Korak
Privacy & Security

Privacy & Security Policy

Effective date: 10 April 2026 · Controller: Zbor MNE DOO, Janka Đonovića 40, 81000 Podgorica, Montenegro · Tax ID: 03506177

Contents
  1. Introduction
  2. Data we collect
  3. Purpose of processing
  4. Legal basis
  5. Visibility & sharing
  6. Retention & deletion
  7. Payment security
  8. Technical safeguards
  9. Fraud & abuse protection
  10. Incident management
  11. Your rights
  12. Your security duties
  13. Children
  14. International transfers
  15. Supervisory authority
  16. Updates to this policy
  17. Contact

01 Introduction

This document is the Privacy and Security Policy of the Korak mobile application, owned and operated by Zbor MNE DOO, with its registered office at Janka Đonovića 40, 81000 Podgorica, Montenegro (Tax ID: 03506177).

Its purpose is to protect users' personal data, financial transactions, and the integrity of the Korak platform.

The provider undertakes to apply technical and organisational protection measures in accordance with:

02 Data we collect

We collect the following categories of data:

All data is stored in a secure database with technical and organisational safeguards applied.

03 Purpose of processing

Data provided by users is processed solely for the following purposes:

Korak uses personal data only in ways consistent with the purpose for which it was collected or for which users have given authorisation, in accordance with applicable law.

No advertising use

User data is never used for advertising and is not shared with advertisers or marketing platforms without the user's explicit consent.

We process personal data on the following legal bases:

Users have the right to withdraw consent at any time. Such withdrawal does not affect the lawfulness of processing carried out before withdrawal.

05 Visibility & sharing

Only basic information (first name, photo, qualifications and general professional information) is publicly visible on a therapist's profile. Email address, password and phone number are never publicly accessible and are stored with appropriate security measures.

Full personal data is accessible only to the Korak administrative team, and only for purposes of security and system administration.

Third parties we share data with

User data is not shared with third parties except in the following cases:

06 Retention & deletion

Personal data is kept for as long as there is a purpose for processing it or until the user requests its deletion. If a user deletes their account, all of their data is permanently erased, except where there is a legal basis for continued retention (for example, invoices or tax records, which are kept only for the period required by law and are not used for any other purpose).

How to delete your account

You can delete your account and all associated data at any time:

  • From inside the app: open Korak → Profile tab → scroll to the bottom → tap Delete account and confirm. Your account is removed immediately.
  • Without the app: visit our account-deletion page or email support@korak.to from the address linked to your account. We will process the request within 30 days.

Deletion removes your profile, messages, bookings, uploaded documents, saved payment cards, search history, and all authentication identifiers (email, phone, Google identity link). Anonymous, aggregated usage analytics that cannot be linked back to you may be retained.

All users are responsible for keeping their accounts secure and using the platform in accordance with the Terms of Service.

Korak is obliged to ensure the security of the personal data it processes. To prevent unauthorised access or disclosure, to maintain the accuracy of data, and to ensure its proper use, Korak has adopted appropriate physical, electronic and administrative procedures.

Korak strives to protect the privacy of personal data and accidental disclosure is unlikely. In the event of such an unplanned disclosure, Korak will take reasonable steps to limit and remedy the disclosure and to notify affected users.

07 Payment security

All payment transactions are processed through certified payment processors compliant with PCI DSS standards. Korak does not collect, store or process payment-card data on its own servers. Payment data is transmitted over an encrypted channel (TLS/SSL) directly to the payment processor.

Security measures for payment transactions include:

08 Technical safeguards

Encryption

Access control

Infrastructure

09 Fraud & abuse protection

Korak applies the following measures:

In the event of suspicious activity, Korak reserves the right to temporarily suspend an account, request additional identity verification, and notify the competent authorities.

10 Incident management

In the event of a security incident, Korak will:

11 Your rights

Users have the following rights under the Law on Personal Data Protection:

To exercise any of these rights, contact support@korak.to. We will respond within 30 days.

12 Your security duties

To help keep your account secure you should:

13 Children

Korak is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact support@korak.to and we will delete it.

14 International transfers

Some of our service providers (listed in section 5) may process data outside Montenegro, including in the European Economic Area and the United States. Where data is transferred outside Montenegro, we rely on appropriate safeguards such as Standard Contractual Clauses and service providers' compliance with recognised security standards.

15 Supervisory authority

If you believe your rights regarding the processing of personal data have been infringed, you have the right to lodge a complaint with the Agency for Personal Data Protection and Free Access to Information of Montenegro:

Address
Bulevar Svetog Petra Cetinjskog 147, Podgorica
Web
www.azlp.me
Email
azlp@t-com.me

You also have the right to judicial protection in accordance with applicable law.

16 Updates to this policy

Korak reviews and updates this policy regularly. Users will be notified of material changes through the app or by email. This policy entered into force on 10 April 2026.

17 Contact

For any questions, incident reports or requests related to security and data protection:

Company
Zbor MNE DOO
Address
Janka Đonovića 40, 81000 Podgorica, Montenegro
General
info@korak.to
Support
support@korak.to