Data protection
Privacy Policy
This policy explains in clear terms which personal data VleraPro processes, why it is processed, the applicable legal bases, and your rights.
Version: 15 August 2026
Data controller
BISSOLUX LLC
30 N Gould StSheridan, WY 82801-6317
United States
Limited Liability Company under the laws of the State of Wyoming
Alban Berisha
info@bissolux.comEU representative pursuant to Article 27 GDPR
Alban Berisha
Berliner Straße 10453757 Sankt Augustin
Germanyinfo@bissolux.com
For privacy requests, email info@bissolux.com with the subject “Privacy”. You may also contact the EU representative.
1. Scope and legal bases
This policy covers the public website, accounts, business profiles, requests, offers, chats, reviews, and the VleraPro dashboard. Depending on the purpose, processing relies on Article 6(1)(b) GDPR for a contract or pre-contractual steps, Article 6(1)(c) for legal duties, Article 6(1)(f) for legitimate interests, or Article 6(1)(a) for consent. Legitimate interests include secure operation, abuse prevention, matching requests, and providing a useful business directory.
2. Visits, technical logs, and security
When the website is accessed, technically necessary data such as IP address, time, requested path, user agent, response status, and security signals is processed. We use it to deliver and diagnose the site, apply rate limits, prevent fraud, and protect systems. The bases are providing the requested service and our legitimate interest in secure operation.
3. Account, authentication, and communication
For registration and sign-in we process first and last name, email, optional phone, account type, role, acceptance of terms, verification status, hashed password, and hashed session, invitation, verification, or reset tokens. Businesses and agencies may start with email only; personal details and a password are requested only after the secure link is opened. Verification, invitation, password recovery, and important service messages are sent through Microsoft Graph / Microsoft 365. Passwords are not emailed or stored as readable text.
4. Provider profiles and business directory
Profiles may include the business name, contact person, descriptions and taglines in selected languages, categories and subcategories, service areas, business address, website, phone, email, legal form, employee count, founding year, supplied registration or tax numbers, logo, and work photographs. Fields marked public appear on profile and search pages.
- One account may manage several profiles, and a profile may grant access to authorised owners, managers, or agencies. We record roles, permissions, invitations, and the history of grants, revocations, and ownership transfers.
- Bissolux may create or maintain a profile in the business’s interest without presenting itself as owner; ownership can be transferred by email or user ID without changing the profile or review history.
- Unclaimed listings may come from identified public or licensed sources. OpenStreetMap records show the exact source object, contributor attribution, and ODbL licence.
- Under Article 14 GDPR, third-party source data mainly consists of public identification, contact, location, and service information. A business may request correction, object, request erasure, or claim management of its profile.
- We may use a published business contact to send an individual, non-automated notice about its listing, material review activity, correction options, or the claim process. The business may object to further outreach at any time.
5. Requests, offers, contact, and chat
When a client posts a request, we process its title, description, category, city, budget, timing, and up to five photographs. Phone numbers, emails, websites, addresses, and social-media identifiers are removed server-side from free text before storage; the same filter applies to offers before the chat is activated. Sending an offer is free; after acceptance, one credit is charged to the provider only when the client replies for the first time, once per request and provider. Archived requests leave active results, while necessary job history may remain for evidence, chat, and review.
6. Photographs and files
Logos and profile, work, request, and review photographs are compressed and may be converted to WebP; technical metadata such as EXIF is removed where possible. Files are stored in Hetzner Object Storage in a dedicated VleraPro area. Non-public request photographs are delivered only to authorised parties in the platform flow. Do not upload identity documents, sensitive data, or people who have not given permission.
7. Reviews, reports, and moderation
For reviews we process the rating, title, text, photographs, the public company response, job link, and verification status. A customer may use a business review link or QR without an account, including when the public profile has not yet been claimed by the business; the email is used for confirmation, one-review-per-business enforcement, and security, is never public, and is removed from the review after confirmation while only a keyed hash remains. When management is claimed or ownership transfers, confirmed review history remains attached to the same profile without giving the business a right to remove criticism. Completed VleraPro-job reviews are labelled separately and carry stronger ranking weight. Reports include reasons, evidence, and moderation decisions.
8. Profile statistics and ranking
Providers may see profile views, request and website clicks, phone and email reveals, unlocked leads, accepted offers, and completed jobs. Public profile contacts are returned by the backend only after a visitor clicks; security signals and IP-based rate limits are processed for this purpose. The owner's activity is excluded and the same visitor/action is counted once per day. We currently use no third-party marketing cookies or analytics tools. Sponsored placements are labelled.
9. Providers, hosting, and recipients
Data is disclosed only on a need-to-know basis: Hetzner for infrastructure and media objects, Microsoft for transactional email, and advisers or authorities where legally required. PostgreSQL stores application data, while Redis supports security and rate limits in the service's private network. Google Maps opens only when a user activates an external link; it is not automatically embedded. The Inter font is served locally by the application. We currently do not request card data for functions supplied without charge; if payments are enabled, the payment provider, relevant data, legal basis, and retention details will be identified before use.
10. International transfers
The controller is established in the United States and the service is directed to users in Kosovo, Albania, North Macedonia, and Europe. Where an international transfer requires safeguards, we use an adequacy decision, standard contractual clauses, or another permitted mechanism and supplementary technical measures as appropriate. Details of a transfer mechanism can be requested by email.
11. Retention
Account data and active content are retained while the account is used and afterwards only as needed for deletion, security, evidence, claims, or legal duties. A standard session may last up to 30 days; email verification links up to 24 hours and password reset links up to 1 hour. A readable email address on an unconfirmed review is removed no later than 48 hours after its last activity and is removed immediately on confirmation. Technical logs and rate-limit data are retained for short periods according to security needs.
- Following a valid erasure request, content is removed from active use without undue delay.
- Copies in backups or immutable retention storage may remain inaccessible until the configured period expires, after which they are deleted or overwritten unless legal preservation is required.
- Reported content may be kept longer only as necessary to investigate, defend claims, or meet legal duties.
12. Your rights
We may request reasonable information to verify a request. Rights are not absolute; if a request is lawfully limited, we will explain why.
- Access to and a copy of your data
- Correction of inaccurate data
- Erasure or restriction where statutory conditions are met
- Data portability where applicable
- Objection to processing based on legitimate interests
- Withdrawal of consent for the future
- Complaint to a competent data protection authority
13. Required data, children, and automation
Fields marked required are needed for the relevant function; without them an account, request, or offer may not be possible. The platform is not directed at children, and accounts must be used by persons aged at least 18 or authorised business representatives. We do not make automated decisions with legal or similarly significant effects under Article 22 GDPR.
14. Changes to this policy
We update this policy when features, providers, retention practices, or legal requirements change. The current version and date are published here. Material changes may also be announced in the platform or by email.