Privacy Policy

Last updated: 20 July 2026.

1. Who we are

The data controller within the meaning of Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act is ERGI Ltd. (ЕРГИ ЕООД), Company ID (ЕИК) 208774195, VAT № BG208774195, registered address: 36 Klokotnitsa Str., fl. 5, ap. 8, Sofia 1233, Bulgaria.

GDPR contact: office@ergi.bg
Phone: +359 898 446 516 (Monday–Friday, 09:00–17:00 EET)
Website: https://ergi.bg

We have not appointed a Data Protection Officer (DPO) — our processing activities do not fall within the cases under Article 37 GDPR that require a mandatory DPO.

2. What personal data we process

2.1. Site visitors (everyone)

  • Technical data: IP address (anonymised), browser type, OS, pages visited, date and time
  • Collected via self-hosted Matomo, cookieless mode, with IP anonymisation

2.2. Registered users

  • Email address
  • Password (stored as a one-way cryptographic hash — bcrypt/phpass; cannot be revealed even by administrators)
  • First and last name (optional)
  • Shipping and billing address (when provided)
  • Phone number (when provided)

2.3. Order data (including guest checkout)

  • Recipient first and last name
  • Email address
  • Phone number
  • Delivery address (street address or courier office/locker)
  • Billing address (only when an invoice is requested)
  • Order history and purchased products

2.4. Card payment data

We do not store card data on our servers. The card number, security code (CVV/CVC) and expiry date are entered directly on the secure myPOS (myPOS Limited) payment page you are redirected to, and never reach the ergi.bg servers. We only receive and store:

  • Transaction ID
  • A flag recording that the payment was successfully verified
  • Amount and currency

We never receive or store the card number — not even in masked form.

Refunds are processed through the myPOS system using the stored transaction identifier — the refund always goes to the original card without ergi.bg processing any card data.

2.5. Communication

2.5.1. Via the website contact form

When you submit an inquiry through the form on our "Contact" page, we process:

  • Name (required)
  • Email address (required) — used both for identification and to send our reply
  • Subject and message content
  • A one-way cryptographic hash (SHA-256) of your IP address — stored for 60 seconds solely to enforce a per-IP submission rate limit. The raw IP address is not retained.
  • Your browser's User-Agent — recorded in the internal diagnostic footer of the email sent to us, to help diagnose technical issues

The content of the inquiry is sent by email to office@ergi.bg via our internal SMTP relay (see section 4 "Hosting"). It is not written to the website database.

2.5.2. Via email or social media

When you write to us directly at office@ergi.bg or message us on social media, we process the contents of the correspondence, your email or your username on the respective platform.

3. Purposes and legal bases

Purpose Legal basis
Order fulfilment, delivery, returns, refunds Art. 6(1)(b) GDPR — performance of contract
User account management Art. 6(1)(b) GDPR — performance of contract
Issuing and storing invoices and accounting documents Art. 6(1)(c) GDPR — legal obligation (Bulgarian Accountancy Act, Tax Procedure Code, VAT Act)
Site traffic analytics (Matomo, cookieless) Art. 6(1)(f) GDPR — legitimate interest (service improvement)
Fraud prevention Art. 6(1)(f) GDPR — legitimate interest
Spam and automated-request protection on public forms Art. 6(1)(f) GDPR — legitimate interest
Newsletter and marketing (when activated) Art. 6(1)(a) GDPR — explicit consent, withdrawable at any time
Customer support Art. 6(1)(b) / (f) GDPR

4. Recipients of personal data

We share personal data only with the following categories of recipients, each acting under a Data Processing Agreement (DPA), as an independent controller by operation of law, or under an explicit legal mandate:

  • myPOS Limited (myPOS) — online card payment processing. Receives payment data (including card data, which ergi.bg does not store). Registered seat: Block 1, 3rd Floor, The Oval, 160 Shelbourne Road, Dublin 4, D04 E7K5, Ireland (reg. No. 700880). Licensed by the Central Bank of Ireland — E-Money Institution, ref. No. C475122. In respect of the card transaction, myPOS Limited acts as an independent controller under its own obligations arising from PSD2, anti-money-laundering rules (AML/KYC) and the card scheme rules — not as an Art. 28 GDPR processor on behalf of ERGI Ltd.. Data Protection Officer: dpo@mypos.com.
  • Speedy AD — courier delivery (name, phone, address or office). When the customer chooses cash on delivery or card-at-courier, Speedy additionally acts as a payment operator.
  • BoxNow Bulgaria — locker delivery (name, phone, email, selected locker ID). For cash on delivery, BOX NOW additionally processes the online payment of the amount via a payment link sent to the customer.
  • Government authorities — only on explicit legal requirement (e.g. tax authority, consumer protection commission, data protection commission, court).

Hosting: the website and database are hosted on ERGI Ltd.'s own physical hardware at our registered address. No external hosting/cloud/colocation processor. The same hardware also runs related internal services — an outbound SMTP relay (mail.naspoint.eu), used to deliver emails sent from the site (including replies from the contact form), and a self-hosted mosparo instance (mosparo.naspoint.eu) for spam protection on the contact form. The naspoint.eu domain is the personal property of the manager of ERGI Ltd. and is used exclusively for ergi.bg infrastructure; there is no separate legal entity or external provider behind it, and no data is transferred to any third party.

Analytics: self-hosted Matomo on the same hardware — no external processor, no cookies, anonymised IPs.

Social media: the website contains links to our profiles on Instagram and Facebook. These platforms are not processors of ergi.bg — no data is sent to them from the site. When you click a link you leave ergi.bg and the relevant platform's privacy policy applies.

5. International data transfers

ERGI Ltd. does not itself transfer personal data outside the EU/EEA. Our entire infrastructure is in Bulgaria, and Speedy AD and BoxNow Bulgaria process data within the EU/EEA.

Processing by myPOS Limited (myPOS) for card payments takes place primarily within the EEA, but myPOS may also transfer data outside the EEA — including to India, the Asia-Pacific region and North and South America — within its group or to its suppliers. Such transfers are made on the basis of a European Commission adequacy decision or, where none applies, appropriate safeguards under Art. 46 GDPR (standard contractual clauses). myPOS provides information about the applicable safeguards on request at dpo@mypos.com.

6. Retention periods

Category Period
Accounting documents (invoices, orders) 10 years — Art. 12 Bulgarian Accountancy Act
Tax and social security data 5 years — Tax Procedure Code
Active customer accounts Until deletion by user or account closure
Inactive customer accounts 2–3 years after last activity, followed by notice and deletion
Newsletter / marketing lists Until consent is withdrawn
Technical and security logs 6 months
Abandoned carts (no order created) 30 days
Inquiry / complaint correspondence Until resolved + 1 year
Hashed IP for contact-form rate-limit 60 seconds
Contact-form spam protection logs (mosparo) 30 days

After expiry, data is deleted or anonymised. When we are legally required to retain a document (e.g. an invoice), we keep it for the full statutory period even if the customer requests deletion — personal data within it are anonymised.

7. Your rights under GDPR

  • Right of access (Art. 15) — request a copy of your data
  • Right to rectification (Art. 16)
  • Right to erasure / "right to be forgotten" (Art. 17)
  • Right to restrict processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21) — to processing based on legitimate interest
  • Right not to be subject to automated decision-making (Art. 22) — we do not perform such
  • Right to withdraw consent at any time, where processing is based on consent
  • Right to lodge a complaint with a supervisory authority

To exercise rights, email office@ergi.bg. We will process within 30 calendar days (extendable by 60 days for complex requests).

7.1. Account deletion

To delete your account, send an email to office@ergi.bg with the subject "Account deletion" and specify the email of the account. Order history is retained for 10 years per Article 12 of the Bulgarian Accountancy Act, but personal data within it is anonymised.

7.2. Complaint to a supervisory authority

Bulgarian Commission for Personal Data Protection (CPDP/КЗЛД)
Address: бул. „Проф. Цветан Лазаров" № 2, гр. София 1592
Email: kzld@cpdp.bg
Website: https://www.cpdp.bg

8. Data security

  • HTTPS/TLS encryption for all connections between you and the site
  • Passwords hashed via one-way algorithm (bcrypt/phpass)
  • Database access restricted to authorised personnel only
  • Regular backups and software updates
  • Card data accessed only by myPOS Limited (myPOS); ergi.bg does not store card data
  • Automated-request protection on the contact form via self-hosted mosparo (no cookies, no external processor) plus server-side measures — honeypot and rate limiting (60 s/IP)

8.1. Spam protection on the contact form

To protect the contact form against automated requests and spam, we use mosparo — a self-hosted solution running on the same infrastructure described in section 4 "Hosting". Mosparo uses no cookies and does not transfer data to any third party. When the form is submitted, the mosparo instance receives one-way SHA-256 hashes of the field values (not the raw values themselves), short-lived session tokens, the IP address and the User-Agent — solely for bot heuristics and rate limiting at the spam-protection layer. Your browser performs a small proof-of-work computation locally; no user-supplied content is sent to any external system.

9. Cookies

The site uses only strictly necessary (essential) cookies for cart, user account and checkout functionality. We do not use marketing or analytics cookies. See the Cookie Policy for the full list.

10. Newsletter

We currently do not send marketing emails. If we activate such a service, it will be based on explicit opt-in consent, withdrawable at any time. Your order email is not automatically added to a marketing list.

11. Children

The site is intended for persons aged 18 or above. We do not knowingly collect personal data of minors. If you notify us that we have received data of an under-age user, we will delete it immediately.

12. Changes to this policy

We may update this Privacy Policy when legislation or our practices change. The current version is always available on this page. The "Last updated" date at the top indicates the most recent material change.

13. Contact

For any questions about the processing of personal data, contact us at:
office@ergi.bg
ERGI Ltd. (ЕРГИ ЕООД), Company ID 208774195
36 Klokotnitsa Str., fl. 5, ap. 8, Sofia 1233, Bulgaria