1. Data controller and privacy contact
The controller for the processing described in this policy is Kodesign Sh.P.K., unless another controller is identified for a particular service. Kodesign has not appointed a Data Protection Officer. Privacy questions and rights requests can be sent to the contact below.
- Registered address
- Rr. Hajredin Reshani, Kompleksi Euro Invest, Blloku B3, 70000 Ferizaj, Kosovo
- Kosovo business-registration number
- 812349159
- Fiscal number
- 812349159
- VAT number
- 812349159
- Authorised representatives
- Veton Qerimi, Co-founder & CEO; Lirak Hamiti, Co-founder & CTO
- Email and current privacy contact
- contact@kodesign.dev
- Telephone
- +383 48 687 431
- Data Protection Officer
- No DPO has been appointed.
2. Applicable data-protection framework
Kodesign processes personal data under Kosovo Law No. 06/L-082 on Personal Data Protection. The EU General Data Protection Regulation (GDPR) applies where processing falls within its territorial scope. The Swiss Federal Act on Data Protection (FADP) applies where its scope is met.
Kosovo is not described here as an EU Member State, and this policy does not claim that the GDPR automatically applies to every visitor.
3. Processing activities
| Activity | Data | Purpose | Legal basis | Recipients | Retention |
|---|---|---|---|---|---|
| Contact enquiries | Name, email, optional company, message, optional timeline, meeting preference, enquiry type, locale, source path, privacy-notice acknowledgement | Respond, qualify the request, and prepare next steps | Steps requested before a contract and/or legitimate interests in handling business enquiries | Authorised Kodesign staff; Namecheap hosting and cPanel email; Google Gmail where mail is forwarded | 24 months after the last substantive contact if the enquiry does not become a client relationship |
| Contract-related communication | Enquiry and subsequent correspondence | Prepare, conclude, or perform a contract | Pre-contractual steps or contractual necessity | Kodesign and relevant professional providers, including lawyers only where legal advice is needed | For the relationship and generally six years after it ends; longer where a legal claim or mandatory record period applies |
| Form security | IP address, timing, locale, source path, Origin/Referrer, host, request size, honeypot result, validation outcome, rate-limit timestamps | Prevent spam, abuse, and unsafe requests | Legitimate interests in website and service security | Kodesign and Namecheap hosting/security infrastructure | Rate-limit events count for one hour; cleanup mechanics and provider log criteria are described in sections 5 and 9 |
| Google Analytics 4 | Online and cookie identifiers, page URL/title/referrer, device/browser information, IP-derived approximate location, page views, scrolls, outbound clicks, file downloads, and successful-enquiry events | Measure website use, content performance, traffic sources, and successful enquiries | Prior analytics consent | Google LLC, Google Ireland Limited where applicable, and relevant infrastructure | User-level and event-level data: 14 months; GA cookies: up to two years |
| Meta Pixel | PageView and successful-enquiry events; page URL and referrer; browser, device, network, and Meta-related identifiers; _fbp and _fbc when set | Measure and attribute Meta advertising and optimise campaigns | Prior marketing consent | Meta Platforms, Inc., Meta Platforms Ireland Limited, and relevant infrastructure | Meta documents _fbp and _fbc for 90 days and may retain Event Data for up to two years |
| Theme preference | Light or dark choice | Remember display preference | Necessary website functionality and/or legitimate interests | Stored locally in the visitor's browser | Until removed, browser storage is reset, or the key changes |
| Language preference | Selected language | Return the visitor to the preferred language | Necessary website functionality and/or legitimate interests | Stored locally in the visitor's browser | Until removed, browser storage is reset, or the key changes |
| Consent record | Category choices, status, timestamp, policy version, and expiry | Respect, apply, and demonstrate choices | Legal obligation and legitimate interests | Kodesign; stored locally in the visitor's browser | 180 days, unless withdrawn, browser storage is reset, or a material policy-version change requires renewal sooner |
4. Contact enquiries
- Required
- Enquiry type (project or partnership), message, name, email address, and acknowledgement that the Privacy Policy has been read.
- Optional
- Company, preferred timeline, and a request for a meeting.
- Generated by the website
- Locale, source path, form-start timestamp, and anti-spam/security information.
The form sends the submitted information through the same-origin /contact.php endpoint to contact@kodesign.dev. Namecheap's hosting and cPanel email infrastructure processes the request and resulting business email. Kodesign also forwards business mail to a company Gmail address. Only authorised Kodesign team members have routine access.
Submitting an enquiry does not subscribe the visitor to marketing. There is currently no optional email-marketing consent in the form.
If analytics consent already exists, a successful submission sends a generate_lead event with the contact category to GA4. The message, name, email, company, timeline, meeting preference, and other form contents are not sent to Google Analytics.
If marketing consent already exists, a successful submission may send a standard Lead event without parameters to Meta Pixel. The message, name, email, company, timeline, meeting preference, and enquiry type are not sent to Meta. This does not subscribe the visitor to marketing.
5. Technical information and form security
The server validates the request method, request size, same-origin Origin or Referrer and host information, required fields, lengths, email format, form timing, and a hidden honeypot field. Hosting systems may also create request, error, access, and security logs containing IP addresses and technical request information.
For rate limiting, the endpoint hashes the visitor IP with a service-specific value and stores recent timestamps in the PHP temporary directory. Hashing reduces direct exposure but does not necessarily make the identifier non-personal data. No more than five accepted attempts are allowed in the current one-hour window.
Timestamps cease to count after one hour. Expired rate files are eligible for probabilistic cleanup during later form requests and files with no active timestamps are deleted. A file can nevertheless remain until later form traffic or the hosting environment's temporary-file cleanup. Namecheap may retain access, error, security, and backup data for service operation, restoration, security, legal, and troubleshooting needs under its published policies and Kodesign's service agreement.
6. Consent-based Google Analytics
Kodesign uses Google Analytics 4 with Measurement ID G-TZNQNVZ90W only after Analytics consent. Depending on the visitor and contractual context, relevant providers include Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA, and Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing is governed by Google's applicable Analytics Terms and data-processing terms.
After consent, the site loads gtag.js from www.googletagmanager.com and may send measurement requests to www.google-analytics.com and region1.google-analytics.com. GA4 can receive cookie and online identifiers, IP-derived approximate location, device/browser information, page URL and title, referrer, language, page views, scrolls, outbound clicks, file downloads, and successful-enquiry events.
The current site configuration disables Google Signals, Google advertising-personalisation signals, Privacy Sandbox interest-group storage, and all advertising-related Consent Mode signals. Site search, video engagement, and automatic form-interaction measurement are intended to remain disabled in the GA web-stream settings. Kodesign does not use User-ID and does not currently link this property to Google Ads.
After the contact endpoint confirms a successful submission, the site sends generate_lead with the category contact only if Analytics consent is active. It does not send the visitor's name, email address, company, message, timeline, meeting preference, enquiry type, or other form contents to GA4.
Consent can be withdrawn at any time through Cookie settings. Withdrawal prevents future GA loading from this site, applies denied Analytics consent, removes the loaded script, and attempts to delete accessible GA cookies. Browser controls may be required for third-party storage Kodesign cannot directly remove.
7. Consent-based Meta Pixel
Kodesign uses Meta Pixel ID 1733276837931388 only after marketing consent. Depending on the visitor and service context, relevant providers include Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, and Meta Platforms, Inc., 1 Meta Way, Menlo Park, California 94025, USA. Kodesign and Meta process information under Meta's applicable Business Tools Terms and data-processing terms.
After marketing consent, the site loads the Pixel library from connect.facebook.net and sends requests to www.facebook.com. It reports a PageView and, after a successful enquiry, a standard Lead event without custom parameters. Meta may receive the event, page URL and referrer, timestamp, browser/device/network information, IP address, and Meta or cookie identifiers such as _fbp and _fbc when available. Meta may use information from its business tools in accordance with its terms and privacy policy.
Kodesign uses these events to measure and attribute Meta advertising and optimise campaigns. The current implementation does not create website audiences, enable Advanced Matching or use Conversions API. Automatic event detection is off. It does not send form contents, message text, name, email address, company, timeline, meeting preference, or enquiry type to Meta.
Marketing consent can be withdrawn through Cookie settings. Withdrawal revokes future Pixel collection from this site, removes the Pixel script, and attempts to delete accessible _fbp and _fbc cookies. Browser controls may be required for third-party storage that Kodesign cannot directly remove.
8. Recipients, processors, and international transfers
Access is limited to authorised Kodesign team members and providers who need the information for the purposes described. Lawyers receive enquiry information only if legal advice is necessary. Information may also be disclosed where required by law, a valid authority request, or to establish, exercise, or defend legal claims.
The live service uses Namecheap for hosting, cPanel email, DNS and spam filtering, Google Gmail for forwarded business mail, Google Analytics after Analytics consent, and Meta Pixel after Marketing consent. Providers may process data outside Kosovo, including in the Netherlands, Ireland, the United States, and other locations used by their subprocessors. Relevant provider contracts, data-processing terms, and transfer mechanisms such as standard contractual clauses apply where available and required. Kodesign does not claim that Kosovo has an EU adequacy decision.
| Provider/service | Country or countries | Safeguard/contract |
|---|---|---|
| Namecheap hosting, cPanel email, DNS, and Jellyfish spam filtering | Current hosting server: Netherlands; Namecheap, Inc.: United States; other provider/subprocessor locations may apply | Namecheap service terms, privacy notices, Data Processing Addendum, and applicable transfer clauses |
| Google Gmail forwarding | United States and other Google processing locations | Google terms, privacy terms, and applicable data-transfer mechanisms |
| Google Analytics (only after Analytics consent) | Ireland, United States, and other Google processing locations | Google Analytics Terms, data-processing terms, and applicable transfer mechanisms |
| Meta Pixel (only after marketing consent) | Ireland, United States, and other Meta processing locations | Meta Business Tools Terms, data-processing terms, and applicable transfer mechanisms |
| External media | Not active | Must be reviewed and documented before activation |
9. Retention
Kodesign retains personal data only for the periods or objective criteria below, subject to any longer period needed for a legal claim, investigation, or mandatory accounting, tax, or other record-keeping duty. Kodesign management is responsible for applying this schedule and deletion is performed manually where the system does not expire information automatically.
| Record | Approved period or criterion |
|---|---|
| Unsuccessful enquiries | 24 months after the last substantive contact |
| Enquiries that become client relationships | Held in the client/project file for the relationship and generally six years after it ends; longer only where a legal claim or mandatory duty requires it |
| Contracts, accounting, and tax records | Generally six years after the relevant tax/accounting year; financial statements and supporting books are kept for ten years where the applicable rule requires it |
| Email correspondence | 24 months after the last relevant contact, unless it forms part of a client, contract, legal, accounting, or tax record, in which case that record's period applies |
| Privacy-rights request records | Three years after the request is closed, unless needed longer for a complaint or legal claim |
| Security and abuse records | Up to 12 months after the matter is closed, unless a continuing incident, investigation, legal claim, or legal duty requires longer |
| Rate-limit timestamps/files | Timestamps count for one hour; expired files are removed during later probabilistic cleanup or the hosting environment's temporary-file cleanup |
| Hosting/server logs and backups | For Namecheap's documented operational, security, restoration, contractual, and legal needs; Namecheap states shared-hosting backups are made every three to seven days, but the applicable provider schedule controls deletion |
| Google Analytics | User-level and event-level data: 14 months with reset on new activity disabled; _ga and _ga_TZNQNVZ90W cookies: up to two years unless removed earlier |
| Meta Pixel Event Data and cookies | _fbp and _fbc: 90 days; Meta Event Data: up to two years under Meta's Business Tools Terms |
| Consent records | 180 days; earlier on withdrawal, browser reset, or a material policy-version change |
| Theme and language preferences | Until removed, browser storage is reset, or the storage key changes |
10. Your data-protection rights
Subject to the applicable law and its conditions, you may request access, correction, erasure, restriction, and data portability where applicable, and object to processing based on legitimate interests. You may withdraw consent at any time without affecting processing lawfully carried out before withdrawal, and object at any time to direct marketing. Kodesign does not currently use the general enquiry form for direct-marketing subscriptions.
- Send a request to contact@kodesign.dev. Kodesign may request proportionate information to verify identity and protect information from unauthorised disclosure.
- Under Kosovo Law No. 06/L-082, Kodesign must respond without undue delay and in any event within one month after receiving the request. Where necessary due to complexity or the number of requests, this may be extended by two further months; Kodesign must notify you of the extension and reasons within the first month. A different mandatory period applies where another governing law requires it.
- You may complain to Kosovo's Information and Privacy Agency and, where relevant, the competent EU/EEA or Swiss supervisory authority.
- Kosovo Information and Privacy Agency
- Str. Zejnel Salihu No. 22, 10000 Prishtina, Republic of Kosovo
- info.aip@rks-gov.net
- Telephone
- 0800 600 10
- Official website
- aip.rks-gov.net
11. Security, children, and other information
- Security
- Kodesign uses proportionate technical and organisational safeguards, including validation, same-origin checks, rate limiting, access controls, and provider safeguards. No system can promise absolute security.
- Automated decisions
- The website does not make decisions producing legal or similarly significant effects solely through automated processing.
- Children
- The website and business enquiry form are not directed to children. A child should not submit personal information without appropriate parent or guardian involvement where required.
- Sensitive information
- Do not submit health information, identification numbers, financial credentials, criminal data, or other unnecessary sensitive information through the general form.
12. Policy updates
Kodesign may update this policy when processing, providers, laws, or safeguards change. Material changes to consent purposes or vendors will receive a new policy/banner version and, where required, a new consent request. The effective date, last-updated date, and version above identify the applicable policy.