• Home
  • Services
  • Portfolio
  • About
  • Contact
SQ EN DE
Home Services Portfolio About Contact

Privacy Policy

Last updated: 12 September 2026 Vargu Digital L.L.C. · Pristina, Kosovo

On this page

  1. Who we are
  2. Which law applies to you
  3. What we deliberately do not do
  4. What we actually collect
  5. Who else necessarily sees something
  6. Sending data outside the EEA
  7. When we handle data for a client
  8. Your rights
  9. Our EU representative
  10. How we protect it
  11. Children
  12. Changes to this policy

The short version. This website sets no cookies, runs no analytics, loads no tracking pixels and builds no profiles. We do not sell or share personal data with advertisers, and we never will. What follows explains the small amount of data we do handle, why we handle it, and the rights you have over it.

Who we are

Vargu Digital L.L.C. ("Vargu Digital", "we", "us") is a digital studio registered in the Republic of Kosovo. We build custom business systems, brand identities and websites.

  • Registered name: Vargu Digital L.L.C.
  • Email: legal@vargu.digital
  • Phone: +383 49 481 641

For anything in this policy, write to legal@vargu.digital with "Privacy" in the subject line.

Which law applies to you

Two frameworks apply to us at the same time, and you get the benefit of both.

Kosovo

We are established in Kosovo, so we are bound by Law No. 06/L-082 on the Protection of Personal Data, in force since 13 February 2019. That law transposes the EU General Data Protection Regulation into Kosovo law, so its substance closely mirrors what follows. Our supervisory authority is the Information and Privacy Agency (IPA) of the Republic of Kosovo.

European Union and EEA

Kosovo is not an EU or EEA member state. However, we offer our services to clients and visitors in the EU, so the GDPR (Regulation (EU) 2016/679) applies to that processing directly under Article 3(2)(a). Where this policy refers to a GDPR article, that is the standard we hold ourselves to regardless of where you are.

If you are in the EU or EEA, you keep every right described in this policy and you may complain to your own national supervisory authority as well as to the IPA in Kosovo.

What we deliberately do not do

Most privacy policies bury this. We would rather lead with it. On vargu.digital we do not:

  • set cookies of any kind — not analytics, not advertising, not "functional" ones;
  • run Google Analytics, Meta Pixel, LinkedIn Insight, Hotjar or any comparable product;
  • use device or browser fingerprinting;
  • build profiles, score visitors, or track you across other websites;
  • use advertising networks or retargeting of any kind;
  • sell, rent or trade personal data — to anyone, at any price;
  • make automated decisions with legal or similarly significant effects (GDPR Article 22 does not arise here);
  • add anyone to a mailing list because they emailed or called us.

Because we set no cookies and run no tracking, this site does not need a consent banner under the ePrivacy Directive (2002/58/EC) and you will not see one. We also serve our own fonts from our own servers rather than loading them from a third-party CDN, precisely so that visiting this site does not disclose your IP address to a company you did not choose to deal with.

What we actually collect

Four narrow categories. Each one is listed with the reason we are allowed to process it under GDPR Article 6, and how long we keep it.

DataWhere it comes fromLegal basisKept for
Server logs
IP address, browser user-agent, requested URL, timestamp
Automatically recorded by our hosting provider when any website is served Legitimate interests — Art. 6(1)(f): keeping the site online, diagnosing faults, blocking abuse 14 days
Your message
name, email address, phone number, whatever you choose to tell us
You, when you email or call us Steps before entering a contract — Art. 6(1)(b); otherwise legitimate interests — Art. 6(1)(f): replying to you 24 months from our last exchange, then deleted
Client records
contact details, project files, correspondence, invoices
Our clients, during a project Performance of a contract — Art. 6(1)(b); legal obligation for accounting records — Art. 6(1)(c) Project records: 3 years after the project closes. Invoices and accounting records: 10 years, as required by Kosovo tax and accounting law
Data inside systems we build or host
whatever our client's own system contains
Our client and their users — not from us We are a processor here, not the controller. Our client decides. See section 7. As instructed by the client

We have weighed our legitimate interests against your rights and freedoms as Article 6(1)(f) requires. Server logs are the minimum needed to run a website securely, are not combined with anything else, are never used to identify you personally, and are not used for marketing. You can object to this processing at any time — see your rights.

Who else necessarily sees something

We keep this list as short as we can. These are the only third parties involved in running this website, and none of them are advertising companies.

ProviderWhat they doWhat they see
Hostinger
Frankfurt, Germany (EU)
Web hosting, backups and the VPS this site runs on Server logs, including your IP address, as any web host must
Cloudflare
Zurich, Switzerland
Domain registration, DNS, content delivery and security Your IP address and the request, as any network layer in front of a website must
Our own server
Pristina, Kosovo
Application hosting on infrastructure we operate ourselves Server logs, including your IP address
Proton Mail
Switzerland
Email hosting for our contact@ and legal@ addresses The messages you send us, and what you put in them
Supabase
this website only
Holds the case-study text shown on our own Work pages, which your browser requests directly when you open them. We do not use it for client systems or client data — it serves our own portfolio and nothing else. Your IP address and the request, as a technical necessity of serving that content. No identifier of you is stored against it.

Each of these acts as a processor on our written instructions under GDPR Article 28. We do not permit them to use your data for their own purposes. The sub-processors we use when handling data on a client's behalf are listed in Annex III of our Data Processing Agreement. A list of the tools we use internally to run the business is available on request.

We will publish an update to this page before adding any new third party that receives personal data from this website.

Sending data outside the EEA

Where your data physically sits determines what protection applies:

  • Frankfurt, Germany — inside the European Union, so no third-country transfer arises at all.
  • Switzerland — where our network layer (Cloudflare) and our email (Proton Mail) operate. Switzerland has a European Commission adequacy decision, so data may be transferred there under GDPR Article 45 with no extra safeguard needed.
  • Pristina, Kosovo — our own operations and our own server. Kosovo has no adequacy decision, so transfers here rely on Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c), alongside the measures in section 10.

Under Kosovo's Law No. 06/L-082, equivalent rules on international transfers apply, supervised by the Information and Privacy Agency.

When we handle data for a client

When we build, run or host a system for a client, the personal data inside that system belongs to the client's relationship with their own users. In GDPR terms the client is the controller and we are the processor.

In that role we:

  • act only on the client's documented instructions;
  • sign a Data Processing Agreement under GDPR Article 28(3) before processing begins;
  • bind everyone with access to confidentiality;
  • do not engage a sub-processor without the client's prior authorisation;
  • help the client respond to data-subject requests and to security incidents;
  • return or delete the data at the end of the engagement, at the client's choice.

If you are an end user of a system we built for someone else, your request should go to that organisation, not to us. Tell us anyway and we will point you in the right direction.

Your rights

These rights come from GDPR Chapter III and are mirrored in Kosovo's Law No. 06/L-082. They are free to use. We do not charge for them and we do not make them hard.

  • Access (Art. 15) — a copy of the personal data we hold about you.
  • Rectification (Art. 16) — correct anything inaccurate or incomplete.
  • Erasure (Art. 17) — deletion, where we have no overriding reason to keep it.
  • Restriction (Art. 18) — freeze processing while something is disputed.
  • Portability (Art. 20) — receive data you gave us in a machine-readable format.
  • Objection (Art. 21) — object to processing based on legitimate interests. For direct marketing the objection is absolute and we must stop immediately.
  • Withdraw consent (Art. 7(3)) — wherever we relied on consent, withdraw it at any time, without affecting what was lawful before.
  • Complain (Art. 77) — to a supervisory authority, described below.

How to use them

Email legal@vargu.digital. We respond within one month as GDPR Article 12(3) requires. If a request is unusually complex we may extend that by two further months, and we will tell you why within the first month. We may ask for enough information to be confident of who you are — only to stop us handing your data to someone else.

Complaining about us

Tell us first if you can, but you never have to. You may complain directly to:

  • the Information and Privacy Agency of the Republic of Kosovo (aip.rks-gov.net); or
  • if you are in the EU or EEA, the supervisory authority of the country where you live, work, or where you believe the problem happened.

Our EU representative

Because we are established outside the EU but offer services to people in the EU, GDPR Article 27 requires us to designate a representative inside the Union, unless our processing is occasional, low-risk and involves no large-scale special-category or criminal-offence data.

We have not yet designated a representative in the Union, and we are in the process of appointing one. This section will name them, with their address in the EU, as soon as that is in place.

In the meantime, if you are in the EU or EEA you can reach us directly at legal@vargu.digital, and we will handle your request within the timeframes set out in section 8. You may also complain to your own national supervisory authority at any point, whether or not a representative has been appointed.

An EU representative acts as a local point of contact for data subjects and supervisory authorities. Naming one does not transfer our responsibility — we remain accountable for everything in this policy.

How we protect it

Article 32 asks for measures appropriate to the risk. In practice:

  • everything is served over HTTPS, and HTTP requests are redirected to it;
  • access to client systems is individual, password-protected, and limited to people who need it for the work in hand;
  • administrative interfaces are not open to public sign-up;
  • databases enforce row-level access rules rather than relying on the application alone;
  • we keep the amount of personal data we hold deliberately small, which is the most effective security measure there is.

If something goes wrong

If a breach is likely to result in a risk to your rights and freedoms we will notify the competent supervisory authority within 72 hours of becoming aware of it (Art. 33), and where the risk is high we will tell affected people directly and in plain language (Art. 34).

Children

Our services are sold to businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, tell us and we will delete it.

Changes to this policy

When we change this policy we update the date at the top of the page. If a change materially affects your rights we will say so prominently rather than quietly editing the text. Previous versions are available on request.

This policy was last updated on 12 September 2026.

Site

  • Home
  • Services
  • Portfolio
  • About
  • Contact

Legal

  • Privacy Policy
  • Terms & Conditions
  • Acceptable Use
  • DPA
  • Security

Contact

  • contact@vargu.digital
  • +383 49 481 641
© Vargu Digital. All rights reserved.