Privacy Policy and Personal Data Protection of "R Software" Ltd.

Last updated: 30 July 2026

I. General provisions

This Policy aims to inform visitors and partners of the tattoobook.bg website about the way "R Software" Ltd. ("the Company", "we") collects, uses, stores and protects their personal data. The Company processes personal data in accordance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC ("General Data Protection Regulation" or GDPR), and the Bulgarian Personal Data Protection Act.

Definitions:

  • "Personal data" means any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • "Data controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
  • "Data processor" means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
  • "Processing" means any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • "Consent of the data subject" means any freely given, specific, informed and unambiguous indication of the data subject's wishes, by a statement or by a clear affirmative action, signifying agreement to the processing of personal data relating to him or her.

As a data controller, "R Software" Ltd. processes personal data only on the grounds provided for in the General Data Protection Regulation and the Personal Data Protection Act. Personal data is processed only where a legal ground exists, including:

  • consent of the data subject. This consent may be withdrawn at any time. Withdrawal takes effect for the future and does not affect the lawfulness of processing carried out before it;
  • compliance with a legal obligation;
  • protection of a legitimate interest of the controller.

II. Data controller details

The data controller is "R Software" Ltd., UIC 175315897.

Email: [email protected] (Georgi Ivanov)

Website: www.tattoobook.bg

III. Contact regarding personal data protection

The contact person for personal data protection matters is Georgi Ivanov, email: [email protected]

Supervisory authority:

Commission for Personal Data Protection (CPDP)

Sofia 1592, 2 "Prof. Tsvetan Lazarov" Blvd.

tel. +359 2 915 3518 | e-mail: [email protected]

Website: www.cpdp.bg

IV. What personal data we process

When using the website and contacting us, the following categories of data may be processed:

  • First and last name
  • Email and/or phone number (when filling in a contact form or sending an inquiry)
  • Representative data of a venue/partner (when applying for partnership)
  • Technical data — IP address, logs and cookies. Cookies needed to run the website are used without consent; analytics and marketing cookies only if you agree to them (see section X).

V. Purposes and legal grounds for processing

Processing is carried out only when necessary for:

  • Responding to inquiries and communication with users and partners — Art. 6(1)(b) GDPR (pre-contractual steps).
  • Performance of a contract or pre-contractual steps at the request of the data subject — Art. 6(1)(b).
  • Compliance with legal obligations — Art. 6(1)(c) (e.g. accounting requirements).
  • Marketing communications — only with explicit consent (Art. 6(1)(a)).
  • Protection of a legitimate interest — e.g. improving the website and preventing abuse (Art. 6(1)(f)).

VI. Recipients of personal data

The Company does not disclose personal data to third parties, except:

  • to trusted hosting, accounting and IT service providers, bound by confidentiality agreements;
  • to state authorities, when required by law.

VII. Retention period

  • Inquiry data is stored for up to 12 months after the correspondence ends.
  • Data processed on the basis of a contract is kept for up to 5 years after the contract expires or the applicable legal retention periods.
  • Data processed on the basis of consent is kept until the consent is withdrawn.
  • After the expiry of these periods, the data is deleted or anonymised.

VIII. Your rights as a data subject

As a data subject, you have the following rights:

  • Right of access to your personal data processed by the Controller;
  • Right to request rectification, erasure or restriction of your personal data;
  • Right to be notified before your personal data is first disclosed to a third party;
  • Right to object to the processing of your personal data by the Controller;
  • Right to erasure ("the right to be forgotten"), where the conditions of Art. 17 of the GDPR apply;
  • Right to withdraw your consent to the processing of personal data by the Controller at any time;
  • Right to lodge a complaint with the Commission for Personal Data Protection, address: Sofia, postal code 1592, 2 "Prof. Tsvetan Lazarov" Blvd., tel. +359 2 915 3518, email: [email protected], if you believe your rights regarding the protection of your personal data have been violated.

These rights may be exercised by a written request sent to [email protected] (Georgi Ivanov).

IX. Data protection

"R Software" Ltd. applies organisational and technical measures to protect personal data — encrypted communication (HTTPS), restricted access to databases, access control, and regulated procedures for archiving and destroying data.

X. Cookies and analytics

A cookie is a small file stored by your browser. We divide them into three groups, and you choose which of the optional ones we may use when you first visit the site.

  • Strictly necessary — keep you signed in, remember your chosen language, and store your cookie choice itself. These are required for the website to work, so they are used without consent. We ask for your choice again from time to time.
  • Analytics — Google Analytics 4, used only if you agree. It tells us which pages are visited and how the site is used, so we can improve it. Its cookies expire within 13 months at most.
  • Marketing — used only if you agree, to measure whether our advertising brings visitors to the site and to show more relevant ads.

Until you accept analytics or marketing, nothing is loaded from Google and no such cookie is created. If you decline, no request is made to Google at all.

Where you have agreed, the recipient of this data is Google Ireland Ltd. Data may be transferred outside the EU under the European Commission's standard contractual clauses.

You may change or withdraw your consent at any time via the "Cookie Settings" link in the site footer, with the same ease as giving it. Withdrawal does not affect processing carried out before it.

XI. Policy updates

This Policy may be updated following changes in legislation or in the way we process data. The updated version will be published on the tattoobook.bg website.