Version: 2.0
Last modified: November 21, 2025
HR Alba Sh.pk – Tirana – Albania
NIPT: M02102024G
Contact person for data protection issues:
Email: legal @ hralba .com
Contact form:
https://www.hralba.com/contact/
Website:
www.hralba.com
This Privacy Policy describes how we HR Alba Sh.pk (hereinafter “HR Alba”, “we”, “us”) collects, uses, stores and protects personal data in accordance with:
Regulation (EU) 2016/679 (General Data Protection Regulation – “GDPR”)
Albanian Law No. 9887/2008 on the Protection of Personal Data, as amended by Law no. 35/2020
Applicable legislation in the countries where we operate
This Policy applies to:
Clients of personnel outsourcing services, BPO (Business Process Outsourcing), business support and consulting services
Employees and collaborators of HR Alba
Employees of our corporate clients for whom we provide personnel management services
Candidates who send CVs or register on our advertising platforms and tools and recruiting services, or other software and online tools offered by HR Alba
Users of the platforms and brands developed by HR Alba
Suppliers and business partners
Visitors of this website and other sites and tools owned by HR Alba (including hralba.com, outsourcingcontabilita.it, 3dpartner.it and others)
For employees of our corporate clients:
Personal data: Name, surname, date and place of birth, residence, citizenship
Identity documents: Identity card, passport
Tax information: Tax ID number (Tax ID/VAT/NIPT depending on the country)
Bank details: IBAN for payroll transfers
Contractual data: Level, job title, qualification, salary, hiring dates
Attendance data: Timesheet, holidays, permits, sick leave
Union data (only if relevant and with explicit consent)
For business customers:
Company data (company name, Tax ID/VAT/NIPT, address, legal representative)
Contacts (email, web form)
Contractual data and billing
For professional activities or client companies:
Business data of the activity
Contact details of the referents
Login credentials for tax and accounting platforms (e.g., Fisconline, Entratel, other systems)
End customer data of professional activities (only as Data Processor):
Personal and tax data
Accounting documents (invoices, F24, tax returns)
Bank details
Communications with tax authorities
For candidates:
Name, surname, email
Complete CV (experience, education, skills)
Profile photo (optional)
Job preferences (industry, location, expected salary)
Employment status
Links to professional social profiles (LinkedIn, GitHub, etc.)
For companies:
Company name, Tax ID/VAT/NIPT
Name and contact details of HR representative
Company Description
Job ads (title, description, requirements, salary)
All data necessary for the employment relationship (as per point 3.1)
Performance data and ratings
Training and certification data
Any background check data (with consent)
Technical cookies: IP address, browser type, operating system
Analytical cookies (with consent): Browsing behavior, pages visited
Contact details if you send requests via form
Purpose | Legal Basis (Art. 6 GDPR) |
|---|---|
Employment relationship management | Performance of contract (Art. 6.1.b) |
Tax and social security obligations | Legal obligation (Art. 6.1.c) |
Attendance and payroll management | Performance of contract (Art. 6.1.b) |
Communications with authorities | Legal obligation (Art. 6.1.c) |
Purpose | Legal Basis |
|---|---|
Accounting document processing | Performance of contract (Art. 6.1.b) |
Tax obligations for end customers | Legal obligation (Art. 6.1.c) |
Communications with tax authorities | Legal obligation (Art. 6.1.c) |
Document archiving | Legal obligation (Art. 6.1.c) |
IMPORTANT: For OC/BPO services, HR Alba acts as Data Processor (Data Controller) on behalf of professional activities or client companies, which are the Data Controller (Data Controllers) for the data of their end customers.
Purpose | Legal Basis |
|---|---|
Registration and account management | Performance of contract (Art. 6.1.b) |
CV/Job Advertisement Posting | Performance of contract (Art. 6.1.b) |
Candidate-Position Matching | Legitimate interest (Art. 6.1.f) |
Service improvement | Legitimate interest (Art. 6.1.f) |
Direct marketing (with opt-in) | Consent (Art. 6.1.a) |
Purpose | Legal Basis |
|---|---|
Employment relationship management | Performance of contract (Art. 6.1.b) |
Tax/social security obligations | Legal obligation (Art. 6.1.c) |
Training and development | Performance of contract (Art. 6.1.b) |
Safety at work | Legal obligation (Art. 6.1.c) |
CURRENT SITUATION:
Albania he doesn't have An adequacy decision from the European Commission (as of 21/11/2025), therefore transfers of personal data from Albania to Italy, the EU and Switzerland require appropriate safeguards.
GUARANTEES ADOPTED BY HR ALBA:
For OC/BPO services and other services involving data transfers to the EU, we use the Standard Contractual Clauses (SCC) approved by the European Commission (Decision 2021/914) to ensure the protection of data transferred to our Italian, Swiss, and European customers.
The SCCs are an integral part of our service agreements, URL: https://hralba.com/legal/scc
We implement additional measures such as:
Encryption data in transit (TLS 1.2+) and at rest (AES-256)
Limited access only to authorized personnel
Servers in EU (Hostinger France for cloud infrastructure)
Pseudonymization where possible
Audit trail complete
TOMs are an integral part of our service agreements, URL: https://hralba.com/legal/toms
We have assessed that:
Albania has GDPR-aligned data protection legislation (Law 35/2020)
There are no Albanian laws that mandate unwarranted government access to data
The technical measures implemented guarantee a level of protection equivalent to the GDPR
Personnel Outsourcing Services:
Tax authorities of the country of reference (e.g. TATIME Albania, Italian Revenue Agency)
Social security institutions (e.g. ISSH Albania, INPS Italy)
Banks for salary transfers
Labour consultants external (if necessary)
OC/BPO Services:
Professional activities or client companies (Data Controller)
Tax authorities of the reference countries
Software house (e.g. TeamSystem, Zucchetti) – aggregated/pseudonymized data only
Recruiting Platforms:
Companies who post offers (only candidates who apply)
Candidates visible to companies (public profile data)
Supplier | Service | Server Location |
|---|---|---|
Hostinger UAB | Cloud infrastructure hosting (Nextcloud and applications) | France (EU) |
Siteground | Email hosting | Germany (EU) |
respond.io | Customer messaging | USA (DPA + SCC) |
Neonwiz Technologies | Software development and maintenance | India (DPA + SCC) |
NOTE: All non-EU subprocessors have a DPA contract with SCC. HR Alba's DPAs can be found here: https://hralba.com/legal/dpa
Judicial authorities in case of legitimate requests
Auditors and legal advisors (with confidentiality obligation)
Potential buyers in case of M&A (with NDA)
We do NOT sell or rent personal information to third parties for commercial purposes.
Data Type | Retention Period | Regulatory Basis |
|---|---|---|
Payroll documents | 10 years from termination | Applicable country's labor law |
Tax data | 10 years | Tax code of the applicable country |
Employment contracts | Relationship duration + 10 years | Prescription |
Attendance and holidays | 5 years | Administrative storage |
Data Type | Retention Period | Regulatory Basis |
|---|---|---|
Accounting documents | 10 years | Art. 2220 Italian Civil Code or equivalent |
Tax returns | 10 years | Country tax law |
F24 and payments | 10 years | Tax legislation |
Electronic invoices | 10 years | Country regulations |
Data Type | Retention Period |
|---|---|
CVs of active candidates | Until account is deleted |
CVs of inactive candidates | 2 years, then automatic deletion |
Job advertisements | 12 months from closing |
Application data | 5 years (for anonymous statistics) |
Data Type | Retention Period |
|---|---|
Technical cookies | Session |
Analytical cookies | 26 months (Google Analytics) |
Contact form | 24 months or until response |
At the end of the indicated periods, the data is deleted or irreversibly anonymized.
You have the following rights regarding your personal data:
Obtain confirmation that we are processing your data and receive a copy of it.
Correct inaccurate or incomplete data.
Request deletion of your data, except where required by law.
Limit processing in specific cases (e.g. during accuracy checks).
Receive your data in a structured format and transfer it to third parties.
Object to processing based on legitimate interest or direct marketing.
Not be subject to decisions based solely on automated processes (e.g. profiling).
NOTE: We use matching algorithms on our platforms, but the final hiring decisions are always human.
You can contact us:
E-mail: legal @ hralba.com
Online form: https://www.hralba.com/contact/
We will respond within:
1 month from the request (extendable to 3 months in complex cases)
What we will ask you:
Identification (for security) via document or account credentials
Clear description of the request
Costs:
Free for first reasonable requests
Possible contribution for repetitive or manifestly unfounded requests
If you believe that the processing of your data violates the GDPR, you have the right to lodge a complaint with:
In Albania:
Komisioneri for your Drejtën and Information about your Mbrojtjen and your Personal Dhënave
Address: Blv. “Zhan D'Ark” Nr. 2, Tirana, Albania
Tel: +355 4 2380 944
E-mail: info@idp.al
Web: www.idp.al
In Italy (if you are an EU resident):
Guarantor for the Protection of Personal Data
Piazza Venezia 11, 00187 Rome
Tel: +39 06 696771
Web: www.garanteprivacy.it
Or to the authority of your EU/Swiss country of residence.
Encryption: TLS 1.2+ for transmission, AES-256 for storage
Strong Authentication: 2FA required for admin logins
Firewall and VPN: Access from authorized IPs
Antivirus and anti-malware: Continuous scanning
Backup: Encrypted daily, stored for 30 days
Restricted access: “Need to know” principle
GDPR Training: Mandatory for all staff
NDA: Signed by all employees and collaborators
Incident Response Plan: Documented data breach procedures
Regular audits: Quarterly safety checks
Nextcloud and cloud applications: Self-hosted on Hostinger VPS (France)
E-mail: Siteground (Germany)
Database: MySQL encrypted with incremental backups
Redundancy: Redundant systems for high availability
Despite the measures we have taken, no system at 100% is secure. In the event of a data breach, we will notify you within 72 hours, as required by the GDPR.
Technical Cookies (always active):
Session: Login and navigation management
Safety: CSRF and Attack Prevention
Load balancing: Server optimization
Analytical Cookies (with consent):
Google Analytics: Anonymized visit statistics (truncated IP)
Hotjar: Behavior Heatmap (anonymous)
Marketing Cookies (with consent):
Google Ads: Remarketing
Facebook Pixel: Conversion tracking
LinkedIn Insight Tag: B2B Campaigns
You can manage cookies via:
Cookie banner on first access
Browser settings (e.g. Chrome > Settings > Privacy)
Specific opt-outs:
Google Analytics: Google Analytics Opt-out
Hotjar: Hotjar Opt-out
NOTE: Disabling technical cookies may compromise the functionality of the site.
Our sites may contain links to third-party websites (e.g. LinkedIn, Facebook). We are not responsible for the privacy practices of these sites. We encourage you to read their policies.
This Privacy Policy may be updated to reflect:
Regulatory changes (GDPR, Albanian law, other countries)
New services or features
Security improvements
When we update:
We publish a new version with modification date
We will notify you by email of any material changes (if we have your consent).
We display banners on websites for 30 days
Latest version always available on:
For any questions about this Privacy Policy or the processing of your data:
HR Alba Sh.pk Tirana – Albania
NIPT: M02102024G
Contact person for data protection issues:
Email: legal @ hralba .com
Contact form:
https://www.hralba.com/contact/
Website:
www.hralba.com
Personal Data: Any information relating to an identified or identifiable natural person.
Data Controller: Entity that determines the purposes and means of processing.
Data Controller (Data Processor): Entity that processes data on behalf of the Data Controller.
Data Subject: Natural person whose data is being processed.
Treatment: Any operation on data (collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, communication, cancellation, destruction).
GDPR: General Data Protection Regulation – Regulation (EU) 2016/679.
DPA: Data Processing Agreement – Agreement between Data Controller and Data Processor (Art. 28 GDPR)
SCC: Standard Contractual Clauses – Standard contractual clauses approved by the EU Commission for transfers outside the EU.
Data Breach: A breach of security leading to the destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.
End of Privacy Policy
This Privacy Policy was last updated on: November 21, 2025
Version: 1.0
Tongue: English