Privacy Policy
Last updated: 1 October 2026.
The data controller is "SpestiVreme" OOD, email: [email protected].
This policy describes what data we collect through the site, why, who processes it, and what rights you have.
1. What data we collect
Diagnostic form: name, company, email, phone (optional), business type, and a description of the process you want to automate (frequency, handling time, data sources and destinations, success metric, timeline).
ROI calculator: the numbers you enter are computed entirely in your browser. They reach us only if you choose to include them in your request.
Browser storage: localStorage keeps only your email and process description to recover an unfinished attempt, for up to 24 hours. The copy is deleted after confirmed delivery, when you start a new request, or through the visible “Delete saved form data” action. sessionStorage may keep an ROI estimate until the tab closes. This data never leaves your device except when you submit the form.
Analytics: PostHog (EU cloud). Until you choose, or if you decline, we collect anonymous statistics without cookies and without storing anything in your browser: PostHog computes on its servers a hash of your IP address and browser with a random value that changes daily, without keeping the IP address, so visits on different days cannot be linked. If you accept, PostHog also stores an identifier in your browser to recognize repeat visits and may record interactions with the site to improve usability. We mask input values, page text and attributes; enquiry content, URL parameters, console messages and error text are excluded. Recording starts only after acceptance and stops on withdrawal. Your choice is remembered and can be changed through a visible page control.
2. Why we process it and on what basis
- Responding to your inquiry and preparing a diagnostic/offer — the form permission confirms that we may reply.
- Internal organization of inquiries — automated summary, priority, and reply draft for human review through configured internal tools and service providers — legitimate interest (Art. 6(1)(f)).
- Improving the site through analytics — anonymous statistics without cookies: legitimate interest (Art. 6(1)(f)); an identifier in your browser: only with your consent (Art. 6(1)(a)).
Important: we make no automated decisions with legal or similarly significant effect on you. Internal summaries and drafts are only for human review — every message to you is reviewed and sent personally by a human.
3. Who has access to the data (processors)
We use the following service providers, each strictly for its role:
- Cloudflare — site hosting and form intake;
- automation and model service providers — organizing inquiries, summaries, and drafts for human review;
- Google Workspace (Gmail) — email correspondence;
- PostHog (EU) — analytics, when active.
Some of these providers may process data outside the EEA. For each provider actually used, we document whether a transfer occurs and, where applicable, the GDPR Chapter V mechanism and necessary supplementary measures. We do not sell personal data or share it for advertising.
4. How long we keep the data
Inquiries that did not lead to a contract: up to 6 months from the last contact, then deleted. Under a contract — for its duration and per statutory obligations (e.g. accounting).
You can request earlier deletion at any time (see section 5).
5. Your rights
- access to your data and a copy of it;
- rectification of inaccurate data;
- erasure ("right to be forgotten");
- restriction of and objection to processing;
- data portability;
- withdrawal of consent at any time, without affecting prior lawful processing.
To exercise your rights, write to [email protected]. We will respond within one month. You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP, cpdp.bg).
6. Cookies and local storage
The site uses no advertising or profiling cookies. We use localStorage for the minimal 24-hour unfinished-form copy and the analytics choice, and sessionStorage for a temporary ROI estimate. PostHog stores data in your browser and may record masked interactions only after acceptance, without advertising purposes. Without acceptance, PostHog works without cookies, browser storage or session recording.
7. Do not send sensitive data
Please do not include passwords, API keys, national ID numbers, financial or health data, or sensitive client documents in the form. The system makes a best-effort redaction of obvious secrets in the notification email and in our internal records, but the submission itself is kept as sent for up to 30 days at Cloudflare (form intake), then deleted. So the safest protection is not sending them at all. Such data is discussed only within a contracted project with its own data-handling rules.
8. Changes and contact
If this policy changes, we will update the date at the top. Questions: [email protected].