Privacy Policy

Last updated: 15 July 2026

This Privacy Policy explains which personal data are collected and processed through the vesnici.mk online platform (hereinafter: “the platform”), for what purposes, on what legal basis, and which rights you have as a data subject. The Policy is drawn up in accordance with the Law on Personal Data Protection (“Official Gazette of the Republic of North Macedonia” no. 42/20, as amended).

1. Controller of personal data

The controller of the personal data processed through the platform is the National and University Library “St. Clement of Ohrid” – Skopje (hereinafter: “the Library”), with its seat at Blvd. “Goce Delčev” no. 6, P.O. Box 566, Skopje. For questions regarding personal data protection you may contact: vesnici@nubsk.edu.mk.

2. Which personal data we process

2.1. Data you provide upon registration

When creating a user account, the following are collected: first and last name, e-mail address, number of the membership card issued by the Library, and a password. The password is stored exclusively in cryptographically protected (hashed) form and no one, including the Library, can see it. The date and time of acceptance of the Statement on the Use of Digital Objects are also recorded.

2.2. Data from the contact form

When you contact us through the form on the “Contact” page, the following are processed: name, e-mail address and the content of the message. To protect against abuse (spam), the IP address from which the message was sent is also temporarily recorded.

2.3. Data generated while using the platform

  • a record of recently viewed publications (which publication you opened and when), used exclusively to display the “Recently Viewed” overview on your user profile; these records are automatically deleted after 90 days;
  • standard server logs (IP address, browser type and version, time of access), used exclusively for security, abuse detection and technical maintenance.

3. Purposes and legal basis of processing

  • creating and maintaining a user account and providing access to the digitised publications — performance of a contractual relationship, i.e. provision of the requested service;
  • verification of Library membership when approving the account — legitimate interest of the Library and the Rulebook on membership and use of services;
  • responding to messages sent through the contact form — legitimate interest;
  • security of the platform, prevention of abuse and limitation of unauthorised login attempts — legitimate interest;
  • fulfilment of the Library’s legal obligations.

The platform performs no automated individual decision-making or profiling.

4. Cookies

The platform uses strictly necessary cookies only: session cookies for logged-in users and a cookie remembering the selected language. No analytics, marketing or third-party cookies are used. As only necessary cookies are involved, no separate consent is required for them.

5. To whom we disclose the data

  • The data are stored on a server located in the Republic of North Macedonia and are not transferred to third countries.
  • An e-mail service is used for sending system messages (registration confirmation, account approval, password reset), whereby only your e-mail address is processed.
  • The “Contact” page embeds a map from OpenStreetMap; when it loads, your IP address is transmitted to the servers of the OpenStreetMap Foundation. The map sets no cookies.
  • Should online payment be enabled in the future, payment card data will be processed exclusively by an authorised bank or payment processor; the platform has no access to them.
  • Data may be disclosed to competent state authorities only where required by law.

Personal data are never sold or handed over for marketing purposes.

6. Retention periods

  • user account data — for as long as the account exists; upon its termination the data are deleted or irreversibly anonymised;
  • the record of the accepted Statement on the Use of Digital Objects — for as long as the account exists, and longer where necessary, as evidence of the obligations undertaken;
  • the record of recently viewed publications — 90 days from access, after which it is automatically deleted;
  • messages from the contact form — no longer than 12 months from receipt;
  • server and security logs — no longer than 12 months.

7. Data security

Access to the platform is encrypted (HTTPS). Passwords are stored exclusively in hashed form. Technical and organisational measures are in place to protect against unauthorised access, including restricted administrative access, intrusion prevention systems and regular backups.

8. Your rights

Under the Law on Personal Data Protection you have the right to: access your personal data, rectify inaccurate data, erasure, restriction of processing, data portability, as well as the right to object to processing. Requests may be sent to vesnici@nubsk.edu.mk; we will respond without undue delay and at the latest within one month of receiving the request.

If you believe that the processing of your personal data is not in accordance with the law, you have the right to file a request for establishing a violation of the regulations with the Personal Data Protection Agency (azlp.mk).

9. Changes to this Policy

The Library may amend this Policy. The current version is always published on this page, with the date of the last update indicated. Registered users will be duly notified of substantial changes.

10. Contact

National and University Library “St. Clement of Ohrid” – Skopje
Blvd. “Goce Delčev” no. 6, P.O. Box 566, Skopje
E-mail: vesnici@nubsk.edu.mk