Data protection

Privacy Policy

This policy explains in clear terms which personal data VleraPro processes, why it is processed, the applicable legal bases, and your rights.

Version: 7 August 2026

Data controller

BISSOLUX LLC

30 N Gould St
Sheridan, WY 82801-6317
United States

Limited Liability Company under the laws of the State of Wyoming

Alban Berisha

info@bissolux.com

EU representative pursuant to Article 27 GDPR

Alban Berisha

Berliner Straße 104
53757 Sankt Augustin
Germany
info@bissolux.com

For privacy requests, email info@bissolux.com with the subject “Privacy”. You may also contact the EU representative.

1. Scope and legal bases

This policy covers the public website, accounts, business profiles, requests, offers, chats, reviews, and the VleraPro dashboard. Depending on the purpose, processing relies on Article 6(1)(b) GDPR for a contract or pre-contractual steps, Article 6(1)(c) for legal duties, Article 6(1)(f) for legitimate interests, or Article 6(1)(a) for consent. Legitimate interests include secure operation, abuse prevention, matching requests, and providing a useful business directory.

2. Visits, technical logs, and security

When the website is accessed, technically necessary data such as IP address, time, requested path, user agent, response status, and security signals is processed. We use it to deliver and diagnose the site, apply rate limits, prevent fraud, and protect systems. The bases are providing the requested service and our legitimate interest in secure operation.

3. Account, authentication, and communication

For registration and sign-in we process name, email, phone when supplied, role, verification status, hashed password, and hashed session, verification, or reset tokens. Verification, password recovery, and important service messages are sent through Microsoft Graph / Microsoft 365. Passwords are not emailed or stored as readable text.

4. Provider profiles and business directory

Profiles may include the business name, contact person, descriptions and taglines in selected languages, categories and subcategories, service areas, business address, website, phone, email, legal form, employee count, founding year, supplied registration or tax numbers, logo, and work photographs. Fields marked public appear on profile and search pages.

  • Profiles created by a business are processed for its relationship with the platform.
  • Unclaimed listings may come from identified public or licensed sources. OpenStreetMap records show the exact source object, contributor attribution, and ODbL licence.
  • Under Article 14 GDPR, third-party source data mainly consists of public identification, contact, location, and service information. A business may request correction, object, request erasure, or claim management of its profile.

5. Requests, offers, contact, and chat

When a client posts a request, we process its title, description, category, city, budget, timing, and up to five photographs. Phone numbers, emails, websites, addresses, and social-media identifiers are removed server-side from free text before storage; the same filter applies to offers before unlocking. After acceptance, the provider may unlock contact and chat with credits under the displayed product model. Archived requests leave active results, while necessary job history may remain for evidence, chat, and review.

6. Photographs and files

Logos and profile, work, request, and review photographs are compressed and may be converted to WebP; technical metadata such as EXIF is removed where possible. Files are stored in Hetzner Object Storage in a dedicated VleraPro area. Non-public request photographs are delivered only to authorised parties in the platform flow. Do not upload identity documents, sensitive data, or people who have not given permission.

7. Reviews, reports, and moderation

For reviews we process the rating, title, text, photographs, job link, and verification status. Reviews connected to completed work may be marked verified. Reports include the reason, evidence, and moderation decisions. Processing supports trust, complaint handling, security, and action against illegal content.

8. Profile statistics and ranking

Providers may see profile views, request and website clicks, phone and email reveals, unlocked leads, accepted offers, and completed jobs. Public profile contacts are returned by the backend only after a visitor clicks; security signals and IP-based rate limits are processed for this purpose. The owner's activity is excluded and the same visitor/action is counted once per day. We currently use no third-party marketing cookies or analytics tools. Sponsored placements are labelled.

9. Providers, hosting, and recipients

Data is disclosed only on a need-to-know basis: Hetzner for infrastructure and media objects, Microsoft for transactional email, and advisers or authorities where legally required. PostgreSQL stores application data, while Redis supports security and rate limits in the service's private network. Google Maps opens only when a user activates an external link; it is not automatically embedded. The Inter font is served locally by the application.

10. International transfers

The controller is established in the United States and the service is directed to users in Kosovo, Albania, North Macedonia, and Europe. Where an international transfer requires safeguards, we use an adequacy decision, standard contractual clauses, or another permitted mechanism and supplementary technical measures as appropriate. Details of a transfer mechanism can be requested by email.

11. Retention

Account data and active content are retained while the account is used and afterwards only as needed for deletion, security, evidence, claims, or legal duties. A standard session may last up to 30 days; email verification links up to 24 hours and password reset links up to 1 hour. Technical logs and rate-limit data are retained for short periods according to security needs.

  • Following a valid erasure request, content is removed from active use without undue delay.
  • Copies in backups or immutable retention storage may remain inaccessible until the configured period expires, after which they are deleted or overwritten unless legal preservation is required.
  • Reported content may be kept longer only as necessary to investigate, defend claims, or meet legal duties.

12. Your rights

We may request reasonable information to verify a request. Rights are not absolute; if a request is lawfully limited, we will explain why.

  • Access to and a copy of your data
  • Correction of inaccurate data
  • Erasure or restriction where statutory conditions are met
  • Data portability where applicable
  • Objection to processing based on legitimate interests
  • Withdrawal of consent for the future
  • Complaint to a competent data protection authority

13. Required data, children, and automation

Fields marked required are needed for the relevant function; without them an account, request, or offer may not be possible. The platform is not directed at children, and accounts must be used by persons aged at least 18 or authorised business representatives. We do not make automated decisions with legal or similarly significant effects under Article 22 GDPR.

14. Changes to this policy

We update this policy when features, providers, retention practices, or legal requirements change. The current version and date are published here. Material changes may also be announced in the platform or by email.