Public document
e-Kabineti Privacy Policy
This policy explains the processing and protection of data in the Capital City’s project, budget and reporting management platform.
1. Data processed
The platform processes account data such as name, username, email, status, role and directorate; project, objective, task, progress and risk data; as well as allocations, commitments, reservations, expenditures and budget changes.
Uploaded documents, workflow decisions, imports, notifications, audit trails, correlation IDs, action times and technical information required for security and diagnostics are also processed.
2. Purposes of processing
Data is used for project planning and monitoring, budget administration, execution control, approvals, risk management, executive reporting, controlled imports, institutional notifications, audit and troubleshooting.
Data is not used for advertising and is not sold. Reports must be used only for official purposes and under institutional authorizations.
3. Access, roles and recipients
Access is restricted by role and directorate scope. The System Administrator has global access for administration, audit and troubleshooting. Other users see only modules and data allowed by their active role.
Microsoft Graph receives only data needed to send a notification, such as email address, subject and content. Infrastructure providers may process data only for hosting, security, backup and technical operation.
4. Technical and organizational security
The SQL Server connection uses the dedicated port and TLS. Credentials are stored in private configuration outside the document root. Passwords are hashed and authentication accepts only email or username.
The platform uses protected sessions, HttpOnly/SameSite cookies, CSRF, security headers, server-side authorization, private documents, file scanning, audit and administrator-visible logs.
5. Retention and integrity
Data is retained as required by institutional, financial, audit, archival and security procedures. Financial records and audited actions are not silently changed or deleted.
Backups, logs and private documents are protected by restricted access. When the applicable period ends, data is deleted, anonymized or archived under the approved procedure.
6. Rights and contact
Subject to applicable rules, a person may request access, correction or clarification of their data. Legal and institutional restrictions may require retention of financial, administrative, audit or security records.
Privacy requests and incidents are submitted through the official channels of the Capital City of Prishtina. Identity and authorization may be verified before information is disclosed.