1. Who determines the processing
The data controller is the legal operator identified with this version. Behric is the project and service name; the exact legal identity, address and contact must be displayed before public EOI submission is activated.
Use the privacy contact displayed with this version for questions and rights requests. Do not send identity documents or other sensitive material by ordinary email.
2. Data we process
The public form has no upload. We do not request a passport, bank details, biometrics, health data, religion or confidential AML documents at first contact.
- Public EOI: name, business contact, organisation, country, interest type, sector and a short description.
- Business review: project, role, authority, mandate, relevant checks, communications and decision records.
- Secure portal: account data, assigned case, access scope, security and audit events, and accepted legal versions.
- Technical data: timestamps and cryptographic hashes of IP address and user agent for abuse prevention; these are not retained by the public form as a readable tracking profile.
3. Purposes and legal bases
The basis depends on the activity: steps at your request before a possible contract, legal obligation, a documented legitimate interest, or consent where consent is genuinely required. Consent for optional cookies or future contact is separate from the EOI and may be withdrawn.
- responding to your request and assessing a possible business relationship;
- checking authority, eligibility, risk, conflicts of interest and compliance;
- protecting the service, preventing abuse and maintaining an accountable audit trail;
- meeting legal obligations and establishing, exercising or defending legal claims.
4. Sources and recipients
Most data comes from you. Information about authorised contacts, beneficial owners or relevant business persons may come from the organisation they represent, public registers or approved screening providers. Where required, a person recorded indirectly receives the prescribed notice.
Access is limited to authorised Behric personnel and vetted processors that need the data for hosting, email, security or an approved check. We do not disclose a project or a partner’s identity to the other side without a controlled business and legal step.
5. International transfers
Cooperation may involve contacts in Bosnia and Herzegovina, Türkiye and Gulf countries, but business interest alone does not authorise a personal-data transfer. A transfer takes place only with an authorised legal mechanism, appropriate safeguards, minimum scope and a recorded assessment.
6. Retention and security
We retain data only as long as needed for the case purpose, mandatory periods, evidence of communications, security and legal claims. The period depends on record type, case status, legal duties and any legal hold; an approved retention schedule is a production prerequisite.
Controls include least-privilege access, separate accounts and sessions, audit of risky actions, cryptographic hashes of technical data and controlled access revocation. No internet service is risk-free, so sensitive documents are accepted only through an approved secure flow.
7. Your rights
Submit a request to the privacy contact. Identity is verified in proportion to risk. We respond without undue delay, normally within 30 days, subject to the legally permitted extension for complex requests. You may complain to the Personal Data Protection Agency in Bosnia and Herzegovina and seek judicial protection.
- access to personal data and processing information;
- correction and completion of inaccurate or incomplete data;
- erasure or restriction where the legal conditions are met;
- data portability where applicable;
- objection, particularly to direct marketing and certain legitimate-interest processing;
- withdrawal of consent for future processing that relies solely on consent;
- protection against a solely automated decision with legal or similarly significant effect.
8. Automation and changes
Behric may use explainable internal review suggestions, but does not make a solely automated decision producing legal or similarly significant effects. A responsible person makes and records the business decision.
A material change to purpose, provider, transfer or text creates a new version and, where necessary, a new notice or user choice.