Privacy

What we collect, and why

This notice explains how we handle four things: your language choice, the enquiries you send through the contact form, the technical data used to protect that form from automated abuse, and aggregate website traffic. We do not use advertising or tracking cookies. The contact form collects the data you enter plus the referring internal page path when available, your IP address and the time of submission.

Who is responsible

Dyasol Ltd (Диасол ЕООД), a company registered in Bulgaria under UIC 207785566, registered seat 180 Vasil Stefanov St., 1404 Sofia, Bulgaria. We are the controller for the personal data described here.

For anything to do with your data, use the contact form on this site. We are not required to appoint a Data Protection Officer and have not appointed one.

Cookies

The site uses one first-party preference cookie, dyasol_lang, for up to 180 days after you choose English or Bulgarian. It contains only the language code. The page address selects the language; visiting the root address with a saved Bulgarian preference redirects to the Bulgarian home page. Without that preference, the root address serves English. We do not use your location to choose the language. We do not use advertising, analytics or cross-site tracking cookies, so no consent banner is required. Cloudflare may also set a strictly necessary cookie when an automated-traffic protection is triggered.

If you use the contact form

Only your name, e-mail address and message are required. Everything else is optional.

WhatWhyLegal basisHow long
Name, e-mail addressSo that we can reply to youArt. 6(1)(b) GDPR — steps prior to a contract at your request. Where you write on behalf of an organisation: Art. 6(1)(f) — our legitimate interest in answering business enquiries12 months after our last exchange, unless an engagement follows
Company, subject, organisation size, deadline, desired outcome and messageTo understand what you are asking and answer it properlyAs aboveAs above
Page leading to the enquiry and optional discovery sourceTo learn which information helps people enquire; the page path excludes query parameters and fragments and carries no visitor identifierArt. 6(1)(f) GDPR — our legitimate interest in evaluating business enquiries12 months after our last exchange, unless an engagement follows
Page languageSo that we reply in the language you were readingAs aboveAs above
IP address and submission timeTo detect and stop automated abuse of the formArt. 6(1)(f) GDPR — our legitimate interest in keeping the form usableContained in the notification e-mail to us and kept as long as that e-mail (see above)

The form also carries a technical timestamp used to reject automated submissions. It is checked when you submit and is not stored separately.

How we apply the retention period

The mailbox is reviewed by the engagement owner at least once a quarter. Enquiries that did not lead to an engagement are deleted within 12 months of the last exchange; where an engagement or a dispute follows, the related correspondence is kept for as long as that relationship and the applicable limitation periods require. Deleted mail may remain in the mailbox’s Trash for the provider’s standard recovery window before it is purged. This is a manual practice, not an automated technical guarantee.

How we count visits

We use Cloudflare Web Analytics, which is measured without cookies, without local storage and without fingerprinting. It reports aggregate counts only: which page was viewed, the referring site, country, device type, browser and operating system. It cannot single you out, and we cannot use it to recognise you on a later visit.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in knowing which pages are read.

Who else handles it

  • Cloudflare, Inc. (United States) — hosting, content delivery, security and the analytics above. Cloudflare is certified under the EU–US Data Privacy Framework and relies on the EU standard contractual clauses should that certification lapse.
  • Resend (Plus Five Five, Inc., United States) — sends your enquiry through the selected Amazon SES region in Ireland. The sending region does not determine where all account data, message metadata, logs or API records are stored; Resend states that these records may be processed in the United States. Its data-processing agreement, section 6, incorporates the EU standard contractual clauses for transfers not covered by an adequacy decision, including controller-to-processor transfers. Its current subprocessor list identifies other providers involved.
  • Mailu on mail.angel.bg — the notification e-mail arrives in a mailbox operated by us.
Cloudflare and Resend act as our processors — they handle the data only to provide their service to us — and Resend uses Amazon SES and the other subprocessors identified in its current public list. The notification then arrives in our own Mailu mailbox. These services may retain the message and delivery logs for their own operational and security periods, so a copy is not only in our mailbox. Where a provider is established outside the EU, the transfer relies on the mechanism named above.

Your rights

You may ask for access to your data, correction of it, erasure, restriction of processing, or portability where that right applies, and you may object to processing based on legitimate interest. Use the contact form; we will respond within one month.

You can also complain to the Bulgarian supervisory authority: Commission for Personal Data Protection (CPDP / КЗЛД), 2 Prof. Tsvetan Lazarov Blvd, 1592 Sofia, cpdp.bg.

What we do not do

  • No automated decision-making and no profiling.
  • We do not sell your data, and we do not share it for anyone else’s marketing.
  • No newsletter and no marketing e-mail unless you ask for one.
  • We do not use your enquiry to build a prospect list.

Last reviewed 14 September 2026.