Back

Privacy Policy

Last updated, 16 July 2026.

This policy explains what data mojGO collects, why it is processed, and what your rights are. It is written in line with the General Data Protection Regulation (GDPR) and Serbia's Personal Data Protection Act.

Who processes the data

mojGO is currently developed and operated by Goran Ninković as an independent developer during the beta period. For any data-related questions, contact us at privatnost@mojgo.rs. Once a legal entity providing the service is established, this section will be updated.

What data we collect

Account data: the first name, last name and email address of the people using the app (HR admins, managers, employees). Passwords are stored only in hashed form. Leave data: annual-leave, sick-leave and other absence requests, dates, statuses and generated decisions. Technical data: basic usage data and error logs, for app stability and security.

Legal basis for processing

We process data to perform the service agreement (Art. 6(1)(b) GDPR), to help your employer meet its obligations under the Labor Law (Art. 6(1)(c)), and on the basis of legitimate interest in the security and improvement of the service (Art. 6(1)(f)).

Processors and hosting

Data is stored on servers in the European Union. We use the following processors, each under an appropriate data-processing agreement: Supabase (database and authentication, EU region), Vercel (application hosting), Resend (system email delivery), Sentry (error monitoring) and BetterStack (uptime and log monitoring). We do not sell or share data for marketing purposes.

How long we keep data

We keep account data for as long as the account is active. After an account is deleted, we erase personal data within 30 days, unless the law requires us to keep it longer. Error logs are deleted within 90 days.

Your rights

You have the right to access, rectify, erase, restrict and object to the processing of your data, the right to data portability, and the right to withdraw consent. Send requests to privatnost@mojgo.rs and we respond within 30 days. You also have the right to lodge a complaint with the Serbian Commissioner for Information of Public Importance and Personal Data Protection.

Security

We protect data with encryption in transit (SSL/TLS) and at rest, role-based access, and per-organization data isolation at the database level. Despite these measures, no system is perfectly secure, so we commit to notifying you without undue delay of any significant incident.

Changes to this policy

We may update this policy from time to time. We notify you of material changes in advance, before they take effect.