EPG Reputation contact@epgreputation.com

Privacy policy

Privacy policy

What we collect, why we have it, how long we keep it, and what you can ask us to do about it. Written to be read rather than to be technically survivable.

Version 1.0 · Effective February 2026

1. Who we are

Enterprise Protection Group, trading as EPG Reputation, registration number 812370609, Ukshin Hoti 1, 10000 Prishtinë, Kosovo. We are the controller of the personal data described here. For any privacy question, write to contact@epgreputation.com and we'll respond within 30 days.

2. This website

The site has no contact form, no account system, no advertising, no analytics, and no tracking cookies. We do not set any cookies of our own and we do not build a profile of visitors.

Two things are worth disclosing rather than glossing over:

  • Fonts. Typefaces are loaded from Google Fonts. Your browser connects to Google's servers to fetch them, which means Google receives your IP address and basic request information. We receive nothing from this and have no access to it.
  • Hosting. The site is hosted by Netlify, which keeps standard server logs including IP addresses for security and operational purposes. We do not use these logs for analytics.

3. If you contact us

When you email us we receive whatever you send: your name, email address, business name, the content of your message, and anything you attach. Email is handled through Zoho Mail.

We use this to answer you and, if you go ahead, to run your case. We keep enquiry correspondence for 24 months from the last message, then delete it. If you'd like it deleted sooner, say so and we'll do it.

4. If we contacted you first

We do some business-to-business outreach by email. If you received an unsolicited message from us, this section is the one that concerns you.

We hold a limited record: a business name, a business email address, a contact name and job title where published, a website, and a location. This comes from publicly available business sources and commercial business directories. We do not buy consumer data and we do not hold anything about you as a private individual.

Our basis for this is legitimate interest — contacting businesses about a service relevant to their trade. You can object at any time. Reply with "remove" or email contact@epgreputation.com and we will suppress the address permanently. Suppression means we keep the address on a do-not-contact list precisely so we don't contact you again; that is the only purpose it is retained for.

5. Case material

This is the sensitive part of what we handle, so it gets its own section.

To establish that a reviewer was not a customer, we typically need to see business records: booking systems, invoices, appointment books, staff rosters, employment dates, transaction logs. These records may contain personal data about your customers and staff — people who are not parties to our engagement.

Our commitments on that material:

  • We ask for the minimum needed to establish the ground. Where a redacted extract or a confirmed absence will do, we ask for that instead of the full record.
  • It is used only to build and submit the case, and for nothing else.
  • It is never sold, shared, reused across clients, or used for marketing.
  • It is not used to train any automated system.
  • It is deleted within 90 days of the case closing, unless you ask us to keep it for a possible re-filing, in which case we hold it for 12 months and then delete it.

Where you send us records containing other people's personal data, you remain the controller of that data and we act as processor for it. We will follow your written instructions on it and will assist you with any request you receive about it.

6. Reviewer information

Building a case involves examining publicly visible information about a review and the account that posted it: the review text, the posting date, the account's public review history, and publicly displayed profile information. All of this is visible to anyone using Google Maps.

We do not attempt to identify reviewers beyond what the platform displays, we do not contact them, and we do not compile dossiers on individuals. The material goes into the submission to Google and is deleted with the case file.

7. Who we share data with

We use a small number of service providers. We do not sell data to anyone.

ProviderPurposeLocation
ZohoEmailEU
NetlifyWebsite hostingUS
GoogleCase submissions; web fontsUS

Case submissions necessarily go to Google, since that is the point of the service. We also disclose data where we are legally required to. Nothing else leaves us.

8. International transfers

We are established in Kosovo and process data for clients in Kosovo, the European Union, and the United States. Where personal data of individuals in the EU or the UK is transferred outside those areas, we rely on the appropriate safeguards available under the applicable law, including standard contractual clauses with our providers where required.

9. Your rights

Depending on where you are, you may have some or all of the following rights. We apply them to everyone who asks, regardless of location, because operating two standards is more trouble than it's worth.

  • Ask what we hold about you and get a copy.
  • Have inaccurate information corrected.
  • Have your data deleted.
  • Object to processing, including outreach.
  • Ask us to restrict processing while a dispute is resolved.
  • Receive your data in a portable format.
  • Withdraw consent where processing relies on it.

Email contact@epgreputation.com. There is no charge and we'll respond within 30 days. If you are in the EU or UK and are unhappy with our response, you can complain to your national data protection authority. In Kosovo, that is the Information and Privacy Agency.

10. Retention, in one place

WhatHow long
Enquiry correspondence24 months from last contact
Case files and client records90 days after case closes, or 12 months if you ask us to hold for re-filing
Invoices and accounting recordsAs required by Kosovo tax law
Outreach contact recordsUntil objection, then moved to suppression
Suppression listIndefinitely, so we don't contact you again

11. Security

Accounts are protected with two-factor authentication and access to case material is limited to the people working on the case. We don't hold payment card details — payments are handled by our bank or payment provider, not by us. No arrangement is perfect, and if a breach occurs that affects you we will tell you and the relevant authority within the timeframes the law requires.

12. Children

This is a business service. We do not knowingly collect data about anyone under 18. If you believe we have, tell us and we will delete it.

13. Changes

If this policy changes materially we will update the version and date above. For an active client, we'll email you rather than rely on you noticing.

Privacy questions, access requests, and removal requests all go to the same place: contact@epgreputation.com.