Privacy Policy
Last updated: 7 October 2026
This policy explains what personal data Valyrian Management collects through valyrianmanagement.com and the client workspace, why, how long we keep it, who helps us process it, and the rights you have. We keep it short and specific: we only collect what we need to run the service.
1. Who we are
The controller for the personal data described in this policy is:
Stefan Jelenić, a private individual (natural person) operating under the name Valyrian Management
Bačka Palanka, Republic of Serbia
Email: support@valyrianmanagement.com · Telegram: @stefanjelenic
For anything about your data, write to us at the email above. We answer within 30 days, usually much sooner.
2. What we collect
Visitors of the website
We do not use analytics, advertising or tracking cookies, and we do not load fonts or scripts from third parties: fonts and code are served from our own server. Like every website, our hosting and network providers record technical request data (IP address, browser type, time, requested page) in server logs to keep the site running and secure.
Client workspace accounts
- Account data: your email address and password. Passwords are stored only as a secure hash by our authentication provider; we never see them.
- Verification: one-time codes we email you to confirm your address or reset your password. Codes expire after one hour.
- Team and access: which agency you belong to, your role (owner, member or viewer), which models you can see, and invite links created for you.
- Activity in the workspace: sign-ins, which pages you open, actions you take (for example creating an invite) and active time, recorded as at most one signal per minute while you use the workspace. Owners of your agency can see this for their own team, so they can follow hours and activity. We do not record keystrokes, screen contents or anything outside the workspace.
Agency business data
To run posting for an agency we process the data the agency gives us or that our automation produces: names of the creators (models) the agency manages, social media handles, post links and statuses, account health and follower counts, content left per platform, statistics and invoices. Some of this can identify people.
When you contact us
If you write to us by email or Telegram, we keep the conversation to answer you and to support your agency.
3. Why we use it and legal bases
| Purpose | Data | Legal basis (GDPR Art. 6 / Serbian ZZPL Art. 12) |
|---|---|---|
| Provide the workspace and the posting service | Account, team, agency business data | Performance of a contract |
| Confirm emails and recover accounts | Email, verification codes | Performance of a contract |
| Show owners their team's activity and hours | Activity in the workspace | Legitimate interest of the agency in organising its team; you can object at any time (section 10) |
| Keep the service secure and prevent abuse | Server logs, sign-ins | Legitimate interest in security |
| Billing and accounting | Invoices, agency details | Legal obligation |
| Answer your questions | Messages | Legitimate interest / steps before a contract |
We do not sell personal data, do not use it for advertising and do not make automated decisions that have legal or similarly significant effects on you.
4. Our role for client data
For the agency business data and for the activity of an agency's own team members, the agency is the controller and Valyrian Management acts as its processor: we process that data only to provide the service the agency ordered, following its instructions. Agencies are responsible for having a lawful basis for the data they give us, including informing their team members and the creators they manage. We sign a data processing agreement with any agency that asks for one.
5. Cookies and local storage
The website sets no cookies. The client workspace stores a few items in your browser that are strictly necessary for it to work, so no consent banner is required:
- your sign-in session (so you stay signed in),
- the agency you selected last,
- whether you have already seen the welcome tutorial,
- an invite link you opened, until you finish signing up.
You can remove them at any time by signing out or clearing your browser's site data.
6. Service providers
We use a small number of providers who process data on our behalf under contracts that require them to protect it:
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, authentication and server functions of the workspace | European Union (Ireland) |
| Resend | Sending verification and password emails | European Union (Ireland) |
| Cloudflare | DNS, network protection and delivery | Global network |
| Hetzner Online | Hosting of the website | European Union (Germany) |
We may also disclose data if the law requires it, or to protect our rights, our users or the public.
7. International transfers
We keep workspace data in the European Union. Some providers are companies based in the United States or other countries; where data can be accessed from outside the EU/EEA or Serbia, the transfer is covered by the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.
8. How long we keep data
- Account and team data: as long as the account exists, and deleted within 30 days after the account or the agency's contract ends.
- Activity in the workspace: 12 months, then deleted.
- Agency business data: for the duration of the contract, then deleted or returned to the agency within 30 days, unless the agency asks for earlier deletion.
- Invoices and accounting records: as long as accounting and tax law requires.
- Server logs: up to 30 days, unless needed to investigate a security incident.
- Verification codes: valid for one hour.
9. Security
All traffic is encrypted (HTTPS). Passwords are hashed. Access to data is enforced on the server: every request is checked against your account and agency, so a login only ever sees the agency, models and accounts it was given. Staff tools are delivered only to authorised staff accounts. Device identifiers, login credentials and network details of the posting devices are never shown in the workspace.
If a breach affects your personal data in a way that creates a risk to you, we will inform the competent authority and, where required, you.
10. Your rights
Under the GDPR and the Serbian Law on Personal Data Protection you can ask us to:
- tell you what data we have about you and give you a copy (access),
- correct it (rectification),
- delete it (erasure), or limit how we use it (restriction),
- give it to you in a portable format (portability),
- stop processing based on legitimate interest, including activity tracking (objection),
- withdraw any consent you gave, at any time.
Write to us at the email in section 1. If your data belongs to an agency's workspace, we may forward your request to that agency as the controller. You also have the right to complain to a supervisory authority: in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs); in the EU, the data protection authority of your country.
11. Age
The service is for businesses and is not intended for anyone under 18. We do not knowingly collect data from minors.
12. Changes
If we change this policy we update the date at the top. If the change is significant, we tell workspace users by email or in the workspace before it applies.
