Privacy policy
How NexaSphere Technologies SH.P.K. collects, uses, shares and protects personal data — under the Law on Protection of Personal Data of the Republic of Kosovo, the EU General Data Protection Regulation (GDPR) and the UK GDPR.
Your name, company and contact details when you get in touch, plus basic technical logs to keep the site secure.
Analytics cookies are set only after you click "Accept". No advertising trackers, no selling of data — ever.
Ask us to access, correct or delete your data at any time by emailing privacy@nexasphere.net.
1.Who we are (data controller)
The controller responsible for the processing of personal data described in this policy is:
NexaSphere Technologies SH.P.K.
- Trading as
- NexaSphere Technologies · nexasphere.net
- Legal form
- Limited liability company (Shoqëri me përgjegjësi të kufizuara) under the laws of the Republic of Kosovo
- Registered office
- Rruga Muharrem Fejza 74, 10000 Prishtinë, Republic of Kosovo
- Telephone
- +383 45 437 762
- Privacy contact
- privacy@nexasphere.net
We have not appointed a statutory Data Protection Officer because our processing does not meet the thresholds that require one. All privacy enquiries are handled personally by the company's management via the privacy contact above.
2.Scope and applicable law
This policy applies to personal data we process when you visit nexasphere.net, contact us, or do business with us as a client, prospect, supplier or partner. It does not cover data we process on behalf of our clients as a processor (for example, data inside software we build and operate for a client) — that processing is governed by the data processing agreement we sign with each client.
We are established in the Republic of Kosovo and comply with Law No. 06/L-082 on Protection of Personal Data. Because we offer our services to businesses in the European Union and the United Kingdom, we also apply the EU GDPR (Regulation (EU) 2016/679) and the UK GDPR and Data Protection Act 2018 to data relating to individuals in those territories. Where these laws differ, we apply the standard that gives you the greater protection.
3.What data we collect, why, and on what legal basis
| When | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| You visit our website | IP address, browser type and version, operating system, referring URL, pages viewed, date and time (server log data) | Delivering the site, security, detecting abuse and diagnosing faults | Legitimate interests (Art. 6(1)(f) GDPR) — running a secure website | Up to 30 days in logs |
| You submit the contact form or email us | Name, company, email address, telephone, country, service of interest, budget range, and the content of your message | Responding to your enquiry, preparing a proposal, following up | Pre-contractual steps at your request (Art. 6(1)(b)); legitimate interests in responding to business enquiries (Art. 6(1)(f)) | 24 months after our last contact, unless a contract follows |
| You become a client, supplier or partner | Contact details of your representatives, contract and project data, correspondence, invoicing and payment details | Performing the contract, project delivery, support, invoicing, accounting | Contract (Art. 6(1)(b)); legal obligations, e.g. tax and accounting (Art. 6(1)(c)) | Duration of the relationship plus the statutory retention period for financial records (generally 6–10 years) |
| You accept analytics cookies | Pseudonymous usage data: pages visited, approximate location (city level, IP truncated), device and browser category, interaction events | Understanding how the site is used so we can improve it | Consent (Art. 6(1)(a) GDPR; Art. 5 LPPD), which you may withdraw at any time | 14 months |
| You receive our newsletter or updates | Name, email address, company, open and click statistics | Sending information about our services, insights and events | Consent (Art. 6(1)(a)); for existing clients, legitimate interests in direct marketing with an opt-out in every message | Until you unsubscribe, then a suppression record only |
| You interact with us on LinkedIn or other platforms | Your public profile information and messages you send us | Networking, responding to messages, business development | Legitimate interests (Art. 6(1)(f)) | As long as relevant to the relationship |
We do not process special categories of personal data (such as health or political data) through this website, and we do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
Where your data comes from. Most of it comes directly from you. For business development we may also use publicly available business sources — company websites, LinkedIn, trade registers and business directories — to obtain the professional contact details of decision-makers. When we do, we tell you where we obtained your details at first contact and give you a simple way to object.
6.International data transfers
We are located in the Republic of Kosovo, which is outside the European Economic Area and the United Kingdom and has not yet received an adequacy decision from the European Commission or the UK Government. When you contact us from the EU or the UK, your data is therefore transferred to Kosovo. We protect such transfers by:
- applying Kosovo's Law on Protection of Personal Data, which is closely modelled on the GDPR and supervised by an independent authority;
- entering into the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) with EU and UK clients for whom we act as processor;
- keeping client project data on servers located in the EU (for example Frankfurt, Amsterdam or Paris) whenever a client requires EU data residency;
- applying the technical and organisational security measures described in section 8.
Where the GDPR or UK GDPR requires us to designate a representative in the EU or the UK (Article 27), details of the representative are available on request from privacy@nexasphere.net.
7.How long we keep personal data
We keep personal data only for as long as necessary for the purpose it was collected, as set out in the table in section 3. In summary:
- Enquiries that do not lead to a contract: deleted 24 months after our last exchange.
- Client, supplier and partner records: for the duration of the relationship, then for the period required by Kosovo tax and accounting law and, where applicable, the law of the client's country (generally 6–10 years for invoices and contracts).
- Server logs: 30 days. Analytics data: 14 months.
- Marketing consent and unsubscribe records: kept as evidence of your choice for as long as we send marketing communications.
When the retention period ends, data is securely deleted or irreversibly anonymised.
8.How we protect your data
We apply technical and organisational measures appropriate to the risk, including: TLS encryption of all traffic to and from our website and email; encryption of data at rest with our hosting and productivity providers; multi-factor authentication and least-privilege access for all company accounts; regular software updates and security patching; secure-development practices (OWASP) in everything we build; and confidentiality obligations for everyone who works with us. In the unlikely event of a personal data breach that is likely to result in a risk to you, we will notify the competent supervisory authority within 72 hours and inform you without undue delay where the law requires it.
9.Your rights
Under Kosovo law, the GDPR and the UK GDPR you have the right to:
- Access — obtain a copy of the personal data we hold about you and information about how we use it;
- Rectification — have inaccurate or incomplete data corrected;
- Erasure — have your data deleted where there is no longer a legal reason to keep it;
- Restriction — ask us to limit how we use your data in certain circumstances;
- Portability — receive data you gave us in a structured, machine-readable format;
- Object — object to processing based on legitimate interests, and to direct marketing at any time;
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of processing before withdrawal.
To exercise any right, email privacy@nexasphere.net or write to the address in section 1. We will respond within 30 days (extendable by up to two further months for complex requests, in which case we will tell you). We may ask you to confirm your identity before acting on a request. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.
10.Complaints and supervisory authorities
We would like the chance to resolve any concern first — please contact us. You also have the right to lodge a complaint with a supervisory authority, in particular:
- Kosovo: Information and Privacy Agency (Agjencia për Informim dhe Privatësi), Prishtinë — aip.rks-gov.net
- United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
- Germany: the data protection authority of your federal state (Landesdatenschutzbehörde) or the BfDI — bfdi.bund.de
- France: CNIL — cnil.fr
- Netherlands: Autoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl
- Belgium: Autorité de protection des données / Gegevensbeschermingsautoriteit — dataprotectionauthority.be
11.Children
Our services are directed at businesses. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
12.Changes to this policy
We review this policy at least once a year and whenever our processing, our suppliers or the law change. The version and effective date are shown at the top of the page. For material changes that affect you, we will give notice on this website or, where we hold your contact details and the change is significant, by email.
13.Contact
NexaSphere Technologies SH.P.K., Rruga Muharrem Fejza 74, 10000 Prishtinë, Republic of Kosovo
privacy@nexasphere.net · +383 45 437 762 · Legal notice / Impressum