Congress Travel Service

Privacy And Cookie Policy

I. Who We Are and How to Contact Us

Congress Travel Service DOOEL Skopje (hereinafter referred to as “CTS Skopje,” “we,” or “us”) is a limited liability company for trade and services, located at:

Address: Vladimir Polezinoski 22/5, 1000 Skopje, Republic of North Macedonia
Email: office@congresstravelservice.com
Phone: +389 2 3230 967, +389 70 345 047

CTS Skopje is a highly competitive corporate travel agency, providing world-class corporate travel management. As the data controller, we are committed to protecting the personal data of our clients, partners, and website visitors.

We have appointed a Data Protection Officer (DPO) to ensure that all processing of personal data is lawful and in accordance with local and international regulations.

DPO Contact:

Name: Ljubica Krstevska
Email: dpo@congresstravelservice.com

You may contact our DPO regarding all data protection matters, including the exercise of your rights under applicable laws.


II. Key Definitions and Data Protection Principles

In accordance with the Law on Personal Data Protection (LPDP) and relevant international standards, we define key terms as follows:

  • Personal Data: Any information related to an identified or identifiable natural person.
  • Processing: Any operation performed on personal data (e.g., collection, storage, use, or disclosure).
  • Controller: The legal entity that determines the purposes and means of processing.
  • Processor: A party that processes data on behalf of the controller.
  • Data Subject: The individual whose personal data is being processed.
  • Consent: A freely given, specific, informed, and unambiguous indication of the data subject’s wishes.
  • Filing System: A structured set of personal data accessible based on specific criteria.

Our Data Protection Principles:

We are committed to:

  • Lawful, fair, and transparent data processing
  • Processing only for specified, legitimate purposes
  • Data minimization
  • Data accuracy and up-to-date records
  • Limited retention periods
  • Appropriate data security measures
  • Full accountability and documentation

III. How We Process Your Personal Data

We collect and process personal data only as needed and based on appropriate legal grounds.

A. When You Use Our Website

Legal Basis: Legitimate interest

  • Cookies: Our website uses only strictly necessary cookies to ensure functionality and security. These do not require your consent and do not collect identifiable personal data. If you block these cookies, certain features may not work properly.
  • Website Security & Analytics: We monitor:
    • IP address
    • Date and time of visit
      for the purposes of ensuring security and improving service.

We do not use third-party tracking, analytics, or marketing cookies.


B. When You Make an Online Transfer Booking

Legal Basis: Contract

We collect the following information via our transfer booking form:

  • Name and surname
  • Contact email and phone
  • Pickup and drop-off addresses
  • Transfer date
  • Payment details (processed by certified platforms; we do not store them)

C. When You Use Our Services (Clients)

Legal Basis: Contract, Legal Obligation

Depending on the services used (e.g., airline tickets, accommodation, insurance), we may process:

Data Category Details
Identification Name, surname, gender, date/place of birth, citizenship, passport number, personal identification number
Contact Info Email address, phone number
Travel Data Transfer and accommodation details, travel dates
Insurance Info Insurance type, coverage region
Payment Info Electronic payment details (not stored by us)
Special Requests Accommodation or travel-related needs

IV. Who Has Access to Your Data?

Your personal data is accessed only by authorized staff at CTS Skopje. When necessary, we may share your data with:

  • Transfer providers
  • Certified payment processors
  • Airlines and railway companies
  • Hotels and accommodation providers
  • Insurance providers
  • Government institutions (e.g., PIOM, FZ, PRO), if legally required
  • Banking institutions and partners under contract
  • Courts or law enforcement (only if legally obligated)

International Data Transfers:
We may transfer your data to other countries only when necessary to deliver your requested services. In such cases, we use appropriate safeguards (e.g., contractual clauses or adequacy decisions) to protect your data.


V. How We Protect and Store Your Personal Data

We implement technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, or destruction.

  • Access is granted only to authorized staff or contracted processors.
  • We never sell or rent your personal data to third parties.
  • We store data only as long as necessary, based on legal requirements and service needs.

Retention Periods:

  • Clients: Up to 10 years after termination of the service agreement, or for the duration of the contract.
  • Booking Records: As required by applicable laws and regulations.

VI. Your Rights Regarding Your Personal Data

You have the right to access, control, and manage your personal data. To exercise your rights, contact our DPO at: dpo@congresstravelservice.com

Right Description Response Time
Right to Be Informed Know how and why we process your data At the time of data collection
Right to Access Request a copy of your personal data Within 30 days (up to 90 if complex)
Right to Rectification Correct inaccurate or incomplete data Within 15 days
Right to Erasure Request deletion of your data (in certain cases) Within 30 days
Right to Restrict Processing Temporarily pause data processing Within 30–90 days
Right to Data Portability Receive your data in a machine-readable format Within 30–90 days
Right to Object Object to processing based on legitimate interest Within 30–90 days
Right to Withdraw Consent Stop processing based on prior consent Immediately

We may request additional information to verify your identity before fulfilling your request.


VII. Filing a Complaint

If you believe that your personal data is being processed unlawfully, you have the right to file a complaint with the national supervisory authority:

Agency for Personal Data Protection
Address: Blvd. Goce Delchev no. 18, 1000 Skopje, North Macedonia
Email: info@privacy.mk
Website: www.azlp.mk


Questions?

For questions related to this Privacy and Cookies Policy or how we handle your personal data, please contact us at:
📧 dpo@congresstravelservice.com