Breadcrumb
-
Home
- Privacy policy
Privacy policy
Last updated: 28.08.2026
1. Who we are
Aperseco EOOD (“Aperseco”, “we”, “us”) is a single-owner limited liability company registered in the Commercial Register and Register of Non-Profit Legal Entities of the Republic of Bulgaria.
- Company: Aperseco EOOD
- UIC (ЕИК): registration with the Bulgarian Commercial Register is in progress
- VAT number: not yet VAT-registered.
- Registered seat: blvd. "Makedonia" 34, 1606 Sofia, Bulgaria
- Represented by: Predrag Tasevski, Manager
- Email: privacy@aperseco.eu
- Website: https://aperseco.eu
We are the data controller for personal data processed through this website.
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Privacy questions go to the address above.
2. What this policy covers
This policy explains how we handle personal data of visitors to aperseco.eu.
It does not cover personal data that we process on behalf of our clients when operating their infrastructure. In that role we act as a processor, not a controller: our client decides what is processed and why, and the terms are set out in a Data Processing Agreement concluded under Article 28 GDPR. If you are a data subject of one of our clients, please contact that client — they are your controller. Section 9 below summarises how we work as a processor.
3. What we collect, why, and on what legal basis
3.1 Contact form
When you submit the contact form we receive your name, organisation, email address, the EU programme you select, and your message.
- Purpose: to answer your enquiry and, where relevant, to scope and quote for our services.
- Legal basis: Article 6(1)(b) GDPR (steps at your request prior to entering into a contract) and, where you are enquiring on behalf of an organisation, Article 6(1)(f) GDPR (our legitimate interest in responding to business enquiries).
- Retention: 24 months from our last correspondence with you, unless the enquiry leads to a contract, in which case it is retained under Section 3.4.
The form is protected by FriendlyCaptcha, a privacy-focused, self-hosted spam prevention tool. It performs a computation in your browser and does not profile you, track you across sites, or set advertising cookies. The form also uses a hidden honeypot field, which processes no personal data.
Providing your name, email and message is necessary for us to reply. If you would rather not use the form, email us directly.
3.2 Server logs
Our web server records each request in a log file: IP address, date and time, the URL requested, HTTP status code, referrer, and browser user-agent string.
- Purpose: to operate the site securely, detect and investigate attacks and abuse, and diagnose faults.
- Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is the security and availability of our own infrastructure — an interest recognised in Recital 49 GDPR.
- Retention: [14] days, after which logs are deleted automatically.
3.3 Analytics
We use Matomo, an open-source analytics tool that we host ourselves on our own EU infrastructure. No analytics data is sent to any third party, and we do not use Google Analytics or any advertising or profiling network.
We configure Matomo to anonymise IP addresses before storage, so that we cannot identify individual visitors; to operate without cookies and without cross-site tracking; and to respect your browser’s Do Not Track setting.
- Purpose: to understand which pages are read and how the site performs, so we can improve it.
- Legal basis: Article 6(1)(f) GDPR — our legitimate interest in understanding and improving our own website. Because the data is anonymised at collection and no cookies or similar technologies are stored on your device, no consent is required under Article 5(3) of the ePrivacy Directive.
- Retention: aggregated reports for [24] months; raw visit data for [6] months.
3.4 Client and supplier records
If we enter into a contract with you or your organisation, we process the names, business contact details and correspondence of the individuals involved.
- Purpose: to perform the contract, provide support, and meet our accounting and tax obligations.
- Legal basis: Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(c) GDPR (legal obligation, in particular under the Bulgarian Accountancy Act).
- Retention: for the life of the contract, then for the statutory retention periods under Bulgarian accounting and tax law — generally 5 years for accounting records and 10 years for payroll-related records.
4. Cookies and local storage
This website sets no analytics, advertising, or profiling cookies, and we do not embed third-party content that could set them.
The site loads no external resources whatsoever — all fonts, stylesheets, scripts and images are served from our own servers. Nothing about your visit reaches a third party by loading the page.
A strictly necessary session cookie may be set if you log in to an administrative area of the site, and a cookie may be used to carry a security token on form submission. These are exempt from the consent requirement under Article 5(3) of the ePrivacy Directive because they are strictly necessary to provide a service you have requested.
Because we set no non-essential cookies, this site displays no cookie consent banner.
5. Who we share data with
We do not sell personal data, and we do not share it for advertising.
We disclose personal data only to:
- Our hosting provider, [PROVIDER NAME], which operates the data centre in [COUNTRY], acting as our processor under Article 28 GDPR;
- Our accountants and auditors, where required for statutory bookkeeping;
- Public authorities, where we are legally obliged to disclose;
- Unicis.Tech, our compliance and advisory partner, only where you have asked us to involve them in your project or where our engagement includes their advisory services. We do not pass on enquiry data automatically.
6. International transfers
None. All personal data described in this policy is stored and processed on infrastructure located within the European Union. We do not transfer personal data to countries outside the EU/EEA, and we do not use service providers subject to third-country access regimes for this data.
This is a deliberate design choice, not merely a statement of current practice. If it ever changes, we will update this policy and rely on a valid Chapter V GDPR transfer mechanism.
7. How we protect data
We apply the same security practices to our own systems that we build for clients: encryption in transit (TLS), access control on a least-privilege basis, multi-factor authentication for administrative access, monitoring and alerting, encrypted backups, and prompt patching.
No system is perfectly secure, but we will notify you and the supervisory authority of a personal data breach where the GDPR requires it.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Article 15);
- rectify inaccurate or incomplete data (Article 16);
- erase your data where the grounds in Article 17 apply;
- restrict processing in the circumstances set out in Article 18;
- data portability for data you provided to us, where processing is based on consent or contract and carried out by automated means (Article 20);
- object to processing based on our legitimate interests, on grounds relating to your particular situation (Article 21) — including our analytics and log processing;
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, email privacy@aperseco.eu. We will respond within one month, which we may extend by two further months for complex requests, telling you if we do. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects (Article 22).
9. When we act as a processor for our clients
When we operate infrastructure for a client — file storage, email, project management, monitoring, or any other service in our stack — we process personal data on that client’s documented instructions and for no other purpose. We:
- conclude a written Data Processing Agreement under Article 28 GDPR with every client;
- maintain a record of processing activities under Article 30(2) GDPR;
- name every sub-processor and give clients advance notice of any change;
- assist clients with data subject requests, breach notification, and data protection impact assessments;
- return or delete client data at the end of the engagement, at the client’s choice;
- keep all such data within the European Union.
Because open-source software gives us full control over where data sits and who can reach it, our clients retain a genuine exit path. We will export a client’s data in a usable, documented format on request.
10. Complaints
If you believe we have handled your personal data unlawfully, we would prefer you tell us first so we can put it right. You also have the right to lodge a complaint with the Bulgarian supervisory authority:
Commission for Personal Data Protection (Комисия за защита на личните данни)
2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
Telephone: +359 2 915 3518
Email: kzld@cpdp.bg
Web: https://www.cpdp.bg
If you live or work in another EU Member State, you may complain to your local supervisory authority instead.
11. Changes to this policy
We will update this policy when our processing changes. The date at the top shows when it was last revised. Where a change materially affects your rights, we will say so prominently on this page.
12. Contact
Questions about this policy or about how we handle personal data:
Aperseco EOOD
blvd. "Makedonia" 34, 1606 Sofia, Bulgaria
privacy@aperseco.eu