This policy explains what personal data Assortiqa collects about you, why we collect it, who we share it with, and the rights you have over it. It covers our website and the services described in our Terms and Conditions.
1. Who is responsible
The controller of your personal data is:
| Controller | [TO BE COMPLETED] |
|---|---|
| Trading as | Assortiqa |
| Address | [TO BE COMPLETED] |
| Company registration number | [TO BE COMPLETED] |
| Country | Bulgaria |
| Contact for privacy questions | support@assortiqa.com |
We are a controller because we decide why and how your data is processed. We use suppliers such as Stripe to carry out parts of that processing, but that does not move the responsibility away from us.
We have not appointed a Data Protection Officer. We are not required to, because our core activity is not large-scale monitoring of individuals or processing of special category data. Privacy questions go to the address above.
2. Short summary
- We collect the minimum needed to run your account and deliver the service you ordered.
- We never see or store your card number. Stripe handles payments.
- We do not sell your data, and we do not use it for advertising.
- We record your IP address at the moment you accept our Terms, because we are required to be able to prove what you agreed to.
- You can ask us for a copy of your data, or to delete it, at any time.
3. What we collect and why
3.1 Account data
Your email address and a cryptographic hash of your password. We never store your password itself. This is what identifies your account and lets you sign in, and it is the address we use to contact you about your requests and payments.
3.2 Google sign-in data
If you sign in with Google, we receive your Google account identifier and the basic profile information Google returns, such as your email address and name, together with access tokens that let us confirm your sign-in. We do not use these tokens to read anything else in your Google account.
3.3 Your requests and instructions
The website addresses, categories, business goals and notes you enter when you submit a feasibility request. This is business information, but it is linked to you, so we treat it as personal data. We use it only to assess and carry out the work you asked for.
3.4 Payment and billing records
Your Stripe customer identifier, and records of the offers you were sent, what you paid, when, and the current state of any subscription. We keep these to run your contract, to answer billing queries, and because tax law requires us to keep accounting records.
3.5 Records of your agreement
When you accept our Terms at checkout, we record which version you accepted, the date and time, the confirmations you gave, your IP address and your browser user agent string. If you use the withdrawal function, we record that too, with your IP address.
We keep these because consumer law requires us to be able to demonstrate what you agreed to and when. It is also what protects you: it is the evidence of the rights you retained.
3.6 Dashboards and deliverables
Which dashboards and datasets are assigned to your account, so that we can show you your own results and nobody else's.
3.7 Technical data
Session cookies that keep you signed in, and server logs kept by our hosting provider which record IP addresses, timestamps and the pages requested. Logs are used to keep the service running and secure, and to investigate faults and abuse.
3.8 Enquiries you send us
If you use the contact form on our home page, we collect the name, email address and message you enter, together with the time of submission and the IP address it came from. You do not need an account to use it, so this may be the only data we hold about you.
We use it only to read and answer your enquiry. The IP address is used to limit how many messages can be sent from one place, which is what stops the form being used to send unwanted mail. Your message is delivered to our team by email and is not stored in a separate database, so we keep it only as long as it stays in that mailbox, and no longer than 24 months from your last contact with us.
4. Our legal bases
Under Article 6 of the GDPR we rely on the following:
| Performance of a contract | Running your account, assessing your request, delivering the service, taking payment, and providing support. |
|---|---|
| Legal obligation | Keeping accounting and tax records, and keeping evidence of the terms you accepted and of any withdrawal you exercise. |
| Legitimate interests | Answering enquiries you send us before there is any contract between us, keeping the platform secure, preventing fraud and abuse, and defending legal claims. We have considered your rights and do not think this processing overrides them, as it is limited to what running a service safely requires and to replying to people who asked us to. |
| Consent | Only where we ask for it separately and clearly. You can withdraw consent at any time without affecting anything done before. |
We do not send marketing email unless you have asked us to. Every message we send about a request, an offer, a payment or a cancellation is a service message about your contract, not marketing.
5. Card details and payments
We never receive, see or store your card number, expiry date or security code. Payment pages are hosted by Stripe, and your card details go directly to them.
What we hold is a Stripe customer reference and the outcome of each payment. Stripe processes your payment data as a controller in its own right for its own compliance and fraud-prevention purposes, and its privacy policy applies to that processing. We share your email address with Stripe so your invoices and receipts reach you.
6. Data we collect from websites
Our service collects publicly available information from websites you identify, such as product listings and prices. This is commercial information about products, not about people.
We do not set out to collect personal data from these sources, and we do not collect anything behind a login or paywall. If a piece of personal data were needed for an engagement, we would agree separate data processing terms with you first, because in that arrangement you would be the controller and we would act as your processor.
7. Who we share data with
We do not sell your personal data and we do not share it for anyone else's marketing. We use the following suppliers to run the service:
| Stripe | Payment processing, subscriptions, invoices and the billing portal. |
|---|---|
| Render | Hosting of the application and its database. |
| Delivery of our email, and sign-in if you choose to use Google to sign in. |
We may also disclose data where the law requires it, to professional advisers under a duty of confidence, or to a buyer if the business is sold, in which case we will tell you first.
8. Transfers outside the EEA
Our application and database are hosted within the European Union.
Stripe and Google are established in the United States and some processing may take place there. Where data leaves the European Economic Area, it is protected by the safeguards that the GDPR requires, which for these suppliers means the European Commission's standard contractual clauses, and where applicable their certification under the EU-US Data Privacy Framework. You can ask us for details of the safeguards that apply.
9. How long we keep it
| Account data | While your account is open, then deleted or anonymised within 12 months of closure. |
|---|---|
| Requests and deliverables | For the life of the contract, then up to 12 months so you can come back to past work. |
| Invoices and accounting records | As long as tax and accounting law requires, which in Bulgaria is generally several years, regardless of whether your account is closed. |
| Terms acceptance and withdrawal records | For as long as a claim could be brought about the contract, so that both of us can rely on the evidence. |
| Server logs | A short period set by our hosting provider, typically weeks rather than months. |
| Contact form enquiries | Held in our mailbox while we deal with your enquiry, and no longer than 24 months from your last contact with us. |
Deleting your account does not delete records we are legally required to keep, such as invoices. We restrict those to that purpose only.
10. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Rectification of anything inaccurate or incomplete.
- Erasure, where we no longer have a lawful reason to keep it.
- Restriction of processing while a dispute about accuracy or legitimacy is resolved.
- Portability of the data you gave us, in a machine-readable format.
- Object to processing based on legitimate interests.
- Withdraw consent, where we relied on consent.
Email support@assortiqa.com to exercise any of these. We will respond within one month. We may need to confirm your identity first, and we will not charge you unless a request is manifestly unfounded or excessive.
11. Cookies
We use only the cookies needed to make the site work:
| Session cookie | Keeps you signed in while you use the site. |
|---|---|
| CSRF cookie | Protects forms against cross-site request forgery. |
| Sign-in cookies | Set during the Google sign-in exchange to complete it securely. |
These are strictly necessary for a service you have asked for, so they do not require your consent. We do not use advertising, profiling or analytics cookies. If that ever changes, we will ask for your consent first.
12. Security
We use encrypted connections, store passwords only as salted hashes, keep payment card handling entirely with Stripe, and restrict access to production data to those who need it. No system is perfectly secure, but if a breach ever put your rights at risk, we will notify the supervisory authority and, where required, you.
13. Automated decisions
We do not make decisions about you by automated means alone, and we do not profile you. Whether a request is feasible is decided by a person.
14. Children
Assortiqa is a business service and is not directed at children. We do not knowingly collect data about anyone under 16. If you believe we have, tell us and we will delete it.
15. Complaints
Please contact us first at support@assortiqa.com; most things are quickest to fix directly.
You also have the right to complain to a data protection supervisory authority. In Bulgaria that is the Commission for Personal Data Protection. If you live in another EU country, you may complain to the authority where you live or work instead.
16. Changes to this policy
We will update this policy when what we do with your data changes, for example if we add a new supplier. The version and date at the top always show what is currently in force, and we will tell you by email before any change that materially affects your rights.
Version 1.1, in force from 5 September 2026. See also our Terms and Conditions.