Privacy and Personal Data Protection Policy

A clear explanation of what Citiwell receives, why it is needed, who may receive it and how you can control your data.

Last updated: 26 July 2026Effective from 13 July 2026

Only what is neededData required for a request, service, website security or analytics you choose.
Each purpose has its own legal basisBooking and service are linked to a contract, required records to legal obligations, and website security to legitimate interests. Analytics and advertising are enabled only with prior consent.
No sale of personal dataDisclosure only to service providers or recipients required by law.
You remain in controlRequest access, correction and deletion, or change cookie settings.

1. Scope and applicable law

This Policy applies to citiwell.rs, booking and contact forms, communications with Citiwell, job applications and the initial organisation of services in Serbia. Separate notices or consent forms may apply to a specific treatment, contraindication assessment, photography or another special operation.

The controller for the website and central contact channels is CITIWELL BG d.o.o. Beograd, company registration number 22095714, TIN 114954357, registered address: CARICE MILICE 7, apartment 3, 11000 Belgrade (Stari Grad), Republic of Serbia.

We primarily apply the Serbian Personal Data Protection Act (Official Gazette of the Republic of Serbia No. 87/2018). The GDPR applies in addition only where a particular processing operation falls within its territorial scope, including the situations described in Article 3.

Your statutory rights come first

This Policy does not restrict rights granted by law or make optional information mandatory. Mandatory law prevails if it conflicts with this text.

2. Data we process and where it comes from

The data depends on how you interact with Citiwell.

Category
What it may include
Source
Contact data
Name, telephone number, selected messenger, email and language.
You provide it in a form, by telephone, email or messenger.
Booking and service interest
Gender, city, studio, service, package, areas, preferred time and comments.
Website form, administrator or your messages.
Communications
Request text, conversation history, confirmations and service messages.
WhatsApp, Viber, Instagram, email, telephone or form.
Technical and advertising data
IP, browser, device, pages, referrer, UTM and click IDs such as gclid, fbclid, yclid, ttclid and msclkid.
Browser, campaign link and consented analytics tools.
Approximate location
City and country inferred from IP when a request is submitted.
ipapi.co during form submission.
Candidate data
Name, phone, messenger, vacancy, experience and profile text.
Careers form and later communication.
Treatment safety data
Skin, tanning, medication, pregnancy, contraindications or related factors when genuinely needed.
Only from you during consultation or a separate questionnaire.

We may receive minimal campaign or account information when you follow an advertisement or contact us through a platform. We do not buy personal-data lists.

Do not submit unnecessary sensitive information

The public booking form is not intended for medical documents, diagnoses, intimate photographs, identity documents or payment-card details. Provide such data only when an authorised specialist specifically requests it through an appropriate channel.

3. Purposes and legal bases

Each purpose is tied to a lawful basis. We do not use data for an incompatible purpose without a new basis.

Purpose
Data
Legal basis
Answer a question, prepare an offer and arrange a booking.
Contact details, service, studio, package and comments.
Steps at your request before a contract and performance of a contract.
Organise a visit, send reminders and provide a service.
Booking, communication, organisational and customer records.
Contract; legitimate interest in administering the service.
Assess treatment safety and individual restrictions.
Only necessary health or skin information.
Explicit consent where it is the appropriate basis; another statutory condition only where it applies to the specific processing.
Review a job application.
Contact, experience, vacancy and communications.
Pre-contractual steps at your request; legitimate recruitment interest.
Protect the website and legal rights.
IP, logs, technical data, communications and records.
Legitimate interest, legal duty, establishment or defence of claims.
Measure visits and improve pages.
Cookie identifiers, device, events and page visits.
Your prior analytics consent.
Measure advertising and create audiences.
Advertising identifiers, events, UTM and click IDs.
Your prior advertising consent.
Comply with law and lawful authority requests.
Only data relevant to the requirement.
Legal obligation; another basis only where it applies to the specific processing.

Where we rely on legitimate interests, we consider necessity, reasonable expectations and impact on individual rights. You may object. Marketing is not a condition of booking and requires a separate basis.

4. Forms, requests, messengers and careers

The standard request form asks for a name, telephone number, messenger and gender to identify and answer the request and provide relevant service information. Other displayed fields are voluntary unless expressly marked otherwise.

When the form is submitted, the browser contacts ipapi.co to infer an approximate city and country from the IP address. The request, page, referrer, UTM and click IDs is then sent to Citiwell's server and delivered to a restricted Citiwell Telegram work chat. Candidate requests go to a separate work chat.

If you choose WhatsApp, Viber, Instagram or another external service, its operator receives data under its own policy and may act as an independent controller.

Another person's details

If you provide someone else's contact details, you confirm that you are authorised to do so and have informed that person. Do not impersonate another person and provide accurate information.

5. Special-category data and treatment safety

Health, skin, pregnancy, medication or contraindication information may be special-category data. We request it only where reasonably necessary for consultation and safe treatment.

  • Do not place it in public comments or advertising posts.
  • Access is limited to staff and specialists who need it.
  • Where explicit consent is required, processing starts after it is obtained.
  • Refusal to provide genuinely necessary information may mean that we cannot safely perform the treatment.

We do not use health data for advertising profiles.

6. Cookies, analytics and advertising technologies

The website uses essential local storage to remember privacy choices. Google Analytics 4 and Yandex Metrica load only after analytics consent; Meta Pixel loads only after separate advertising consent. Google Consent Mode v2 starts with analytics and advertising storage denied. If you select “analytics — yes, advertising — no”, ad_storage, ad_user_data, ad_personalization and Google Signals remain disabled.

Your explicit choice is stored for 180 days. Global Privacy Control and Do Not Track signals are treated as a rejection of optional technologies until you change the settings yourself.

Category
Purpose
Essential
Website operation, security, forms and storing your preferences. These cannot be disabled in the panel.
Analytics
Google Analytics 4 and Yandex Metrica for page visits, events, device data and aggregated statistics. Loaded only with consent.
Advertising
Meta Pixel for advertising measurement and audiences. Loaded only with consent.

Consent is voluntary. Reject and settings controls are presented with the accept button. You can change your choice at any time. Withdrawal prevents future loading of optional tools and removes known first-party cookies accessible to the site where technically possible. Cookies set on external domains must be removed through browser or provider settings.

Hosting technical telemetry

GoDaddy hosting injects its own traffic and telemetry script at platform level. It may send the page URL, IP address and browser information to csp.secureserver.net and use cookies in the _tccl_* family (_tccl_visitor and _tccl_visit) as well as _scc_session for hosting performance, security and diagnostics. These technologies are not controlled by Citiwell's consent panel; their retention and subsequent processing are determined by GoDaddy and browser settings.

Provider settings determine identifier retention, generally no longer than 24 months. Providers may update their technologies; current cookies are visible in your browser.

7. Recipients and service providers

Access is limited by need. We do not sell or rent personal data.

Recipient / service
Role and possible data
Authorised Citiwell staff and specialists
Requests, booking, communication, service, safety and support.
GoDaddy and IT providers
Website hosting, server logs, browser telemetry, support, performance and infrastructure security.
Telegram
Delivery of a request to a restricted Citiwell work chat.
ipapi.co
Approximate city and country inference from IP during submission.
Google Maps
Studio address and map display; Google may receive the IP address and browser technical data.
Google Analytics and Yandex Metrica
Website analytics after consent.
Meta Pixel / Instagram / WhatsApp
Advertising measurement after consent or communication you initiate.
Viber and other chosen channels
Message delivery and user-initiated communication.
Lawyers, accountants, insurers and authorities
Only for law, contract, audit or legal claims.

A provider may be a processor, joint controller or independent controller depending on the operation. Where it acts on our instructions, we require confidentiality and appropriate safeguards within applicable law and contract.

8. International transfers

Some technology and communications providers may process data outside Serbia, the European Union or the European Economic Area. The applicable protection and transfer mechanism depends on the country, provider and operation.

Where a special transfer mechanism is required, we rely on a recognised adequate level of protection, appropriate safeguards, standard contractual clauses or other contractual guarantees, explicit informed consent or another basis permitted by the Serbian Personal Data Protection Act. Where the GDPR applies, we also use its Chapter V mechanisms. You may request information about a specific transfer at info@citiwell.rs.

External platforms

After you move to an external website or messenger, its operator controls its infrastructure and rules. Citiwell remains responsible for its provider choices and its own processing, but cannot control every subsequent operation by an independent platform.

9. Retention

We use a stated period or criterion rather than retaining data indefinitely.

Category
Period or criterion
Enquiry without a later service
Usually up to 12 months after the last meaningful contact, unless a dispute or lawful need requires longer.
Booking, contract and customer records
During the relationship and then for applicable accounting, contractual and limitation periods.
Treatment safety data
Only while needed for safe service and related legal requirements, not longer than the related customer record.
Job application
Usually up to 12 months after closure or rejection unless you separately agree to a talent pool.
Marketing consent
Until withdrawal; a minimal suppression record may remain to prove messages must stop.
Analytics and advertising IDs
Under provider settings, generally up to 24 months, or until consent is withdrawn.
Security logs
Usually up to 12 months, longer only for an incident or legal requirement.
Rights requests and complaints
As needed to respond and demonstrate compliance, including the applicable limitation period.

At the end of retention, data is deleted, anonymised or remains only in restricted backups until scheduled overwrite.

10. Your rights

Subject to the applicable law, you may exercise the following rights:

Information and accessLearn whether we process your data and obtain access or a copy.
CorrectionCorrect inaccurate and complete incomplete data.
ErasureRequest erasure where there is no longer a lawful basis to retain data.
RestrictionRestrict processing in circumstances provided by law.
PortabilityReceive provided data in a structured format where applicable.
ObjectionObject to legitimate-interest processing and direct marketing.
Withdraw consentWithdraw consent without affecting earlier lawful processing.
Human reviewAvoid a solely automated significant decision where the right applies.

Email info@citiwell.rs and state your name, contact details, request and the channel you used. We may request reasonable identity verification to prevent unauthorised disclosure.

We respond without undue delay and no later than 30 days after receiving a request. This period may be extended by a further 60 days where necessary because of complexity or the number of requests, with timely notice and reasons.

If you believe processing violates the law, you may complain to the Commissioner for Information of Public Importance and Personal Data Protection, Bulevar kralja Aleksandra 15, 11120 Belgrade, office@poverenik.rs, +381 11 3408 900, or seek judicial protection.

Rights are not absolute

We may retain some data or limit a request where required by law, another person's rights, accounting duties, abuse prevention or the establishment, exercise or defence of legal claims. We will explain the reason unless the law prohibits this.

11. Security and incidents

We apply proportionate technical and organisational measures, including role-based access, restricted work channels, account protection, transmission encryption where supported, updates, backups and provider controls.

No website, messenger or storage method is absolutely secure. Citiwell does not promise impossible "100% security", but remains responsible for appropriate measures and incident response. We assess and document incidents and, where legally required, notify the Serbian Commissioner without undue delay and, where feasible, within 72 hours after becoming aware, and notify affected individuals where a high risk to their rights and freedoms is likely.

12. Minors and other people’s data

The website is not intended for independent booking by young children. A minor's treatment may require parent or legal-representative involvement or consent depending on age, procedure and law.

If you believe a child submitted data without appropriate involvement, contact us so we can investigate and delete or restrict data without a lawful basis.

13. Automated decisions, changes and responsibility

Citiwell does not use website data for solely automated decisions that produce legal or similarly significant effects. Analytics and advertising tools may create statistical segments, but they do not decide whether you can receive a service.

We update this Policy when the website, services, processing or law changes. Material updates appear here with a new date. Continued use does not replace active consent where law requires it.

This Policy describes processing and is not a waiver of legal responsibility. It does not create guarantees beyond mandatory law or make Citiwell responsible for independent-platform conduct outside our reasonable control.

Questions, requests and complaints

Contact us about access, correction, erasure, cookie settings or other processing. You may also complain to the Serbian Commissioner.