Last updated: 18 August 2026
Version: 2.0
1. Data Controller
- COR NET d.o.o.
- Kneza Višeslava 14, 88 000 Mostar, Bosnia and Herzegovina
- Phone: +387 36 833 468
- E-mail: info@cor-net.net
- Registration number: 58-01-0103-14
- ID number: 4227838740005
2. EU Representative (Article 27 GDPR)
- Softly d.o.o.
- Trondheimska 4D, 21000 Split, Republic of Croatia
- E-mail: compliance@softlyst.eu
The Representative acts as a contact point for questions concerning the processing of personal data of data subjects in the European Union and for communications with competent supervisory authorities on behalf of COR NET d.o.o.
3. Scope and legal framework
This Privacy Policy applies to the publicly accessible website cor-net.net. It explains what personal data we process, for which purposes, on what legal basis, for how long, and what rights you have.
Merely using the website does not constitute consent to the processing of personal data. Where consent is required, we obtain it separately and through an explicit action, for example through cookie settings or a separate checkbox on a form.
Processing is carried out in accordance with the Personal Data Protection Act of Bosnia and Herzegovina (“Official Gazette of BiH”, No. 12/25), applicable from 4 October 2025, and, where applicable, Regulation (EU) 2016/679 (GDPR) and other applicable laws.
4. Personal data we process and why
4.1. Technical data and server logs
Whenever you access the website, our systems may automatically record technical data necessary to deliver content, maintain security and diagnose issues. This may include:
- IP address of the device;
- date and time of access;
- URL of the page or file requested;
- HTTP status code;
- amount of data transferred;
- browser, device and operating-system information;
- referring page, where available.
Purpose: technical operation, security, detection of misuse and attacks, diagnostics and performance improvement. Legal basis: COR NET d.o.o.’s legitimate interests (Article 8(1)(f) of the BiH Act and, where applicable, Article 6(1)(f) GDPR).
Retention: server and security logs are retained for no longer than 12 months and then deleted or anonymised, unless needed for the investigation of a security incident or the establishment, exercise or defence of legal claims.
4.2. Cookies, Google Analytics and privacy settings
The website uses essential cookies for basic operation, security and remembering certain settings. Optional analytics or marketing cookies may be activated only after your consent through our cookie-management tool.
We may use Google Analytics, implemented through Google tools for WordPress (Google Site Kit), to measure website usage. When analytics is enabled with your consent, data may include pages visited, visit duration, traffic source, approximate location derived from an IP address, browser/device information and usage events. We use this information for statistics and to improve our content and services.
Essential cookies and local storage may also be used to remember your language selection and cookie-consent choices. A detailed and current list of cookies, their purposes and durations is available in our Cookie Policy.
Legal basis: consent for optional analytics/marketing technologies; legitimate interests or necessity to provide a requested service for strictly necessary technologies, depending on the processing activity.
4.3. Contact, demo and business enquiries
If you contact us through a contact form, demo/quote form or by e-mail, we may process your first and last name, company name, e-mail address, phone number, message content, selected topic/service and technical metadata required to deliver and protect the form.
Purpose: responding to your enquiry, preparing a quote or demonstration, providing support, establishing or developing a business relationship and maintaining a record of business communications. Legal basis: our legitimate interest in business communications and, where the enquiry concerns a potential contract, taking steps at your request prior to entering into a contract.
Fields marked as mandatory are required so that we can process your request. Other information is voluntary.
Retention: if no business relationship is established, enquiry data is normally deleted within 30 days after the communication ends, unless longer retention is required for legal claims or another legal obligation. If a business relationship is established, relevant communications become business records and are retained in accordance with applicable accounting, tax and other requirements.
4.4. Newsletter and marketing communications
If you voluntarily subscribe to a newsletter or expressly request marketing communications, we process your e-mail address and, where applicable, your name and technical data relating to delivery and interactions with messages (for example opens and clicks, if such measurement is enabled).
Legal basis: your consent. Newsletter consent is separate from accepting this Privacy Policy or Terms and Conditions and must not be pre-selected. You may withdraw consent at any time through an unsubscribe link or by contacting info@cor-net.net.
Retention: until consent is withdrawn, subject to limited retention of data needed to demonstrate the lawfulness of communications previously sent.
4.5. WhatsApp and social networks
A WhatsApp contact widget is available on the website. If you choose to contact us through WhatsApp, your phone number, profile information made available through WhatsApp, message content and related technical data may also be processed through WhatsApp/Meta Platforms Ireland Ltd. The provider’s own privacy terms also apply to that processing.
The website may also contain links to Facebook, Instagram and LinkedIn. Clicking such a link takes you to the relevant third-party platform. If marketing pixels or similar social-media technologies are activated on the website in the future, they will only be used where an appropriate legal basis exists and, where required, after your consent.
4.6. Job applications and the COR NET Internship
If you apply for an open position, submit an unsolicited application or apply for the COR NET Internship, we may process your name, e-mail address, phone number, CV, education, work experience, skills and interests, cover letter, references and previous employer/project-manager contact details, message content and notes or assessments created during the selection process.
Purpose and legal basis: evaluating candidates and communicating during recruitment (steps prior to entering into a contract), complying with legal obligations and our legitimate interest in documenting the selection process and protecting legal interests. Where consent is required to keep an unsuccessful candidate in a separate talent pool after the selection process, we will request that consent.
Providing information marked as mandatory is necessary for us to consider your application. Other information is voluntary.
Retention: candidate data is kept for no longer than 2 years after the selection process ends, unless a shorter period applies, consent for a talent pool is withdrawn, or another legal basis requires retention. If a candidate becomes an employee, relevant data becomes part of employee records and is retained under labour law and internal rules.
4.7. Video surveillance at our premises
COR NET d.o.o. premises may be covered by video surveillance to protect persons and property, ensure visitor safety and prevent or document unlawful acts. Visitors are informed by visible notices before entering monitored areas.
Legal basis: the controller’s legitimate interests. Access to recordings is restricted to authorised persons, and recordings may be disclosed to competent authorities or used for the establishment, exercise or defence of legal claims where a lawful basis exists.
Retention: no longer than 30 days, unless a recording is required for an official investigation, proceeding or legal claim, in which case the relevant recording may be retained until that purpose is completed.
5. Recipients and international transfers
We disclose personal data only where necessary for the purposes described above. Categories of recipients may include hosting and IT infrastructure providers, e-mail and newsletter providers, analytics providers, external IT/marketing consultants, accounting and legal advisers, and competent public authorities where required by law.
Known external providers may include Google Ireland Ltd. (analytics, when enabled), Meta Platforms Ireland Ltd. (WhatsApp and related social services) and Softly d.o.o., Croatia as our EU Representative. Other contracted processors may be identified in the Cookie Policy or relevant service documentation.
Where personal data is transferred outside Bosnia and Herzegovina, we use the transfer mechanisms and safeguards required by applicable law, including appropriate contractual safeguards where necessary.
6. Other rights and information
Data subject rights
- right of access – to obtain confirmation whether we process your personal data and, where applicable, a copy of the data and information about the processing;
- right to rectification of inaccurate data and completion of incomplete data;
- right to erasure where the statutory conditions are met;
- right to restriction of processing in the cases provided by law;
- right to object to processing based on legitimate interests;
- right to data portability where processing is based on consent or a contract and is carried out by automated means;
- right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
- right to lodge a complaint with a supervisory authority. If you are located in the European Union, you may also lodge a complaint with the supervisory authority of the Member State of your habitual residence, place of work or place of the alleged infringement.
You may submit a request to info@cor-net.net or by post to our registered office. To protect your data, we may request additional information reasonably necessary to verify your identity. Exercising your rights is generally free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, we may charge a reasonable fee or refuse to act, as permitted by law.
We will respond without undue delay and no later than 30 days after receiving your request. This period may be extended by up to two additional months where necessary because of the complexity or number of requests; if so, we will inform you of the extension and the reasons within the initial period.
Automated decision-making and profiling
We do not use the public website for solely automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you. If such processing is introduced, this Policy will be updated before it is used.
Withdrawal of consent
Where processing is based on consent, you may withdraw that consent at any time, for example through cookie settings, an unsubscribe link in a newsletter, or by emailing info@cor-net.net. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Further cookie information is available in our Cookie Policy.
Children
Our websites and services are primarily intended for business users and persons aged 18 or over. We do not knowingly collect children’s personal data through the public website. If you believe that a child has provided personal data without an appropriate legal basis, please contact us so that we can take appropriate action.
Data security
We apply appropriate technical and organisational measures proportionate to the risk, including:
- restricted physical and logical access to systems and data;
- access control through user accounts, passwords and roles;
- firewalls, antivirus and other security tools;
- SSL/TLS encryption (HTTPS) for data in transit;
- encryption and pseudonymisation where appropriate;
- regular backups;
- contractual confidentiality obligations for employees and contractors;
- regular testing, assessment and improvement of the effectiveness of security measures.
Personal data breaches
If a personal data breach occurs, we follow our internal information-security incident procedure and applicable law. Where the breach is likely to result in a risk to individuals’ rights and freedoms, we notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of it. We notify affected individuals where required by law.
Links to other websites
Our website may contain links to third-party websites, including social networks, partners and clients. Once you leave our website, the privacy policy of the third-party operator applies. COR NET d.o.o. does not control those third parties’ privacy practices.
Complaints, questions and requests
For privacy questions or requests, contact us at info@cor-net.net, phone +387 36 833 468, or by post at COR NET d.o.o., Kneza Višeslava 14, 88 000 Mostar, Bosnia and Herzegovina.
If you believe your rights have been infringed, you have the right to lodge a complaint with the Personal Data Protection Agency in Bosnia and Herzegovina (AZLP), Dubrovačka 6, 71000 Sarajevo; phone +387 33 726-250; e-mail azlpinfo@azlp.ba; web www.azlp.ba.
The contact details +387 33 726-258 and szzp@azlp.ba refer to the Data Protection Officer of the Agency (AZLP), not a Data Protection Officer of COR NET d.o.o.
Changes to this Privacy Policy
We may update this Policy from time to time to reflect changes to our services, technology, legal requirements or security measures. The updated version will be published on this page with a revised “Last updated” date. Where changes are material, we will provide an additional notice where appropriate.






