📞 0879 472 874  |  📧 [email protected]  |  Facebook ↗

Privacy Policy

Effective 6 October 2026 · Българска версия

This is an English translation provided for convenience. In case of discrepancy, the Bulgarian version prevails.

This policy explains what personal data we collect, why, on what legal basis, who we share it with, how long we keep it and what rights you have. We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act.

1. Data controller

We are not required to appoint a Data Protection Officer. For all data protection matters, please write to [email protected].

2. What data we collect

2.1. Data you provide to us

2.2. Data collected automatically

2.3. Building data

To deliver our services we process data about the building — cadastral identifier, area, year of construction, structure, data from public registers (cadastre/KAIS, property register). Most of this is not personal data, but where it relates to an identifiable individual (for example an owner) it is treated as personal data under this policy.

We do not intentionally collect special categories of data (health, ethnicity, political opinions, etc.). Please do not send us such data through our forms.

3. Purposes and legal bases

Purpose Legal basis (GDPR)
Responding to enquiries, preparing offers, free consultationArt. 6(1)(b) — pre-contractual steps
Performing the contract — survey, technical passport, energy certificate, designArt. 6(1)(b) — performance of a contract
Invoicing, accounting, tax reportingArt. 6(1)(c) — legal obligation
Filing documentation with authorities and funding programmes on your instructionArt. 6(1)(b) and Art. 6(1)(c)
Newsletter and marketing messagesArt. 6(1)(a) — your consent
Website security, abuse prevention, technical logsArt. 6(1)(f) — legitimate interest
Defending rights in disputes and complaintsArt. 6(1)(f) — legitimate interest

Where the basis is consent, you may withdraw it at any time; this does not affect the lawfulness of processing before withdrawal.

4. Cookies and similar technologies

We use only strictly necessary cookies and local storage in order to:

We do not use advertising or tracking cookies, remarketing pixels, or profiling for advertising. You can delete cookies in your browser settings; some features may then stop working correctly.

5. Who we share data with

We do not sell or rent personal data. We share data only where necessary, with the following categories of recipients:

All of our processors act under written agreements containing confidentiality commitments and security measures.

6. Use of Google API data

Where we use Google services and interfaces (for example the Google Workspace / Gmail API, Google Calendar API, Google Drive API) to handle correspondence, scheduling and documents, access to that data is limited to what is necessary to provide our services.

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

7. Transfers outside the EU/EEA

We process data primarily in Bulgaria and the European Economic Area. Some providers (for example Cloudflare and Google) may process data outside the EEA. In such cases transfers take place on the basis of an adequacy decision or the European Commission's standard contractual clauses, together with supplementary technical measures.

8. How long we keep data

After the relevant period expires, data is deleted or anonymised.

9. Your rights

Under the GDPR you have the right to:

To exercise your rights, write to [email protected] or call +359 879 472 874. We respond within one month; for complex requests this may be extended by a further two months, and we will inform you. We may ask for additional information to verify your identity.

Supervisory authority:
Commission for Personal Data Protection (CPDP)
2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria
Phone: +359 2 915 3 518 · Email: [email protected] · cpdp.bg

10. Automated decision-making

We do not carry out automated decision-making with legal effects for you, and we do not profile for advertising purposes. We use automated processing only to pre-sort and draft responses to enquiries; every communication sent to you is reviewed by a human.

11. Security

We apply appropriate technical and organisational measures: encrypted connections (HTTPS/TLS), need-to-know access control, strong passwords and separate access rights, regular backups, storage of form submissions outside the public area of the website, and restricted access to accounting and contractual documentation.

No measure is absolute. In the event of a personal data breach likely to result in a high risk to you, we will notify you and inform the CPDP in accordance with Articles 33 and 34 GDPR.

12. Children's data

Our services are intended for adults and legal entities. We do not knowingly collect data relating to persons under 18. If you believe such data has been sent to us, please let us know and we will delete it.

13. External links

The website contains links to external sites (regulatory registers, Facebook, Google and others). This policy does not apply to them — please review their own policies.

14. Changes to this policy

We may update this policy. The current version is always published at this address with its effective date. For material changes we will notify you through a visible notice on the website or by email, where we have one.

15. Related documents

Terms of Service

Last updated: 6 October 2026