БГ
To the site

Privacy Policy

This policy explains what personal data connectedybg.com collects, why it collects it, and what anyone whose data we process can ask for.

In force since 2 August 2026

Who processes the data

The data controller is ConnecTEDY Ltd. („КънекТеди“ ЕООД), company no. 206853808, registered at 1 Bukova Planina St., Bistritsa, Sofia, Bulgaria.

For questions and to exercise your rights: info@connectedybg.com.

What we collect

The site requires no registration and collects nothing from visitors who simply browse it.

Data is collected only when someone books a session through the form:

  • the name you enter;
  • your email address;
  • the date and time you chose and the type of meeting (coaching or training);
  • the note, if you write one — so please do not put sensitive information there;
  • the moment of the request and the moment of cancellation, if the session is cancelled.

Client accounts

After an intro meeting and an agreement, Teodora may create an account for you, from which you book your own sessions. The account is created by her — the site has no self-registration.

For the account we process:

  • first and last name and email address — for signing in and for the emails;
  • the password you chose — stored only as an irreversible fingerprint (scrypt). The password itself is kept nowhere and cannot be recovered, not even by us;
  • the number of agreed, used and returned sessions, with the date of every change;
  • the moments of creation, of accepting the invitation and of the last sign-in.
  • the amounts agreed for the package and what has been paid, when, and how much was refunded. No card number is stored anywhere on our side.

Technical data

When a request is sent, the server briefly keeps your IP address in order to limit repeated automated requests. That address is not linked to the booking and is not stored in the bookings database.

The web server keeps standard access logs for a short time, for security and for spotting technical problems.

Why we process the data and on what basis

  • To reserve and confirm your session — processing is necessary to carry out your request and the steps before entering into a contract (Art. 6(1)(b) GDPR).
  • To send you a confirmation and a cancellation link — on the same basis.
  • To protect the form from abuse — on the basis of legitimate interest (Art. 6(1)(f)).

Where the data goes

We use several external providers, each for one specific task:

  • Google Ireland Ltd. — the booked session is created as an event in Google Calendar. Your name and email go into the event description, and for online sessions you also receive an invitation as an attendee, so the session appears in your own calendar.
  • Google Meet — a video room is created for online sessions. Joining it is subject to Google's own terms and policy.
  • Resend — the confirmation is sent to you through this service. It receives your email address and the contents of the message.
  • Stripe Payments Europe Ltd. — only when a session package is paid for. Card details are entered on a page hosted by Stripe and do NOT pass through this site; we receive only the confirmation that the payment went through. Stripe processes the name, email, amount and card data as a controller in its own right, under its own policy.
  • The provider of the server that runs the site and the database.

How long we keep it

Bookings are kept for up to 24 months after the date of the session, for accounting and organisational traceability. If a session is cancelled, the record remains but is marked as cancelled.

The calendar event is deleted immediately upon cancellation.

A client account is kept for as long as the work together lasts. On request it is deleted, and the sessions linked to it remain only as an accounting record, with no link back to the account.

Your rights

At any time you may request:

  • access to the data we hold about you;
  • correction of inaccurate data;
  • erasure of your data;
  • restriction of processing, or objection to it;
  • a copy of your data in a machine-readable format.

Complaints

If you believe your data is being processed unlawfully, you may complain to the Bulgarian Commission for Personal Data Protection — 2 Prof. Tsvetan Lazarov Blvd., Sofia, cpdp.bg.

Children

The services are intended for adults. We do not knowingly collect data from anyone under 18 without the consent of a parent or guardian.