Privacy Policy
Last updated: August 4, 2026
1. Who is responsible for processing your data?
The entity responsible for processing your personal data is Contemporary Student Solutions Albania SHPK (hereinafter, “CSSA”), located at “Rruga Bulevardi Kryesor, Nr. pasurie 2/83+2-5, Zona kadastrale 8514, Durrës, Albania, 2001”, registered in the National Business Registry on 16/07/2024 with identification number M41916501C.
This Privacy Policy governs access to and use of the website www.studentcard.al (hereinafter, the “Website”) that CSSA makes available to internet users (hereinafter, the “Users”) interested in the products and services (hereinafter, the “Services”) offered by CSSA.
Contact email: contact@studentcard.al
2. Recommendations
Please read and follow these recommendations carefully:
- Keep your device updated with antivirus software against malware and spyware that could compromise your internet navigation and stored information.
- Read and review this Privacy Policy and all legal texts provided by CSSA on the Website.
3. Information collected by CSSA through the Website
For proper functionality, CSSA may access the following data provided by the User:
- Identification data: name, surname, identity document (national ID card or passport), and identification photo.
- Personal characteristics: date of birth, gender, nationality.
- Contact data: email and phone number.
- Academic data: level of education, educational institution, faculty, and study programme.
- Usage data, collected automatically: the pages you visit, the actions you take on the Website, your device and browser type, approximate location (IP), session recordings of your visit, and technical error reports. See Section 5.
As part of the application, the User uploads images of their identity document and proof of study. These documents are processed solely to verify the User’s eligibility for an ISIC card. Payment for the card is handled by our third-party payment provider; CSSA does not store the User’s full card or banking details.
4. Why is CSSA authorized to process your data?
The legal basis for processing User data via this Website is the User’s consent, as well as the execution of a contract or pre-contractual measures requested by the User.
By accepting this Privacy Policy and checking the corresponding boxes, the User consents to the processing of their data.
CSSA ensures the secure handling of your personal data in accordance with the EU General Data Protection Regulation (GDPR) (Regulation 2016/679) and Albanian Law No. 124/2024 “On the Protection of Personal Data” (in force since 31 January 2025), which is harmonised with the GDPR.
Users can withdraw their consent at any time by emailing contact@studentcard.al, without affecting the lawfulness of prior data processing.
5. Purposes of data processing
Your personal data collected by CSSA may be used for the following purposes, depending on the consent provided:
- To provide the services and content of the Website.
- To send communications about CSSA’s products and services via mail, email, or equivalent methods.
- To manage and respond to User’s requests, inquiries, or issues.
CSSA uses PostHog, an analytics and error-monitoring tool, to understand how the Website is used and to improve the application process. PostHog records the pages you visit, the actions you take on the Website, your device and browser type, approximate location (IP), and technical error reports. Where you are signed in, this activity is linked to your account, so that we can find and fix the points where Users get stuck. PostHog processes this data on servers within the European Union. CSSA does not use it for advertising and does not sell it.
To find the points where Users get stuck, PostHog also makes session recordings: a replication of your visit that shows the pages you viewed, your mouse movement, clicks and scrolling, and the text you type into forms. This means information you enter while applying for an ISIC, such as your name, date of birth, phone number, and academic details, can appear in a recording.
The identity documents, study documents and photograph you upload are never recorded. They are blocked inside your browser and are not sent to PostHog, so no document or photograph of yours ever appears in a recording — not while you are applying, and not later on your profile page. Recordings are stored on servers within the European Union and are deleted automatically after 30 days.
Everything described in this section happens only if you consent. On your first visit you are asked to accept or decline, and until you choose, none of it is collected. If you decline, PostHog stores nothing on your device, no session recording is made, your IP address is not stored, and your activity is not linked to your account; we then only count visits using a daily code that cannot be traced back to you. Your choice is remembered for 12 months, after which you are asked again. You can change it at any time from the control at the top of our Cookie Policy, which also explains this in full.
6. Accuracy of data provided by Users
Users guarantee the accuracy of their data and commit to informing CSSA of any changes. CSSA reserves the right to deny services to any User who provides false information.
Users should protect their data diligently using appropriate security tools. CSSA will not be responsible for unauthorized alterations, theft, or data loss unless caused by CSSA’s negligence.
7. Data retention
User data will be retained as long as it remains relevant for the purposes for which it was collected, or until the User requests deletion. Afterward, CSSA will retain information for legally mandated periods.
The identity and study documents uploaded by the User are securely stored for as long as the User’s ISIC application and membership remain active, after which they are deleted in line with CSSA’s retention periods.
Session recordings made by PostHog (Section 5) are kept for a shorter period than other data and are deleted automatically 30 days after they are made.
CSSA is committed to maintaining the confidentiality of personal data as required by law.
8. User rights
Users have the right to:
- Access their personal data.
- Request the correction of inaccurate data.
- Request the deletion of their data.
- Limit data processing.
- Object to data processing.
- Request data portability.
- Avoid decisions based solely on automated data processing.
To exercise these rights, Users can email contact@studentcard.al with their request and a copy of their ID.
Users can file complaints with supervisory authorities if they believe their rights are violated.
9. Data security
CSSA has implemented measures to protect User data against unauthorized access, loss, or misuse, ensuring compliance with applicable legislation. However, Users should be aware that no online security system is infallible.
10. Transfers to third parties
CSSA does not sell your personal data. We share it only with the service providers that help us deliver the Services, and only to the extent necessary for the purposes set out in Section 4. These providers act as our processors and are bound to protect your data:
- ISIC Association (Nytorv 5, 1450 Copenhagen, Denmark; CVR 26746760) — issues and verifies ISIC cards and maintains cardholder records.
- Supabase — database, authentication, and secure storage of uploaded documents.
- Vercel — hosting of the Website.
- POK (Nebula Ltd) — secure payment processing.
- Google and Microsoft — sign-in, only where the User chooses to log in with one of these providers.
- PostHog — product analytics, session recordings and error monitoring, to measure how the Website and the application process are used. Data is stored on servers within the European Union.
International transfers: in connection with issuing and verifying your ISIC card, ISIC Association stores cardholder data on servers within the European Union (Amazon Web Services, Ireland) and may verify your card internationally when you use it to obtain benefits abroad. Any such transfer is carried out under appropriate safeguards as required by applicable data-protection law.
11. Questions
For any questions about this Privacy Policy, contact contact@studentcard.al.
Users can file complaints with the Albanian Commissioner for the Right to Information and Protection of Personal Data (IDP.al) via phone (+355 42237200), postal address (Rr. “Abdi Toptani”, Nd. 5, Kodi postar 1001, Tiranë), or online at https://idp.al/kontakt/.
12. Acceptance and consent
By accepting this Privacy Policy, the User agrees to the processing of their personal data by CSSA in the manner and for the purposes stated.