Privacy & Personal Data Protection Policy
This Policy explains what personal data may be processed, why it is processed and what rights users have.
Last updated: 07. September 2026.
1. Data controller
The provider operating Dženana Vocal Academy / DženanaVoice acts as the data controller for personal data processed in connection with this website.
Privacy requests may be submitted through the website contact page or official contact email.
2. Applicable rules
Personal data is processed under applicable Bosnia and Herzegovina data-protection legislation, including the Personal Data Protection Law of Bosnia and Herzegovina, Official Gazette of BiH No. 12/25.
Where applicable, relevant GDPR requirements are also observed.
3. Data we may process
We may process names, email and contact details, account information, service purchases, bookings, messages, newsletter subscriptions, vocal assessment responses, AI Vocal Coach inputs, IP addresses, browser/device information, security logs and transaction information.
4. Purposes of processing
Data may be processed to manage accounts, deliver services, organize courses and sessions, process transactions, answer inquiries, provide AI and vocal assessment functions, deliver newsletters, protect the service and comply with legal obligations.
5. Legal bases
Depending on the circumstances, processing may rely on performance of a contract, pre-contractual steps, legal obligations, legitimate interests or consent.
6. AI Vocal Coach
Text submitted to AI Vocal Coach may be processed to generate responses and may involve contracted AI or cloud providers.
Users should not submit passwords, financial data, identification documents or unnecessary sensitive information.
7. Payments
Payments may be processed by external payment providers. We may retain transaction amount, currency, status, purchased service and transaction identifiers where necessary.
8. Service providers
Data may be shared where necessary with hosting, email, anti-spam, analytics, payment, cloud and AI service providers for the relevant purpose.
9. Retention
Personal data is retained only as long as necessary for the relevant purpose, contractual relationship, dispute handling and applicable legal, tax, accounting and security obligations.
10. Security
Reasonable technical and organizational measures are used to protect personal data against unauthorized access, loss, misuse, alteration or disclosure.
11. User rights
Subject to applicable law, individuals may have rights to information, access, correction, deletion, restriction, objection, portability where applicable, withdrawal of consent and complaint to the competent authority.
12. Children and minors
Special care is taken with minors data. Parental or legal-guardian consent must be obtained where required by applicable law.
13. Cookies
Information about cookies, cookie categories and consent management is available in the Cookie Policy.
