Home › Privacy Policy

Privacy Policy

Short and in plain language. No 47 pages of fine print.

Version: 2026-08-08

Version in force This is the current edition of the policy and describes the processing we carry out today. We notify registered customers by email 30 days before any material change.

1. Who processes your data

Data controller: Hostika EOOD, registered office ul. Louis Ayer 13, 1404 Sofia, Bulgaria. Contact email for data questions: privacy@hostika-bg.com.

2. What we collect and when

When you fill a form (builder, demo, newsletter, affiliate signup) we collect the name, email, phone, and project details you provide. Visiting the site logs IP and user-agent (for security and traffic measurement). Paying customers enter billing details through the client area (WHMCS). We do not store card data — payments go directly through PCI-DSS-certified processors.

3. Legal basis

Consent (inquiry forms, newsletter). Contract performance (for paying hosting and service customers). Legitimate interest (security, abuse prevention, basic anti-spam). Legal obligation (accounting records under Bulgarian tax law).

4. How long we keep your data

Form leads — 24 months from last contact. Customer accounts — for the duration of the contract. Accounting documents (invoices and accounting registers) — 10 years from 1 January of the year following the reporting period, as required by art. 12 of the Bulgarian Accountancy Act. Web server logs (IP address, user agent) — 14 days. Newsletter — until you unsubscribe. On a deletion request we remove your data from live systems immediately; encrypted backups are never edited in place, so the corresponding records disappear as their rotation expires (up to 12 months).

5. Who else sees your data

We share data only with processors who help deliver the service: AlexHost SRL (servers — production machine in Sofia, backup machine in Zürich, Switzerland), Brevo (newsletter), Stripe / Revolut Business (payments), Google Ireland Ltd. (advertising measurement — only if you consent through the cookie banner). If you became a customer through one of our affiliate partners, that partner can see your name, e-mail address and orders in their affiliate dashboard so they can track their commission; affiliates are bound by a confidentiality obligation and may not use this data for any other purpose. We do not sell data. We do not pass data to third parties for marketing.

6. International transfers

The production server is in Sofia, inside the EU. Daily encrypted backups are held on a second server in Zürich, Switzerland. Switzerland is covered by a European Commission adequacy decision under GDPR Article 45, and backups are encrypted at source before they leave the server. If any other subprocessor handles data outside the EU, we rely on EU Standard Contractual Clauses (SCCs) or an adequacy decision under Article 45.

7. Your rights

You have the right to: access your data, correction, deletion ("right to be forgotten"), restriction of processing, data portability, objection to processing based on legitimate interest, and withdrawal of consent at any time. Email privacy@hostika-bg.com — we respond within 30 days.

8. Complaints to the supervisory authority

If you believe we have not handled your request properly, you may file a complaint with the Bulgarian Commission for Personal Data Protection (KZLD): kzld.bg, 2 Prof. Tsvetan Lazarov Blvd, 1592 Sofia.

9. Cookies

Functional cookies: csrf_token (form protection), hostika_consent (stores your cookie-banner choice), a session cookie in the client area; sessionStorage for builder drafts. Language is determined by the URL (/en/), not a cookie. With your explicit consent from the banner we enable Google Ads conversion measurement (Google Ireland Ltd.) — _gcl_* cookies; without consent nothing advertising-related is stored. You can withdraw consent at any time via "Cookies" in the footer — withdrawal also deletes any advertising cookies already set.

10. Security

TLS everywhere, CSRF protection on forms, parameterized SQL, hashed passwords (bcrypt), administrative server access by cryptographic key only (no passwords), login rate limiting, daily encrypted backups on a separate server, and external availability monitoring. Perfect security does not exist — but we do more than required.

11. Changes

For material changes, we email registered customers 30 days in advance. Last-edited date is shown at the top of the page.

12. Contact

Data protection questions, requests, complaints: privacy@hostika-bg.com. General questions: contact@hostika-bg.com.

Have a question about how we handle your data? Email us.

privacy@hostika-bg.com