Откуцај
SRENРУ Log in

Privacy policy

In force from 1 September 2026 · Changed 5 October 2026 · Otkucaj (otkucaj.com)

Where this policy describes what the regulations require, that is our understanding of them, not legal advice. The regulations themselves prevail.

This English version is provided for convenience. If the two differ in meaning, the Serbian version prevails.

1. Who we are

Otkucaj is an ESIR, an electronic invoice issuing system developed and maintained by Saša Mihajlović pr Računovodstveni poslovi TEFIS Vlasotince (below: "Tefis" or "we"). Tefis is the data controller within the meaning of the Serbian Personal Data Protection Act, to the extent set out in section 3 of this policy.

Registered nameSaša Mihajlović pr Računovodstveni poslovi TEFIS Vlasotince
Registered seatVlasotince, Republic of Serbia (address: Terms of use, section 1)
TIN (PIB)112978955
Company number66482405
RegisterSerbian Business Registers Agency (APR)
E-mail[email protected]
Contactthe contact form at otkucaj.com/kontakt

For anything to do with data protection, write to us at [email protected] or through the contact form.

2. What we process

  • User accounts: username, display name, e-mail, password (stored only as a hash, never in readable form), sign-in times, and the phone number entered when the account is opened.
  • Taxpayer business details: business name, TIN, registration number (matični broj), address and name of the point of sale, that is, the details the taxpayer enters themselves when opening the account and in order to issue receipts.
  • Receipt data: line items, amounts, taxes, means of payment, time of issue, PFR identifiers. The content of a receipt is prescribed by the Law on Fiscalization (article 5), and the duty to fiscalize is the user's, as the taxpayer.
  • The buyer ID is entered only where a regulation or the buyer requires it (for example a receipt carrying the buyer's TIN) and is shown on the receipt.
  • The buyer's e-mail address, where the user sends a receipt to the buyer by e-mail.
  • Technical records: IP address and actions in the activity log, for security and for evidence.
  • Messages sent through the contact form: whatever the sender enters into the form, and the content of the message.
  • Billing data: invoices issued for the service and payments made, where the service is charged for.

We neither ask for nor want special categories of personal data in free text fields (item name, note, point of sale name), such as data on health, religion, political opinion or biometrics. If a user enters them anyway, they do so on their own responsibility and without our agreement.

You provide account and billing data in order to conclude and perform the contract: without it an account cannot be opened. The data a receipt must contain is prescribed by article 5 of the Law on Fiscalization, so a receipt cannot be issued without it.

3. Who is controller and who is processor

Two groups of data have to be told apart, because who is responsible for what depends on it:

  • Tefis is the controller for user account data, technical records, messages sent through the contact form, and billing data for the service. There we determine the purpose and the means of processing.
  • The user (the taxpayer) is the controller for personal data they themselves enter into Otkucaj about their own buyers and their own business, and Tefis is a processor in respect of that data, processing it on the user's instruction, to provide the service and to meet legal obligations.

The user declares and warrants that they have a valid legal basis for every item of personal data they enter into Otkucaj, that they have informed the individuals concerned as required, and that they enter only what is necessary. The user must handle requests from their own buyers and from anyone else whose data they enter. If such a request reaches us, we will pass it to the user and tell the person who the controller is. The user, not Tefis, is responsible for the lawfulness of processing that data.

Tefis does not choose, review or monitor what the user enters. The application takes what is typed into it and has neither a technical nor a legal duty to examine it. Tefis is therefore not answerable for what the user entered, on what basis, whether the individuals were informed, or whether the data could lawfully be collected at all.

The user indemnifies Tefis and holds it harmless against any damage, cost, fine or award, including legal costs, arising from a claim by a buyer, an employee, an authority or a third party which originates in data the user entered into Otkucaj, in the basis for processing it, in the user's relationship with the individuals concerned, or in the user acting contrary to this policy, the Terms of use or data protection law.

4. Legal basis and purpose

We process data in order to:

  • perform the contract with a user who is an entrepreneur, or pursue a legitimate interest where the account is used by a user's employee (opening and running accounts, providing the invoice issuing service, support, billing);
  • meet Tefis's own legal obligations (accounting and tax regulations for billing data, orders of courts and other competent authorities); fiscal data entered by the user is processed by Tefis on the user's instruction (section 3), and the obligations under the Law on Fiscalization are the user's;
  • pursue a legitimate interest (the security and integrity of the system, preventing misuse and fraud, evidencing actions in the activity log, establishing, exercising and defending legal claims).

We take no decisions based solely on automated processing that would produce legal effects for an individual, and we do not profile for marketing purposes.

5. Who the data goes to

  • The Tax Administration of the Republic of Serbia: by the very nature of electronic fiscalization, fiscal data is forwarded to the processor of fiscal invoices (L-PFR or V-PFR) and to the Fiscalization Management System. This is a legal obligation and does not depend on the user's consent.
  • Infrastructure providers: Hetzner Online GmbH (the server in Germany on which the application and its database run, and Hetzner's backups of that server), Cloudflare (traffic protection and delivery in front of the site, and the check on the sign-in and contact pages) and Migadu (the [email protected] mailbox, which also receives contact form messages). These providers process data as part of the services they provide to us.
  • Tefis's own mail relay server, through which the e-mail the application sends passes, including contact form messages and receipts sent to buyers.
  • Competent authorities: where there is a legal duty to disclose, or an order from a court or another competent authority. In that case we need not seek the user's consent first, nor inform them where the law rules out informing them.
  • Tefis's legal and accounting advisers, to the extent needed to establish and defend legal claims.
  • A legal successor, on a corporate change or a transfer of the business, keeping the same level of protection.
  • We do not sell data and do not pass it to third parties for marketing purposes.

The list of processors and infrastructure may change. We announce an intended change in advance, in the manner set out in section 12.

6. Transfers abroad

The application and its database run on a server in Germany, so the data is held outside Serbia. Data processed by Cloudflare and Migadu may also be transferred and processed outside Serbia.

7. How long we keep data

  • Fiscal data (the receipt data the user enters): for as long as the user's account exists, and after it ends in line with section 16 of the Terms of use. The retention periods for accounting documents and business books are imposed by law on the user, not on Tefis, so the user downloads and keeps its own records.
  • Accounts and user data: for as long as the contractual relationship lasts, and afterwards in line with section 16 of the Terms of use: the user may request an export within 30 days, and once that period passes the data is deleted without separate notice.
  • Billing data: for the periods that accounting and tax regulations impose on Tefis.
  • Backups: data deleted from the application may remain in the backups described in section 5 until those backups are deleted.
  • Technical and security records: no longer than 24 months.
  • Messages sent through the contact form: no longer than 24 months after the last exchange.
  • Data needed for legal claims: until the limitation period expires and any proceedings that have begun are concluded.

8. Security

All traffic is encrypted (HTTPS/TLS). Passwords are stored as hashes. Access is limited by role, and actions are written to the activity log. Database backups are taken daily.

No measure gives absolute security and we do not guarantee that an incident cannot happen. The user must see to security on their own side: keeping passwords and API keys safe, protecting devices and networks, limiting access for staff, and promptly withdrawing access from people who no longer need it. The user must notify us of a suspected account compromise within 24 hours. Tefis is not responsible for incidents originating with the user or with third parties.

If a personal data breach occurs on our side, we will act as the Act requires: we will notify the Commissioner within the prescribed period and, where the law provides for it, the individuals concerned. Such a notification is not an admission of liability.

9. Your rights

You have the right of access, rectification and erasure (to the extent the regulations requiring us to keep data allow), the right to restriction of processing, the right to portability of data you gave us where the processing is based on a contract and carried out by automated means, and the right to complain to the Commissioner for Information of Public Importance and Personal Data Protection, Bulevar kralja Aleksandra 15, 11120 Belgrade. Send requests to [email protected] or through the contact form.

Right to object. Where we process data on the basis of a legitimate interest (section 4), you may object to that processing at any time, on grounds relating to your particular situation.

If we have reasonable doubts about the identity of the person making a request, we may ask for the additional information needed to confirm it. We act on a request without delay and within 30 days at the latest, a period that may be extended by a further 60 days, in which case we tell you. A manifestly unfounded or excessive request, particularly a repeated one, may be refused or charged at the necessary administrative cost, under article 21 of the Act. There is no right of erasure to the extent a regulation requires us to keep the data, nor for data needed to bring, exercise or defend a legal claim.

If you are a buyer of an Otkucaj user rather than the user themselves, address your request to that business, which is the controller for that data (see section 3).

10. Cookies

We use only the cookies and browser storage needed for the service you asked for: a session cookie for signing in, which also remembers the chosen language; a "remember me" cookie, if you leave that option on when signing in, which keeps you signed in on that browser until you sign out (the browser may shorten that); a cookie remembering the chosen light or dark theme, for one year; and the browser's local storage, where the till keeps carts, the item list, receipts waiting to be sent and the menu layout. On the sign-in and contact pages Cloudflare Turnstile checks that the visitor is a person. As we understand article 160 of the Law on Electronic Communications, no consent is required for these. We use no third party marketing or analytics cookies and we do not track you across other sites.

11. Links to other sites

Otkucaj pages may link to third party sites, for example to the Tax Administration. We are not responsible for their content or for how they process data.

12. Processing on the user's instruction (the processing agreement)

This policy together with the Terms of use constitutes the personal data processing agreement required by article 45 of the Personal Data Protection Act, for the data in section 3 where the user is the controller and Tefis the processor. No separate document is concluded unless the user asks for one in writing and the parties sign it.

  • Subject and duration: processing lasts as long as Otkucaj is used, and afterwards only for the periods in section 7.
  • Nature and purpose: storing, displaying, printing, sending and transmitting data in order to issue and record fiscal receipts and to provide the service.
  • Types of data and categories of individuals: the data the user enters, about their buyers, cashiers and staff, as listed in section 2.
  • Instructions: Tefis processes the data solely on the user's documented instruction, and only the use of the application's published features counts as an instruction. Tefis is not obliged to act on a special or additional instruction requiring development, modification or any act outside the existing features; such an instruction is agreed and charged separately. Processing on a legal obligation is not the user's instruction and happens without it.
  • Legal obligation: where a regulation requires us to process this data other than on the user's instruction, we will inform the user before the processing starts, unless the law prohibits that information.
  • Unlawful instruction: if we consider that an instruction from the user does not comply with data protection law, we will warn the user without delay.
  • Personal data breach: we will notify the user of a breach affecting data for which the user is the controller without undue delay after becoming aware of it.
  • Confidentiality: the people at Tefis who can reach the data are bound to confidentiality.
  • Sub-processors: the user gives general prior authorisation for the sub-processors in section 5. We announce an intended addition or replacement of a sub-processor at least 15 days in advance, by publishing on this page, so that the user can object; a user who does not accept the change has one remedy only, to stop using the service, with no right to compensation.
  • Assistance: so far as is technically reasonable and using the features the application already has, Tefis assists the user in answering individuals' requests and in meeting security and breach notification duties. Assistance requiring work outside the existing features is charged at the rate in force.
  • Deletion and return: after access ends, the user may request an export of its data in a machine-readable form within 30 days. Once that period passes, Tefis may permanently delete the data for which the user is the controller, unless a regulation requires Tefis to keep it.
  • Audit: on request we make available to the user the information needed to show that we meet these obligations, and we allow audits by the user or a person it authorises, as a rule once a year, on at least 30 days' notice, in working hours, without access to other users' data, and at the user's cost.

Tefis does not use user data for its own purposes, to develop its own products, to train artificial intelligence systems, for profiling, or to pass to third parties for marketing.

13. Limitation of liability

Every claim connected with data processing is subject to the limitations of liability in section 13 of the Terms of use, to the extent mandatory law allows. In particular Tefis is not liable for:

  • the lawfulness, accuracy, completeness and legal basis of data the user entered;
  • incidents arising on the user's side, or with their staff, equipment, network or third parties, including compromised passwords and API keys;
  • the transmission of fiscal data from the fiscal receipt processor to the Tax Administration and its processing there, which happen outside Tefis's control;
  • the acts of authorities, courts and others to whom disclosure is ordered by law;
  • lost profit, lost turnover, reputation and indirect loss, unless the loss was caused intentionally or by gross negligence;
  • force majeure, outages at infrastructure providers, and unavailability of the Tax Administration's systems.

Pointing out a shortcoming, notifying an incident, acting on an individual's request or taking a voluntary measure is not an admission of liability and is no ground for a claim against Tefis.

14. Suspension and withdrawal of access

Nothing in this policy limits the provider's right, under section 6 of the Terms of use, to suspend or withdraw access to the service at any time and with no reason given. What happens to data after access ends is governed by section 7 of this policy and section 16 of the Terms of use.

15. Changes

We will announce changes to this policy on this page. The date it takes effect is at the top. Continuing to use the service after a change takes effect counts as having been made aware of it.