Privacy Policy
1. Data Controller
Zone2 technologies Ltd., a Bulgarian single-member limited liability company, registered in the Bulgarian Commercial Register under UIC 206921440 and VAT number BG206921440, with seat and management address at Bulgaria, Sofia 1000, Izgrev region, Iztok district, 6 Dr. Lyuben Rusev Str., fl. 5, ap. 81 (“Zone2”, “We”, “Us”, or “Our”).
Through the website zone2.tech, Zone2 presents its engineering consultancy: AI systems, web platforms, product development, and identity and access for startups and scale-ups. The Website exists so that You can read about that work and get in touch.
Zone2 is a Data Controller within the meaning of Article 4(7) of the GDPR and, as such, is responsible for processing Your data in a fair, transparent, and secure manner, as required by the Regulation and national legislation.
This Privacy Policy relates to the activities of Zone2 (“the Controller”) in connection with the management of the website zone2.tech and the inquiries You send through it. To fulfill legal requirements, this Privacy Policy provides You with information about Your rights, the types of personal data collected, the basis for their processing, how they are stored and used, and when they are disclosed to third parties.
In accordance with the Controller’s obligations under Regulation 2016/679 of the European Parliament and of the Council (“General Data Protection Regulation” or “GDPR”), the Controller guarantees that the processing of Your personal data will always comply with the Regulation and applicable Bulgarian data protection legislation.
Contact Information:
Zone2 technologies Ltd. Email: contact@zone2.tech Website: zone2.tech
2. Personal Data We Collect
As the Controller of the website zone2.tech (“the Website”), Zone2 determines the purposes, collects, and processes personal data of website users necessary for their identification and contact.
According to Article 4 of EU Regulation 2016/679, “personal data” means any information relating to an identified natural person or to a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or by one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
The Website has no user accounts. Cookies are set only with Your consent (Section 13), except the one that remembers the language You chose, and the Website’s analytics run without cookies on aggregated data. Personal data reaches Us only in the following ways:
Contact Data (when You send Us an inquiry through the contact form on the Website or by email):
- Name
- Organisation
- Email address
- The content of Your message
Inquiries submitted through the contact form are delivered to Us by email and are not stored in a database on the Website.
Bot Protection Data:
- To verify that a contact form submission comes from a person and not an automated bot, Cloudflare Turnstile runs a check in the browser and processes technical signals such as IP address and browser characteristics (Section 8). The content of Your message is not sent to Cloudflare.
Consent Data (when You make a choice in the cookie banner):
- Your consent choice per category and the time of the decision. The consent tool stores this in Your browser (local storage and, where needed, a cookie) so Your choice stays saved, and records it with Our consent management provider (Section 8) so that We can demonstrate consent was obtained
- When the banner configuration is loaded, the consent service processes technical data of the request, such as IP-derived country information, to determine which consent rules apply
Usage Data (while You browse the Website, only if You have consented to analytics, Section 13):
- Aggregated, cookieless usage statistics collected by Vercel Web Analytics (Section 8), such as pages viewed, referrer, browser and device type, and country. No cookies are set for this, no cross-site identifiers are used, and no personal profiles are built
Technical Data:
- To deliver the Website and keep it secure, Our hosting provider processes technical data in server logs, such as IP address, browser type, requested pages, and the date and time of access.
Contract and Billing Data:
- If an inquiry leads to an engagement, that engagement is governed by a separate agreement, and the processing of personal data under it, including the invoicing and payment records We are legally required to keep, is governed by the data protection clause of that agreement. This Policy covers the Website and Your inquiries.
Providing Your contact data (name, organisation, email) is necessary for Us to answer Your inquiry. Without this data, We cannot respond to You.
Providing data for analytics purposes (through optional technologies) is voluntary. Declining to provide this data does not affect Your ability to use the Website.
3. Personal Data We Do NOT Collect
Zone2 does not collect or process personal data that:
- Reveals racial or ethnic origin
- Reveals political opinions, religious or philosophical beliefs, or trade union membership
- Consists of genetic or biometric data
- Concerns health or medical conditions
- Concerns sex life or sexual orientation
IMPORTANT: if such information is shared by users of the Website, it will not be subject to processing and will be destroyed immediately.
The Controller does not use Your personal data for automated individual decision-making, including profiling, within the meaning of Article 22 of EU Regulation 2016/679.
4. Purpose of Data Processing
Zone2 collects and uses Your personal data for the following activities and purposes:
- To receive and respond to Your inquiries and to hold the intro call
- To protect the contact form from spam and automated abuse
- To remember the language You chose on the Website
- To remember Your cookie choices and to demonstrate that consent was obtained where processing is based on consent
- To understand aggregate use of the Website through cookieless statistics, where You have consented (Sections 8 and 13)
- For communication purposes, including scheduling
- To comply with legal requirements, settle potential disputes, and protect against fraud
- To ensure the security of the Website and Our infrastructure
Your personal data may also be processed if a government authority requests Zone2’s cooperation in connection with official procedures, including pre-trial, judicial, and administrative proceedings related to claims, fraud, etc. In such cases, Zone2 discloses only the amount of data requested by the authorities, not exceeding the scope of the specific request.
| Data category | Processing purpose | Legal basis |
|---|---|---|
| Contact data (name, organisation, email, message) | Communication on inquiries | Steps taken toward a contract |
| Bot protection data (IP address, browser characteristics) | Protecting the contact form from abuse | Legitimate interest |
| Technical data (IP address, browser) | Security and technical maintenance | Legitimate interest |
| Language cookie | Remembering Your chosen language | Legitimate interest |
| Consent data (cookie choices, consent record) | Demonstrating consent | Legal obligation (Article 7(1) GDPR) |
| Analytics data (Vercel Analytics data) | Analyzing traffic | Consent |
5. Retention Period
We retain Your data for the following periods:
- Correspondence and inquiry data: up to 6 months after the communication ends
- Where an inquiry leads to an engagement, the data is retained for the periods set out in that agreement and in the Bulgarian Accountancy Act
- Technical data in server logs: for the retention period of Our hosting provider (Section 8)
- Cookie consent data: until consent is withdrawn or for the validity period of the respective cookie; the consent record for the period in Section 13.4
You may request deletion of Your personal data at any time by contacting Us at contact@zone2.tech. We will process deletion requests in accordance with applicable law, subject to any legal obligations requiring Us to retain certain data.
6. Legal Basis for Processing
We collect Your data on the following legal bases:
- Steps taken toward a contract (Article 6(1)(b) GDPR): processing necessary to answer Your inquiry and to take the steps You request before entering into a contract
- Legal obligation (Article 6(1)(c) GDPR):
- Where processing is required to comply with applicable laws, such as accounting and tax legislation
- To demonstrate consent given for the use of cookies and other technologies pursuant to Article 7(1) of the GDPR
- Legitimate interests (Article 6(1)(f) GDPR):
- Ensuring the technical soundness and security of the Website, including protection against DDoS attacks and malicious software (through server logs)
- Protecting the contact form from automated abuse and spam (through Cloudflare Turnstile)
- Remembering the language You chose on the Website
- Establishing, exercising, or defending legal claims arising from the use of the Website
You have the right to receive information about the balancing test We have carried out, on request at contact@zone2.tech.
- Consent (Article 6(1)(a) GDPR): where You have given explicit consent for specific processing activities, such as analytics (Sections 8 and 13)
7. Technical Security
The Controller has implemented all technical and organizational measures necessary for the processing and protection of personal data in accordance with EU Regulation 2016/679 and applicable Bulgarian legislation.
The measures taken correspond to the specific risks associated with the processing and storage of personal data. Organizational and technical measures are in place to protect Your data from loss, alteration, theft, or unauthorized access by third parties.
These measures include:
- Encryption of data in transit
- Access controls and authentication
- Secure hosting infrastructure
- Data minimization: the Website collects no data it does not need
However, no internet transmission is completely secure, and We cannot guarantee absolute security of data transmitted to Us online.
8. Recipients of Personal Data
8.1. Data Processors
The Controller provides personal data to providers who act on its behalf and on its instructions under a written contract pursuant to Article 28 of EU Regulation 2016/679. These parties may not use the data for their own purposes and include:
a) Vercel Inc. (USA): hosting and cloud infrastructure provider, ensuring the technical operation and security of the Website.
Hosting:
- Vercel hosts the Website and processes the technical data described in Section 2 as part of delivering it. For more information, see https://vercel.com/legal/privacy-policy
Analytics:
- Vercel also provides the Website’s cookieless Web Analytics, loaded only after Your consent. It processes technical data such as pages viewed, referrer, browser and device type, and country in aggregated form; it sets no cookies and uses no cross-site identifiers. For more information, see https://vercel.com/legal/privacy-policy
b) Cloudflare, Inc. (USA): provider of the bot check on Our contact form.
Bot Protection:
- Cloudflare provides the Turnstile check on Our contact form, which verifies that submissions come from real people, not automated bots. When the form is displayed, Cloudflare receives Your IP address and technical information about Your browser in order to tell human visitors from automated ones. The content of Your message is not sent to Cloudflare. This is a security measure necessary to protect the form from abuse. For more information, see https://www.cloudflare.com/privacypolicy/
c) Postmark (Wildbit LLC, USA): email delivery provider for inquiry-related communication.
Email Delivery:
- Postmark delivers Your inquiry from the contact form to Us as email. Your name, organisation, email address, and message are shared with this provider for email delivery purposes. For more information, see https://postmarkapp.com/privacy-policy
- Direct email correspondence is processed by the email service provider that operates Our mailboxes, as part of normal email delivery
d) CookieYes (CookieYes Limited, United Kingdom): provider of software solutions for cookie consent management.
Consent Management:
- CookieYes hosts the consent management service behind the cookie banner. It delivers the banner configuration, determines from technical request data (such as IP-derived country) which consent rules apply, and stores the consent records described in Section 2 and Section 13.4 on Our behalf. For more information, see https://www.cookieyes.com/privacy-policy
8.2. Independent Controllers
The Controller discloses data to third parties who carry independent responsibility for Your data:
- Professional advisors (accountants and lawyers): to fulfill legal obligations or protect legitimate interests
- Banks and payment institutions: to handle payments
- State authorities (the Bulgarian National Revenue Agency, the Commission for Personal Data Protection): where a legal obligation exists
The Controller will share personal data with third parties only after explicitly ensuring the technical and legal mechanisms under which the processing of shared personal data will be carried out in accordance with the requirements of Regulation 679/2016 and Bulgarian legislation. We do not sell personal data.
9. Data Processing Principles
The Controller guarantees that the personal data it processes are:
a) Processed lawfully, fairly, and in a transparent manner in relation to You (“lawfulness, fairness, and transparency”);
b) Collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes (“purpose limitation”);
c) Adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed (“data minimization”);
d) Accurate and, where necessary, kept up to date; all reasonable steps are taken to ensure that inaccurate personal data are erased or rectified without delay (“accuracy”);
e) Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed (“storage limitation”);
f) Processed in a manner that ensures appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures (“integrity and confidentiality”).
10. Your Data Protection Rights
Under the GDPR, You have the following rights:
Right of Access
Upon Your request, You have the right to access the personal data stored about You. You also have the right to request a copy of the personal data being processed.
Right to Rectification
You have the right to request correction of incorrect, inaccurate, or incomplete personal data. Depending on the purposes of processing, You may have the right to supplement incomplete personal data, including by providing an additional statement.
Right to Erasure (“Right to Be Forgotten”)
You have the right to request the deletion of personal data when they are no longer necessary or if their processing is unlawful. Please note that Article 17 of the GDPR defines the cases in which We are obliged to delete Your data. Please also note that We may be required to retain Your data even if You have requested their deletion (for example, to comply with a legal obligation under EU or Bulgarian law).
Right to Restriction of Processing
Under certain circumstances, You have the right to request restriction of the processing of Your personal data. For example, You may exercise this right when We no longer need Your personal data for processing purposes, but We must keep them in Our systems for use in situations such as exercising rights or defending claims.
Right to Data Portability
Under certain circumstances, You have the right to receive the personal data You have provided to Us in a structured, commonly used, and machine-readable format (i.e., in digital form), and You may have the right to request the transfer of such data to another person without hindrance from Us, if such transfer is technically feasible.
Right to Object
Under certain circumstances, You have the right to object to the processing of Your personal data, and We may be required to stop processing them in the future. You may exercise this right, for example, if We use Your email address for direct marketing purposes. In this case, after Your objection, We will no longer be able to send You marketing materials.
Right to Withdraw Consent
When the processing of Your personal data is based on Your consent, You may withdraw Your consent at any time without giving Us a reason. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
How to Exercise Your Rights
Given the scope and nature of Our activities, We are not required to appoint a Data Protection Officer and have not appointed one. To exercise Your rights, You may contact Us with a written request at contact@zone2.tech. We will respond to Your questions and requests without undue delay and within 1 month at the latest. You may be asked to provide information to verify Your identity in order to exercise Your rights.
11. Complaint to Supervisory Authority
If for any reason You are not satisfied with the way We process Your personal data, please first inform Us so that We can understand the cause of the problem and try to resolve it. We will carefully review Your request and answer all Your questions.
If You believe You have not received adequate assistance from Zone2 or that Your right has been violated, You have the right to lodge a complaint with a supervisory authority. This authority in the Republic of Bulgaria is:
Commission for Personal Data Protection: Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria Phone: 02/915 35 18 Email: kzld@cpdp.bg Website: www.cpdp.bg
12. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including:
- United States (where some of Our service providers are located)
- Other countries where Our infrastructure providers maintain servers
When We transfer Your data outside the EEA, We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Transfers to countries with an adequacy decision
- Other legally recognized transfer mechanisms
13. Cookies and Similar Technologies
13.1. What Are Cookies?
The Website uses cookies and other similar technologies (e.g., local storage, scripts). These are small data files stored on Your device that allow Us to collect certain information during Your visit. These technologies help Us ensure the security and proper functioning of the Website and remember Your preferences. In this Policy, “cookies” means any technology that falls within the scope of Article 4a of the Bulgarian Electronic Commerce Act.
13.2. Types of Cookies We Use
We classify the technologies used into the following categories:
- Required: These technologies are strictly necessary for the basic functioning and security of the Website (e.g., protecting the contact form, remembering Your language, or storing Your consent). They cannot be switched off
- Analytics: These technologies help Us collect aggregated statistics about traffic and how the Website is used, in order to improve its operation
The Website uses no marketing technologies.
13.3. List of Technologies Used
We do not load non-required technologies without Your prior, explicit consent. You can change Your choice at any time via the “Cookie settings” link at the bottom of the page.
| Name | Provider | Purpose | Type | Retention period | Legal basis |
|---|---|---|---|---|---|
| cookieyes-consent | CookieYes | Store Your consent choice and the consent ID under which the record of it is kept (in cookies and in local storage). | Required | 1 year | Legal obligation (Article 7(1) GDPR) |
| NEXT_LOCALE | The Website | Remembers the chosen language of the Website. | Required | Session (until the browser closes) | Legitimate interest |
| Cloudflare Turnstile | Cloudflare | Protects the contact form from automated attacks. | Required | Session (no persistent data on the device) | Legitimate interest |
| Vercel Analytics | Vercel | Aggregated traffic statistics. | Analytics | Session (stores no data on the device) | Consent |
13.4. Demonstrating Consent
To meet Our accountability obligation under Article 7(1) of the GDPR, We keep a record (log) of every consent You give. This record includes the domain on which the consent was given, a partially masked (pseudonymous) IP address, the country derived from it, the date and time in UTC, a consent ID, and the categories You accepted or rejected. We keep this record for 5 years from the last change or withdrawal of the consent, for defense against potential legal claims.
14. Policy Updates
To keep this Privacy Policy up to date, it may be changed in whole or in part at any time without special notice. Please check this Policy periodically for updates. The date of the last update will be indicated below.
This Privacy Policy was adopted on September 24, 2023.
Last Updated: September 10, 2026.