Privacy policy
What we collect, why we have it, how long we keep it, and what you can ask us to do about it. Written to be read rather than to be technically survivable.
Enterprise Protection Group, trading as EPG Reputation, registration number 812370609, Ukshin Hoti 1, 10000 Prishtinë, Kosovo. We are the controller of the personal data described here. For any privacy question, write to contact@epgreputation.com and we'll respond within 30 days.
The site has no contact form, no account system, no advertising, no analytics, and no tracking cookies. We do not set any cookies of our own and we do not build a profile of visitors.
Two things are worth disclosing rather than glossing over:
When you email us we receive whatever you send: your name, email address, business name, the content of your message, and anything you attach. Email is handled through Zoho Mail.
We use this to answer you and, if you go ahead, to run your case. We keep enquiry correspondence for 24 months from the last message, then delete it. If you'd like it deleted sooner, say so and we'll do it.
We do some business-to-business outreach by email. If you received an unsolicited message from us, this section is the one that concerns you.
We hold a limited record: a business name, a business email address, a contact name and job title where published, a website, and a location. This comes from publicly available business sources and commercial business directories. We do not buy consumer data and we do not hold anything about you as a private individual.
Our basis for this is legitimate interest — contacting businesses about a service relevant to their trade. You can object at any time. Reply with "remove" or email contact@epgreputation.com and we will suppress the address permanently. Suppression means we keep the address on a do-not-contact list precisely so we don't contact you again; that is the only purpose it is retained for.
This is the sensitive part of what we handle, so it gets its own section.
To establish that a reviewer was not a customer, we typically need to see business records: booking systems, invoices, appointment books, staff rosters, employment dates, transaction logs. These records may contain personal data about your customers and staff — people who are not parties to our engagement.
Our commitments on that material:
Where you send us records containing other people's personal data, you remain the controller of that data and we act as processor for it. We will follow your written instructions on it and will assist you with any request you receive about it.
Building a case involves examining publicly visible information about a review and the account that posted it: the review text, the posting date, the account's public review history, and publicly displayed profile information. All of this is visible to anyone using Google Maps.
We do not attempt to identify reviewers beyond what the platform displays, we do not contact them, and we do not compile dossiers on individuals. The material goes into the submission to Google and is deleted with the case file.
We use a small number of service providers. We do not sell data to anyone.
| Provider | Purpose | Location |
|---|---|---|
| Zoho | EU | |
| Netlify | Website hosting | US |
| Case submissions; web fonts | US |
Case submissions necessarily go to Google, since that is the point of the service. We also disclose data where we are legally required to. Nothing else leaves us.
We are established in Kosovo and process data for clients in Kosovo, the European Union, and the United States. Where personal data of individuals in the EU or the UK is transferred outside those areas, we rely on the appropriate safeguards available under the applicable law, including standard contractual clauses with our providers where required.
Depending on where you are, you may have some or all of the following rights. We apply them to everyone who asks, regardless of location, because operating two standards is more trouble than it's worth.
Email contact@epgreputation.com. There is no charge and we'll respond within 30 days. If you are in the EU or UK and are unhappy with our response, you can complain to your national data protection authority. In Kosovo, that is the Information and Privacy Agency.
| What | How long |
|---|---|
| Enquiry correspondence | 24 months from last contact |
| Case files and client records | 90 days after case closes, or 12 months if you ask us to hold for re-filing |
| Invoices and accounting records | As required by Kosovo tax law |
| Outreach contact records | Until objection, then moved to suppression |
| Suppression list | Indefinitely, so we don't contact you again |
Accounts are protected with two-factor authentication and access to case material is limited to the people working on the case. We don't hold payment card details — payments are handled by our bank or payment provider, not by us. No arrangement is perfect, and if a breach occurs that affects you we will tell you and the relevant authority within the timeframes the law requires.
This is a business service. We do not knowingly collect data about anyone under 18. If you believe we have, tell us and we will delete it.
If this policy changes materially we will update the version and date above. For an active client, we'll email you rather than rely on you noticing.
Privacy questions, access requests, and removal requests all go to the same place: contact@epgreputation.com.