Valyrian Management
Legal

Privacy Policy

Last updated: 7 October 2026

This policy explains what personal data Valyrian Management collects through valyrianmanagement.com and the client workspace, why, how long we keep it, who helps us process it, and the rights you have. We keep it short and specific: we only collect what we need to run the service.

1. Who we are

The controller for the personal data described in this policy is:

Stefan Jelenić, a private individual (natural person) operating under the name Valyrian Management
Bačka Palanka, Republic of Serbia
Email: support@valyrianmanagement.com · Telegram: @stefanjelenic

For anything about your data, write to us at the email above. We answer within 30 days, usually much sooner.

2. What we collect

Visitors of the website

We do not use analytics, advertising or tracking cookies, and we do not load fonts or scripts from third parties: fonts and code are served from our own server. Like every website, our hosting and network providers record technical request data (IP address, browser type, time, requested page) in server logs to keep the site running and secure.

Client workspace accounts

Agency business data

To run posting for an agency we process the data the agency gives us or that our automation produces: names of the creators (models) the agency manages, social media handles, post links and statuses, account health and follower counts, content left per platform, statistics and invoices. Some of this can identify people.

When you contact us

If you write to us by email or Telegram, we keep the conversation to answer you and to support your agency.

3. Why we use it and legal bases

PurposeDataLegal basis (GDPR Art. 6 / Serbian ZZPL Art. 12)
Provide the workspace and the posting serviceAccount, team, agency business dataPerformance of a contract
Confirm emails and recover accountsEmail, verification codesPerformance of a contract
Show owners their team's activity and hoursActivity in the workspaceLegitimate interest of the agency in organising its team; you can object at any time (section 10)
Keep the service secure and prevent abuseServer logs, sign-insLegitimate interest in security
Billing and accountingInvoices, agency detailsLegal obligation
Answer your questionsMessagesLegitimate interest / steps before a contract

We do not sell personal data, do not use it for advertising and do not make automated decisions that have legal or similarly significant effects on you.

4. Our role for client data

For the agency business data and for the activity of an agency's own team members, the agency is the controller and Valyrian Management acts as its processor: we process that data only to provide the service the agency ordered, following its instructions. Agencies are responsible for having a lawful basis for the data they give us, including informing their team members and the creators they manage. We sign a data processing agreement with any agency that asks for one.

5. Cookies and local storage

The website sets no cookies. The client workspace stores a few items in your browser that are strictly necessary for it to work, so no consent banner is required:

You can remove them at any time by signing out or clearing your browser's site data.

6. Service providers

We use a small number of providers who process data on our behalf under contracts that require them to protect it:

ProviderWhat forWhere
SupabaseDatabase, authentication and server functions of the workspaceEuropean Union (Ireland)
ResendSending verification and password emailsEuropean Union (Ireland)
CloudflareDNS, network protection and deliveryGlobal network
Hetzner OnlineHosting of the websiteEuropean Union (Germany)

We may also disclose data if the law requires it, or to protect our rights, our users or the public.

7. International transfers

We keep workspace data in the European Union. Some providers are companies based in the United States or other countries; where data can be accessed from outside the EU/EEA or Serbia, the transfer is covered by the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.

8. How long we keep data

9. Security

All traffic is encrypted (HTTPS). Passwords are hashed. Access to data is enforced on the server: every request is checked against your account and agency, so a login only ever sees the agency, models and accounts it was given. Staff tools are delivered only to authorised staff accounts. Device identifiers, login credentials and network details of the posting devices are never shown in the workspace.

If a breach affects your personal data in a way that creates a risk to you, we will inform the competent authority and, where required, you.

10. Your rights

Under the GDPR and the Serbian Law on Personal Data Protection you can ask us to:

Write to us at the email in section 1. If your data belongs to an agency's workspace, we may forward your request to that agency as the controller. You also have the right to complain to a supervisory authority: in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs); in the EU, the data protection authority of your country.

11. Age

The service is for businesses and is not intended for anyone under 18. We do not knowingly collect data from minors.

12. Changes

If we change this policy we update the date at the top. If the change is significant, we tell workspace users by email or in the workspace before it applies.