Legal information

Privacy policy

Last updated: October 4, 2026

This Privacy Policy explains how Omikron processes personal data when you use our website or communicate with us. We apply the Law on Personal Data Protection of Bosnia and Herzegovina (Official Gazette of BiH No. 12/25), which aligns with core GDPR principles. This page explains our practice and is not legal advice.

Who we are and the data controller

The controller is Omikron s.p. Dušan Radenović, Baje Stanišića 35, 76300 Bijeljina, Bosnia and Herzegovina. Contact us by telephone at +387 65 709 668, by email at sales@omikron.ba, or through omikron.ba. Omikron determines the purposes and means of processing data received through this website and direct business communication.

What data we process and how we receive it

When you use the contact form, we may receive your name, email address, company or organisation, telephone number if voluntarily provided, selected service/inquiry category, message or project brief, and selected language. If the form was opened from a vacancy or Careers page, we may also receive that vacancy or application context.

Email communications may naturally contain the sender’s name, email address, message content, and further information voluntarily supplied. We do not ask for dates of birth, payment-card data, government identification documents, health information, or special-category data through this website.

Why and on what basis we process data

We use data to respond to inquiries; discuss requested services or projects; prepare proposals and take pre-contractual steps; deliver and communicate about an agreed project; process Careers, open-application, or Job inquiries; protect the form and website from abuse; comply with applicable legal and accounting obligations; and maintain reasonable business and project documentation.

For service inquiries, requested proposals, project discussions, and performance of an agreed engagement, we rely on Article 8(1)(b) of the Law: contractual necessity or steps taken at the data subject’s request before entering into a contract. For general business communications where that basis does not apply, website security, prevention of spam and abuse, necessary operational records, and an appropriate language experience, we rely on Article 8(1)(f), legitimate interests. Those interests must not override your rights and freedoms. Where necessary for accounting, tax, regulatory, or other legal duties, we rely on Article 8(1)(c), legal obligation.

Contact form and security

The contact form uses a WordPress nonce, a honeypot field, rate limiting, sanitisation, and server-side validation. Its anti-abuse/rate-limit mechanism derives a temporary key from request/IP-related technical data. We do not maintain a permanent raw-IP database for that purpose. This technical data is used only to protect the form, prevent spam or abuse, and maintain site security.

Hosting, email, and recipients

We use Hostinger for hosting, WordPress infrastructure, and business email infrastructure. Where Hostinger processes data on our behalf for those services, it acts as a processor or service provider. Hostinger may use authorised subprocessors necessary to provide hosting, infrastructure, email delivery, security, and related services. We do not reproduce their list here because it may change; the relevant terms are available in the Hostinger Data Processing Addendum.

We do not sell personal data. Recipients may include authorised people within Omikron who need access, Hostinger and its authorised subprocessors where necessary for the services above, and competent public authorities where disclosure is legally required.

International processing

Hostinger is an international provider, so data may be processed or transferred outside Bosnia and Herzegovina. Where this occurs, Hostinger’s contractual and privacy framework provides safeguards applicable to its services, including appropriate contractual mechanisms where applicable. We do not claim that all data always remains physically in Bosnia and Herzegovina.

How long we keep data

We retain inquiries only as long as reasonably necessary to answer them, follow up on requested communication, and establish whether a business relationship or project will proceed. Where no further purpose exists, we delete or anonymise data, subject to applicable legal requirements.

For active projects, we retain relevant communications and project data for the duration of the project. After completion, certain records may remain as long as reasonably necessary for project maintenance or support, business documentation, establishing, exercising, or defending legal claims, applicable accounting/legal obligations, and legitimate technical or reference purposes. Publicly available business information used in project or reference work may remain longer where there is a legitimate operational, portfolio, or documentation reason. Technical, staging, or backup copies may remain longer where reasonably necessary for maintenance, support, reference, or system recovery; access is limited where appropriate and personal data are removed when no longer needed for a legitimate purpose.

Language, GeoIP, and local preferences

The website may temporarily infer a visitor’s country from the GEOIP_COUNTRY_CODE server variable supplied by Hostinger or the server to suggest an appropriate language. There is no automatic forced redirect: you can accept the suggestion or remain on the current language. The Omikron theme does not store a country history and does not use this feature for advertising or profiling.

Your browser may keep your explicitly chosen language and a temporary dismissal of the language suggestion in local storage. A dismissal is remembered for seven days. These are functional/preference settings, not analytics or advertising tracking.

Cookies and tracking

The public website currently does not intentionally use advertising pixels, behavioural advertising, analytics tracking, marketing cookies, or third-party tracking scripts. WordPress may use necessary cookies for authenticated administrators and essential technical functionality. Language preference and dismissal are stored locally in the browser as described above. If we introduce non-essential analytics or marketing technology later, we will update this policy and any required consent mechanism before or when that processing begins.

Your rights

Under applicable law, you may request access to data, correction of inaccurate data, completion of incomplete data, erasure, restriction of processing, objection to processing, portability where applicable, and information about processing and recipients. Send a request through the contact form or to sales@omikron.ba. We may request information reasonably necessary to verify identity before acting on a request.

We respond to a valid request without undue delay and, as a rule, within 30 days under applicable law. Where legally permitted because of the complexity or number of requests, this period may be extended with notice to the requester.

Security, automated decision-making, and children

We apply reasonable technical and organisational measures appropriate to the nature of the data and processing to protect personal data against unauthorised access, alteration, disclosure, loss, or misuse. We do not use data collected through this website for automated decision-making or profiling that produces legal or similarly significant effects. Language suggestion is not such decision-making or profiling.

Our website and services are intended primarily for business and professional users, and we do not intentionally seek to collect children’s personal data.

Changes to this policy

We may update this policy when processing changes, service providers change, new functionality is introduced, or legal requirements change. The latest version will be published on this page with its update date.

Contact and supervisory authority

For privacy questions, contact Omikron at sales@omikron.ba. You may also complain to the Personal Data Protection Agency in Bosnia and Herzegovina or seek judicial protection where applicable.

Personal Data Protection Agency in Bosnia and Herzegovina
Dubrovačka br. 6
71000 Sarajevo, Bosnia and Herzegovina
Telephone: +387 33 726 250
Email: azlpinfo@azlp.ba