Corebit Studio
Back to Home

Privacy Policy

Detailed guidelines regarding the collection, processing, protection, and rights associated with your personal data at Corebit Studio.

Last updated: July 2026

1. Categories and Scope of Collected Personal Data

Corebit Studio collects personal data through two distinct channels: (a) Directly Provided Data: When you voluntarily submit a project inquiry, request a website price calculation, or initiate communication via our integrated contact forms, WhatsApp, or Telegram widgets, we collect personal details including your full name, corporate email address, telephone contact number, messenger usernames, and any project-specific descriptions you choose to disclose. (b) Automatically Collected Data: During your interaction with studio.corebitsystems.io, we collect technical log data containing your IP address, browser type and version, language configuration, operating system, referrer URLs, and network speed performance statistics. We do not gather or process sensitive personal information, biometric data, or financial credentials on this website.

2. Legitimate Purposes and Scope of Data Processing

All personal data gathered is processed strictly under the legal bases of pre-contractual negotiations, consent, and legitimate interest. Specifically, the data is used to: (a) Respond to your requests, calculate commercial offers, and coordinate contract details for web design and custom software development services. (b) Monitor website security, prevent spam transmissions, and diagnose performance bottlenecks. (c) Analyze traffic statistics to improve loading speeds. Corebit Studio enforces a strict zero-sharing policy: we never sell, lease, rent, trade, or distribute your personal details to marketing agencies, advertising networks, or third-party corporations for promotional purposes.

3. GDPR Compliance, Balkan Regulations, and User Rights

In strict compliance with the European Union General Data Protection Regulation (EU GDPR) and the Law on Personal Data Protection of Montenegro, Serbia, and Albania, users possess comprehensive rights over their data. These rights include: (a) The Right of Access to inspect what data we store. (b) The Right to Rectification to update inaccurate details. (c) The Right to Restriction of processing. (d) The Right to Portability. (e) The Right to Erasure ('Right to be Forgotten') to demand the complete deletion of your records from our databases. To exercise any of these statutory rights, please contact our data protection officer directly at corebitstudio@corebitsystems.io. We commit to responding to and processing all verified compliance requests within 30 calendar days.

4. Security Infrastructure and Data Storage Protocols

We utilize robust technical and administrative measures designed to protect your personal data against accidental loss, unauthorized access, alteration, disclosure, or destruction. All data transmissions through studio.corebitsystems.io are encrypted using Secure Socket Layer (SSL) protocols. Personal information is stored securely inside protected server environments with restricted access control lists, ensuring that only authorized personnel directly involved in client relations can inspect client data. While we implement industry-standard security measures, no digital transmission over the internet or database storage system can be guaranteed to be 100% secure, and users share information at their own risk.

5. Data Sub-Processors, Storage Limitation (Art. 5(1)(e) GDPR), and Right to Erasure

In strict compliance with GDPR Article 5(1)(e) (Storage Limitation Principle), Corebit Studio engages the following third-party data sub-processors to facilitate operational communication pipelines: (a) Meta Platforms Ireland Ltd. (WhatsApp Business Framework) — personal data routed via WhatsApp contact channels to US-based Meta infrastructure under Standard Contractual Clauses (SCC) as the approved EEA-to-third-country transfer mechanism. (b) Telegram FZ-LLC — personal data processed via Telegram notification bots operating from UAE-based infrastructure, outside the European Economic Area, on the basis of explicit user consent provided when interacting with Telegram deep-link channels. In accordance with Article 5(1)(e), personal operational data acquired via contact forms is securely retained for a strict duration of 12 months from the date of capture before undergoing automated anonymization or permanent erasure. Users retain the Right to Erasure under Article 17 of the GDPR and may request immediate deletion of all personal records at any time by contacting our Data Protection Officer at corebitstudio@corebitsystems.io.