NEW-PAY
PRIVACY POLICY
This Policy explains how personal data is processed when you use the New-Pay mobile application, the New-Pay portal at www.new-pay.tech, an Account, support and related features (together, the “Service”). Processing depends on the functions you use, the self-service machine Operator and your payment method.
1. Who processes your data
Providers and data controllers
- Registered office
- Nedeljka Gvozdenovića 5, floor 1, apt. 7, 11070 Belgrade, Republic of Serbia
- Company No. / Tax ID
- 21498114 / 111534933
- Registered office
- Živojina Žujovića 14, Belgrade, Republic of Serbia
- Company No. / Tax ID
- 20361107 / 105386304
LESS IS MORE d.o.o. Beograd-Novi Beograd and Avantech Electronics d.o.o. Beograd are together the “Providers”. They jointly own the New-Pay software solution in equal undivided shares of 50% each: LESS IS MORE d.o.o. owns 50% and Avantech Electronics d.o.o. owns 50% of the proprietary rights in the software solution, excluding third-party components and rights governed differently by a separate written agreement.
Roles in data processing
To the extent that the Providers jointly determine the purposes and means of processing for the New-Pay Account and central platform functions, they act as joint controllers. Their internal arrangement allocates practical responsibilities but does not limit your rights against either Provider where mandatory law provides otherwise. You may contact both through support@new-pay.tech.
Where an Operator determines why and how data is processed for sales, machines, loyalty, fiscalisation or complaints, the Operator is a separate controller and one or both Providers may act as its processors according to the actual technical and contractual role. The Bank or Payment Service Provider is a separate controller for card payments. Their privacy notices also apply.
2. Personal data we may process
- Account and contact data: name, username, email, phone number, protected password, language and settings.
- Identifiers: internal user ID, Account ID, session token, QR/NFC identifier, Operator or machine ID, and device or app identifiers.
- Transaction data: amount, time, currency, machine, item, status, Bank reference, top-up, balance, bonus, change, refund and history. The Providers generally do not receive the full card number, PIN or CVV; the Bank or payment processor handles them.
- Purchase and product data: selected item, quantity, price, label/allergen information entered by the Operator and a PDF fiscal receipt if available.
- Data you submit: support messages, complaints, attachments, form responses and other user content.
- Technical and diagnostic data: device model, operating system, app version, IP address, network, access time, crash logs, performance and security events.
- Camera: only when you grant access for QR scanning or another feature; content is not retained unless necessary and separately disclosed.
- Location: approximate or precise location only if you enable a feature requiring it, such as nearby machines. You can withdraw permission in device settings.
- Age data or an age-eligibility result only where needed for a restricted product or feature. An ID copy is not retained unless legally necessary and separately disclosed.
3. Sources of data
We receive data from you, your device and app, the Operator and machine, the Bank or payment processor in limited form, the fiscal system, sign-in or notification providers, and our support and security records. Accuracy of displayed information primarily depends on the source entering or supplying it.
4. Purposes and legal bases
| Purpose | Examples | Typical legal basis |
|---|---|---|
| Provide the Service | Account, login, QR/NFC, machine display, balance, history, receipt, support | Contract / steps requested by user |
| Payment and records | Request transmission, Bank status, top-up, Operator cash record | Contract; responsible party’s legal duty |
| Security and abuse prevention | Authentication, logs, fraud detection, incidents | Legitimate interests and legal duty |
| Legal and evidentiary duties | Tax/fiscal data, authority requests, claims | Legal obligation; legal claims |
| Location, camera, optional features | Nearby machines, QR scan, optional analytics | Your action/permission; consent where needed |
| Improve the Service | Aggregated statistics, diagnostics, bug fixing | Legitimate interests balanced against user rights |
| Marketing | Offers and non-essential notices | Consent or another permitted basis; opt-out |
Where processing relies on consent, you may withdraw it at any time without affecting prior lawful processing. Where data is necessary for a contract or law, the relevant feature may not be available without it.
5. Payments and Bank responsibility
The Bank or Payment Service Provider independently determines processing required for authorisation, authentication, fraud prevention, processing, settlement and chargebacks. The Providers do not assume the Bank’s payment-service obligations. If a payment partner processes data on Provider instructions for a specific feature, the applicable notice or agreement will describe the roles.
6. Goods, Operator data and accuracy
The Operator is responsible for information it enters or supplies about items, prices, ingredients, allergens, stock, expiry, machines, cash and fiscal receipts. The Providers process it to operate the system but cannot guarantee its accuracy if it does not reflect the actual situation. Questions about goods, food, allergens or fiscal documents should be directed to the Operator.
7. Who receives data
- between the Providers only as necessary for joint platform operation, support, security and rights requests;
- the Operator whose machine or offer you use, to complete purchases, balances, receipts, complaints and support;
- the Bank and payment processor to initiate and confirm cashless payments;
- contracted hosting, infrastructure, communications, analytics, authentication, support and security providers;
- advisers, auditors, insurers, authorities or courts where needed for law, rights or safety; and
- a legal successor in a corporate transaction, subject to statutory safeguards.
The Providers do not sell personal data. They do not use it for unrelated advertising without a proper legal basis and any required consent.
8. International transfers
Data is primarily processed in Serbia and/or the European Economic Area, depending on service providers used. For transfers to a country without adequate protection, permitted safeguards such as standard contractual clauses and additional technical and organisational measures are used where required. You may request information about the applicable safeguard.
9. Retention
- Account data - while the Account is active and for a reasonable period after deletion for backups and legal claims;
- transaction and fiscal records - for statutory tax, accounting, payment and evidence periods of the responsible participant;
- support and complaints - until resolution and then for the applicable claims period;
- security and technical logs - for a short, proportionate period needed for security, diagnostics and abuse prevention; and
- consent-based data - until withdrawal or earlier end of purpose, unless further retention is lawful.
The exact period depends on data type, Provider role, Operator contract and mandatory law. At expiry, data is deleted, anonymised or isolated until secure deletion from backups.
10. Security
We apply reasonable technical and organisational measures, including access controls, event logging, transmission protection, vulnerability management, backups and processor obligations. No system is risk-free. Protect your device, password and codes and promptly report suspicious activity.
11. Your rights
Depending on applicable law and controller role, you may request access, a copy, rectification, erasure, restriction and portability; object to legitimate-interest processing; and withdraw consent. You may complain to the Serbian Commissioner for Information of Public Importance and Personal Data Protection or another competent authority.
Send requests to support@new-pay.tech. We may request reasonable identity verification and information needed to identify the responsible participant. If the Operator or Bank is responsible, we will forward the request where permitted or direct you to it.
12. Account deletion
Delete your Account through Settings -> Account -> Delete account, where available, or email support@new-pay.tech. Deletion does not cover data that an Operator, Bank or Provider must retain by law or for disputes, fraud prevention and legal claims. Unneeded data will be deleted or anonymised.
13. Children and restricted products
The Service is not designed to override legal age restrictions. The Operator is responsible for lawful sale of age-restricted products and the age-verification method. If we learn that a child’s data was received without a proper basis, we will take reasonable steps to delete it. A parent or guardian may contact support.
14. Automated decisions and marketing
The Providers do not make solely automated decisions producing legal or similarly significant effects on users unless specifically disclosed and lawfully implemented with safeguards. You may opt out of marketing through the link or settings; essential service and security notices may continue while you use the Service.
15. Device permissions and cookies
Control camera, location and notification permissions in device settings; some features may then be unavailable. The native app does not use web cookies in the same way as a website but may use local storage, SDKs and similar identifiers. The New-Pay portal may use necessary cookies, and optional analytics or marketing only with an appropriate legal basis and user choice where required.
16. Changes and contact
We may update this Policy due to changes in the Service, participants or law. We will publish the new version and date and appropriately notify you of material changes. Privacy contact for both Providers: support@new-pay.tech. Contact page: www.new-pay.tech/contacts.