Effective 6 October 2026 · Българска версия
This is an English translation provided for convenience. In case of discrepancy, the Bulgarian version prevails.
This policy explains what personal data we collect, why, on what legal basis, who we share it with, how long we keep it and what rights you have. We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act.
We are not required to appoint a Data Protection Officer. For all data protection matters, please write to [email protected].
To deliver our services we process data about the building — cadastral identifier, area, year of construction, structure, data from public registers (cadastre/KAIS, property register). Most of this is not personal data, but where it relates to an identifiable individual (for example an owner) it is treated as personal data under this policy.
We do not intentionally collect special categories of data (health, ethnicity, political opinions, etc.). Please do not send us such data through our forms.
| Purpose | Legal basis (GDPR) |
|---|---|
| Responding to enquiries, preparing offers, free consultation | Art. 6(1)(b) — pre-contractual steps |
| Performing the contract — survey, technical passport, energy certificate, design | Art. 6(1)(b) — performance of a contract |
| Invoicing, accounting, tax reporting | Art. 6(1)(c) — legal obligation |
| Filing documentation with authorities and funding programmes on your instruction | Art. 6(1)(b) and Art. 6(1)(c) |
| Newsletter and marketing messages | Art. 6(1)(a) — your consent |
| Website security, abuse prevention, technical logs | Art. 6(1)(f) — legitimate interest |
| Defending rights in disputes and complaints | Art. 6(1)(f) — legitimate interest |
Where the basis is consent, you may withdraw it at any time; this does not affect the lawfulness of processing before withdrawal.
We use only strictly necessary cookies and local storage in order to:
We do not use advertising or tracking cookies, remarketing pixels, or profiling for advertising. You can delete cookies in your browser settings; some features may then stop working correctly.
We do not sell or rent personal data. We share data only where necessary, with the following categories of recipients:
All of our processors act under written agreements containing confidentiality commitments and security measures.
Where we use Google services and interfaces (for example the Google Workspace / Gmail API, Google Calendar API, Google Drive API) to handle correspondence, scheduling and documents, access to that data is limited to what is necessary to provide our services.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
We process data primarily in Bulgaria and the European Economic Area. Some providers (for example Cloudflare and Google) may process data outside the EEA. In such cases transfers take place on the basis of an adequacy decision or the European Commission's standard contractual clauses, together with supplementary technical measures.
After the relevant period expires, data is deleted or anonymised.
Under the GDPR you have the right to:
To exercise your rights, write to [email protected] or call +359 879 472 874. We respond within one month; for complex requests this may be extended by a further two months, and we will inform you. We may ask for additional information to verify your identity.
Supervisory authority:
Commission for Personal Data Protection (CPDP)
2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria
Phone: +359 2 915 3 518 · Email: [email protected] · cpdp.bg
We do not carry out automated decision-making with legal effects for you, and we do not profile for advertising purposes. We use automated processing only to pre-sort and draft responses to enquiries; every communication sent to you is reviewed by a human.
We apply appropriate technical and organisational measures: encrypted connections (HTTPS/TLS), need-to-know access control, strong passwords and separate access rights, regular backups, storage of form submissions outside the public area of the website, and restricted access to accounting and contractual documentation.
No measure is absolute. In the event of a personal data breach likely to result in a high risk to you, we will notify you and inform the CPDP in accordance with Articles 33 and 34 GDPR.
Our services are intended for adults and legal entities. We do not knowingly collect data relating to persons under 18. If you believe such data has been sent to us, please let us know and we will delete it.
The website contains links to external sites (regulatory registers, Facebook, Google and others). This policy does not apply to them — please review their own policies.
We may update this policy. The current version is always published at this address with its effective date. For material changes we will notify you through a visible notice on the website or by email, where we have one.
Last updated: 6 October 2026