Elbasan, Republic of Albania info@invicta.al +355 69 221 1677

Privacy Policy

Last updated: January 2025

Invicta — Assurance International ("Invicta", "we", "us") is an independent ISO certification body registered in the Republic of Albania. This Privacy Policy explains how we collect, use, and protect personal information when you use our website (www.invicta.al) and its associated forms. We are committed to handling personal data responsibly and in accordance with applicable data protection legislation.

1. Who We Are

Data Controller: Invicta Assurance International
Address: Lagjia Skënderbeu, Italdruri/AFZE, 3004 Elbasan, Republic of Albania
Email: info@invicta.al
Telephone: +355 69 221 1677

Invicta operates as an ISO management system certification body in conformance with ISO/IEC 17021-1. Confidentiality and the protection of personal data are integral to our operating principles.

2. What Personal Data We Collect

We collect personal data only when you actively submit it to us through our website forms. The data we collect depends on which form you use:

Certification Enquiry Form (contact.html)

First name, last name, organisation name, email address, telephone number (optional), selected ISO standard of interest, number of employees (optional), and message text.

Certificate Verification Form (verify.html)

Full name, email address, organisation name, name of the certificate holder being queried, ISO standard, certificate number (optional), and additional notes.

We do not use cookies for tracking, do not deploy analytics scripts, and do not collect any data through passive tracking mechanisms. We do not collect sensitive personal data.

3. How We Use Your Personal Data

We use the personal data you submit for the following purposes:

  • To respond to certification enquiries and prepare quotations
  • To process and respond to certificate verification requests
  • To communicate with you regarding your enquiry or request
  • To maintain records of interactions as required by our operational procedures under ISO/IEC 17021-1

We do not use your personal data for marketing purposes without explicit consent, and we do not sell, rent, or share your data with third parties for commercial purposes.

4. Legal Basis for Processing

We process personal data on the following legal bases:

  • Legitimate interests — responding to your direct enquiry about our certification services
  • Consent — for certificate verification requests, where you actively confirm acceptance of this policy before submitting
  • Legal obligation — maintaining records as required by applicable regulations and our ISO/IEC 17021-1 certification body obligations

5. Data Retention

We retain personal data for no longer than is necessary for the purpose for which it was collected:

  • General enquiries that do not result in a certification engagement are retained for 12 months and then securely deleted.
  • Certificate verification requests are retained for 24 months as part of our audit trail obligations.
  • Data relating to active certification clients is retained for the duration of the certification relationship and for 5 years thereafter, in accordance with ISO/IEC 17021-1 record-keeping requirements.

6. Data Security

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure. Form submissions from our website are transmitted via encrypted connections (HTTPS) and processed through Formspree, a GDPR-compliant form processing service. Internal communications containing personal data are handled within secured systems with access restricted to authorised personnel only. Our confidentiality obligations under ISO/IEC 17021-1 are operationalised through documented policies binding on all staff and contractors.

7. Third-Party Services

We use the following third-party service to receive form submissions from our website:

Formspree (formspree.io)

Used to receive and forward website form submissions to our email inbox. Formspree processes form data on servers within the European Economic Area and operates in conformance with GDPR. We do not use Formspree for any purpose other than receiving enquiries submitted through our website contact and verification forms.

We do not embed social media widgets, advertising scripts, or third-party analytics on this website. No personal data is transmitted to social media platforms or advertising networks as a result of visiting our website.

8. Your Rights

Under applicable data protection legislation, you have the following rights in relation to personal data we hold about you:

  • Right of access — to request a copy of the personal data we hold about you
  • Right to rectification — to request correction of inaccurate personal data
  • Right to erasure — to request deletion of your personal data, subject to our legal retention obligations
  • Right to object — to object to processing of your data based on legitimate interests
  • Right to withdraw consent — where processing is based on consent, to withdraw it at any time without affecting the lawfulness of prior processing

To exercise any of these rights, please contact us at info@invicta.al. We will respond within 30 days. You also have the right to lodge a complaint with the relevant supervisory authority in Albania.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable legislation. The date of the most recent revision is shown at the top of this page. We encourage you to review this policy periodically. Continued use of our website after changes are posted constitutes acceptance of the updated policy.

10. Contact

For any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal data, please contact us:

Invicta — Assurance International Lagjia Skënderbeu, Italdruri/AFZE, 3004 Elbasan, Albania
info@invicta.al  ·  +355 69 221 1677