Privacy Policy
Seven Pilates & Sculpt Doo
Effective Date: May 2026
1. Introduction
Seven Pilates & Sculpt d.o.o. ("Studio", "we", "us", or "our"), located at Braće Nedića 27,
Belgrade, Serbia, is committed to protecting your personal data. This Privacy Policy explains
what personal data we collect, how we use it, your rights in relation to it, and how we keep it
safe.
Belgrade, Serbia, is committed to protecting your personal data. This Privacy Policy explains
what personal data we collect, how we use it, your rights in relation to it, and how we keep it
safe.
This Policy applies to all personal data we collect through our website at www.sevenstudio.rs
("Website"), in person at our studio, and through our booking and payment systems.
("Website"), in person at our studio, and through our booking and payment systems.
We process personal data in accordance with the Law on Personal Data Protection of the
Republic of Serbia ("ZZPL", Official Gazette RS No. 87/2018) and applicable secondary
legislation.
Republic of Serbia ("ZZPL", Official Gazette RS No. 87/2018) and applicable secondary
legislation.
2. Who is the Data Controller
The data controller responsible for your personal data is:
Seven Pilates & Sculpt d.o.o.
Braće Nedića 27, Belgrade, Serbia
Email: Marina@sevenstudio.rs
Website: www.sevenstudio.rs
Braće Nedića 27, Belgrade, Serbia
Email: Marina@sevenstudio.rs
Website: www.sevenstudio.rs
3. What Data We Collect
We may collect and process the following categories of personal data:
3.1 Data You Provide Directly
• Full name
• Email address
• Phone number
• Date of birth (where required for age verification or health purposes)
• Health information you voluntarily disclose prior to class participation
• Payment details (processed securely via third-party payment providers; we do not
store full card details)
• Email address
• Phone number
• Date of birth (where required for age verification or health purposes)
• Health information you voluntarily disclose prior to class participation
• Payment details (processed securely via third-party payment providers; we do not
store full card details)
3.2 Data Collected Automatically
• IP address and device information
• Browser type and operating system
• Pages visited and time spent on our Website
• Referring URLs
• Browser type and operating system
• Pages visited and time spent on our Website
• Referring URLs
This data is collected via cookies and similar tracking technologies. Please see Section 9
(Cookies) for more detail.
(Cookies) for more detail.
3.3 Data From Booking Systems
When you book a class or purchase a package through our booking platform, we receive data
generated by that transaction, including booking history, attendance records, and package
usage.
generated by that transaction, including booking history, attendance records, and package
usage.
4. How We Use Your Data
We use your personal data for the following purposes:
4.1 Performance of a Contract
• Processing class bookings and package purchases
• Managing your account and booking history
• Processing payments and issuing receipts
• Communicating with you about your bookings, cancellations, and class credits
• Managing your account and booking history
• Processing payments and issuing receipts
• Communicating with you about your bookings, cancellations, and class credits
4.2 Legitimate Interests
• Improving our services and website based on usage data
• Sending administrative communications (e.g., class schedule changes, studio
updates)
• Maintaining the safety and security of our studio and systems
• Sending administrative communications (e.g., class schedule changes, studio
updates)
• Maintaining the safety and security of our studio and systems
4.3 Consent
• Sending promotional emails, newsletters, or offers about our classes and events
(only where you have opted in)
• Using your photos or testimonials in marketing materials (only with your explicit
written consent)
(only where you have opted in)
• Using your photos or testimonials in marketing materials (only with your explicit
written consent)
4.4 Legal Obligation
• Complying with applicable Serbian law, including tax and financial record-keeping
obligations
• Responding to lawful requests from public authorities
obligations
• Responding to lawful requests from public authorities
5. Legal Basis for Processing
Under the ZZPL, we rely on the following legal bases:
• Contract: processing necessary to fulfil your booking or purchase
• Legitimate interests: where our interests in operating the studio and improving our
services do not override your rights
• Consent: for marketing communications and use of your image or testimonial
• Legal obligation: where processing is required by Serbian law
• Legitimate interests: where our interests in operating the studio and improving our
services do not override your rights
• Consent: for marketing communications and use of your image or testimonial
• Legal obligation: where processing is required by Serbian law
Where we rely on consent, you have the right to withdraw it at any time without affecting the
lawfulness of processing prior to withdrawal.
lawfulness of processing prior to withdrawal.
6. Who We Share Your Data With
We do not sell your personal data. We may share it with the following categories of third parties
only to the extent necessary:
only to the extent necessary:
• Booking and studio management platform providers (e.g., Glofox or equivalent),
solely to operate the booking system
• Payment processing providers, for secure transaction processing
• Email and communication service providers, for sending booking confirmations and
notifications
• Accountants or legal advisors, where required to meet our legal obligations
• Public authorities, where required by law
solely to operate the booking system
• Payment processing providers, for secure transaction processing
• Email and communication service providers, for sending booking confirmations and
notifications
• Accountants or legal advisors, where required to meet our legal obligations
• Public authorities, where required by law
All third-party processors are required to handle your data in accordance with applicable data
protection law and are bound by appropriate data processing agreements.
protection law and are bound by appropriate data processing agreements.
7. International Data Transfers
Some of our third-party service providers (such as booking or email platforms) may process
your data outside the Republic of Serbia. Where this occurs, we ensure that appropriate
safeguards are in place in accordance with the ZZPL, such as standard contractual clauses or
adequacy decisions.
your data outside the Republic of Serbia. Where this occurs, we ensure that appropriate
safeguards are in place in accordance with the ZZPL, such as standard contractual clauses or
adequacy decisions.
8. How Long We Keep Your Data
We retain your personal data only for as long as necessary for the purposes described in this
Policy, or as required by law. Our standard retention periods are:
Policy, or as required by law. Our standard retention periods are:
• Account and booking data: 3 years from your last interaction with us
• Financial and transaction records: 5 years, as required by Serbian accounting law
• Health information: deleted within 30 days of your last class, unless you request
otherwise
• Marketing consent records: retained until you withdraw consent, plus 1 year
• Financial and transaction records: 5 years, as required by Serbian accounting law
• Health information: deleted within 30 days of your last class, unless you request
otherwise
• Marketing consent records: retained until you withdraw consent, plus 1 year
After the applicable retention period, data is securely deleted or anonymised.
9. Cookies
Our Website uses cookies and similar technologies to improve functionality and analyse
usage. We use:
usage. We use:
• Essential cookies: necessary for the Website to function (e.g., session management,
booking functionality)
• Analytics cookies: to understand how visitors use our Website (e.g., Google Analytics
or equivalent)
• Marketing cookies: only if you consent, to track the effectiveness of our promotional
activity
booking functionality)
• Analytics cookies: to understand how visitors use our Website (e.g., Google Analytics
or equivalent)
• Marketing cookies: only if you consent, to track the effectiveness of our promotional
activity
You can manage or disable cookies through your browser settings at any time. Disabling
essential cookies may affect the functionality of our Website.
essential cookies may affect the functionality of our Website.
10. Your Rights
Under the ZZPL, you have the following rights in relation to your personal data:
• Right of access: to request a copy of the personal data we hold about you
• Right to rectification: to request correction of inaccurate or incomplete data
• Right to erasure: to request deletion of your data, subject to legal retention
obligations
• Right to restriction: to request that we limit processing of your data in certain
circumstances
• Right to data portability: to receive your data in a structured, machine-readable
format
• Right to object: to object to processing based on legitimate interests or for direct
marketing
• Right to withdraw consent: where processing is based on consent, to withdraw it at
any time
• Right to rectification: to request correction of inaccurate or incomplete data
• Right to erasure: to request deletion of your data, subject to legal retention
obligations
• Right to restriction: to request that we limit processing of your data in certain
circumstances
• Right to data portability: to receive your data in a structured, machine-readable
format
• Right to object: to object to processing based on legitimate interests or for direct
marketing
• Right to withdraw consent: where processing is based on consent, to withdraw it at
any time
To exercise any of these rights, please contact us at Marina@sevenstudio.rs. We will respond
within 30 days. We may need to verify your identity before fulfilling your request.
within 30 days. We may need to verify your identity before fulfilling your request.
If you are not satisfied with how we handle your request, you have the right to lodge a
complaint with the Commissioner for Information of Public Importance and Personal Data
Protection of the Republic of Serbia (www.poverenik.rs).
complaint with the Commissioner for Information of Public Importance and Personal Data
Protection of the Republic of Serbia (www.poverenik.rs).
11. Data Security
We take appropriate technical and organisational measures to protect your personal data
against unauthorised access, loss, destruction, or alteration. These include secure access
controls, encrypted data transmission (HTTPS), and limited staff access to personal data on a
need-to-know basis.
against unauthorised access, loss, destruction, or alteration. These include secure access
controls, encrypted data transmission (HTTPS), and limited staff access to personal data on a
need-to-know basis.
While we take all reasonable steps to protect your data, no system is entirely immune to risk. In
the event of a data breach that is likely to result in a risk to your rights and freedoms, we will
notify the relevant supervisory authority and, where required, you directly, in accordance with
the ZZPL.
the event of a data breach that is likely to result in a risk to your rights and freedoms, we will
notify the relevant supervisory authority and, where required, you directly, in accordance with
the ZZPL.
12. Children's Privacy
Our services are intended for persons aged 18 and over. We do not knowingly collect personal
data from minors. If a parent or guardian believes their child has provided us with personal
data, please contact us and we will delete it promptly.
data from minors. If a parent or guardian believes their child has provided us with personal
data, please contact us and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on our
Website with a revised effective date. We encourage you to review this Policy periodically.
Continued use of our services following any update constitutes acceptance of the revised
Policy.
Website with a revised effective date. We encourage you to review this Policy periodically.
Continued use of our services following any update constitutes acceptance of the revised
Policy.
14. Contact Us
For any questions, requests, or concerns regarding this Privacy Policy or how we handle your
personal data, please contact us at:
personal data, please contact us at:
Seven Pilates & Sculpt d.o.o.
Braće Nedića 27, Belgrade, Serbia
Email: Marina@sevenstudio.rs
Website: www.sevenstudio.rs
Braće Nedića 27, Belgrade, Serbia
Email: Marina@sevenstudio.rs
Website: www.sevenstudio.rs
Start your
routine
Seven Studio is ready when you are. Take the first step toward consistent, purposeful training