HR Alba

PRIVACY POLICY

HR Alba Sh.pk

Version: 2.0
Last modified: November 21, 2025


1. DATA CONTROLLER

HR Alba Sh.pk – Tirana – Albania
NIPT: M02102024G

Contact person for data protection issues:
Email: legal @ hralba .com

Contact form:
https://www.hralba.com/contact/

Website:
www.hralba.com


2. INTRODUCTION AND SCOPE

This Privacy Policy describes how we HR Alba Sh.pk (hereinafter “HR Alba”, “we”, “us”) collects, uses, stores and protects personal data in accordance with:

  • Regulation (EU) 2016/679 (General Data Protection Regulation – “GDPR”)

  • Albanian Law No. 9887/2008 on the Protection of Personal Data, as amended by Law no. 35/2020

  • Applicable legislation in the countries where we operate

This Policy applies to:

  1. Clients of personnel outsourcing services, BPO (Business Process Outsourcing), business support and consulting services

  2. Employees and collaborators of HR Alba

  3. Employees of our corporate clients for whom we provide personnel management services

  4. Candidates who send CVs or register on our advertising platforms and tools and recruiting services, or other software and online tools offered by HR Alba

  5. Users of the platforms and brands developed by HR Alba

  6. Suppliers and business partners

  7. Visitors of this website and other sites and tools owned by HR Alba (including hralba.com, outsourcingcontabilita.it, 3dpartner.it and others)


3. WHAT PERSONAL DATA WE COLLECT

3.1 Personnel Outsourcing and HR Management Services

For employees of our corporate clients:

  • Personal data: Name, surname, date and place of birth, residence, citizenship

  • Identity documents: Identity card, passport

  • Tax information: Tax ID number (Tax ID/VAT/NIPT depending on the country)

  • Bank details: IBAN for payroll transfers

  • Contractual data: Level, job title, qualification, salary, hiring dates

  • Attendance data: Timesheet, holidays, permits, sick leave

  • Union data (only if relevant and with explicit consent)

For business customers:

  • Company data (company name, Tax ID/VAT/NIPT, address, legal representative)

  • Contacts (email, web form)

  • Contractual data and billing

3.2 OC/BPO Services (Accounting Outsourcing and Business Process Outsourcing)

For professional activities or client companies:

  • Business data of the activity

  • Contact details of the referents

  • Login credentials for tax and accounting platforms (e.g., Fisconline, Entratel, other systems)

  • End customer data of professional activities (only as Data Processor):

    • Personal and tax data

    • Accounting documents (invoices, F24, tax returns)

    • Bank details

    • Communications with tax authorities

3.3 Recruiting Platforms and Online HR Services

For candidates:

  • Name, surname, email

  • Complete CV (experience, education, skills)

  • Profile photo (optional)

  • Job preferences (industry, location, expected salary)

  • Employment status

  • Links to professional social profiles (LinkedIn, GitHub, etc.)

For companies:

  • Company name, Tax ID/VAT/NIPT

  • Name and contact details of HR representative

  • Company Description

  • Job ads (title, description, requirements, salary)

3.4 Alba HR Employees and Collaborators

  • All data necessary for the employment relationship (as per point 3.1)

  • Performance data and ratings

  • Training and certification data

  • Any background check data (with consent)

3.5 Website and Platform Visitors

  • Technical cookies: IP address, browser type, operating system

  • Analytical cookies (with consent): Browsing behavior, pages visited

  • Contact details if you send requests via form


4. PURPOSE AND LEGAL BASIS OF THE PROCESSING

4.1 Personnel Outsourcing and HR Management Services

Purpose

Legal Basis (Art. 6 GDPR)

Employment relationship management

Performance of contract (Art. 6.1.b)

Tax and social security obligations

Legal obligation (Art. 6.1.c)

Attendance and payroll management

Performance of contract (Art. 6.1.b)

Communications with authorities

Legal obligation (Art. 6.1.c)

4.2 OC/BPO Services

Purpose

Legal Basis

Accounting document processing

Performance of contract (Art. 6.1.b)

Tax obligations for end customers

Legal obligation (Art. 6.1.c)

Communications with tax authorities

Legal obligation (Art. 6.1.c)

Document archiving

Legal obligation (Art. 6.1.c)

IMPORTANT: For OC/BPO services, HR Alba acts as Data Processor (Data Controller) on behalf of professional activities or client companies, which are the Data Controller (Data Controllers) for the data of their end customers.

4.3 Recruiting Platforms and Online HR Services

Purpose

Legal Basis

Registration and account management

Performance of contract (Art. 6.1.b)

CV/Job Advertisement Posting

Performance of contract (Art. 6.1.b)

Candidate-Position Matching

Legitimate interest (Art. 6.1.f)

Service improvement

Legitimate interest (Art. 6.1.f)

Direct marketing (with opt-in)

Consent (Art. 6.1.a)

4.4 HR Alba Employees

Purpose

Legal Basis

Employment relationship management

Performance of contract (Art. 6.1.b)

Tax/social security obligations

Legal obligation (Art. 6.1.c)

Training and development

Performance of contract (Art. 6.1.b)

Safety at work

Legal obligation (Art. 6.1.c)


5. DATA TRANSFER OUTSIDE THE EU (ALBANIA → ITALY/EU/SWITZERLAND)

CURRENT SITUATION:
Albania he doesn't have An adequacy decision from the European Commission (as of 21/11/2025), therefore transfers of personal data from Albania to Italy, the EU and Switzerland require appropriate safeguards.

GUARANTEES ADOPTED BY HR ALBA:

5.1 Standard Contractual Clauses (SCC)

For OC/BPO services and other services involving data transfers to the EU, we use the Standard Contractual Clauses (SCC) approved by the European Commission (Decision 2021/914) to ensure the protection of data transferred to our Italian, Swiss, and European customers.

The SCCs are an integral part of our service agreements, URL: https://hralba.com/legal/scc 

5.2 Technical and Organizational Measures (TOMs)

We implement additional measures such as:

  • Encryption data in transit (TLS 1.2+) and at rest (AES-256)

  • Limited access only to authorized personnel

  • Servers in EU (Hostinger France for cloud infrastructure)

  • Pseudonymization where possible

  • Audit trail complete

TOMs are an integral part of our service agreements, URL: https://hralba.com/legal/toms 

5.3 Risk Assessment (Transfer Impact Assessment)

We have assessed that:

  • Albania has GDPR-aligned data protection legislation (Law 35/2020)

  • There are no Albanian laws that mandate unwarranted government access to data

  • The technical measures implemented guarantee a level of protection equivalent to the GDPR


6. WHO WE SHARE YOUR DATA WITH

6.1 Recipients Required for the Services

Personnel Outsourcing Services:

  • Tax authorities of the country of reference (e.g. TATIME Albania, Italian Revenue Agency)

  • Social security institutions (e.g. ISSH Albania, INPS Italy)

  • Banks for salary transfers

  • Labour consultants external (if necessary)

OC/BPO Services:

  • Professional activities or client companies (Data Controller)

  • Tax authorities of the reference countries

  • Software house (e.g. TeamSystem, Zucchetti) – aggregated/pseudonymized data only

Recruiting Platforms:

  • Companies who post offers (only candidates who apply)

  • Candidates visible to companies (public profile data)

6.2 Service Providers (Sub-processors)

Supplier

Service

Server Location

Hostinger UAB

Cloud infrastructure hosting (Nextcloud and applications)

France (EU)

Siteground

Email hosting

Germany (EU)

respond.io

Customer messaging

USA (DPA + SCC)

Neonwiz Technologies

Software development and maintenance

India (DPA + SCC)

NOTE: All non-EU subprocessors have a DPA contract with SCC. HR Alba's DPAs can be found here: https://hralba.com/legal/dpa 

6.3 Other Recipients

  • Judicial authorities in case of legitimate requests

  • Auditors and legal advisors (with confidentiality obligation)

  • Potential buyers in case of M&A (with NDA)

We do NOT sell or rent personal information to third parties for commercial purposes.


7. STORAGE PERIOD

7.1 Personnel Outsourcing Services

Data Type

Retention Period

Regulatory Basis

Payroll documents

10 years from termination

Applicable country's labor law

Tax data

10 years

Tax code of the applicable country

Employment contracts

Relationship duration + 10 years

Prescription

Attendance and holidays

5 years

Administrative storage

7.2 OC/BPO Services

Data Type

Retention Period

Regulatory Basis

Accounting documents

10 years

Art. 2220 Italian Civil Code or equivalent

Tax returns

10 years

Country tax law

F24 and payments

10 years

Tax legislation

Electronic invoices

10 years

Country regulations

7.3 Recruiting Platforms

Data Type

Retention Period

CVs of active candidates

Until account is deleted

CVs of inactive candidates

2 years, then automatic deletion

Job advertisements

12 months from closing

Application data

5 years (for anonymous statistics)

7.4 Website Visitors

Data Type

Retention Period

Technical cookies

Session

Analytical cookies

26 months (Google Analytics)

Contact form

24 months or until response

At the end of the indicated periods, the data is deleted or irreversibly anonymized.


8. YOUR RIGHTS (Art. 15-22 GDPR)

You have the following rights regarding your personal data:

8.1 Right of Access (Art. 15)

Obtain confirmation that we are processing your data and receive a copy of it.

8.2 Right of Rectification (Art. 16)

Correct inaccurate or incomplete data.

8.3 Right to Erasure / “Right to be Forgotten” (Art. 17)

Request deletion of your data, except where required by law.

8.4 Right of Limitation (Art. 18)

Limit processing in specific cases (e.g. during accuracy checks).

8.5 Right to Portability (Art. 20)

Receive your data in a structured format and transfer it to third parties.

8.6 Right to Object (Art. 21)

Object to processing based on legitimate interest or direct marketing.

8.7 Right Not to Be Subjected to Automated Decisions (Art. 22)

Not be subject to decisions based solely on automated processes (e.g. profiling).

NOTE: We use matching algorithms on our platforms, but the final hiring decisions are always human.


9. HOW TO EXERCISE YOUR RIGHTS

You can contact us:

We will respond within:

  • 1 month from the request (extendable to 3 months in complex cases)

What we will ask you:

  • Identification (for security) via document or account credentials

  • Clear description of the request

Costs:

  • Free for first reasonable requests

  • Possible contribution for repetitive or manifestly unfounded requests


10. RIGHT TO COMPLAIN

If you believe that the processing of your data violates the GDPR, you have the right to lodge a complaint with:

In Albania:
Komisioneri for your Drejtën and Information about your Mbrojtjen and your Personal Dhënave
Address: Blv. “Zhan D'Ark” Nr. 2, Tirana, Albania
Tel: +355 4 2380 944
E-mail: info@idp.al
Web: www.idp.al

In Italy (if you are an EU resident):
Guarantor for the Protection of Personal Data
Piazza Venezia 11, 00187 Rome
Tel: +39 06 696771
Web: www.garanteprivacy.it

Or to the authority of your EU/Swiss country of residence.


11. DATA SECURITY

11.1 Technical Measures

  • Encryption: TLS 1.2+ for transmission, AES-256 for storage

  • Strong Authentication: 2FA required for admin logins

  • Firewall and VPN: Access from authorized IPs

  • Antivirus and anti-malware: Continuous scanning

  • Backup: Encrypted daily, stored for 30 days

11.2 Organizational Measures

  • Restricted access: “Need to know” principle

  • GDPR Training: Mandatory for all staff

  • NDA: Signed by all employees and collaborators

  • Incident Response Plan: Documented data breach procedures

  • Regular audits: Quarterly safety checks

11.3 Infrastructure

  • Nextcloud and cloud applications: Self-hosted on Hostinger VPS (France)

  • E-mail: Siteground (Germany)

  • Database: MySQL encrypted with incremental backups

  • Redundancy: Redundant systems for high availability

Despite the measures we have taken, no system at 100% is secure. In the event of a data breach, we will notify you within 72 hours, as required by the GDPR.


12. COOKIES AND TRACKING TECHNOLOGIES

12.1 Types of Cookies Used

Technical Cookies (always active):

  • Session: Login and navigation management

  • Safety: CSRF and Attack Prevention

  • Load balancing: Server optimization

Analytical Cookies (with consent):

  • Google Analytics: Anonymized visit statistics (truncated IP)

  • Hotjar: Behavior Heatmap (anonymous)

Marketing Cookies (with consent):

  • Google Ads: Remarketing

  • Facebook Pixel: Conversion tracking

  • LinkedIn Insight Tag: B2B Campaigns

12.2 How to Manage Cookies

You can manage cookies via:

NOTE: Disabling technical cookies may compromise the functionality of the site.


13. LINKS TO THIRD PARTY SITES

Our sites may contain links to third-party websites (e.g. LinkedIn, Facebook). We are not responsible for the privacy practices of these sites. We encourage you to read their policies.


14. CHANGES TO THE PRIVACY POLICY

This Privacy Policy may be updated to reflect:

  • Regulatory changes (GDPR, Albanian law, other countries)

  • New services or features

  • Security improvements

When we update:

  • We publish a new version with modification date

  • We will notify you by email of any material changes (if we have your consent).

  • We display banners on websites for 30 days

Latest version always available on:


15. CONTACTS

For any questions about this Privacy Policy or the processing of your data:

HR Alba Sh.pk Tirana – Albania
NIPT: M02102024G

Contact person for data protection issues:
Email: legal @ hralba .com

Contact form:
https://www.hralba.com/contact/

Website:
www.hralba.com


16. GLOSSARY

Personal Data: Any information relating to an identified or identifiable natural person.

Data Controller: Entity that determines the purposes and means of processing.

Data Controller (Data Processor): Entity that processes data on behalf of the Data Controller.

Data Subject: Natural person whose data is being processed.

Treatment: Any operation on data (collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, communication, cancellation, destruction).

GDPR: General Data Protection Regulation – Regulation (EU) 2016/679.

DPA: Data Processing Agreement – Agreement between Data Controller and Data Processor (Art. 28 GDPR)

SCC: Standard Contractual Clauses – Standard contractual clauses approved by the EU Commission for transfers outside the EU.

Data Breach: A breach of security leading to the destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.


End of Privacy Policy


This Privacy Policy was last updated on: November 21, 2025
Version: 1.0
Tongue: English