Personal data protection
Privacy Policy
PRIVACY AND PERSONAL DATA PROTECTION POLICY OF “BOYBEL” OOD This Privacy Policy sets out the terms and conditions under which “BOYBEL” OOD processes and protects the personal data of individuals who use the boybel.com website (the “Website”), submit enquiries regarding information and intermediary services, enter into agreements with the Company, or contact us in person, in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and the Bulgarian Personal Data Protection Act.
Last updated: 24 September 2026
I. INFORMATION ABOUT THE DATA CONTROLLER
Article 1. (1) The data controller is:
“BOYBEL” OOD (BOYBEL LTD.) UIC: 208934963 Registered office and business address: Republic of Bulgaria, Sofia 1359, Lyulin District, Lyulin residential complex, Block 503, Entrance A, Floor 8, Apartment 51 Email address: boybelltd@gmail.com Telephone: +359 883 416 685 EUR bank account, IBAN: BG24UBBS80021483592710
(2) Due to the nature and scope of its activities, the Company is not required to appoint a Data Protection Officer (DPO). All enquiries and requests concerning your personal data may be addressed directly to the Company’s directors at the email address provided above.
II. CATEGORIES OF DATA SUBJECTS, PURPOSES, LEGAL BASES AND RETENTION PERIODS FOR PROCESSING
Article 2. “BOYBEL” OOD collects and processes personal data solely for specific, explicit and lawful purposes, as follows:
2.1. Handling enquiries and providing a free service for connecting clients with Partners
a) Purpose: To receive and process your online enquiry, establish contact with you and initially connect you with the relevant independent professional Partner (credit intermediary, insurance broker, investment intermediary, estate agent, franchisor, accountant, lawyer or other professional/business);
b) Data processed: Name, telephone number, email address, selected service category and description of the enquiry;
c) Legal basis: Article 6(1)(b) of the GDPR (performance of a contract for a free connection service or taking pre-contractual steps at your request), in conjunction with Article 6(1)(a) of the GDPR (your explicit consent to the disclosure of your data to the selected/suitable Partner);
d) Retention period: Up to 6 (six) months from the date of the final referral or from the date on which it is established that contact has ended;
e) Mandatory nature: Providing this data is voluntary; however, without it, we cannot process your enquiry or connect you with a Partner.
2.2. Provision of consultancy services
a) Purpose: To carry out financial analysis of an operating business and/or provide consultancy in connection with acquisitions, business combinations, mergers, business management and other similar matters, without providing investment, insurance, credit, accounting, legal or other advice for which a licence, registration or authorisation is required;
b) Data processed: Full name, personal identification number (EGN), address, telephone number and email address;
c) Legal basis: Article 6(1)(b) of the GDPR (performance of an individual contract);
d) Retention period: Up to 5 (five) years from the completion of the contract, in accordance with the general limitation period applicable to contractual claims under the Bulgarian Obligations and Contracts Act;
e) Mandatory nature: Providing this data is voluntary; however, without it, we cannot enter into a contract with you or provide the requested consultancy services.
2.3. Monitoring payments and accounting for commissions payable by Partners
a) Purpose: To monitor whether a Client referred by us has entered into an agreement with the Partner and whether the Partner has received payment under that agreement, for the accurate calculation, invoicing and collection of the commission payable to “BOYBEL” OOD, as well as to prevent unfair practices and circumvention of the intermediary;
b) Data processed: Enquiry identification number/code, Client’s name, date of the agreement with the Partner, performance status, amount and date of the Client’s payment to the Partner, and amount of the commission charged;
c) Legal basis: Article 6(1)(f) of the GDPR (the legitimate interests of the Controller) in protecting its commercial receivables and evidencing performance under B2B intermediary agreements;
d) Retention period: Up to 5 (five) years following the end of the relevant financial year, in accordance with the limitation periods under the Bulgarian Obligations and Contracts Act and the requirements of the Bulgarian Accountancy Act and Tax and Social Security Procedure Code;
e) Safeguards: Data exchanged is strictly minimised and limited solely to the financial parameters necessary for calculating the commission.
2.4. Accounting, tax and corporate reporting
a) Purpose: Issuing primary accounting documents (invoices), maintaining accounting records and fulfilling tax reporting obligations under the Bulgarian Value Added Tax Act and Corporate Income Tax Act;
b) Data processed: Name/company name, UIC/personal identification number (where applicable for invoicing), address, bank details and transaction value;
c) Legal basis: Article 6(1)(c) of the GDPR (compliance with a legal obligation under the Bulgarian Accountancy Act, Tax and Social Security Procedure Code and Value Added Tax Act);
d) Retention period: 10 (ten) years, commencing on 1 January of the reporting period following the reporting period to which the records relate, in accordance with Article 12 of the Bulgarian Accountancy Act.
2.5. Direct marketing and electronic newsletters
a) Purpose: Sending newsletters, promotional offers, market analyses and news concerning the services of “BOYBEL” OOD;
b) Data processed: Name and email address;
c) Legal basis: Article 6(1)(a) of the GDPR (explicit consent);
d) Retention period: Until consent is withdrawn (by clicking the unsubscribe link included in each email or by contacting boybelltd@gmail.com).
2.6. Technical security, traffic analysis and cookie management
a) Purposes of processing: Ensuring the technical functionality of the Website, retaining users’ privacy settings and carrying out statistical analysis of website traffic;
b) Categories of data processed: IP address (anonymised/truncated), browser type and version, operating system, referring URL, date and time of visit, cookie identifiers and records (logs) of consent given;
c) Legal bases:
Article 6(1)(f) of the GDPR (legitimate interests) for strictly necessary technical cookies and server logs used for security purposes;
Article 6(1)(c) of the GDPR in conjunction with Article 7(1) of the GDPR (legal obligation to demonstrate consent) in relation to retaining logs of the user’s choices made through the cookie banner;
Article 6(1)(a) of the GDPR (consent) for analytics cookies (Google Analytics).
d) Retention periods: As set out in detail in our Cookie Policy, ranging from the end of the session to 2 years for analytics cookies, and up to 5 years for consent logs retained as evidence of consent in accordance with the applicable limitation periods for administrative liability.
III. CATEGORIES OF RECIPIENTS OF PERSONAL DATA
Article 3. In carrying out its activities, “BOYBEL” OOD may disclose personal data to third parties, with recipients classified according to their functional role within the meaning of the GDPR:
3.1. Data Processors (under a written agreement pursuant to Article 28 of the GDPR)
The Controller may provide personal data to external service providers who process such data solely on behalf of and in accordance with the documented instructions of “BOYBEL” OOD. These parties are not permitted to use the data for their own purposes and are bound by strict confidentiality and security obligations. Such providers include:
a) Hosting, cloud infrastructure and server maintenance providers: Netlify, providing the physical and virtual infrastructure for the Website and databases;
b) Transactional email and communication service providers: specialised platforms for the automated delivery of system emails and enquiry confirmations;
c) Consent Management Platforms: providers supporting the cookie banner and the technical recording of users’ choices;
d) CRM and software operators: providers of software for managing customer enquiries and internal organisational processes;
e) Marketing and advertising agencies: where they carry out technical activities related to the management of advertising campaigns strictly in accordance with the Company’s instructions, without the right to enrich their own profiles using the data provided.
3.2. Joint Controllers (pursuant to Article 26 of the GDPR)
In specifically limited circumstances relating to digital marketing and the measurement of conversions on the Website, “BOYBEL” OOD and the relevant online platform provider jointly determine the purposes and means of processing during the stage of collecting and initially transmitting data from the Website through the relevant scripts, pixels and tags:
a) Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) — where technologies for measuring conversions and advertising events in Google Ads are used. “BOYBEL” OOD and Google are joint controllers for the stage involving the generation and transmission of data from the Website to Google. Their relationship is governed by Google’s terms under Article 26 of the GDPR (Google Controller Terms). Once the data has been received by Google’s systems, Google Ireland Ltd. acts as an independent controller for subsequent processing operations involving measurement, aggregation and targeting.
3.3. Independent Data Controllers
The Controller may disclose personal data to third parties that process the data for their own lawful, contractual and professional purposes and bear direct and independent responsibility for the lawfulness of such processing:
a) Intermediary Partners: Credit intermediaries (registered with the Bulgarian National Bank), insurance brokers (registered with the Financial Supervision Commission), licensed investment intermediaries, estate agencies, franchisors, lawyers and accountants — to whom contact details are transferred solely on the basis of your explicit consent or your request to receive the relevant specialised service;
b) Independent professional advisers: Lawyers and law firms (for legal representation and defence under Article 29 et seq. of the Bulgarian Bar Act), registered auditors (for statutory independent financial audits under the Bulgarian Independent Financial Audit and Assurance Act) and external accounting firms (where they independently provide accounting services and prepare financial statements);
c) Banks and payment institutions: Licensed banks and payment service providers for making and receiving bank transfers, verifying payment instructions and preventing fraud in accordance with the Bulgarian Payment Services and Payment Systems Act.
3.4. Competent Public, Regulatory and Judicial Authorities
Personal data may be disclosed to public authorities, including the National Revenue Agency (NRA), the Commission for Consumer Protection (CCP), the Commission for Personal Data Protection (CPDP), the State Agency for National Security (SANS), the Ministry of Interior authorities, the public prosecution authorities and the courts, where there is a specific legal basis arising under applicable legislation (including the Tax and Social Security Procedure Code, Bulgarian Accountancy Act, Consumer Protection Act, Personal Data Protection Act, Civil Procedure Code and Criminal Procedure Code), and within the scope of their legally established supervisory, audit, regulatory or judicial powers.
IV. INTERNATIONAL TRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES
Article 4. (1) “BOYBEL” OOD processes and stores the main sets of personal data on servers and technical infrastructure located in the Republic of Bulgaria and in countries within the European Economic Area (EEA).
(2) When using certain global technology services (such as tools provided by Google Ireland Ltd., Meta Platforms Ireland Ltd. or global email service providers), certain technical data, cookie identifiers or encrypted (hashed) parameters may be transferred to or accessed by affiliated entities and servers located in the United States of America (USA) or other third countries outside the EEA.
(3) In all cases involving international transfers, “BOYBEL” OOD ensures that legally recognised safeguards under Chapter V of the GDPR are applied:
1. Adequacy Decision (Article 45 of the GDPR): Transfers to organisations in the USA that are certified under the EU–U.S. Data Privacy Framework (European Commission Adequacy Decision of 10 July 2023), including Google LLC and Meta Platforms, Inc., are carried out without the need for additional authorisation.
2. Standard Contractual Clauses (Article 46(2)(c) of the GDPR): For providers outside the scope of the adequacy decision, Standard Contractual Clauses approved by the European Commission by Commission Implementing Decision (EU) 2021/914 are used, together with additional technical measures such as end-to-end encryption, pseudonymisation and access control.
V. DATA THAT ARE NOT PROCESSED
Article 5. “BOYBEL” OOD does not collect or process special categories of personal data within the meaning of Articles 9 and 10 of the GDPR, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for the purpose of uniquely identifying an individual, data concerning health, sex life or sexual orientation, or data relating to criminal convictions and offences. If any such data are inadvertently provided by a user, they will not be processed and will be deleted immediately.
VI. AUTOMATED DECISION-MAKING AND PROFILING
Article 6. The Controller does not carry out automated individual decision-making or profiling within the meaning of Article 22 of the GDPR.
VII. RIGHTS OF DATA SUBJECTS
Article 7. (1) As a data subject under the GDPR and the Bulgarian Personal Data Protection Act, you have the following rights:
1. Right of access (Article 15 GDPR): To obtain confirmation as to whether we process your personal data, information about the data we process, and a free copy thereof;
2. Right to rectification (Article 16 GDPR): To request the correction of inaccurate or incomplete personal data concerning you;
3. Right to erasure (“right to be forgotten”) (Article 17 GDPR): Where the legal basis for processing no longer applies, unless the law requires us to retain the data;
4. Right to restriction of processing (Article 18 GDPR): Where you contest the accuracy or lawfulness of the processing;
5. Right to data portability (Article 20 GDPR): To receive your personal data in a structured, commonly used and machine-readable format and transmit it to another controller;
6. Right to object (Article 21 GDPR): To object at any time to processing based on legitimate interests, including commission monitoring, or to processing for direct marketing purposes;
7. Right to withdraw consent (Article 7(3) GDPR): Where processing is based on consent, without affecting the lawfulness of processing carried out before the withdrawal;
8. Right to lodge a complaint (Article 77 GDPR): With the supervisory authority — the Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria, email: kzld@cpdp.bg, website: {"fallbackMarkdown":"www.cpdp.bg","reference":{"matched_text":"","prefix":null,"start_idx":1582,"end_idx":1619,"safe_urls":[],"refs":[],"alt":"www.cpdp.bg","prompt_text":"www.cpdp.bg","type":"url","title":"www.cpdp.bg","item":{"title":"www.cpdp.bg","url":"https://www.cpdp.bg?utm_source=chatgpt.com","attribution":"cpdp.bg","pub_date":null,"snippet":null,"attribution_segments":null,"supporting_websites":null,"refs":[],"hue":null,"attributions":null},"layout":null,"logo":null},"showLoginRequiredCard":false}.
(2) Procedure for exercising your rights: To exercise any of your rights, you may submit a written request by email to boybelltd@gmail.com or to the Company’s registered office in Sofia. The request should include your name, contact details and a precise description of your request. The Controller shall respond and provide the requested information free of charge within one (1) month of receiving the request.
(3) Exercise of rights in cases of joint controllership: Pursuant to Article 26(3) of the GDPR, irrespective of the arrangements between “BOYBEL” OOD and the joint controllers (Google, Meta), you may exercise your rights under the GDPR in relation to and against each of the joint controllers. You may also directly manage and restrict your advertising preferences through your personal account on the relevant platform (Google Ads Settings / Meta Ad Preferences).
VIII. TECHNICAL AND ORGANISATIONAL SECURITY MEASURES
Article 8. “BOYBEL” OOD implements appropriate technical and organisational measures in accordance with Article 32 of the GDPR to ensure a level of security appropriate to the degree of risk. These measures include encryption of web communications using SSL/TLS protocols, encryption of databases both at rest and in transit, restricting physical and logical access to authorised persons only, implementing two-factor authentication (2FA) for business email accounts, protection against malware, and maintaining regular backups.
IX. PRINCIPLES FOR THE PROCESSING OF PERSONAL DATA
Article 9. The Controller ensures that the personal data it processes are:
a) processed lawfully, fairly and transparently in relation to you (“lawfulness, fairness and transparency”);
b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes (“purpose limitation”);
c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (“data minimisation”);
d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that inaccurate personal data are erased or rectified without delay, having regard to the purposes for which they are processed (“accuracy”);
e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed (“storage limitation”);
f) processed in a manner that ensures an appropriate level of security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (“integrity and confidentiality”).
