Privacy Policy

How we collect, use, and protect your personal data

Last updated: August 2026

1. Introduction

PrivaxisOS ("we", "our", or "us") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our privacy governance platform and visit our website.

We process personal data in accordance with Albanian Law No. 124/2024 "On Personal Data Protection" and the General Data Protection Regulation (GDPR), which the Albanian law transposes.

2. Our Role: Controller and Processor

PrivaxisOS handles personal data in two different roles, and which one applies decides who you should contact about your data.

We are the controller for the personal data we collect for our own purposes: visitors to this website, people who contact us or request a demo, and the account details of the people who administer a client's subscription. This policy governs that data.

We are a processor for the personal data our clients hold inside the platform - registers of processing, assessments, vendor records, and the privacy requests individuals submit through a client's intake portal. The client organisation is the controller of that data. We process it only on their documented instructions under a data processing agreement meeting Art. 26(3) of Law 124/2024 and Art. 28(3) of the GDPR, and we do not use it for our own purposes, sell it, or use it to train artificial-intelligence or machine-learning models. Their privacy policy governs that data, not this one; Section 10 explains where to direct a request about it.

The controller for the data described in this policy is:

IT&Soft SH.P.K., an Albanian limited liability company, which operates PrivaxisOS
Email: support@itsoft.al
Phone: +355 69 569 7010

Data Protection Officer: We have not designated a Data Protection Officer. Privacy questions and requests reach us at the contact details above.

3. Personal Data We Collect

3.1 Information You Provide

3.2 Information Collected Automatically

3.3 Data We Process for Our Clients

Personal data about a client's employees, customers and other individuals passes through the platform. We process it as a processor, on the client's instructions:

The client decides what is collected, why, and how long it is kept. Sections 4 to 7 describe how we treat data we hold as controller; they do not determine the client's own purposes or retention periods.

4. Legal Basis for Processing

We process your personal data based on the following legal grounds under Law 124/2024 and the GDPR:

For the data described in Section 3.3 the legal basis is determined by the client organisation as controller, not by us.

5. How We Use Your Data

We use your personal data for the following purposes:

6. Data Sharing and Disclosure

We do not sell your personal data. We may share your data with:

7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Specifically:

8. Cookies

This website sets no cookies, uses no local or session storage, and loads no third-party scripts, fonts or analytics. Nothing on it requires a consent banner.

The platform uses the following types of cookies:

We do not use advertising or tracking cookies anywhere. You can manage cookie settings through your browser preferences.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

10. Your Rights

Under Arts. 12-21 of Law 124/2024, and the equivalent Arts. 12-22 of the GDPR, you have the following rights regarding your personal data:

If your personal data sits in a client's platform account - because you submitted a privacy request through their portal, or because your employer records you in their register of processing activities - that organisation is the controller and you should send your request to them. If you contact us instead we will pass it on and tell you we have done so; we cannot act on it ourselves without the client's instruction.

To exercise any of these rights over the data we hold as controller, contact us using the details below. Under Art. 12 of Law 124/2024 we respond within 30 days of receiving your request. Where the request is complex we may extend that to 60 days in total, and we will tell you within the first 30 days if we do. If we refuse a request we will tell you why, within the same 30 days, and explain how to complain.

11. International Data Transfers

The platform is hosted on Amazon Web Services in the Frankfurt (eu-central-1) region. Data stays within the European Union in the ordinary course of the service.

Albania is not part of the European Economic Area, so hosting in Germany is itself an international transfer. Transfers are governed by Arts. 39-42 of Law 124/2024, the equivalent of GDPR Arts. 44-49. Where the destination is covered by the Commissioner's adequacy decision, the transfer rests on that decision; otherwise we put appropriate safeguards in place, such as standard contractual clauses or other legally recognised mechanisms.

12. Children's Privacy

Our platform is designed for business use and is not directed at individuals under the age of 16. We do not knowingly collect personal data from children.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website with a revised "Last updated" date. We encourage you to review this policy periodically.

14. Supervisory Authority

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Albanian Information and Data Protection Commissioner (Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale) or the relevant supervisory authority in your jurisdiction.

15. Contact Us

For any questions or requests regarding this Privacy Policy or your personal data, please contact us:

Email: support@itsoft.al

Phone: +355 69 569 7010