PRIVACY POLICY
This Privacy Policy explains how Struktor Pro Bulgaria OOD processes personal data relating to visitors to struktorr.com, persons sending enquiries, prospective and existing customers, suppliers and other business contacts. It is prepared in accordance with Regulation (EU) 2016/679 (the “GDPR”) and applicable Bulgarian data-protection law.
1. Data controller
The controller is Структор Про България ООД (Struktor Pro Bulgaria OOD), UIC/EIK 208867308, with registered office and management address at 149 Brezovsko Shose Str., 4003 Plovdiv, Bulgaria.
Email for data-protection questions and rights requests: info@struktorr.com.
The company has not appointed a Data Protection Officer because, as of the date of this policy, it is not legally required to do so.
2. Personal data we process
- Data you provide through the enquiry form: name, email address, the content of your message and, if you choose to provide them, company and city.
- Business-communication data: information contained in subsequent correspondence, quotations, orders and contractual relationships.
- Technical and security data: IP address, date and time of access, requested URL, browser/device type and other data that may be contained in server or security logs.
- Data relating to cookies or similar technologies, where used, as described in the Cookie Policy.
We do not request special categories of personal data (for example health, religious or biometric data). Please do not include such data, or unnecessary personal data relating to other persons, in the free-text enquiry field.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Responding to enquiries, providing technical consultation and preparing quotations | Article 6(1)(b) GDPR where processing is necessary to take steps at your request before entering into a contract or to perform a contract with you. Where you contact us as an employee/representative of a company, Article 6(1)(f) GDPR applies — our legitimate interest in communicating with business customers and partners and responding to their enquiries. |
| Website security, abuse prevention and technical maintenance | Article 6(1)(f) GDPR — our legitimate interest in protecting our website, systems and communications. |
| Compliance with accounting, tax and other legal obligations | Article 6(1)(c) GDPR — compliance with a legal obligation. |
| Establishment, exercise or defence of legal claims | Article 6(1)(f) GDPR — our legitimate interest in protecting our rights and interests. |
| Analytics or marketing technologies, if introduced in the future | Article 6(1)(a) GDPR — your prior consent, where consent is required. Such technologies must not be activated before consent. |
4. Mandatory and optional enquiry-form data
The Name, Email and Message fields are mandatory because without them we cannot identify and respond to your enquiry. Company and City are optional. If you do not provide the mandatory information, the form cannot be submitted.
5. Recipients of personal data
Depending on the circumstances, personal data may be disclosed to:
- hosting, cloud-infrastructure and security providers;
- email providers and, where used, enquiry-management or CRM providers;
- IT-support and web-development providers to the extent access is necessary for maintenance;
- accountants, lawyers and other professional advisers where necessary;
- competent public authorities where disclosure is required by law.
Where a service provider processes personal data on our behalf, we put in place an Article 28 GDPR data-processing agreement or other required safeguards where applicable. We do not sell or rent personal data.
6. Transfers outside the European Economic Area
Some service providers or their subprocessors may process data outside the European Economic Area (EEA). Where such a transfer takes place, it is based on an applicable mechanism under Chapter V GDPR, such as a European Commission adequacy decision or Standard Contractual Clauses and, where necessary, supplementary safeguards. You may request information about the applicable safeguards at info@struktorr.com.
7. Retention periods
| Category | Retention |
|---|---|
| Enquiries that do not result in a contractual relationship | Up to 12 months from the last communication, unless a specific documented need requires longer retention. |
| Contractual and business correspondence | For the duration of the relationship and afterwards to the extent necessary to establish, exercise or defend legal claims and comply with legal obligations. |
| Accounting and tax records | For the periods required by applicable accounting and tax law; for some accounting records the statutory period is generally 10 years. |
| Server and security logs | Normally up to 90 days, unless a specific security incident requires longer retention or the technical provider applies a shorter period. |
When personal data is no longer necessary for the relevant purpose and there is no legal basis for further retention, it is deleted or anonymised.
8. Your rights
Subject to the conditions of the GDPR, you have the right to:
- access your personal data and obtain information about its processing;
- rectify inaccurate or incomplete data;
- request erasure where the legal conditions are met;
- request restriction of processing;
- data portability where processing is based on consent or contract and is carried out by automated means;
- object to processing based on legitimate interests, including an unconditional right to object to direct marketing;
- withdraw consent at any time for processing based on consent, without affecting the lawfulness of processing before withdrawal.
To exercise a right, contact info@struktorr.com. We normally respond without undue delay and no later than one month. Where a request is complex or numerous requests are received, this period may be extended by up to two additional months; you will be informed of the extension within the first month. Where necessary, we may request additional information to verify identity.
You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP): 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria; email: kzld@cpdp.bg; website: www.cpdp.bg.
9. Automated decision-making and profiling
We do not carry out automated decision-making producing legal effects or similarly significantly affecting you within the meaning of Article 22 GDPR. As of the date of this policy, we do not carry out advertising profiling through the website.
10. Security and personal-data breaches
We apply technical and organisational measures appropriate to the risk, including encrypted connections (TLS/HTTPS), access restrictions, updates and resilience/backup measures where appropriate.
In the event of a personal-data breach, we notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the breach is likely to result in a high risk to affected individuals, we communicate the breach to them without undue delay unless a legal exception applies.
11. Changes to this policy
We may update this policy when the website, service providers, processing purposes or applicable law change. The current version will be published on this page with the date of the latest update.