Our Solutions

Book a Free C-Media Demo Today

Discover how our content management software can transform your business and drive revenue.
  • Get in touch

    Last updated: 18 August 2026

    Version: 2.0

    1. Data Controller

    2. EU Representative (Article 27 GDPR)

    The Representative acts as a contact point for questions concerning the processing of personal data of data subjects in the European Union and for communications with competent supervisory authorities on behalf of COR NET d.o.o.

    3. Scope and legal framework

    This Privacy Policy applies to the publicly accessible website cmedia.cor-net.net, including the public C‑Media offering pages and, when enabled, user-account, webshop and C‑Media service functionality. It explains what personal data we process, for which purposes, on what legal basis, for how long, and what rights you have.

    Merely using the website does not constitute consent to the processing of personal data. Where consent is required, we obtain it separately and through an explicit action, for example through cookie settings or a separate checkbox on a form.

    Processing is carried out in accordance with the Personal Data Protection Act of Bosnia and Herzegovina (“Official Gazette of BiH”, No. 12/25), applicable from 4 October 2025, and, where applicable, Regulation (EU) 2016/679 (GDPR) and other applicable laws.

    C‑Media involves two distinct types of processing: (1) processing relating to visitors of the public website and (2) processing relating to a user account, contracted C‑Media service and the purchase of digital licences when those functions are enabled. The public shop may temporarily be unavailable or under preparation; the provisions on purchases and payments apply only when you actually use such functionality.

    4. Personal data we process and why

    4.1. Technical data and server logs

    When you access the website, technical information may be logged automatically, including IP address, date and time, requested URL/file, HTTP status, amount of data transferred, browser and operating-system information and referrer where available.

    Purpose and legal basis: technical operation, security, prevention of misuse, diagnostics and performance improvement, based on COR NET d.o.o.’s legitimate interests.

    Retention: traffic and security logs are retained for no longer than 12 months unless required for a security incident, investigation or legal claim.

    4.2. Cookies, analytics, WooCommerce and Sourcebuster

    C‑Media uses essential and functional cookies for security, language settings, consent management and, where enabled, user login, session maintenance and webshop functions. This may include WordPress/WooCommerce login, cart and session cookies and Sourcebuster cookies used to record the traffic source and campaign.

    We may use Google Analytics or other analytics tools to measure website usage. Optional analytics and marketing cookies are used only where there is an appropriate legal basis and, where required, after your consent.

    If Stripe checkout is enabled, Stripe may set security cookies such as __stripe_mid and __stripe_sid to support secure payment processing and fraud prevention.

    The current list of cookies, durations and purposes is available in the C‑Media Cookie Policy.

    4.3. Contact, demo and business enquiries

    If you contact us about sales, a demonstration, a general enquiry or support, we may process your name, company name, e-mail address, phone number, message content and other information you voluntarily provide.

    Purpose and legal basis: responding to the enquiry, arranging a demonstration, preparing a proposal or business relationship and providing support, based on legitimate interests and, where applicable, steps taken prior to entering into a contract.

    Retention: where no business relationship is established, data is normally deleted within 30 days after communication ends; if a relationship is established, relevant data becomes part of business records.

    4.4. C‑Media user accounts and service usage

    If you use the C‑Media service or a user account, we may process:

    Purpose and legal basis: performance of a contract and provision of the C‑Media service, account/licence/subscription management, service notices, customer support, security, fraud prevention, service improvement and compliance with accounting and tax obligations.

    Retention: data required for an active account and service is retained for the duration of the contractual relationship. After termination, some data is deleted or anonymised, while accounting, tax and other business records are retained for the periods required by law and internal policies.

    4.5. Purchases of digital licences and payments

    When the C‑Media webshop/checkout is enabled and you purchase a digital licence or other service, we may process order details, the product/licence, amount and currency, transaction status, customer name/company, billing address, e-mail address, tax information where required and transaction identifiers.

    Payment-card data is processed by an authorised payment service provider such as Stripe Payments Europe, Limited. COR NET d.o.o. does not store the full payment-card number, CVC/CVV or other sensitive card data entered directly into the payment provider’s secure system.

    Legal basis: performance of a contract, statutory accounting/tax obligations and legitimate interests in fraud prevention and transaction security. Retention: order and invoice data is retained in accordance with statutory business and accounting retention periods.

    4.6. Content uploaded by C‑Media business customers

    C‑Media allows business customers to manage and display media content. If a customer uploads content containing personal data of third parties, COR NET d.o.o. will generally process such data as a processor on the business customer’s instructions, while the business customer determines the purpose and legal basis and is responsible for the lawfulness of the content. Such processing should be governed by an appropriate Data Processing Agreement (DPA).

    4.7. Newsletter and marketing communications

    If you subscribe to a newsletter or marketing communications, we process your e-mail address and other information you voluntarily provide. Message interactions may be measured if that feature is enabled. The legal basis is consent, which you may withdraw at any time.

    4.8. Video surveillance at our premises

    If you visit COR NET d.o.o. premises, the area may be covered by video surveillance to protect persons and property and ensure visitor safety. Recordings are kept for no longer than 30 days unless needed for an official investigation, proceeding or legal claim.

    5. Recipients and international transfers

    Depending on the feature you use, recipients may include hosting and IT infrastructure providers, analytics providers, e-mail/newsletter services, payment providers, external IT contractors, accounting and legal advisers and competent public authorities.

    Known providers may include Google Ireland Ltd. (analytics, when enabled), Stripe Payments Europe, Limited, Ireland (payments, when checkout is enabled), Meta Platforms Ireland Ltd. (if Meta/WhatsApp functionality is enabled), and Softly d.o.o., Croatia as our EU Representative.

    C‑Media web infrastructure may include servers located in the Netherlands. Where data is transferred outside Bosnia and Herzegovina, we apply the lawful transfer mechanisms and contractual safeguards required by applicable law.

    6. Other rights and information

    Data subject rights

    You may submit a request to info@cor-net.net or by post to our registered office. To protect your data, we may request additional information reasonably necessary to verify your identity. Exercising your rights is generally free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, we may charge a reasonable fee or refuse to act, as permitted by law.

    We will respond without undue delay and no later than 30 days after receiving your request. This period may be extended by up to two additional months where necessary because of the complexity or number of requests; if so, we will inform you of the extension and the reasons within the initial period.

    Automated decision-making and profiling

    We do not use the public website for solely automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you. If such processing is introduced, this Policy will be updated before it is used.

    Withdrawal of consent

    Where processing is based on consent, you may withdraw that consent at any time, for example through cookie settings, an unsubscribe link in a newsletter, or by emailing info@cor-net.net. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Further cookie information is available in our Cookie Policy.

    Children

    Our websites and services are primarily intended for business users and persons aged 18 or over. We do not knowingly collect children’s personal data through the public website. If you believe that a child has provided personal data without an appropriate legal basis, please contact us so that we can take appropriate action.

    Data security

    We apply appropriate technical and organisational measures proportionate to the risk, including:

    Personal data breaches

    If a personal data breach occurs, we follow our internal information-security incident procedure and applicable law. Where the breach is likely to result in a risk to individuals’ rights and freedoms, we notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of it. We notify affected individuals where required by law.

    Links to other websites

    Our website may contain links to third-party websites, including social networks, partners and clients. Once you leave our website, the privacy policy of the third-party operator applies. COR NET d.o.o. does not control those third parties’ privacy practices.

    Complaints, questions and requests

    For privacy questions or requests, contact us at info@cor-net.net, phone +387 36 833 468, or by post at COR NET d.o.o., Kneza Višeslava 14, 88 000 Mostar, Bosnia and Herzegovina.

    If you believe your rights have been infringed, you have the right to lodge a complaint with the Personal Data Protection Agency in Bosnia and Herzegovina (AZLP), Dubrovačka 6, 71000 Sarajevo; phone +387 33 726-250; e-mail azlpinfo@azlp.ba; web www.azlp.ba.

    The contact details +387 33 726-258 and szzp@azlp.ba refer to the Data Protection Officer of the Agency (AZLP), not a Data Protection Officer of COR NET d.o.o.

    Changes to this Privacy Policy

    We may update this Policy from time to time to reflect changes to our services, technology, legal requirements or security measures. The updated version will be published on this page with a revised “Last updated” date. Where changes are material, we will provide an additional notice where appropriate.