Privacy and Personal Data Protection Policy
Last updated: May 5, 2026
EntroLead / EntroLead Digital Agency (“EntroLead”, “we”, “us” or “our”) respects your privacy and the right of every individual to the protection of their personal data.
This Privacy Policy explains in a transparent manner how we collect, use, store, analyse, transmit and protect personal data when you:
- visit or use entrolead.com;
- submit a contact, consultation or Lead Generation form;
- submit an EntroLead form through Meta, Facebook, Instagram or other platforms;
- contact us via email, telephone, WhatsApp, social media or other communication channels;
- request information, a proposal, audit, consultation or services from EntroLead;
- become a client, representative of a client, partner, supplier or business contact;
- interact with our advertisements, website, landing pages or marketing and measurement systems.
This Policy applies to processing activities for which EntroLead acts as a data controller. Where EntroLead processes personal data on behalf of and under the documented instructions of a client, EntroLead may act as a data processor. Such processing may also be governed by applicable Data Processing Agreements and by the privacy policy or privacy notice of the relevant client.
1. Applicable Legal Framework
Depending on the location of the data subject and the nature of the processing, EntroLead processes personal data in accordance with applicable data protection and privacy laws, including, where relevant:
- Law No. 124/2024 “On Personal Data Protection” of the Republic of Albania;
- Regulation (EU) 2016/679 – General Data Protection Regulation (“GDPR”), where applicable;
- applicable Albanian legislation governing electronic commerce and electronic communications;
- applicable European Union and Member State rules governing electronic communications privacy, cookies and direct marketing;
- other mandatory laws, regulations or regulatory requirements applicable in the relevant jurisdiction.
We apply the principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability.
2. Identity and Contact Details of the Controller
Data Controller: EntroLead / EntroLead Digital Agency
Website: entrolead.com
Privacy Email:
info@entrolead.com
Telephone / WhatsApp:
+355 68 208 6930
Address: Tirana-Durrës Highway, Rruga Industriale Km1, Tirana, Albania
2.1 Privacy Contact Point
For questions, requests or complaints relating to privacy or the processing of personal data, you may contact us at info@entrolead.com.
2.2 European Union Representative
Where and to the extent that applicable European Union data protection law requires EntroLead to appoint a representative in the European Union, EntroLead will appoint such representative in accordance with the applicable legal requirements and will make the relevant contact details available.
3. Personal Data We May Collect
The categories of personal data we process depend on how you interact with EntroLead. We aim to collect only data that is adequate, relevant and limited to what is necessary for the applicable purpose.
3.1 Identification and Contact Data
- first name and last name;
- email address;
- telephone number and/or WhatsApp number;
- professional position or role within a business;
- company, clinic or organisation name;
- website or professional/social media profiles, where provided by you or relevant to your request.
3.2 Professional and Business Information
When you request Lead Generation, Performance Marketing, CRM, Automation, SEO or other services from EntroLead, we may collect information such as:
- type of business or clinic;
- industry or business sector;
- your role within the company or clinic;
- markets or countries from which you wish to generate customers or patients;
- marketing and sales objectives;
- existing Lead Generation and follow-up processes;
- information relating to CRM systems, sales teams or contact operators;
- marketing budget, where requested by us or voluntarily provided by you;
- your intended timeframe for starting a potential engagement;
- other information that you voluntarily provide in relation to your business.
3.3 Form and Enquiry Data
When you submit forms through our website, landing pages, Meta Lead Ads or other platforms, we may process the information entered in the form, responses to qualification questions, lead source, relevant campaign information, date and time of submission and the subsequent status of communications relating to the enquiry.
3.4 Communications Data
We may retain communications and information relating to:
- email correspondence;
- telephone communications and operational notes;
- WhatsApp messages;
- Facebook, Instagram or other social media messages;
- meetings and consultations;
- support or service requests;
- the history of our relationship with a client or prospective client.
Telephone calls are not automatically recorded by EntroLead unless you are informed beforehand and an appropriate legal basis exists for such recording.
3.5 Contractual, Financial and Administrative Data
If you become a client, supplier or partner, we may process information required for:
- preparing and administering contracts;
- billing and payments;
- accounting;
- tax and legal obligations;
- administration of the professional relationship;
- establishment, exercise or defence of contractual and legal rights.
3.6 Technical and Usage Data
When you visit our website or landing pages, certain technical data may be processed automatically, including:
- IP address;
- browser type and version;
- device type and operating system;
- online or device identifiers;
- referring URL and traffic source;
- pages visited and interactions with those pages;
- date, time and duration of visits;
- events and data associated with conversion tracking;
- technical information used for security, diagnostics and abuse prevention.
3.7 Cookies, Pixels and Similar Technologies
Depending on your preferences and the configuration of our website, we may use cookies, pixels, tags, server-side tracking, conversion APIs and similar technologies for website functionality, analytics, performance measurement, conversion attribution, advertising and remarketing.
These technologies may generate or process online identifiers and information about your interaction with our website and advertising.
4. Sources of Personal Data
We may obtain personal data:
- directly from you;
- through forms submitted on entrolead.com or our landing pages;
- from Meta, Facebook, Instagram or other platforms when you submit a Lead Form;
- from partners or referrals, where lawful;
- from clients or representatives of your organisation;
- from lawful professional or publicly available sources, where permitted by applicable law;
- through our CRM, analytics, advertising or automation platforms as a result of your interactions.
Where personal data is not obtained directly from you, we will comply with the applicable transparency and information obligations concerning the source and processing of such data.
5. Purposes for Which We Process Personal Data
EntroLead may process personal data for the following purposes:
- to respond to an enquiry, form submission or communication;
- to contact you following a request for information, a proposal or consultation;
- to assess your business needs and the suitability of our services;
- to prepare and provide requested proposals or commercial offers;
- to enter into and perform contracts;
- to provide Lead Generation, Performance Marketing, CRM, Automation, Tracking, SEO and related services;
- to administer relationships with clients and prospective clients;
- to organise follow-up and operational communications;
- to measure the performance of our website, landing pages and advertising campaigns;
- for analytics and improvement of the user experience;
- for conversion tracking and attribution;
- for remarketing and advertising, where the appropriate legal basis and/or required consent exists;
- for direct marketing communications, where permitted by law;
- to maintain the security of our website, infrastructure and systems;
- to prevent spam, fraud, abuse or unauthorised access;
- to comply with legal, tax, accounting and administrative obligations;
- to establish, exercise or defend legal claims and rights;
- for auditing, documentation and demonstration of legal compliance.
6. Legal Bases for Processing
We do not process personal data without an appropriate legal basis. Depending on the circumstances, processing may rely on one or more of the following legal bases:
| Purpose | Typical Legal Basis |
|---|---|
| Responding to forms, enquiries and consultation requests | Pre-contractual steps at your request and/or legitimate interests |
| Provision and administration of services | Performance of a contract |
| Billing, accounting, tax and administrative obligations | Compliance with a legal obligation |
| CRM management, organisation of prospects and follow-up on an active enquiry | Pre-contractual steps and/or legitimate interests |
| Security, anti-spam, fraud prevention and protection of systems | Legitimate interests and, where applicable, legal obligations |
| Analytics cookies, advertising, remarketing and other non-essential technologies | Consent, where required by applicable law |
| Electronic direct marketing | Consent or another basis expressly permitted under applicable law |
| Establishment, exercise or defence of legal claims | Legitimate interests and/or legal obligation |
Where processing is based on legitimate interests, we assess our interests or those of a third party against the interests, rights and fundamental freedoms of the relevant data subject.
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
7. Meta Lead Ads, Facebook and Instagram
EntroLead may use Meta Ads and forms integrated within Facebook or Instagram (“Instant Forms” / “Lead Ads”) to enable interested persons to request information, consultation or commercial proposals.
When you submit such a form, the information you choose to provide may be transmitted to EntroLead by the relevant platform. EntroLead may process this information to:
- contact you regarding your enquiry;
- understand your business requirements;
- qualify your enquiry;
- prepare a proposal or consultation;
- manage the lead within our CRM;
- measure campaign performance and conversions.
Advertising platforms may also process personal data in accordance with their own terms, privacy policies and applicable data protection roles. Depending on the specific service and processing activity, a platform may act as an independent controller, joint controller or processor under the relevant agreements and applicable law.
8. Direct Marketing
We may send information about our services, commercial offers or professional content only where we have a valid legal basis to do so.
Where applicable law requires prior consent for commercial communications sent by email, SMS or similar electronic channels, we will obtain the required consent before sending such communications.
You may object to or unsubscribe from direct marketing at any time and free of charge by:
- using an “unsubscribe” option where one is provided;
- emailing us at info@entrolead.com;
- informing us during a communication that you no longer wish to receive marketing materials.
Following such a request, we may retain a minimal amount of information in a suppression list solely for the purpose of ensuring that your marketing preference continues to be respected.
9. Cookies, Analytics, Pixel, CAPI and Advertising Tracking
9.1 Strictly Necessary Cookies
Cookies or similar technologies that are strictly necessary for the operation, security or delivery of a function explicitly requested by you may be used without consent where permitted by applicable law.
9.2 Analytics and Performance
With your consent, where required, we may use analytics technologies to understand how our website is used and to improve its performance, structure and user experience.
9.3 Advertising and Remarketing
With your consent, where required, we may use technologies provided by advertising platforms for:
- conversion measurement;
- attribution;
- audience creation;
- remarketing;
- advertising optimisation;
- campaign effectiveness measurement.
9.4 Server-Side Tracking and Conversion APIs
Depending on our technical configuration, EntroLead may use server-side tracking or Conversion API technologies to measure conversions and campaign performance.
Where transmission of information through such technologies legally depends on consent for advertising or tracking, the user's consent preference must also be respected for server-side transmissions and not solely for browser-based cookies.
9.5 Consent Management
Where our website uses non-essential cookies or similar technologies requiring consent, you should have the ability to:
- accept or reject the relevant categories;
- change your preferences;
- withdraw consent at any time.
10. CRM, Automation and Lead Processing
EntroLead uses CRM systems and automation processes to administer enquiries, prospective clients and client relationships.
These processes may be used for:
- registering a lead;
- removing duplicate records;
- segmenting leads by source or interest;
- assigning lead statuses;
- organising follow-up;
- sending requested or authorised communications;
- measuring funnel and conversion performance;
- performance reporting.
We may use automation to organise or operationally prioritise enquiries. Unless we expressly inform you otherwise and an appropriate legal basis exists, EntroLead does not intend to subject you to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.
11. Sensitive Data and Health Information
EntroLead's B2B website and general marketing forms are not designed to routinely collect special categories or sensitive categories of personal data.
Please do not send us health information, diagnoses, medical records or other sensitive information through standard contact or Lead Generation forms unless such information is specifically required, requested and supported by an appropriate legal basis.
Because EntroLead provides marketing services to clinics and healthcare businesses, in certain client projects EntroLead may process personal data on behalf of a healthcare client. In such cases:
- the relevant clinic or healthcare organisation will generally determine the purposes and legal basis of the processing;
- EntroLead processes such information in accordance with its contractual role and the documented instructions of the client;
- enhanced security and confidentiality measures may apply where required;
- this Privacy Policy does not replace the privacy information or privacy notice that the clinic is required to provide to its patients or leads.
12. When EntroLead Acts as a Processor for Clients
When providing Lead Generation, CRM, automation, tracking or marketing technology services, EntroLead may process personal data on behalf of a client.
In such cases, the roles and responsibilities of the parties may be defined in a contract or Data Processing Agreement (“DPA”), as appropriate.
Such agreements may address, among other matters:
- the subject matter, nature, purpose and duration of processing;
- the categories of personal data and data subjects;
- the obligation to process information only on documented instructions;
- confidentiality;
- technical and organisational security measures;
- the use of sub-processors;
- assistance with data subject rights;
- management of incidents and personal data breaches;
- deletion or return of data following termination of the services, where required.
13. Parties With Whom We May Share Personal Data
EntroLead does not sell or rent users' personal data as a commercial product.
However, personal data may be disclosed or made available to third parties where this is necessary, proportionate and lawful, including:
- hosting and cloud infrastructure providers;
- email and communications providers;
- CRM platforms;
- automation platforms;
- analytics and measurement providers;
- advertising platforms, including Meta or Google where used;
- security, anti-spam and technical maintenance providers;
- payment providers or financial service providers, where necessary;
- accountants, auditors, lawyers or other professional advisers;
- authorised subcontractors and partners with a legitimate need for access;
- public authorities, courts or regulatory bodies where disclosure is required by law.
Where a third party processes personal data on behalf of EntroLead, we require, where appropriate and legally required, suitable contractual, security and confidentiality safeguards.
14. Sub-Processors and Technology Providers
Due to the nature of marketing and technology services, the list of technical service providers used by EntroLead may change over time.
We aim to select providers that offer appropriate security measures and contractual commitments regarding the protection of personal data.
Where EntroLead acts as a processor for a client, the appointment or replacement of sub-processors will be managed in accordance with the applicable agreement with the client and applicable data protection law.
15. International Transfers of Personal Data
Because EntroLead operates from Albania and may use international technology providers or work with clients and individuals located in the European Union and other jurisdictions, personal data may be subject to international transfers.
Where personal data is transferred to a country that is not covered by an applicable adequacy decision, we use, where required, appropriate legal and contractual mechanisms, which may include:
- Standard Contractual Clauses (“SCCs”);
- standard clauses or mechanisms approved by the competent Albanian authority;
- Data Processing Agreements;
- transfer risk assessments;
- additional technical, organisational or contractual safeguards;
- other mechanisms recognised under applicable data protection law.
Where an international transfer requires specific legal safeguards, EntroLead will carry out the transfer only where the necessary legal basis and transfer mechanism are in place.
16. Data Retention
We do not retain personal data for longer than is necessary for the purpose for which it was collected, except where applicable law, contractual requirements or the protection of legal rights requires a longer retention period.
| Category | Typical Retention Period / Criteria |
|---|---|
| Contact forms, Lead Forms and proposal requests that do not result in a client relationship | Generally for up to 24 months following the last interaction where a legitimate business purpose continues to exist, unless earlier deletion is requested or a lawful reason requires longer retention |
| Prospective client information in CRM systems | For as long as a reasonable and lawful business relationship or business interest exists, subject to periodic review |
| Client and contractual information | For the duration of the contractual relationship and subsequently for periods required by law or necessary to protect legal rights |
| Invoices and accounting/tax records | In accordance with mandatory tax, accounting and commercial retention requirements |
| Technical and security logs | Generally for a limited period based on security requirements; they may be retained for longer where connected to an incident, dispute or legal claim |
| Cookies and analytics/advertising identifiers | According to the declared lifespan of the relevant technology and consent configuration, and no longer than necessary |
| Data processed on behalf of clients | In accordance with client instructions, the applicable DPA and relevant legal obligations |
| Marketing objection / suppression records | Minimal information may be retained for as long as necessary to ensure that your request not to receive marketing is respected |
At the end of the applicable retention period, personal data is securely deleted, anonymised or archived where a legal retention obligation continues to apply.
17. Data Security
EntroLead implements technical and organisational measures appropriate to the nature, context and risks associated with the processing of personal data.
Such measures may include, where appropriate:
- access controls and access restrictions;
- need-to-know and least-privilege access principles;
- strong authentication and account security measures;
- encryption during transmission and, where appropriate, at rest;
- backups and recovery measures;
- security monitoring and logging;
- system maintenance and security updates;
- controls applicable to sub-processors and technology providers;
- contractual confidentiality obligations for persons with access to personal data;
- incident response procedures;
- data minimisation and segregation where appropriate.
Although we implement reasonable and appropriate security measures, no information system or internet transmission can be guaranteed to be completely secure.
18. Personal Data Breaches
If a security incident constitutes a personal data breach, EntroLead will assess the incident and take the measures required under applicable data protection law.
Where legally required, we will notify the competent supervisory authority without undue delay and, where the applicable legal deadline is 72 hours, within that period after becoming aware of the breach, unless the law provides otherwise or notification is not required.
Where a personal data breach is likely to result in a high risk to the rights and freedoms of individuals, affected persons will be informed where and in the manner required by law.
19. Your Data Protection Rights
Depending on the law applicable to your circumstances, you may have the following rights:
- Right to information about how your personal data is processed;
- Right of access to personal data we hold about you;
- Right to rectification of inaccurate or incomplete personal data;
- Right to erasure where the applicable legal conditions are satisfied;
- Right to restriction of processing in certain circumstances;
- Right to object where processing is based on legitimate interests or in other cases provided by law;
- Right to object to direct marketing at any time;
- Right to data portability, where applicable legal conditions are met;
- Right to withdraw consent at any time where processing is based on consent;
- Rights relating to automated decision-making and profiling, where applicable;
- Right to lodge a complaint with the competent supervisory authority.
20. How to Exercise Your Rights
To exercise any of your data protection rights, you may submit a request to:
Email: info@entrolead.com
Please provide sufficient information regarding your request to enable us to identify and process it appropriately.
Where we have reasonable doubts concerning the identity of the individual making a request, we may request additional information solely to the extent necessary to verify identity and protect personal data from unauthorised disclosure.
We will respond within the timeframe established by applicable law, generally within 30 days. Where permitted by law and where a request is complex or a large number of requests have been received, the response period may be extended, in which case we will inform you of the extension and the reasons for it.
The exercise of data protection rights is generally free of charge. Where requests are manifestly unfounded, repetitive or excessive, applicable legal rules and limitations may apply.
21. Right to Lodge a Complaint
If you believe that the processing of your personal data does not comply with applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority.
In Albania, the supervisory authority is the Commissioner for the Right to Information and Protection of Personal Data.
Where the GDPR applies to the processing of your personal data, you may also have the right to lodge a complaint with the competent data protection authority in an EU/EEA Member State in accordance with the GDPR.
Contacting a supervisory authority does not limit any other administrative or judicial remedies that may be available to you.
22. Children and Minors
EntroLead provides B2B services and its services are not intended for children or persons under the age of 18.
We do not knowingly seek to collect personal data from children for marketing or sales purposes.
If you believe that a minor has provided personal data to us without the necessary legal basis or authorisation, please contact us at info@entrolead.com so that we can assess the situation and, where required, delete the relevant information.
23. Third-Party Links and Embedded Content
Our website may contain links, videos, widgets, maps, social media features or embedded content provided by third-party websites and services.
When you interact with such services, the relevant third party may process personal data in accordance with its own privacy policy.
EntroLead does not control the privacy practices of independent third-party websites or services, and we encourage you to review their privacy policies before providing them with personal data.
24. Changes to This Privacy Policy
We may update this Privacy Policy from time to time as a result of:
- changes in applicable laws or regulations;
- guidance issued by supervisory authorities;
- changes to our services;
- changes to the technologies we use;
- changes to how we process personal data.
The most recent version of this Privacy Policy will be published on this page and the “Last updated” date will be amended accordingly.
Where a change is material and applicable law requires a new notice or renewed consent, we will take the necessary steps to provide such notice or obtain such consent.
25. Contact Us
If you have any questions regarding this Privacy Policy, how EntroLead processes personal data or if you wish to exercise your data protection rights, please contact us:
EntroLead / EntroLead Digital Agency
Website: entrolead.com
Email: info@entrolead.com
Telephone / WhatsApp: +355 68 208 6930
Address: Tirana-Durrës Highway, Rruga Industriale Km1, Tirana, Albania
Transforming Marketing Budgets into Measurable Growth.