Privacy Policy
Website: juristbiro.com
Last updated: 31 August 2026.
This Privacy Policy explains which personal data we collect when you use the juristbiro.com website, for which purposes we process it, with whom we share it, how long we keep it and which rights you have in relation to your data.
1. Who is the data controller
The controller of personal data collected through the juristbiro.com website is:
JURIST SOFT DOO NIŠ-CRVENI KRST
Registered office: Aleksandra Medvedeva bb, 18000 Niš (Crveni Krst), Republic of Serbia
Company registration number: 21637483 | Tax ID (PIB): 112261125
Contact for privacy matters: contact form at juristsoft.com
For all matters not expressly governed by this Privacy Policy, the General Terms of Use of the JuristBiro platform apply. This Policy and any disputes relating to the processing of data are governed by the law of the Republic of Serbia, with the agreed jurisdiction of the court in Niš.
2. Which data we collect
2.1 Data you provide to us yourself
We do not ask for your first and last name when you register an account. The website has no contact form, no request-for-quote form and no newsletter sign-up.
| Data | When it is entered |
|---|---|
| E-mail address | Registration, sign-in, password reset, account deletion request |
| Password | Registration (stored exclusively as a hash), sign-in, opening an employee account at an employer's invitation |
| Company name | Registration |
| Telephone | Registration (optional) |
| „How did you hear about us“ | Registration (optional) |
After registration, before the application is first used, you go through a short initial setup in which company data (name, company registration number, tax ID and the name of the legal representative) and the first employee (first and last name) are entered. We process that data on the instructions of the company that opened the account, in the role of a processor – see section 11.
2.2 Data we collect automatically
- Server logs: IP address, user agent (browser/operating system/device), visited URL, referring page, time of visit.
- WAF (protection against abuse): IP address and the decision of the system (allowed/blocked).
- Rate limiting: the IP address is temporarily (15 minutes to 1 hour) kept in the server cache in order to limit the number of sign-in attempts, password reset requests and account deletion requests.
- Signals for Google reCAPTCHA v3: on the pages for sign-in, registration (including opening an account by invitation), password reset and account deletion request, Google receives the IP address and technical browser signals in order to distinguish humans from bots.
- Password security check (Have I Been Pwned): while you type a password during registration, reset or password change, your browser – and, when the password is saved, our server as well – sends the first 5 hexadecimal characters of the SHA-1 hash of the password (never the password itself) to the api.pwnedpasswords.com service, so that we can warn you if the password is known from a data breach. Your actual password is neither transmitted nor disclosed; the password cannot be reconstructed from those 5 characters.
We do not collect location/GPS data. The website does not use browser geolocation.
3. Why we process your data and on which legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and maintaining a user account (14-day trial period) | E-mail, password, company name, telephone, how you heard about us | Performance of a contract / steps taken prior to entering into a contract |
| Sign-in, password reset, account deletion | Performance of a contract | |
| Protecting accounts and forms against abuse (CSRF, reCAPTCHA, password check, rate limiting) | Session data, IP address, browser signals, partial password hash | Legitimate interest – system security |
| Notifying administrators of a new registration | E-mail, company name, telephone (sent in an internal notification; not stored additionally) | Legitimate interest – operational functioning of the service |
| Measuring traffic on public pages | Pseudonymised daily identifier (hash of the IP address and the browser), UTM/gclid parameters | Legitimate interest – analytics without identifying the user |
| Measuring the effectiveness of Google ads (offline conversions) | gclid and the time of registration (without an e-mail address or other personal data) | Legitimate interest – measuring marketing effectiveness |
| Keeping security logs | IP address, time, URL, status, referrer, user agent | Legitimate interest – security and prevention of abuse |
4. Cookies and similar technologies
The juristbiro.com website uses only one first-party cookie and does not use any analytical or marketing cookie. For that reason the website has no cookie consent banner – nothing is written to your device for analytical or marketing purposes without your knowledge.
PHPSESSID (our own, strictly necessary cookie)
- Purpose: maintaining the session during sign-in/registration and while working in the application, protecting forms against abuse (CSRF), remembering the selected language within the session.
- Where it is set: on the pages for sign-in, registration, password reset and account deletion request, and in the application after sign-in. No cookie whatsoever is set on the public pages (home, pricing, templates, this page).
- Duration: until the browser is closed; the session on the server expires after 24 minutes of inactivity.
- Attributes: Secure, HttpOnly, SameSite=Lax.
- Category: strictly necessary.
jb.lang (localStorage, not a cookie)
- Purpose: remembering the language you selected (Serbian, English, Slovenian).
- Where it is set: public pages.
- Duration: until you delete it from the browser.
- Category: functional; it contains no personal data and is not sent to the server.
Google reCAPTCHA (third-party cookie, e.g. _GRECAPTCHA)
- Purpose: protecting forms against automated abuse (bots).
- Who processes it: Google LLC processes the IP address and technical data about the browser.
- Where it is set: the pages for sign-in, registration, password reset and account deletion request.
- Duration: determined by Google (approximately 6 months).
- Category: third-party security cookie.
What the website does NOT use
- Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Insight, Hotjar or similar tracking tools.
- Marketing or remarketing cookies.
- A „remember me“ cookie.
Traffic measurement without cookies
We measure traffic on the public pages with our own system (jbstat), which uses no cookies and runs on our infrastructure. Each visitor is assigned a temporary identifier obtained by hashing (SHA-256) the IP address, browser data, the date, the domain and a secret value (salt). This identifier changes every day and cannot be linked to a specific person; the IP address is not stored in readable form. The script is not loaded inside the application after sign-in. Individual page-view records are deleted after 12 months (section 7).
5. With whom we share data
We do not sell your data. We share it exclusively with service providers who help us run the website, and only to the extent necessary for that purpose:
| Recipient | Role | Data shared |
|---|---|---|
| AWS (Amazon Web Services) | Hosting, database, logs, sending internal notifications (SNS) | All data listed in sections 2.1 and 2.2 |
| Mailgun (EU) | Sending verification, reset and confirmation e-mail messages | E-mail address |
| Google reCAPTCHA | Protection against bots | IP address, technical browser signals |
| Google Ads | Measuring ad effectiveness (offline conversions) | gclid, time of registration (pseudonymised) |
| Have I Been Pwned / Cloudflare | Checking that the password is not known from earlier data breaches | The first 5 characters of the SHA-1 hash of the password; the IP address of the browser (check from the browser) or of our server (check on the server) |
| jbstat | Our own traffic analytics (on our infrastructure) | Pseudonymised daily identifier, UTM/gclid |
6. Transfer of data outside the Republic of Serbia
Part of the data is processed outside the Republic of Serbia:
- Germany (Frankfurt, AWS eu-central-1 region, EU): hosting, database, file storage and logs.
- Mailgun: e-mail infrastructure hosted on EU servers (the parent company Sinch is from the USA).
- Google (USA): reCAPTCHA and Google Ads.
- Cloudflare / Have I Been Pwned (USA): password security checks.
Where data is transferred outside the European Economic Area, we rely on the appropriate safeguards provided for by the applicable data protection regulations (e.g. standard contractual clauses or adequacy decisions), to the extent that our service providers ensure them.
7. How long we keep data
| Data | Retention period |
|---|---|
| Session (PHPSESSID) | Until the browser is closed / max. 24 minutes of inactivity on the server |
| Rate-limiting counters (IP address) | 15 minutes to 1 hour |
| Password reset link and verification link | 1 hour |
| Account deletion token | 48 hours; after confirmation, a 7-day grace period, then anonymisation of the account |
| Server logs (Apache) | Around 30 days locally (weekly rotation, 4 archives) + 30 days in CloudWatch |
| WAF logs | 30 days (CloudWatch) |
| Account data (registration) | Until the user requests deletion (after which it is anonymised); expired trial accounts are not deleted automatically |
| jbstat – individual page views (pseudonymised daily identifier) | 12 months, then deleted |
| jbstat – conversion data (time of registration, UTM/gclid; without personal data) | Permanently, for statistical purposes |
8. Your rights
In relation to your personal data you have the right to:
- access the data we process about you;
- request the rectification of inaccurate data;
- request the erasure of data (through the account deletion feature on the website or by a direct request);
- request the restriction of processing;
- object to processing based on legitimate interest (e.g. analytics, ad measurement);
- request data portability, where this is technically feasible;
- lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia, if you consider that the processing of your data has been carried out contrary to the regulations.
You can submit requests through the contact form at juristsoft.com.
9. Data security
- All traffic with the website takes place over an HTTPS/TLS connection (AWS Application Load Balancer); forms are transmitted in encrypted form.
- The PHPSESSID cookie is set with the Secure, HttpOnly and SameSite=Lax attributes.
- Passwords are stored exclusively as hashes; when a password is chosen, it is checked that it is not known from earlier data breaches.
- Access to the infrastructure (SSH) is restricted to allowed IP addresses.
- Only authorised persons (system administrators) and the service providers listed in section 5, in the role of data processors, have access to the data.
- A Web Application Firewall (WAF) is used to protect against automated attacks.
- The most sensitive employee data entered into the platform (section 11) – personal identification number, ID card and passport number, address, bank account, salary amount and similar – is encrypted with a key held by the Service User; the key is not stored permanently on the server but exists only within the Service User's session, so without it that data is not readable.
10. Third-party scripts on public pages
Only three external scripts are loaded on the public pages of the website:
- www.google.com/recaptcha/api.js – on the pages for sign-in, registration, password reset and account deletion request;
- s.juristbiro.com/s.js – our own script for traffic measurement (without cookies), on the public pages and the sign-in/registration pages; it is not loaded inside the application;
- api.pwnedpasswords.com – called only while the user is entering a password, for a security check.
All other resources (Bootstrap, jQuery, the Inter font and similar) are loaded locally from our server – we do not use Google Fonts or other CDN services.
11. The JuristBiro platform – processing of employee data (the role of processor)
The website is the entry point to the JuristBiro platform, intended exclusively for legal entities and entrepreneurs: HR records, payroll, employment-law documentation, absences and working-time records – including the TEMPUS by Jurist Soft mobile application and the attendance terminal. A different division of roles applies to the data of employees and engaged personnel that the Service User enters into the platform (starting with the initial setup from section 2.1):
- The Service User (the legal entity or entrepreneur who opened the account) has the status of Controller of the data of its employees and engaged personnel.
- Jurist Soft acts exclusively as the Processor, which processes the data on the instructions and directions of the Service User, on technical infrastructure hosted in Frankfurt, Germany (AWS).
Within working-time records, the following may also be processed if the Service User enables them:
- location data for the purpose of confirming presence at the workplace – the Service User defines the coordinates and the radius of the workplace, and an attendance check-in is verified against them; the coordinates of a successful check-in are not stored, while for a refused check-in (outside the permitted radius) the coordinates and the distance are stored so that the Service User can review them;
- biometric verification of identity on the employee's device – the biometrics themselves (fingerprint, face) remain on the device and are processed by the device's operating system; the platform receives only the confirmation that the verification succeeded and stores the enrolment status, the identifier of the approved device and the history of changes to that status;
- for mobile application sessions: the IP address and device data (user agent) together with the session token, for account security.
The conditions of processing within the platform – including the obligations of the Service User regarding the legal basis, informing employees and the data protection impact assessment – are governed by the General Terms of Use and by the special terms for individual modules, which supplement this Policy: TEMPUS (Android), TEMPUS (iOS), the attendance terminal.
12. Minors
The website and the service are not intended for minors. We do not knowingly collect data of minors.
13. Changes to this policy
We may update this Privacy Policy from time to time, for example due to changes in the way the website operates or in legal regulations. The date of the last change is stated at the top of this document. Where necessary, we will also notify you of more significant changes via the e-mail address registered with your account.
14. Contact
For all questions relating to this Privacy Policy or to the processing of your personal data, you can contact us at:
JURIST SOFT DOO NIŠ-CRVENI KRST
Contact form: juristsoft.com/contact
Address: Aleksandra Medvedeva bb, 18000 Niš (Crveni Krst), Republic of Serbia
Company registration number: 21637483 | Tax ID (PIB): 112261125