1. Who processes your data
The controller under Regulation (EU) 2016/679 (GDPR) is:
- Trader
- 3D Code EOOD („3Д Код“ ЕООД)
- Company number (ЕИК)
- 208728073
- VAT number
- BG208728073
- Registered seat
- Stara Zagora, Bulgaria
- office@aividimost.bg
- Phone
- +359 884 336 456
- Website
- aividimost.bg
We are not required to appoint a data protection officer. Anything about this policy goes to office@aividimost.bg.
2. What we collect
We collect little, and only what the service cannot work without. No registration, no account, no password.
- Email address — the only personal data you type in. It is how you get the link to your report and the payment confirmation.
- Company name and website — business data, not data about an individual. If a company name contains a personal name, it is processed as part of it.
- Publicly available content of the site you name — we read it to work out what the business offers.
- Order data — status, amount, currency, time of payment and the Stripe payment identifier.
- The report itself — the questions, the models' answers and the calculated scores.
- Technical records — server logs with the time of a request and technical information about it, needed for security and troubleshooting.
- Visit records — when a page is opened we store the time, the page address, your IP address, the browser and device details from the request, and where you arrived from (the referring site or the campaign tag).
We set no tracking cookies, use no third-party analytics service, and do not link visit records to your email address or to any particular check. We build no profile and do not follow you across other sites.
We neither receive nor store card numbers, CVV codes or bank credentials. We do not collect special category data under Article 9 GDPR and ask you not to send us any.
3. Why we use it and on what basis
- Producing and delivering the report, sending the link and confirmation by email
- performance of a contract — Art. 6(1)(b) GDPR
- Processing payment and issuing a payment document
- performance of a contract and legal obligation — (b) and (c)
- Accounting and tax records
- legal obligation — (c)
- Security of the service, abuse prevention and technical troubleshooting
- legitimate interest — (f)
- Answering your enquiry or complaint
- performance of a contract and legitimate interest — (b) and (f)
- At most two reminders if you started a check and did not complete it with payment
- legitimate interest — (f)
- Site visit statistics — how many people open it, where they arrive from and on what device
- legitimate interest — (f)
Reminders concern an unfinished order and nothing else — they refer to the check you ran, the first about an hour after it, the second the next day. Each one carries a one-click opt-out link. Opting out stops the reminders; email about an order you have paid for still reaches you.
We send no marketing newsletters and do not use your email for any other marketing. If we ever do, we will ask for separate consent that you can withdraw in one click.
We do not sell or rent data to third parties for their own purposes.
4. What exactly we send to the language models
This is the question we get most often, so here is the detail.
- To OpenAI, Anthropic and Google we send the company name, the website address, the public content extracted from it, and the simulated customer questions.
- We do not send your email address, your payment data, or anything else that identifies you as an individual.
- Requests go through the providers' programmatic access (API). Under their API terms, content sent this way is not used to train their models.
- Providers retain requests for a short period for security and abuse purposes, under their own policies.
5. Who we share it with
We work with a small number of providers, each processing data only on our instructions and under a contract:
- Stripe Payments Europe, Ltd.
- payment processing, receipt and invoice
- OpenAI, Anthropic, Google
- the language models that answer the questions
- Cloud infrastructure provider
- hosting for the site, database and files — servers in the European Union (Frankfurt)
- Email provider
- sending the report link and confirmations
Beyond these, data is disclosed only to a competent public authority where the law requires it, and to our accountant for record-keeping.
6. Transfers outside the European Union
The site, the database and the reports are stored on servers in the European Union.
Some language model providers process requests on servers in the United States. Those transfers rely on the standard contractual clauses adopted by the European Commission and/or the EU–US Data Privacy Framework. As described above, no data identifying you as an individual travels to those providers.
7. How long we keep it
- The report and the check record — for as long as we maintain the service, so you can reopen your link. We delete them earlier at your request.
- The email address — together with the record of the corresponding check.
- Payment and accounting documents — 10 years under the Bulgarian Accountancy Act. This period cannot be shortened at your request.
- Server logs — up to 90 days.
- Visit records, including the IP address — 180 days, after which they are deleted automatically.
- Correspondence about an enquiry or complaint — up to 3 years after it is closed.
To have your data deleted sooner, write to office@aividimost.bg — we act within 30 days. Deleting the record means the link to your report stops working permanently, so save a copy first.
8. Your rights
Under the GDPR you have the right to:
- access the data we hold about you and receive a copy;
- have inaccurate data corrected;
- have data erased (the right to be forgotten), so far as no legal obligation requires us to keep it;
- have processing restricted;
- receive your data in a machine-readable format and port it to another controller;
- object to processing based on legitimate interest;
- withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal;
- lodge a complaint with a supervisory authority.
9. How to exercise them
Write to office@aividimost.bg from the address you used for the check. We reply within 30 days, usually much sooner. There is no charge, except for manifestly unfounded or excessively repetitive requests.
Objecting to the reminder emails takes no letter to us: the opt-out link inside the reminder stops them for that address immediately and for good.
If you believe we have infringed your rights, you can complain to the Bulgarian Commission for Personal Data Protection: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, +359 2 915 3518, kzld@cpdp.bg, cpdp.bg. We would be glad to try to settle it directly first.
11. Automated processing
The analysis and the scores in a report are produced automatically by language models. That processing concerns the business being checked, not you as an individual, and produces no legal effects for you.
We take no automated decisions under Article 22 GDPR about individuals and do not profile visitors.
12. Security
- All traffic to the site runs over an encrypted connection (HTTPS).
- A report opens only with the personal code contained in its link.
- The admin area is protected by a password and a signed token with a limited lifetime.
- The database is not publicly reachable and sits in the European Union.
- Your card details never pass through our systems.
If a security breach does occur that is likely to result in a high risk to your rights, we will notify you and the supervisory authority within the GDPR deadlines.
13. Children
The service is intended for business use and is not directed at anyone under 18. We do not knowingly collect children's data. If we find any, we delete it.
14. Changes to this policy
The current version is always here, with the date of the last change at the top. When something material changes — a new type of data, a new purpose or a new recipient — we will mark it clearly on the page.
