Petitions.com

Marrëveshja për Përpunimin e të Dhënave (MPD)

Përditësuar së fundi: 2026-07-14

Faqja e Nën-procesuesve e Përditësuar së Fundmi: 2026-07-04

Kjo MSA përshkruan kushtet sipas të cilave ne përpunojmë të dhënat personale në emrin tuaj.

Ky Marrëveshje për Përpunimin e të Dhënave (Marrëveshja) përshkruan detyrimet dhe kushtet sipas të cilave Petitions.com Group Oy (Ofruesi i Shërbimit) përpunon të dhënat personale në emër të autorit të peticionit (Autori i Peticionit ose Kontrolluesi i të Dhënave) në ofrimin e shërbimeve të pritjes së peticioneve online (Shërbimet).

Modifikimi i Kushteve

Ne rezervojmë të drejtën të ndryshojmë ose modifikojmë këto Kushte në çdo kohë pa njoftim të mëparshëm.

Përkufizimet dhe Rolitë

  • Ofrues Shërbimi: Petitions.com (Petitions.com Group Oy), duke vepruar si Përpunuesi i të Dhënave, përpunon të dhënat personale në emër të Kontrolluesit të të Dhënave sipas nevojës për të ofruar Shërbimet.
  • Kontrolluesi i të Dhënave: Autori i Peticionit, i cili përcakton qëllimet dhe mënyrat e përpunimit të të dhënave personale të mbledhura nga nënshkruesit e peticionit të tyre. Si autori i një peticioni të pritur në Petitions.com, ju konsideroheni Kontrollues i të Dhënave. Ju vendosni përmbajtjen e peticionit, çfarë kërkohet nga nënshkruesit, qëllimet për përpunimin e të dhënave të tyre personale dhe kohëzgjatjen për të cilën të dhënat personale ruhen. Petitions.com ofron një platformë online për krijimin dhe mbajtjen e peticioneve, duke lehtësuar rolin tuaj si Kontrollues i të Dhënave me autonominë për të formësuar mbledhjen dhe përdorimin e të dhënave të peticionit sipas objekteve dhe detyrimeve tuaja ligjore.

Fusha e Përpunimit

The Service Provider will process personal data solely based on the Data Controller's instructions and only as necessary to provide the Services, unless required to do so by Union or Member State law to which the Service Provider is subject. In such a case, the Service Provider will inform the Data Controller of that legal requirement before processing, unless that law prohibits it on important grounds of public interest. Qëllimi i aktivitetit të përpunimit është i kufizuar në hosting, menaxhimin dhe lehtësimin e peticioneve online.

As a Data Processor, the Service Provider does not erase signature data on its own initiative. Every erasure of signature data is carried out on the documented instructions of the Data Controller — whether given specifically or in advance through this Agreement.

The Data Controller's acceptance of this Agreement constitutes the Data Controller's documented instructions to the Service Provider, including the procedures for handling signatory erasure requests described below and any self-service tools the Service Provider makes available to signatories on the Data Controller's behalf.

Mbrojtja e të Dhënave

Ofruesi i Shërbimit angazhohet të zbatojë masa teknike dhe organizative për të siguruar sigurinë e të dhënave personale kundër aksesit të paautorizuar, humbjes ose dëmtimit.

Mbledhja e Ndaluar e të Dhënave

Ndalohet kërkimi i numrave të identifikimit personal (të tillë si numrat e identifikimit kombëtar) nga nënshkruesit.

Nënproçesorë

Ofruesi i Shërbimeve mund të angazhojë nënprodhues për të ndihmuar në ofrimin e Shërbimeve. Ofruesi i Shërbimit do të sigurojë që nënpunësit të përmbushin detyrimet për mbrojtjen e të dhënave në përputhje me këtë DPA. Ju pranoni dhe bini dakord që Ofruesi i Shërbimit të mbajë diskrecionin për të zgjedhur dhe zëvendësuar nënprocesorët sipas nevojës për të ofruar Shërbimet në mënyrë efikase.

Lista e nën-përpunuesve. (Përditësuar për herë të fundit: 2026-07-04)

Përgjegjësitë e Kontrolluesit të të Dhënave

Kontrolluesi i të Dhënave është përgjegjës për të siguruar që mbledhja, përpunimi dhe trajtimi i të dhënave personale përputhen me të gjitha ligjet dhe rregulloret e zbatueshme.

Identifikimi i Kontrolluesit të të Dhënave

Sipas Rregullores së Përgjithshme për Mbrojtjen e të Dhënave (GDPR), është e nevojshme që identiteti i kontrolluesit të të dhënave të jetë i deklaruar qartë. Dispozitat e mëposhtme janë bërë për autorët e peticioneve që përdorin faqen tonë të internetit:

Autorë Individualë të Peticioneve

Nëse ju, si individ, krijoni një peticion, ju kërkohet të jepni emrin tuaj të plotë ligjor. Kjo shërben si identifikimi juaj si kontrolluesi i të dhënave për qëllimet e Rregullores së Përgjithshme për Mbrojtjen e të Dhënave (GDPR).

Autorët Organizativë të Peticioneve

Nëse një peticion krijohet në emër të një organizate, duhet të sigurohet emri i plotë ligjor i organizatës. Për më tepër, organizata duhet të caktojë dhe të japë detajet e kontaktit të një përfaqësuesi përgjegjës për aktivitetet e përpunimit të të dhënave, si një Zyrtar për Mbrojtjen e të Dhënave (DPO) ose të ngjashëm.

Të Drejtat e Subjektit të të Dhënave

Kontrolluesi i të dhënave duhet të sigurojë që subjektet e të dhënave (nënshkruesit e peticioneve) të mund të ushtrojnë të drejtat e tyre sipas GDPR-së, si p.sh. e drejta për të aksesuar, korrigjuar ose fshirë të dhënat e tyre, ose për të ankuar te një autoritet mbikëqyrës.

Trajtimi i Kërkesave për Fshirjen e të Dhënave nga Subjektet e të Dhënave

The roles differ depending on the data in question. For personal data collected through petition signatures, the Service Provider acts as the Data Processor and the Petition Author acts as the Data Controller. For the Service Provider's own operational data — such as account information, technical logs, and contact-form messages — the Service Provider acts as an independent Data Controller.

Because the Service Provider acts only on the Data Controller's documented instructions, the procedure below constitutes the Data Controller's standing instruction for handling such requests, authorising the Service Provider to act without seeking separate approval for each request.

When a signatory asks the Service Provider to erase personal data connected to a signature, the Service Provider will, without undue delay, hide the signature from public view and make information about the erasure available to the Petition Author within the Services (for example, on a data-protection overview page and through an in-account indicator). The Service Provider is not required to send a separate email for each erasure. The Petition Author is given 14 days to review the request and to erase any copies of the signatory's personal data that they have downloaded, exported, printed, or otherwise stored outside the Services. The Petition Author may object to the erasure only where there is a lawful ground to continue processing the data (for example, the establishment, exercise, or defence of legal claims); a mere preference to retain the signature is not a valid ground. Any such objection must be made by contacting the Service Provider within that period, stating the lawful ground; the Service Provider does not provide an automatic means for the Petition Author to reverse an erasure. If the Petition Author does not object on such grounds within that period, the Service Provider will permanently delete the signature data from the active database. The Service Provider aims to complete the process within the one-month period required by the GDPR.

The Service Provider may also make available a self-service tool — such as a removal link in signature confirmation messages or on the petition page — allowing signatories to remove their own signature directly. Where such a tool is used, the Service Provider acts on the Data Controller's behalf under the documented instructions set out in this Agreement.

Personal data may persist in routine backups for a limited period after deletion from the active database. Such backups are not used for day-to-day processing and are overwritten on a rolling cycle, after which the data is permanently removed.

Regjistrat teknikë mund të përmbajnë të dhëna personale, siç janë adresat IP ose metadata e dërgimit të email-it. These logs are deleted within 30 days. Contact-form messages may be retained for up to 5 years for audit, security, and dispute-resolution purposes.

The Service Provider keeps a minimal record that an erasure was carried out (without retaining the erased personal data) in order to demonstrate compliance.

Handling Rectification Requests from Signatories

The right to rectification is handled on the same basis as erasure: as a Data Processor, the Service Provider does not alter signature data on its own initiative, but only on the Data Controller's documented instructions, including any self-service tool the Service Provider makes available to signatories on the Data Controller's behalf for correcting their own data.

Once a correction is made, the live signature list maintained within the Services reflects the corrected value. In accordance with the obligation to use up-to-date signature data, the Data Controller must rely only on a freshly retrieved copy and update or discard any outdated copies accordingly; the Service Provider is not required to disclose the previous (incorrect) value to the Data Controller.

The Service Provider may keep an internal record of the change (for example, the previous and new values, and the time of the change) for fraud prevention, security, and dispute-resolution purposes. This record is not made available to the Data Controller by default and is retained only for as long as necessary for those purposes.

Notifying Recipients

Where the Data Controller has disclosed signature data to any recipient (such as a decision-maker or other third party), the Data Controller is responsible, under Article 19 of the GDPR, for communicating any subsequent erasure or rectification of that data to each such recipient, unless this proves impossible or involves a disproportionate effort. The Service Provider's removal or correction of data within the Services does not discharge this obligation in respect of copies the Data Controller has shared outside the Services.

Përgjegjësia dhe Pajtueshmëria

Kontrolluesi i të dhënave duhet të jetë në gjendje të demonstrojë pajtueshmëri me GDPR, duke përfshirë edhe përgjigjen ndaj kërkesave të subjekteve të të dhënave lidhur me të dhënat e tyre personale.

Politika ose Njoftimi për Privatësinë

Një politikë privatësie e qartë dhe e aksesueshme ose një njoftim duhet të ofrohet, duke përshkruar se si përpunohen të dhënat personale, qëllimet e përpunimit dhe si subjektet e të dhënave mund të ushtrojnë të drejtat e tyre.

Njoftimi për Ndryshime

Autorët e peticioneve duhet të njoftojnë Petitions.com (Petitions.com Group Oy) për çdo ndryshim në statusin e tyre si kontrollues të të dhënave ose në detajet e kontaktit të përfaqësuesit të tyre.

Rishikimi Vjetor i Përpunimit të të Dhënave

Autori i Peticionit është i detyruar të kryejë një rishikim vjetor për të konstatuar nëse ende ekziston një arsye valide për vazhdimin e përpunimit të të dhënave personale të nënshkruesve. Ky rishikim duhet të vlerësojë nevojën dhe rëndësinë e të dhënave në lidhje me qëllimin e peticionit. Nëse Autori i Peticionit përcakton se nuk ka më një arsye të vlefshme për të vazhduar përpunimin e të dhënave, ai duhet të ndërmarrë hapat e duhur për të ndërprerë përpunimin dhe të nisë fshirjen e të dhënave në përputhje me ligjet e zbatueshme për mbrojtjen e të dhënave.

Use of Up-to-Date Signature Data

Before the Data Controller discloses signature data to any third party (such as a decision-maker or other recipient of the petition), or otherwise processes the data outside the Services — including contacting signatories by email — the Data Controller must retrieve a fresh copy of the signature list from the Services and use only that current version. Signatories may exercise their right to erasure at any time, and only the live list maintained within the Services reflects such erasures. The Data Controller must not rely on previously downloaded, exported, or printed copies for these purposes, and must securely discard outdated copies.

Ruajtja dhe Fshirja e të Dhënave

Në rast se Kontrolluesi i të Dhënave (autori i peticionit) shkel ndonjë kusht të Marrëveshjes për Përpunimin e të Dhënave (DPA), përfshirë, por jo të kufizuar te dështimi në kryerjen e një rishikimi vjetor të aktiviteteve të përpunimit të të dhënave ose dhënien e një justifikimi të vlefshëm për përpunimin e vazhdueshëm të të dhënave personale të nënshkruesve, Ofruesi i Shërbimit rezervon të drejtën të heqë ose fshijë të dhënat personale të lidhura me peticionin e tyre.

Kufizimi i Përgjegjësisë

Në asnjë rast përgjegjësia totale e Përpunuesit të të Dhënave ndaj Kontrolluesit të të Dhënave për të gjitha dëmet, humbjet dhe shkaktarët e veprimit, qoftë në kontratë, tort (përfshirë neglizhencën) apo ndryshe, nuk e kalon shumën totale të paguar nga Kontrolluesi i të Dhënave te Përpunuesi i të Dhënave sipas kësaj marrëveshjeje.

Legjislacioni i zbatueshëm

Ky Marrëveshje do të drejtohet nga ligjet e Finlandës.