Privacy Policy
Last updated: 5 August 2026
1. Who we are
This platform (Bazata) is operated by Vtornik Ltd., VAT 207226236, 10 Georgi Benkovski str., Kazanlak.
Questions about this policy: coworking@bazata.bg
2. What personal data we collect
- Account data: name, email address, phone number, profile picture.
- Authentication data: hashed password (bcrypt), password-reset tokens.
- Booking & subscription data: reservation dates, subscription types, payment amounts, invoice details.
- Company data: VAT number, legal name, address (if you provide these for invoicing).
- Access logs: door-entry timestamps and cryptographic access codes derived from your user ID.
- Email logs: a record of transactional emails sent to you (subject, status, timestamp).
- Login history: date and time of each login.
3. How we use your data
| Purpose | Lawful basis |
|---|---|
| Provide access to Bazata and its facilities | Performance of a contract (Art. 6(1)(b)) |
| Process payments and issue invoices | Legal obligation + contract (Art. 6(1)(b)(c)) |
| Send transactional emails (booking confirmations, reminders) | Contract performance (Art. 6(1)(b)) |
| Operate door-access control | Legitimate interest — building security (Art. 6(1)(f)) |
| Audit logs for security and dispute resolution | Legitimate interest (Art. 6(1)(f)) |
| Comply with accounting & tax law | Legal obligation (Art. 6(1)(c)) |
4. Third-party processors
We share data with the following processors who act under our instructions:
- MyPOS — payment processing (name, email, amount). Subject to the processor's privacy policy.
We do not sell personal data or use it for advertising.
5. Data retention
- Account data: retained while your account is active. Anonymised upon account erasure request.
- Invoice & payment records: retained for 10 years per Bulgarian accounting law.
- Email logs: automatically purged after 0 days.
- Door-access logs: automatically purged after 0 days.
- Login history: retained for 12 months.
6. Cookies
This platform uses one essential session cookie (next-auth.session-token) solely to keep you logged in. This cookie is HTTP-only, expires after 24 hours, and is not used for tracking or advertising. No third-party cookies are set.
7. Your rights under GDPR
You have the right to:
- Access the personal data we hold about you (Art. 15).
- Rectify inaccurate data — you can update your name, phone, and email from your profile page.
- Erasure — you can request anonymisation of your account from your profile page. This removes all identifying information while preserving anonymised records for legal/security purposes.
- Restrict processing — contact us to pause processing while a dispute is resolved.
- Data portability — contact us to receive a copy of your data in machine-readable format.
- Object to processing based on legitimate interests — contact us.
To exercise any right, email coworking@bazata.bg. We respond within 30 days. You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP).
8. Security
Passwords are stored using bcrypt with salt. All data is transmitted over HTTPS. Access to the database is restricted to authorised personnel.
9. Changes to this policy
We may update this policy. Material changes will be communicated by email or a notice on the platform. The current version is always available at /privacy.