The short version
- We only collect what we need to reply to you, work with you and send you invoices.
- We don't sell personal data, and we don't use advertising or tracking cookies.
- Analytics only runs if you allow it. You can change your mind at any time.
- You can ask for a copy of your data, or ask us to correct or delete it, whenever you like.
Who we are
The controller of your personal data is [LEGAL NAME], [REGISTERED ADDRESS], North Macedonia, company registration number (EMBS) [EMBS], tax number (EDB) [EDB] ("CodeFellas", "we", "us").
We are a small studio run by Andrej and Matej. We have not appointed a data protection officer. For anything about your data, write to [email protected] and one of us will answer personally.
This policy is written to meet the Law on Personal Data Protection of North Macedonia (Official Gazette Nos. 42/20, 294/21 and 101/25) and, where they apply to you, the EU General Data Protection Regulation (GDPR) and the UK GDPR.
What we collect and why
| When | What we collect | Why | Legal basis | How long we keep it |
|---|---|---|---|---|
| You contact us or send an offer from our website | Name, email, phone number, what your business needs, your message, and the options you picked in the offer builder | To reply to you and prepare a quote | Steps you ask us to take before a contract | 12 months after our last contact, if we don't end up working together |
| You become a client | Contact details, company name, address, tax number, invoices, project messages and the files you send us | To deliver the work, invoice you and keep proper records | Our contract with you, and our legal duties under tax and accounting law | During our work together. After that, invoices and accounting records for as long as tax and accounting law requires, and project messages and files until the time limit for legal claims has passed |
| You sign up for our emails | Email address, name if you give it, and a record of when and how you agreed | To send you occasional tips and offers | Your consent | Until you unsubscribe. We then keep only your email address on a "do not contact" list, so we never email you by mistake |
| You make a data request | The details in your request and our reply | To handle your request and show that we did | Our legal duty to respond | 3 years |
| You visit our website | Technical data such as IP address, browser type and time of visit, handled by our hosting provider | To deliver the site and protect it from attacks | Our legitimate interest in a working, secure website | A short period set by the hosting provider, usually days. We don't use it to identify you |
| You open our prices page | The country your connection comes from, worked out from your IP address by Cloudflare as the page loads | To show you the right set of prices (local or international) | Our legitimate interest in showing correct prices | We don't save it. It is used only while the page loads |
| You allow analytics | Pseudonymous usage data: pages viewed, approximate location (city level), device type | To see which pages help visitors | Your consent | 14 months |
| You leave us a review | Your name or first name as you choose to show it, your business name if given, and your review | To show genuine feedback from real clients | Your consent | Until you ask us to remove it |
Why we ask for a phone number. Many clients prefer a short call to talk through a project. We only use your number for that, and never for sales calls you didn't ask for.
Please don't send sensitive data. We don't need health, religious, political or similar information to build a website, so please leave it out of messages and files.
What we don't do
- We don't sell or rent personal data.
- We don't use advertising cookies, social media pixels or cross-site tracking.
- We don't make decisions about you by automated means, and we don't build profiles of you.
- We don't send marketing emails without your consent.
Websites we build and host for clients
When we build, host or maintain a website for a client, the personal data collected on that website belongs to the client. For that data, the client is the controller and we act only as their processor, following their instructions and our data processing terms (see our Terms of Service). If you want to use your rights about data on one of our clients' websites, please contact that business. If you contact us instead, we will pass your request to them without delay.
Transfers between countries
Some of our providers store data outside North Macedonia, including in the United States. We only use providers that protect personal data with safeguards recognised by the Law on Personal Data Protection and the GDPR, such as an adequacy decision or standard contractual clauses.
If you are in the EU, EEA, UK or Switzerland, your data comes to us in North Macedonia, which does not currently have an adequacy decision from the European Commission or the UK. Data you give us directly, for example through our forms or by email, is transferred because you ask us to reply or to work with you. Data that clients send us is protected by the European Commission's Standard Contractual Clauses and, for UK data, the UK Addendum.
You can ask us for a copy of the relevant safeguards.
How we protect your data
We use encrypted connections (HTTPS) everywhere, two-factor authentication on accounts that hold client data, and access limited to the two of us. Backups are encrypted and kept for 30 days. No system is perfectly secure, but if a breach ever affects your data, we will tell you and the authorities as the law requires.
Your rights
You have the right to:
- Access your data and get a copy of it
- Correct data that is wrong or incomplete
- Delete your data, where we no longer need it or have no legal reason to keep it
- Restrict how we use your data while a question is being resolved
- Object to processing based on our legitimate interests
- Take your data with you in a common electronic format (data portability)
- Withdraw your consent at any time, for example by unsubscribing or changing your cookie settings. This does not affect what we did before you withdrew it.
To use any of these rights, fill in our data request form or email [email protected]. It's free. We will answer within one month. If a request is complex, we may need up to two more months, and we'll tell you why within the first month. To protect your data, we may ask you to confirm your identity before we act.
Complaints. If you're unhappy with how we handle your data, please tell us first so we can fix it. You also have the right to complain to the Agency for Personal Data Protection of North Macedonia (azlp.mk), or to the data protection authority in the country where you live or work. In the UK, that is the Information Commissioner's Office (ico.org.uk).
If you are in the United States. We don't sell or share personal information, as those terms are defined in US state privacy laws, and we don't use it for targeted advertising. You can use the rights in this section wherever you live.
Age
Our website and services are meant for adults. You must be 18 or older to use our forms, sign up for our emails or work with us. We don't knowingly collect personal data from anyone under 18. If you believe a child has sent us their data, please contact us and we will delete it.
Changes to this policy
We'll update this policy when our services or the law change, and we'll change the date at the top. If a change affects how we use client data in a significant way, we'll email our clients before it takes effect.
Contact
[LEGAL NAME], [REGISTERED ADDRESS], North Macedonia
Email: [email protected] · Phone: [PHONE]