Privacy Policy
Last updated: 8 October 2026
This Privacy Policy explains how Shtrak BG Ltd ("Shtrack", "we", "us") collects and uses personal data when you visit www.shtrack.com, contact us or book a consultation. We process personal data under the EU General Data Protection Regulation (GDPR) and Bulgarian data protection law.
Summary
- We collect what you send us through forms, and technical data needed to run and protect the website.
- Analytics cookies are used only after you agree to them. You can change your choice at any time.
- We do not sell your personal data.
- You can ask us to access, correct or delete your data by writing to [email protected].
1. Who is responsible for your data
The data controller is:
Shtrak BG Ltd
72 Tzar Osvoboditel Blvd, office 1, 9000 Varna, Bulgaria
UIC: 201099172
VAT: BG201099172
Email: [email protected]
2. What data we collect
- Data you give us. Your name, email address, phone number, company name, job role and anything else you write in a contact form or a booking.
- Usage data. Your IP address, browser and device type, pages you visit, the time of your visit, the page that referred you, and similar technical information.
- Cookie data. Identifiers stored in cookies and similar technologies. Details are in our Cookie Policy.
You do not have to give us any personal data. If you do not, we may not be able to answer your enquiry.
3. Why we use your data, and the services involved
Running and securing the website, and handling your requests
Website hosting (DigitalOcean, LLC)
- Purpose
- Hosting the website, its database and the messages sent through our forms.
- Data
- All data processed by the website, including form submissions, server logs and IP addresses.
- Legal basis
- Our legitimate interest in running the website (GDPR Art. 6(1)(f)), and the legal bases of the processing it supports.
- Where
- European Union (servers in the EU). DigitalOcean, LLC is based in the USA.
- Transfer safeguard
- EU–US Data Privacy Framework and Standard Contractual Clauses, for any access from outside the EU.
- More
- Provider privacy policy
Contact forms (This website (Contact Form 7))
- Purpose
- Receiving and answering enquiries and consultation requests you send us.
- Data
- Name, email address, phone number, company name, the content of your message, and any other details you choose to include.
- Legal basis
- Steps at your request before entering into a contract, and our legitimate interest in answering enquiries (GDPR Art. 6(1)(b) and (f)).
- Where
- European Union (DigitalOcean servers in the EU)
- Kept for
- Up to 24 months after our last contact, unless a contract follows.
Google reCAPTCHA (Google Ireland Limited)
- Purpose
- Protecting our forms and login from spam and automated abuse.
- Data
- Usage data, device and browser information, IP address, and the cookies and interaction signals Google uses to tell humans from bots.
- Legal basis
- Our legitimate interest in keeping the website secure (GDPR Art. 6(1)(f)).
- Where
- Ireland / USA
- Transfer safeguard
- EU–US Data Privacy Framework.
- More
- Provider privacy policy
Cloudflare (Cloudflare, Inc.)
- Purpose
- Content delivery, performance and protection against attacks and bots.
- Data
- IP address, request data and technical cookies.
- Legal basis
- Our legitimate interest in a fast and secure website (GDPR Art. 6(1)(f)).
- Where
- Global network, Cloudflare, Inc. is based in the USA
- Transfer safeguard
- EU–US Data Privacy Framework and Standard Contractual Clauses.
- More
- Provider privacy policy
Wordfence (Defiant, Inc. (plugin running on this website))
- Purpose
- Firewall and login security for this website.
- Data
- IP address, request data, and login attempts.
- Legal basis
- Our legitimate interest in keeping the website secure (GDPR Art. 6(1)(f)).
- Where
- European Union (DigitalOcean servers in the EU). Threat data may be exchanged with Defiant, Inc. (USA).
- Transfer safeguard
- Standard Contractual Clauses.
- More
- Provider privacy policy
Google Tag Manager (Google Ireland Limited)
- Purpose
- Loading our analytics tags. Tag Manager itself does not set cookies, and the tags it loads follow your consent choices.
- Data
- Usage data and IP address.
- Legal basis
- Our legitimate interest in managing website tags (GDPR Art. 6(1)(f)).
- Where
- Ireland / USA
- Transfer safeguard
- EU–US Data Privacy Framework.
- More
- Provider privacy policy
Vimeo (Vimeo.com, Inc.)
- Purpose
- Playing videos embedded on our pages. Our embeds use Vimeo's "do not track" mode, so Vimeo does not set tracking cookies.
- Data
- IP address and technical playback data.
- Legal basis
- Our legitimate interest in showing video content (GDPR Art. 6(1)(f)).
- Where
- USA
- Transfer safeguard
- Standard Contractual Clauses.
- More
- Provider privacy policy
Calendly (Calendly, LLC)
- Purpose
- Booking a consultation. Our booking buttons open Calendly's own website, where Calendly processes the details you enter.
- Data
- Name, email address, booking time and any answers you give in the booking form.
- Legal basis
- Steps at your request before entering into a contract (GDPR Art. 6(1)(b)).
- Where
- USA
- Transfer safeguard
- EU–US Data Privacy Framework and Standard Contractual Clauses.
- More
- Provider privacy policy
Analytics (only with your consent)
Google Analytics 4 (Google Ireland Limited)
- Purpose
- Measuring how visitors use the website so we can improve it.
- Data
- Usage data, pages visited, approximate location, device and browser information, cookie identifiers.
- Legal basis
- Your consent (GDPR Art. 6(1)(a)).
- Where
- Ireland / USA
- Transfer safeguard
- EU–US Data Privacy Framework.
- More
- Provider privacy policy · Opt out
Microsoft Clarity (Microsoft Corporation)
- Purpose
- Heatmaps and session recordings that show how visitors interact with our pages.
- Data
- Usage data, mouse movements, clicks and scrolls, device and browser information, cookie identifiers. Form inputs are masked.
- Legal basis
- Your consent (GDPR Art. 6(1)(a)).
- Where
- USA
- Transfer safeguard
- EU–US Data Privacy Framework.
- More
- Provider privacy policy
Clients and business contacts
If you or your company become our client, we process the contact details of your team to perform our contract and to meet accounting and tax obligations. The service agreement may contain further terms on data processing, including a data processing agreement where we process personal data on your behalf.
4. Who we share data with
- The service providers listed above, who process data for us under contract or as independent controllers under their own privacy policies.
- Our accountants, lawyers and auditors where needed.
- Public authorities when the law requires it.
- A buyer or successor of our business, if the business is reorganised or sold.
We do not sell personal data.
5. Transfers outside the European Economic Area
Some providers process data in the United States or other countries outside the EEA. We rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework where the provider is certified, and on Standard Contractual Clauses approved by the European Commission otherwise. You can ask us for a copy of the relevant safeguards.
6. How long we keep data
- Enquiries that do not lead to a contract: up to 24 months after our last contact.
- Client and accounting records: for as long as Bulgarian accounting and tax law requires, normally up to 10 years.
- Cookies: for the periods stated in the Cookie Policy.
- Security logs: for a short period, normally no more than 90 days, unless needed to investigate an incident.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy;
- have inaccurate data corrected;
- have your data deleted;
- restrict how we use your data;
- receive your data in a portable format;
- object to processing based on our legitimate interests, and to direct marketing at any time;
- withdraw your consent at any time, without affecting processing done before you withdrew it. For cookies, use Cookie settings.
To use any of these rights, email [email protected]. We answer within one month. We may ask you to confirm your identity first.
You can also complain to the Bulgarian supervisory authority: Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd, 1592 Sofia, Bulgaria, https://www.cpdp.bg/, or to the authority in the EU country where you live or work.
8. Automated decisions
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
9. Security
We use encryption in transit, a web application firewall, access controls and regular updates to protect personal data. No system is completely secure, so please tell us at once if you believe your data has been put at risk.
10. Children
This website is meant for businesses and is not directed at children under 16. We do not knowingly collect their data.
11. Visitors from the United States
Depending on the state where you live, you may have the right to know what personal information we collect and to correct or delete it. We do not sell personal information, and we do not share it for cross-context behavioural or targeted advertising. To make a request, email [email protected]. We will not treat you differently for using these rights.
12. Changes to this policy
We may update this policy when our services or the law change. The date at the top shows the latest version. If a change needs your consent again, we will ask for it through the cookie banner.
13. Contact
Shtrak BG Ltd
72 Tzar Osvoboditel Blvd, office 1, 9000 Varna, Bulgaria
UIC: 201099172
VAT: BG201099172
Email: [email protected]
