Controller and contact details
The controller of personal data described in this Policy is VMTech DOO Beograd, registration number 22069152, tax identification number 114779614, Topalovićeva 4, 11050 Belgrade (Zvezdara), Republic of Serbia ("VMTech", "we"). For questions, requests and exercise of rights, contact support@richananas.rs or write to the registered office.
VMTech has not appointed a separate data protection officer because, considering the present scale and nature of processing, such appointment is not mandatory. Requests are handled by VMTech's authorised responsible person. If the obligation or decision to appoint a data protection officer changes, that person's contact details will be published in this Policy and submitted to the competent authority where required.
Scope of the Policy and processing roles
This Policy applies to the RichAnanas public website, registration, Studio, APIs, plugins, integrations, contact and support. VMTech determines the purposes and means of processing and acts as controller for account users, business contacts, visitors, billing, security and communications data.
For personal data that a business Customer enters, imports or synchronises within its catalogues, orders and sales operations, the Customer normally determines the purpose and acts as controller, while VMTech acts as processor. The Customer must provide required notices to its buyers, employees and other persons and ensure a valid legal basis. The Terms of Use contain VMTech's contractual obligations as processor.
Categories of data
Depending on how the Service is used, we may process:
- account-user identification and contact data: name, business email, language, email-verification status and login information;
- organisation data: business name, tax identification number, registration number, address, telephone, business email, memberships, roles and permissions;
- billing data: plan, period, amount, currency, invoice status, due and payment dates, electronic-invoicing data and business correspondence;
- Customer operational data: products, SKU/EAN, descriptions, attributes, images, video, prices, inventory, warehouses, discounts, rich content, imports, exports and synchronisation statuses;
- order data retrieved by the Customer from a connected store: order identifier, items, status, recipient name and contact, delivery address, shipment and label information where available through the integration;
- content voluntarily submitted through an AI feature, support, contact form or feedback;
- technical and security data: IP address, user agent, session, access times, authentication events, audit trail, API and integration events, errors, device identifiers and language or theme settings;
- integration information and secrets in protected form, such as tokens, keys and connected-store identifiers.
Sources of data
We obtain data directly from users and organisations, from an owner or administrator inviting a team member, from connected marketplace and WooCommerce stores at the Customer's request, from imported files, from interaction with the Service and from technical systems protecting and recording its operation.
Where data is not obtained directly from the person concerned, such as order-recipient data from a Customer store, the Customer is responsible for having a legal basis and providing appropriate information to that person. VMTech processes such data under the Customer's instructions and does not use it for its own direct marketing.
Purposes and legal bases
We process data to register and authenticate users; form and perform contracts; manage teams, plans and billing; provide catalogue, media, order, integration, import, export and support features; carry out a user-requested action; prevent fraud and unauthorised access; maintain stability, audit trails and evidence of transactions; resolve disputes; improve the product using aggregated or limited data; and meet tax, accounting, security and other legal obligations.
Depending on the purpose, the legal basis is performance of a contract or pre-contractual steps, compliance with a legal obligation, VMTech's or the Customer's legitimate interest in a secure and efficient B2B service, or consent where required, particularly for optional analytics and non-essential storage on a device. When relying on legitimate interest, we assess necessity, reasonable expectations and impact on individual rights.
Required and voluntary data
Data marked as required is necessary to open and protect an account, verify a business user, perform the contract, connect a selected integration or issue an invoice. Without it, a particular feature or the Service cannot be provided.
Sending a contact message, additional content, feedback and starting automated features is voluntary. The user decides which permitted materials to submit but should provide only data necessary for the specific purpose.
User-initiated automated processing
Data is not sent to automated-processing providers merely because a user accesses Studio. A transfer occurs when the user knowingly starts a specific AI or similar feature. The instruction, selected text, product context or image may then be sent to a specialised provider to generate or process the requested output.
Buyers' data, special categories of personal data, health information, biometric data, payment information, passwords, secret keys and confidential data unnecessary for product processing must not be submitted. VMTech selects providers after assessing contractual and security safeguards and seeks to prevent them from using content for their independent purposes or training general models unless such processing is lawfully agreed and the user is informed in advance.
Recipients and provider categories
We may disclose data only as necessary to: authorised VMTech personnel; hosting, database, storage and backup providers; email and communications providers; authentication and automated-abuse prevention services; analytics providers after required consent; specialised text or image processors when a user starts the relevant feature; accounting, legal and tax advisers under confidentiality; connected sales platforms on the Customer's instruction; and competent authorities under a valid legal request.
VMTech does not sell personal data. Recipients receive only the data needed for their role and are bound by contract or law to appropriate confidentiality and protection. More information about provider categories and, where justified, processor identity may be requested through the contact address.
Processing location and international transfers
The Service's primary infrastructure is located in Germany. Certain specialised providers may process data in other countries, including countries outside Serbia and the European Economic Area, only where required for a selected feature or infrastructure.
Before an international transfer, VMTech assesses the legal basis and applies safeguards required by the Serbian Personal Data Protection Act, such as transfer to a country providing an adequate level of protection, contractual clauses, binding recipient commitments, additional technical measures or another legally permitted mechanism. Information about the applicable mechanism may be requested at support@richananas.rs, subject to protection of trade secrets and security information.
Retention periods and criteria
We retain account, organisation and operational content while an account is active and after termination for as long as reasonably necessary for a requested export, account closure, support resolution, collection, backups, abuse prevention and defence of legal claims. When no longer needed, data is deleted, anonymised or permanently removed from regular use unless law or a documented Customer instruction requires otherwise.
Security, audit, API and integration records may be retained for up to five years for security, traceability, evidence of actions, contractual integration requirements and legal claims. Invoices and business records are kept for periods required by tax, accounting and other laws. Contact and support data is kept while a matter is active and thereafter as needed for relationship history and legal claims. Codes and tokens are kept until expiry or revocation, with a protective trace possibly retained. Prepared export files automatically expire after 24 hours.
Backups rotate according to an operational cycle and may for a limited period contain data removed from the active system. Such data is not restored to regular use except for recovery, and deletion requests are reapplied after restoration. The precise period may depend on data type, contract, risk and a current legal duty.
Analytics and user-experience recording
VMTech may activate Google Analytics and Yandex Metrica to measure visits, performance, feature usage and improve user experience. Yandex Metrica may include Webvisor, which may record interaction with a page such as clicks, scrolling, navigation and a technical session view. These tools will not be activated for a user before clear notice and consent where legally required, and the user will be able to refuse or later withdraw consent.
Before analytics is activated, VMTech will apply minimisation, field masking and recording restrictions so that passwords, secret keys, payment data, order content and other unnecessary confidential data are not intentionally recorded. Analytics may process online identifiers, IP address to the permitted extent, device, browser, approximate location, traffic source, events and usage duration. An analytics provider may process data outside Serbia under an appropriate transfer mechanism. While these tools are not technically active, the described analytics processing does not take place.
Automated decisions
VMTech does not make decisions producing legal effects or similarly significantly affecting an individual solely through automated processing or profiling. Automated features produce suggestions and technical outputs that a business user reviews and decides whether to use.
Automated security controls may temporarily block a suspicious request, limit attempts or require additional verification. A user who believes such a measure is incorrect may contact support for a reasonable review by an authorised person.
Safeguards
VMTech applies technical, organisational and personnel measures appropriate to risk, including organisation- and role-based access controls, communications protection, cryptographic protection of sensitive integration values, masking secrets in logs, backups, event monitoring, attempt limiting, system updates and incident-response procedures.
No system is absolutely secure. The user is responsible for a strong unique password, device security, timely removal of team members, token protection and integration review. If a personal-data breach may create risk, VMTech will comply with legal duties to notify the Customer, individuals and the Commissioner, depending on its role and the assessed risk.
Individual rights
Subject to legal conditions, an individual may request information and access, correction of inaccurate and completion of incomplete data, erasure, restriction, portability, objection to processing based on legitimate interest, and withdrawal of consent without affecting prior lawful processing. Rights are not absolute; a request may be limited to protect others' rights, trade secrets, security, statutory retention or establishment and defence of legal claims.
An individual may lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection and seek judicial protection. Contacting VMTech before a complaint is not mandatory, but a direct request often enables faster resolution.
How to exercise rights
A request should be sent to support@richananas.rs with enough information to identify the person, organisation, account and subject of the request. To protect data, we may request additional confirmation of identity or authority. We respond without undue delay, normally within 30 days; where permitted by law due to complexity or number of requests, this may be extended by a further 60 days with timely notice.
If a request concerns buyer or recipient data that VMTech processes only for a business Customer, we will direct the individual to that Customer or assist it under the contract because the Customer decides the request as controller. Requests are normally free; measures allowed by law may apply to manifestly unfounded, excessive or repeatedly submitted requests.
Legal age and business purpose
RichAnanas is not intended for children, minors or private consumers. An account for a legal entity or entrepreneur may be opened only by an adult at least 18 years old who is authorised for the business action. If we learn that a minor has submitted data without a proper basis, we will take reasonable steps to remove it.
Policy changes and controlling version
We may amend this Policy when the Service, processing, providers, analytics, law or safeguards change. We will publish the new version and revision date and notify active users through Studio or email of material changes where reasonable and required.
The Policy is available in several languages. The Serbian version is original and controlling in case of translation differences unless mandatory law requires otherwise. Questions about this Policy may be sent to support@richananas.rs.