Skip to main content
Wine Vision
Home

Data Protection Policy

Effective Date: May 15, 2026

Wine Vision by Open Balkan is committed to protecting personal data responsibly. This Data Policy outlines the principles and guidelines for handling personal data in compliance with the General Data Protection Regulation (GDPR) and the Serbian Law on Personal Data Protection. The core principles that guide our approach are: Lawfulness, Fairness & Transparency; Purpose Limitation; Data Minimization; Accuracy; Storage Limitation; Integrity & Confidentiality; and Accountability.


1. Lawfulness, Fairness and Transparency

Personal data is processed lawfully, ensuring a valid legal basis exists for every processing activity — whether consent, contractual necessity, legal obligation, or legitimate interest. Fairness is maintained by never using data in ways that individuals would not reasonably expect. Transparency is achieved through a publicly accessible Privacy Policy, cookie notices, and clear notices on data-collection forms. Explanations are written in plain language and avoid unnecessary jargon so that individuals can make informed decisions about their data.


2. Purpose Limitation

Data is collected only for specific, explicit, and legitimate purposes that are clearly communicated at the point of collection. Registration data, for example, is used to serve the following purposes:

  • Event organization and logistics
  • Account management and participant communication
  • Marketing and promotional activities (where consent has been obtained)
  • Service improvement and analytics

Data is never repurposed without a new, compatible legal basis or renewed consent. Whenever a new processing purpose arises, affected individuals are notified in advance and, where required, asked to provide explicit consent before processing commences.


3. Data Minimization

Only data that is necessary and proportionate to the stated purpose is collected. Optional fields are clearly marked so individuals understand what is required versus voluntary. Irrelevant or excessive data fields are not included in forms or databases. Processing activities are periodically reviewed to identify and eliminate data items that are no longer necessary. Internal access to personal data is restricted to staff members who require it to fulfil their responsibilities.


4. Accuracy

Reasonable steps are taken to ensure that personal data held is accurate, complete, and up-to-date. Individuals can correct inaccurate data at any time by contacting the organization at [email protected] or by updating their account settings directly. Pre-event communications may include requests for participants to verify and update their details. Data that is found to be inaccurate is promptly rectified or, where rectification is not possible, deleted without undue delay.


5. Storage Limitation

Personal data is retained only for as long as it is necessary to fulfil the purposes for which it was collected. Specific retention schedules are documented in the Privacy Policy. Once the retention period expires, data is securely anonymized or permanently deleted. Data that must be kept to satisfy a legal or regulatory obligation is retained only for the minimum period required by the applicable statute. Internal databases are reviewed periodically to identify and purge records that have passed their retention date. Backup systems are subject to finite retention windows, and backups containing personal data are securely destroyed when the retention period ends.


6. Integrity and Confidentiality

Technical Measures

All data in transit is protected using SSL/TLS encryption. Server infrastructure is protected by firewalls and anti-malware software that is kept up-to-date. Sensitive identifiers are pseudonymized where technically feasible, and account passwords are stored using strong one-way hashing algorithms.

Access Control

Access to personal data is governed by role-based access controls, ensuring that staff can access only the data required for their specific function. Strong password policies are enforced across all internal systems. Two-factor authentication (2FA) is required for any remote access to systems that hold personal data. Physical server facilities are secured against unauthorized entry.

Organizational Policies

Documented internal policies govern how personal data is handled, stored, and shared. All staff receive data protection training commensurate with their role. Subcontractors and third-party processors are bound by confidentiality agreements and data processing clauses before being granted access to personal data.

Incident Response

A documented breach response plan is maintained and regularly tested. In the event of a personal data breach, the relevant supervisory authority is notified within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk to the rights and freedoms of individuals, those individuals are notified directly without undue delay.

Testing and Audits

Periodic vulnerability assessments and penetration tests are conducted to identify weaknesses in systems that handle personal data. Access logs are monitored for anomalous activity. External security audits are commissioned on a regular basis to provide independent assurance.

Secure Development

Secure coding practices are followed throughout the software development lifecycle to prevent vulnerabilities such as SQL injection and cross-site scripting (XSS). Hardware and storage media that reach end-of-life are subject to secure data-wiping procedures before decommissioning or disposal.


7. Accountability

A designated privacy coordinator is responsible for tracking processing activities and ensuring compliance with this policy. A Record of Processing Activities is maintained in accordance with GDPR Article 30, documenting the purposes, legal bases, data categories, recipients, and retention periods for each processing activity.

Data Protection Impact Assessments

A Data Protection Impact Assessment (DPIA) is carried out before commencing any processing activity that is likely to result in a high risk to the rights and freedoms of individuals — for example, large-scale profiling or the introduction of new surveillance technologies.

Third-Party Management

All third-party processors are carefully vetted before engagement. Data Processing Agreements are executed with each processor, setting out their obligations under GDPR. Ongoing compliance is monitored, and processors that fall short of required standards are addressed through corrective action or contract termination.

Staff are encouraged to report compliance concerns promptly through internal channels. Procedures for handling data subject rights requests — including access, rectification, erasure, and portability — are documented and tested. Annual compliance reviews assess the effectiveness of controls and drive continuous improvement.


8. Rights of Data Subjects

Consent and Choice

Where consent is the legal basis for processing, it is obtained in a manner that is freely given, specific, informed, and unambiguous. Consent is captured via explicit opt-in checkboxes; pre-ticked boxes are never used. Individuals can withdraw consent at any time via unsubscribe links in marketing communications or by contacting the organization directly, with no adverse consequences.

Children's Data

Under Serbian law, individuals under the age of 15 require parental or guardian consent before their personal data can be processed. Where services may be used by children, age-appropriate explanations of data use are provided, and consent mechanisms are designed to be verifiable.

Privacy by Design and Default

Privacy considerations are embedded into the design of new features and services from the outset, rather than being added as an afterthought. By default, user profiles and data-sharing settings are configured to the highest level of protection available — personal data is not made publicly accessible without an affirmative choice by the individual.

Continuous Improvement

Feedback from individuals on data-handling practices is welcomed and actively considered. Emerging industry best practices and regulatory guidance are monitored and evaluated for adoption where they would improve the protection of personal data.


9. International Data Transfers

Within the Open Balkan Region

Co-organizers and partner organizations based in Serbia, North Macedonia, and Albania who receive personal data are contractually required to uphold GDPR-equivalent standards of data protection, including appropriate security measures and restrictions on onward transfer.

Outside the European Economic Area

Regardless of the citizenship or location of the data subject, personal data is treated in accordance with GDPR principles whenever it is transferred outside the EEA. Standard Contractual Clauses (SCCs) approved by the European Commission are used as the transfer mechanism where required, and where transfers to the United States are necessary, providers are required to participate in approved compliance frameworks.

Processor Oversight

Each third-party processor that handles personal data on our behalf is individually documented, including the nature of data transferred and the safeguards in place. Compliance is verified through due diligence, including review of certifications such as ISO 27001 and executed SCCs. All cross-border data flows are recorded in the Register of Processing Activities.


10. Enforcement and Review

Internal Enforcement

Employees and contractors who violate the principles set out in this Data Policy are subject to disciplinary action proportionate to the severity of the violation. Internal reporting channels are available for staff to raise data protection concerns confidentially and without fear of retaliation.

User Redress

Individuals who believe their data has been mishandled may contact the organization directly. All such complaints are investigated promptly and a substantive response is provided within a reasonable timeframe. Where an investigation reveals a breach of policy, corrective action is taken and the complainant is informed of the outcome.

Regulatory Compliance

The organization cooperates fully with supervisory authorities in the exercise of their powers, including providing requested information and implementing orders or recommendations. Data protection compliance is viewed as a continuous journey rather than a one-time exercise, and the organization actively engages with regulatory developments.

Periodic Reviews

This Data Policy and the underlying controls are reviewed at least annually. Reviews may be conducted with the assistance of external data protection experts to provide an independent perspective and ensure the policy remains aligned with evolving legal requirements and best practices.


11. Contact the Data Protection Office

For questions, concerns, or requests relating to this Data Policy or to the handling of your personal data, please contact our Data Protection Office:

Wine Vision by Open Balkan — Belgrade FairData Protection Office

Bulevar Vojvode Mišića 14, 11030 Belgrade, Serbia

Phone: +381 11 26 55 239 · +381 11 26 55 113

Email: [email protected] · Subject: "Data Policy"

Supervisory authority: Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti www.poverenik.rs

By adhering to these principles, Wine Vision by Open Balkan ensures that personal data is handled with the utmost care and respect. Data represents real people — colleagues, partners, visitors, and customers — and their privacy is treated accordingly. We are committed to upholding these standards consistently and improving our practices over time.