Convenience translation. This is an English translation of the Bulgarian text. If the two differ, the Bulgarian text prevails.
General terms and conditions of Kibersigurnost EOOD under Article 28 of Regulation (EU) 2016/679 · Version of 4 October 2026
Section I. Subject matter and parties
Article 1. (1) This Agreement governs the processing of personal data that Kibersigurnost EOOD, UIC 205848886, with its seat and registered address at 23 Akad. Petar Dinekov St., Sofia (the “Provider”), carries out in providing the Romfeya UBP service (the “Service”) on behalf of the person that has concluded a contract with it for the use of the Service (the “Client”), and constitutes a contract under Article 28(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the “Regulation”).
(2) The Agreement forms an integral part of the contract for the use of the Service (the “Contract”). It is handed to the Client when the Contract is concluded, and the Client confirms in writing in the Contract that it accepts it; the Agreement is not signed separately.
(3) The Agreement applies for as long as the Provider processes personal data on behalf of the Client.
Article 2. (1) “Client Data” means the data that the Client and the natural persons to whom it has given access to the Service (the “Users”) enter, create or store in the Service, including the user accounts, the authentication data and the records of access to the Service and of the actions carried out in it. With regard to the personal data contained in the Client Data, the Client is the controller and the Provider is the processor.
(2) The Provider is a controller only with regard to the personal data of the Client, where the Client is a natural person, and of the Client's legal representatives, authorised representatives and contact persons, which it processes in connection with the conclusion and performance of the Contract. This processing is not the subject matter of the Agreement and is described in the Personal Data Protection Policy (the “Policy”).
(3) Other terms have the meaning given to them in Article 4 of the Regulation.
Section II. Description of the processing
Article 3. The subject matter of the processing is the personal data contained in the Client Data. The processing continues for the term of the Contract and after its termination – until the data and their backups are erased in accordance with Section VI.
Article 4. (1) The processing consists of storing, arranging, retrieving, displaying and altering the data as a result of the actions of the Client and the Users, making backups, restoring and erasing.
(2) The Provider processes the data solely in order to provide, maintain and protect the Service. It does not use them for its own purposes, including for advertising, profiling, analytics or the development of products and services.
Article 5. (1) The following types of personal data are processed:
- for the Client's workers and employees – names, photograph, contact details, position, data on their work and its history, appraisals, rewards and disciplinary sanctions, as well as the documents attached by the Client;
- for the Users – names, contact details, username, authentication data, role and permissions, and records of access to the Service and of the actions carried out in it, including time and network address;
- for the Client's current and prospective counterparties who are natural persons, and for the representatives and contact persons of its counterparties – names, position, contact details and the data contained in commercial and accounting documents;
- for the persons with whom the Client corresponds through the Service – names, contact details, the content of the correspondence, and preferences and consents regarding the receipt of commercial communications.
(2) Documents attached by the Client and free-text fields may contain a personal identification number (EGN) and, at the Client's discretion, special categories of personal data under Article 9 of the Regulation. The Service does not require them to be entered.
Article 6. The data subjects are:
- the Client's workers and employees, and the Users;
- the Client's current and prospective counterparties who are natural persons, and the representatives and contact persons of its counterparties;
- the persons with whom the Client corresponds through the Service;
- other natural persons whose data are contained in the documents entered by the Client.
Article 7. (1) The Client Data are stored in the territory of the Republic of Bulgaria.
(2) Diagnostic information about the operation of the Service and about errors occurring in it is stored in the territory of the European Union. This also applies to any personal data from the Client Data that it may contain.
(3) Access by the Client and the Users to the Service from outside the Republic of Bulgaria takes place as decided by the Client.
(4) The display of the Service uses publicly available files that the User's device downloads from content delivery networks, whereby their operators receive the network address of the device. By accepting the Agreement, the Client instructs that the Service be provided to it in this way. On request, the Provider informs the Client of the names of these operators and of the countries in which they are established.
Section III. Obligations of the Provider
Article 8. (1) The Provider processes the personal data only on documented instructions from the Client, including with regard to their transfer to a third country or an international organisation.
(2) The Contract, this Agreement and the actions that the Client and the Users carry out through the functions and settings of the Service are deemed documented instructions. Additional instructions are given in writing, including by electronic means.
(3) Where Union law or Bulgarian law requires the Provider to carry out processing outside the Client's instructions, the Provider informs the Client of that legal requirement before the processing, unless that law prohibits such information on important grounds of public interest.
(4) The Provider immediately informs the Client if, in its opinion, an instruction infringes the Regulation or other Union or Member State data protection provisions.
Article 9. The Provider ensures that the persons authorised to process the personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality, and gives them access to the data only to the extent necessary for the performance of the Contract.
Article 10. (1) The Provider takes all necessary technical and organisational measures in accordance with Article 32 of the Regulation, which include at least:
- encryption of the connection between the Users and the Service;
- separation of each client's data from the data of the other clients;
- access to the data according to roles and permissions that the Client determines for the Users;
- storage of passwords only in irreversibly transformed form;
- the possibility of two-factor authentication of the Users;
- temporary blocking of access after repeated failed login attempts;
- records of access to the Service and of changes to the data;
- making backups and restoring the data where necessary.
(2) The Provider reviews the measures and may improve them without reducing the level of protection achieved.
(3) On request, the Provider provides the Client with such additional information about the measures as the Client needs to assess their suitability.
Article 11. (1) Taking into account the nature of the processing, the Provider assists the Client by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Client's obligation to respond to requests for exercising the data subject's rights under Chapter III of the Regulation. The assistance is provided through the functions of the Service and, on the Client's written request, also by the Provider retrieving, rectifying, restricting or erasing data.
(2) The Provider forwards to the Client without delay any request from a data subject that it receives and does not respond to the request on the merits unless the Client entrusts it with doing so.
Article 12. Taking into account the nature of the processing and the information available to it, the Provider assists the Client in fulfilling the Client's obligations under Articles 32 to 36 of the Regulation.
Article 13. (1) The Provider notifies the Client without undue delay after becoming aware of a personal data breach concerning personal data processed on behalf of the Client.
(2) The notification is sent to the Client's correspondence address specified in the Contract and contains a description of the nature of the breach, including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned, of its likely consequences and of the measures taken or proposed to address it. Where it is not possible to provide all the information at the same time, it is provided in phases without further undue delay.
Article 14. (1) The Provider gives the Client access to all information necessary to demonstrate compliance with the obligations under Article 28 of the Regulation and allows for and contributes to audits, including inspections, conducted by the Client or by another auditor mandated by the Client.
(2) Audits are carried out at reasonable intervals, but not more often than once every twelve months, unless there are grounds to believe that there is non-compliance or the audit is requested by a supervisory authority. The Client notifies the Provider in writing at least 14 days in advance.
(3) The audit is carried out during working hours and in a manner that does not jeopardise the security and confidentiality of other clients' data. The persons carrying it out undertake an obligation of confidentiality. Each party bears its own costs of the audit.
Section IV. Other processors and external services
Article 15. (1) The Client gives the Provider general written authorisation to engage other processors for the following activities:
- providing the hosting infrastructure of the Service – by a person established in a Member State of the European Union, with a data centre in the territory of the Republic of Bulgaria;
- diagnosing errors in the operation of the Service – with the diagnostic information stored in the territory of the European Union.
(2) When the Contract is concluded, the Provider provides the Client with a list of the other processors engaged, stating the name and address of each of them, the activity entrusted to it and the place of processing. The list forms an integral part of the Agreement and is amended in accordance with Article 16.
(3) Where another processor is established in a third country, the Provider provides it with personal data only under the conditions of Chapter V of the Regulation – on the basis of an adequacy decision of the European Commission or subject to appropriate safeguards under Article 46 of the Regulation. The basis is stated in the list referred to in paragraph 2. By accepting the Agreement, the Client instructs the transfer under these conditions.
Article 16. (1) The Provider informs the Client in writing of any intended engagement or replacement of another processor at least 30 days in advance, stating its name and address, the activity entrusted to it and the place of processing.
(2) The Client may object in writing within that period. If the objection is not upheld, the Client has the right to terminate the Contract by written notice without owing a penalty or compensation for the termination.
Article 17. The Provider entrusts processing activities to another processor only under a written contract imposing on it the same data protection obligations as those set out in this Agreement. The Provider remains fully liable to the Client for the performance of the other processor's obligations.
Article 18. (1) Where the Client, at its own choice, connects the Service to an external service of a third party, personal data are provided to that party on the Client's documented instructions.
(2) The provider of the external service is not another processor engaged by the Provider. The Client is responsible for its relationship with that provider and for the lawfulness of the provision of the data, including compliance with Chapter V of the Regulation where the external service is provided from a third country.
Section V. Obligations and rights of the Client
Article 19. (1) The Client determines which personal data are entered in the Service, for what purposes and for how long they are kept, and is responsible for the lawfulness of their processing, including for the existence of a legal basis.
(2) The Client provides its workers and employees, the Users and the other data subjects with the information under Articles 13 and 14 of the Regulation and makes the Users familiar with the Policy.
(3) The Client creates and manages the Users' accounts, determines their roles and permissions and is responsible for their actions in the Service.
(4) The Client enters personal identification numbers (EGN) and special categories of personal data only where it has a legal basis to do so, and does not enter copies of identity documents, driving licences or residence documents unless this is provided for by law.
(5) Where it uses the Service to monitor access, working time or labour discipline, the Client adopts the rules and procedures required by law and informs its workers and employees of them.
(6) The Client gives the Provider only lawful instructions.
Article 20. The Client has the right to give the Provider documented instructions, to receive information and carry out audits under Article 14, to object to the engagement of other processors under Article 16, to be notified of personal data breaches under Article 13 and to choose the return or erasure of the data under Article 21.
Section VI. Return and erasure of the data
Article 21. (1) After the termination of the Contract, the Provider, at the Client's choice, returns all personal data to the Client or erases them. Until that choice is made, but for no longer than 12 months after the termination, the Provider stores the Client Data solely so that they can be returned to the Client and does not process them for any other purpose.
(2) The Client states its choice in writing. The data are returned in a commonly used electronic format, and the return is certified by a written record.
(3) If the Client has not stated a choice by the end of the period under paragraph 1, the Provider returns the data to the Client by sending it an archive of them by post, to be held for collection, with advice of delivery. The archive is sent in encrypted form, and the means of accessing it is communicated to the Client separately, at the correspondence address specified in the Contract. A postal item returned as unclaimed is destroyed, and the obligation to return the data is deemed fulfilled.
(4) The Provider erases the data and their existing copies within 30 days of the signing of the record under paragraph 2, of the delivery of the postal item under paragraph 3 or of its return as unclaimed, or, where the Client has chosen erasure, of the receipt of its request, unless Union law or Bulgarian law requires their storage, and confirms the erasure in writing on request. Article 22 applies to backups and diagnostic information.
Article 22. Personal data contained in backups and in the diagnostic information under Article 7(2) are erased when the retention period of the relevant copy or record expires, but no later than 150 days after the erasure under Article 21(4). Until then they are kept subject to the measures under Article 10 and are not otherwise processed.
Section VII. Liability
Article 23. (1) Each party is liable to the other for damage resulting from non-performance of this Agreement and of its obligations under the Regulation in connection with the processing under it, regardless of the basis of the claim, subject to the limitations of liability agreed in the Contract. The same applies to the right of each party to claim back from the other compensation paid under Article 82(5) of the Regulation.
(2) The Provider is liable to the Client for the acts and omissions of the other processors under Article 17 as for its own and cannot escape liability by invoking them. Paragraph 1 applies to the amount of this liability.
(3) The limitations under paragraph 1 do not apply in the case of intent or gross negligence.
(4) This Article does not affect the rights of data subjects under Article 82 of the Regulation or the powers of the supervisory authorities, including the imposition of administrative fines under Article 83 of the Regulation.
Section VIII. Amendments to the Agreement
Article 24. (1) The Provider communicates any amendment to the Agreement directly to the Client in writing, including by electronic means, at the correspondence address specified in the Contract, together with the full text of the amendment and the date from which it takes effect.
(2) The amendment takes effect on the date specified in the communication, but not earlier than 30 days after it has been communicated, and is binding on the Client unless by that date the Client states in writing that it rejects it.
(3) If the Client rejects the amendment, the Contract continues to be performed under the previous version of the Agreement.
(4) An amendment that changes the subject matter, duration, nature or purpose of the processing, the type of personal data or the categories of data subjects takes effect only after the Client has accepted it in writing.