MyFinn FINN CONSULTING DOOEL

Legal documents

Privacy Policy

How we collect, use and protect personal data in MyFinn

In force from 29/08/2026

This is a courtesy translation. In case of any discrepancy, the Macedonian version prevails. Open the Macedonian version →

Introduction

This Privacy Policy explains how FINN CONSULTING DOOEL processes personal data when providing accounting and related services and when the MyFinn platform (https://finn.mk) is used.

The policy is drawn up in accordance with the Law on Personal Data Protection ("Official Gazette of the Republic of North Macedonia" No. 42/2020 and 294/2021) and the secondary legislation adopted under it.

We take data protection seriously: we work with salaries, personal identification numbers, sick-leave records and bank accounts belonging to people who have never met us. So we collect only what we need, keep it only as long as we must, and grant access only to those staff who need it for their work.

Data controller

  • Name: FINN CONSULTING DOOEL
  • Registered office: 11-ti Oktomvri St. 13, 1300 Kumanovo, Republic of North Macedonia
  • Company registration number (ЕМБС): 7080638
  • Tax number (ЕДБ): 4017015529312
  • Email: info@finnconsulting.mk
  • Phone: +389 31 618 861 | +389 73 220 222

Data protection officer: Albina Zumeri Deari Privacy contact: info@finnconsulting.mk

When we are a controller and when a processor

Our role depends on whose data is being processed:

We are a controller for data we process for our own purposes:

  • data on platform users (accounts, access logs);
  • data on contact persons and representatives of our clients;
  • data processed to meet our own legal obligations (accounting, tax, anti-money-laundering);
  • data on our own employees and job applicants.

We are a processor for third-party data entrusted to us by a client for the purpose of delivering the service — above all the data of the client's employees and of the client's business partners. In that case the client is the controller, we act on the client's instructions, and the relationship is governed by a written data processing agreement, as the law requires.

This matters to the data subject: if you are employed by one of our clients, you exercise your rights primarily with your employer, and we are obliged to assist them in doing so. You may of course also contact us directly.

What personal data we process

Platform user data: name and surname, username, email address, phone number, role and permissions, password (stored only in cryptographically hashed form), time and IP address of logins, active sessions, records of significant actions in the system.

Client contact person data: name and surname, position, email, phone, signature and stamp where required for a document.

Data on employees and engaged persons of clients: name and surname, personal identification number (ЕМБГ), date and place of birth, gender, citizenship, home address, ID card number, level of education and occupation, employment details (position, working hours, start and end dates, length of service), salary, allowances, contributions and taxes, bank account, absence records (annual leave, sick leave, parental leave), data on dependants, and the documents containing this data (contracts, addenda, decisions, rulings, certificates, payslips).

Data on clients' business partners: name, ЕМБС/ЕДБ or ЕМБГ for natural persons, address, contact details, bank accounts, data on invoices issued and received and on payments.

Financial and accounting data: invoices, bank statements, payment orders, travel expenses, tax calculations and returns.

Data from public sources and registers: data obtained from the Central Registry, from the Public Revenue Office system and from other publicly available registers, for verifying and completing data on legal entities.

Technical data: IP address, device and browser type, date and time of access, pages opened in the system, cookies necessary for the platform to operate.

Data from public forms: when you submit data through a link (for example, for a travel order or to complete an employee's missing details), we process the data you enter in that form, including photographs of fiscal receipts where you upload them.

Special categories of personal data

To a limited extent we also process health-related data — specifically, data arising from absence due to illness or care for a family member (боледување), which is necessary in order to calculate the allowance and to file it with the competent authorities.

We process this data only in order to meet obligations and exercise rights arising from employment and social insurance, to the extent strictly necessary for that purpose, with restricted access and enhanced protective measures.

We do not process data on racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, or data on sexual life or orientation.

Purpose Legal basis
Delivering the agreed accounting service and managing the business relationship Performance of a contract
Payroll, contributions and tax processing; filings with УЈП, ПИОМ, ФЗОМ Legal obligation of the client, carried out through us as processor
Issuing and electronically delivering invoices Performance of a contract and legal obligation
Keeping books of account and retaining accounting records Legal obligation
Anti-money-laundering and counter-terrorist-financing measures Legal obligation
Granting and administering user access Performance of a contract and legitimate interest
System security, access logs, prevention of misuse Legitimate interest
Notifications about deadlines and the status of the client's matters Performance of a contract
Responding to questions and requests addressed to us Legitimate interest, or performance of a contract
Establishing or defending legal claims Legitimate interest
Processing for which no other basis exists Consent, which may be withdrawn at any time

Where processing is based on legitimate interest, that interest has been balanced beforehand against the rights and freedoms of the data subject. You have the right to object — see below.

Where processing is based on consent, withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Who we share data with

Data is not sold and is not passed on for anyone else's marketing purposes. We disclose it only where necessary for the service or where required by law:

  • State authorities and institutions — the Public Revenue Office (УЈП), the Pension and Disability Insurance Fund (ПИОМ), the Health Insurance Fund (ФЗОМ), the Central Registry, the State Statistical Office, inspection services, courts, the Financial Intelligence Office (УФР), and other competent authorities, within their statutory powers.
  • Banks and payment service providers — for executing payments and receiving statements.
  • The client-employer — where we act as a processor, the data is available to the client whose employees are concerned.
  • Technical service providers (processors) — server hosting and maintenance, email service, backup service. We have agreements in place with all of them imposing confidentiality and equivalent protection standards.
  • Legal and audit advisers — where necessary in order to establish or defend legal claims.

Within our organisation, access is limited to those employees who need it to carry out their duties, and only to the extent determined by their role in the system. All of them are bound by a confidentiality undertaking.

Where data is stored and international transfers

Data is stored on servers located in the Federal Republic of Germany, that is, in a member state of the European Union, with an established hosting provider. Backups are held with the same provider at a separate location, and at a secured location on the Company's premises.

We do not routinely transfer data to a third country outside the European Economic Area. Should such a transfer become necessary, it will be carried out only on one of the bases provided for in the Law on Personal Data Protection (an adequacy decision, standard contractual clauses, or another appropriate basis), and data subjects will be informed.

How long we keep data

Category Retention period
Accounting and tax documentation At least 10 years, in accordance with accounting and tax regulations
Employment documentation (contracts, decisions, payslips) In accordance with employment and pension insurance regulations; salary and length-of-service records are kept permanently where so prescribed
Anti-money-laundering documentation 10 years from the end of the business relationship or from the transaction
User account data For the duration of access and at most 12 months after it is revoked
Access logs and security logs Up to 12 months, except where needed to investigate an incident
Correspondence and requests Up to 3 years after the end of the communication
Data processed on the basis of consent Until consent is withdrawn

Once the period expires, data is securely deleted or anonymised. Where a document is required for ongoing court or administrative proceedings, it is retained until those proceedings conclude with final effect.

Your rights

Under the Law on Personal Data Protection, you have the right:

  • to be informed — to know who processes which data, why, and for how long;
  • of access — to obtain confirmation whether your data is being processed and a copy of it;
  • to rectification — to have inaccurate data corrected and incomplete data completed;
  • to erasure ("right to be forgotten") — where data is no longer needed, consent has been withdrawn, or processing is unlawful. This right does not apply where we are required by law to retain the data;
  • to restriction of processing — in the cases set out in law;
  • to data portability — to receive the data you have provided to us in a structured, commonly used and machine-readable format;
  • to object — to processing based on legitimate interest;
  • not to be subject to automated decision-making, including profiling;
  • to withdraw consent at any time;
  • to lodge a request for a finding of infringement with the Personal Data Protection Agency, and the right to judicial protection.

How to exercise your rights

You may submit a request:

  • by email to info@finnconsulting.mk;
  • in writing to 11-ti Oktomvri St. 13, 1300 Kumanovo, Republic of North Macedonia;
  • in person at the Company's premises.

To guard against misuse, we will verify your identity before acting on the request. We respond within 30 days of receiving it. Where a request is complex or where several requests are made, the period may be extended by a further 60 days; you will be notified of this, with reasons.

Acting on a request is free of charge. Where a request is manifestly unfounded or excessive, in particular where it is repetitive, we may charge a reasonable fee or refuse to act, giving written reasons.

If you are employed by one of our clients, please address your request to your employer as the controller; we will give them full support in handling it and, if you contact us directly, we will forward the request to them without delay.

Security measures

We apply the following technical and organisational measures:

  • encrypted connection (HTTPS/TLS) for all communication with the platform;
  • passwords are stored only in cryptographically hashed form — no password is retrievable in readable form anywhere in the system;
  • role-based access — each user sees only what they need; clients and employees see only their own data;
  • a limit on concurrent sessions per account;
  • PIN confirmation before particularly sensitive actions in the system;
  • an audit trail — who changed what, and when;
  • rate limiting of login attempts, to prevent password-guessing attacks;
  • regular backups in several locations, with verification that they are sound;
  • regular updates of server and application software;
  • confidentiality undertakings signed by all staff, and training on handling personal data;
  • physical protection of premises and data carriers.

Personal data breaches

In the event of a security breach likely to result in a risk to the rights and freedoms of data subjects, we will notify the Personal Data Protection Agency within 72 hours of becoming aware of it.

Where a breach is likely to result in a high risk, we will also inform the affected data subjects without undue delay, describing the nature of the breach, its likely consequences and the measures taken. Where we act as a processor, we notify the client-controller without delay.

Automated decision-making and profiling

The platform performs no automated decision-making producing legal effects or similarly significantly affecting individuals, and no profiling for such purposes.

The automatic calculations in the system (salaries, contributions, taxes, deadlines) are arithmetic operations following prescribed formulas; every result is reviewed and approved by an authorised person before it is used or filed.

Cookies

The platform uses a limited number of cookies, necessary for it to work and to remember your interface preferences. We use no analytics cookies, no advertising cookies, and no third-party tracking cookies.

The full overview is set out in the Cookie Policy.

Minors

The platform is not intended for minors and we do not collect their data directly. Data concerning minors (for example, an employee's dependants) is processed only where necessary to exercise rights arising from employment, tax relief or social insurance, and only to the extent prescribed by law.

Notice for job applicants

When you send us a job application, we process your data in order to conduct the selection process. If you are not selected, we keep the documents for at most one year, unless you ask for earlier deletion or agree to longer retention for future vacancies.

Changes to this policy

We update this policy when regulations, our processing practices or the platform's features change. Each new version is published on this page with the date it takes effect. For material changes we notify users by email or by an in-platform notice.

Contact and supervisory authority

For all questions concerning the processing of personal data:

  • FINN CONSULTING DOOEL, 11-ti Oktomvri St. 13, 1300 Kumanovo, Republic of North Macedonia
  • Email: info@finnconsulting.mk · Phone: +389 31 618 861 | +389 73 220 222

If you believe your rights have been infringed, you have the right to lodge a request for a finding of infringement with:

Агенција за заштита на личните податоци (Personal Data Protection Agency) Web: www.azlp.mk · Email: info@privacy.mk

This is a courtesy translation. The official version of this document is the Macedonian one; in the event of any discrepancy, the Macedonian text prevails.

FINN CONSULTING DOOEL · Dimitrie Tucovic br.13, 1300 Kumanovo, Maqedonia e Veriut
Questions about this document? info@finnconsulting.mk · +389 31 618 861 | +389 73 220 222