Privacy Policy
This policy explains how Silvercode handles personal information as a company: on the silvercode.dev website, in the contact form, and in the business correspondence that follows. Each Silvercode application also has its own policy covering what that application processes.
We limit the collection of personal information to the data required to operate and maintain our digital products. Data is transmitted through secure HTTPS connections and access is restricted using appropriate authentication and access controls. We do not sell personal information, and this website carries no analytics, advertising, or tracking scripts.
1. Who is responsible
Silvercode is an independent software studio based in Bosnia and Herzegovina. It builds web and mobile products and is the controller responsible for the processing described in this policy.
For privacy questions, access requests, or deletion requests, use the protected Silvercode contact form. You do not need to publish your request publicly.
2. What this policy covers
This policy covers the silvercode.dev website, the contact API at api.silvercode.dev, and the correspondence and client relationships that arise from them.
Silvercode products are covered by their own policies, because each product processes different data:
- Moj Dom, the iOS household organizer, is covered by the Moj Dom Privacy Policy.
- ZaigrajMe, the browser game collection at zaigraj.me, is operated by Silvercode. That site runs its own consent controls, where you can see and switch the individual measurement and error-reporting tools it uses, at zaigraj.me/privatnost.
Where a product publishes its own policy, that policy governs the product. This policy governs Silvercode as a company.
3. Information we process
Website visits
The website is served by Firebase Hosting, a Google service. Google processes technical request data on our behalf, including IP address, user agent, requested address, and timestamps, in order to deliver the site, secure it, and produce delivery statistics.
Silvercode adds no analytics, advertising, or tracking scripts to
silvercode.dev. Loading a page requests files only from silvercode.dev,
and the site sets no cookies. The only value stored in your browser is
a silvercode-language entry in local storage that
remembers your language choice. You can clear it at any time in your
browser settings.
Contact form
When you send a message through the contact form, we process the email address you enter, an optional name, the message text, and the language of the page. The name is limited to 80 characters, the email address to 254, and the message to between 20 and 2,000 characters.
Your message is delivered by email to a Silvercode mailbox through Amazon Simple Email Service. Your email address is set as the reply address so we can answer you directly.
Anti-abuse information
The contact API protects itself from automated abuse with a signed challenge token, a minimum form-completion time, a hidden honeypot field, an allowlist of accepted origins, and rate limits of five submissions per fifteen minutes and twenty challenge requests per ten minutes for each source.
The records that make this work contain only a keyed hash (HMAC) of the source address, request counters, challenge identifiers, and expiry timestamps. They never contain your name, your email address, your message, or your raw IP address.
Our application logs record a request identifier, the route, the HTTP status, the response size, and an error type. They do not record message contents, email addresses, challenge tokens, or raw source addresses.
Business correspondence
If a conversation continues by email or leads to a project, we process the contact and project details you share with us, such as names, email addresses, company details, and the content of our correspondence, together with any records we are required to keep.
4. How we use information
- Deliver, secure, and maintain the website and the contact API.
- Receive, verify, and answer enquiries sent through the form.
- Prevent automated abuse, spam, and misuse of the contact service.
- Discuss, plan, and deliver work for clients.
- Keep records that we are legally required to keep.
Under the GDPR, we rely on our legitimate interests in operating and protecting our own services and in answering enquiries (Article 6(1)(f)), on steps taken at your request before entering a contract and on the performance of a contract (Article 6(1)(b)), and on compliance with legal obligations where they apply (Article 6(1)(c)).
We do not use your information for automated decision-making that produces legal or similarly significant effects, and we do not build advertising profiles from website visits.
5. When information is shared
Silvercode does not sell personal information and does not share it for advertising. Information is shared only with the service providers that run our infrastructure, and only to the extent they need it:
- Google, for Firebase Hosting, which serves the website and processes request data described above. See Firebase privacy information and Google's Privacy Policy.
- Amazon Web Services, for the contact API. The stack uses API Gateway, Lambda, DynamoDB, Simple Email Service, Systems Manager Parameter Store, Certificate Manager, and Route 53, hosted in the Europe (Frankfurt) region. See the AWS Privacy Notice.
We may also disclose information where the law requires it, or where it is necessary to establish, exercise, or defend legal claims.
6. Retention
- Anti-abuse records expire automatically. Rate-limit counters expire within twice their window, and challenge records expire roughly an hour after the challenge is issued.
- Messages sent through the form are kept in the Silvercode mailbox for as long as needed to answer the enquiry and to keep a reasonable record of it, and are deleted afterwards or on request.
- Hosting request logs are retained by Google according to Firebase Hosting's own retention periods.
- Client and accounting records are kept for as long as the applicable legal retention periods require.
7. Security
All traffic is served over HTTPS with HSTS, and the site sends a strict Content Security Policy that blocks third-party scripts and connections. The contact API accepts only requests from our own origins.
Secrets are stored encrypted in AWS Systems Manager Parameter Store, and the contact function is permitted to read only those secrets, write only its own table, send only from its configured address, and write only its own logs. Access to the mailbox and to our cloud accounts is restricted and protected by authentication controls.
No system is perfectly secure, but we design for the smallest amount of data that still lets the service work.
8. International processing
Silvercode operates from Bosnia and Herzegovina, which is outside the European Economic Area. The contact API runs in the AWS Europe (Frankfurt) region. Firebase Hosting is a global content delivery network, so website requests may be served and logged outside your country. Our providers rely on their own transfer mechanisms, including the European Commission's standard contractual clauses where they apply.
9. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form.
Send requests through the protected contact form. We may ask for information that lets us confirm the request comes from you before we act on it.
You can also complain to a supervisory authority. In Bosnia and Herzegovina, this is the Personal Data Protection Agency. In the European Economic Area, it is the authority of your country of residence.
10. Children
The silvercode.dev website is aimed at people looking for professional software work and is not directed at children. We do not knowingly collect personal information from children through this site. Age requirements for individual products are described in their own policies and store listings.
11. Changes to this policy
This policy may be updated when our services, providers, or legal obligations change. The updated date appears at the top of this page, and material changes will be communicated through an appropriate channel when required.
12. Contact
Controller and privacy contact: Silvercode, Bosnia and Herzegovina. Use the protected contact form for questions or privacy requests.
Politika privatnosti
Ova politika objašnjava kako Silvercode kao firma obrađuje lične podatke: na web stranici silvercode.dev, u kontakt obrascu i u poslovnoj korespondenciji koja iz njih proizlazi. Svaka Silvercode aplikacija ima i svoju politiku koja pokriva ono što ta aplikacija obrađuje.
Prikupljanje ličnih podataka ograničavamo na ono što je potrebno za rad i održavanje naših digitalnih proizvoda. Podaci se prenose preko sigurnih HTTPS veza, a pristup je ograničen odgovarajućom autentikacijom i kontrolama pristupa. Ne prodajemo lične podatke, a ova web stranica nema analitičke, oglasne ni prateće skripte.
1. Ko je odgovoran
Silvercode je nezavisni softverski studio sa sjedištem u Bosni i Hercegovini. Gradi web i mobilne proizvode i kontrolor je odgovoran za obradu opisanu u ovoj politici.
Za pitanja o privatnosti, zahtjeve za pristup ili zahtjeve za brisanje koristite zaštićeni Silvercode kontakt obrazac. Vaš zahtjev ne morate objavljivati javno.
2. Šta ova politika pokriva
Ova politika pokriva web stranicu silvercode.dev, kontakt API na api.silvercode.dev, te korespondenciju i klijentske odnose koji iz njih proizlaze.
Silvercode proizvodi pokriveni su vlastitim politikama, jer svaki proizvod obrađuje različite podatke:
- Moj Dom, iOS organizator domaćinstva, pokriven je Politikom privatnosti za Moj Dom.
- ZaigrajMe, kolekcija igara u pregledniku na zaigraj.me, u vlasništvu je Silvercodea. Ta stranica ima vlastite kontrole pristanka, gdje možete vidjeti i pojedinačno uključiti ili isključiti alate za mjerenje i prijavu grešaka, na zaigraj.me/privatnost.
Kada proizvod ima vlastitu politiku, ta politika važi za taj proizvod. Ova politika važi za Silvercode kao firmu.
3. Informacije koje obrađujemo
Posjete web stranici
Web stranicu poslužuje Firebase Hosting, Googleova usluga. Google u naše ime obrađuje tehničke podatke zahtjeva, uključujući IP adresu, korisnički agent, traženu adresu i vremenske oznake, kako bi stranica bila dostavljena i zaštićena i kako bi se izradila statistika isporuke.
Silvercode na silvercode.dev ne dodaje analitičke, oglasne ni prateće
skripte. Učitavanje stranice traži datoteke isključivo sa
silvercode.dev, a stranica ne postavlja kolačiće. Jedina vrijednost
pohranjena u vašem pregledniku je stavka
silvercode-language u lokalnoj pohrani koja pamti vaš
izbor jezika. Možete je obrisati u postavkama preglednika.
Kontakt obrazac
Kada pošaljete poruku kroz kontakt obrazac, obrađujemo e-mail adresu koju unesete, ime ako ga navedete, tekst poruke i jezik stranice. Ime je ograničeno na 80 znakova, e-mail adresa na 254, a poruka na između 20 i 2.000 znakova.
Vaša poruka se e-mailom dostavlja u Silvercode sandučić putem usluge Amazon Simple Email Service. Vaša e-mail adresa se postavlja kao adresa za odgovor kako bismo vam mogli odgovoriti direktno.
Informacije za zaštitu od zloupotrebe
Kontakt API se štiti od automatizirane zloupotrebe potpisanim tokenom, minimalnim vremenom popunjavanja obrasca, skrivenim honeypot poljem, listom dozvoljenih izvora i ograničenjima od pet slanja u petnaest minuta i dvadeset zahtjeva za token u deset minuta po izvoru.
Zapisi koji to omogućavaju sadrže samo kriptografski sažetak (HMAC) izvorne adrese, brojače zahtjeva, identifikatore tokena i vremena isteka. Nikada ne sadrže vaše ime, e-mail adresu, poruku ni vašu izvornu IP adresu.
Naši zapisi aplikacije bilježe identifikator zahtjeva, rutu, HTTP status, veličinu odgovora i vrstu greške. Ne bilježe sadržaj poruka, e-mail adrese, tokene ni izvorne adrese.
Poslovna korespondencija
Ako se razgovor nastavi e-mailom ili preraste u projekat, obrađujemo kontakt i projektne podatke koje podijelite, kao što su imena, e-mail adrese, podaci o firmi i sadržaj naše prepiske, zajedno sa zapisima koje smo dužni čuvati.
4. Kako koristimo informacije
- Isporuka, zaštita i održavanje web stranice i kontakt API-ja.
- Primanje, provjera i odgovaranje na upite poslane obrascem.
- Sprječavanje automatizirane zloupotrebe i neželjene pošte.
- Dogovaranje, planiranje i isporuka posla za klijente.
- Vođenje evidencija koje smo zakonski dužni čuvati.
Prema GDPR-u oslanjamo se na legitimni interes za rad i zaštitu vlastitih usluga i za odgovaranje na upite (član 6(1)(f)), na radnje poduzete na vaš zahtjev prije sklapanja ugovora i na izvršenje ugovora (član 6(1)(b)), te na ispunjenje zakonskih obaveza gdje one postoje (član 6(1)(c)).
Ne koristimo vaše podatke za automatizirano odlučivanje sa pravnim ili sličnim značajnim učinkom i ne gradimo oglasne profile na osnovu posjeta stranici.
5. Kada dijelimo informacije
Silvercode ne prodaje lične podatke i ne dijeli ih za oglašavanje. Podaci se dijele samo sa pružaocima usluga koji čine našu infrastrukturu i samo u mjeri u kojoj im je potrebno:
- Google, za Firebase Hosting, koji poslužuje web stranicu i obrađuje podatke zahtjeva opisane iznad. Pogledajte Firebase informacije o privatnosti i Google Politiku privatnosti.
- Amazon Web Services, za kontakt API. Koriste se API Gateway, Lambda, DynamoDB, Simple Email Service, Systems Manager Parameter Store, Certificate Manager i Route 53, u regiji Evropa (Frankfurt). Pogledajte AWS Obavještenje o privatnosti.
Podatke možemo otkriti i kada to zakon zahtijeva ili kada je to potrebno radi utvrđivanja, ostvarivanja ili odbrane pravnih zahtjeva.
6. Čuvanje podataka
- Zapisi za zaštitu od zloupotrebe ističu automatski. Brojači ograničenja ističu unutar dvostrukog trajanja svog prozora, a zapisi tokena otprilike sat vremena nakon izdavanja.
- Poruke poslane obrascem čuvaju se u Silvercode sandučiću onoliko koliko je potrebno da se na upit odgovori i da o njemu ostane razuman trag, a zatim se brišu ili na vaš zahtjev.
- Zapise zahtjeva hostinga čuva Google prema vlastitim rokovima za Firebase Hosting.
- Klijentska i računovodstvena dokumentacija čuva se koliko zahtijevaju važeći zakonski rokovi.
7. Sigurnost
Sav promet ide preko HTTPS-a sa HSTS-om, a stranica šalje strogu Content Security Policy koja blokira skripte i veze trećih strana. Kontakt API prihvata zahtjeve samo sa naših vlastitih izvora.
Tajne su pohranjene šifrirano u AWS Systems Manager Parameter Storeu, a kontakt funkcija smije čitati samo te tajne, pisati samo u svoju tabelu, slati samo sa konfigurirane adrese i pisati samo vlastite zapise. Pristup sandučiću i cloud računima je ograničen i zaštićen kontrolama autentikacije.
Nijedan sistem nije savršeno siguran, ali projektujemo za najmanju količinu podataka sa kojom usluga i dalje radi.
8. Međunarodna obrada
Silvercode posluje iz Bosne i Hercegovine, koja je izvan Evropskog ekonomskog prostora. Kontakt API radi u AWS regiji Evropa (Frankfurt). Firebase Hosting je globalna mreža za isporuku sadržaja, pa zahtjevi prema stranici mogu biti posluženi i zabilježeni izvan vaše zemlje. Naši pružaoci usluga oslanjaju se na vlastite mehanizme prijenosa, uključujući standardne ugovorne klauzule Evropske komisije gdje one važe.
9. Vaša prava
Ovisno o tome gdje živite, možete imati pravo na pristup ličnim podacima koje čuvamo o vama, na njihov ispravak ili brisanje, na ograničenje ili prigovor na obradu, te na prijenos podataka u prenosivom obliku.
Zahtjeve pošaljite putem zaštićenog kontakt obrasca. Prije postupanja možemo zatražiti podatke koji nam potvrđuju da zahtjev dolazi od vas.
Možete se obratiti i nadzornom tijelu. U Bosni i Hercegovini to je Agencija za zaštitu ličnih podataka, a u Evropskom ekonomskom prostoru tijelo vaše zemlje prebivališta.
10. Djeca
Web stranica silvercode.dev namijenjena je osobama koje traže profesionalni softverski rad i nije usmjerena na djecu. Preko ove stranice svjesno ne prikupljamo lične podatke djece. Dobne granice za pojedine proizvode opisane su u njihovim politikama i na stranicama trgovina.
11. Izmjene politike
Ova politika može biti ažurirana kada se promijene naše usluge, pružaoci usluga ili zakonske obaveze. Datum izmjene prikazan je na vrhu ove stranice, a o značajnim izmjenama obavijestit ćemo odgovarajućim kanalom kada je to potrebno.
12. Kontakt
Kontrolor i kontakt za privatnost: Silvercode, Bosna i Hercegovina. Za pitanja i zahtjeve o privatnosti koristite zaštićeni kontakt obrazac.