)Your consent (Art. 6(1)(a)), which you can withdraw at any time by editing or removing them
Comply with legal obligations and respond to lawful requestsLegal obligation (Art. 6(1)(c))

Where processing relies on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Where processing relies on our legitimate interests, you have the right to object (see Section 8).

4. Cookies

We use strictly necessary cookies to keep you signed in and to protect your account. We do not currently use advertising cookies. For details, see our Cookie Policy.

5. Who we share your data with

We do not sell your personal data. We share it only as described below:

  • Other users of the Service — your public profile and activity (for example your username, name, avatar, city, teams, and confirmed match results) are visible to other players and clubs, because that is the purpose of the platform. Your email address and password are never shown to other users.
  • Service providers (processors) acting on our instructions under a data-processing agreement, including: Brevo (Sendinblue SAS) for sending transactional emails; Cloudflare, Inc. (R2 object storage) for hosting club logos and news images; and our hosting provider for running the servers and database.
  • Authorities and advisers — where required by law, court order, or to establish, exercise or defend legal claims, or to protect the rights, safety and property of Bandeha, our users or the public.
  • Successors — in connection with a merger, acquisition, or sale of assets, subject to this Policy.

6. International data transfers

Some of our service providers may process data outside the Republic of Serbia and/or the European Economic Area (for example, email delivery and image hosting infrastructure). Where personal data is transferred internationally, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses and, for transfers from Serbia, the mechanisms permitted under the ZZPL and decisions of the Serbian supervisory authority. You may request a copy of the relevant safeguards by contacting us.

7. How long we keep your data

  • Account and profile data — for as long as your account is active. If you delete your account (or ask us to), we delete or irreversibly anonymise your personal data within a reasonable period, except where we must keep certain data longer to comply with legal obligations or to resolve disputes.
  • Match and team records — confirmed match results may be retained in an anonymised or pseudonymised form as part of the historical record of the community, even after an account is deleted, so that other participants’ records remain accurate.
  • Security and audit logs — kept for a limited period necessary for security and legal purposes.
  • Verification, password-reset and session tokens — kept only until they expire or are used.

8. Your rights

Under the GDPR and the ZZPL you have the following rights regarding your personal data:

  • Access — obtain confirmation of whether we process your data and a copy of it.
  • Rectification — have inaccurate or incomplete data corrected (you can edit most profile data directly in your account).
  • Erasure ("right to be forgotten") — have your data deleted where the legal conditions are met.
  • Restriction — ask us to limit processing in certain circumstances.
  • Data portability — receive the data you provided in a structured, commonly used, machine-readable format.
  • Objection — object to processing based on our legitimate interests.
  • Withdraw consent — where processing is based on consent, withdraw it at any time.
  • Not be subject to solely automated decision-making — we do not make decisions producing legal or similarly significant effects about you based solely on automated processing.

To exercise any of these rights, email us at [email protected]. We will respond within the time limits set by law (as a rule, within 30 days). Exercising your rights is free of charge, unless requests are manifestly unfounded or excessive.

You also have the right to lodge a complaint with the supervisory authority. In Serbia this is the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti), https://www.poverenik.rs. If you are in the EU/EEA, you may also complain to your local data protection authority.

9. How we protect your data

We apply appropriate technical and organisational measures to protect personal data, including encryption of traffic in transit (HTTPS), hashing of passwords, httpOnly cookies for authentication tokens, access controls, and revocable sessions. No method of transmission or storage is completely secure, but we work to protect your data and to respond promptly to any incident, including notifying you and the supervisory authority where required by law.

10. Children

The Service is not directed to children under 15. In line with the ZZPL, 15 is the minimum age at which a child may consent to information-society services in Serbia; younger children may not create an account. If you are between 15 and 18, you should review this Policy with a parent or guardian. If we learn that we have collected personal data from a child below the applicable age without the required consent, we will delete it.

11. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the "last updated" date and, where appropriate, notify you through the Service or by email. Your continued use of the Service after the changes take effect means you have read the updated Policy.

12. Contact us

Questions, requests or complaints about your privacy: [email protected], or by post to [LEGAL ENTITY NAME] d.o.o., [Street and number], [Postal code] [City], Republic of Serbia.