This policy explains how HAXNA DOOEL collects, uses, and protects your personal data. We are committed to full compliance with the General Data Protection Regulation (GDPR) and applicable Macedonian data protection law.
HAXNA DOOEL is a technology company registered in the Republic of Macedonia. We provide IT services, software development, IT consulting, infrastructure solutions, and project outsourcing to businesses across Macedonia and the European Union.
For the purposes of GDPR, HAXNA DOOEL acts as the data controller for personal data collected through our website (haxna.com) and in the course of providing our services.
| Detail | Information |
|---|---|
| Company Name | HAXNA DOOEL |
| Registered Country | Republic of Macedonia |
| Website | haxna.com |
| Privacy Contact | contact@haxna.com |
We collect only the data we need to provide our services and communicate with you. We do not collect sensitive personal data and we do not sell your data under any circumstances.
Messages submitted through our contact form are delivered directly to us by email and are not stored in any website database.
| Category | Data Points | How Collected |
|---|---|---|
| Contact Data | Full name, email address, company name, phone (if provided) | Contact form on haxna.com |
| Message Content | Project description, enquiry details, any information you include in your message | Contact form submission |
| Contract Data | Name, company, address, VAT number, billing details | During onboarding as a client |
| Technical Data | IP address, browser type, device type, pages visited, time on page, geographic region | Automatically via Google Analytics 4 |
| Communication Data | Email correspondence, meeting notes | Direct communication with HAXNA |
Under GDPR, we must have a lawful basis for every type of data processing we carry out. Below is a clear explanation of each purpose and its legal basis.
| Purpose | Legal Basis | Details |
|---|---|---|
| Responding to enquiries | Legitimate Interest (Art. 6(1)(f)) | When you contact us, we use your data to respond. You expect this when you submit a form. |
| Providing contracted services | Contract Performance (Art. 6(1)(b)) | Once you become a client, we process your data to deliver the agreed services. |
| Invoicing & accounting | Legal Obligation (Art. 6(1)(c)) | Macedonian law requires us to retain financial records for a minimum of 5 years. |
| Website analytics | Consent (Art. 6(1)(a)) | We use Google Analytics 4 only after you accept cookies via our cookie banner. |
| Security & fraud prevention | Legitimate Interest (Art. 6(1)(f)) | We process technical data to protect our systems and detect abuse. |
We use cookies and similar technologies to understand how visitors use our website. You will be asked for your consent before any non-essential cookies are placed on your device.
Cookie consent is required. We do not place analytics or tracking cookies until you actively accept them via our cookie banner. You can withdraw consent at any time by clearing your browser cookies and declining on your next visit.
| Cookie / Tool | Type | Purpose | Retention |
|---|---|---|---|
| Essential cookies | Strictly necessary | Theme preference (dark/light mode). No consent required. | Session / 1 year |
| Google Analytics 4 | Analytics | Page views, session duration, geographic region, device type, traffic sources. IP addresses are not stored. | 14 months |
Google Analytics 4 does not log or store IP addresses. Your IP is used only momentarily to derive an approximate geographic region and is then discarded — it is never retained by us or by Google. We do not use Google Analytics advertising features, Google Signals, or cross-site tracking.
We never sell your data. We never share your data with third parties for their own marketing purposes. The following parties may access your data only where strictly necessary to deliver our services.
| Recipient | Role | Why | Location |
|---|---|---|---|
| Our Accountant | Data Processor | Legal obligation — financial records, invoicing, tax compliance | Macedonia |
| Google LLC | Data Processor | Google Analytics 4 (website analytics only) | USA (SCCs apply) |
| Hosting Provider | Data Processor | Website hosting and infrastructure | EU / to be confirmed |
| Legal Authorities | — | Only where required by law or court order | Macedonia |
SCCs = Standard Contractual Clauses approved by the European Commission for transfers outside the EU/EEA.
We keep your data only as long as necessary for the purpose it was collected, or as required by law.
| Data Type | Retention Period | Reason |
|---|---|---|
| Contact form enquiries (no contract) | 12 months | Held only as an email record (not in a database). Sufficient time to follow up on leads; deleted after if no relationship develops. |
| Client contract data | 5 years after contract end | Required by Macedonian accounting and tax law. |
| Email correspondence | 3 years | For reference and dispute resolution purposes. |
| Google Analytics data | 14 months | Google Analytics default retention period. Automatically deleted after this period. |
| Invoices and financial records | 5 years minimum | Mandatory under Macedonian Law on Accounting. |
Some of our service providers are based outside the European Economic Area (EEA), including in the United States. When we transfer data to countries that do not have an adequacy decision from the European Commission, we rely on Standard Contractual Clauses (SCCs) as the legal mechanism to ensure your data remains protected to the same standard as within the EU.
Specifically, data processed by Google LLC (Google Analytics 4) is covered by Google's Data Processing Terms which incorporate SCCs. Transfers to other US-based processors are handled equivalently.
If you are located in the EU/EEA or are otherwise covered by GDPR, you have the following rights regarding your personal data. You can exercise any of these rights by contacting us at contact@haxna.com. We will respond within 30 days.
We will never charge a fee for exercising your rights unless the request is manifestly unfounded or excessive. In such cases we may charge a reasonable fee or refuse the request, with explanation.
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, accidental loss, destruction, or alteration. These measures include:
— HTTPS encryption on all website pages and data transmissions
— Access controls limiting who within HAXNA can access personal data
— Secure email via our self-hosted mail server (mail.haxna.com) using TLS/StartTLS encryption
— Regular review of data handling practices and third-party processors
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR Article 33 and 34.
Our website and services are directed exclusively at businesses and professionals. We do not knowingly collect personal data from individuals under the age of 16. If we become aware that we have inadvertently collected data from a child, we will delete it promptly. Please contact us at contact@haxna.com if you believe this has occurred.
We may update this privacy policy from time to time to reflect changes in our practices, services, or legal requirements. When we make material changes, we will update the "Last Updated" date at the top of this page. We encourage you to review this policy periodically.
Continued use of our website or services after changes are posted constitutes your acceptance of the updated policy. If you disagree with any changes, please contact us or discontinue use of our services.
For any questions, requests, or complaints regarding this privacy policy or our data handling practices, please contact us using the details below. We aim to respond to all privacy requests within 30 days.
This privacy policy was prepared for HAXNA DOOEL and reflects the company's data practices as of the effective date above. This document is provided for informational purposes. HAXNA recommends periodic review by a qualified legal professional to ensure continued compliance with evolving data protection regulations.