Skip to content

GDPR • DATA PROTECTION

Privacy Policy

Zevs Consult OOD is a personal data controller under the General Data Protection Regulation (GDPR) and operates in full compliance with European and Bulgarian legislation in the field of personal data protection.

This policy describes how we collect, use, store, and protect the personal data of our website visitors in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Bulgarian legislation.

Effective from 02.01.2025 • Last updated: 15.09.2025

Section I — Information about the website administrator

Art. 1. (1) The website is managed and administered by:

Name
Zevs Consult OOD (ZEVS CONSULT Ltd.)
Company ID
208481139
VAT registration
BG208481139 (from 13.10.2025)
Legal form
Limited liability company (OOD)
Registered office and address
Sofia 1402, Lozenets District, 109 Cherni Vrah Blvd.
Managers
Martin Plamenov Zhelyazkov
Evgeni Valeriev Venkov
Serhat Ikmet Mustafa
Contact Us
office@z-consult.bg
e.venkov@z-consult.bg

(2) Competent supervisory authority:

Commission for Personal Data Protection, Sofia, "Prof. Tsvetan Lazarov" Blvd. No. 2, tel. 02 915 3518, www.cpdp.bg.

Section II — Definitions Used

Art. 2. For the purposes of this privacy policy, the terms used shall have the following meaning:

„Personal Data“
any information relating to an identified or identifiable natural person — name, address, email, telephone, IP address, etc.
„Personal Data Controller“
the legal entity which, alone or jointly with others, determines the purposes and means of the processing of personal data.
„Personal Data Processor“
a natural or legal person who processes personal data on behalf of the controller, based on a written agreement.
„Data Processing“
any operation performed on personal data — collection, recording, organisation, storage, use, sharing, and erasure.
„Consent“
any freely given, specific, informed, and unambiguous indication of the data subject's wishes.
„Security Breach“
an incident leading to accidental or unlawful destruction, alteration, unauthorised disclosure of, or access to, processed personal data.
„Profiling“
automated processing of personal data to evaluate behavioural patterns, preferences, and characteristics.
„Cookies“
small text files created when visiting the website, which support its functionality.
„Data Recipient“
a natural or legal person, public authority, or other structure to whom personal data is disclosed.
„Third Country“
a country outside the European Union and the European Economic Area.

Section III — Legal Basis for Collecting, Processing, and Storing Your Personal Data

Art. 3. (1) The Controller collects and processes a minimum volume of information necessary to provide its corporate services and maintain website functionality. This includes initial contact data via the contact form, as well as technical information for optimising website performance.

(2) When processing personal data, we apply the principle of data minimisation, collecting only information directly necessary for the specific purpose.

Art. 4. The processing of personal data is carried out based on at least one of the following legal grounds:

  • Explicit consent of the data subject — freely given and informed, for specific purposes (marketing communications, analytical cookies).
  • Performance of contractual obligations or taking steps prior to entering into a contract at the request of the data subject — including processing data when inquiring via the contact form.
  • Compliance with legal obligations — accounting and tax documentation, regulatory requirements.
  • Legitimate interests of the controller — information security, prevention of abuse, analysis of website usage, and technical support.

Section IV — Principles for Collecting, Processing, and Storing Your Personal Data

Art. 5. (1) When processing personal data based on legitimate interest, the Controller conducts a preliminary impact assessment to ensure that the interests or fundamental rights and freedoms of the data subject are not overridden.

(2) Where processing is based on consent, the data subject has the right to withdraw their consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

(3) For processing for direct marketing purposes, the data subject has the right to object at any time.

Art. 6. We apply the principles of lawfulness, transparency, purpose limitation, data minimisation, and accuracy, in accordance with Art. 5 of the GDPR.

Art. 7. In accordance with Articles 12–14 of the GDPR, we provide comprehensive information about our role, the categories of data processed, the purposes and legal bases, retention periods, and organisational protective measures.

Section V — Types of Personal Data and the Purpose for which they are Processed

Art. 8. The Controller processes the following categories of personal data:

Identifying personal data

Fields: first and last name, telephone, email

Purpose: Feedback to the data subject on submitted inquiries.

Legal Basis: Art. 6, para. 1, lit. „b“ of the GDPR — processing necessary for pre-contractual relations.

Technical data upon sending an inquiry

Fields: IP address, browser type, operating system and device, approximate location determined by IP address (country/city), page from which the inquiry was sent, source of visit (referrer, UTM parameters)

Purpose: Form security, spam and abuse protection, normal operation of the service and, where applicable, information on the channel from which the inquiry originated. We do not use GPS location and do not create a digital device fingerprint. The IP address is deleted after a short period, as defined in system settings.

Legal Basis: Art. 6, para. 1, letter 'f' of the GDPR — legitimate interest for security and abuse prevention.

User experience data

Fields: IP address, device type, frequency of visits, last visit, time on site, pages viewed

Purpose: Content personalisation and website improvement. Data is anonymised and encrypted.

Legal Basis: Art. 6, para. 1, lit. „e“ of the GDPR — legitimate interest for optimisation.

Data for marketing communications

Fields: email

Purpose: Sending newsletters with news and know-how in business development, digital marketing, and SEO.

Legal Basis: Art. 6, para. 1, lit. „a“ of the GDPR — explicit consent.

Section VI — Retention Period for Your Personal Data

Art. 9. (1) The Controller stores data only for the period necessary to achieve the stated purposes or when there is a legal obligation to retain it for longer.

(2) We observe the following periods:

  • Identifying personal data collected via contact form — up to 1 year;
  • Data for concluded contracts — up to 5 years;
  • User experience data — up to 2 years from the last visit;
  • Newsletter data — until unsubscribed by the data subject.

(3) The duration of the period is determined by the duration of the services provided, the necessity for exercising or defending legal claims, and the existence of a legal obligation to retain.

Section VII — Rights of Data Subjects

Art. 10. Right to withdraw consent at any time — fully or partially, without affecting the lawfulness of processing prior to withdrawal.

Art. 11. Right to information and access to processed personal data, purposes, recipients, and periods. The first copy is free of charge.

Art. 12. Right to rectification or completion of inaccurate data — within 30 days.

Art. 13. Right to erasure, when data is no longer necessary, consent is withdrawn, there is a legitimate objection, or processing is unlawful.

Art. 14. Right to data portability — where technologically feasible.

Art. 15. In case of a security breach, the Controller notifies affected individuals and the supervisory authority within 72 hours.

Art. 16. Right to restriction of processing when accuracy is contested, processing is unlawful, necessity has ceased, or an objection has been lodged.

Art. 17. Rights are exercised via a written request, containing identification, description, and preferred communication method. Response within one month (with a possible extension of two additional months in complex cases).

Art. 18. Right to object to processing based on legitimate interest, including profiling.

To exercise your rights, please write to us at office@z-consult.bg.

Section VIII — Storage and Transfer of Personal Data

Art. 19. Data is primarily stored on servers within the EU/EEA. If transfer outside these territories is necessary, measures in accordance with Chapter V of the GDPR apply — adequacy decisions, standard contractual clauses, or other mechanisms under Articles 46–49.

Art. 20. (1) For website usage analysis, we use Google Analytics with anonymised IP addresses, disabled sharing with Google, and a retention period of 24 months.

(2) For email communication management, we use a platform with servers in the EU; access is limited to the necessary scope.

Art. 21. Upon expiry of the applicable period, data is securely erased or anonymised.

Art. 22. We apply a multi-layered approach to protection — encryption during transfer and storage, access control, and regular security audits.

Art. 23. We do not sell or rent personal data to third parties for marketing purposes. We share data only with service providers necessary for website functionality, under signed agreements pursuant to Art. 28 of the GDPR.

Section IX — Final Provisions

Art. 24. In case of rights infringement, the data subject has the right to lodge a complaint with the Commission for Personal Data Protection, including electronically.

Art. 25. The Controller reserves the right to update the policy periodically. Amendments come into force after a 14-day notification period or publication on the website (if no objection is raised), or upon receipt of explicit consent.

Art. 26. For any matters not covered, Regulation (EU) 2016/679, the Personal Data Protection Act, and applicable Bulgarian legislation shall apply.

Art. 27. This policy was adopted and came into force on 02.01.2025. Last update of controller data: 15.09.2025.

For questions regarding this policy or the processing of your data: office@z-consult.bg. Back to top →