Romfeya UBP

Legal information

Romfeya UBP data protection policy

The general terms on personal data in the system: who processes what, where the data are stored and with whom rights are exercised. They concern the system, not the website.

Convenience translation. This is an English translation of the Bulgarian text. If the two differ, the Bulgarian text prevails.

General terms and conditions of Kibersigurnost EOOD · Version of 4 October 2026


Section I. General provisions

Article 1. (1) This Policy governs the protection of personal data in the provision and use of the Romfeya UBP service – a business management system provided by electronic means (the “Service”).

(2) The Service is provided by Kibersigurnost EOOD, UIC 205848886, with its seat and registered address at 23 Akad. Petar Dinekov St., Sofia (the “Provider”).

(3) The Policy constitutes general terms and conditions of the Provider and forms an integral part of the contract for the use of the Service (the “Contract”). It is handed to the Client when the Contract is concluded, and the Client confirms in writing in the Contract that it accepts it.

(4) The processing of personal data that the Provider carries out on behalf of the Client is governed by the Personal Data Processing Agreement (the “Agreement”), which also forms an integral part of the Contract.

Article 2. (1) For the purposes of this Policy:

  1. “Client” means the person that has concluded a Contract with the Provider;
  2. “User” means a natural person to whom the Client has given access to the Service;
  3. “Client Data” means the data that the Client and its Users enter, create or store in the Service, including the user accounts, the authentication data and the records of access to the Service and of the actions carried out in it;
  4. “Regulation” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).

(2) Other terms have the meaning given to them in Article 4 of the Regulation.

Section II. Roles of the Client and of the Provider

Article 3. (1) With regard to the personal data contained in the Client Data, the Client is the controller and the Provider is the processor.

(2) The Client determines which personal data are processed in the Service, for what purposes and on what legal basis, which persons have access to them and for how long they are kept.

(3) The Provider processes these data solely on behalf of the Client and on its documented instructions, in order to provide, maintain and protect the Service, and does not use them for its own purposes.

Article 4. The Provider is a controller only with regard to the personal data of the Client, where the Client is a natural person, and of the Client's legal representatives, authorised representatives and contact persons, which it processes in connection with the conclusion and performance of the Contract. Information about this processing is contained in Section V.

Article 5. (1) Users obtain access to the Service by decision of the Client and use it in performing their employment or contractual obligations towards the Client.

(2) The processing of the Users' personal data in the Service is not based on their consent, and no such consent is required for the use of the Service. The legal basis for the processing is determined by the Client in its capacity as controller.

(3) With respect to the Users and the other data subjects, the Policy is for information purposes and does not affect their rights under Chapter III of the Regulation.

Section III. Processing of personal data in the Service

Article 6. (1) The Service processes the personal data that the Client and its Users enter in it:

  1. for the Client's workers and employees – names, photograph, contact details, position, data on their work and its history, appraisals, rewards and disciplinary sanctions, as well as the documents attached by the Client;
  2. for the Users – names, contact details, username, authentication data, role and permissions;
  3. for the Client's current and prospective counterparties who are natural persons, and for the representatives and contact persons of its counterparties – names, position, contact details and the data contained in commercial and accounting documents;
  4. for the persons with whom the Client corresponds through the Service – names, contact details, the content of the correspondence, and preferences and consents regarding the receipt of commercial communications.

(2) Documents attached by the Client and free-text fields may contain a personal identification number (EGN) and, at the Client's discretion, special categories of personal data under Article 9 of the Regulation. The Service does not require them to be entered.

Article 7. The Service records each User's access and the changes the User makes to the data, including the time of access and the network address at login. The records are kept for the security of the Service and for the traceability of actions in the Client's interest, and are provided to the Client on request.

Article 8. (1) The Client Data are stored in the territory of the Republic of Bulgaria.

(2) Diagnostic information about the operation of the Service and about errors occurring in it is stored in the territory of the European Union. This also applies to any personal data from the Client Data that it may contain.

(3) The Provider does not transfer personal data to a third country or an international organisation, except on documented instructions from the Client or where it is required to do so by Union law or Bulgarian law.

(4) Access by the Client and its Users to the Service from outside the Republic of Bulgaria takes place as decided by the Client.

Article 9. (1) Except in the cases under paragraphs 4 and 5, the Provider discloses personal data from the Client Data only to other processors that it has engaged under the conditions of the Agreement:

  1. a provider of hosting services established in a Member State of the European Union, with a data centre in the territory of the Republic of Bulgaria;
  2. a provider of a service for diagnosing errors in the operation of the Service that is established in a third country and stores the diagnostic information under Article 8(2) in the territory of the European Union; personal data are provided to it only under the conditions of Chapter V of the Regulation.

(2) The names and addresses of the persons under paragraph 1 are communicated to the Client in a list provided when the Contract is concluded.

(3) When the Service is loaded, the User's device downloads publicly available files needed to display it from content delivery networks, whereby their operators receive the network address of the device.

(4) Where the Client, at its own choice, connects the Service to an external service of a third party, the data exchanged with that service are provided to that party on the Client's documented instructions and under the Client's responsibility.

(5) The Provider provides personal data to a public authority only where it is required to do so by law.

Article 10. The Client Data are kept for the term of the Contract, unless they are erased earlier on the Client's instructions. After the termination of the Contract, they are kept for up to 12 months so that they can be returned to the Client, and are erased under the conditions and within the periods laid down in the Agreement.

Article 11. The Provider applies appropriate technical and organisational measures for the security of personal data, which are described in the Agreement.

Article 12. (1) The Users and the other persons whose personal data are contained in the Client Data exercise their rights under Chapter III of the Regulation with the Client, which is the controller of those data.

(2) A request received by the Provider is forwarded to the Client without delay.

(3) Every data subject has the right to lodge a complaint with the Commission for Personal Data Protection, 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, www.cpdp.bg.

Section IV. Obligations of the Client

Article 13. (1) The Client provides its workers, employees and Users and the other data subjects with the information under Articles 13 and 14 of the Regulation about the processing of their personal data in the Service.

(2) The Client makes its Users familiar with this Policy before giving them access to the Service, and its legal representatives, authorised representatives and contact persons – before providing their personal data to the Provider.

Section V. Information about the processing for which the Provider is the controller

Article 14. The controller of the personal data under this Section is the Provider. Requests and questions concerning the processing are sent in writing to the Provider's registered address specified in Article 1(2) or to the email address for correspondence specified in the Contract.

Article 15. (1) The Provider processes the following personal data of the persons under Article 4: names; position or the capacity in which the person acts; contact details; signature; the data contained in the Contract and in the accounting documents; the content of the correspondence with the Provider.

(2) The data are obtained from the person concerned, from the Client and from the Commercial Register and Register of Non-Profit Legal Entities.

Article 16. (1) The data are processed for the following purposes and on the following legal bases:

  1. conclusion, performance and administration of the Contract, including correspondence and support – point (f) of Article 6(1) of the Regulation and, where the data subject is himself or herself a party to the Contract, point (b) of Article 6(1) of the Regulation;
  2. issuing and keeping accounting documents – point (c) of Article 6(1) of the Regulation in conjunction with the Accountancy Act, the Value Added Tax Act and the Tax and Social Insurance Procedure Code;
  3. establishment, exercise or defence of legal claims – point (f) of Article 6(1) of the Regulation.

(2) The legitimate interests of the Provider are to conclude and perform the Contract by maintaining contact with the persons who represent the Client or act on its behalf, and to defend its rights in the event of a dispute. The processing also serves the Client's legitimate interest in receiving the agreed Service.

Article 17. The Provider discloses the data under this Section only to:

  1. processors acting on its behalf – providers of hosting services and of email services, and the persons who provide its accounting services;
  2. public authorities, where it is required to do so by law;
  3. courts, bailiffs and lawyers – where this is necessary for the establishment, exercise or defence of legal claims.

Article 18. (1) The data are kept for the term of the Contract and five years after its termination – the general limitation period under Article 110 of the Obligations and Contracts Act – and, in the event of a pending dispute, until it has been finally resolved.

(2) Accounting documents and the personal data contained in them are kept for the periods under Article 12 of the Accountancy Act and Article 38 of the Tax and Social Insurance Procedure Code.

Article 19. (1) The data subject has the right to request from the Provider access to the personal data concerning him or her, their rectification or erasure, and restriction of their processing. The right to data portability applies where the processing is based on a contract with the data subject and is carried out by automated means.

(2) The rights are exercised by a written request, including by electronic means, addressed to the Provider in accordance with Article 14.

(3) The data subject has the right to lodge a complaint with the Commission for Personal Data Protection.

Article 20. Right to object. Where the Provider processes personal data on the basis of a legitimate interest, the data subject has the right to object, at any time and on grounds relating to his or her particular situation, to the processing. The Provider ceases the processing unless it demonstrates that there are compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or that the processing is necessary for the establishment, exercise or defence of legal claims.

Article 21. The provision of personal data under this Section is a requirement necessary for the conclusion and performance of the Contract. Without them, the Contract cannot be concluded or performed.

Section VI. Amendments to the Policy

Article 22. (1) The Provider communicates any amendment to the Policy to the Client in writing, including by electronic means, at the correspondence address specified in the Contract, together with the full text of the amendment and the date from which it takes effect.

(2) The amendment takes effect on the date specified in the communication, but not earlier than 30 days after it has been communicated, and is binding on the Client unless by that date the Client states in writing that it rejects it.

(3) If the Client rejects the amendment, the Contract continues to be performed under the previous version of the Policy.

(4) The Client brings the amendment to the attention of the persons under Article 13(2).