1. Who we are
Saleonix.com is operated by Vortarix LLC, a limited liability company registered with the Kosovo Business Registration Agency (ARBK) under unique identification number 812339986, with its registered address at Rr. “Koqo Flloku” nr. 1, Pejë, Republic of Kosovo (“Saleonix”, “we”, “us”).
We are a commerce platform and merchant of record: businesses sell their products and services through Saleonix, and we process the related payments. This policy explains what personal data we collect, why, and what rights you have. It applies to sellers who use our platform, to buyers who pay at a Saleonix checkout, and to visitors of our website.
For privacy matters, contact us at info@saleonix.com.
2. Personal data we collect
If you are a seller (platform account holder):
- Account data: name, email address, and a hashed password (we never store passwords in plain text).
- Verification (KYC) data: personal and business information you submit to go live — business name, registration details, addresses, and identity information required for our onboarding review.
- Bank details for payouts, stored with field-level encryption (AES-256-GCM).
- Your catalog, orders, invoices, subscriptions, payout history, and store configuration.
- Support tickets and the messages and attachments you send us.
If you are a buyer (paying at a Saleonix checkout):
- Order data: your name, email address, the items purchased, amounts, and — where the seller ships goods — your shipping address.
- Payment card data: your card number, expiry, and security code are used solely to execute the payment through our payment gateway (Payten) and acquiring bank (BKT). We never store, log, or retain card numbers or security codes on our systems.
- Receipts, invoices, refunds, and (for subscriptions) recurring billing records.
For all users and visitors (technical data):
- Security and audit logs: IP address, browser user-agent, and the outcome of security-relevant actions (sign-in attempts, password resets, administrative actions, payment sessions). We keep these to protect accounts, prevent fraud, and meet our obligations as a payment platform.
- Aggregated, cookieless usage analytics for our website (see section 8 — Cookies).
3. Why we process your data (purposes and legal bases)
- To provide the service (performance of a contract): operating your account, executing payments, delivering receipts and invoices, managing subscriptions, and paying out sellers.
- To meet legal obligations:Kosovo’s anti-money-laundering law (05/L-096), accounting and financial-reporting law (06/L-032), the payment-system law (04/L-155), and related record-keeping duties. This is why verification data and transaction records must be kept for statutory periods even after an account closes.
- For our legitimate interests: securing the platform, preventing fraud and abuse (rate limiting, security audit logs), reconciling payments, and improving the product using aggregated analytics.
- With your consent, where required — for example optional communications. We do not send marketing to buyers.
4. Our role: controller and processor
Because Saleonix is the merchant of record, we are the data controller for the personal data needed to process payments — buyer order and payment data, seller account and verification data, and our security logs.
For customer data that a seller manages through the platform beyond the payment itself (for example their customer lists and order history used to run their business), the seller is the controller of that relationship and Saleonix acts on the seller’s behalf. Data-processing terms form part of our terms and conditions.
6. International transfers
Some of our providers (hosting, email) may process data in the European Union or the United States. Where personal data leaves Kosovo or the EU/EEA, we rely on appropriate safeguards such as the providers’ standard contractual clauses and data-processing agreements.
7. How long we keep data
- Transaction, invoice, and verification records: for the periods required by Kosovo accounting, tax, and anti-money-laundering law.
- Account data: for as long as your account exists, then deleted or anonymized except where retention is legally required.
- Security and audit logs (IP address, browser user-agent, action outcomes): security and sign-in logs are kept for up to 24 months and other platform activity logs for up to 12 months; payment-related audit logs are kept for up to 5 years, in line with anti-money-laundering and dispute-handling duties. Logs past these periods are deleted automatically.
- Support tickets: for as long as needed to resolve the issue and maintain service history.
9. How we protect your data
Details are on our security page. In short: TLS encryption in transit with HSTS, AES-256-GCM field-level encryption for sensitive data such as bank details, hashed passwords, multi-factor authentication (required for administrative access and available to every account), role-based access control, rate limiting, and comprehensive audit trails of security-relevant events. Card data is passed directly to our payment gateway and never stored on our systems.
10. Your rights
Under Kosovo’s Law No. 06/L-082 on Protection of Personal Data and, where it applies, the EU GDPR, you have the right to:
- Access the personal data we hold about you and receive a copy;
- Correct inaccurate or incomplete data;
- Request deletion of your data (subject to the statutory retention duties in section 7);
- Restrict or object to certain processing;
- Receive your data in a portable format;
- Withdraw consent at any time, where processing is based on consent;
- Lodge a complaint with the Information and Privacy Agency of Kosovo (AIP) or your local supervisory authority.
Sellers can exercise the most important rights directly, without contacting us: the Privacy & Data tab in your account settings lets you download a complete copy of your data (JSON export) and delete your account. Deletion removes or anonymizes your personal data immediately; transaction, invoice, and verification records that the law requires us to keep (section 7) are retained, and accounts with an outstanding balance or a payout in progress must receive their funds first.
For anything else — or if you are a buyer — email info@saleonix.com from the address associated with your account, or open a support request. We respond within the legally required timeframes.
Buyers: if your question concerns the product you bought (rather than the payment), the seller you bought from is your first contact; we will help route your request where needed.
11. Changes to this policy
We may update this policy as the service and the law evolve. Material changes will be announced on the platform. The date of the latest revision is shown below.