Who Is the Controller
The Platform sherbimekontabiliteti.al is operated by Ronin Holdings LLC, a limited liability company formed in the State of Texas, USA ("Ronin", "we", "us", the "Company"). Ronin is the data controller for the platform and customer relationship — the website, the €30 consultation, monthly retained accounting, the registered-agent service and company formation, and all communication and payment handling that flows through the Platform.
The professional accounting and tax work itself is delivered by Valbona Xhanaj, an Albanian-established certified tax and customs consultant (the "Accountant"). For that professional work — preparing and submitting tax declarations, meeting her own statutory duties and professional retention obligations — the Accountant acts as a separate and independent data controller, on her own lawful bases (legal obligation and legitimate interests) and under her own retention periods. She is not our employee, partner, agent, or processor, and the contractual labels in any agreement cannot change that legal reality (EDPB Guidelines 07/2020, accountants example).
Because Ronin is a foreign controller offering services to people in Albania, Law No. 124/2024 "On the protection of personal data" (Neni 4(1)(b)) applies to us, and we act through a representative in Albania — the Accountant (Valbona Xhanaj), acting in the separate statutory capacity of Ronin's representative in Albania under Law 124/2024 Neni 25 — who is notified to the Commissioner where legally required. This representative capacity does not make her Ronin's agent for the professional accounting work. Where we process the personal data of clients located in the EU, we also appoint an EU representative under Article 27 GDPR where required.
Data We Collect
Depending on how you use the Platform, we collect:
- Contact data — name, email address, phone number and the content of the messages you send us.
- Business data — company name, NIPT/tax identification number, legal form and activity description.
- Identity and KYC documents and source-of-funds information — ID or passport data and supporting documents that anti-money-laundering law requires us to collect.
- Powers of attorney (PoA) — signed and, where applicable, notarised authorisations enabling representation.
- Financial and tax records — invoices, ledgers, declarations and other accounting documents you provide or that are prepared for you.
- Registered-agent mail — physical correspondence received at your registered address, scanned and logged for you.
- Payment metadata — the amount, currency, reference and status of a payment (card details are handled directly by our payment processor; we do not store full card numbers).
- Technical and IP data — IP address, browser and device information, and log data generated when you use the site.
Data Obtained Indirectly / Sources
Some of the personal data we process is not about you as the website user but about other individuals — beneficial owners, directors, shareholders, employees, counterparties, and third parties named in registered-agent mail and in the documents a business customer uploads to us. We receive this data indirectly: from our business customer who provides it, and from public registries such as the QKB (National Business Center). The categories are the same as those listed under "Data We Collect" above (identifying, business, contact and, where relevant, KYC data). We process it on the same legal bases (contract performance for our customer, legal obligation, and legitimate interest). Where Law 124/2024 (~ Article 14 GDPR) requires it, and it does not prove impossible or involve a disproportionate effort, we or our business customer inform those individuals. Any such individual can exercise the same rights set out below by contacting us at info@sherbimekontabiliteti.al.
Legal Bases
We process personal data only where the law allows it, under Law 124/2024 Neni 7 (which mirrors Article 6 GDPR):
- Performance of a contract — to provide the consultation, accounting, registered-agent or formation services you have requested and to manage our relationship with you.
- Compliance with a legal obligation — Ronin and the Accountant are "obliged entities" under Law 9917/2008 ("On the prevention of money laundering and terrorist financing") for the registered-agent, company-formation and accounting services, and keep AML/KYC records for 5 years from the end of the business relationship (Neni 16). Statutory accounting and fiscal retention (10 years, Law 25/2018 "On accounting and financial statements", Neni 8(1)) rests principally on the Accountant as an independent controller who keeps the books; Ronin retains only the copies it holds, to the extent the law requires.
- Legitimate interest — securing the Platform, preventing fraud and abuse, keeping internal records, and communicating with you about a service you are using, always balanced against your rights.
- Consent — for analytics and any marketing cookies, which run only if you accept them and which you can withdraw at any time.
Automated Decision-Making
We use two automated processes on the Platform: (1) automated per-IP abuse-blocking, which can temporarily block access to our API when it detects a pattern of abusive requests; and (2) an automated company-name availability check against the QKB (National Business Center) register when you use the name-check tool. Neither makes, on a solely automated basis, a decision that produces legal effects concerning you or similarly significantly affects you: the abuse-block only restricts automated request traffic and can be reviewed and lifted by a person, and the QKB check merely reports whether a name is free or taken and leads to no automated decision about you. We do not carry out solely-automated decision-making with legal or similarly significant effect within the meaning of Law 124/2024 Neni 21 / Article 22 GDPR. If that ever changed, we would tell you the logic involved and the consequences, and you would have the right to obtain human review, to express your point of view, and to contest the decision.
Sub-Processors and Recipients
We share personal data only with the service providers we rely on to run the Platform, each bound by a data-processing agreement, and with the Accountant. Our main recipients are:
- Cloudflare — website hosting, the D1 database, R2 storage and Browser Rendering.
- Google Workspace — Gmail, Drive, Calendar and Docs for communication and document handling.
- Stripe — card payment processing.
- Wise — bank-transfer processing and reconciliation.
- Resend — transactional and notification email delivery.
- Cloudflare Workers AI / AutoRAG — the "Pyet" assistant that answers general questions on the site.
- Google Analytics 4 and Microsoft Clarity — website analytics, loaded only with your consent.
- The Accountant (Valbona Xhanaj) — who receives the data needed to perform the professional work, as a separate and independent controller.
We do not sell your personal data.
International Transfers
Some of our providers, and Ronin itself, process data in the United States (Cloudflare, Google, Stripe and Ronin). Ronin is not certified under the EU–US Data Privacy Framework and does not rely on it. Where personal data of people in the EU is transferred to the USA, we safeguard it with the EU Standard Contractual Clauses (European Commission Decision 2021/914) supported by a transfer impact assessment.
Information that you choose to send to us directly, on your own initiative, is not a "transfer" within the meaning of Chapter V of the GDPR (EDPB Guidelines 05/2021).
Our representative in the EU, UK and Switzerland
Ronin Holdings, LLC has appointed DataRep (Data Protection Representative Limited, 77 Camden Street Lower, Dublin, D02 XE80, Ireland) as its Data Protection Representative: in the EU/EEA under Article 27 GDPR, in the United Kingdom under Article 27 UK GDPR, and in Switzerland under the Federal Act on Data Protection (FADP).
If you are located in those jurisdictions, you may raise any request or question about your personal data with us through DataRep:
- by email at datarequest@datarep.com, quoting "Sherbime Kontabiliteti / Ronin Holdings, LLC" in the subject line;
- through the online form at www.datarep.com/data-request; or
- by post, to any of DataRep's addresses in the EU/EEA, the UK and Switzerland (the full list is on the form page above). Please note: letters must be addressed to "DataRep" — not "Sherbime Kontabiliteti" — or they may not reach us.
For general questions about our services (not data-rights requests), please write to us directly at info@sherbimekontabiliteti.al.
Retention
We keep personal data only for as long as the law requires or the purpose demands:
- Accounting and tax records — 10 years after the close of the reporting period (Law 25/2018, Neni 8(1)). This duty rests principally on the Accountant as an independent controller who keeps the books; Ronin retains only the copies it holds, to the extent the law requires.
- AML/KYC records — 5 years after the end of the business relationship (Law 9917/2008, Neni 16), which Ronin and the Accountant keep as obliged entities.
- Contact and lead data — until your request or enquiry is resolved, plus a short additional period, unless it becomes part of a record we must retain for one of the reasons above.
- Analytics data — as described in the Cookies section below.
Your Rights and How We Handle Them
Under Law 124/2024 (Nenet 12–20) you have the right to access and obtain a copy of your data, to have inaccurate data rectified, to request erasure, to restrict or object to processing, and to data portability. We respond within the statutory deadline (in principle one month).
We handle erasure requests honestly rather than promising unconditional deletion. When you ask us to erase your data, we separate the data we can erase from the records we are required by law to keep — statutory retention (accounting and AML above) overrides the right to erasure (Law 124/2024; Article 17(3)(b) GDPR). We will erase everything that is not subject to a retention obligation, and for the records we must keep we will refuse erasure with a clear explanation of the lawful basis — while still disclosing those records to you in response to an access request.
To exercise any right, or for any privacy question, email us at info@sherbimekontabiliteti.al; we respond within the statutory deadline. We have not appointed a Data Protection Officer, as we are not required to under Law 124/2024 Neni 33.
Children
The Platform is a professional, business-to-business service and is not directed to children under 18. We do not knowingly collect personal data from children, and we will delete any such data that comes to our attention.
Complaints
If you believe we have processed your data unlawfully, you may lodge a complaint — free of charge — with the Commissioner for the Right to Information and Protection of Personal Data under Law 124/2024 Neni 86:
- Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale
- Rr. Abdi Toptani, Nd. 5, Tiranë, Albania
- info@idp.al · idp.al
If you are located in the EU, you may also complain to the supervisory authority of your country of habitual residence.
Cookies
This site uses technical cookies that are necessary for it to work; these are always set. In addition, we use the following analytics services, but only with your consent:
- Google Analytics 4 (GA4) — measures the number of visitors, the most-visited pages and traffic sources. It sets cookies such as
_gaand_ga_*that last up to 2 years. - Microsoft Clarity — records how visitors interact with the site (clicks, mouse movements) to help us improve usability. It sets cookies such as
_clckand_clsk.
These cookies are set only if you accept the consent banner when you visit the site. If you refuse, no analytics script is loaded and no tracking cookies are set.
You can change your choice at any time by deleting cookie_consent from your browser's localStorage — the banner will appear again.
Contact
For any question about this Privacy Policy or about how your personal data is processed, or to exercise any of your rights, email us at info@sherbimekontabiliteti.al. You may also reach our representative in Albania — the Accountant (Valbona Xhanaj), acting in the separate statutory capacity of Ronin's representative in Albania under Law 124/2024 Neni 25 — where legally required. We will respond within the applicable statutory deadline. We have not appointed a Data Protection Officer, as we are not required to under Law 124/2024 Neni 33.