Last updated: 10 August 2026
These Terms of Use and Privacy Notice govern access to and use of the Pentest Scheduling and Project Management application operated by DEJAN LEVAJA PR RAS-INFORMACIONE TEHNOLOGIJE, with registered office at Bračka 28V, 11050 Beograd (Zvezdara), Srbija, registration number 63385999, hereinafter referred to as the “Company”.
1. Purpose of the Application
The application is intended for scheduling and managing penetration testing engagements and related communication between the Company and its clients.
Authorized client users may use the application to request penetration testing engagements, select the type of penetration test, request preferred testing dates, view their own bookings and projects, modify or cancel their own booking requests where permitted, and provide information related to an engagement.
Available penetration testing categories may include Web Application Penetration Testing, Mobile Application Penetration Testing, and Infrastructure Penetration Testing. Allocation of individual Company consultants and internal resources is performed exclusively by the Company and is not visible to client users.
2. User Accounts
Access to the client portal requires an authorized user account. Users are responsible for providing accurate account information, protecting authentication credentials, not sharing accounts with unauthorized persons, and promptly notifying the Company of suspected unauthorized access.
The Company may suspend or disable an account where it reasonably believes that the account has been compromised, misused, or used in violation of these Terms.
3. Booking Requests
A booking request submitted through the application does not automatically constitute a confirmed reservation. A request may initially have the status Pending Approval and becomes reserved only after approval by the Company.
The Company may approve, reject, or propose changes to a requested period based on resource availability, contractual arrangements, technical requirements, or other operational reasons.
4. Privacy of Other Clients
Users may access only information relating to their own organization, account, booking requests, and projects. Information concerning other clients is confidential.
Where periods are unavailable because of existing engagements, the application may display such periods only as Unavailable or equivalent. The identity of another client, project details, consultant assignments, and other confidential information relating to another engagement are not disclosed through the client portal.
5. Personal Data We Process
When a user accesses or uses the application, the Company may process the following categories of personal data where provided or generated:
- Account information: first name, last name or contact name, business email address, organization/company name, role or position where applicable, account identifier, and password hash or other authentication information. Passwords are not stored in plain text.
- Booking and project information: requested penetration testing type, requested testing dates, project and booking information, scope descriptions, notes and comments entered by the user, and booking change/approval history.
- Technical and security information: IP address, date and time of access, successful and unsuccessful authentication events, session information, browser/user-agent information, actions performed in the application, changes to bookings/projects/account information, and security/application event logs.
- Terms acceptance evidence: user account, accepted Terms version, date and time of acceptance, IP address, user-agent information, and a cryptographic hash identifying the accepted document version.
Users should avoid entering unnecessary personal, confidential, or sensitive information into free-text fields.
6. Purposes of Processing
Personal data may be processed for creation and administration of accounts; authentication and access control; provision of scheduling and project-management functions; administration of penetration testing requests; engagement-related communication; protection of the application and Company systems; detection and investigation of unauthorized access or misuse; maintenance of audit trails; troubleshooting and technical support; establishing, exercising, or defending legal claims; and compliance with applicable legal or regulatory obligations.
Application security logs are not used for unrelated advertising purposes.
7. Legal Basis for Processing
Depending on the purpose and applicable law, processing may be based on one or more lawful grounds, including processing necessary to provide the requested service and perform contractual obligations, compliance with legal obligations, legitimate interests in protecting systems and maintaining reliable and auditable services, and consent where consent is specifically required for a particular processing activity.
Where processing is specifically based on consent, a user may withdraw that consent in accordance with applicable law. Withdrawal does not affect processing lawfully performed before withdrawal and does not require the Company to stop processing where another valid legal basis applies.
8. Security and Audit Logging
Because the application contains information concerning penetration testing engagements and client organizations, the Company maintains security and audit logs. These logs may record successful and unsuccessful login attempts, booking creation/modification/cancellation, booking approvals or rejections, account changes, administrative actions, access-control events, and other security-relevant activity.
These records are used for security monitoring, investigation of incidents, troubleshooting, prevention of abuse, accountability, and protection of the Company and its clients.
9. Cookies and Session Data
The application uses an essential session cookie required for authentication, session security, and normal operation of the service. The application does not require advertising or behavioral-tracking cookies for its core functionality.
10. Retention of Personal Data
Personal data is not retained longer than reasonably necessary for the purpose for which it was collected, subject to contractual, legal, security, audit, accounting, and regulatory requirements.
Retention periods are determined according to factors including whether an account or client relationship remains active, the need to maintain engagement records, security and incident-investigation requirements, statutory retention obligations, and the need to establish, exercise, or defend legal claims. Data that is no longer required will be deleted or anonymized in accordance with the Company's retention procedures.
11. Access to Personal Data
Personal data may be accessed only by persons who require such access for legitimate business, administrative, project-management, security, or technical purposes. Access privileges are restricted according to role and responsibility.
12. Service Providers
Where necessary to operate the application, the Company may use service providers acting on its behalf, such as hosting, infrastructure, email delivery, backup, security, or monitoring providers. Where such providers process personal data on behalf of the Company, appropriate contractual and security measures will be applied as required by applicable law.
13. International Data Transfers
If personal data is transferred to another country or international organization, such transfer will be performed only where a valid legal basis and appropriate safeguards exist under applicable data-protection law.
14. Security Measures
The Company implements technical and organizational security measures appropriate to the application and information processed. These may include encrypted HTTPS communications, role-based access controls, password hashing, session protection, audit logging, network access restrictions, backups, monitoring, administrative controls, and regular software maintenance and security updates.
No information system can be guaranteed to be completely secure. Users are also responsible for keeping their credentials confidential and promptly reporting suspected security incidents.
15. User Rights
Subject to applicable data-protection law, a user may have the right to request information about processing, access personal data, request correction, request deletion where applicable, request restriction of processing, object to certain processing, request portability where applicable, withdraw consent where processing is based on consent, and submit a complaint to the competent data-protection authority.
Some rights may be subject to limitations where continued processing is required by law, necessary for contractual or security purposes, or required for the establishment, exercise, or defence of legal claims.
Privacy requests may be submitted to [email protected].
16. Account Termination
A client may request deactivation of a user account by contacting the Company. Account termination does not necessarily result in immediate deletion of all associated information. Information may be retained where required for contractual, accounting, legal, security, audit, fraud-prevention, or dispute-resolution purposes and deleted or anonymized after the relevant retention requirement expires.
17. Prohibited Use
Users must not attempt to access another client's data; bypass authorization controls; probe, scan, or test this application without explicit authorization; obtain information regarding internal Company resource assignments; interfere with normal operation; share credentials with unauthorized persons; or use the application for unlawful purposes.
18. Changes to These Terms
The Company may update these Terms of Use and Privacy Notice where necessary due to changes in the application, security requirements, business processes, or applicable law. For material changes, users may be required to review and accept the updated version before continuing to use the client portal.
The application may record the Terms version, document hash, date and time of acceptance, user account, IP address, and user-agent information as evidence that the applicable terms were presented and accepted.
19. Contact
DEJAN LEVAJA PR RAS-INFORMACIONE TEHNOLOGIJE
Bračka 28V, 11050 Beograd (Zvezdara), Srbija
Email: [email protected]
Privacy contact: [email protected]