+359 893 560 371 Support 24/7 · sales 9:00–18:00 All services operational

Privacy

What data we collect, why we need it, who sees it and how long we keep it. All in a table — not eight pages of text.

In force from 1 March 2026
Under GDPR
Data is held in Bulgaria

First, what we do not do

This is the question people open such a page with. The answer is here, not in the eighth paragraph.

We do not sell dataTo nobody, ever. Nor “anonymised” sales — that usually means the same thing.
We do not track you across other sitesWe have no Facebook pixels or similar. We do not know where you go after you leave.
We do not read your siteWe access your files only when you ask for help, and we log when and why.
No marketing without consentWe write about your service and invoices. For anything else — only if you said yes.

What we collect and why

Each row says four things: which data, why we need it, on what basis we keep it and for how long.

Which dataWhat forBasisHow long
Name, email, phonefrom the orderTo start your service and reach you if there is a problemcontractup to 3 yafter the service ends
Invoicing detailscompany, reg. number, addressTo issue an invoice, as the law requireslaw11 yrequired by law
Connection addresswhen logging into the panelTo spot someone else logging into your accountinterest12 mo
Server logswho requested whatTo fix problems and stop attacksinterest30 daysthen deleted automatically
Your site contentfiles, databaseSo the service works. We do not read or use itcontract30 daysafter the service stops
Conversations with supportemail and chatTo remember what was said and what was doneinterest3 y
Email for notificationsif you signed upTo write to you about changes or newsconsentuntil you opt outwith one click
contract needed for the service to worklaw we are obligedinterest for security and qualityconsent only if you said yes

Who else sees the data

We list them by name. “Trusted partners” is a phrase that could hide anyone.

The payment providerSees the name and amount so the payment goes through. We never see your card number — it does not reach us at all.EUIreland
The domain registryWhen a domain is registered the owner’s details go there — the registry rules require it, not us.EUdepends on the domain
The accountantsSees the invoices in order to book them. There is a signed processing agreement.BulgariaPlovdiv
State authoritiesOnly on a lawful request and only what is requested. We tell you, unless the law forbids it.Bulgariaon request
That is the whole list. No ad networks, no visitor tracking tools, no sale to third parties. The servers are in Plovdiv and the data does not leave the country, except in the listed cases.

What you can ask for

Every right comes with a button or a concrete step. A quote from the law without an action helps nobody.

Download everything

A copy of all data we hold about you — profile, invoices, support conversations, site content.

Have them deleted

Deletion of everything we are not legally required to keep. Invoices remain — they have an eleven-year retention period.

Write to uswithin 30 days
Have them corrected

If something is recorded wrongly — name, address, invoicing details. Most things you change yourself in the panel.

Stop the notifications

Opt out of news and announcements. Service and invoice emails continue — they are part of the contract.

Take them elsewhere

An archive in a form another provider can read. We give it even when you are moving to a competitor.

Write to uswithin 7 days
Object

Against processing we do “for our interest”. We stop it, unless there is a stronger reason — and we explain it.

Write to uswithin 30 days

Cookies, briefly

Three kinds, and only the first is required. The other two ask for consent and work only if you said yes.

requiredTo make the site workThey remember that you are logged in and what is in your basket. Without them nothing works.
optionalTo count visitorsHow many people were here and which pages they read. We do not know who you are.
optionalFor convenienceThey remember the language and how you arranged the panel. Small things.
See all cookiesSettings can be changed at any time, from the bottom of any page.

If data leaks despite everything

Almost nobody writes what happens then. And that is precisely the moment this page matters.

What we do and by when
at onceWe stop the leak and start working out exactly what leaked and whose it was.
within 72 hWe notify the data protection authority — that is a statutory deadline, not our choice.
within 72 hWe write to everyone affected — what leaked, since when, and what to do. Even when the law does not require it.
within 30 daysWe publish what happened and what we changed so it does not repeat.

Ask us

For anything on this page, write to the address below. We answer within 30 days, usually much sooner.

Data contactMaxBG Ltd
1 Primerna St, Plovdiv, Bulgaria
danni@maxbg.net

Or complain

If you believe we have not acted properly, you have the right to complain directly to the supervisory authority. You do not have to ask us first.

Commission for Personal Data Protection2 Prof. Tsvetan Lazarov Blvd, Sofia
cpdp.bg
Two more things

Our services are not for children under 16. We do not knowingly collect data from them. If we find that we have, we delete it at once.

We do not want sensitive data — about health, faith, origin or the like. If you nevertheless upload it to your own site, that remains your responsibility. We do not read or process it.

AI assistantinstant answers, 24/7