Privacy Policy
How Werklist collects, uses, and protects personal data. Drafted under the GDPR and the Serbian Law on Personal Data Protection.
1.Introduction
Through this Privacy Policy, we tell you transparently which personal data we collect, why, how we process it, how long we retain it, and what your rights are.
Data Controller
WERKLIST DOO · Svetozara Radojčića 80V · 11050 Belgrade (Zvezdara) · Serbia
Tax ID (PIB): 115344942 · Registration No. (MB): 22144812
For questions, requests, or complaints about your data: fran@werklist.com with the note “PERSONAL DATA PROTECTION”.
2.What is personal data
Personal data means any information relating to an identified or identifiable natural person. Direct identification means the data itself reveals who it refers to; indirect identification means the person can be recognised by combining several available data points. This Policy applies to natural persons only. Data on legal entities is not personal data within the meaning of this Policy. We do not collect personal data of minors under 16.
3.What personal data we collect
3.1Job candidates
- Identification — name, date and place of birth, citizenship
- Contact — residential address, phone, email, social media URL
- Education — institution, qualification, period of study, languages, computer skills, driving licence, certificates
- Work experience — employers, roles, duration, project descriptions
- Employment — desired roles, availability, expected compensation
- Assessment — results of any competency tests in selection
- Photograph — only if voluntarily attached
3.2Business partners
- Name and surname, position
- Email, phone, business address
- Company name and tax number
- Other data relevant to the cooperation
3.3Website visitors
- Technical — IP address, browser, OS, screen resolution, time and duration of visit
- Cookie data — see Cookie Policy
3.4Contact and communication
If you contact us through a form, email, or other channel, we process the data you enter — name, email, phone, reason, message.
4.Why we process your data
4.1Candidates
- Determining your interest in employment and including you in our database
- Conducting selection — interviews, testing, evaluation
- Matching candidates with employers
- Communication during and after selection
- Notifying you about new opportunities matching your profile (with consent)
- Sending newsletters and marketing content (with consent)
- Fulfilling legal obligations — work permits, tax, records
4.2Business partners
- Performing contracts — invoicing, offers, deliverables
- Maintaining the business relationship
- Measuring satisfaction with our services
4.3General
- Improving services and the website
- Network and information security
- Responding to data subject and authority requests
- Protecting our legitimate interests
5.Legal basis
- Performance of a contract — necessary for a contract you are party to or for pre-contractual steps you requested.
- Legal obligation — tax, labour, accounting, immigration.
- Legitimate interest — sourcing and selecting candidates, service improvement, security.
- Consent — newsletters, marketing, future-opportunity outreach. Withdraw at any time without affecting prior lawful processing.
7.Transfer to third countries
Your data is generally processed within the EEA and Serbia. For exceptional transfers outside the EEA, we apply Standard Contractual Clauses approved by the European Commission or other safeguard mechanisms.
8.Profiling and automated decision-making
We do not carry out automated decision-making, and we do not create profiles for that purpose. None of our decisions are based on automated data processing.
12.Data security
We apply technical and organisational measures including:
- Encryption and modern protection methods
- Access control to resources containing personal data
- Pseudonymisation where possible
- Data minimisation in every process
- Confidentiality requirements for staff and associates
- Continuous monitoring of processing resources
- Regular security audits and staff training
13.Retention periods
- Mandatory legal retention (accounting, tax) — duration prescribed by law, deletion within a reasonable period after
- Job candidates — up to 3 years from last active communication, unless earlier deletion is requested or consent is withdrawn
- Consent-based — until withdrawal, then deleted as soon as possible
- Legitimate interest — for as long as the interest exists, then deleted within one year
- Contact and communication — until withdrawal of consent or end of business need
- Technical (cookies, IP) — up to 12 months
If legal proceedings are initiated, we retain data until their final conclusion, in line with applicable rules.
14.Your rights
- Access — confirmation of processing, access to data, and information on how it is processed.
- Rectification — correction of inaccurate data, completion of incomplete data.
- Erasure — when there is no longer a legal basis or under other applicable grounds.
- Restriction — in defined situations, e.g. where accuracy is contested.
- Data portability — receive data in a structured, machine-readable format and transfer to another controller.
- Object — to processing based on legitimate interest.
- Withdraw consent — at any time, without affecting prior lawful processing.
- Lodge a complaint — with the competent supervisory authority.
How to exercise rights. Send a request to fran@werklist.com or by mail with the note “Data Subject Request”. We may verify your identity. Rights are exercised free of charge; for frequent or excessive requests we may charge a reasonable administrative fee or refuse. We respond within one month, with a possible two-month extension for complex or high-volume cases.
15.Consent management
You may amend or withdraw consent in whole or part at any time by writing to fran@werklist.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. After withdrawal we will no longer use the data for the relevant purposes; this may make it impossible to provide certain services. If you do not provide data necessary for a contract or for legal obligations, we may not be able to provide the agreed services.
16.Use of digital services
Data you provide through forms, applications, or email is used only for the purposes in this Policy and treated as confidential. Access to the website follows standard technical protocols that record certain technical data (visit time, OS, screen resolution, transfer size) used to ensure functionality, security, and a better experience.
17.Protecting our interests
We may verify the identity of anyone submitting a request, accept requests only through defined channels, assess each request on the merits, and refuse those that are manifestly unfounded or excessive. Where rights are abused, we may take legal action.
18.Changes to this Policy
We may amend this Policy to keep it aligned with practice and law. Material changes will be communicated through the website. We recommend reviewing the Policy regularly.
19.Final provisions
Matters not covered here are governed by the Serbian Law on Personal Data Protection, the GDPR, and other applicable rules. Anyone who believes their rights have been violated may contact us by email at fran@werklist.com; we respond within one month. You also have the right to address the competent supervisory authority or court.
20.Contact
WERKLIST DOO
Svetozara Radojčića 80V · 11050 Belgrade (Zvezdara) · Republic of Serbia
Email: fran@werklist.com
10.Social media
10.1Facebook
If you visit our Facebook page, Meta Platforms Ireland Limited and Werklist are joint controllers of your personal data in the context of that visit. Meta processes data under its own privacy rules; we influence this only by designating user groups relevant to our business. We receive only anonymised, statistical data. Comments and inquiries on the page are not separately stored outside the platform. We are responsible for our posts and messages on Facebook; Meta is not.
10.2Other platforms
The same applies to LinkedIn, Instagram, YouTube, and similar — each processes personal data under its own privacy policy.