Under the EU General Data Protection Regulation (GDPR) and the Law on Personal Data Protection of the Republic of North Macedonia, you have seven rights over your personal data. Choose the right you want to exercise below, complete the dedicated form, and we'll verify your identity and respond within 30 calendar days. For complex requests we may extend by up to two further months, in which case we'll tell you why within the original 30 days.
Data subject requests.
Exercise your seven GDPR rights — access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Submit a request and we respond within 30 days.
Choose the right you'd like to exercise.
Each link below opens a dedicated form.
Right of access
Get a copy of the personal data we hold about you, why we process it, who we share it with, and how long we keep it.
Right to rectification
Correct inaccurate personal data or complete data that is incomplete.
Right to erasure ("right to be forgotten")
Ask us to delete personal data we hold about you when it is no longer needed or you withdraw consent.
Right to restriction of processing
Limit how we process your data — useful while you contest its accuracy or our lawful basis.
Right to data portability
Receive your personal data in a structured, machine-readable format and transmit it to another controller.
Right to object
Object to processing based on legitimate interests or for direct marketing.
Right to withdraw consent
Withdraw consent at any time when processing relies on it. Past processing remains lawful.
Response timeline
We acknowledge every request within 5 business days and respond substantively within 30 calendar days. For requests that are particularly complex or numerous, we may extend by up to two additional months and will explain why within the original 30 days. There is no fee for a request unless it is manifestly unfounded or excessive.
Identity verification
We must verify your identity before acting on a request — this protects your data from anyone else trying to access it in your name. We'll only ask for information that lets us match the request to a person in our systems, and we never use that information for any other purpose. For irreversible actions such as erasure, we may ask for slightly stronger proof.
When we may refuse or delay
In limited cases we may refuse or delay a request — for example where granting it would adversely affect the rights and freedoms of others, where we are required by law to retain the data, or where a request is manifestly unfounded or excessive. If we refuse, we always explain why and tell you how to complain to the supervisory authority.
Complaints
If you're unhappy with how we handle your request, you can lodge a complaint with a data-protection supervisory authority. In North Macedonia this is the Agency for Personal Data Protection (Агенција за заштита на личните податоци — AZLP, www.azlp.mk). If you are in the EU/EEA, you may also complain to the supervisory authority in your country of residence or work.