Effective Date: 19.02.2026
Last Updated: 19.02.2026
1. LEGAL NOTICE AND SCOPE
This Privacy Policy (“Policy”) establishes the principles governing the collection, processing, storage, disclosure, and protection of personal data by Gizharovski Translations (“Controller”, “Company”, “we”, “us”).
This Policy is adopted in accordance with:
- Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)
- Applicable national data protection laws
- ISO/IEC 27001 Information Security standards
- ISO/IEC 27701 Privacy Information Management requirements
This Policy applies to all personal data processed in connection with:
- Our website and digital platforms
- Translation, localization, interpretation, and linguistic services
- Client communications
- Vendor and contractor relationships
2. DATA CONTROLLER IDENTIFICATION
Data Controller:
[Company Name]
Registered Address: [Address]
Email: [Email]
Telephone: [Phone]
Data Protection Officer (if applicable):
Name: [DPO Name]
Email: [DPO Contact]
3. DEFINITIONS
For purposes of this Policy:
- Personal Data: Any information relating to an identifiable natural person.
- Processing: Any operation performed on personal data.
- Data Subject: The individual to whom the personal data relates.
- Processor: A party processing data on behalf of the Controller.
4. CATEGORIES OF PERSONAL DATA PROCESSED
4.1 Identification Data
- Full name
- Employer or company affiliation
- Job title
4.2 Contact Data
- Email address
- Telephone number
- Postal address
4.3 Financial and Transaction Data
- Billing details
- Payment records
- Tax identification data
4.4 Technical and Usage Data
- IP address
- Browser information
- Device identifiers
- Website interaction logs
4.5 Client Content Data
Materials submitted for linguistic services may contain personal data.
Such data is processed solely for contract fulfillment and under strict confidentiality obligations.
5. PURPOSES OF PROCESSING AND LEGAL BASIS
Personal data is processed strictly in accordance with GDPR Article 6.
5.1 Contractual Performance
Processing necessary to:
- Deliver linguistic services
- Manage projects
- Provide client support
- Process payments
5.2 Legal Compliance
Processing required to meet:
- Tax regulations
- Accounting laws
- Regulatory reporting obligations
5.3 Legitimate Interests
Processing conducted for:
- Information security
- Fraud prevention
- Service quality management
- Business continuity
- Legal claims defense
Legitimate interest assessments are performed prior to processing.
5.4 Consent-Based Processing
Processing occurs upon explicit consent for:
- Marketing communications
- Non-essential cookies
- Newsletter distribution
Consent may be withdrawn at any time.
6. PROCESSING OF SPECIAL CATEGORY DATA
We do not intentionally collect special category data.
Where such data is contained within client translation materials:
- Processing is conducted solely under client instruction
- Data minimization principles apply
- Confidentiality safeguards are strictly enforced
7. DATA CONFIDENTIALITY AND PROFESSIONAL SECRECY
All personnel and subcontractors are bound by:
- Contractual confidentiality clauses
- Professional ethics obligations
- Non-disclosure agreements
Access to client materials is restricted based on role necessity.
8. DATA SHARING AND DISCLOSURE
Personal data may be disclosed only to:
8.1 Authorized Personnel
Employees and contractors requiring access for operational duties.
8.2 Data Processors
Including:
- Linguistic subcontractors
- IT infrastructure providers
- Cloud hosting providers
- Payment service providers
All processors operate under GDPR-compliant Data Processing Agreements.
8.3 Legal Authorities
Where disclosure is mandated by law.
No personal data is sold or transferred for commercial profiling purposes.
9. INTERNATIONAL DATA TRANSFERS
Transfers outside the EEA occur only where appropriate safeguards exist:
- Standard Contractual Clauses
- Adequacy decisions
- Certified privacy frameworks
Risk assessments are conducted prior to transfer.
10. DATA RETENTION POLICY
Personal data is retained only as long as necessary for lawful purposes.
Typical retention periods:
- Financial records: up to 10 years
- Client account data: duration of relationship + statutory period
- Project files: retained for operational necessity unless deletion requested
- Marketing data: until consent withdrawal
Secure deletion procedures are implemented.
11. INFORMATION SECURITY MEASURES
The Company maintains an Information Security Management System aligned with ISO standards.
Security controls include:
- Encryption protocols
- Secure file transfer systems
- Access control mechanisms
- Multi-factor authentication
- Network security monitoring
- Data backup and recovery systems
- Incident response procedures
- Periodic security audits
12. DATA SUBJECT RIGHTS
Data subjects have rights under GDPR Articles 12–23:
- Right of access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability
- Right to object
- Right to withdraw consent
Requests must be submitted in writing.
Responses are provided within statutory deadlines.
13. DATA BREACH MANAGEMENT
In the event of a personal data breach:
- Risk assessments are conducted immediately
- Supervisory authorities are notified within 72 hours where required
- Affected individuals are informed where risks are high
14. COMPLAINTS AND SUPERVISORY AUTHORITY
Data subjects may file complaints with their national data protection authority.
15. COOKIE POLICY
15.1 Use of Cookies
Our website uses cookies and similar technologies to ensure secure and efficient functionality.
Cookies are small data files stored on user devices.
15.2 Types of Cookies Used
Strictly Necessary Cookies
Required for:
- Website security
- Session management
- Authentication
These cannot be disabled.
Functional Cookies
Enable:
- Language preferences
- User interface customization
Analytical Cookies
Used to collect anonymized usage statistics.
Marketing Cookies
Used only with explicit consent to track user behavior for marketing purposes.
15.3 Legal Basis for Cookie Use
- Necessary cookies: Legitimate interest
- Non-essential cookies: Explicit consent
15.4 Cookie Consent Management
Users may:
- Accept or reject cookies via consent banner
- Modify preferences at any time
- Delete cookies through browser settings
15.5 Third-Party Cookies
Some cookies may be placed by third-party service providers such as analytics platforms.
These providers operate under their own privacy policies.
16. AUTOMATED DECISION-MAKING
We do not engage in automated decision-making or profiling that produces legal effects.
17. CHILDREN’S DATA
Services are not directed toward individuals under 16 years of age.
18. POLICY UPDATES
This Policy may be updated periodically to reflect regulatory or operational changes.
Updated versions will be published on our website.
19. CONTACT INFORMATION
For privacy inquiries:
Gizharovski Translations
Email: info@gizharovskitranslations.com
Address: Pandil Siskov 29, Skopje, R.N. Macedonia