Privacy Policy

Last modified: 23.12.2024

1. Introduction

Palata Nauke is a visitor guide application that allows its users to independently explore Palata Nauke with interactive stories and audio guides (collectively: “Tours”). Visitors use smartphones to pick stories in which they play a lead role. During the interactive tour, visitors follow points of interest, find clues, and solve a range of challenges until the story is concluded. Challenges take the form of puzzles and riddles. They can only be solved by visual or physical interaction with exhibits, and they unlock interesting educational facts. Visitors can also use their smartphones to access an immersive audio guide.

Please read this Privacy Policy (“Policy”) carefully before using the “Palata Nauke” application, which is owned, controlled, managed, operated and maintained by the Miodrag Kostić Endowment, registered in accordance with the laws of the Republic of Serbia, with headquarters at 11 Kralja Milana St., Belgrade.

This Policy describes what information the Endowment will collect about you when you access or use the Service and why, how the information will be used and disclosed, and how you can control the collection, correction and/or deletion of data. This Policy is an integral part of our Terms and Conditions (“Terms and Conditions”). Capitalized terms not defined in this Policy have the meaning given to them in our Terms and Conditions.

This Policy describes your privacy rights and the legal protections afforded to you when you access our CMS (“CMS”) and use our mobile application (“Application”) [CMS and Application together: “Palace of Science].

The Policy applies to all clients, administrators, moderators, users, visitors and others who access or use the Palata Nauke application (“You” or “Your”). Your access and use are conditioned on your acceptance of and compliance with this Policy. By accessing or using it, you consent to the collection and use of your data in accordance with this Policy. If you do not agree with any part of the Policy, you will not be able to access the Palata Nauke application. By continuing to use our CMS and Application, you confirm your express agreement to be bound by our Policy and Terms of Use.

Our priority is safeguarding your privacy and personal data. This Privacy Policy aims to provide you with comprehensive insights into how we handle and protect your personal information. 

 

1. Data Controller

ZADUŽBINA MIODRAGA KOSTIĆA, 11 Kralja Milana St., 11000 Belgrade, Serbia, TIN: 112819127  

Contact:  [email protected]

 

3. Information We Collect and Store and Data Processing for the Palata Nauke Application

3.1. User registration

If you want to use Palata Nauke application, you can do so without creating an account.

Data necessary to create a Palata Nauke profile on Palata Nauke mobile application:

  • Type of data: Username, First & last name (when you log in with Google or Apple or Facebook accounts), email address*, date and time of registration
  • Legal basis: Consent
  • Reason: Necessary for gamification, obtaining levels and prizes inside the app by doing challenges when visiting organization exhibition

*Check data retention section for more info

Data necessary to use Palata Nauke CMS

  • Type of data: First & last name, email address, date and time of registration
  • Legal basis: Legitimate interest
  • Reason: Necessary for concluding a contract and access to CMS
  • Data type: Administrator activities
  • Legal basis: Legitimate interest
  • Reason: Necessary for platform security

3.2. Users’ feedback

The user can manually submit feedback about a particular Tour.

  • Type of data: Rating, the content of the message, message date and time
  • Legal basis: Legitimate interest
  • Reason: Anonymous feedback used to improve user experience

3.3. Device data

Device data is not collected and/or stored by Palata Nauke but by our dynamic links provider Branch.io whose own terms and conditions and privacy policy are applicable.


Terms and conditions: https://legal.branch.io/#branchio-ts-cs

Privacy policy: https://legal.branch.io/#branchio-privacypolicy

  • Type of data: Device information
  • Legal basis: Legitimate interest
  • Reason: Used to correctly open deep links on Android and iOS devices (QR codes, NFC tags and links)

Device data is not collected and/or stored by Palata Nauke, but by our push notification service provider OneSignal whose own terms and conditions and privacy policy apply.

Privacy policy: https://documentation.onesignal.com/docs/data-collected-by-the-onesignal-sdk

  • Data type: Device information and IP address* 
  • Legal basis: Legitimate interest
  • Reason: It is used for the normal functioning of push notifications

* The IP address is only collected outside the EU member states

3.4. Gamification

If you participate in gamification, we collect achievements, rewards and levels earned.

  • Data type: Achievements, rewards, and levels
  • Legal basis: Consent
  • Reason: Used to track activity when participating in gamification so that rewards can be awarded to specific users

 

4. How We Use, Share and Disclose Information

We may use the data only in accordance with the instructions of the user and according to the applicable law.

For example, the user can use the service to grant and revoke access to the platform, assign roles and configure settings, access, modify, export, share and delete data and apply its rules to the use of the application.

We use the information we collect (such as: account creation information, device information, anonymous statistical data, user feedback, achievements, rewards and levels) for various purposes to provide the service of access and use of Palata Nauke, such as:

  • creating or updating accounts and enabling access;
  • enabling connection by application and providing the option to reset your password upon your request;
  • management, maintenance, improvement and provision of all functionalities;
  • preventing or solving errors, security and technical problems;
  • responding to your comments, questions and requests and providing support;
  • informing about Palata Nauke and changes, sending important security-related notifications and administrative messages;
  • adjusting the experience of using Palata Nauke and developing additional functions;
  • addressing important notices related to Palata Nauke, violation of intellectual property and privacy rights;
  • invoicing, account management and collection monitoring;
  • analysis of usage, trends and other activities related to Palata Nauke;
  • for marketing or promotional purposes, e.g. to provide news, offers, promotions and events and other information related to the Palace of Science. You can opt out of receiving marketing messages in the “Your rights and choices” section below. However, you cannot unsubscribe from other messages related to your account, as they are considered an integral part of using Palata Nauka. If you no longer wish to receive such messages, you may unsubscribe by canceling your account;
  • protection of Palata Nauke, research and prevention of abuse, unauthorized access and other illegal activities;
  • as necessary, in accordance with applicable law, legal procedure or regulation;

Except as described in this Policy, we will not intentionally disclose your information collected or stored by third parties without your consent.

The user determines his own rules for sharing and disclosing data. Therefore, we have no control over how Client chooses to share or disclose data.

We can share and disclose Information with third parties in the following cases:

  • Client data. We can share and disclose data in accordance with the Client’s instructions and applicable law and legal procedure.
  • Information without restrictions. Any Information you choose to make available in the Palata Nauke application will be available to any user who has access to that content.
  • Third party service providers. We work with third-party service providers who provide maintenance, application development and other services for us. These third parties may have access to Other Information as part of providing those services. We limit the information provided to these services to the reasonably necessary to perform their functions, and our agreements with them require them to keep that information confidential.
  • Third party services. Third-party services are not owned or controlled by us and may have their own policies and practices for the collection and use of Other Information. Check the privacy settings and notices of those services.
  • Related parties. We may share information with our related parties.
  • Non/personal information. We can share or use non-personal information with third parties for any purpose, including: (i) complying with various reporting obligations; (ii) for business or marketing purposes; or (iii) to help those parties understand the interests, habits and usage patterns of our clients and users.
  • Legal requirements. We can disclose information if required to do so by law or if we believe such action is in compliance with applicable law, regulation or legal procedure.
  • Realization of rights, security and fraud prevention. We reserve the right to disclose such Other Information as we deem appropriate or necessary to: (i) protect ourselves or others from fraud, abuse or illegal use of the Service; (ii) investigate and defend against any claims by third parties; (iii) protect the security or integrity of the Service and any facilities or equipment used to provide the Service; or (iv) exercise or protect our rights, property or safety, execute our agreements or policies, or protect the rights, property or safety of others.
  • Change of ownership. In the event of a merger, acquisition, bankruptcy, reorganization, liquidation, sale of assets, debt financing, public offering of securities, acquisition of all or part of our business or similar transactions, some or all of your information can be disclosed and transferred only if the recipient of the information accepts the Privacy Policy that has terms substantially consistent with this Policy.
  • Your consent. We can disclose information to third parties with your consent.

We can transfer your information to countries other than the one in which you live in order to store and process that information, fulfill your requests and operate the service. By submitting Personal Information, you agree that we can transfer that information in accordance with this Policy and applicable data protection laws.

Some countries may not have the same data protection framework as the country from which you use the Service. When we transfer information, we will protect it as described in this Policy. We will act in accordance with applicable legal requirements that provide adequate protection for the transfer of personal information.

5. Data Retention

5.1. Account deletion

To delete your account and all user personal data, use the option “Delete account” inside the app settings.

If your personal data was collected when you were under the age of consent for data collection, you have the right to request the erasure of your personal data. 

Our web server backups can hold the data for a maximum of 4 weeks after deletion. The backups are not used to restore individual user data.

When your account is deleted, all your data is permanently deleted from our systems, except for your hashed email address or hashed apple ID if your email is hidden (The hashed email address or apple ID is dissociated from any personally identifiable information and cannot be reversed to its original form. This approach helps us meet our legal requirements while respecting your privacy.).  This means we cannot recover any of the information you provided, including your personal information. 

If you have participated in gamification all your rewards, achievements and levels will be deleted. Write down your reward codes somewhere safe and they can still be used after deleting your account.

When you utilize social login through Google, Apple or Facebook to create an account or log in to our application, please make sure that the accounts are correctly disconnected from Palata Nauke on those platforms. We kindly ask users to review the privacy policies and terms of use of those platforms and take necessary actions to delete their data according to their own preferences and needs.

Google Privacy Policy: https://policies.google.com/privacy

Google Terms of Service: https://policies.google.com/terms

Apple Privacy Policy: https://www.apple.com/legal/privacy/data/en/apple-id/

Apple Terms of Service: https://www.apple.com/legal/internet-services/itunes/

Facebook Privacy Policy: https://www.facebook.com/privacy/policy/

Facebook Terms of Service: https://www.facebook.com/terms.php

5.2. Deleting data from Facebook

If you want to delete your data from the Palace of Science, you can do so by following the following steps:

1. Go to Facebook Account’s Setting & Privacy. Click on “Settings”

2. Find “Apps and Websites” and you will see all the apps and websites you have connected to your Facebook.

3. Find and click “Palata Nauke” on the search bar.

  1. Scroll and click “Remove”.

 

6. Information Security

The security of your information is important to us. Therefore, we strive to apply generally accepted standards to protect your information, both during transmission and when we receive it. We implement appropriate administrative, technical and physical safeguards to protect information from accidental or unlawful destruction, accidental loss, unauthorized alteration, unauthorized disclosure or access, misuse and any other unlawful form of processing. This includes password crypto-protection, encryption of transmitted data, ensuring permanent confidentiality, integrity, availability and resilience of processing systems and services, ensuring the establishment of re-availability and access to personal data in the event of physical or technical incidents in the shortest possible time, conducting regular testing, evaluation and evaluation of the effectiveness of technical, organizational and personnel security measures.

However, please note that no method of data transmission over the Internet or method of electronic storage is 100% secure. Therefore, we cannot guarantee the absolute security of any information you transmit to us or store on the Palace of Science, and you do so at your own risk. Also, we cannot guarantee that such information will not be accessed, disclosed, altered or destroyed as a result of a breach of any of our industrial physical, technical or managerial protection measures.

If we learn that information has been compromised due to a security breach, we will notify you without undue delay, in accordance with applicable law.

If you believe your information has been compromised, please contact us.

 

7. Relationships with Third Parties

Palata Nauke may contain links to third-party websites or services that are not owned, maintained, supported or controlled by us. This Policy does not apply to any third-party website or service.

The Endowment has no control over, and assumes no responsibility for, the content, privacy policies, or practices of any third-party websites or services. Users acknowledge and agree that the Endowment shall not be liable, directly or indirectly, for any damage or loss caused or alleged to be caused by the use of or reliance on any such content, goods or services available on or through such websites or services. The use of third-party websites or services is solely between the customer and/or user, on the one hand, and the respective third-party provider, on the other hand.

If third-party websites or services are enabled for the Customer Platform, please note the information that will be shared with the third-party provider and the purposes for which the provider requests such access. We will not be responsible for any use, disclosure, modification or deletion of Information transmitted or accessed through third party websites or services.

 

8. User Rights

Users of the Palata Nauke application have the opportunity to exercise the right to:

  • Access to personal data
  • Correction of incorrect data
  • Deleting personal data
  • Restriction of processing
  • Data portability
  • Objection to the processing of personal data

You can request to exercise your rights:

  • by sending an e-mail to: [email protected]
  • by sending a request to the physical address: 11 Kralja Milana St., 11 000 Belgrade, Serbia

We respond to all requests within the legal term of thirty days.

Objections to specific processing can be sent to the supervisory body for the protection of personal data: the Commissioner for Information of Public Importance and Protection of Personal Data.

 

9. Amendments

9.1. The privacy policy applies only to the Palata Nauke application and not to third-party platforms or services that users can access through Palata Nauke.

9.2. We reserve the right to make changes to the Privacy Policy, or any policy or guidelines of Palata Nauke at any time and at our sole discretion. We will notify you of any changes by updating the “Last Updated” date in the Privacy Policy and you waive any right to receive separate notice of any such change. It is your responsibility to periodically review the Privacy Policy to stay informed of updates. You will be subject to changes in any revised Privacy Policy, and you will be deemed to have read and accepted them, if you continue to use the Palata Nauke application after the date of publication of the Privacy Policy.

10. Completeness of the Policy

If any provision of this Policy is held to be null, void, unenforceable or illegal, the other provisions will continue to be in full force and effect.

 

11. Dispute Resolution

In the event of a dispute arising from or related to this Policy, the competent court will be the Higher Court in Belgrade.

 

12. Notices

Unless otherwise agreed in writing, all notices and communications regarding the Policy will be made via e-mail, in-app notifications or through the platform through the Service.

Send notifications to [email protected]

Notices shall be deemed duly served (i) the day after posting, in the case of e-mail notices; and (ii) on the same day, in the case of notifications made through the Service.

 

13. Contact us

If you have any questions or comments regarding this Policy, please contact us.