Privacy Policy Mobile Application
NOTICE ON THE PROCESSING OF PERSONAL DATA
(General Notice for Users of the Mobile Application of the Public Utility Company for Public Garages and Parking Lots “Parking Servis” Belgrade)
The Public Utility Company for Public Garages and Parking Lots “Parking Servis” Belgrade, in accordance with the Law on Personal Data Protection and the Rulebook on Personal Data Protection of the Public Utility Company “Parking Servis” Belgrade (consolidated text) No. 2569/1 dated 5 May 2026, hereby provides the necessary information regarding the processing of personal data:
Section 1
Information on the Controller
The controller of personal data is the Public Utility Company for Public Garages and Parking Lots “Parking Servis” Belgrade, 28v Prekonoška Street, Belgrade.
Section 2
Information on the Data Protection Officer
For all questions and requests related to the processing of personal data, the data subject may contact the Data Protection Officer.
The Data Protection Officer at the Public Utility Company “Parking Servis” Belgrade is:
Tanja Perović, Professional Associate for Legal Affairs, Cooperation with the Commissioner for Information of Public Importance and Personal Data Protection, and Personal Data Protection Affairs.
Address: Headquarters, 28v Prekonoška Street, Belgrade
e-mail: lice.zzpl@parking-servis.co.rs
telephone: +381 11 2228 050
Section 3
Types of Personal Data of Mobile Application Users That Are Processed
The Company, acting as the controller, processes the following personal data of users of the Company’s mobile application:
- when creating a user account: password (encrypted), first and last name, e-mail address, and vehicle registration plate number(s);
- when using the “Google Sign-In” service: first and last name, e-mail address, connection with the User’s Google profile (account ID), and (optionally) a link to the User’s Google profile picture;
- when using the “Apple Sign-In” service: first and last name, e-mail address (whereby Apple offers two options: sharing the User’s actual e-mail address or forwarding through a private anonymous e-mail address – Apple generates a unique, random address that forwards messages to the User’s actual e-mail address).
Section 4
Purpose and Legal Basis for the Processing of Personal Data of Mobile Application Users
The personal data of users of the Company’s mobile application are processed exclusively for the purpose of creating and authenticating a user account within the mobile application, in order to provide a personalized and secure user experience. These data are necessary for the basic functioning of the application and are not used for any other purposes.
The legal basis for the processing of personal data of users of the Company’s mobile application is the consent of the data subjects.
Section 5
Consent of the Data Subject to the Processing of Personal Data
When personal data are collected and processed on the basis of consent, the Company, acting as the controller, shall inform the data subject, in an appropriate manner and prior to the collection of the data, about the following:
- that consent is given voluntarily and may be withdrawn at any time;
- the legal consequences of withdrawing consent;
- the purpose of the processing of personal data;
- the processing activities performed on the personal data;
- the period during which the personal data will be processed;
- the rights available to data subjects;
- the data protection measures applied in relation to the data;
- the manner of establishing contact with the Data Protection Officer within the Company;
- other important information relating to the processing.
The consent of the data subject must be given in written form (in the form of a written statement) and must satisfy the following requirements:
- that it is freely given (not given under coercion, pressure, or duress);
- that it is unconditional (not conditioned upon acceptance of other services or conditions);
- that it is specific (given for a particular purpose);
- that it is granular (given separately for each purpose);
- that it is informed (the data subject understands what they are consenting to); and
- that it may be withdrawn at any time.
Section 6
Processing of Geolocation Data, Camera Data (Barcode/Text), and Notifications
The Company’s mobile application may collect data regarding the User’s current location only with the User’s permission (through the mobile device settings). Geolocation data are used for the following purposes:
- automatic recommendation of the appropriate parking zone in which the User is located (when paying for parking);
- displaying the User’s current position on the map when using the “Locator” feature (navigation to available parking spaces).
The Company does not store the User’s location history.
Location data are used only while the Company’s mobile application is active.
The User may disable access to location data at any time through the phone’s system settings (and the Company’s mobile application will continue to function, but without automatic zone recommendations).
Camera Data (Barcode/Text)
When the User photographs a parking ticket (unique ticket number) for the purpose of payment in a garage, the mobile application uses the camera solely for text and barcode recognition. Image data are processed exclusively locally on the User’s device and are neither transmitted to nor stored on the Company’s servers.
Notifications
The application may send notifications (“push notifications”) to the User regarding:
- expiration of parking time;
- issued electronic daily parking tickets (eDPT);
- the location to which the towing service has relocated the User’s vehicle (“Where Is My Car”).
Sending such notifications requires the User’s permission (which may be withdrawn through the phone settings).
Notifications do not contain sensitive data, except for the vehicle registration plate number and vehicle location.
If the User is not connected to the internet or if technical conditions do not permit delivery, some of the above notifications may not be received, which shall not release the User from the obligation to pay for parking in accordance with the Decision on Public Parking Lots.
Section 7
Data Retention Period
Account and transaction data are retained for as long as the User maintains an active account, and for a maximum period of 3 years after account deletion (due to statutory accounting obligations).
Payment data are retained for 10 years (in accordance with tax regulations).
Section 8
Recipients of Personal Data
The personal data of users of the mobile application are processed for the purposes specified in this Notice. Where necessary for the achievement of those purposes, certain recipients may have access to the data, such as banks, competent public authorities, and other entities.
The Company shares data with third parties only in the following cases:
|
Third party
|
Type of data |
Purpose |
|
Bank processor |
Card data entered directly by the User on the bank’s website |
Payment processing |
|
Google (if the User uses Google Sign-In) |
Data required by Google |
Authentication
|
|
Apple (if the User uses Apple sign in) |
Data required by Apple
|
Authentication
|
|
Competent public authorities
|
Account data (e.g. vehicle registration plate numbers)
|
Where there is a legal obligation (e.g. compliance with orders of judicial authorities, etc.) |
Section 9
Rights of the Data Subject (Users of the Mobile Application)
Data subjects (users of the mobile application) have the following rights:
- the right to request information regarding the processing;
- the right to request access to personal data from the Company;
- the right to request rectification, supplementation, or erasure of personal data, as well as restriction of processing;
- the right to data portability;
- the right to object;
- the right to lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection, the right to judicial protection, as well as the right to compensation in the event of unlawful processing;
- other rights guaranteed by the applicable Law on Personal Data Protection.
The data subject may submit a request for exercising the rights referred to in paragraph 1, items 1–5 of this Section using the prescribed form, which should be delivered to:
- e-mail address: lice.zzpl@parking-servis.co.rs; or
- the address of the Public Utility Company “Parking Servis” Belgrade, 28v Prekonoška Street, Belgrade,
with the indication: “Request for Personal Data Protection”.
The Request Form for exercising the rights referred to in paragraph 2 of this Section is available on the official website of Parking Servis Beograd, as well as on the Company’s premises, provided that the data subject is also authorized to submit the request in free form. The request must be personally signed by the applicant.
The Data Protection Officer shall, upon request, provide the data subject with all necessary information regarding the manner of exercising their rights.
Section 10
Source of Personal Data of Mobile Application Users
The Company collects personal data of mobile application users in one of the following ways:
- directly from the data subject, upon access to the mobile application.
Section 11
Transfer of Personal Data to Other States and International Organizations
The personal data of mobile application users are processed within the Republic of Serbia.
Section 12
Processing Operations
Within the meaning of this Rulebook and Article 4 of the Law on Personal Data Protection, “processing of personal data” means any operation or set of operations which is performed, whether or not by automated means, on personal data or sets of personal data, such as collection, recording, classification, grouping or structuring, storage, adaptation or alteration, disclosure, consultation, use, disclosure by transmission or delivery, duplication, dissemination or otherwise making available, comparison, restriction, erasure, or destruction (hereinafter: processing).
Section 13
Measures for the Protection of Personal Data
The Company, acting as the controller, is obliged to undertake all necessary technical, organizational, and personnel measures for the protection and security of personal data that it collects and processes, both in the case of automated and non-automated data processing.
In the case of automated processing of personal data, technical measures are implemented within the organizational unit of the Company responsible for information technologies, which:
- introduces and maintains all necessary software programs within which personal data are recorded, stored, and processed;
- undertakes all other technical measures within the IT system through which personal data are permanently protected against misuse, unauthorized use, collection, disclosure, as well as any other activities that may jeopardize the confidentiality of personal data.
Data Security When Using the Mobile Application
- The Company uses SSL/TLS encryption for data transmission between the mobile application and the Company’s servers;
- The payment processing bank is PCI DSS certified;
- The Company’s servers are protected by firewalls, antivirus software, and access control systems;
- Access to User data is granted only to authorized employees (customer support and IT administration), solely for the purpose of service provision.
Data Storage
- Account data (name, e-mail address, and vehicle registration plate numbers) are stored on the Company’s protected servers located in the Republic of Serbia;
- Passwords are stored in hashed (encrypted) form;
- Payment card data are not stored by the Company, but exclusively by the payment processing bank;
- Geolocation data are not stored and are used only in real time;
- Camera images are not stored and are processed locally on the device.
Section 14
Employees who process personal data are obliged to implement the prescribed measures and procedures for the protection of personal data that they become acquainted with in the course of performing their duties.
The Company, acting as the controller, through a separate Notice, informs all employees of their rights, obligations, and responsibilities regarding the protection of personal data, in accordance with the applicable regulations and the Rulebook on Personal Data Protection. The separate Notice for employees is available on the Company’s website Parking Servis Beograd, and a written copy of the Notice is also delivered directly to employees.
The obligation to protect personal data does not cease upon termination of employment.
For employees of the Company, failure to comply with the provisions of the Rulebook on Personal Data Protection shall constitute a breach of work obligations.
Section 15
Through this Notice, the Company, acting as the controller, informs all service users, clients, and business partners of their rights, obligations, and responsibilities regarding the protection of personal data, in accordance with the applicable regulations and the Company’s Rulebook on Personal Data Protection.
English
српски