Privacy and Cookies Policy
Privacy & Cookies Policy
Effective Date: October 24, 2025
This Policy explains how NEURAOPTICS d.o.o. Beograd (“NEURAOPTICS”, “we”, “us”, “our”) collects, uses, shares and stores personal data, and how we use cookies and similar technologies on our website and online store.
1) Who we are (Data Controller)
NEURAOPTICS d.o.o. Beograd
Company number: 22138545
Tax ID (PIB): 115291743
Address: Prizrenska 5, apt. 3, 11080 Zemun, Belgrade, Serbia
Privacy contact email: info@bluverra.com
Phone: +381 69 747 747
Data Protection Officer (DPO): Joksović, Stojanović & Partners Law Office (JSP Law)
Address: Hadži Melentijeva 46, 11000 Belgrade, Serbia
Main office phones: +381 11 344 59 70 / +381 11 344 38 37 / +381 11 344 08 22
Fax: +381 11 344 59 72
General email: office@jsplaw.co.rs
Website: jsplaw.co.rs
Contact – Alex Petrović (Senior Partner):
-
Email: alex@jsplaw.co.rs
-
Mobile: +381 62 166 0320
EU representative (GDPR Article 27): not appointed; will be designated in the EU/EEA according to Article 27 GDPR when applicable.
We process personal data in accordance with the laws of the Republic of Serbia and the General Data Protection Regulation (GDPR) where applicable.
2) Definitions (summary)
-
Personal data: information relating to an identifiable natural person (e.g. name, address, email, IP address).
-
Processing: any operation on data (collecting, storing, using, disclosing, deleting).
-
Cookies: small files stored on your device for site functionality, analytics, and advertising.
3) Data we collect
We only collect data necessary for defined purposes:
-
Order & delivery details: full name, address, email, phone, cart content, order number, delivery options, notes.
-
Payment information:
-
Card payments (Visa, Mastercard, Dina, Amex) – card details are processed by authorized payment processors/banks; we do not have access to or store full card details.
-
IPS (NBS Instant/QR) – payment details (amount, reference, payer/recipient account), date and time of transaction.
-
Cash on delivery – amount, payment status, shipment reference.
-
-
Account data: if you create an account – username/email, password (hashed), order history.
-
Communication: messages via contact form, email, phone; complaints and requests.
-
Marketing & subscriptions: newsletter email, preferences, email engagement (if applicable).
-
Technical data & cookies: IP address, cookie identifiers, device/browser type, language settings, page views, traffic sources, on-site behaviour.
4) Purpose of processing & legal basis
-
Order fulfilment & delivery (contract performance): order processing, billing, delivery, customer support.
-
Complaints & warranty (legal obligation): handling consumer rights and legal record-keeping.
-
Security & fraud prevention (legitimate interest): account protection, fraud detection.
-
Analytics & website improvement (consent): user experience, performance monitoring. Non-essential cookies load only after consent.
-
Marketing (consent): newsletters and promotional communication. You may unsubscribe at any time.
You may withdraw consent at any time via the Cookie Settings banner or the unsubscribe link in marketing emails.
5) Cookies & similar technologies
5.1 Types of cookies we use
-
Necessary: session, cart, checkout, security.
-
Functional: language/region preferences.
-
Analytics: traffic measurement and UX improvements.
-
Marketing: ads personalization and campaign measurement.
5.2 Consent management
On your first visit, a cookie banner will appear. Non-essential cookies (functional, analytics, marketing) are set only after explicit consent. You can accept all, reject non-essential or customize Cookie Settings. You can change your choice later from the footer or browser settings.
Note: third-party tools (analytics/ads) must not load before consent is given.
5.3 Cookie list (example – adjust for your store)
| Category | Example cookie | Purpose | Retention |
|---|---|---|---|
| Necessary | session_id, cart, checkout_token | Session, cart, checkout | Session – 2 years |
| Functional | locale_pref, cookie_consent | Preferences, language | 1 month – 1 year |
| Analytics | _ga, _gid | Google Analytics | 1 day – 2 years |
| Marketing | _fbp, _gcl_au | Ads & attribution | 1 day – 3 months |
Note: update cookie names and durations based on actual setup.
6) Data recipients & processors
-
E-commerce platform (Shopify) – hosting, checkout, technical operations.
-
Payment processor/bank (CorvusPay / Banca Intesa) – card transaction processing; we do not store card details.
-
IPS payments (NBS) – bank-level processing.
-
Courier services – logistics and COD collection.
-
Accounting – invoicing & legal records.
-
Email/marketing providers – transactional and marketing messages.
-
Analytics & advertising – measurement, personalization (with consent).
-
IT security & support – system maintenance.
All processors operate under contractual data protection obligations.
7) International transfers
If data is transferred outside RS/EU (e.g. Canada/USA services), we apply Standard Contractual Clauses and additional safeguards as required.
8) Data retention
We retain data only as long as necessary:
-
Orders & invoices: accounting/legal retention (typically 5–10 years).
-
Support/complaints: until case resolution + legal period.
-
User accounts: until deletion request (unless legal retention applies).
-
Marketing: until consent withdrawal/unsubscribe.
-
Cookies: as listed in section 5.3.
9) Your rights
You may request: access, correction, erasure, restriction, data portability, objection (including marketing), and withdrawal of consent at any time.
Responses are provided within 30 days (may extend 60 days for complex requests). You may file a complaint with the Serbian Commissioner for Information & Data Protection or an EEA authority.
10) Data security
We implement technical and organizational security measures (encryption, access control, minimization, processor contracts). No system is 100% secure, but we act promptly to reduce risk and manage incidents.
11) Payment & refund policy (summary)
-
Cards: refunds only via transaction reversal.
-
IPS: refunds only to buyer’s bank account.
-
Cash on delivery: refunds only to bank account.
See full policy on the website.
12) Changes to this Policy
We may update this Policy occasionally. The latest version is published on this page with the updated effective date.
13) Contact
Privacy & Cookies inquiries:
NEURAOPTICS d.o.o. Beograd – Privacy Department
Email: info@bluverra.com
Address: Prizrenska 5, apt. 3, 11080 Zemun, Belgrade, Serbia
14) Data provision requirements
Providing data necessary for purchasing, delivery and invoicing is a contractual and/or legal requirement. Without it, we cannot fulfil your order. Marketing data is optional.
15) Automated decision-making
We do not use automated decision-making or profiling that produces legal or significant effects. If policies change, we will notify users and preserve GDPR rights.
16) Source of data
We obtain data directly from you during purchase/registration and through cookies & similar technologies. Limited third-party data may apply for shipping & payment execution only.
17) EU/EEA customers
If we offer services to individuals in the EU/EEA or monitor behaviour, GDPR obligations apply, including appointing an EU representative when required.
18) Privacy declaration (bank requirement)
On behalf of NEURAOPTICS d.o.o. Beograd (bluverra.com), we commit to protecting customer privacy. We collect only essential data needed for business operations. Users may request removal from marketing lists. All data is securely stored and accessible only to authorized staff and partners under confidentiality obligations.

