Privacy Policy
BalkanOps Ltd. ('we', 'us', 'our') respects your privacy and is committed to protecting your personal data. This privacy policy will inform you about how we process your personal data and your rights under the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
1. Data Controller
BalkanOps Ltd. is the data controller and responsible for your personal data. We are registered in Bulgaria and you can contact us at office@balkanops.com or +359 888 123 456.
2. Legal Basis for Processing
We process your personal data on the following legal grounds: (a) contract performance - to process your order and deliver products; (b) legitimate interest - to improve our services and prevent fraud; (c) consent - for marketing communications and analytics (where applicable); (d) legal obligations - to comply with accounting and tax requirements.
3. What Data We Collect
We collect and process the following categories of personal data:
- Identity data: first name, last name, phone number, email address (optional)
- Order data: delivery address, preferred courier, delivery notes, custom clothing measurements
- Technical data: IP address, browser type, device information (for site functionality only)
- Communication data: correspondence with our support team, reviews, inquiries
4. How We Use Your Data
We use your personal data for the following purposes:
- Order processing and fulfillment: to deliver products you've ordered, including creating custom-sized garments
- Communication: to send order confirmations, delivery updates, and customer service
- Legal obligations: to comply with accounting, tax, and other legal requirements (retaining invoices for 10 years per Bulgarian law)
- Service improvements: to analyze trends and improve our website and services (only with your consent)
5. Data Retention
We retain your personal data only as long as necessary for the purposes for which we process it. Order and invoice data is stored for 10 years in accordance with Bulgarian tax law. Customer support data is retained for 3 years. Technical data (logs) is automatically deleted after 90 days. Marketing data (if you've subscribed) is retained until consent withdrawal.
6. Your Rights Under GDPR
Under GDPR, you have the following rights:
- Right of access: to request a copy of your personal data we process
- Right to rectification: to request correction of inaccurate or incomplete data
- Right to erasure ('right to be forgotten'): to request deletion of your data under certain conditions
- Right to restriction: to request restriction of processing of your data
- Right to data portability: to receive your data in a structured, commonly used format
- Right to object: to object to processing of your data for certain purposes
- Right to lodge a complaint: to file a complaint with the Commission for Personal Data Protection (CPDP) in Bulgaria
7. Your Rights Under CCPA (California Residents)
If you are a California resident, you have the following additional rights:
- Right to know: what personal data we collect, use, disclose, and sell
- Right to deletion: to request deletion of your personal data
- Right to opt-out: to opt-out of the sale of your personal data (Note: We DO NOT sell personal data)
- Right to non-discrimination: not to be discriminated against for exercising your CCPA rights
8. Data Security
We have implemented appropriate technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction. All data is transmitted via secure SSL/TLS connections. Access to personal data is restricted to authorized personnel only. We regularly backup data and use encryption for sensitive information. However, no method of transmission over the internet or electronic storage is 100% secure.
9. Third-Party Sharing
We only share your data with trusted third parties necessary to fulfill our services: Courier services (Speedy, Econt, InTime, BoxNow) - name, phone, delivery address only. Email service providers (Resend, Sender.net) - only for sending order confirmations and newsletters (if you provided email). Google reCAPTCHA - to protect forms from spam and abuse. This service collects hardware and software information such as device and application data, and sends it to Google for analysis. For more information, see Google's Privacy Policy and Terms of Service. Analytics and marketing services (only if you accept cookies) - Google Analytics 4, Google Tag Manager, Meta (Facebook) Pixel, TikTok Pixel, LinkedIn Insight Tag, Twitter/X Pixel - used for traffic analysis, improving user experience, and retargeting ads. These services collect data about user behavior, including visited pages, clicks, time on site, device, and browser. Google Tag Manager is a tag container for managing multiple tracking codes from one place and includes consent mode support for GDPR compliance. All these services load ONLY if you accept cookies and you can withdraw your consent at any time. Accounting services - for legal obligations only. We DO NOT sell, rent, or trade your personal data to third parties for marketing purposes.
10. International Transfers
Your data is processed primarily within the European Economic Area (EEA). Some of our service providers may process data outside the EEA. In such cases, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
11. Children's Privacy
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us.
12. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the 'Last Updated' date. We recommend reviewing this policy periodically for any changes.
13. Email Communication and Marketing
If you provide an email address, we will use it only for: order confirmations and delivery updates, responses to your inquiries, newsletter subscription (only if you've explicitly subscribed). You can unsubscribe from marketing emails at any time via the link at the bottom of each email or by contacting us.
14. Cookie Policy
We use cookies to improve the user experience on our site. Cookies are small text files stored on your device. You can manage your cookie preferences through our consent banner that appears on your first visit.
Essential Cookies
These cookies are strictly necessary for the site to function and cannot be disabled. They include: cart storage, language preferences, cookie consent. These cookies do not store personally identifiable information.
Analytics and Marketing Cookies
We currently DO NOT use third-party analytics, tracking, or marketing cookies (such as Google Analytics, Facebook Pixel, etc.). If we decide to add them in the future, we will explicitly request your consent before activating them.
15. Contact Us
If you have questions about this privacy policy or wish to exercise your rights, please contact us:
Company: BalkanOps Ltd.
Email: privacy@balkanops.com
Phone: +359 888 123 456