Privacy Policy
PRIVACY POLICY
TEG.AL
Last updated: 27.07.2026
1. Who we are
This Privacy Policy explains how TEG ("TEG", "we", "us", "our") collects, uses, stores and protects the personal data of users who visit www.teg.al and, where applicable, use membership, loyalty club, application, Webforms or Mall Performance Cloud ("MPC") functionalities provided by Placewise Group in connection with our services.
For any questions about this Privacy Policy or your personal data, you may contact us at:
Tirana East Gate
Adress: Tiranë, Farkë, Lundër, Qendra Tregtare TEG, Rruga Nacionale Tiranë- Elbasan
Email: e.minga@teg.al
Phone:+355 69 706 6829
2. What data we collect
When you use our website or the relevant functionalities, we may collect the following categories of personal data:
2.1 Technical, security and website usage data
- IP address, device type, browser, visit time, pages visited and similar technical information;
- data relating to the operation, performance, maintenance and protection of the website;
- data collected through cookies or similar technologies, depending on your preferences and applicable legal requirements.
2.2 Data processed through Mall Performance Cloud / Placewise
When you register as a member or use membership, loyalty club, application, Webforms or similar services supported by the MPC platform, the following data may also be collected and processed:
- email address;
- mobile phone number;
- name and surname;
- date of birth;
- consents given, including, as applicable, sms_marketing, email_marketing, dmp_profiling and cookie_tracking;
- the date and version of the privacy policy in force at the time consent was given;
- data generated during the membership, such as application activity, receipt scanning, rewards used or other similar information relating to the use of the programme.
We do not intend to collect special categories of personal data through the website or platform unless this becomes necessary and is carried out in accordance with applicable legal requirements.
3. Why we use your data
We use personal data for the following purposes:
- to respond to your requests or questions submitted through the website;
- to communicate with you regarding TEG services, activities, offers or information;
- to manage registration, membership, the loyalty club, benefits, rewards and MPC-related functionalities, where applicable;
- to manage your consents and preferences, including marketing communications, profiling or cookie tracking, where your consent is required;
- to send transactional communications and, where you have consented, marketing communications;
- to maintain, monitor and improve our website, application, platform and services;
- to ensure the security of our website, platform and systems and to prevent unauthorised use;
- for statistical analysis and aggregated or anonymised reporting;
- to comply with our legal, contractual and operational obligations.
4. Legal basis for processing
We process your personal data in accordance with applicable data protection legislation, including Law No. 124/2024 "On Personal Data Protection".
Depending on the case, processing may be based on:
- your consent, particularly for non-essential cookies, marketing communications, profiling or tracking, where required by law;
- our legitimate interest in managing the website, responding to requests, improving services and ensuring the security of the website and platform;
- taking steps prior to entering into a contractual relationship or performing a contractual relationship, for example in relation to membership or related benefits;
- compliance with legal obligations.
5. Cookies, analytics tools, plug-ins and other tracking tools
Our website uses cookies that are necessary for its operation and may use functional, analytics, security or similar cookies to monitor the performance, operation and security of the website.
In the current configuration, the website uses the following tools, plug-ins and technologies:
- Google Analytics / Site Kit by Google;
- Contact Form 7;
- Wordfence Security;
- WP 2FA;
- Really Simple SSL;
- Popup Builder;
- Polylang;
- technical, functional and security cookies for the operation and protection of the website.
For the MPC / Placewise platform, the available information does not contain a full and specific list of all cookies, analytics tools, plug-ins or tracking scripts. However, the platform provides for the cookie_tracking consent, which controls whether tracking cookies and other client-side identifiers may be used for the member.
Where data is sent to advertising partners, it is sent in hashed and anonymised form, using only one-way identifiers and not directly identifying data. The transactional and marketing messaging system keeps data only for the duration of processing, after which it is cleaned up.
Non-essential cookies will be used only if you give your consent, where required by law. You may change your cookie preferences at any time through the options provided on our website, the relevant application or through your browser settings.
6. Where data is stored and who has access
6.1 MPC / Placewise platform
Data processed through the MPC platform is stored in the following infrastructure:
- the operational databases of the MPC platform, hosted on Amazon Web Services (AWS);
- AWS regions located within the European Union / European Economic Area (EEA), by default;
- within an Amazon Virtual Private Cloud (VPC), which is not reachable from the public internet;
- encrypted backups in a separate multi-zone location with controlled access;
- transfers outside the EEA, if any, protected by Standard Contractual Clauses approved by the European Commission or other legally applicable mechanisms.
Access to data in the MPC platform is restricted according to the principle of least privilege and on a need-to-know basis. Access to raw data warehouse tables is reserved for a very limited number of named technical roles. Authentication is carried out through corporate single sign-on and multi-factor authentication (MFA) for privileged actions. Access changes and employment termination trigger access revocation, all access is logged for audit purposes, and database access is reviewed periodically.
7. Who we share data with
We may share your personal data only where necessary, with:
- service providers for hosting, technical maintenance, security and IT support;
- Placewise Group or other MPC platform providers/operators, where membership, loyalty club, application or Webforms services are supported by this platform;
- providers of transactional or marketing communication services, in accordance with your preferences and consents;
- advertising partners, only in hashed, anonymised or aggregated form, where applicable and in accordance with the law;
- group companies, where necessary to handle your request or administer the services;
- public authorities, where required by law.
We do not sell your personal data.
8. International transfers
In some cases, your data may be processed by service providers located outside Albania. For the MPC platform, data is stored by default in AWS regions within the European Union / EEA. If a transfer outside the EEA or the relevant jurisdiction takes place, such transfer must be protected by Standard Contractual Clauses approved by the European Commission or other applicable data protection mechanisms.
TEG takes measures to ensure that the transfer and processing of personal data is carried out in accordance with applicable data protection requirements.
9. How long we keep your data and how it is deleted
9.1 MPC / Placewise platform
For data processed through the MPC platform, the following retention and deletion rules apply:
- data is kept for as long as the membership remains active;
- members with no activity for 24 months are automatically deleted under the inactivity rule;
- backups are retained in accordance with the documented backup retention policy; the specific period should be set by the Controller;
- system logs are retained in accordance with the documented log retention policy;
- anonymised data in the data warehouse may be retained for statistical purposes even after the member has been deleted.
The automatic deletion process is carried out through a scheduled daily job that identifies members who have passed the threshold of 24 months without activity. If configured, a warning message may be sent to the member before deletion, giving the member the opportunity to reactivate the account. If no new activity occurs, identifying data is deleted from the operational database and the process is logged for audit purposes.
Previous backups expire according to the relevant policy and restoring a backup should not restore deleted data. The member identifier can no longer be resolved after deletion and is never reused. Remaining data in the data warehouse is considered anonymised under Recital 26 of the GDPR.
The member may leave the loyalty club at any time through the self-service interface, including the mobile application or Webforms, or by sending a request to privacy@placewise.com. After confirmation of the opt-out, identifying data is deleted according to the same technical procedure as inactivity-based deletion and the member is informed that the request has been completed.
10. How we protect your data
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or misuse.
These measures may include, as applicable, access restriction, strong authentication, encryption of backups, storage in controlled environments, access logging, periodic access reviews and other security measures appropriate to the nature of the processing.
However, no online system can guarantee absolute security.
11. Your rights
You have the right to request:
- access to your personal data;
- correction of inaccurate data;
- deletion of your data;
- restriction of processing;
- objection to processing;
- data portability, where applicable;
- withdrawal of consent, where processing is based on consent.
To exercise your rights in relation to TEG, you may contact us at: e.minga@teg.al For requests directly related to your account or membership in the MPC / Placewise platform, you may also use the self-service functionalities of the application or Webforms, or contact privacy@placewise.com , as applicable.
You also have the right to lodge a complaint with the Commissioner for the Right to Information and Personal Data Protection.
12. Children's Privacy
The Company’s services are not intended for children under the age of 16 without the consent or authorization of a parent or legal guardian, except where a lower age threshold is expressly permitted by applicable Albanian legislation.
The Company does not knowingly collect children's personal data unlawfully.
If we become aware that personal data relating to a child has been collected without appropriate authorization, the Company will take appropriate measures to delete such data.
13. Changes to this Privacy Policy
TEG may update this Privacy Policy from time to time. The latest version will always be published on www.teg.al or in the relevant channel where the service is provided.
Continued use of the Company's services following the publication or communication of the changes shall constitute acknowledgment of the updated Policy, to the extent permitted by applicable law.