Introduction
As part of our IT consulting, tax, IT security, project portfolio management, and GDPR compliance activities, we are committed to protecting the confidentiality and security of the personal data of our clients, partners, and users of our website. This privacy policy aims to inform you about how we collect, use, and protect your personal data.
Data Controller
The data controller is:
D2F Compliant D.O.O
Radnička 41, 11000 Belgrade SERBIA
contact@d2fcompliant.com
[SIRET/Identification Number if applicable]
Personal Data Collected
As part of our services, we may collect the following data:
Identification Data: last name, first name, postal address, email address, telephone number.
Professional Data: position, company name, industry sector.
Contractual Data: information related to consulting services, quotes, invoices, contracts. Technical data: IP address, browser type, operating system, browsing data. Sensitive data (if applicable): only for GDPR-compliant tasks with explicit and justified consent.
Purposes of processing
Data is processed for the following purposes:
Provision of consulting services (IT, tax, IT security, project management, GDPR);
Monitoring of contractual and commercial relationships;
Conducting security or compliance audits and analyses;
Managing invoicing and accounting obligations;
Sending information, news, or commercial proposals (with your consent);
Continuous improvement of our services and security of our website.
Legal basis for processing
Processing is carried out on the following legal bases:
Execution of a contract or pre-contractual measures;
Compliance with legal or regulatory obligations;
Legitimate interest (security, improvement of services);
Explicit consent, when required (e.g., sending newsletters, processing certain GDPR data).
Data Recipients
Data may be communicated to:
Our employees or partners as strictly necessary for the mission;
Technical service providers (hosting providers, collaborative tools, secure cloud solutions);
Administrative or judicial authorities, in the event of a legal obligation.
No data transfer outside the European Union is made without appropriate safeguards.
Retention Period
Data is retained for:
The duration of the contractual relationship + 5 years;
10 years for accounting and tax data;
Until consent is withdrawn for marketing communications.
Data Security
We implement security measures appropriate to the nature of the data processed, including:
Encryption of sensitive data;
Restricted and controlled access to information;
Regular backups;
Compliance audit and security testing (penetration, code review, etc.).
Your Rights
In accordance with the GDPR, you have the following rights:
Right of access to your data;
Right of rectification;
Right to erasure (right to be forgotten);
Right to restriction of processing;
Right to object;
Right to data portability;
Right to determine the fate of your data after your death.
To exercise your rights: [GDPR/DPO dedicated email address].
You can also file a complaint with the CNIL (French Data Protection Authority): www.cnil.fr
Cookies
Our website uses cookies for strictly technical and analytical purposes. You can manage or refuse their use via the cookie management banner or your browser settings.
For more information, see our [Cookie Policy].
Policy Updates
We reserve the right to modify this policy to reflect legal or technical developments. The latest version is always available on our website.
Last updated: April 25, 2025