Section 1

Who we are

Buletin Sh.p.k. is a company registered in Albania. In this policy, "we", "us" and "Buletin" mean Buletin Intelligence Sh.p.k.

"The Services" means, together: our website at buletin.al and any subdomain we operate; the Buletin Intelligence platform, its dashboards, exports and interfaces; the Narrative Threat Analysis pipeline and the briefs and reports it produces; any application or integration we operate on a third-party platform; and our support, sales and correspondence channels.

By accessing or using the Services in any manner, you acknowledge that you have read this policy and understand that we collect, use and share your data as described in it. Your use of the Services is at all times subject to our terms of service, or to any separate agreement your organisation has signed with us. Terms used here without a definition have the meaning given to them in those documents. "Personal data" in this policy means any information relating to an identified or identifiable individual, including what other laws call personal information or personally identifiable information.

For most of what we do we are a data controller. When we monitor, analyse or report on the documented instructions of a client, we are a processor and the client is the controller. Section 13 explains what that means for a request you make to us.

If you need this policy in an alternative format, write to INFO@buletin.al and we will provide one.

Section 2

What this policy covers

This policy covers how we treat personal data that we gather when you access or use the Services, as defined in section 1, and personal data that reaches us from the sources described in section 4.

It does not cover the practices of companies we neither own nor control. That includes the social platforms, publishers, broadcasters and data providers from which we collect published content, and any third-party website we link to. Their handling of your data is governed by their own policies, and you should read those to understand what they do with it. It also does not cover what a client does with a report after we deliver it.

If you are resident in the European Economic Area or the United Kingdom, sections 8, 11 and 13 set out the additional rights and information you are entitled to.

Two separate populations of data. Most people reading this fall into one of two groups, and it matters which. If you use the Services, sections 3, 4 and 7 describe what we hold about you. If you are a person whose published content appears in our monitoring — because you posted publicly, or because a publisher wrote about you — section 5 is the section that applies, and we did not collect that content because you visited our website or opened an account.

Section 3

Categories of data we collect

This table sets out the categories of personal data we collect and may have collected over the past 12 months, and who we share each category with. Section 9 describes the recipients in full.

Contact data Name, work email, employer, role, telephone number, postal addressService providers

Account data Username, password hash, language and notification settings, monitoring topics, saved searches and filters, your use of the platform Service providers

Billing data Organisation registration and VAT details, billing address, contract terms, invoices, payment recordsService providers; professional advisers

Log data IP address, date and time of use, device and browser type, operating system, session identifiers, interface calls, error tracesService providers

Analytics data Referring source, pages viewed, searches run, reports opened and exported, non-identifying interaction statisticsService providers

Client material Documents, datasets and media exports you upload for analysis, which may contain personal data about third partiesService providers, on your instructions

Publicly available content, including social media information Profile information such as display name, username, follower and following counts, profile URL, stated location, language, verification status; profile content such as biography and stated occupation; post content such as text, timestamp, hashtags, language and any location tag the author attached; and published articles, broadcasts and transcripts Service providers; clients who commissioned the monitoring

Third-party platform data Posts, comments, engagement metrics and audience insights for accounts and pages a client has authorised us to monitor; the platform identifier of the person who authorised the connectionService providers; the client who authorised the connection

We do not collect geolocation data from your device. We do not seek out special category data — health, political opinions, religious belief, trade union membership, sexual life — as a category of collection. Published political commentary about public figures may contain material of that kind because its author published it; where that happens we handle it under section 5 and we do not use it to profile private individuals.

Section 4

Where the data comes from

From you

When you give it to us directly — opening an account, contracting with us, uploading material, writing to us — and when it is collected automatically as you use the services, as described under cookies and tracking in section 15.

From third parties

  • Service providers: hosting, analytics, support and security providers that process data on our behalf and report back to us about how the Services are used and protected.
  • Platforms you connect: where you or your organisation connects an account or page to our application, some content and information from that account is transmitted to us under the permissions granted. See section 6.
  • Published and licensed sources: media outlets, broadcasters and publishers; content aggregators and data providers operating under licence; and public registers such as company, tax, procurement and court publication records where relevant to a mandate.
  • Public content you posted yourself: material published openly on social platforms and websites. See section 5.
Section 5

Publicly available content

Media & Data monitoring necessarily involves personal data, because news is about people. Our position is as follows.

We collect content that has already been published by its author or publisher and is accessible without circumventing a technical restriction, a paywall or a login. We do not access private accounts, closed groups or password-protected areas, and we do not attempt to re-identify anonymous or pseudonymous authors.

We process this content for journalistic, research, archival and statistical purposes: measuring coverage volume, tone and reach, mapping narratives, detecting coordinated or misleading information campaigns, and reporting on public debate. Our lawful basis is our legitimate interest, and our clients' legitimate interest, in understanding public discourse, weighed against the rights of the people named in it. Where Albanian and European law provide a specific regime for processing carried out for journalistic and academic purposes, we rely on it.

Because our clients commission the monitoring, publicly available content about you may be included in a report delivered to a client.

We do not publish those reports ourselves and we do not sell this content as a data product.

Our editorial standards apply to every output: the presumption of innocence is maintained, allegations are attributed to their source, and contested claims are tagged as requiring verification rather than presented as fact.

If you do not want your content processed

You have two routes, and the first is immediate. Setting your account or your individual posts to private, or restricting who can follow or view them, removes that content from what we are able to collect going forward. Alternatively, or in addition, write to info@buletin.al. You can object to our processing, ask for correction of an inaccurate record about you, or ask for your data to be removed from our index. We will weigh the request against the public interest in the material and answer you with reasons.

Section 6

Third-party platform data

This section applies to data we obtain through the application programming interfaces of third-party platforms — social networks, video and publishing platforms, and comparable services — where we are authorised to access them. Platform operators generally call this platform data and require it to be handled under stricter rules than ordinary collection. We apply those rules to all of it.

What we obtain and from whom

  • Account and page data belonging to our clients: where a client authorises our application through a platform's login or connection flow and grants the relevant permissions, we receive posts, comments, engagement metrics and audience insights for the accounts or pages they administer.
  • Public content: where we hold the relevant access, public posts and public comments from accounts and pages relevant to a monitoring mandate.
  • Basic profile data of the authorising person: name, platform user identifier, and email address where granted, used only to create and secure the account that connects the pages.

What we do with it

Platform data is used for one purpose: to deliver the monitoring, analysis and reporting the client asked for. Specifically, to index content, classify sentiment, detect narrative patterns and coordinated behaviour, and produce briefs and reports for that client.

What we never do

  • We do not sell, licence or rent platform data.
  • We do not transfer platform data to data brokers, information resellers, advertising networks, or any party that monetises data.
  • We do not use platform data to build profiles for advertising or ad targeting, to determine eligibility for credit, insurance, housing, employment or education, or for any surveillance purpose.
  • We do not use platform data to identify or infer sensitive characteristics about individuals.
  • We do not combine platform data with data from other sources in order to identify a person who is not already publicly identified in the content.
  • We do not attempt to access data beyond the permissions a user or page owner has granted, and we do not circumvent any technical restriction in a platform's interfaces.

Our commitments to platform operators and to users

We comply with the developer terms, platform policies and data use policies of every platform whose interfaces we access, including their requirements on purpose limitation, onward transfer, security and deletion. We keep platform data only as long as it is needed for the purpose above or as required by law, and we delete it when a client's authorisation is withdrawn, when their contract ends, when the platform operator instructs us to, or when a valid deletion request is made under section 14.

If a subprocessor handles platform data on our behalf, it is contractually bound to equivalent obligations and we remain responsible for its conduct.

Disconnecting our application in the settings of the platform concerned revokes our access immediately. Removing the integration stops all further collection; section 14 explains how to have what we already hold erased.

Section 7

How we use the data

Delivering, maintaining and improving the Services

  • Creating and administering accounts, and authenticating the people who use them.
  • Running the monitoring: collecting, indexing, classifying and analysing content, and producing the briefs and reports a client has commissioned.
  • Providing support, and responding to questions about a deliverable.
  • Processing orders, invoicing and collecting payment.
  • Testing, research and internal analytics to improve coverage, classification accuracy and the performance of the Services.
  • Security, fraud prevention, debugging and abuse detection.

Communicating with you

  • Answering correspondence, and sending service notices about changes, incidents and maintenance.
  • Marketing our services to institutional contacts, subject to the opt-out in section 13.
  • Where we record a call for training or note-taking purposes, we tell you before the recording starts and you can decline.

Meeting legal obligations and protecting rights

  • Complying with law, regulation, a court order or other legal process.
  • Investigating and preventing security incidents and prohibited activity.
  • Protecting the rights, property or safety of you, of us, or of another party.
  • Enforcing our agreements and resolving disputes.

We will not collect additional categories of personal data, or use what we have collected for a materially different and incompatible purpose, without telling you first.

Section 8

Lawful bases

We process personal data only where we have a lawful basis. Which basis applies depends on the category.

Contractual necessity

Contact data, account data, billing data, client material. Without these we cannot provide the Services, and failure to supply them means some or all of the Services will not work for you.

Legitimate interest

Contact data, account data, log data, analytics data, publicly available content, third-party platform data — for operating and improving the service, monitoring public discourse, supporting clients, marketing to institutional contacts, and protecting against fraud and security threats.

Consent

Optional analytics cookies, and any processing where we ask you at the point of collection. You can withdraw consent at any time.

Legal obligation

Accounting and tax records, responses to lawful requests from authorities, breach notification.

Journalistic, academic and research purposes

Publicly available content processed under section 5, to the extent the applicable regime provides for it.

Legal claims and public interest

Data needed to establish, exercise or defend a legal claim, or to protect the vital interests of any person.

Where we rely on legitimate interest we have carried out a balancing assessment, and you can ask us for a summary of it.

Section 9

How we share data

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We disclose it to the recipients below and to no one else.

  • Service providers. Third parties acting on our behalf: cloud hosting and storage, AI model providers, email and ticketing, error monitoring, analytics, payment processing and accounting. Each is bound by contract to confidentiality, security and purpose limitation, and may not use the data for its own ends.
  • Clients who commissioned the monitoring. Monitoring results and reports, which may include publicly available content about you, go to the commissioning client. They do not go to anyone else, and we do not offer this content as a standalone data feed.
  • Professional advisers. Lawyers, auditors and insurers, under professional confidentiality.
  • Authorities. Where we are legally required to disclose, and only to the extent required. We assess every request, refuse those without a valid basis, and notify the person affected unless the law forbids it.
  • An acquirer. If the business is sold, merged or reorganised, data may transfer to the acquiring party. We will make reasonable efforts to notify you before your data becomes subject to a different privacy policy.

A current list of our subprocessors is available to clients on request from info@buletin.al.

Section 10

Automated analysis and AI

Our analysis pipeline uses natural language processing and large language models to extract metadata, classify sentiment , summarise and translate, and flag potential disinformation patterns.

Three points matter here. Our providers are bound not to use the content we send them to train their models. Classification outputs are treated as analytical signals, not as findings about a person, and every sentiment tag carries a justification so a human can check it.

And no decision producing a legal or similarly significant effect on an individual is made by automated means — our reports inform human judgement, they do not substitute for it.

Section 11

International transfers

We are established in Albania, and the Services are hosted and operated from Albania and the European Economic Area. Some of our providers operate in the EEA, the United Kingdom and the United States, so personal data may be transferred outside Albania, and the law where a recipient sits may differ from the law where you live.

Where we transfer data to a country without an adequacy decision, we rely on Standard Contractual Clauses approved by the European Commission, on the authorisation of the Albanian Information and Data Protection Commissioner where that is required, and on technical measures including encryption in transit and at rest. You can ask us which safeguard applies to a specific transfer.

Section 12

Security and retention

How we protect data

We apply physical, technical, organisational and administrative measures proportionate to the data and the processing: encryption in transit using current Transport Layer Security and at rest in our databases, role-based access control with least privilege, multi-factor authentication for staff, network and application logging, segregated client environments, vetted subprocessors, and confidentiality undertakings from everyone who handles client material. Access to a client's data is limited to the analysts assigned to that engagement. Paper material is held under lock and converted to secure electronic records, with originals archived or destroyed.

You can help by choosing a strong password, keeping it to yourself, limiting access to your device, and signing out when you finish. No method of transmitting or storing data is completely secure, and we cannot guarantee absolute security.

If a breach occurs that is likely to result in a risk to people's rights, we will notify the Albanian Information and Data Protection Commissioner within 72 hours of becoming aware of it, notify affected clients without undue delay, and notify affected individuals where the risk is high. Where data obtained from a third-party platform is involved, we will also notify that platform operator as required by its developer terms.

How long we keep it

  • Contact, account and billing data: while the account is open, then up to 12 months after closure, except where accounting law requires longer.
  • Client material and deliverables: for the term of the engagement plus the period agreed in the contract; otherwise deleted or returned on request.
  • Monitoring index and archives: for as long as the client relationship requires, reviewed periodically, and removed earlier on a successful objection or erasure request.
  • Third-party platform data: only as long as the monitoring purpose requires, and deleted when authorisation is withdrawn.
  • Log and analytics data: up to 12 months.

We keep data for longer where it is necessary to comply with a legal obligation, resolve a dispute or collect a fee owed. When a retention period ends we delete the data or irreversibly anonymise it, and anonymised or aggregated records that cannot identify you may be kept indefinitely. Backups are deleted on their own rotation schedule, which may run for a short period after live deletion.

Section 13

Your rights

Subject to the conditions in applicable law, you have the right to:

  • Access: be told whether we hold data about you, learn the categories, sources, purposes and recipients involved, and receive a copy.
  • Rectification: have inaccurate data corrected and incomplete data completed.
  • Erasure: have your data deleted, subject to the exceptions in section 14.
  • Restriction: have processing paused while a dispute is resolved.
  • Objection: object to processing based on legitimate interest, including to your inclusion in our monitoring index.
  • Portability: receive data you gave us in a machine-readable format, and have it sent to another controller where technically feasible.
  • Withdrawal of consent: at any time, without affecting processing already carried out.
  • Opt-out of marketing: by using the unsubscribe link in any marketing email, or by writing to us. We may still send you service notices and communications required by law.
  • Complaint: to a supervisory authority.

Making a request

Write to info@buletin.al. Give us enough information to verify who you are, and describe what you want in enough detail for us to understand and act on it. We answer within 30 days of receipt, and where a matter is complex we will tell you within that period and explain how much longer we need. There is no charge unless a request is manifestly unfounded, excessive or repetitive, in which case we will tell you the fee and the reason before proceeding.

We may not always be able to comply in full — where a request is unfounded, where it would prejudice the rights of others, or where the law does not require it. In those cases we will still respond and explain the decision. You may authorise someone to act on your behalf. We will ask for written proof of that authority.

If we hold your data for a client. Where we process personal data as a processor on a client's instructions, that client is the controller and should be your first point of contact. Tell us anyway and we will forward the request and support them in answering it.

You can complain to the Information and Data Protection Commissioner of Albania. If you are in the European Economic Area or the United Kingdom, you can also complain to the supervisory authority where you live, where you work, or where the alleged infringement took place.

Section 14

Deleting your data

Connected platform users. If you connected a social media account or page to our application and want the data we obtained through it deleted, you do not need an account with us to ask.

To have it deleted, do one of the following.

Remove the integration on the platform

Open the platform's settings, go to the area listing connected applications — usually named Apps and websites, Connected accounts or Business integrations — find the Buletin application, and remove it. This revokes our access at once. Where the platform sends us a deletion signal, we act on it automatically and erase the data associated with your platform user identifier from our production systems.

Ask us directly

Email info@buletin.al with the subject line Data deletion request and tell us the platform, the account or page, or the email address concerned. We will confirm receipt, verify that you are entitled to make the request, and complete the deletion within 30 days.

We will confirm in writing when it is done. Material we are legally required to keep — accounting records, or data needed to establish or defend a legal claim — is retained for that purpose only and is otherwise restricted from use. Published content of public interest is assessed under section 5 rather than deleted automatically, and we will explain our reasoning if we decline.

The permanent address of these instructions is https://buletin.al/privacy#data-deletion.

Section 15

Cookies and tracking

We use cookies and similar technologies, including pixels and scripts, on our website and platform.

Strictly necessary cookies keep you signed in, maintain your session and protect against cross-site request forgery. These cannot be switched off without breaking the service. Optional analytics cookies help us understand how the site and platform are used; they run only if you accept them, and you can change your choice at any time through the cookie settings link in the site footer or by clearing cookies in your browser.

We do not use advertising cookies, we do not run third-party ad trackers, and we do not share data through cookies in a way that would constitute a sale or a sharing of personal data under any applicable law.

Section 16

Children

The Services are sold to institutions and are not directed at children. We do not knowingly collect or solicit personal data from anyone under 16 as a platform user, and if you are under 16 you should not register or send us personal data. If we learn that we have collected data from a child under 16 through an account, we will delete it as quickly as possible. If you believe a child has provided us with personal data, write to info@buletin.al.

Section 17

Public sector engagements

Where we work for a public body, an embassy or a donor-funded programme, that engagement may be governed by a specific legal regime — classification rules, archive and record-keeping obligations, audit rights, or a statutory framework governing the authority's own records. Where such a regime applies to data we handle for that authority, it controls to the extent it conflicts with this policy, and the authority is the controller of the records concerned.

Staff who handle classified or restricted material are briefed on the applicable rules before they are given access, and unauthorised access to or disclosure of that material is prohibited. Report a suspected breach to info@buletin.al.

Section 18

Changes to this policy

We update this policy when our practices, our providers or the law change. The version number and dates at the top of the page always reflect the current text. For material changes we notify account holders by email at least 14 days before the new version takes effect, and we keep previous versions available on request. Data we collected before a change remains governed by the policy in force when it was collected.

Section 19

Contact

Questions about this policy, a request about your data, or a concern about something we published:

Email info@buletin.al

We investigate and respond to a complaint within 30 days of receipt. If the matter is complex and our investigation will take longer, we will tell you.

Buletin Sh.p.k. · Tirana, Albania

Examining the current trends shaping public communication.