Privacy Policy
Effective Date: July 2026
Last Updated: August 2026
1. Introduction
This Privacy Policy (the "Policy") explains how Advokat Miomir A. Stojković, attorney-at-law, operating under the brands Stojković Attorneys (STATT) and Immigrate to Serbia (the "Firm", "we", "us", or "our"), collects, uses, stores, discloses, transfers, protects, and otherwise processes personal data.
The Firm is committed to protecting the privacy, confidentiality, and security of personal data entrusted to it in the course of providing legal and related professional services and operating its digital platforms.
This Policy applies to all individuals whose personal data is processed by the Firm, including prospective clients, clients, website visitors, business partners, suppliers, representatives of legal entities, job applicants, and other individuals interacting with the Firm.
This Policy should be read together with our Terms of Use, Cookie Policy, Payment Terms, Refund Policy, Consumer Rights and Complaints Policy, and any engagement agreement or other written agreement entered into with the Firm, where applicable.
2. Scope of This Policy
This Policy applies to the processing of personal data in connection with:
- www.statt.rs;
- www.immigratetoserbia.com;
- any other website, domain, subdomain, digital platform, client portal, online service, or mobile application operated by or on behalf of the Firm;
- online consultations, contact forms, questionnaires, document submissions, appointment scheduling, newsletters, webinars, seminars, and other digital interactions;
- email, telephone, video conferencing, messaging applications, social media communications, and other electronic communications;
- legal services, consulting services, immigration services, corporate services, compliance services, and any other professional services provided by the Firm;
- business relationships with clients, prospective clients, counterparties, experts, consultants, suppliers, service providers, and other third parties.
This Policy applies regardless of the technology used to access or interact with the Firm's services.
3. Data Controller
Unless expressly stated otherwise, the controller of your personal data is:
Advokat Miomir A. Stojković
Operating under the brands:
Stojković Attorneys (STATT)
Immigrate to Serbia
Cara Dušana 55/3
11000 Belgrade
Republic of Serbia
Registration Number: 57304880
Tax Identification Number (TIN): 106420279
Email: office@statt.rs
Website:
www.statt.rs
www.immigratetoserbia.com
Where required by applicable law, the Firm acts as the data controller responsible for determining the purposes and means of processing personal data.
In certain circumstances, the Firm may process personal data jointly with other controllers or on behalf of clients, public authorities, or other parties where required by law, professional obligations, or contractual arrangements.
4. Applicable Law
The Firm processes personal data in accordance with applicable data protection legislation, including, where relevant:
- the Law on Personal Data Protection of the Republic of Serbia;
- the General Data Protection Regulation (EU) 2016/679 (GDPR) where applicable;
- legislation governing the legal profession, attorney-client privilege, professional secrecy, anti-money laundering, sanctions compliance, accounting, taxation, and other applicable legal and regulatory requirements.
Where different legal regimes apply simultaneously, the Firm will process personal data in accordance with the applicable mandatory legal requirements.
5. Definitions
For the purposes of this Policy:
"Personal Data" means any information relating to an identified or identifiable natural person.
"Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, restriction, deletion, destruction, or any other form of processing.
"Client" means any individual or legal entity whose legal representation or engagement has been accepted by the Firm.
"Prospective Client" means any individual or legal entity that contacts the Firm or otherwise expresses an interest in obtaining legal or related professional services.
"User" means any individual accessing or using the Firm's websites, digital platforms, online services, or other technologies.
"Services" means legal, immigration, corporate, tax, compliance, consulting, educational, digital, administrative, technological, or other services provided or facilitated by the Firm.
6. Categories of Personal Data We May Process
Depending upon the nature of your relationship with the Firm, we may process the following categories of Personal Data.
Identity Information
This may include:
- name;
- surname;
- title;
- nationality;
- citizenship;
- date and place of birth;
- passport or identification details;
- photographs;
- signatures;
- identity verification information;
- other information necessary for identification.
Contact Information
This may include:
- residential or business address;
- email address;
- telephone number;
- messaging application details;
- country of residence;
- correspondence details;
- preferred communication methods.
Professional and Business Information
This may include:
- employer;
- company details;
- professional position;
- ownership interests;
- business activities;
- corporate affiliations;
- publicly available professional information.
Legal Matter Information
Depending upon the engagement, this may include:
- information relating to legal matters;
- immigration status;
- documentation;
- supporting evidence;
- communications;
- legal instructions;
- due diligence materials;
- compliance documentation;
- information required for legal representation or professional services.
Financial Information
Where relevant, this may include:
- billing information;
- payment information;
- banking details;
- invoicing information;
- tax-related information;
- transaction records.
For the avoidance of doubt, the Firm does not intentionally store complete payment card details except where required by law or where processed by authorised payment service providers in accordance with applicable legal requirements.
Technical Information
This may include:
- IP address;
- browser type;
- operating system;
- device identifiers;
- language settings;
- access logs;
- website usage information;
- cookies and similar technologies;
- diagnostic information;
- cybersecurity logs.
Communications
This may include:
- emails;
- letters;
- telephone records where legally permitted;
- video conference information;
- online meeting records;
- correspondence;
- messages;
- enquiries;
- feedback;
- questionnaires;
- submitted documents.
Compliance Information
Where required by law or professional obligations, we may process information relating to:
- client identification;
- conflict checks;
- anti-money laundering requirements;
- sanctions compliance;
- regulatory obligations;
- fraud prevention;
- risk management;
- legal claims;
- legal proceedings.
The categories of Personal Data processed by the Firm will always depend upon the specific circumstances, the nature of the requested services, applicable legal obligations, and the relationship between you and the Firm.
7. Sources of Personal Data
The Firm may obtain Personal Data from various lawful sources, including:
- directly from you;
- from your authorised representatives;
- from your employer or organisation where appropriate;
- from publicly available registers and databases;
- from competent governmental authorities;
- from courts, administrative authorities, or regulatory bodies;
- from professional advisers or experts engaged in connection with a matter;
- from counterparties or their representatives;
- from publicly available sources;
- through your use of the Site;
- through communications with the Firm;
- through technology providers acting on behalf of the Firm where legally permitted.
The Firm does not knowingly collect Personal Data by unlawful or deceptive means.
8. Purposes of Processing
The Firm processes Personal Data only where there is a lawful basis for doing so and solely for legitimate, specified, and appropriate purposes.
Depending on the nature of your relationship with the Firm, Personal Data may be processed for one or more of the following purposes:
- responding to enquiries and requests for information;
- assessing whether the Firm is able or willing to accept a proposed engagement;
- conducting conflict-of-interest checks;
- verifying identity and carrying out client due diligence;
- complying with anti-money laundering, sanctions, regulatory, and other legal obligations;
- providing legal representation and related professional services;
- preparing legal analyses, opinions, contracts, applications, submissions, and other legal documentation;
- communicating with clients, prospective clients, public authorities, courts, counterparties, advisers, experts, and other relevant persons;
- managing client relationships and professional engagements;
- administering payments, invoicing, accounting, and financial records;
- maintaining internal administrative, operational, and risk management procedures;
- ensuring the security, integrity, availability, and proper functioning of the Site and the Firm's information systems;
- detecting, preventing, investigating, and responding to fraud, cyber incidents, security breaches, unlawful activities, or other misuse;
- improving the quality, accessibility, performance, and functionality of the Firm's services and digital platforms;
- maintaining professional records and complying with document retention obligations;
- establishing, exercising, or defending legal claims;
- complying with applicable legal, regulatory, ethical, professional, judicial, or governmental requirements; and
- any other purpose that is compatible with the original purpose for which the Personal Data was collected or otherwise permitted by applicable law.
The Firm will not process Personal Data for purposes that are incompatible with those described in this Policy unless required or permitted by applicable law.
9. Legal Bases for Processing
The Firm processes Personal Data only where there is a lawful basis under applicable data protection legislation.
Depending on the circumstances, processing may be based on one or more of the following legal grounds:
Performance of a Contract
Processing that is necessary to enter into, perform, administer, or enforce an engagement agreement or other contract with you.
Pre-Contractual Measures
Processing necessary to evaluate enquiries, assess potential engagements, communicate with prospective clients, perform conflict checks, or take other steps requested prior to entering into a contractual relationship.
Compliance with Legal Obligations
Processing required to comply with applicable laws, professional regulations, court orders, anti-money laundering legislation, sanctions requirements, tax obligations, accounting obligations, or other mandatory legal requirements.
Legitimate Interests
Processing necessary for the legitimate interests pursued by the Firm, provided that such interests are not overridden by your fundamental rights and freedoms.
Such legitimate interests may include:
- operating and administering the Firm;
- protecting clients, personnel, and information systems;
- ensuring cybersecurity;
- maintaining professional standards;
- preventing fraud and abuse;
- improving services;
- managing professional risk;
- maintaining business continuity;
- exercising or defending legal rights.
Consent
Where required by law, the Firm will rely upon your consent before processing Personal Data for specific purposes, including certain marketing communications or the use of non-essential Cookies.
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal of consent shall not affect the lawfulness of processing carried out before such withdrawal.
Establishment, Exercise, or Defence of Legal Claims
The Firm may process Personal Data where necessary for the establishment, exercise, or defence of legal claims or legal proceedings.
10. Professional Secrecy and Confidentiality
The protection of confidential information forms one of the fundamental principles governing the Firm's professional practice.
In addition to applicable data protection legislation, information received by the Firm in connection with legal representation or the provision of professional services may also be protected by attorney-client privilege, professional secrecy obligations, legal professional privilege, confidentiality obligations, and other protections arising under applicable law and professional rules governing attorneys.
The Firm implements appropriate organisational, contractual, administrative, and technical measures designed to preserve the confidentiality of information entrusted to it.
Nothing contained in this Privacy Policy shall be interpreted as limiting or replacing any confidentiality obligations owed by the Firm under applicable law or professional ethics.
11. Artificial Intelligence and Digital Technologies
In order to improve efficiency, accuracy, security, and the quality of its services, the Firm may use various digital technologies, including artificial intelligence ("AI"), machine learning, document automation, workflow automation, secure cloud services, communication platforms, and other technology solutions.
Such technologies may be used to assist with administrative, operational, analytical, research, document management, translation, summarisation, drafting, knowledge management, or similar functions.
The Firm does not rely exclusively on automated processing to make decisions that produce legal effects concerning clients or similarly significant effects, unless expressly authorised or required by applicable law.
Where AI-assisted technologies are used, appropriate human oversight remains an integral part of the Firm's professional processes.
The Firm continuously evaluates technological solutions with due regard to confidentiality, professional secrecy, cybersecurity, legal privilege, and applicable legal and ethical obligations.
12. Automated Decision-Making
The Firm does not intentionally make decisions concerning individuals solely by automated means where such decisions produce legal effects concerning those individuals or similarly significantly affect them, except where expressly authorised or required by applicable law.
Should the Firm introduce any automated decision-making processes that are subject to applicable data protection legislation, this Privacy Policy will be updated accordingly, and any additional rights available to affected individuals under applicable law will be respected.
13. Data Accuracy
The Firm endeavours to ensure that Personal Data is accurate, complete, and, where necessary, kept up to date.
You are responsible for ensuring that the information you provide to the Firm is accurate and for informing the Firm of any material changes affecting your Personal Data.
The Firm may, where reasonably appropriate, request updated or additional information in order to maintain accurate records, comply with legal obligations, or provide professional services.
14. Disclosure of Personal Data
The Firm treats Personal Data as confidential and does not sell, rent, trade, or otherwise disclose Personal Data for commercial purposes.
Personal Data may be disclosed only where reasonably necessary for the purposes described in this Policy or where required or permitted by applicable law.
Depending on the circumstances, Personal Data may be disclosed to:
- attorneys, employees, trainees, consultants, and authorised personnel of the Firm;
- external attorneys, foreign counsel, experts, interpreters, translators, notaries, accountants, auditors, tax advisers, investigators, and other professional advisers engaged in connection with a matter;
- courts, governmental authorities, regulatory bodies, law enforcement authorities, bar associations, public registries, and other competent authorities where required or permitted by law;
- banks, payment service providers, insurance providers, and financial institutions where necessary;
- providers of hosting, cloud infrastructure, cybersecurity, communications, information technology, software, document management, artificial intelligence, identity verification, payment processing, scheduling, customer relationship management, analytics, and other business support services;
- any other person where disclosure is necessary for the provision of requested services, compliance with legal obligations, or the protection of the Firm's legitimate rights and interests.
All recipients processing Personal Data on behalf of the Firm are required to maintain appropriate confidentiality and data protection standards.
The Firm requires service providers processing Personal Data on its behalf to implement appropriate technical and organisational measures designed to protect Personal Data.
15. International Data Transfers
Personal Data may be processed or stored in the Republic of Serbia, Member States of the European Economic Area (EEA), the United Kingdom, or other jurisdictions where the Firm, its professional advisers, or its service providers operate.
Where Personal Data is transferred outside the Republic of Serbia or the EEA, the Firm will take appropriate measures to ensure that such transfers are carried out in accordance with applicable data protection legislation.
Such safeguards may include:
- adequacy decisions;
- standard contractual clauses;
- legally recognised transfer mechanisms;
- contractual confidentiality obligations;
- technical and organisational security measures; or
- other safeguards recognised under applicable law.
16. Data Retention
The Firm retains Personal Data only for as long as reasonably necessary to fulfil the purposes for which it was collected or to comply with applicable legal, regulatory, professional, contractual, accounting, tax, anti-money laundering, record-keeping, or ethical obligations.
Retention periods may vary depending upon the nature of the data and the relevant legal or professional requirements.
As a general guideline:
- enquiry data may be retained for up to twenty-four (24) months;
- marketing data will generally be retained until consent is withdrawn or the data is no longer required;
- client files and engagement records will be retained in accordance with applicable professional obligations and legal retention requirements;
- technical logs and security records will be retained for periods reasonably necessary to protect the security, integrity, and proper operation of the Firm's systems.
The Firm may retain Personal Data for longer where reasonably necessary to:
- establish, exercise, or defend legal claims;
- comply with legal or regulatory obligations;
- protect the Firm, its clients, or third parties;
- resolve disputes;
- enforce contractual rights; or
- comply with professional obligations applicable to attorneys.
Upon expiry of the applicable retention period, Personal Data will be securely deleted, anonymised, or otherwise disposed of in accordance with applicable law and the Firm's internal policies.
17. Data Security
The Firm implements appropriate technical, organisational, administrative, and physical security measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, or other unlawful processing.
Such measures may include, where appropriate:
- access controls based on business need;
- authentication mechanisms;
- encryption during transmission and, where appropriate, storage;
- secure backups;
- logging and monitoring;
- cybersecurity controls;
- vulnerability management;
- incident response procedures;
- confidentiality obligations;
- secure document management;
- regular review of internal security practices.
Although the Firm takes reasonable measures designed to protect Personal Data, no method of electronic transmission, storage, or processing can be guaranteed to be completely secure.
Accordingly, the Firm cannot guarantee absolute security and disclaims liability for unauthorised access or events beyond its reasonable control, except where liability cannot be excluded under applicable law.
18. Your Rights
Subject to applicable law, you may have the right to:
- request access to your Personal Data;
- request correction of inaccurate or incomplete Personal Data;
- request deletion of Personal Data where applicable;
- request restriction of processing;
- object to certain processing activities;
- withdraw consent where processing is based upon consent;
- request data portability where applicable;
- lodge a complaint with the competent supervisory authority.
The exercise of these rights may be subject to legal limitations, including obligations relating to attorney-client privilege, professional secrecy, legal claims, regulatory obligations, and other mandatory legal requirements.
Requests relating to Personal Data may be submitted to:
The Firm may request reasonable information necessary to verify the identity of the person submitting the request before responding.
19. Complaints
If you believe that the Firm has processed your Personal Data in a manner inconsistent with applicable law, you may contact the Firm using the contact details provided in this Policy.
You also have the right, where applicable, to lodge a complaint with the competent supervisory authority responsible for data protection.
For processing activities subject to Serbian law, the competent supervisory authority is:
Commissioner for Information of Public Importance and Personal Data Protection
Bulevar kralja Aleksandra 15
11120 Belgrade
Republic of Serbia
Email: office@poverenik.rs
Website: https://www.poverenik.rs
The Firm encourages individuals to contact the Firm first so that any concerns may be considered and, where appropriate, resolved promptly and amicably.
20. Cookies and Similar Technologies
The Firm uses cookies and similar technologies in connection with the operation of the Site and certain digital services.
Further information regarding the categories of cookies we use, the purposes for which they are used, the legal basis for their use, and the manner in which you may manage your cookie preferences is available in our separate Cookie Policy, which forms an integral part of this Privacy Policy.
Where required by applicable law, the Firm will obtain your consent before placing cookies or similar technologies that are not strictly necessary for the operation of the Site.
21. Children's Privacy
The Site and the Firm's services are not directed to children.
The Firm does not knowingly collect Personal Data directly from individuals who are unable to validly provide consent under applicable law without the involvement of a parent, legal guardian, or other authorised representative.
Where the Firm provides legal services involving minors, Personal Data will be processed only where appropriate legal authority exists and in accordance with applicable law and professional obligations.
If you believe that Personal Data relating to a child has been provided to the Firm without appropriate authority, please contact us so that appropriate measures may be taken.
22. Third-Party Websites and Services
The Site may contain links to websites, applications, platforms, governmental portals, payment systems, or other services operated by independent third parties.
This Privacy Policy applies solely to Personal Data processed by or on behalf of the Firm.
The Firm does not control, and is not responsible for, the privacy practices, security measures, content, or policies of third-party websites or services.
Users are encouraged to review the privacy policies and terms of any third-party service before providing Personal Data to such third parties.
23. Business Reorganisations
The Firm reserves the right to reorganise its business and professional operations in accordance with applicable law.
Accordingly, Personal Data may, where legally permitted and subject to appropriate confidentiality and data protection obligations, be transferred or otherwise made available in connection with:
- the establishment of affiliated entities;
- mergers;
- acquisitions;
- business restructurings;
- transfers of professional practice;
- transfers of business assets;
- succession arrangements;
- financing transactions;
- or other lawful corporate or professional reorganisations.
Any recipient of Personal Data in such circumstances shall be required to process Personal Data in accordance with applicable law and appropriate confidentiality obligations.
Nothing in this Section shall permit disclosure of information protected by attorney-client privilege, professional secrecy, or other mandatory confidentiality obligations except where permitted or required by applicable law.
24. Changes to This Privacy Policy
The Firm may amend, update, replace, or supplement this Privacy Policy from time to time in order to reflect:
- changes in applicable law;
- regulatory guidance;
- professional obligations;
- technological developments;
- changes to the Firm's services;
- changes to the operation of the Site; or
- other legitimate business requirements.
The most current version of this Privacy Policy will always be available on the Site.
Any revised version shall become effective upon publication unless a later effective date is expressly specified.
Where required by applicable law, the Firm will provide additional notice regarding material changes.
Your continued interaction with the Site following publication of the revised Privacy Policy shall constitute acknowledgement of the updated Policy to the extent permitted by applicable law.
25. Contact Information
Questions, requests, or concerns relating to this Privacy Policy or the processing of Personal Data may be directed to:
Stojković Attorneys (STATT)
Advokat Miomir A. Stojković
Cara Dušana 55/3
11000 Belgrade
Republic of Serbia
Email: office@statt.rs
Telephone: +381 11 328 1914
Websites:
www.statt.rs
www.immigratetoserbia.com
26. Final Provisions
This Privacy Policy shall be interpreted in a manner consistent with applicable data protection legislation, the professional obligations governing attorneys, and other applicable laws of the Republic of Serbia.
If any provision of this Privacy Policy is held to be invalid, illegal, or unenforceable, the remaining provisions shall continue in full force and effect.
Nothing contained in this Privacy Policy shall be interpreted as limiting, waiving, or otherwise affecting any duty of confidentiality, attorney-client privilege, legal professional privilege, professional secrecy, or other legal protection applicable to the Firm or its clients.
This Privacy Policy is intended to promote transparency regarding the processing of Personal Data. It does not create any contractual rights beyond those provided by applicable law, nor does it modify the terms of any engagement agreement, legal services agreement, or other written agreement entered into between the Firm and a client.
© Advokat Miomir A. Stojković. All rights reserved. Stojković Attorneys®
