Privacy policy
How we collect, use and protect your personal data, under Law No. 06/L-082 on the Protection of Personal Data.
1. Who the data controller is
The data controller is cyphera, based at Rr. Nexhip Dragaj 81, Mitrovicë 40000, Republic of Kosovo. We determine the purposes and means of processing the personal data we collect through registrations, sessions and the workspace.
For any question or request about personal data, contact us at contact@cypheraks.com or on +383 49 215 527.
2. Legal basis
Processing is carried out under Law No. 06/L-082 on the Protection of Personal Data, which is harmonised with EU Regulation 2016/679 (GDPR). Depending on the case, we rely on the following bases:
- Performance of a contract — to organise your training, group and schedule.
- Legal obligation — for invoicing, accounting and tax duties.
- Explicit consent — for photographs, video, promotional communication and the use of artificial intelligence tools.
- Legitimate interest — for the security of the premises through camera surveillance, balanced against your rights.
3. The principles we apply
Under Article 4 of the Law, your data is processed:
- lawfully, fairly and transparently;
- only for specified and legitimate purposes;
- limited to what is necessary;
- accurately and kept up to date;
- stored no longer than necessary;
- with appropriate technical and organisational security;
- with accountability — we are responsible and can demonstrate compliance.
4. What data we collect
4.1 Participants
- First name, surname and date of birth
- Prior knowledge, from the placement test
- Session attendance and progress
- Work created during the programme — projects, code, designs
4.2 Parents or legal guardians
- First name and surname
- Phone number and email address
- Billing details, when an invoice is requested
4.3 Coworking members
- Name, contact and billing details
- Records of entry and use of the space
4.4 From the website
Our website uses no tracking cookies and contains no third-party advertising or analytics tools. Your language preference is stored only in your browser and is never sent to us. If we add analytics in future, this policy will be updated and your consent will be sought beforehand.
At the bottom of the site we show an embedded Google Maps map to indicate our location. When it loads, Google may set cookies or collect data under its own privacy policy, over which we have no control. If you prefer to avoid this, you can open the location directly in Google Maps via the "Get directions" button.
4.5 When you submit the registration form
Besides the details you enter yourself, we store the date and time of submission and an irreversible fingerprint of your IP address — an encoded string from which the address cannot be recovered. This fingerprint serves only to limit automated submissions and to recognise abuse; it is never used to identify or track you. The full IP address is not stored.
Requests submitted through the form are stored outside the public area of the website and are accessible only to authorised staff, with a username and password. They are deleted automatically after twelve months, unless a contractual relationship has been formed in the meantime.
5. Children's data
Article 7 of the Law provides that processing a child's data on the basis of consent is lawful where the child is at least sixteen (16) years old. For participants below that age, consent is given or authorised by the parent or legal guardian.
- Registration for minors is always completed by the parent or guardian.
- Separate consents — photos, video, AI tools — are signed in writing by the parent.
- We never ask children for data we do not need.
- Communication about progress and billing goes to the parent, not the child.
6. Photographs and recordings
During sessions and demonstrations we may take photographs or recordings. These are used only with separate written consent — from the parent for minors, and from the person themselves for adults.
- Consent is given on a form separate from the contract and may be withdrawn at any time.
- Withdrawal does not affect the lawfulness of processing carried out beforehand.
- There is an option to publish without a full name or without a visible face.
- Refusal has no effect whatsoever on participation or treatment in the programme.
7. Artificial intelligence tools
Where a programme involves AI tools, strict rules apply:
- Only academy accounts are used, supervised by the instructor.
- Participants do not open personal accounts on these tools.
- Entering names, photos or any identifying data is prohibited.
- For minors, written parental consent is required before the module begins.
- No topic is worked on with AI before the participant masters it without one.
- The use of AI is not permitted in practical assessments.
The specific tools vary by programme and are updated over time. Each provider has its own terms and age limits, which apply in parallel with these rules. The list of tools used in a given programme is provided in writing before it begins, and a parent may request that their child not use them, with no consequence for participation.
In line with Article 21 of the Law, we make no decisions based solely on automated processing and we carry out no profiling that produces legal effects or similarly significant impact on you.
8. Video surveillance
The premises are monitored by cameras for the safety of people and equipment. Covered areas are marked with a visible notice at the entrance. There are no cameras in toilets or rest areas. Recordings are kept for a limited period of 30 days, after which they are deleted automatically, and are released only to competent authorities where required by law.
9. Who we share data with
We do not sell or trade your data. Data relating to your membership, payments and participation is shared with no one — except where sharing is expressly required by law by the competent state authorities.
The only operational exception are the technical service providers we use for email and file storage. They act as data processors on our instructions, bound by contract, and have no right to use the data for their own purposes.
If any provider is located outside Kosovo, transfer takes place only to countries with an adequate level of protection or with appropriate safeguards, under the relevant chapter of the Law.
10. How long we keep data
- Registration data — during the programme and two years after it ends.
- Billing data — according to statutory accounting and tax periods.
- Participant work and portfolio — until you request deletion.
- Camera recordings — 30 days, then deleted automatically.
- Consent forms — as long as needed to demonstrate compliance.
11. Your rights
Under Articles 11 to 21 of the Law, you have the right:
- To be informed about how your data is processed.
- To access the data we hold about you or your child.
- To request rectification of inaccurate or incomplete data.
- To request erasure where there is no legal duty to retain.
- To request restriction of processing in certain circumstances.
- To receive your data in a structured format and port it to another controller.
- To object to processing based on legitimate interest.
- To withdraw consent at any time, with no consequence for participation.
- Not to be subject to automated decision-making, including profiling.
Requests go to contact@cypheraks.com. We reply within 30 days; if the request is complex, this period may be extended and we will tell you why. The service is free, except where requests are manifestly unfounded or excessive.
12. The right to complain
If you believe your rights have been breached, you have the right to complain to the Information and Privacy Agency (IPA), the independent supervisory authority established by Law No. 06/L-082, and to seek judicial remedy.
13. Data security
We apply appropriate technical and organisational measures: role-based access limits, individual staff accounts and passwords, regular backups, and locked storage of physical documents such as consent forms.
14. Data breach notification
In the event of a security breach that risks your rights and freedoms, we document the incident, notify the Information and Privacy Agency without undue delay, and inform you where the breach presents a high risk.
15. Changes to this policy
If this policy changes materially, we will notify you by email and update the date at the top of this page. The version in force is always the one published here.