Legal

Data Protection Policy

KPX IT Services L.L.C.

Address: Rexhep Mala Street 28/A, 10000 Prishtina, Republic of Kosovo

Business Registration No.: 812252138

Email: info@kpx-ks.com

Website: https://www.kpx-ks.com

Effective date: January 14, 2026

1. Purpose and Scope

1.1 This Privacy Policy is issued by KPX IT Services L.L.C. (hereinafter: “KPX” or the “Company”), acting in its capacity as Data Controller, for the purpose of providing transparent information to data subjects regarding the processing of personal data, in accordance with Law No. 06/L-082 on the Protection of Personal Data of the Republic of Kosovo.

1.2 This Privacy Policy applies to all personal data processed by KPX in the course of its business activities, including but not limited to the use of the website, contractual and pre-contractual relationships, electronic communications, and the provision of IT, software, SaaS, hosting, managed services, and consulting services.

1.3 Categories of data subjects. This Privacy Policy applies in particular to (i) website visitors, (ii) customers’ and prospects’ representatives and contact persons, (iii) business partners and their representatives, (iv) users of KPX services where KPX acts as Data Controller (e.g., account administration), and (v) individuals who contact KPX via e-mail or support channels.

1.4 Data sources. KPX may collect personal data (i) directly from the data subject, (ii) from the data subject’s employer/customer (e.g., when a customer designates authorized users or contacts), (iii) from publicly available sources (e.g., business registers, professional networking sites) where permitted by law, and/or (iv) generated through the use of KPX systems (e.g., logs).

1.5 Requirement to provide data and consequences. Where KPX requests personal data to conclude or perform a contract, the provision of such data may be necessary. If the required data are not provided, KPX may be unable to provide certain services or respond to requests.

2. Principles of Personal Data Processing

2.1 KPX processes personal data in compliance with the principles of lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability, as prescribed by Law No. 06/L-082.

3. Categories of Personal Data

3.1 Depending on the legal relationship or interaction with KPX, the following categories of personal data may be processed

  • aIdentification data (name, surname, business name);
  • bContact data (email address, telephone number, business address);
  • cProfessional data (job title, employer, role);
  • dContractual and financial data (contracts, invoices, payment information);
  • eTechnical data (IP address, access logs, user identifiers);
  • fCommunication data (correspondence, support requests, inquiries).

3.2 KPX does not intentionally process special categories of personal data, except where such processing is expressly required by law or lawfully permitted. Data subjects and customers are requested not to provide special categories of personal data to KPX unless expressly requested or necessary for a specific lawful purpose.

4. Purposes of Processing

4.1 Personal data are processed for the following purposes

  • aconclusion and performance of contracts;
  • bprovision of IT, software, SaaS, hosting and technical support services;
  • ccommunication with clients and business partners;
  • dinvoicing, accounting and fulfillment of tax and financial obligations;
  • eensuring system security and service continuity;
  • fcompliance with legal and regulatory obligations;
  • gprotection of KPX’s legitimate interests, including the establishment, exercise or defense of legal claims.

4.2 Legitimate interests. Where KPX relies on legitimate interests as a legal basis, such interests may include: ensuring IT and information security (e.g., preventing fraud, abuse and unauthorized access), maintaining and improving service reliability, and establishing, exercising or defending legal claims. Data subjects may object to processing based on legitimate interests as described in Section 9.

5. Legal Bases for Processing

5.1 Personal data are processed on one or more of the following legal bases

  • aconsent of the data subject;
  • bnecessity for the performance of a contract or pre-contractual measures;
  • ccompliance with a legal obligation;
  • dprotection of vital interests;
  • elegitimate interests pursued by KPX, insofar as such interests do not override the fundamental rights and freedoms of the data subject.

6. Recipients of Personal Data

6.1 Personal data may be disclosed to

  • aauthorized employees of KPX;
  • bcontractual data processors (IT service providers, hosting and cloud providers);
  • cprofessional advisors (lawyers, auditors, accountants);
  • dpublic authorities, where disclosure is required by applicable law.

6.2 All data processors are contractually bound to confidentiality and data protection obligations. Where required, KPX concludes data processing agreements with processors in accordance with Law No. 06/L-082.

7. International Data Transfers

7.1 Where personal data are transferred outside the Republic of Kosovo, including within the KPX Group and to its subcontractors, as well as to third-party providers that issue software licenses ordered by the Customer (e.g., Microsoft 365 or other external providers), KPX ensures that such transfers are carried out solely on the basis of appropriate legal, technical, and organizational safeguards, in full compliance with applicable data protection legislation.

7.2 Transfer safeguards (examples). Such safeguards may include, as applicable, (i) transfer to jurisdictions recognized as providing an adequate level of protection under applicable law, (ii) standard contractual clauses or equivalent contractual safeguards, and/or (iii) additional technical measures such as encryption in transit and at rest, access controls, and data minimization.

7.3 Further information. Upon request, KPX will provide data subjects (or, where applicable, customers acting as controllers) with additional information regarding the relevant transfer safeguards, unless restricted by law or confidentiality obligations.

8. Data Retention Periods

8.1 Personal data are retained only for as long as necessary to achieve the purposes of processing and in accordance with statutory retention periods under applicable tax, accounting and commercial legislation, and will be deleted or anonymized once no longer necessary for the purposes for which they were collected, unless longer retention is required or permitted by law.

8.2 Retention criteria (examples). Depending on the context, retention periods may be based on

  • acontract duration and limitation periods for potential claims;
  • bstatutory accounting and tax retention obligations (e.g., invoices and accounting records);
  • csecurity and audit requirements (e.g., access logs retained for a limited period necessary for security monitoring and incident investigation).

9. Rights of Data Subjects

9.1 Data subjects are entitled to the following rights

  • aright of access;
  • bright to rectification;
  • cright to erasure (right to be forgotten);
  • dright to restriction of processing;
  • eright to data portability;
  • fright to object to processing;
  • gright to withdraw consent at any time;
  • hright to lodge a complaint with the Agency for Information and Privacy of the Republic of Kosovo.

9.2 Requests may be submitted by email to info@kpx-ks.com. KPX will respond within the statutory deadlines.

9.3 Identity verification. To protect personal data, KPX may request additional information to verify the identity of the requesting person before responding.

10. Data Security

10.1 KPX implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, unlawful disclosure or destruction. Such measures may include, as appropriate, access controls, encryption, backups, logging/monitoring, and staff confidentiality obligations.

11. Processing of Data on Behalf of Clients

11.1 Where KPX processes personal data on behalf of its clients, such processing is governed by a separate Data Processing Agreement (DPA), concluded in accordance with Law No. 06/L-082.

11.2 Roles of the parties. In such cases, the client is the Data Controller and KPX acts as Data Processor with respect to the client’s data, as specified in the DPA.

12. Cookies and Website Data

12.1 The KPX website uses only strictly necessary cookies required for functionality and security. Where additional cookies are used, users will be duly informed and their consent will be obtained where required by law.

12.2 Cookie control. Users can control cookies through their browser settings. Disabling strictly necessary cookies may affect website functionality.

12.3 Third-party services on the website. If KPX uses third-party services that may process technical data (e.g., hosting, security services, content delivery), such providers will be treated as recipients/processors as described in Section 6 and, where applicable, may involve international transfers as described in Section 7.

13. Automated Decision-Making

13.1 KPX does not apply automated decision-making or profiling that produces legal effects or similarly significant effects on data subjects.

14. Amendments to the Privacy Policy

14.1 KPX reserves the right to amend or update this Privacy Policy at any time, in order to reflect changes in legislation or organizational practices. The updated version shall be published on the website. Where required by applicable law, KPX will provide appropriate notice of material changes.

15. Contact Information

15.1 For any questions or requests relating to the processing of personal data, please contact: KPX IT Services L.L.C. Email: info@kpx-ks.com

15.2 Data protection contact. For privacy-specific inquiries, data subjects may also use the subject line “Data Protection Request” to help KPX route requests internally.

Book a free consultation