Privacy
What we collect, why, how long we keep it, and what you can ask for.
Who we are
KASP is an academic press based in Pristina. This page explains what we collect when you use the catalogue, read a book or buy a copy, why we collect it, and how long we keep it.
What we collect
We collect only what the thing you asked for requires. There is no analytics, no third-party tracker, and nothing is sold to anyone.
When you create an account
Your email address and a hashed password. The address is how we reach you about an order and how you recover access; the password is never stored readably.
When you read a book
We store where you left off, so you can continue from the same place on another device. We also record which account opened which chapter — our licence agreements require it, and it is used for nothing else.
How long we keep it
Reading records are kept for as long as your access to the title lasts, plus the reporting period the contract requires. The table below states it exactly.
When you search the catalogue
We store the search text and how many results it returned, unlinked from your account. It is for one purpose: a search that finds nothing is usually something the catalogue should have had.
How long we keep it
Searches are kept in aggregate and cleared periodically. They contain no email address, no full IP address and no name.
Storing your data
Data is stored inside the European Union. Audit and content-access logs are append-only: once written they cannot be altered or deleted, including by us. That is a protection for you and an obligation to our licensors at the same time.
Your rights
You can ask for a copy of your data, or for it to be erased, from your account page. We answer within one month.
Access to your data
The export contains your account, your orders, the access granted to you, your consents and your reading records — everything that carries your name.
Erasure
Erasure pseudonymises your account in place. It does not remove the append-only logs above, because they cannot be removed — but after erasure they no longer lead back to you. The table below states exactly what survives.
Who else sees it
The payment provider sees what it needs to take the payment, and nothing of your reading history. Licensors receive aggregate sales reports, never reader names. Nobody else.
Changes to this policy
Every version of this page carries its own number, printed at the foot. The consent you gave refers to one exact version, so you can always see the text you agreed to.
| How long | What and why |
|---|---|
| 30 days | Expired or closed sessions are deleted after 30 days. Until then they let you see where you were signed in and sign out everywhere. |
| 30 days | Records of sent email are deleted after 30 days — long enough to investigate a message that did not arrive. |
| 180 days | Access logs are kept 180 days and the identifiers in them are hashed, so they do not trace back to you. They exist for abuse detection and rightsholder reporting. |
| 365 days | Searches are kept for a year, with no name and a hashed session, so we know what readers look for and do not find. |
| Kept permanently | Where you have reached in a book is kept for as long as you have an account. Closing the account removes it. |
| Kept permanently | The audit log is never deleted. It records staff actions — not your activity — and is what makes what happened to contracts, refunds and access verifiable. |
| Kept permanently | Consents and their withdrawals are never deleted: they are the proof of what you agreed to and when you withdrew it. Deleting them would remove the evidence that protects you. |
| Kept permanently | Requests about your data are kept, as proof that we answered and when. |
Policy version: 2026-09-16-draft