Privacy Policy
This policy explains what data the central account processes, why it is processed and the rights available to you.
1. Data controller
The controller for personal data processed through the central Pametan Tiket Account is MARKO BELOICA PR WEB PORTALI MARBEL TECHNOLOGIES KRUŠEVAC.
For privacy questions, rights requests or security concerns, contact support@pametantiket.rs.
2. Scope of this policy
This Policy applies to the central account at nalog.pametantiket.rs and authentication for:
- pametantiket.rs and pametantiket.com,
- fudbalstatistika.rs and fudbalstatistika.com,
- poeniigraca.rs and poeniigraca.com.
An individual platform may process additional product-specific data such as favorites, saved tickets or preferences. Where additional rules are needed for such processing, they will be presented on the relevant platform.
3. Data we process
Depending on the features you use, the central account may process:
- account data: email address, first name, last name, display name and language preference;
- authentication data: cryptographic password hash, email verification status, password-change/reset information and hashed security tokens;
- session data: login time, last activity, Remember Me status and technical session identifiers;
- security data: hashed network identifiers, user-agent/browser information, successful and failed login attempts and security events;
- consent records: accepted version of the Terms and Privacy Policy and, where selected, marketing consent;
- product access data: connected products used by the account and the current access level or plan.
We do not store your password in readable form. It is stored only as a security hash used for authentication.
4. Why we process data
We process data to:
- create and maintain your account;
- verify your email address and provide secure sign-in;
- enable one account across connected domains;
- provide password reset, sign-out and session management;
- prevent brute-force attacks, abuse and unauthorized access;
- record accepted legal terms and preferences;
- provide support and resolve technical issues;
- comply with legal obligations and protect user and operator rights.
5. Legal bases
Depending on the purpose, processing may be based on:
- performance of the account service you requested;
- our legitimate interests in securing accounts, preventing abuse and maintaining a stable service;
- compliance with legal obligations;
- your consent, for example for optional marketing messages.
Where processing relies on consent, you may withdraw that consent for future processing without affecting processing already carried out lawfully before withdrawal.
6. How the central account and SSO work
Your password is checked only by the central service at nalog.pametantiket.rs. When you sign in to a connected domain, the central service issues a short-lived, single-use code. The connected server exchanges that code and receives only information required to create a local user session, such as the account identifier, basic profile and access entitlement.
Connected websites do not receive your central password. One-time SSO codes expire quickly and cannot be reused after exchange.
7. Cookies and technical sessions
The central account uses necessary first-party cookies and sessions to:
- keep you signed in;
- support Remember Me when you choose it;
- protect forms and authentication flows;
- return you securely to the connected platform after sign-in.
These cookies are not intended for advertising profiling. If optional analytics or marketing technologies requiring consent are added later, you will be offered an appropriate choice before they are activated.
8. Recipients and processors
We do not sell personal data. Information may be available only to people and service providers that need it to operate the service, such as hosting/infrastructure providers, email/SMTP providers, technical support or other contracted processors.
Such providers receive only the information needed for the relevant service and are expected to process it subject to applicable confidentiality and security obligations.
We may disclose information to a competent authority where required by a valid legal obligation or lawful request.
9. International data transfers
Some technical service providers may process data outside the Republic of Serbia. Where such a transfer applies, we aim to use providers and safeguards that provide an appropriate level of protection under applicable law.
10. Retention
Core account information is kept while your account remains active and afterwards only for as long as needed to complete deletion requests, comply with legal obligations, resolve disputes or protect the service.
Verification and password-reset tokens expire after a limited period. Sessions expire or can be revoked. Security logs and login records are retained for a reasonable period necessary to prevent abuse, investigate incidents and protect the service.
When information is no longer needed and no other legal basis requires retention, it is deleted or anonymized in line with technical capabilities and applicable obligations.
11. Security
We use technical and organizational measures appropriate to the service, including HTTPS, password hashing, short-lived single-use SSO codes, CSRF protection, login-rate limiting, HttpOnly/Secure session cookies, session revocation and security logging.
No information system can guarantee absolute security, but we adapt safeguards to risk and platform development.
12. Your rights
Subject to the requirements of applicable data-protection law, you may have the right to:
- receive information about processing and access your personal data;
- correct inaccurate or incomplete data;
- request deletion where the legal conditions are met;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive portable data where the legal conditions are met;
- withdraw consent where processing relies on consent;
- lodge a complaint with the competent data-protection authority.
To protect your account, we may request reasonable identity verification before acting on a rights request.
13. Marketing communications
Marketing messages are sent only where an appropriate legal basis exists, including consent where required. During registration, the marketing option is separate from the mandatory acceptance of the Terms and Privacy Policy.
If you consented, you can withdraw that consent using an available unsubscribe option or by contacting support. Transactional and security emails, such as email verification or password reset, are not marketing messages.
14. Children
The service is not intended to collect children's personal data contrary to applicable law. Sports content is informational; if a user connects that information with betting or gambling, all age restrictions and rules applicable in that user's jurisdiction must be observed.
15. Changes to this Policy
We may update this Policy when functionality, data processing or legal requirements change. The current version and effective date will always be available on this page.
16. Privacy contact and requests
For privacy questions or requests, contact:
