Privacy Policy
Version 1.2 — in force from 12 August 2026. The change from 1.1: this policy described payments, card handling and credit ledgers that do not exist. Nothing is sold, so all of it is gone. Version 1.1 stopped writing visitors' IP addresses to our server logs.
This explains what we do with information about you. It is written to be understood rather than to be technically unassailable, but it is accurate: every item below corresponds to something the software actually does.
1. Who is responsible
The data controller is "SYNTOPIA" EOOD („СИНТОПИЯ" ЕООД), a single-member limited liability company, UIC 208876257, registered at Chayka district, bl. 9, entr. B, fl. 3, apt. 25, 9000 Varna, Bulgaria.
Contact for anything in this document: office@syntopia.bg.
We have not appointed a Data Protection Officer. We are not required to: we do not monitor people on a large scale and we do not process special categories of data.
2. What we collect, and why
When you register
| What | Why | Legal basis |
|---|---|---|
| Email address | It identifies your account, it is where password resets and service notices go | Performance of our contract with you — Art. 6(1)(b) GDPR |
| Password | So you can get back in | Contract — Art. 6(1)(b) |
| The date you registered | Account administration, and working out what you are owed | Contract — Art. 6(1)(b) |
Your password is stored as an Argon2id hash, never as text. We cannot read it, recover it, or tell you what it is — only replace it.
If you sign in with Google
| What | Why | Legal basis |
|---|---|---|
| Your Google account identifier | It links your Google login to your Deklarify account | Contract — Art. 6(1)(b) |
| The email address on your Google account, and whether Google has verified it | To create or identify the account | Contract — Art. 6(1)(b) |
We ask Google for two things only — openid and email. We do not ask for,
and cannot see, your contacts, your calendar, your files, your Google profile
photo, or anything else. You can disconnect Google from your account at any
time, provided you have a password to get back in with.
When you use the site
| What | Why | Legal basis |
|---|---|---|
| Which company reports you have opened, and when | It is how the free-report count works — three new companies a month, and a company you have already opened does not use another | Contract — Art. 6(1)(b) |
| Session records (a hashed token, when it was made, when it expires) | Keeping you logged in | Contract — Art. 6(1)(b) |
| Password-reset records (a hashed token and its timestamps) | Letting you reset a password safely, once | Contract — Art. 6(1)(b) |
We want to be direct about the first row. The list of companies you have looked up says something about your financial interests. We keep it because the product cannot work without it — it is the record of what you already own — and for no other reason. We do not profile you with it, we do not sell it, and we do not use it to target anything at you.
Automatically, whenever anyone visits
| What | Why | Legal basis |
|---|---|---|
| Your IP address, for as long as it takes to serve the request | Rate limiting, and refusing traffic that is attacking the site | Our legitimate interest in keeping the service up and unabused — Art. 6(1)(f) |
We do not write it down. Our request log records which page was asked for, what the answer was and how long it took — not who asked. Your address is held in the server's memory only for as long as the rate limiter counts it, which is an hour at the most, and a sweep runs every minute to drop it once that hour is up. Hetzner, whose machine this runs on, keeps network logs of its own under its own policy; those are not ours to read.
Only if you agree
| What | Why | Legal basis |
|---|---|---|
| Google Analytics: pages viewed, roughly where you are, what device and browser, and a random identifier that recognises your browser on a later visit | Understanding which parts of the site people use, so we build the right things | Your consent — Art. 6(1)(a), and Art. 5(3) of the ePrivacy Directive for storing it on your device |
Nothing analytics-related loads until you say yes. If you decline, or ignore the banner, no Google Analytics code runs at all — not in a limited mode, not anonymously, not at all. You can change your mind either way, at any time, from Cookie settings in the footer. See the Cookie Policy.
3. What we do not do
- We do not sell your data. Not to anyone, at any price.
- We do not use it for advertising, and we run no ad networks.
- We do not send marketing email you did not ask for. Every email we send is about your own account: confirming your address when you register, and password resets.
- We do not knowingly collect anything about anyone under 18, who should not be using the site at all.
- We do not ask for special category data — health, beliefs, politics, and so on — and you should not send it to us.
- We make no automated decisions about you that have legal or similarly significant effects. Our reports are generated by software, but they are about listed companies, not about you; nothing we run scores, ranks, or profiles the reader.
4. Who else sees it
We use a small number of outside services to run Deklarify. Each is bound by a contract that lets it use the data only to serve us.
Every one of them is listed, by name and country, in processors.md. That list is part of this policy, and it is kept current — if we add a service that touches personal data, it appears there.
Beyond that list, we disclose data only where the law requires it, or to professional advisers under a duty of confidence, or to a buyer if the business is sold — in which case we would tell you first.
5. Data leaving the EU
We keep things in the EU where we can. Some of our providers are American, or are European subsidiaries of American companies that may involve their parent.
Where data goes outside the EEA it is protected by the European Commission's Standard Contractual Clauses, and in some cases additionally by the provider's certification under the EU–US Data Privacy Framework, which the Commission has found to give adequate protection.
Which provider relies on what is set out in processors.md.
6. How long we keep it
| What | How long |
|---|---|
| Your account, and the record of which reports you opened | Until you close your account, then deleted within 30 days |
| Login sessions | 30 days, then they expire and are removed. Logging out ends one immediately |
| Password-reset tokens | 60 minutes, or until used — whichever comes first |
| Consent records | While we rely on the consent, and 3 years after it ends, so we can show it was given |
| Our server's request logs | Capped by size and rolled over, which at our traffic is a matter of weeks. They record no IP address and nothing else that identifies you |
| Google Analytics data | 14 months |
Closing your account removes it — the account, the reading history and the sessions. We hold no financial records of any kind, because nothing is sold.
7. Your rights
Under the GDPR you may ask us to:
- Tell you what we hold about you, and give you a copy.
- Correct anything wrong.
- Delete it — the right to erasure. We will, unless the law makes us keep a particular record, in which case we will tell you exactly what and why.
- Restrict what we do with it while a dispute is sorted out.
- Hand it over in a portable format, or send it to another provider.
- Object to anything we do on the basis of legitimate interest.
- Withdraw consent to analytics, at any time, without giving a reason and without it affecting anything that happened before. This one needs no email: it is the Cookie settings link in the footer.
Email office@syntopia.bg. We reply within one month. It is free; we would only charge for a request that is repetitive or excessive, and we would tell you before doing so.
We may ask you to confirm you are who you say you are — we are not going to hand your account history to whoever asks for it.
8. Complaining
If we get this wrong, tell us and we will fix it.
If that is not good enough, you can complain to the Bulgarian supervisory authority:
Commission for Personal Data Protection (Комисия за защита на личните данни) 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria cpdp.bg · kzld@cpdp.bg
If you live in another EU country, you can complain to your own national authority instead.
9. Keeping it safe
Passwords are hashed with Argon2id. Session tokens are 256 bits of randomness and are stored only as digests, so a copy of our database does not let anyone log in as you. Traffic is encrypted in transit.
None of that makes a system unbreakable, and we are not going to claim it does. If a breach happens that puts you at risk, we will tell the CPDP within 72 hours and tell you without undue delay.
10. Changes
If we change this policy in a way that matters, we will email you and update the version and date at the top. Minor corrections take effect when published.
"SYNTOPIA" EOOD · UIC 208876257 · Chayka district, bl. 9, entr. B, fl. 3, apt. 25, 9000 Varna, Bulgaria · office@syntopia.bg