Privacy Policy
Last updated: 1 June 2026
1. Who We Are
Inverba d.o.o. (hereinafter "Inverba", "we", "us", "our") is a company registered in the Republic of Serbia that operates the InVerba AI document intelligence platform.
Our role under the GDPR depends on the data in question. We are the data controller for personal data processed through our website (inverba.app) and for platform account data (names, e-mails, usage records of platform users). For the content of documents your organisation uploads to the platform - and any personal data those documents contain - your organisation is the data controller and Inverba acts as a data processor, processing that content only on your organisation's instructions under a Data Processing Agreement (Art. 28 GDPR).
Contact: office@inverba.app · Beograd, Serbia
Privacy enquiries: office@inverba.app
2. What Data We Collect
2.1 Website visitors
- Contact form submissions: name, business email address, company name, job title, phone number (optional), message content, and selected industry
- Server logs: IP address, browser type, referring page, pages visited, timestamp - retained for 90 days for security purposes
2.2 Platform customers
- Account data: name, business email, organisation name, billing address
- Usage data: query logs (questions asked, documents retrieved, timestamps), session identifiers, feature usage statistics
- Document data: documents your organisation uploads are stored in your dedicated, encrypted S3 bucket and are not accessible to Inverba staff except under explicit support requests subject to your written authorisation. Inverba processes document content solely as a processor, on your organisation's instructions (see Section 1)
2.3 What we do not collect
Through our website and account management we do not collect biometric data, health data, payment card numbers (we bill by invoice and do not process card payments), or data from individuals under 18 years of age.
Documents uploaded to the platform by your organisation may contain special categories of personal data (for example, health data in a medical institution's records). For such content your organisation remains the data controller and is responsible for its lawful basis; Inverba processes it only on your organisation's instructions under the Data Processing Agreement. Onboarding of special-category document sets (such as medical records) takes place only after a joint data protection impact assessment (DPIA) with the client.
3. How We Use Your Data
- Providing the service: answering your demo request, provisioning and managing your account, processing queries against your documents
- Customer support: diagnosing technical issues, responding to helpdesk tickets
- Service improvement: aggregated, anonymised usage analytics to improve product features
- Security: detecting and preventing unauthorised access, fraud, and abuse
- Legal compliance: fulfilling obligations under Serbian and EU law, including tax and accounting obligations
- Marketing: sending product updates and relevant content by email, only to contacts who have given explicit consent or are existing customers (with opt-out in every email)
4. Legal Basis for Processing
Under the GDPR and the Serbian Law on Personal Data Protection, we rely on the following legal bases:
- Contract performance (Art. 6(1)(b) GDPR): processing necessary to deliver the platform to paying customers
- Legitimate interests (Art. 6(1)(f) GDPR): security monitoring, product improvement using anonymised analytics, and responding to enquiries
- Legal obligation (Art. 6(1)(c) GDPR): tax records, audit requirements
- Consent (Art. 6(1)(a) GDPR): marketing emails to non-customers; you may withdraw consent at any time
5. Data Retention
- Contact enquiries: 24 months from last contact, unless a customer relationship develops
- Customer account data: for the duration of the contract plus 5 years (legal obligation)
- Customer document data: deleted within 30 days of account termination or upon your written request
- Server logs: 90 days
- Marketing consent records: until consent is withdrawn plus 3 years
6. Third-Party Processors
We share personal data only with processors who have agreed to appropriate data protection terms:
- Amazon Web Services (AWS) - cloud hosting, storage, database, and authentication (S3, RDS, KMS, Cognito); data stored in eu-central-1 (Frankfurt, Germany); AWS DPA applies
- AWS Bedrock - AI model inference; document content is processed in-region (Frankfurt) over a private network endpoint and not used for model training under our configuration
- AWS SES - transactional email delivery (EU region)
We do not sell, rent, or trade personal data to any third party for their own marketing purposes.
7. International Transfers
Customer data is stored and processed in AWS eu-central-1 (Frankfurt, Germany) within the European Economic Area. The EEA offers an adequate level of data protection under Serbian law.
For any processing outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.
8. Your Rights Under GDPR
If you are based in the EU, EEA, or Serbia, you have the following rights:
- Right of access (Art. 15): request a copy of the personal data we hold about you
- Right to rectification (Art. 16): ask us to correct inaccurate data
- Right to erasure (Art. 17): request deletion of your data where we no longer have a legal basis to hold it
- Right to restriction (Art. 18): ask us to limit processing while a dispute is resolved
- Right to data portability (Art. 20): receive your data in a machine-readable format
- Right to object (Art. 21): object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent: at any time for consent-based processing, without affecting prior lawful processing
To exercise any of these rights, email office@inverba.app. We respond within 30 days. You also have the right to lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia (www.poverenik.rs) or a supervisory authority in your EU member state.
9. Security
We implement technical and organisational measures to protect your personal data, including:
- AES-256 encryption at rest, TLS 1.2+ in transit
- Per-client AWS KMS keys for document storage
- Role-based access control; Inverba staff have no standing access to customer document data
- Full audit trails for all data access events
- Annual security reviews and vulnerability assessments
See our Security page for details.
10. Cookies
Our marketing website (inverba.app) uses only strictly necessary cookies required for secure page delivery. We do not use third-party analytics cookies or advertising cookies without explicit consent. The platform may use session cookies for authentication; these are strictly necessary and do not require consent.
11. Children's Privacy
The InVerba platform is a business-to-business service intended for professionals aged 18 and over. We do not knowingly collect personal data from children.
12. Updates to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to registered customers at least 30 days before taking effect. The "Last updated" date at the top of this page reflects the most recent revision.
Questions about this policy? Email office@inverba.app.