Privacy Notice
Last updated: [set at launch]
This Privacy Notice explains how AHELIA CONSULTING EOOD processes your personal data when you use this website, submit the contact form, correspond with us by email, or book a call with us. It describes the purposes and lawful bases for the processing, the recipients of the data, the retention periods, and your rights as a data subject under the General Data Protection Regulation (GDPR). A natural person who contacts us on behalf of a company is still a data subject, and this notice applies to them.
Controller and contact details
The data controller is AHELIA CONSULTING EOOD (АХЕЛИЯ КОНСУЛТИНГ ЕООД), EIK 200016241, with registered seat in Sofia (Mladost district), Bulgaria. ж.к. Младост 3, бл. 326, вх. 1, ап. 33
For questions regarding the processing of personal data, you may contact us by email at info@ahelia.com or in writing at the address of our registered seat.
Data Protection Officer
The company has not appointed a Data Protection Officer (DPO), as the conditions of Art. 37 GDPR do not apply to our processing activities. Questions about personal data protection can be addressed to the contact email above. (Draft default: confirm the Art. 37 assessment with counsel.)
Purposes and lawful bases for processing
We process your personal data for the following purposes and on the following lawful bases:
- Contact form, to handle your inquiry about our services, on the basis of Art. 6(1)(b) GDPR (steps prior to entering into a contract, taken at your request).
- Email correspondence, to reply to your inquiry and conduct any follow-up exchange you initiate, on the basis of Art. 6(1)(b) GDPR (pre-contractual steps) or, where no contract is contemplated, Art. 6(1)(f) GDPR (legitimate interest in responding to correspondence addressed to us).
- Booking a call, to schedule and hold the introductory call you request, on the basis of Art. 6(1)(b) GDPR (pre-contractual steps taken at your request).
- Security logs, to protect the website and its infrastructure against abuse, on the basis of Art. 6(1)(f) GDPR (legitimate interest).
We do not send marketing email and we operate no newsletter. If that ever changes, marketing communications will rest on your prior consent and this notice will be updated first.
Legitimate interests
Where we process data on the basis of legitimate interest (Art. 6(1)(f) GDPR), that interest is the prevention of abuse, the detection of security incidents, and the maintenance of network and information security for this website and the systems that handle form submissions, and, for correspondence, the ability to respond to messages addressed to us. For each such processing we carry out a balancing test in which we assess whether your interests, fundamental rights, and freedoms override our legitimate interest.
Categories of data collected
Depending on how you interact with the site, we collect the following categories of data:
- Contact form: name, company, email address, your message, and your optional answer to the "What would you automate first?" question, together with a submission timestamp.
- Email correspondence: your email address, the content of your messages, and the exchange history.
- Booking: the details you provide to the booking tool, typically name, email address, and the chosen time slot. [TBD-owner: booking provider, to be named here once selected]
- Security logs: technical data processed by our infrastructure provider when a page or the form is requested, such as IP address, user agent, and the result of the bot-protection check.
The website itself is measured with Cloudflare Web Analytics, which is cookieless and aggregates traffic data without building visitor profiles. See the Cookie Policy for the full statement of our cookieless posture.
Recipients of the data
We do not sell personal data. We share data only with service providers that process it on our behalf under a data processing agreement, or where disclosure is required by law. Recipients include:
| Hosting, content delivery, bot protection, and analytics | Cloudflare, Inc. (USA). The website is served through Cloudflare, the contact form is protected by Cloudflare Turnstile, and form submissions are handled by a Cloudflare Worker with an audit log. |
|---|---|
| Email delivery | Resend (USA), which delivers contact-form submissions to us as email. |
| Call booking | [TBD-owner: booking provider and its jurisdiction, once selected]. The provider will be added here with its transfer safeguard before the booking feature goes live. |
| Public authorities | where required pursuant to a lawful request. |
International data transfers
Cloudflare, Inc. and Resend receive data in the USA. Transfers to them rest on their certification under the EU-US Data Privacy Framework, which the European Commission has recognised as providing an adequate level of protection, and/or on the European Commission Standard Contractual Clauses (2021). (Draft note: verify the current DPF certification status of each processor at go-live; where a processor is not certified, the Standard Contractual Clauses apply, accompanied by a transfer impact assessment and supplementary measures where necessary.)
If the Data Privacy Framework ceases to apply or is unavailable for a given recipient, transfers are carried out on the basis of the Standard Contractual Clauses as described above.
Retention periods
We retain personal data only for the period necessary for the relevant purpose. The following periods are proposed defaults, subject to counsel confirmation before go-live:
| Contact-form submissions and related correspondence | 24 months from our last exchange with you. |
|---|---|
| Booking data held by us | 24 months from the call. The booking provider retains its own records under its own policy, which will be referenced here once the provider is selected. [TBD-owner] |
| Form audit log (Cloudflare Worker KV) | 12 months from submission. |
| Security logs | 90 days. |
Data needed to establish, exercise, or defend legal claims, or that we must keep under accounting and tax legislation, may be retained for the longer statutory period.
Your rights as a data subject
You have the right to: access your data, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interest.
Where any processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal. At present no processing described in this notice rests on consent; if a consent-based activity is added, the withdrawal path will be stated here.
You may exercise your rights by email at info@ahelia.com or in writing at the address of our registered seat. We respond within one month of receiving the request, as required by Art. 12(3) GDPR.
Complaint to a supervisory authority
If you consider that the processing of your personal data infringes the applicable legislation, you have the right to lodge a complaint with the supervisory authority:
Commission for Personal Data Protection (Комисия за защита на личните данни, КЗЛД), 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria, email kzld@cpdp.bg, phone +359 2 915 3 518.
If you are located in another EU or EEA member state, you may also complain to the supervisory authority of your habitual residence or place of work.
AHELIA CONSULTING EOOD is established in the EU (Bulgaria), so no EU representative under Art. 27 GDPR is needed.
Whether providing data is required
Providing data through the contact form or the booking tool is voluntary, but it is necessary for us to process your inquiry or schedule your call. Without it, we would be unable to respond or to hold the call. Nothing on this website requires you to provide personal data in order to read it.
The contact form asks you to tick a box confirming that you have read this notice before submitting. That confirmation is a transparency measure and a record that the notice was provided at the point of collection; the lawful basis for processing the form data remains Art. 6(1)(b) GDPR as stated above, not consent.
Automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR is carried out. The bot-protection check on the contact form distinguishes humans from automated traffic and produces no legal or similarly significant effect on you.
For visitors from the United States
We serve clients in the United States, so we state our position on US state privacy laws (such as the California Consumer Privacy Act as amended, and comparable laws in other states). Based on our size, revenue, and the volume of personal data we process, AHELIA CONSULTING EOOD does not currently meet the applicability thresholds of these laws. (Draft default: threshold assessment to be confirmed with counsel.)
Regardless of formal applicability, if you are a US resident and ask us to disclose, correct, or delete the personal data we hold about you, we will honor the request on the same terms as the GDPR rights described above. Contact us at info@ahelia.com. We do not sell or share personal data as those terms are defined in US state privacy laws, and we do not use personal data for targeted advertising.
Changes to this notice
We may update this notice when our processing, our providers, or the applicable law changes. The date at the top shows the current version. Material changes will be highlighted on this page.