Privacy Policy
Last Updated: 2026-08-07
This policy explains what personal data C9 Group collects through c9group.dev, why we collect it, who we share it with, how long we keep it, and what rights you have. We have tried to write it in plain language and to be specific: vague privacy policies are usually hiding something.
1. Who Is Responsible for Your Data
C9 Group is the controller of the personal data described in this policy, meaning we decide why and how it is processed.
C9 Group OÜ (Estonia)
Company registration (registrikood, Estonia): 17578890
Registered office: Tartu mnt 67/1-13b, 10115 Tallinn, Estonia
KRISTIJAN SEKEREŠ PR C9 GROUP (Serbia)
Tax identification (PIB, Serbia): 111484314
Company registration (MB, Serbia): 65445948
Registered office: Jaše Ignjatovića 7, Novi Sad, Serbia
Office: Neubergerjeva 15, Ljubljana, Slovenia
Email: office@c9group.dev
Telephone: +386 71 809 267
We apply the General Data Protection Regulation (EU) 2016/679 (GDPR) to everyone this policy covers, including visitors outside the European Union, and we also comply with the Serbian Law on Personal Data Protection.
Where we handle personal data inside systems we build or operate for a client, that client is normally the controller and we act as their processor under a written Data Processing Agreement. This policy does not govern that data: the client's own privacy notice does.
2. What We Collect
Data you give us
When you fill in a contact form, book a meeting, apply for a role, subscribe to updates, or email us, we receive what you choose to send. Typically that is your name, business email address, company name, and a description of your enquiry, plus your telephone number, job title, and links to a professional profile if you provide them.
We ask for the minimum needed to reply usefully. Please do not send us confidential or special-category personal data through a web form; if the subject is sensitive, ask us for an NDA first.
Data collected automatically
When you load a page, our infrastructure and (subject to your consent) our analytics and advertising tools receive:
- IP address and approximate location derived from it
- Browser type and version, operating system, device type, and screen size
- The page requested, the referring page, and the time of the request
- Pages viewed, time on page, and interactions during your visit
- Advertising click identifiers (`gclid`, `wbraid`, `gbraid`) and campaign parameters when you arrive from an advertisement
- Your cookie preferences
On your first visit we make a request to Cloudflare to determine your country, so we can show the site in a likely language. That request reveals your IP address to Cloudflare; we do not store the result beyond your language preference.
3. Why We Use It, and Our Legal Basis
Under the GDPR every purpose needs a lawful basis. Ours are:
| Purpose | Data used | Legal basis |
|---|---|---|
| Responding to your enquiry and preparing a proposal | Contact and enquiry details | Steps prior to a contract (Art. 6(1)(b)) or legitimate interests in responding to business enquiries (Art. 6(1)(f)) |
| Managing a client engagement, invoicing, and support | Contact and contract details | Contract performance (Art. 6(1)(b)) |
| Operating, securing, and troubleshooting this website | Request telemetry, server logs | Legitimate interests in running a secure, functioning website (Art. 6(1)(f)) |
| Measuring how the site is used so we can improve it | Analytics data | Consent (Art. 6(1)(a)) |
| Measuring advertising performance and attributing enquiries to campaigns | Advertising identifiers, campaign parameters | Consent (Art. 6(1)(a)) |
| Remembering your language and cookie choices | Preference data | Legitimate interests / strictly necessary |
| Assessing job applications | Application details | Steps prior to a contract (Art. 6(1)(b)) and consent for retention beyond the role |
| Meeting accounting, tax, and other legal obligations | Contract and billing records | Legal obligation (Art. 6(1)(c)) |
| Establishing, exercising, or defending legal claims | Whichever records are relevant | Legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You can object to that processing at any time: see Your Rights.
We do not sell personal data, and we do not share it with third parties for their own marketing.
5. Who Receives Your Data
We share personal data only with the service providers we need to run the site and reply to you. Each acts under a data processing agreement and may use the data only on our instructions.
| Recipient | Purpose | Location | Set only with consent |
|---|---|---|---|
| Amazon Web Services | Hosting and content delivery for this website | Application and storage in Frankfurt, Germany (eu-central-1); edge delivery global | No: necessary |
| Cloudflare | Country lookup to select your language on first visit | Global edge network | No: necessary |
| Our email delivery provider | Delivering form submissions to us and our reply to you | European Union | No: necessary |
| Calendly | Meeting scheduling, if you book a call. Privacy policy | United States | No. You choose to use it |
| WhatsApp (Meta) | Messaging, if you start a chat. Privacy policy | United States | No. You choose to use it |
| Google: Analytics, Tag, Ads | Traffic measurement and advertising performance. Privacy policy | United States | Yes |
| LinkedIn: Insight Tag | Advertising performance measurement. Privacy policy | United States | Yes |
We may also disclose personal data to professional advisers under a duty of confidentiality, to authorities where the law requires it, and to a successor entity in the event of a merger or acquisition, in which case we would tell you before your data became subject to a different privacy policy.
The technical and organisational measures behind these arrangements are described in our Security and Data Handling statement.
6. International Transfers
This website is hosted in the European Union. Some of the recipients above are established in the United States, which means certain data is transferred outside the European Economic Area.
For those transfers we rely on the European Commission's Standard Contractual Clauses, on the recipient's certification under the EU-US Data Privacy Framework where it applies, and on supplementary measures including encryption in transit and data minimisation. You can request the transfer mechanism applying to any specific recipient by writing to office@c9group.dev.
7. How Long We Keep It
We keep personal data only as long as it serves the purpose it was collected for, or as long as the law requires.
| Data | Retention period |
|---|---|
| Enquiries that do not become an engagement | 24 months from your last contact with us |
| Client contract, project, and billing records | 10 years from the end of the engagement, to meet statutory accounting and tax obligations |
| Meeting bookings | 24 months from the meeting date |
| Job applications for a specific role | 12 months from the decision, unless you consent to us keeping them longer |
| Server and application logs | 90 days |
| Advertising click attribution stored in your browser | 90 days from your visit |
| Analytics data | 14 months |
| Record of your cookie consent | 12 months |
| Records needed for a legal claim | Until the claim and any appeal period ends |
When a period expires we delete the data or irreversibly anonymise it.
8. Your Rights
Subject to the conditions in the GDPR, you have the right to:
- Access: Obtain confirmation of whether we process your data and receive a copy of it.
- Rectification: Have inaccurate or incomplete data corrected.
- Erasure: Have your data deleted where we no longer have grounds to keep it.
- Restriction: Have processing limited while a dispute about accuracy or lawfulness is resolved.
- Portability: Receive data you gave us in a structured, machine-readable format, and have it sent to another controller where technically feasible.
- Object: Object to processing based on our legitimate interests, and to direct marketing at any time, for direct marketing, we stop with no further assessment.
- Withdraw consent: Withdraw consent at any time, without affecting processing carried out beforehand.
- Complain: Lodge a complaint with a supervisory authority: see below.
9. How to Exercise Your Rights
Write to office@c9group.dev. Tell us what you want and enough detail for us to find your data. There is no charge, and you do not need to use any particular form of words.
We may ask for information to verify your identity, but only what is necessary. We will not use a verification request as a way to collect more data about you or to stall.
Our response commitment
We acknowledge every request within one business day and respond substantively within 30 days, which is inside the one-month statutory deadline. If a request is genuinely complex we may extend by up to two further months, but we will tell you within the first month why, rather than letting the deadline pass in silence.
10. Automated Decision-Making
We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not carry out profiling of that kind.
Our advertising providers may build interest profiles for ad targeting where you have given marketing consent. That processing happens on their platforms under their own privacy policies, and you can withdraw consent at any time to stop it.
11. How We Protect It
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, least-privilege access with multi-factor authentication, logging, dependency and vulnerability monitoring, and code review. These are described in detail in our Security and Data Handling statement.
No system is perfectly secure, and we do not claim otherwise. If a breach affecting your personal data occurs and it is likely to result in a risk to your rights, we notify the competent supervisory authority within 72 hours and inform you without undue delay where the risk to you is high.
12. Children
This website is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact office@c9group.dev and we will delete it.
13. Complaints
If you are unhappy with how we have handled your data, please raise it with us first at office@c9group.dev. We would rather fix it directly.
You also have the right to complain to a supervisory authority. You may contact the authority in the EU or EEA country where you live, where you work, or where the issue arose. The authorities relevant to us are:
- Serbia: Commissioner for Information of Public Importance and Personal Data Protection, poverenik.rs
- Slovenia: Information Commissioner (Informacijski pooblaščenec), ip-rs.si
Complaining to a supervisory authority does not affect any other remedy available to you.
14. Changes to This Policy
We update this policy when our practices or the law change. The version on this page is the one in force, and the "Last Updated" date shows when it last changed. Where a change materially affects how we use data you have already given us, we will tell you directly rather than relying on you to notice.
16. Contact Us
Questions about this policy, or about how we handle your data, are always welcome.
C9 Group
Email: office@c9group.dev
Telephone: +386 71 809 267
Offices: Tartu mnt 67/1-13b, Tallinn, Estonia · Neubergerjeva 15, Ljubljana, Slovenia · Jaše Ignjatovića 7, Novi Sad, Serbia
We reply within one business day
Every message reaching us gets a response from a person within one business day. Data protection requests are acknowledged in the same time and answered within 30 days.
17. Language
Authoritative version
This policy is published in several languages. The English version is the authoritative text. Where a translation differs, the English version prevails.