1. Data controller
The data controller for personal data processed through certificatory.com is BIG DREAMS GROUP, UIC 206986388, registered office Skobelev 42, Sofia, Bulgaria. For any privacy question, including exercising your rights under the General Data Protection Regulation (GDPR, Regulation 2016/679) and the Bulgarian Personal Data Protection Act (Закон за защита на личните данни - ЗЗЛД), contact us at [email protected].
2. What we process
We process the following categories of personal data:
- Account data: name, email address, password hash, role, account creation date.
- Event data: event names, dates, template files, attendee names, email addresses and titles you upload to issue certificates.
- Transactional data: invoice identifiers, payment amount, payment status (card data is handled by the payment processor - we never see or store it).
- Technical data: IP address, browser user-agent, timestamps of access and downloads, error logs.
- Support data: the content of any email or contact-form message you send us.
3. Purposes and legal bases
- Providing the Service (Art. 6(1)(b) GDPR - performance of a contract): creating accounts, generating certificates, hosting templates, delivering PDFs.
- Billing and accounting (Art. 6(1)(c) GDPR - legal obligation under Bulgarian tax and accounting law): issuing invoices, keeping records for the statutory retention period.
- Security and fraud prevention (Art. 6(1)(f) GDPR - legitimate interest): rate limiting, anomaly detection, audit logs.
- Transactional email (Art. 6(1)(b) GDPR): welcome, password reset, payment receipts, certificate delivery.
- Support (Art. 6(1)(b) and (f) GDPR): responding to your questions and fixing problems.
We do not use your personal data for advertising and we do not sell it.
4. Your role when you issue certificates
When you upload an attendee list, you are the controller of that list and we act as your processor under Art. 28 GDPR. You are responsible for having a lawful basis to share those names and emails with us and for informing the attendees. We process the list only to generate the certificates you asked for and, where you enable it, to email certificates to attendees.
5. Retention
- Account data: for as long as your account exists and up to 12 months afterwards to defend against legal claims, then deleted.
- Event content and attendee lists: until you delete the event, then removed from active storage. Copies may remain in encrypted backups for up to 30 days before being overwritten.
- Generated certificate PDFs: retained for the lifetime of the event; deleted when the event is deleted.
- Invoices and tax records: 11 years from the end of the tax year, as required by Bulgarian accounting law.
- Technical logs: up to 90 days.
- Demo accounts: deleted automatically 24 hours after creation.
6. Subprocessors
We use a small number of vetted service providers to operate the Service:
- A hosting provider that runs our servers (data stored in the European Union).
- A payment processor for card payments (PCI-DSS-compliant, certified under the EU-US Data Privacy Framework where applicable).
- A transactional email provider for the messages you receive from us.
- A content-delivery and edge-security provider (Cloudflare) to route traffic and protect against abuse.
On request we will share the current list of subprocessors, including company names, roles and processing locations.
7. International transfers
Personal data is stored primarily within the European Union. Where a subprocessor transfers data outside the EEA (for example, for email delivery), the transfer is covered by appropriate safeguards under Art. 46 GDPR, typically Standard Contractual Clauses.
8. Your rights
Under the GDPR and the Bulgarian Personal Data Protection Act, you have the right to:
- access your personal data (Art. 15);
- request rectification of inaccurate data (Art. 16);
- request erasure (“right to be forgotten”, Art. 17);
- request restriction of processing (Art. 18);
- data portability (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- withdraw consent where processing is based on consent.
To exercise any of these, email [email protected]. We will respond within one month and free of charge, except where requests are manifestly unfounded or excessive.
You also have the right to lodge a complaint with the Bulgarian supervisory authority: Commission for Personal Data Protection (КЗЛД), 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, kzld.bg.
9. Security
Passwords are stored hashed with bcrypt. Access to production data is restricted to named operators over encrypted channels. Uploaded files are stored in the EU on hardware we control. We review incidents and notify affected users and the supervisory authority without undue delay in the event of a qualifying personal-data breach, as required by Art. 33-34 GDPR.
10. Changes to this policy
We may update this Privacy Policy. The “Last updated” date at the top indicates when it was last changed. For material changes we will notify active users by email.