Last updated: 18 August 2026
Version: 2.0
1. Data Controller
- COR NET d.o.o.
- Kneza Višeslava 14, 88 000 Mostar, Bosnia and Herzegovina
- Phone: +387 36 833 468
- E-mail: info@cor-net.net
- Registration number: 58-01-0103-14
- ID number: 4227838740005
2. EU Representative (Article 27 GDPR)
- Softly d.o.o.
- Trondheimska 4D, 21000 Split, Republic of Croatia
- E-mail: compliance@softlyst.eu
The Representative acts as a contact point for questions concerning the processing of personal data of data subjects in the European Union and for communications with competent supervisory authorities on behalf of COR NET d.o.o.
3. Scope and legal framework
This Privacy Policy applies to the publicly accessible website cmedia.cor-net.net, including the public C‑Media offering pages and, when enabled, user-account, webshop and C‑Media service functionality. It explains what personal data we process, for which purposes, on what legal basis, for how long, and what rights you have.
Merely using the website does not constitute consent to the processing of personal data. Where consent is required, we obtain it separately and through an explicit action, for example through cookie settings or a separate checkbox on a form.
Processing is carried out in accordance with the Personal Data Protection Act of Bosnia and Herzegovina (“Official Gazette of BiH”, No. 12/25), applicable from 4 October 2025, and, where applicable, Regulation (EU) 2016/679 (GDPR) and other applicable laws.
C‑Media involves two distinct types of processing: (1) processing relating to visitors of the public website and (2) processing relating to a user account, contracted C‑Media service and the purchase of digital licences when those functions are enabled. The public shop may temporarily be unavailable or under preparation; the provisions on purchases and payments apply only when you actually use such functionality.
4. Personal data we process and why
4.1. Technical data and server logs
When you access the website, technical information may be logged automatically, including IP address, date and time, requested URL/file, HTTP status, amount of data transferred, browser and operating-system information and referrer where available.
Purpose and legal basis: technical operation, security, prevention of misuse, diagnostics and performance improvement, based on COR NET d.o.o.’s legitimate interests.
Retention: traffic and security logs are retained for no longer than 12 months unless required for a security incident, investigation or legal claim.
4.2. Cookies, analytics, WooCommerce and Sourcebuster
C‑Media uses essential and functional cookies for security, language settings, consent management and, where enabled, user login, session maintenance and webshop functions. This may include WordPress/WooCommerce login, cart and session cookies and Sourcebuster cookies used to record the traffic source and campaign.
We may use Google Analytics or other analytics tools to measure website usage. Optional analytics and marketing cookies are used only where there is an appropriate legal basis and, where required, after your consent.
If Stripe checkout is enabled, Stripe may set security cookies such as __stripe_mid and __stripe_sid to support secure payment processing and fraud prevention.
The current list of cookies, durations and purposes is available in the C‑Media Cookie Policy.
4.3. Contact, demo and business enquiries
If you contact us about sales, a demonstration, a general enquiry or support, we may process your name, company name, e-mail address, phone number, message content and other information you voluntarily provide.
Purpose and legal basis: responding to the enquiry, arranging a demonstration, preparing a proposal or business relationship and providing support, based on legitimate interests and, where applicable, steps taken prior to entering into a contract.
Retention: where no business relationship is established, data is normally deleted within 30 days after communication ends; if a relationship is established, relevant data becomes part of business records.
4.4. C‑Media user accounts and service usage
If you use the C‑Media service or a user account, we may process:
- first and last name, if provided;
- e-mail address and authentication data (for example, a securely stored password record);
- last or other relevant IP addresses and session information;
- service-usage and traffic data within the C‑Media application, technical logs and events needed for operation, security and support;
- organisation, licence, subscription or contracted-service information;
- information required for invoicing and business records.
Purpose and legal basis: performance of a contract and provision of the C‑Media service, account/licence/subscription management, service notices, customer support, security, fraud prevention, service improvement and compliance with accounting and tax obligations.
Retention: data required for an active account and service is retained for the duration of the contractual relationship. After termination, some data is deleted or anonymised, while accounting, tax and other business records are retained for the periods required by law and internal policies.
4.5. Purchases of digital licences and payments
When the C‑Media webshop/checkout is enabled and you purchase a digital licence or other service, we may process order details, the product/licence, amount and currency, transaction status, customer name/company, billing address, e-mail address, tax information where required and transaction identifiers.
Payment-card data is processed by an authorised payment service provider such as Stripe Payments Europe, Limited. COR NET d.o.o. does not store the full payment-card number, CVC/CVV or other sensitive card data entered directly into the payment provider’s secure system.
Legal basis: performance of a contract, statutory accounting/tax obligations and legitimate interests in fraud prevention and transaction security. Retention: order and invoice data is retained in accordance with statutory business and accounting retention periods.
4.6. Content uploaded by C‑Media business customers
C‑Media allows business customers to manage and display media content. If a customer uploads content containing personal data of third parties, COR NET d.o.o. will generally process such data as a processor on the business customer’s instructions, while the business customer determines the purpose and legal basis and is responsible for the lawfulness of the content. Such processing should be governed by an appropriate Data Processing Agreement (DPA).
4.7. Newsletter and marketing communications
If you subscribe to a newsletter or marketing communications, we process your e-mail address and other information you voluntarily provide. Message interactions may be measured if that feature is enabled. The legal basis is consent, which you may withdraw at any time.
4.8. Video surveillance at our premises
If you visit COR NET d.o.o. premises, the area may be covered by video surveillance to protect persons and property and ensure visitor safety. Recordings are kept for no longer than 30 days unless needed for an official investigation, proceeding or legal claim.
5. Recipients and international transfers
Depending on the feature you use, recipients may include hosting and IT infrastructure providers, analytics providers, e-mail/newsletter services, payment providers, external IT contractors, accounting and legal advisers and competent public authorities.
Known providers may include Google Ireland Ltd. (analytics, when enabled), Stripe Payments Europe, Limited, Ireland (payments, when checkout is enabled), Meta Platforms Ireland Ltd. (if Meta/WhatsApp functionality is enabled), and Softly d.o.o., Croatia as our EU Representative.
C‑Media web infrastructure may include servers located in the Netherlands. Where data is transferred outside Bosnia and Herzegovina, we apply the lawful transfer mechanisms and contractual safeguards required by applicable law.
6. Other rights and information
Data subject rights
- right of access – to obtain confirmation whether we process your personal data and, where applicable, a copy of the data and information about the processing;
- right to rectification of inaccurate data and completion of incomplete data;
- right to erasure where the statutory conditions are met;
- right to restriction of processing in the cases provided by law;
- right to object to processing based on legitimate interests;
- right to data portability where processing is based on consent or a contract and is carried out by automated means;
- right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
- right to lodge a complaint with a supervisory authority. If you are located in the European Union, you may also lodge a complaint with the supervisory authority of the Member State of your habitual residence, place of work or place of the alleged infringement.
You may submit a request to info@cor-net.net or by post to our registered office. To protect your data, we may request additional information reasonably necessary to verify your identity. Exercising your rights is generally free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, we may charge a reasonable fee or refuse to act, as permitted by law.
We will respond without undue delay and no later than 30 days after receiving your request. This period may be extended by up to two additional months where necessary because of the complexity or number of requests; if so, we will inform you of the extension and the reasons within the initial period.
Automated decision-making and profiling
We do not use the public website for solely automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you. If such processing is introduced, this Policy will be updated before it is used.
Withdrawal of consent
Where processing is based on consent, you may withdraw that consent at any time, for example through cookie settings, an unsubscribe link in a newsletter, or by emailing info@cor-net.net. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Further cookie information is available in our Cookie Policy.
Children
Our websites and services are primarily intended for business users and persons aged 18 or over. We do not knowingly collect children’s personal data through the public website. If you believe that a child has provided personal data without an appropriate legal basis, please contact us so that we can take appropriate action.
Data security
We apply appropriate technical and organisational measures proportionate to the risk, including:
- restricted physical and logical access to systems and data;
- access control through user accounts, passwords and roles;
- firewalls, antivirus and other security tools;
- SSL/TLS encryption (HTTPS) for data in transit;
- encryption and pseudonymisation where appropriate;
- regular backups;
- contractual confidentiality obligations for employees and contractors;
- regular testing, assessment and improvement of the effectiveness of security measures.
Personal data breaches
If a personal data breach occurs, we follow our internal information-security incident procedure and applicable law. Where the breach is likely to result in a risk to individuals’ rights and freedoms, we notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of it. We notify affected individuals where required by law.
Links to other websites
Our website may contain links to third-party websites, including social networks, partners and clients. Once you leave our website, the privacy policy of the third-party operator applies. COR NET d.o.o. does not control those third parties’ privacy practices.
Complaints, questions and requests
For privacy questions or requests, contact us at info@cor-net.net, phone +387 36 833 468, or by post at COR NET d.o.o., Kneza Višeslava 14, 88 000 Mostar, Bosnia and Herzegovina.
If you believe your rights have been infringed, you have the right to lodge a complaint with the Personal Data Protection Agency in Bosnia and Herzegovina (AZLP), Dubrovačka 6, 71000 Sarajevo; phone +387 33 726-250; e-mail azlpinfo@azlp.ba; web www.azlp.ba.
The contact details +387 33 726-258 and szzp@azlp.ba refer to the Data Protection Officer of the Agency (AZLP), not a Data Protection Officer of COR NET d.o.o.
Changes to this Privacy Policy
We may update this Policy from time to time to reflect changes to our services, technology, legal requirements or security measures. The updated version will be published on this page with a revised “Last updated” date. Where changes are material, we will provide an additional notice where appropriate.