This notice explains what personal data Square Software processes when you use www.square.al (the "Site"), why we process it, what we do with it, how long we keep it, and what you can require of us. It is written to satisfy article 13 of Albanian Law no. 124/2024 "On the protection of personal data" and article 13 of Regulation (EU) 2016/679 (the "GDPR"), both of which apply to us.
We have tried to write it in plain language and to describe only what the Site actually does. Where a paragraph says we do not do something, we mean it: it is a statement about how the Site is built, not a promise about our intentions.
This notice covers the Site only. It does not cover other websites you may reach through a link from here, and it does not cover what we do with personal data a client asks us to process on their behalf under a separate contract. In that situation the client is the controller and we act as their processor.
1. Who is responsible for your data
The data controller is Square Software SH.P.K., a limited liability company registered with the National Business Centre (QKB) of Albania under NIPT M51418039H, with its registered office at Rruga Millosh Shutku, Nd. 14, H. 3, Ap. 17, Njësia Administrative Nr. 1, 1004 Tiranë, Albania.
For anything in this notice, write to privacy@square.al. That address reaches the people who can actually act on a request, and it is the address to use for exercising any of the rights in section 8.
We have not appointed a data protection officer. Article 33 of Law 124/2024 requires one only from public authorities, from controllers whose core activity is large-scale regular and systematic monitoring of individuals, and from controllers whose core activity involves large-scale processing of sensitive or criminal data. None of those describes us: our core activity is building software to order, and the processing in this notice is incidental to running a website. The mailbox above is the contact point instead.
We have not designated a representative in the European Union. We have assessed our EU-facing processing against the exemption in article 27(2) GDPR and concluded that it applies, because that processing is limited to what this notice describes, involves no large-scale processing of special category data, and is unlikely to result in a risk to your rights and freedoms. You can reach us directly at the address above, and section 9 sets out where to complain if you would rather not.
2. Which law applies
We are established in Albania, so Law no. 124/2024 "On the protection of personal data" applies to everything we process, wherever the processing happens (article 4(1)(a)). That law replaced Law no. 9887 of 10 March 2008, which article 99(1) repealed when the new law entered into force in 2025. Any reference you find in an older document of ours to Law 9887/2008 should be read as a reference to Law 124/2024.
We also offer our services to people and companies in the European Union, so the GDPR applies to us in parallel under its article 3(2) in respect of visitors in the EU. Law 124/2024 states in its own text that it is fully approximated to the GDPR, so in practice the two impose the same duties on us and this one notice satisfies both. Where the two could ever diverge, we apply whichever gives you more protection.
3. What we process, why, and on what legal basis
a) Serving the Site, and keeping it up. To deliver a page to you, our servers and our content delivery network necessarily handle your IP address, the address of the page you asked for, the time of the request, the response status and your browser and operating system identification. We use it to deliver the Site, to diagnose faults, and to stop abuse such as automated floods. The legal basis is our legitimate interest in operating and defending a working website (article 7(1)(dh) of Law 124/2024, article 6(1)(f) GDPR). We do not use these records to build a picture of you and we do not combine them with anything else.
b) Counting visits, without identifying you. Separately from any analytics product, we count page views and a short fixed list of interactions on our own servers, for every visitor. This measurement does not use cookies, writes nothing to your device and reads nothing from it. It creates no identifier of any kind, not even a temporary or hashed one, and your IP address is never read: the country is taken from a header our content delivery network adds before the request reaches us. What is stored is a daily total per page, per event, per country, per language and per referring website. No record of an individual visit is ever created, so nothing here can be traced back to you, and no personal data is processed. If your browser sends a Global Privacy Control or Do Not Track signal we do not count the visit at all.
c) Analytics, only if you consent. If you enable Analytics in the cookie banner we use Google Analytics 4 to understand in aggregate how the Site is used. Until you consent, Google Consent Mode holds all four storage signals at "denied" and no analytics cookies are written. The legal basis is your consent (article 7(1)(a) of Law 124/2024, article 6(1)(a) GDPR), which you can withdraw at any time from "Cookie settings" in the footer.
d) Session replay, only if you consent. If you enable Analytics we also load Microsoft Clarity, which records clicks, mouse movement, scrolling and a replay of your interaction with the page, so we can find things that are broken. It is not merely signalled about your choice, it is not loaded at all until you consent, so nothing is recorded before then. The contact form and the job application form are masked in full, so what you type into them, including any file you attach, is never recorded. We do not use it to identify you. The legal basis is your consent.
e) Advertising, only if you consent. We promote our own services through Google Ads. If you enable Advertising, advertising identifiers may be stored on your device so we can measure which advertisement led to an enquiry and, where applicable, show you our advertisements elsewhere. If you leave it off, no advertising storage is used and advertising click identifiers are stripped from outgoing requests. The legal basis is your consent, and it can be refused on its own without refusing analytics.
f) Where an enquiry came from, only if you consent. If you enable Analytics we note in your browser, for the length of your visit, the first page you saw, the site that referred you and any campaign parameters in the address, and we attach that to an enquiry if you send one, so we know which channels actually produce work. If you do not enable Analytics, nothing is written and the information is lost as soon as you leave. The legal basis is your consent.
g) The contact form. When you send us an enquiry we process your name, your email address and your message, which are required, plus your telephone number, company and subject if you give them, whether you asked us for a mutual NDA, the language you wrote in, and the enquiry-source information in (f) if you consented to it. We also record the IP address the enquiry came from and your browser identification. The legal basis for handling the enquiry itself is that the processing is necessary to take steps at your request before entering into a contract (article 7(1)(b) of Law 124/2024, article 6(1)(b) GDPR), or our legitimate interest in answering you where no contract is in prospect. The legal basis for the IP address and browser identification is narrower: our legitimate interest in preventing and evidencing abuse of a public form, which is also why we rate-limit it. They are deleted well before the enquiry itself, as section 7 sets out.
h) Job applications. If you apply for a role we process your first and last name, email address, the role you applied for, and, if you provide them, your telephone number, LinkedIn and portfolio addresses, your covering letter and your CV file. We also record the IP address and browser identification, for the same anti-abuse reason as above. The legal basis is that the processing is necessary to take steps at your request before entering into an employment contract, and our legitimate interest in running a hiring process. Please do not send us data revealing health, religion, political opinion, trade union membership, sexual life, ethnic origin or biometric or genetic information: we do not ask for it, we do not need it, article 9 of Law 124/2024 prohibits processing it without a specific ground, and if you send it anyway we will delete it rather than use it.
i) Answering you afterwards. Once you have written to us, we process the correspondence that follows on our own mail server, on the same bases as the enquiry or application it belongs to.
j) Tools that keep your data on your device. The salary, VAT, NIPT and fiscalisation calculators, the project estimator and the CV builder all run in your browser. The calculators send us nothing at all. The project estimator stores the estimate in your browser for the length of your visit only, so that the contact form can be pre-filled if you choose to send it, at which point (g) applies. The CV builder saves what you type, including any photograph you add, in your own browser storage and nowhere else: it is never transmitted to us, we cannot see it, and clearing your browser storage or using the tool’s own clear control removes it.
k) The live chat. If you open the chat and send a message, we process what you write, the page you started from, your country, your browser identification, and your name and email address if you choose to give them. You do not have to: the chat works without them, and we will not know who you are unless you tell us. A random token is stored in your browser so we can show you your own conversation if you come back. The conversation is relayed to our internal Mattermost workspace so a person, not a robot, answers you. The legal basis is that the processing is necessary to take steps at your request before entering into a contract, or our legitimate interest in answering you. Your browser identification is deleted after 3 months and the whole conversation after 12.
4. Cookies and similar technologies
Only strictly necessary storage is active by default. Analytics and Advertising are each optional, each separately refusable, and neither is enabled unless you enable it. You can change your choice at any time through "Cookie settings" in the footer, and withdrawing is exactly as easy as consenting, which article 8(3) of Law 124/2024 requires.
When you make a choice we record it in your browser together with the date and the version of the categories you were shown, because article 8(1) requires us to be able to demonstrate that you consented. That record stays on your device, is not sent to us, and is not used to track you.
Our Cookie Policy lists every cookie and storage key the Site uses, what each one is for, and which of them require consent.
5. Who else sees your data
We do not sell personal data, we do not share it for anyone else’s advertising, and we are not part of a corporate group that data is passed around inside. The following are the only categories of recipient, and each is engaged under a written contract that binds them to process only on our instructions, as article 26 of Law 124/2024 requires.
- Hetzner Online GmbH (Germany), which provides the servers in Finland where the Site and its database run, and therefore has technical access to what is stored there.
- Cloudflare, Inc., which sits in front of the Site as our content delivery network and security layer, and therefore handles the traffic data in section 3(a).
- Google Ireland Limited and its affiliates, for Google Analytics 4 and Google Ads, and only for the visitors who consented.
- Microsoft Ireland Operations Limited and its affiliates, for Microsoft Clarity, and only for the visitors who consented.
- Our own systems that we host ourselves rather than buy: the mail server that carries the notification and the reply, and the internal Mattermost workspace on our own domain where a new enquiry or application is posted so the right person sees it. Neither is a third-party service.
- Professional advisers such as lawyers and accountants, where we need advice on a matter that involves your data.
- Public authorities and courts, where we are legally obliged to provide information or need to defend a legal claim.
- Stripe Payments Europe, Limited (Ireland) and its affiliates, which process card payments and invoices, and only for subscribers of Square Tender Alerts, as section 14 describes.
If we ever transfer the business, or part of it, the data described here may pass to the acquirer, who would be bound by this notice until they lawfully told you otherwise.
6. Where your data is stored, and transfers abroad
The Site and its database run on servers located in Helsinki, Finland, inside the European Union. Enquiries, job applications and CVs are therefore stored in the EU, not in Albania, although we access them from Albania where we are established.
Because you give us your data directly and we are the controller receiving it, that initial collection is not a "transfer" for GDPR purposes, and no transfer mechanism is needed for it. What can amount to a transfer is our onward use of providers outside Albania, which article 39 and following of Law 124/2024 govern. Where the recipient is in a country the Commissioner has recognised as offering an adequate level of protection under article 40, that is the basis. Where there is no such decision, the basis is the appropriate safeguards in article 41, in practice the standard contractual clauses in our providers’ data processing terms. The providers in section 5 are contracted through their Irish or German entities, and some of them process data in the United States under those clauses.
You are entitled to know which safeguards apply and to obtain a copy of them. Write to privacy@square.al and we will tell you which countries are involved and send you the relevant clauses.
7. How long we keep it
We keep personal data only as long as the purpose it was collected for requires, and we enforce that with a scheduled job rather than by intention. The periods run from the date we received the data.
- Enquiries sent through the contact form: 36 months, after which the whole record is deleted. The IP address, browser identification and enquiry-source information attached to it are erased earlier, after 12 months, because the anti-abuse purpose they serve is spent long before the commercial one.
- Job applications: the CV file is deleted after 12 months, and the rest of the application after 24 months. If we hire you, the application becomes part of your employment file and is kept under the rules that apply to that instead.
- Correspondence by email: kept with the enquiry or application it belongs to, and deleted on the same schedule.
- Live chat conversations: your browser identification is deleted after 3 months and the whole conversation, including anything you typed and any name or email you gave, after 12 months.
- Traffic and security records in section 3(a): days to weeks, under the retention our infrastructure providers apply, and never used beyond the purposes in that paragraph.
- Google Analytics 4 and Microsoft Clarity data: retained by Google and Microsoft under the settings their products expose to us, and our Analytics property is set to the shortest event-data retention it offers.
- Our own visit counters: kept indefinitely, because they are daily totals and contain no personal data to expire.
- Your cookie choice: stays in your browser until you change it or clear your browser storage.
- Square Tender Alerts accounts, login records, the delivery log and trial records: the periods set out in section 14.
We may keep something longer than the periods above only where we must, for example while a legal claim or a request from an authority is live, and only for as long as that lasts.
8. Your rights
Articles 13 to 20 of Law 124/2024, and the equivalent articles of the GDPR, give you the following rights over your own data. They are free to exercise.
- To be informed about the processing, which is what this document is for.
- To obtain confirmation of whether we process data about you, and a copy of it, together with the details in article 14.
- To have inaccurate data corrected and incomplete data completed.
- To have data erased, including the right to be forgotten in article 16, where one of the grounds in the law applies.
- To have processing restricted while a dispute about accuracy or lawfulness is resolved.
- To receive the data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another controller where that is technically feasible.
- To object to processing based on our legitimate interest. Where we process for direct marketing, the objection is absolute: article 46(4) gives you the right to object at any time and we must stop, without weighing our interest against yours.
- Not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect on you.
- To withdraw a consent you gave, at any time, without affecting the lawfulness of what was done before you withdrew it.
To exercise any of these, write to privacy@square.al and say which right you are exercising. We will answer within 30 days, as article 14 requires. If your request is unusually complex we may need longer, in which case we will tell you why within those 30 days. If we cannot tell who you are from the request we may ask for enough information to be sure, because handing your data to the wrong person would be a worse failure than a slow answer.
We do not profile you. The only automated decision anywhere on the Site is the free-trial check of Square Tender Alerts described in section 14, which affects nothing but the trial and which a person will review at your request.
9. If you want to complain
We would rather you told us first, because most things are quicker to fix directly. But you do not have to, and you can complain to a supervisory authority whether or not you have raised it with us.
In Albania the authority is the Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale: Rr. "Abdi Toptani", Nd. 5, 1001 Tiranë, Albania, telephone +355 42 237 200, email info@idp.al, idp.al.
If you are in the European Union or the European Economic Area you may instead complain to the data protection authority of the country where you live or work, or where the problem happened. You also have the right to go to court, and to claim compensation for damage caused by unlawful processing.
10. Children
The Site is aimed at businesses and at people looking for work, not at children, and we do not knowingly collect data about children. Where we rely on consent for an online service, article 8(6) of Law 124/2024 makes that consent valid only from the age of 16, and below that age it must be given or authorised by a parent or guardian. If you believe a child has given us personal data, write to us and we will delete it.
11. Security, and what happens if it fails
Traffic to and from the Site is encrypted in transit and the Site is served over HTTPS only, with HTTP Strict Transport Security. The administrative area where enquiries, applications and CVs are reviewed is behind authentication, a CV can only be downloaded by an authenticated administrator, and access is limited to the people who need it. The public forms are rate-limited and carry an unseen field that catches automated submissions. We keep the platform and its dependencies patched. No measure makes a system perfectly safe, and we do not claim otherwise.
If a breach of personal data happens, article 29 of Law 124/2024 requires us to notify the Commissioner as soon as possible and no later than 72 hours after becoming aware of it, unless the breach is unlikely to risk your rights and freedoms, and to tell you directly where the risk to you is likely to be high. We have a written procedure for doing that and we document every breach, as article 29(6) requires.
12. Whether you have to give us your data
The data in section 3(a) is unavoidable: it is how the internet delivers a page, and if it could not be processed the Site could not be shown to you. Everything else is your choice. You can read the whole Site without consenting to anything, without filling in any form and without telling us who you are.
If you do choose to contact us or apply for a role, the fields marked as required really are required, and the only consequence of not providing them is that we cannot answer the enquiry or consider the application. There is no other disadvantage to you.
13. Changes to this notice
If we change how we process personal data we will update this page and change the date at the top before the change takes effect. Where a change materially affects you we will do more than change the date: we will say so on the Site, and where the change needs your consent we will ask for it again rather than assume it.
This version, dated 7 September 2026, replaces the version last updated in August 2026 in full. It was rewritten because the previous text was based on Law 9887/2008, which has been repealed.
14. Square Tender Alerts
This section applies only if you create an account for Square Tender Alerts, our paid service that emails subscribers the new public procurement notices published by the Public Procurement Agency (APP) and lists them in a subscriber panel. Everything above applies to the service too; this section adds what is specific to it.
What we process. The email address you sign up with; your company name and NIPT; the categories and billing plan you choose; the date and version of the terms you accepted; a record of each login link we send you and of each login session; a record of which notices we emailed you and when; and the emails about your subscription that we send you. When you subscribe, Stripe collects your card details and billing address on its own payment page. We never see or store your card number: from Stripe we receive your customer and subscription references, the status of your payments, your invoices, the name and email address you entered for billing, and the card fingerprint, a code that identifies a card without revealing its number.
Why, and on what legal basis. To create and run your account, send you the daily email, answer you and bill you, the basis is that the processing is necessary for the contract you enter into when you accept our terms (article 7(1)(b) of Law 124/2024, article 6(1)(b) GDPR). Keeping invoices and payment records is a legal obligation under Albanian tax and accounting law (article 7(1)(c), article 6(1)(c) GDPR). Two further uses rest on our legitimate interest (article 7(1)(dh), article 6(1)(f) GDPR): the records that let us stop automated abuse of login and signup, and the rule that each company, identified by its NIPT, gets the free trial only once.
The one automated decision in the service. To apply the one-trial rule we compare the card fingerprint of a new trial with the fingerprints of earlier trials. If the same card has already been used for a trial under a different NIPT, the new subscription starts without a free trial. This happens automatically. It has no effect other than on the trial, and you can ask for a person to review it, and contest it, by writing to privacy@square.al.
Who else sees it. In addition to the recipients in section 5, Stripe processes payments and invoices for us (Stripe Payments Europe, Limited, Ireland). For the card data it collects on its payment page, and for its own fraud prevention and legal obligations, Stripe acts as a separate controller under its own privacy policy; for the rest it processes data on our instructions. Stripe may process data in the United States, on the safeguards described in section 6. The daily emails and the login links are sent from our own mail server.
Browser notifications. They are optional and switched on separately on each device, from the Abonimi page in the panel. To send them we store, with your account, the push address and encryption keys your browser gives us for that device and a short device label taken from your browser (for example "Chrome, Android"). Each notification is encrypted and delivered through the push service of your browser's maker (for example Google, Mozilla, Apple or Microsoft), which sees only that a message is sent to that address. It says how many new notices there are in your categories and, while you are logged in on that device, the title of the first one. The device is removed when you switch notifications off or remove it in the panel, when the push service reports the address no longer valid, or after five failed deliveries in a row. The basis is performing the service you asked for (article 7(1)(b) of Law 124/2024, article 6(1)(b) GDPR).
Previewing documents. A tender's documents stay on app.gov.al. When you click Shiko (View) on a PDF or an image, your browser opens it directly from app.gov.al. When you click it on a Word, Excel or PowerPoint document, it opens in Microsoft's free Office viewer (view.officeapps.live.com): your browser loads Microsoft's page, which fetches the public document from app.gov.al itself, so Microsoft receives your browser's request as with any website. This happens only when you click Shiko; Shkarko (Download) fetches the file directly from app.gov.al.
Invitation links. If you arrive through an invitation link we sent you, the address carries a short code naming that invitation. It is passed to the signup form in the address only, nothing is stored in your browser, and it is kept with your account so we know which of our invitations led to a signup. Landings on a page carrying a code are counted as a bare total per code. The basis is our legitimate interest in knowing which of our own outreach works (article 7(1)(dh) of Law 124/2024, article 6(1)(f) GDPR).
Information about other people in the notices. The notices come from the public procurement export of the Public Procurement Agency and include the names and NIPTs of the operators that won a procedure. Where a winner is a natural person, for example a sole trader, that is personal data about them. We show it only as the Agency publishes it, only inside the subscriber panel and the emails, and only for the purpose the Agency publishes it for, the transparency of public procurement. We do not combine it with anything else and we do not use it to contact anyone. The basis is our legitimate interest in giving a complete record of each procedure (article 7(1)(dh) of Law 124/2024, article 6(1)(f) GDPR). If you are such a person, you have the rights in section 8, including the right to object.
The panel and the emails. The subscriber panel sets one strictly necessary cookie, which keeps you logged in and is listed in our Cookie Policy. It is counted with the same cookieless measurement described in section 3(b): no cookie, no identifier and no record of an individual visit, only daily totals, including how often each feature of the panel is used, such as applying a filter, opening a notice or downloading a document. Every notice page is counted under one shared address, so the totals never show which notices were opened. Microsoft Clarity, described in section 3(d), is loaded in the panel only if you have enabled Analytics in the cookie banner, the same choice that applies on the rest of the Site, which you can change at any time from "Cilësimet e cookie-ve" (Cookie settings) in the panel. When it is loaded, everything shown or typed in the panel is masked, so it records clicks, scrolling and movement between pages but not the notices, your account details or anything you enter, and it is not loaded at all on a page whose address contains a search or a one-time code. The panel loads no Google Analytics and no advertising tools. The daily email contains no tracking pixel, and you can stop it at any time from a link in every email or from the panel.
How long we keep it:
- Login links: deleted 7 days after they are created. A link stops working after 15 minutes, or as soon as it is used.
- Login sessions: a session lasts 30 days and is deleted when you log out, or one day after it expires.
- The record of which notices we emailed you, and the emails about your subscription: 180 days.
- An account whose email address was never confirmed and that never subscribed: deleted 30 days after signup.
- An account that was confirmed but never subscribed: deleted 24 months after the last login.
- An account whose last subscription has ended: deleted, with everything attached to it, 24 months after the subscription ended.
- The trial record (the NIPT, the billing name and email address entered at checkout, and the card fingerprint): 36 months after the trial was claimed, so that the one-trial rule can be applied. Once the account is deleted, the record is no longer linked to it.
- Invoices and payment records: kept for as long as Albanian accounting and tax law requires, also after the account is deleted.
- Stripe keeps its own records under its own retention rules.
What you have to give us. An email address, a company name and a NIPT are required to create an account, and a card is required to start the trial or to subscribe. Without them we cannot provide the service; there is no other consequence. To close your account, write to privacy@square.al: we cancel any running subscription and delete the account, keeping only the trial and invoice records described above.
For any question about this notice, or to exercise any of your rights, write to privacy@square.al.