Privacy policy
Last updated 30 April 2026
Effective date 29 April 2026
1. Introduction
1.1 Who we are
This Privacy Policy describes how Здружение за животна средина ЕКОХАБ Скопје, a citizens' environmental association registered in the Republic of Macedonia with registration number 7939248 and registered office at ул. Сава Михајлов 2 бр.15, Скопје - Гази Баба, Република Македонија ("Chisto.mk," "we," "us," or "our"), collects, uses, stores, and protects your personal data when you use our mobile applications (iOS and Android) and our public website (collectively, the "Platform").
We operate Chisto.mk as a civic environmental initiative focused on transparency and community reporting about local environmental conditions.
Most account, reporting, and map interaction features run in the apps. The website is mainly marketing, legal information, and contact; it may use a small number of cookies or local storage as described in our Cookie Policy.
Effective date: 29 April 2026.
1.2 Our commitment
We are committed to protecting your privacy and complying with applicable data protection laws, including:
- Law on Personal Data Protection of the Republic of Macedonia (Official Gazette No. 42/2020)
- Regulation (EU) 2016/679 - General Data Protection Regulation ("GDPR")
- Law on Electronic Communications (Official Gazette No. 39/2014)
1.3 Contact information
- Data controller:
- Здружение за животна средина ЕКОХАБ Скопје
- ул. Сава Михајлов 2 бр.15, Скопје - Гази Баба, Република Македонија
- Email: info@ekohab.mk
- Phone: +389 75 770 803
- Data protection officer (if applicable):
- Email: Not applicable
- Supervisory authority:
- Agency for Personal Data Protection
- Republic of Macedonia
- Website: https://www.dzlp.mk
- Email: info@dzlp.mk
2. Scope and application
2.1 This Privacy Policy applies to personal data we process when you:
- Use the Chisto.mk mobile apps
- Use the website at https://www.chisto.mk (including forms or newsletters we operate)
- Email or otherwise contact us
It also covers processing by subprocessors we use to host or operate the service (listed in general terms below and in agreements we maintain).
2.2 This Policy does not govern:
- Independent websites or apps you open via links from us (their policies apply)
- Processing by public authorities or third parties that act on their own legal basis
- Content you exchange with other users outside our systems
2.3 By using the Platform, you confirm that you have read this Policy. Some processing relies on consent (for example optional marketing or optional analytics on the website); you may withdraw consent where the law allows, as described below.
3. Personal data we collect
We collect personal data to run the civic map, authenticate users, moderate content, and improve reliability. Categories include:
3.1 Data you provide directly
3.1.1 Account data (apps)
- First and last name
- Email address
- Mobile phone number (used for sign-in and verification with one-time codes)
- Password (we store a secure hash, not the plain password)
- Optional profile photo and in-app preferences
- Optional multi-factor authentication data if you enable it
- Gamification fields tied to your account (for example points), where the product includes them
3.1.2 Reports and sites
When you submit a pollution report we collect the report text, category and similar fields you enter, photos you attach, coordinates and address or place text for the location, timestamps, and moderation outcomes. Reports are linked to a "site" record on the map. Other users may see public report and site content according to product rules.
3.1.3 Community and events
Comments and likes on sites, saves, and share actions you trigger
Cleanup events shown in the product (scheduled time, linked site, organiser fields the UI collects, participant counts)
3.1.4 Support and contact
What you send us by email, contact forms, or comparable channels
3.1.5 Payments
We do not operate in-app purchases or paid subscriptions in the current product. If we introduce paid features later, we will update this Policy and name the payment processor.
3.2 Data collected automatically
3.2.1 Technical and security data
- IP address, device type, operating system and app or browser version where available
- Session or device records we need for security (for example refresh token identifiers, optional device description)
- Server and application logs for reliability and abuse detection
3.2.2 Usage data
Interactions needed to operate features you use (for example opening a report, voting, commenting)
Optional product analytics if implemented in the apps (we will describe the vendor here when enabled)
3.2.3 Location
Precise location when you choose to attach a location to a report or use map features that require it. We do not intend to track your location continuously in the background; if that ever changes, we will ask for a separate permission and update this Policy.
3.2.4 Push notifications
If you opt in, we store a push device token (for example via Firebase Cloud Messaging) and related preference flags so we can deliver notifications you request.
3.2.5 Website cookies and storage
The public website uses strictly necessary storage plus, if you agree, Vercel Web Analytics. Details are in the Cookie Policy.
3.3 Third-party sources
We may use mapping or geocoding services (for example Carto basemaps or Esri imagery in the apps, and geocoding helpers) to render maps or resolve addresses; those providers may receive technical requests needed to load tiles or geocode coordinates. We do not operate social login in the current apps; if we add it, we will update this section.
4. Legal basis for processing
Under GDPR Article 6, we rely on:
4.1 Contract (Art. 6(1)(b))
Operating accounts, publishing reports you submit, showing map content, comments, events, and notifications you ask for.
4.2 Legitimate interests (Art. 6(1)(f))
Securing the service, preventing abuse, debugging and reliability, internal statistics that do not require marketing profiles, and limited product improvement, balanced against your rights.
4.3 Legal obligation (Art. 6(1)(c))
Accounting, tax, or regulatory duties where they apply, and lawful requests from authorities.
4.4 Consent (Art. 6(1)(a))
Where required, for example optional marketing communications, optional website analytics cookies, or any future feature we offer only on an opt-in basis. You may withdraw consent without affecting earlier processing that was lawful.
4.5 Vital interests (Art. 6(1)(d))
Rare processing needed to protect life or serious safety.
5. How we use your personal data
5.1 Running the Platform
Authenticate you, maintain your profile, and operate map, report, comment, event, and notification features you use.
5.2 Safety, trust, and moderation
Review reports of abuse, enforce our Terms, protect users, and keep infrastructure stable.
5.3 Communications
Send service messages (for example security notices or report status) using contact details you provide. Marketing or newsletter messages only where we have a lawful basis (usually consent).
5.4 Aggregates for partners
Produce statistics that do not identify individuals where we describe in agreements or product copy.
5.5 Legal and compliance
Meet retention duties, respond to lawful requests, and defend legal claims.
5.6 Improvement
Understand errors and performance in aggregate; we avoid unnecessary profiling beyond what the product needs.
6. Data sharing and disclosure
6.1 Consent or instruction
We share data with third parties when you ask us to or when you deliberately make content public in the product.
6.2 Infrastructure and operations
We use vetted processors, for example:
- Hosting and API infrastructure: Amazon Web Services (AWS) in AWS eu-central-1 (Frankfurt, Germany) (or as updated in our records)
- Email delivery for website contact forms and update notifications: Resend for website contact and update notifications; Mailchimp only if newsletters are enabled later
- SMS verification: Twilio where SMS one-time codes are active
- Push notifications: Google Firebase Cloud Messaging for device delivery
- Mobile diagnostics and analytics: Firebase Crashlytics and Firebase Analytics when included in the production app
- Website analytics (if you opt in on the site): Vercel Web Analytics
- Support channel: Email support at info@ekohab.mk
Contracts require processors to use data only on our instructions and to apply appropriate security.
6.3 Maps and geolocation helpers
Map tiles may be loaded from Carto (OpenStreetMap-based raster tiles) and, where the UI offers it, Esri World Imagery or similar imagery providers. Geocoding may use platform APIs you already bundle. Those providers receive technical requests (tile coordinates, IP in server logs) as normal for map delivery.
6.4 Authorities and aggregates
We may share anonymised or aggregated environmental statistics with municipalities or partners. We may disclose identifiers or content if the law compels us, to protect rights and safety, or to enforce our Terms.
6.5 Reorganisation or succession
If we merge, restructure, or another organisation continues the service, personal data may transfer to the successor. We will require them to respect this Policy or notify you.
6.6 Public visibility
Reports, comments, usernames, and event listings you publish may be visible to other users and, depending on configuration, on the open web.
7. International data transfers
7.1 Data storage locations
Your personal data is primarily stored on servers located in European Union / EEA.
7.2 Transfers outside EU/EEA
If we transfer data to countries outside the European Economic Area that do not have an adequacy decision from the European Commission, we ensure appropriate safeguards:
- EU Standard Contractual Clauses (SCCs)
- Binding Corporate Rules (where applicable)
- Recipient's certification under approved frameworks
- Your explicit consent for specific transfers
7.3 Macedonian context
As a candidate country for EU membership, the Republic of Macedonia aligns its data protection framework with EU standards. We treat data protection with the same rigor as EU member states.
8. Data retention
We keep personal data only as long as needed for the purposes above or as the law requires. Exact schedules evolve with the product; the following reflects our current intent.
8.1 Accounts and security
Profile and credentials: while your account is active, then typically up to 90 days after closure unless law or dispute resolution needs more time.
Sessions and security logs: long enough to detect abuse (often months, not years, unless an investigation needs longer).
8.2 Reports, sites, and community content
Environmental reports may stay visible as part of the civic map for a long time or indefinitely because they document conditions in the public interest. If you exercise erasure rights, we may remove or anonymise your personal link to a report (for example detaching your account) while keeping non-personal location and imagery that cannot identify you, unless law requires otherwise. We handle erasure and anonymisation requests in line with this description.
Photos and rich media: retained with the report until deletion or anonymisation rules apply.
Comments, votes, saves: retained until you delete them, we moderate them away, or the related site is removed according to product rules.
8.3 Events
Cleanup events stay linked to sites for scheduling history; any participant lists follow the same principles as account data.
8.4 Marketing and contact history
Marketing consents and proof of opt-in or opt-out: as required by law, usually a few years after the last message.
8.5 Legal, tax, and backups
Records we must keep for accounting, tax, or litigation hold periods set by Macedonian law.
Backups rotate; purging from backups may lag production deletion by up to 90 days.
8.6 Inactive accounts
We may warn you before deleting long-inactive accounts, then remove personal data subject to the report anonymisation rules above.
9. Your rights under GDPR
Under GDPR and Macedonian data protection law, you have the following rights:
9.1 Right of access (Article 15)
You have the right to obtain:
- Confirmation whether we process your personal data
- A copy of your personal data
- Information about processing purposes, categories, recipients, and retention periods
- How to exercise: Email info@ekohab.mk with subject "Data Access Request"
- Response time: Within 30 days (may extend to 60 days for complex requests)
- Cost: Free for the first request; reasonable fee for excessive requests
9.2 Right to rectification (Article 16)
You have the right to correct inaccurate or incomplete personal data.
How to exercise:
- Update directly through account settings in the apps where available
- Email info@ekohab.mk with correct information
- Response time: Without undue delay, maximum 30 days
9.3 Right to erasure / "Right to be forgotten" (Article 17)
You have the right to request deletion of your personal data when:
- Data is no longer necessary for original purposes
- You withdraw consent (where consent was the legal basis)
- You object to processing and there are no overriding legitimate grounds
- Data was unlawfully processed
- Legal obligation requires deletion
Exceptions: We may refuse deletion when required for:
- Legal compliance (e.g., tax records)
- Legal claims defense
- Public interest or scientific research
How to exercise: Account settings > Delete Account in the apps where available, or email info@ekohab.mk
Response time: 30 days; data purged within 90 days including backups
9.4 Right to restriction of processing (Article 18)
You have the right to limit processing when:
- You contest data accuracy (during verification)
- Processing is unlawful but you oppose deletion
- We no longer need data, but you need it for legal claims
- You objected to processing (pending verification of legitimate grounds)
How to exercise: Email info@ekohab.mk with specific restriction request
Effect: Data marked and stored, but not actively processed
9.5 Right to data portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
Applies to:
- Data provided by you
- Processing based on consent or contract
- Processing carried out by automated means
- How to exercise: Account settings > Export Data in the apps where available, or email info@ekohab.mk
- Format: JSON, CSV, or PDF
- Response time: 30 days
9.6 Right to object (Article 21)
9.6.1 Marketing
You have the absolute right to object to direct marketing.
How to exercise: Click "Unsubscribe" in emails, or update preferences in account settings in the apps where available
9.6.2 Legitimate interest processing
You have the right to object to processing based on legitimate interests.
How to exercise: Email info@ekohab.mk with specific objection
Effect: We will cease processing unless we demonstrate compelling legitimate grounds
9.6.3 Profiling and automated decision-making (Article 22)
We do not currently engage in automated decision-making with legal or significant effects. If this changes, you will have the right to:
- Obtain human intervention
- Express your point of view
- Contest the decision
9.7 Right to withdraw consent
Where processing is based on consent, you can withdraw at any time without affecting prior lawful processing.
How to exercise: Account settings > Privacy Preferences in the apps where available, or email info@ekohab.mk
9.8 Right to lodge a complaint
You have the right to file a complaint with the supervisory authority:
- Agency for Personal Data Protection
- Republic of Macedonia
- Address: Boulevard Goce Delchev 18, Skopje, Republic of Macedonia
- Website: https://www.dzlp.mk
- Email: info@dzlp.mk
- Phone: +389 2 3230 635
For EU residents: You may also lodge a complaint with the supervisory authority in your EU member state of residence.
10. Data security
We implement technical and organizational measures appropriate to the risk, taking into account the nature of the processing and the state of the art.
10.1 Measures we may use
Depending on how the service is hosted and developed, measures may include:
- Encryption of personal data in transit (for example TLS)
- Passwords stored using strong one-way hashing
- Access controls for systems and accounts, including multi-factor authentication for administrative access where we deploy it
- Patching, monitoring, and logging for reliability and abuse detection
- Safeguards against common application risks (for example input validation and protections against injection and cross-site scripting where applicable)
We review and adjust controls as the service evolves.
10.2 Organization and vendors
We maintain practices suited to our size and risk, including how we work with hosting and other processors we engage.
10.3 Personal data breaches
If we become aware of a breach that is likely to affect your rights and freedoms, we will notify the supervisory authority without undue delay and within 72 hours where the GDPR or applicable law requires it, and we will inform affected users when the law requires that too.
10.4 Your part
Use a strong unique password, enable multi-factor authentication in the apps if offered, sign out on shared devices, and contact us promptly if you suspect unauthorized access to your account.
11. Children's privacy
11.1 The Platform is not intended for children under 18 years of age.
11.2 We do not knowingly collect personal data from children under 18 without parental consent.
11.3 If we become aware that we have collected data from a child under 18 without verified parental consent, we will delete that information as quickly as possible.
11.4 If you are a parent or guardian and believe your child has provided personal data to us, please contact us at info@ekohab.mk.
11.5 Parents may supervise minors' use of the Platform, but minors may not create accounts independently.
12. Cookies and tracking technologies
The public website uses strictly necessary storage plus optional Vercel Web Analytics if you opt in through our banner. We do not run separate functional or marketing cookie toggles on the site today. Full detail is in the Cookie Policy at https://www.chisto.mk/en/cookies.
The mobile apps use on-device storage, push tokens, and map caches as described in Sections 3 and 6, not browser cookies.
13. Third-party links and services
13.1 The website may link to social profiles or partner pages. The apps load map tiles and geocoding from providers such as Carto (OpenStreetMap data) or Esri where offered.
13.2 Those services have their own privacy notices. We do not control them.
13.3 We do not embed social login in the current mobile product. If we add integrations, we will list them here.
14. Changes to this Privacy Policy
14.1 Notification of changes
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:
- Email notification to registered users (at least 30 days before changes take effect)
- Prominent notice on the Platform
- In-app notification
- Updated "Last Updated" date at the top of this Policy
14.2 Your acceptance
Continued use of the Platform after changes take effect constitutes acceptance of the updated Policy. If you do not agree with changes, you must stop using the Platform and may close your account.
14.3 Version history
We maintain a version history of this Policy. Previous versions are available upon request at info@ekohab.mk.
15. Specific provisions for Macedonian users
15.1 Language
This Privacy Policy is provided in Macedonian, English, and Albanian. In case of conflict, the Macedonian version prevails for users in the Republic of Macedonia.
15.2 Supervisory authority
- The competent supervisory authority for data protection matters in Macedonia is:
- Агенција за заштита на личните податоци
- (Agency for Personal Data Protection)
- Address: Boulevard Goce Delchev 18, Skopje, Republic of Macedonia
- Website: https://www.dzlp.mk
- Email: info@dzlp.mk
15.3 Legal basis
Processing of personal data is conducted in accordance with:
Закон за заштита на личните податоци (Official Gazette No. 42/2020)
EU GDPR principles as adopted in Macedonian legislation
16. Contact us
For questions, concerns, or requests regarding this Privacy Policy or your personal data:
- Privacy inquiries:
- Email: info@ekohab.mk
- Phone: +389 75 770 803
- Address: ул. Сава Михајлов 2 бр.15, Скопје - Гази Баба, Република Македонија
- Data protection officer (if applicable):
- Email: Not applicable
- General contact:
- Email: info@ekohab.mk
- Website: https://www.chisto.mk
- Response time: We aim to respond to all privacy inquiries within 48 hours and resolve requests within 30 days.
BY USING THE PLATFORM, YOU CONFIRM THAT YOU HAVE READ THIS PRIVACY POLICY. WE PROCESS PERSONAL DATA AS DESCRIBED HEREIN, INCLUDING PROCESSING THAT DOES NOT RELY ON CONSENT WHERE THE LAW ALLOWS OTHER LEGAL BASES.