Privacy Policy

IN COMPLIANCE WITH GDPR

Effective Date: 29 December 2025

Notice on the Collection and Processing of Personal Data

In accordance with the provisions of the Law on Personal Data Protection (“Official Gazette of the Republic of Serbia”, No. 87/2018, hereinafter: the “Law”), NEW LOOK Entertainment d.o.o. Belgrade hereby informs its clients, business partners, users and visitors, users of our users and other persons referred to in this Policy, other engaged persons, as well as potential employees (hereinafter: “Data Subjects”) about the purposes and legal grounds for the collection and processing of personal data, the types of data processed, data recipients, data retention practices, as well as the rights that Data Subjects have in relation to the processing of their personal data and the manner in which such rights may be exercised.

NEW LOOK Entertainment d.o.o., with its registered office at Knićaninova 14, 11158 Belgrade, company registration number: 20204575, e-mail: office@m1.rs, collects and processes the personal data of its clients, business partners, users and visitors, users of our users and other persons referred to in this Policy, in a lawful, fair and transparent manner, in accordance with the applicable regulations of the Republic of Serbia. NLE also retains data relating to former employees and former clients, to the extent and for the periods prescribed by applicable law.

Personal data means any information relating to an identified or identifiable natural person, whether directly or indirectly, while the processing of personal data means any operation or set of operations performed on personal data, whether by automated or non-automated means, such as collection, recording, storage, use, access, transfer, deletion or destruction of data.

Contact for questions and requests relating to personal data protection:
Danijela Stankovic
danijela.stankovic@m1.rs

What is GDPR – General Data Protection Regulation?

The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is a regulation through which the European Parliament, the Council and the European Commission sought to strengthen and harmonise data protection for individuals within the European Union (EU).

The purpose of the Regulation is to ensure that the level of protection of individuals’ rights and freedoms with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the protection against and prevention of threats to public security, is consistent across all Member States. In addition, data protection in the EU extends the scope of data protection legislation to companies outside the EU that process the data of EU residents and provides a framework for harmonising data protection regulations throughout the European Union.

The principle of accountability is a fundamental element of the GDPR. Organisations should be able to demonstrate that they have implemented GDPR requirements relating to the processing of personal data through a system that enables compliance with applicable requirements.

The Regulation was adopted on 27 April 2016 and has applied since 25 May 2018.

In addition to GDPR, NEW LOOK implements a quality management system (ISO 9001:2015) and an information security management system (ISO/IEC 27001:2022) in order to ensure consistent process management, information protection and continuous improvement.

These protective measures are based on risk assessment and the requirements of ISO/IEC 27001:2022, as well as on obligations arising from the GDPR and applicable regulations of the Republic of Serbia.

NEW LOOK implements appropriate technical and organisational measures to protect personal data and information security, including access control, system and communications protection, incident management, supplier management and business continuity measures. These measures are regularly reviewed and improved in accordance with internal procedures.

We comply with the applicable regulations of the Republic of Serbia and relevant requirements relating to data protection and information security.

Please read this Privacy Policy carefully before accessing or using any of our services.

Purpose of the Privacy Policy

The NEW LOOK Privacy Policy describes how we collect and use information relating to our unregistered and registered users.

The purpose of this Privacy Policy is to provide you with a clear explanation of when, why and how we collect and use your personal data, as well as an explanation of your statutory rights. This Privacy Policy is not intended to override the terms of any agreement you have entered into with us, nor any rights you may have under applicable data protection legislation.

This Policy describes our privacy practices, including what information we collect about our visitors and users, how we collect such data, what we do with it, how we protect it, and what rights you have in relation to such information.

If you access or use any of our services, you acknowledge that you have read this Privacy Policy.

What Information Do We Collect?

We collect two types of information: personal information (which may be used to uniquely identify an individual) and non-personal information (which does not identify an individual).

We collect information relating to our users and visitors, users of our users and other persons referred to in this Policy, including:

1. Non-identifying information relating to visitors or unidentified users, which may be made available to us or collected automatically. Such non-personal information does not enable us to identify the visitor or user from whom the data was collected. The information we collect generally consists of technical and aggregated usage data, such as visitor and user activity, clickstream activity, etc.

2. Individual information, meaning information that identifies an individual or may, with reasonable efforts, lead to the identification of an individual, or information that may be private or sensitive in nature (“Personal Information”). The personal information we collect generally consists of information required for entering into contracts and contact details (e.g. e-mail addresses).

For the avoidance of doubt, any non-personal information that is linked to personal data in order to improve the services we provide shall also be considered and treated by us as personal information.

We collect similar information relating to visitors and users of our websites and our clients’ websites (“Users-of-Users”). With regard to Users-of-Users, NewLook Entertainment acts as a data processor and collects and processes such information solely on behalf of and in accordance with the documented instructions of our clients, who act as data controllers in such cases. NewLook Entertainment does not independently determine the purposes and means of processing such data, except where necessary to comply with legal obligations applicable to us as a processor.

Cookies

Our website may use cookies and similar technologies for the basic functioning of the website, analytics and improvement of the user experience. Details regarding the types of cookies used and the management of consent are available in a separate Cookie Policy and/or through the cookie management banner.

How Do We Collect Information?

We collect information in the following ways:

We collect all information required for entering into contracts and carrying out our core business activities, as regulated by applicable legal provisions. All contracts are entered into in accordance with applicable laws and contain the minimum information required.

We collect information when you visit our website or use our services. In such cases, data may be collected and such use may be recorded, independently or with the assistance of third-party services, including through the use of cookies and other tracking technologies, as described in more detail below.

We also collect information from third-party sources, as described below. When you visit or use our services, you may also provide us with certain information, either automatically through the use of the service or manually.

Why Do We Collect Information?

The processing of personal data is based on the performance of a contract, the consent provided by the Data Subject, the legitimate interests of NEW LOOK, or compliance with legal obligations in accordance with the GDPR and the regulations of the Republic of Serbia.

We collect all non-personal and personal information for the following purposes:

  1. To provide and manage the services we offer;
  2. To further develop, customise and improve our services based on the common or individual preferences, experiences and difficulties of visitors and users;
  3. To provide our users with ongoing information;
  4. To contact our visitors and users with general or personalised notifications and promotional messages relating to our services, as described in more detail below;
  5. To collect and process statistical data through non-personal information that we or our business partners may use to provide and improve our respective services;
  6. To improve our data protection capabilities and prevent fraud;

all in accordance with applicable laws and regulations.

We will use your personal data only for the purposes specified in this Policy where we are satisfied that:

  1. The use of your personal data is necessary to comply with an applicable legal or regulatory obligation to which we are subject; or
  2. The processing of your personal data may be necessary for the purposes of pursuing our legitimate interests, including maintaining and improving our services, analysing user trends and assessing the effectiveness of campaigns, provided that such processing is carried out lawfully, appropriately and proportionately and respects your rights and freedoms relating to the protection of personal data.

Our information society services may also be available to minors. A minor who has reached the age of 15 may independently provide consent to the processing of their personal data in connection with the use of such services. For a minor under the age of 15, where processing is based on consent in connection with the use of information society services, consent shall be provided by the parent exercising parental responsibility or another legal representative, in accordance with applicable regulations.

Where NewLook Entertainment processes personal data on behalf of its client, acting as a data processor, the processing shall be carried out in accordance with the documented instructions of the client as data controller, including with regard to the purposes of processing and the target group of users, and in accordance with applicable personal data protection regulations.

We collect and use personal data for purposes for which an appropriate legal basis exists, including communicating with our visitors and users, providing and improving our services, carrying out activities for our clients and complying with legal obligations applicable to us. If we become aware that personal data has been collected or processed in a manner that is not compliant with applicable regulations, we will take appropriate measures, including deleting the data where there is no appropriate legal basis for its further processing.

International Data Transfers

If, in the course of providing our services, we use cloud/SaaS providers whose servers or support services are located outside the Republic of Serbia and/or the European Economic Area (EEA), we carry out data transfers using appropriate safeguards (e.g. EU Standard Contractual Clauses, transfer risk assessments and additional technical measures), in accordance with applicable regulations.

Where Do We Store Your Data?

DATA RETENTION PERIOD: Personal data is retained for as long as necessary to fulfil the purpose of processing, or until consent is withdrawn, except where a longer retention period is prescribed by law.

  • Contracts and business correspondence: During the contractual relationship and, following its termination, for the period necessary to establish, exercise, protect or defend legal claims, in accordance with applicable limitation periods. Where no specific limitation period is prescribed, the general limitation period for claims is 10 years. (LAW ON OBLIGATIONS, “Official Gazette of the SFRY”, Nos. 29/78, 39/85, 45/89 – decision of the Federal Constitutional Court and 57/89; “Official Gazette of the FRY”, No. 31/93; “Official Gazette of Serbia and Montenegro”, No. 1/2003 – Constitutional Charter; and “Official Gazette of the RS”, No. 18/2020.)
  • Accounting and tax documentation (invoices and supporting documents): In accordance with the retention periods prescribed by the Law on Accounting and tax regulations. Accounting documents on the basis of which entries are made in the accounting records shall be retained for 5 years, while certain categories of accounting documentation are retained for longer periods: journals and the general ledger for 10 years, and financial statements and annual business reports for 20 years. The retention period is calculated from the last day of the financial year to which the documentation relates. (LAW ON ACCOUNTING, “Official Gazette of the RS”, Nos. 73/2019 and 44/2021 – other Law.)
  • Marketing communications data: Until consent is withdrawn, or until an objection or unsubscribe request is submitted, where processing is based on consent or the right to object. Thereafter, the data shall be deleted or its processing restricted, unless another valid legal basis or legal obligation exists for further retention.
  • IT logs and security records: Up to 12 months, unless a longer period is justified by security requirements, the investigation of a security incident, the establishment, exercise or defence of legal claims, or a legal obligation.

We store the data we hold on NEW LOOK infrastructure located in a secure physical environment. All data is protected through organisational and technical measures in accordance with the requirements of ISO/IEC 27001:2022 and GDPR.

Service providers that store or process your personal information on behalf of NEW LOOK are contractually required to protect and secure such information in accordance with the requirements set out in the applicable NDA.

NEW LOOK is responsible for the processing of personal information it receives, including with regard to subsequent transfers to third parties acting as agents on behalf of NEW LOOK.

In certain circumstances, NEW LOOK may be required to disclose personal data in response to lawful requests from government authorities, including to comply with national security and law enforcement requirements, and will do so only where permitted by applicable local data protection laws.

Upon your request, NEW LOOK will provide information as to whether we hold any of your personal information. You may access, correct or request deletion of your personal data by contacting us at office@m1.rs. We will respond to your request within the period prescribed by applicable local laws or within a reasonable timeframe.

Please note that permanent deletion removes all your data from NEW LOOK databases and is possible where permitted by applicable regulations. Once this process has been completed, you will no longer be able to use any of our services. Your user account and all associated data will be permanently deleted, and NEW LOOK will not be able to restore your account or retrieve your data in the future. If you contact our support team in the future, the system will not recognise your account.

If you have any concerns regarding the retention of your data, please contact us at office@m1.rs. We will respond as soon as reasonably possible.

Rights Relating to Your Personal Data

ADDITIONAL RIGHTS: Data Subjects have the right to restriction of processing, the right to object to processing, the right to data portability, as well as the right to lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection.

Through the requirements of ISO 9001:2015, ISO/IEC 27001:2022 and GDPR, NEW LOOK has implemented all appropriate technical and organisational measures to enable you to access, receive a copy of, update, amend, delete or restrict the use of your personal data.

Before disclosing the requested personal data, we may request additional information from you in order to verify your identity and ensure security.

You have the right to lodge a complaint with the competent local supervisory authority for data protection. However, we recommend that you contact us first.

If you wish to access and/or request that we correct personal data stored by us, or if you wish to request a list of personal data, if any, that we have disclosed to third parties for direct marketing purposes, please contact us at office@m1.rs.

We will make all reasonable efforts to promptly investigate your request, unless we require additional information from you in order to fulfil it, subject to applicable legal and other permissible considerations.

Data Retention

We may retain your personal information, as well as information relating to users of our clients, for as long as your user account remains active, as specified in this Privacy Policy, or as otherwise necessary to provide our services.

We may continue to retain such personal data even after your user account has been deactivated and/or you have ceased using any particular services, to the extent reasonably necessary to comply with legal obligations, resolve disputes involving our clients or their users, and prevent potential fraud and misuse.

Security

NEW LOOK implements appropriate technical and organisational measures to protect personal data and information, based on risk assessment. These measures are regularly reviewed and improved within the framework of our quality management system (ISO 9001:2015) and information security management system (ISO/IEC 27001:2022).

Regardless of the measures and efforts undertaken by NEW LOOK, we cannot and do not guarantee the absolute protection and security of your personal information, information relating to users of our clients, or any other content we receive.

We are committed to protecting your personal information and use numerous organisational and technical measures to achieve this.

Rights of Data Subjects

In accordance with applicable regulations, you have the right to access, rectification, erasure (where applicable), restriction of processing, objection (to processing based on legitimate interests) and withdrawal of consent (where applicable).

Certain rights may be restricted due to legal obligations of the employer or for the purpose of protecting or defending legal claims.

To exercise your rights, you may contact us at danijela.stankovic@m1.rs.

Who Should You Contact in Case of Additional Questions or Requests for Clarification?

For the purpose of exercising your rights regarding the protection of your personal data, as well as for any necessary explanations concerning data protection, you may contact:

Danijela Stanković
NEW LOOK ENTERTAINMENT d.o.o.
Data Protection Officer (DPO)
E-mail: danijela.stankovic@m1.rs

Notice of the Right to Object

You have the right to object to processing where the processing is carried out solely on the basis of the performance of a task carried out in the public interest or the exercise of official authority vested in the company, or solely for the purposes of pursuing the legitimate interests of the company or a third party.

The company shall cease processing the personal data of the person who has submitted an objection unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights or freedoms of the Data Subject, or the processing is necessary for the establishment, exercise or defence of legal claims.

You have the right to object at any time to the processing of your personal data where the processing is carried out for the purposes of direct marketing, including profiling to the extent that it is related to such direct marketing. In such cases, your data may no longer be processed for these purposes.

You have the right to restriction of processing while the validity of your objection is being assessed. During this period, the data may only be further processed on the basis of your consent, except where the data is being stored, where processing is necessary for the establishment, exercise or defence of legal claims, for the protection of the rights of other natural or legal persons, or for reasons of important public interest.

If you believe that your rights have been violated, you may contact us at danijela.stankovic@m1.rs and/or lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection.

Amendments to This Notice

We may update this Notice from time to time. The latest version will be made available to employees and candidates upon request or through internal channels.