This Policy explains what personal data we collect through the website {{site}}, why we process it, how long we keep it and what rights you have. We take the protection of your personal data seriously and process only what we actually need.
1. Who processes your data
The data controller within the meaning of Regulation (EU) 2016/679 (“GDPR”) is:
- {{company}}
- Company ID (EIK): {{eik}}
- Address: {{address}}
- Telephone: {{phone}}
- E-mail for data protection enquiries: {{dpo_email}}
We are not required to appoint a data protection officer, but all enquiries on the subject are handled at the address above.
2. What data we collect
2.1. Data you provide to us:
- When you use the contact form: your name, e-mail address, telephone (optional) and the content of your message.
- When you place an order: full name, e-mail, telephone, company name, company ID/VAT number, billing address, city, post code and any order notes.
- In correspondence: anything you send us by e-mail or tell us by telephone about your campaign.
2.2. Data collected automatically:
- technical data about your visit — IP address, browser type and version, operating system, referrer, date and time;
- identifiers from cookies and similar technologies — see the Cookie Policy;
- aggregated usage statistics, if you have consented to analytics cookies.
2.3. Payment-related data. When you pay by card, your card details are entered directly on our payment provider’s page. We never receive, see or store your card number, expiry date or security code. We receive only the outcome of the payment, a transaction reference and the amount.
2.4. We do not knowingly collect special categories of personal data (health, ethnic origin, political opinions and so on). Please do not include such information in the free-text fields of your messages.
3. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Replying to an enquiry sent through the contact form | Name, e-mail, phone, message | Art. 6(1)(b) — steps prior to entering into a contract; for general questions, Art. 6(1)(f) — legitimate interest in replying |
| Accepting and performing an order for advertising services | Contact and billing details, order contents | Art. 6(1)(b) — performance of a contract |
| Processing payment | Transaction reference, amount, status, e-mail | Art. 6(1)(b) — performance of a contract |
| Issuing and retaining accounting documents | Billing details | Art. 6(1)(c) — legal obligation (Accountancy Act, VAT Act) |
| Keeping your cart and language preference | Technical identifiers in cookies | Art. 6(1)(f) — legitimate interest in a working website |
| Traffic analysis | Identifiers, on-page behaviour | Art. 6(1)(a) — your consent |
| Displaying embedded maps and external content | IP address, identifiers | Art. 6(1)(a) — your consent |
| Preventing abuse and securing the site | IP address, technical logs | Art. 6(1)(f) — legitimate interest |
| Establishing, exercising or defending legal claims | All relevant data | Art. 6(1)(f) — legitimate interest |
4. Who we share data with
We do not sell or rent your personal data. We disclose it only to the following categories of recipients, and only to the extent necessary:
- Hosting provider — stores the website and its database;
- Payment provider — processes card payments and performs fraud-prevention checks;
- E-mail service provider — delivers transactional e-mails such as order confirmations;
- Accountancy firm — for tax and accounting obligations;
- Web analytics provider — only where you have consented;
- Competent public authorities — where we are legally obliged to disclose.
We have data processing agreements in place under Article 28 GDPR with all of our processors.
5. Transfers outside the EU
As a rule your data is stored within the European Economic Area. Some of our providers (for example for web analytics) may process data outside the EEA. Where that happens, the transfer is based on a European Commission adequacy decision or on standard contractual clauses, accompanied by supplementary technical measures.
6. How long we keep your data
| Category | Retention period |
|---|---|
| Contact form enquiries | Up to 12 months from the last correspondence |
| Order and contract data | 5 years after the contract ends (general limitation period) |
| Accounting and tax documents | 10 years under the Bulgarian Accountancy Act |
| Payment references | 10 years, as part of the accounting records |
| Cart contents | 7 days from the last activity |
| Record of your cookie consent | 6 months |
| Technical security logs | Up to 12 months |
Once the relevant period expires, the data is deleted or irreversibly anonymised.
7. Your rights
Under the GDPR you have the right to:
- Access — obtain confirmation of whether we process your data and a copy of it;
- Rectification — have inaccurate or incomplete data corrected;
- Erasure (“right to be forgotten”) — where the grounds in Article 17 GDPR apply;
- Restriction of processing — in the cases set out in Article 18 GDPR;
- Data portability — receive your data in a structured, machine-readable format;
- Object — to processing based on legitimate interests;
- Withdraw consent — at any time, without affecting the lawfulness of processing before withdrawal;
- Lodge a complaint with a supervisory authority — see section 11.
The right to erasure cannot be exercised over data we are legally required to retain, such as accounting documents.
To exercise a right, write to us at {{dpo_email}}. We reply within one month; for complex requests this may be extended by a further two months, and we will tell you if that happens. The service is free of charge; for manifestly unfounded or excessive requests we may refuse or charge a reasonable fee.
8. Automated decision-making
We do not carry out automated decision-making that produces legal effects for you, nor profiling with such an effect. Our payment provider may apply automated fraud-prevention checks when processing card payments.
9. Data security
We apply appropriate technical and organisational measures, including: encrypted connections (HTTPS/TLS) for all communication with the site; access on a need-to-know basis; regular software updates; backups; and processing card payments exclusively through a PCI DSS certified provider.
No system is entirely secure, however. Should a security breach occur that is likely to result in a high risk to your rights, we will notify you without undue delay.
10. Children’s data
Our services are aimed at business clients and are not intended for anyone under 18. We do not knowingly collect children’s data. If we identify such data, we delete it.
11. Questions and complaints
If you have a question or believe your rights have been infringed, please contact us first at {{dpo_email}} — we will try to resolve the matter quickly.
You also have the right to lodge a complaint with the supervisory authority:
- Commission for Personal Data Protection
- 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
- Telephone: +359 2 915 3 518 · E-mail: kzld@cpdp.bg · Website: cpdp.bg
12. Changes to this Policy
We may update this Policy following changes to our activities, the technologies we use or the law. The current version is always available on this page. We will notify you appropriately of any material change.
Last updated: {{updated}}