← Back

Privacy Policy

Last updated: 5 August 2026

1. Who we are

This platform (Bazata) is operated by Vtornik Ltd., VAT 207226236, 10 Georgi Benkovski str., Kazanlak.

Questions about this policy: coworking@bazata.bg

2. What personal data we collect

  • Account data: name, email address, phone number, profile picture.
  • Authentication data: hashed password (bcrypt), password-reset tokens.
  • Booking & subscription data: reservation dates, subscription types, payment amounts, invoice details.
  • Company data: VAT number, legal name, address (if you provide these for invoicing).
  • Access logs: door-entry timestamps and cryptographic access codes derived from your user ID.
  • Email logs: a record of transactional emails sent to you (subject, status, timestamp).
  • Login history: date and time of each login.

3. How we use your data

PurposeLawful basis
Provide access to Bazata and its facilitiesPerformance of a contract (Art. 6(1)(b))
Process payments and issue invoicesLegal obligation + contract (Art. 6(1)(b)(c))
Send transactional emails (booking confirmations, reminders)Contract performance (Art. 6(1)(b))
Operate door-access controlLegitimate interest — building security (Art. 6(1)(f))
Audit logs for security and dispute resolutionLegitimate interest (Art. 6(1)(f))
Comply with accounting & tax lawLegal obligation (Art. 6(1)(c))

4. Third-party processors

We share data with the following processors who act under our instructions:

  • MyPOS — payment processing (name, email, amount). Subject to the processor's privacy policy.

We do not sell personal data or use it for advertising.

5. Data retention

  • Account data: retained while your account is active. Anonymised upon account erasure request.
  • Invoice & payment records: retained for 10 years per Bulgarian accounting law.
  • Email logs: automatically purged after 0 days.
  • Door-access logs: automatically purged after 0 days.
  • Login history: retained for 12 months.

6. Cookies

This platform uses one essential session cookie (next-auth.session-token) solely to keep you logged in. This cookie is HTTP-only, expires after 24 hours, and is not used for tracking or advertising. No third-party cookies are set.

7. Your rights under GDPR

You have the right to:

  • Access the personal data we hold about you (Art. 15).
  • Rectify inaccurate data — you can update your name, phone, and email from your profile page.
  • Erasure — you can request anonymisation of your account from your profile page. This removes all identifying information while preserving anonymised records for legal/security purposes.
  • Restrict processing — contact us to pause processing while a dispute is resolved.
  • Data portability — contact us to receive a copy of your data in machine-readable format.
  • Object to processing based on legitimate interests — contact us.

To exercise any right, email coworking@bazata.bg. We respond within 30 days. You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP).

8. Security

Passwords are stored using bcrypt with salt. All data is transmitted over HTTPS. Access to the database is restricted to authorised personnel.

9. Changes to this policy

We may update this policy. Material changes will be communicated by email or a notice on the platform. The current version is always available at /privacy.