We use Google Analytics cookies to understand how the site is used. They are only set if you accept. Privacy Policy
Last updated:
This website, datadrill.io, is operated by DataDrill (“DataDrill”, “we”, “us”), a software and data engineering consultancy based in Novi Sad, Serbia. DataDrill is the data controller for the personal data described in this policy.
DataDrill
Valentina Vodnika 21a, 21000 Novi Sad, Serbia
Email: office@datadrill.io
We process personal data in accordance with the Serbian Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti, “ZZPL”) and, where it applies to visitors from the European Economic Area and the United Kingdom, the General Data Protection Regulation (“GDPR”).
This policy explains what personal data we collect when you visit datadrill.io, send us a message, apply for a position, or take part in the benchmark survey, how we use it, who we share it with, and what rights you have.
It does not cover personal data we process on behalf of our clients as part of consulting or engineering engagements. That processing is governed by the contracts and data processing agreements we sign with each client. It also does not cover third-party websites we link to, such as LinkedIn, Instagram or Calendly, which have their own privacy policies.
We collect personal data in five situations. For each one, this section describes what we collect, why, the legal basis we rely on, and how long we keep it.
What we collect. Your full name, email address, message and, if you choose to provide them, your company name and phone number.
Why. To answer your inquiry and, where relevant, to follow up on a potential engagement.
Legal basis. Steps taken at your request prior to entering into a contract, and our legitimate interest in responding to business inquiries (Article 6(1)(b) and (f) GDPR; Article 12 ZZPL).
How it is handled. The form sends your message as an email to our office mailbox using a transactional email service. The website itself does not store your message in a database. We also apply automated spam and abuse checks (a hidden honeypot field and a per-address rate limit) that briefly process your IP address in server memory.
Retention. We keep inquiries for as long as needed to deal with them and for up to 24 months after our last contact with you, unless a business relationship follows, in which case the data is kept for the duration of that relationship and any period required by law.
What we collect. Your full name, email address, the position you are applying for, your CV (PDF or Word document), and, if you choose to provide them, your phone number and a cover letter. Your CV may contain further details you have chosen to include, such as your work history, education, location or links to professional profiles. During the recruitment process we also record our own notes and assessments, such as screening outcomes and interview feedback.
Why. To assess your application, communicate with you about it, and make hiring decisions.
Legal basis. Steps taken at your request prior to entering into an employment contract, and our legitimate interest in recruiting staff (Article 6(1)(b) and (f) GDPR; Article 12 ZZPL). Where we ask to keep your application on file for future roles, we rely on your consent.
How it is handled. Your CV is stored in Microsoft Azure Blob Storage and your application record is stored in DrillApp, our internal recruitment and operations system, both hosted in Microsoft Azure data centres in the European Union. Access is limited to the people involved in recruitment for the role. We do not make automated hiring decisions; every application is reviewed by a person.
Retention. We keep applications for 12 months after the recruitment process for the role concludes, so that we can respond to questions about the process and consider you for similar openings. With your consent we may keep your application for longer for future opportunities. If you are hired, your application becomes part of your employee records.
What we collect. Your name, your work email address and your answers to the survey questions, including any free text you write. If you reached the survey through a link we sent, we also store the short campaign tag in that link (the src value), which tells us where the link came from and nothing about you. Our infrastructure records the browser and operating system identifiers sent with your submission, and a salted hash of your IP address. The raw IP address is never stored.
Why. To send you the findings report, to email you once to arrange the thank you we send participants, and, only if you answered yes to the question at the end of the survey, to ask you a single clarifying question about your answers. The hashed IP address and the payload limits behind it exist to stop automated abuse of a public form.
Legal basis. Your consent, given when you submit the survey (Article 6(1)(a) GDPR; Article 12 ZZPL), and our legitimate interest in protecting a public form from abuse (Article 6(1)(f) GDPR).
How it is handled. Your submission is sent to our own server, which forwards it to DrillApp, our internal operations system, hosted in Microsoft Azure data centres in the European Union. It stays on DataDrill's own infrastructure: there is no third-party form tool, no survey platform and no copy of your answers in any analytics product. Access is limited to the DataDrill team members working on the benchmark. Your individual answers are never published or shared outside DataDrill, and the findings report describes the sample as a whole rather than any one respondent.
Retention. We keep responses until the findings report is complete, and we review what is still needed after it is published. You can ask us to delete your response at any time, and we will remove it.
What we collect. If you accept analytics cookies, we use Google Analytics 4 to collect information about how the site is used: pages viewed, how you arrived at the site, the approximate region you are visiting from, your device type, browser and operating system, and interactions such as scrolling and clicks. Google Analytics 4 uses your IP address to derive a coarse location and, according to Google, does not log or store it.
Why. To understand which content is useful and to improve the site.
Legal basis. Your consent (Article 6(1)(a) GDPR; Article 12 ZZPL). Nothing from Google Analytics loads until you click “Accept” on the cookie banner, and you can withdraw consent at any time as described in section 4.
Retention. User-level analytics data is retained in Google Analytics for no longer than 14 months. Aggregated reports, which cannot be linked to an individual, may be kept for longer.
What we collect. Like almost every website, our hosting infrastructure records technical information about each request: IP address, date and time, the page requested, the referring page, and browser and operating system identifiers.
Why. To deliver the site to you, keep it secure, prevent abuse and diagnose faults.
Legal basis. Our legitimate interest in operating a secure and reliable website (Article 6(1)(f) GDPR; Article 12 ZZPL).
Retention. Infrastructure logs are kept for a short period, generally no longer than 30 days, unless a specific log is needed to investigate a security incident.
We do not sell personal data. We share it only with the service providers below, which process it on our behalf and under our instructions, or where we are legally required to.
Our site also links to services we do not operate. If you book a meeting through our Calendly link, Calendly collects the details you enter under its own privacy policy and shares the booking with us. Links to LinkedIn and Instagram take you to those platforms, which set their own cookies once you arrive. Fonts are served from our own domain, so no font provider receives your data.
We may also disclose personal data where required by law, to a court or regulator, or to protect our rights, and in connection with a merger or sale of our business, in which case this policy will continue to apply to your data.
DataDrill is established in Serbia. The Republic of Serbia is not a member of the European Union, but it is a party to the Council of Europe Convention 108 and its data protection law is closely modelled on the GDPR.
Data you submit is stored on Microsoft Azure infrastructure in the European Union and accessed by our team in Serbia. Where our service providers process data outside Serbia and the European Economic Area, notably Google and Resend in the United States, we rely on appropriate safeguards: the European Commission's Standard Contractual Clauses, which the Serbian Commissioner has also adopted for transfers from Serbia, and, where the provider is certified, the EU-US Data Privacy Framework.
We apply technical and organisational measures appropriate to the risk. The site is served exclusively over HTTPS with HTTP Strict Transport Security. Uploaded files are checked for type and size before storage, and form endpoints are rate-limited and protected against cross-site requests. Data at rest in Azure is encrypted by the platform. Access to applications and CVs is restricted to the people involved in recruitment and protected by authentication.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the competent authority where the law requires it.
Under the ZZPL and the GDPR you have the right to:
To exercise any of these rights, email office@datadrill.io. We will respond within 30 days. We may ask you to confirm your identity before acting on a request. These rights are not absolute and may be limited where the law allows, for example where we must keep data to comply with a legal obligation.
If you believe we have handled your data unlawfully, you have the right to lodge a complaint with a supervisory authority. In Serbia this is the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti), Bulevar kralja Aleksandra 15, 11120 Belgrade, www.poverenik.rs. If you are in the European Economic Area or the United Kingdom, you may also complain to the data protection authority in your country of residence.
This site is intended for a professional audience and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
We will update this policy when our practices change, for example if we add a newsletter or a new service provider. The date at the top of the page shows when it was last revised. Material changes will be highlighted on this page. Continued use of the site after a change does not, on its own, count as consent to processing that requires it; we will ask for that separately.
Questions about this policy or about how we handle your data can be sent to office@datadrill.io or by post to DataDrill, Valentina Vodnika 21a, 21000 Novi Sad, Serbia. You can also use the contact form.