Privacy policy
Privacy statement / Disclaimer
International Trade System (ITS) takes its responsibility regarding the protection of personal data very seriously.
International Trade System (ITS) is the website of the company:
International Trade System (ITS) doo, Viline Vode bb, Slobodna Zona Belgrade, MB: 17234498.
(hereinafter the website) undertakes to protect your privacy and provide you with the best possible experience of using our website. In order to make the most of the time spent on our pages, we need certain personal information from you, which will help us tailor the content to your tastes and wishes.
Please read this statement to understand how we treat your personal data. This statement may change, so we recommend that you check it occasionally.
This privacy policy describes the ways in which International Trade System (ITS) uses the personal data of visitors. By providing your personal data and accepting the Privacy Policy, you confirm that you agree to your data being used in the manner described in this Policy. If the Privacy Policy changes, we will publish the amended text of the Policy on this page. By continuing to use our website, as well as by providing your data when ordering online, you confirm that you agree to the amendments to the Policy.
The Privacy Statement is a document that guarantees the protection of the privacy of our users on the Internet. You can view the website free of charge and without any obligation to reveal your identity or leave any personal data. If you decide to use one of the services we offer (Question, Chat, Ordering, Comment, Experience), it is necessary to provide us with personal data so that we can provide you with what you requested. We only ask for the information necessary to best realise your request. (When a question is asked, we need a contact for feedback; when ordering, we need data for courier delivery…)
Collection of information — method and reason
The Website asks for your personal data only if you want to use one of our services and voluntarily fill in the forms on our website.
When you visit the website, our web provider automatically records data including your computer's IP address, browser type, domain name, visit time, the address of the website you came from and all information about the pages you visit on our website, about which you were informed on all pages of the website.
We use this data for statistical analyses of the use of our pages, with the aim of improving the quality of service.
Note: our web provider does not record your email address or any other data that could be used for your personal identification. You can opt out of recording this data by correctly configuring your web browser – more on that below.
The data we collect is as follows:
- Domain and IP address
- The type of browser and operating system used to access our site
- Access time and length of visit
- Pages you visit
- If you linked to our portal from another site, the address of that site
- If you provide us with information yourself
In which cases do we record your private data:
Asking a question
(Name, email – to which we deliver the answer)
Contact data and questions are stored in an internal database until the author asks for the question to be deleted from the internal database.
Online ordering for Serbia
(First and last name, address, contact phone and email address)
Contact data enters the local CRM, which is kept until the customer asks us to delete it. The database is kept on a local server within the company and a backup on a protected DropBox account. The information customers leave us will also be stored for a maximum of one year on the hosting mail server.
Online ordering outside Serbia
(First and last name, address, email, phone)
Contact data enters the local CRM, which is kept until the customer asks us to delete it, as well as in the website database itself. At any time, the user can ask us to delete them from both. The local database is kept on a local server within the company and a backup on a protected DropBox account. The information customers leave us will also be stored for a maximum of one year on the hosting mail server.
Registration for a prize game
(First and last name, address, email, phone) * if necessary, we can adjust the fields we ask for prize games in accordance with the law on prize games of the Republic of Serbia)
We keep prize game data for as long as prescribed in the prize game itself. At any time, the user can ask us to delete them.
Newsletter registration
(Name, email address)
Through the Newsletter registration, the fields you accept with the rules are clearly marked, and you can choose what kind of information you want to receive. At any time, you can have insight into your account and unsubscribe from the list. In that case, your data is deleted.
Online chat support
(IP address, name, email)
Tawk.to software will record your IP address and determine where you are contacting from, for easier communication. You can see their privacy policy on their website or follow the link below in this policy. Alternatively, you can share your name and email address so we can contact you with an answer. Data is stored in the local database until deletion is requested.
Leaving comments
(Name/nickname, email address, IP address)
*An anonymised nickname of an email address may be provided to the Gravatar service to check whether you use the same service. Here you can see Gravatar's privacy policy. After the comment is approved, your profile picture is visible to the public. Comments are kept until the author requests removal or in some way violates the ideology of the website.
Leaving content
(jpg, gif, png file, IP address)
If you upload images to the website, you should avoid uploading images that contain personal data and image location data (EXIF GPS). Location data of where the image was taken can be read from them. Content can be kept while its application lasts (prize game, photo contest…) or until the author requests the document to be deleted.
Leaving experiences
(First and last name, email, experience)
Experiences and data when entering them are recorded internally on the server and stored in the database until deletion is requested. Also, on the hosting server as a backup, they will remain for a maximum of one year.
Information regarding your health condition will be stored only locally and will not be forwarded or used for additional marketing activities, unless you leave it in the form of a comment. We record it only for the purposes of records and a better understanding of your problem in order to give the best possible answer.
Use of collected information
Your personal information is used:
- To be able to send ordered products to the desired address
- To send you gifts, vouchers, invitations, etc. to the desired address
- To forward it to the company that provides transport services. With direct contact, you will avoid all possible dilemmas and misunderstandings around delivery.
- To occasionally inform you about changes in our offer, special benefits and important changes to our website.
The collected information will not be used for purposes not stated in this statement.
How we share information with others
The Website will not sell, trade, rent or give your personal data to a third party, unless it is necessary for the provision of the service. If you do not want to receive information about changes on our website, news about our offer and similar information, feel free to inform us. Your name will be deleted from our lists shortly after receiving your message.
We may forward information about you to:
- Other brands of the company International Trade System (ITS)
- Trusted third parties that provide us with transport services (Pošta Srbije, City Express) – list below.
- Customs authorities if the shipment is sent outside Serbia
- Employees of International Trade System (ITS) for the purpose of providing better customer service as well as better marketing services.
- Third parties whose services we use to better provide services – list below.
International Trade System (ITS) doo may disclose the client's personal data:
- If required by a court
- If necessary to protect the rights and property of our website
- If necessary to protect the personal safety of our users or the public.
Security of collected information
The Website takes special care that the collected user information is safe and protected from loss, changes, unauthorised access and any type of abuse.
The Website is on a secure SSL server. We adhere to strict security procedures regarding the storage and disclosure of the information you give us in order to prevent unauthorised access to it.
From our site, links may lead to other websites. We are not responsible for the policy or procedures for data protection, nor for the content of these websites.
What is GDPR (General Data Protection Regulation)?
The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is a regulation by which the European Parliament, the Council of the European Union and the European Commission intend to strengthen and harmonise the protection of data for all individuals within the European Union (EU). It creates consistent data protection rules across Europe and applies to companies located in the EU and global companies that process personal data of individuals in the EU. The Regulation enters into force on 25 May 2018.
How does GDPR affect organisations/websites?
In addition to strengthening and standardising user data privacy in EU countries, it will require new or additional obligations for all organisations that deal with the personal data of EU citizens, regardless of where the organisations themselves are located.
Here you can read the full general data protection regulation.
The meaning of the GDPR term 'Personal Data' is explained in this article.
Websites that process personal data will have to provide users with:
- The possibility of insight into their records with the information provider (website/organisation) upon request
- Deletion of all records of that person
- Clear notice upon entering the site about which data is collected
- Where and how the data left by visitors on the site is used
- Whether and to whom that data is forwarded
- How long that data is kept and where
Subprocessors
In order to provide the best possible service, information may be forwarded to the following subprocessors:
| Third party | Reason | Country | Website |
|---|---|---|---|
| City Express | Delivery to address | Serbia | Cityexpress.rs |
| Pošta Srbije | Delivery to address outside Serbia | Serbia | Pošta.rs |
| Customs of Serbia and countries to which goods are sent | Delivery to address outside Serbia | Serbia | Upravacarina.rs |
| MailChimp | Newsletter sending | USA | Mailchimp.com |
| Tawk.to | Live chat service | UK | Tawk.to |
| PayPal | Online payment for foreign orders | USA | Paypal.com |
| Beotel, Inet, Ninet | Hosting – email service | Serbia | |
| Trello | Internal storage of foreign invoices and tracking | Australia | Trello.com |
| Slack | Internal communication for faster order processing via social networks | USA | Slack.com |
| Facebook, Instagram | Chat and ordering via messenger | USA | Facebook.com, Instagram.com |
| DropBox | Backup of the internal database of orderers | USA | Dropbox.com |
| AllSecure doo | Secure storage of cards for purchases | Serbia | allsecure.rs |
| Wordfence | Security of the website and users | Wordfence.com | |
| Limit Login Attempts | Website security | ciphercoin.com | |
| iThemesSecurity | Security of the website and users | ithemes.com |
On their websites you can view the individual privacy policies, but they all fall under the GDPR regulation.
Storage of personal data
We collect and store personal data in our personal database located on an internal server – and if necessary, we can share it with some of the subprocessors that are under the GDPR regulation on the list above. We also collect and store personal data within the email list (database) through the Mailchimp software (email marketing and marketing automation), which has adapted its business to the GDPR regulation (Mailchimp privacy policy), and it will remain on the hosting server for a maximum of one year. PayPal keeps the records of foreign orderers (PayPal privacy policy). Our database backup is also located on a protected DropBox (DropBox privacy policy) account, and for easier records and tracking of foreign shipments, the Tracking Code of shipments is located on an internal Trello (Trello privacy policy) account and can be shared via the internal communication software Slack (Slack privacy policy). Security plugins (Wordfence, Limit Login Attempts, iThemesSecurity) may remember the IP address and store it for the purpose of blacklisting for this website, to protect both the website and visitors. By sending orders via messengers through Facebook and Instagram platforms, you have already accepted their rules – and further, they are stored according to this policy.
Storage of card data
When paying by card on the International Trade System (ITS) website, payment processing is performed through the certified payment services provider AllSecure Payment Gateway. Card data is not stored on the systems of the seller International Trade System (ITS) doo, nor are complete card data available to the seller, such as the card number, CVC/CVV code and other confidential card data.
If the user chooses the option of saving the card for future purchases when paying, the storage of card data is performed exclusively at the payment services provider AllSecure Payment Gateway, using tokenization, SSL protection, 3D Secure protection and PCI-DSS security standards. In that case, the seller does not store the actual card data, but exclusively a token, i.e. a reference provided by the payment processor, can be used for future payments.
The saved card is used exclusively to enable faster and simpler payment on subsequent purchases, if the user chooses that option themselves. The user can delete the saved card from their user account at any time by clicking the button for deleting the card.
As a payment services provider, AllSecure Payment Gateway processes data in accordance with the applicable security standards of the card industry and data protection rules. More information about data processing and protection by the payment services provider can be found in AllSecure's privacy policy.
How long do we keep data?
Below we list exactly how long we keep which data and where:
Ordering from Serbia
- Local server – Excel: We keep the first-level user database for 10 years, after which it is moved to the old users database. When requested, we delete the record about the person.
- DropBox – Excel: We keep the first-level user database for 10 years, after which it is moved to the old users database. When requested, we delete the record about the person.
- Hosting Email – MSG/Text: A maximum of one year.
Ordering from abroad
- WP Database – SQL: We keep the database indefinitely or until deletion is requested.
- Local server – Excel: We keep the first-level user database for 10 years, after which it is moved to the old users database. When requested, we delete the record about the person.
- Hosting Email – MSG/Text: A maximum of one year.
Leaving questions/experiences/content through forms on the site
- Local server – Excel: We keep the first-level user database for 10 years, after which it is moved to the old users database. When requested, we delete the record about the person.
- Hosting Email – MSG/Text: A maximum of one year
Live support
- Tawk.to database: Indefinitely or until the user requests deletion.
- Hosting Email – MSG/Text: A maximum of one year
Newsletter registration
- Mailchimp database: Indefinitely or until the user requests deletion.
- Local server – Excel: Indefinitely or until the user requests deletion.
Cookie policy
By using our website, you agree that we can save and access cookies and IP addresses, use other methods of collecting data about the use of the website and improve your online experience.
Due to recent changes in the law, all websites active in certain parts of the European Union must obtain consent for the use or storage of cookies (or similar technologies) on your computers or mobile devices. This cookie policy provides you with clear and relevant information about the cookies we use and the reasons for their use.
Please contact us for additional information about this policy or if you need a detailed list of all cookies used by our website, at office@itsnatura.com.
Your consent
By continuing to use our website, you agree that we may place cookies on your computer to analyse the way you use our website. Please read this cookie policy carefully to find out the details about the data we collect when you use this site. If you do not want to accept cookies regarding your use of this website, you must stop using it.
What is a cookie?
Cookies are small files that are placed on your computer through the websites you visit or certain email messages you open. Their use is widespread so that websites can function properly and so that their owners can obtain business and marketing information.
The cookies we use on the website help us provide you with a better online experience, remember your settings and help us improve the site. By accessing our websites, you agree that this cookie policy applies whenever you access the website, regardless of the device you use.
What personal information do cookies collect?
In general, a cookie contains a text string with information about the browser. For operation, it is not necessary for the cookie to recognise where you are from; it only needs to remember your browser.
Some cookies we use may store information about you that is of a more personal nature. However, such information is stored only if you have published it yourself on our website.
Can I withdraw my consent?
After you have given us consent regarding the use of cookies, a cookie that remembers this setting for the next time will be saved on your computer or device. This ceases to be valid after a certain period (in any case within 13 months). If at any time you want to withdraw your consent, you will need to delete the cookies through the settings in your internet browser. For additional information on deleting or blocking cookies, visit aboutcookies.org
How can I disable cookies?
Internet browsers allow you to change cookie settings. In your internet browser, these settings are most often located in the "Options" or "Preferences" menu. The links below may help if you want to better understand the settings. Or, for additional information, you should use the "Help" option in your internet browser.
- Cookie settings in Internet Explorer
- Cookie settings in Firefox
- Cookie settings in Chrome
- Cookie settings in Safari
When do we use cookies?
Tracking
Cookies are used to collect statistical data about how users use our site. For example, for:
- collecting user satisfaction feedback through a survey on our website;
- gaining insight into how visitors use the website so that we can improve it in terms of its usability.
Targeting
"Targeting" cookies are related to services provided by third parties, such as the "Like" and "Share" buttons. Third parties provide these services in exchange for recognising that you have visited our website.
Connecting with social networks such as Facebook can lead to them using information about your visit to target advertising to you on other websites.
Cookies provide advertising agencies with information about your visit so that they can offer you ads that might interest you.
All these cookies are managed by third parties, and for additional information you can view the privacy notices on the websites of the third parties themselves.
By using our site, you accept the use of cookies for "targeting". In some cases, accepting these cookies is a condition for using the website; therefore, if you disable/block them, we cannot guarantee how our website will work.
You can choose to be permanently excluded from this type of advertising by visiting http://www.networkadvertising.org/choices
Google Analytics
This website uses Google Analytics to analyse website usage. Google Analytics uses cookies to collect standard internet log data and visitor data in anonymous form. The information generated by the cookie about your use of the website (including your IP address) is transmitted to Google. The information is then used to evaluate the visitor's use of the website and to collect statistical reports on activities on the website.
Google's privacy rules are available at: https://www.google.com/policies/privacy/
Google has developed an additional browser add-on for Google Analytics JavaScript (ga.js, analytics.js, dc.js) that disables it. If you want to be excluded from Google Analytics, you can download and install the add-on for your web browser. For additional information, click here.
Display advertising (Remarketing)
This website implements and may use Google Display advertising to reflect your interests on the web (remarketing). To determine your interests, Google will track your behaviour on the web using cookies.
You can view, delete or add interest categories with your browser using Google's recommended ads manager, available at: https://adssettings.google.com/authenticated. However, this opt-out mechanism uses a cookie, and if you delete the cookies from your browser, the mechanism will not be maintained. To maintain the mechanism in relation to a specific browser, you should use Google's browser.
CrazyEgg web analytics service
This web software uses the set of activities you perform on our website for the purpose of better understanding the user experience on our site and improving it. The service may record mouse clicks, mouse movements, scrolling activity, as well as any text you type, except text in the ordering field. CrazyEgg does not collect data that identifies personal information.
You can choose to disable the service at https://www.crazyegg.com/opt-out.
Tawk.to live chat service
This web software enables us to deliver answers to our visitors' questions in the fastest possible way – in real time. Tawk.to is software that complies with GDPR regulations (more about their policy here).
Security plugins
Security plugins:
- Wordfence
- Limit Login Attempts
- iThemesSecurity
may use your IP address (anonymously) and block it from accessing the website if there is suspicion that unauthorised queries are being sent from that IP address that could harm the website and indirectly users. Plugins may update public "blacklists" with IP addresses from which attacks have been identified and thus protect other sites that use the same plugins.
How to contact us
At any time, you can request to be unsubscribed from our lists or to be sent which of your data we have in the database. You can also request the deletion of that data by sending a request to office@itsnatura.com, with the title GDPR.
You can also contact us by phone: +381 11 20 70 807 or come in person to our headquarters, with prior notice, Viline vode bb, Slobodna Zona Belgrade.
The role of the GDPR Officer is assigned to two persons:
- Ivan Miljanić – ivan.miljanic@itsnatura.com
- Mladen Perić – mladen.peric@itsnatura.com
Disclaimer
The information on this page is of a purely informative nature. Although the content of the website is updated and accurate, we do not make statements or warranties about the completeness, accuracy, reliability or availability of the content on the website relating to information, products, services, graphics. Any reliance on the information on the website is strictly at your own risk.
Under no circumstances is the website liable for any loss or dissatisfaction that may arise as a result of something read on our page or that could be inferred from the content of our site.
Through this website, you can connect to other websites that are not under the control of International Trade System (ITS). We have no control over the nature, content, accuracy and availability of those locations. The existence of such links does not necessarily imply consent with the content or opinions expressed within them.
User experiences
Although we always try and make the greatest efforts to ensure the accuracy, completeness, reliability, timeliness and usability of the information sent to us by users of our products, on the User Experiences pages their individual cases are presented which we collected by phone, social networks, mail and email, and they are not a guarantee of success proven and done under supervised and controlled conditions.
As much as time allows, we will try to be available to our users for all advice regarding the use of our products, but we cannot guarantee success.
Refunds
Since we have no way of tracking our users, we disclaim responsibility and do not accept refunds for ordered products if it is a matter of dissatisfaction with fulfilled expectations (i.e. refunds and partial refunds can only be accepted when the problem is in the delivery itself, delivery delays, inadequate product description or an error in packaging. (This also applies to orders from abroad via PayPal and to customers from Serbia who pay cash on delivery).
Blog
All content from the BLOG section may be inspired by content from the web that is not within our jurisdiction, and so all content found on these pages is only our advice and the opinion of our experts, which we leave to the visitor to assess whether to apply. We disclaim responsibility for the accuracy of the data on these pages.
Within our capabilities, we make every effort to maintain this page. However, the website will not be responsible for the unavailability of web content due to technical problems beyond our control.
Changes to the privacy statement
All changes to the privacy statement will be recorded here, so that visitors to our pages always know what information we collect, how we use it and in what circumstances we share it with a third party.
Shipping and payment
Shipping
The Seller undertakes to deliver a product that has a valid expiry date, packed in its original packaging, and corresponds to the type and description of the product stated on the Website.
Ordered products are packed in a way that they are not damaged during usual handling.
When delivering goods, we ask you to check the delivered goods and to complain about any damage to the courier. If the delivered goods have visible external damage, the buyer has the right to refuse to accept the ordered goods.
Please compare the delivered products (type and quantity of delivered products) with the invoice, and if the order is incomplete or the wrong product was delivered, inform the courier on the spot. The recipient and the courier record and confirm the shortcomings in writing on the spot. Please note that checking the correctness of the shipment is the buyer's responsibility and that subsequent complaints regarding the quantity and type of delivered goods and visible shortcomings are not something we are obliged to accept.
Payment methods
Ordered products are paid:
- By VISA and MasterCard credit cards and Maestro and Dina debit cards; we will charge your card only after we confirm your order and prepare the package for delivery.
- Cash on delivery: in cash to the courier – the employee representative of the courier service with which we cooperate;
The right to free delivery is achieved for all packages, as well as for orders whose total value exceeds 2,999 RSD, and for orders worth up to 2,999 RSD, delivery is charged 399.00 RSD.
After the card details are entered and the payment is confirmed, the bank authorises the transaction and the order is approved and enters the further process of preparation for delivery. The amount will be reserved on your card (account) and will not be available for other purposes.
Right of withdrawal from a distance contract
You can cancel and withdraw from your order, in accordance with Article 27 of the Consumer Protection Act (Official Gazette of RS, no. 88/2021) without giving a reason and without additional costs, within 14 days after taking delivery of the product into possession. In that case, we will take the product back with a refund or replace it with another product, according to your choice. We will collect the goods through the courier service with which we have established cooperation. The costs of one return and the sending of replacement products are borne by International Trade System (ITS), while the direct costs of any subsequent returns are borne by the buyer.
In accordance with Article 36 of the Consumer Protection Act, you will not have the right to withdraw from the contract in the case of:
- delivery of goods that are subject to deterioration of quality or have a short shelf life;
- delivery of sealed goods that cannot be returned due to health or hygiene reasons and that were unsealed after delivery;
- delivery of goods which, after delivery, by their nature, are inseparably mixed with other goods;
If you wish to withdraw from a distance contract and return one or more products, please contact us by email: reklamacije@itsnatura.com
In the case of returning goods and refunding funds to a buyer who previously paid with a card, in whole or in part, and regardless of the reason for the return, International Trade System (ITS) will make the refund exclusively through VISA, EC/MC, Maestro and DINA payment methods, which means that the bank will, at the request of the seller, refund the funds to the card user's account.
If you agree to the use of another means of payment for the refund of the paid amount, you will not bear any costs for such a refund.
Please pay attention to the possibility of liability for the reduction in the value of the goods that occurs as a result of handling the goods in a way that is not adequate, i.e. exceeds what is necessary to establish the nature, characteristics and functionality of the goods.
Data protection during payment
When entering card data, confidential information is transmitted over the public network in a protected (encrypted) form using the SSL protocol, applying the most modern tokenization methods for sensitive data, and in accordance with PCI-DSS standards. At no moment is the card data available to the seller.
3D Secure protection for all merchants and buyers – AllSecure Payment Gateway uses the highest global standards of data protection and privacy. All merchants using AllSecure Payment Gateway are automatically included in 3D-Secure protection, guaranteeing buyers the security of their purchase. Buyers' card numbers are not stored on the merchant's system and the entry itself is protected by SSL data encryption.
PCI DSS Standards – AllSecure Payment Gateway constantly aligns with all requirements of card organisations in order to increase the security level of merchants and buyers. Since 2005 and without interruption, the system has been certified as PCI-DSS Level 1, which represents the highest standard in the industry. The PCI Data Security Standard (PCI-DSS) is the norm that defines the necessary security measures for processing, storing and transferring sensitive card data. PCI Standards protect the card user's sensitive data during the entire payment process: from the moment of data entry at the merchant's point of sale, during communication between the merchant and the relevant banks and card organisations, as well as later storage of that data.
Conversion
"Conversion statement – All payments will be made in dinars (RSD). If paying with cards of foreign issuing banks, the dinar transaction amount will be converted into the settlement currency of the Bank (EUR) according to the exchange rate of the National Bank of Serbia. When charging your card, the already converted amount will be converted into your local currency, according to the exchange rate applied by card operators."
Updated on: 01.09.2026.