for the application “Travel from your couch”
Version: 1.0
Effective date: 09.09.2026
Operator: Rivery Shop Ltd.
Company registration number: BG204954705
Address: Office 2, 23 Milin Kamak Street, Stara Zagora 6000, Bulgaria
This Privacy Policy explains how the operator of the application “Travel from your couch” collects, uses, stores, protects and shares personal data in connection with access to the application, the website and all related platform services.
The Platform enables Clients to connect with Guides for remote interactive tours in real time through video and audio using the Platform’s website and mobile applications for Android and iOS. Guides offer and perform the services, while the Platform provides the technical environment for registration, destination selection, communication, booking, payment, rating, complaints and administration of the relationship between the participants.
The Operator processes personal data in compliance with Regulation (EU) 2016/679, the General Data Protection Regulation, the Bulgarian Personal Data Protection Act and the applicable Bulgarian and European legislation. This Policy is intended to provide clear information about what data is processed, for what purposes, on what legal basis, to whom it may be disclosed, for how long it is stored and how users may exercise their rights.
The Operator acts as a data controller in relation to the personal data processed through the Platform for registration, profile management, bookings, sessions, chats, payments, payouts to Guides, ratings, complaints, technical security, fraud prevention and protection against circumvention of the Platform.
When a Guide obtains access to personal data of a Client through the Platform, the Guide may use such data only for the purposes of the specific request or session through the Platform. The Guide may not use Client data for direct contact, advertising, future services outside the Platform, disclosure to third parties or circumvention of the Platform.
External providers such as Stripe, Agora, AWS and Firebase may process personal data as processors on behalf of the Operator or as independent controllers where the nature of the relevant service or their legal obligations require this.
The Operator processes personal data of Clients who search for, request, book, pay for and participate in remote tours. The Operator also processes personal data of Guides who create a profile, undergo verification, publish information about their services, receive requests, conduct sessions and receive remuneration through the Platform.
The Operator may also process data of visitors to the website or the application when they use public or limited functionalities without registration. Data may also be processed in relation to administrators, employees, contractors or other persons who maintain and manage the Platform.
During real time sessions, third parties may incidentally appear on camera, for example passers by in public places. The Platform does not aim to identify, track or independently process data about such persons. The Guide must avoid deliberately filming persons, children, private spaces, documents, bank details, vehicle registration numbers, security systems and other objects that are not necessary for the tour or whose filming is prohibited.
When an account is created and used, the Operator processes the email address, the bcrypt hash of the password, the user role, the registration date, the blocking date if the account is blocked, hashes of refresh tokens, hashes of password reset tokens and the validity periods of the tokens.
In the event of failed login attempts, an email address and a counter of failed attempts may be processed. Such a record may also be created when the entered email address does not belong to a registered user. These data are used to protect accounts, limit abuse and prevent unauthorised access.
The Operator does not store passwords in readable form. Passwords are stored only as cryptographic hashes.
For Guides, the Operator processes first and last name, city, languages, rate, link to profile photo, link to introductory video, biography, online status, average rating, information whether verification has been completed and information whether the payment onboarding process has been completed.
Some of these data are visible to Clients so that they can choose a suitable Guide according to destination, language, price, availability, rating and description of the offered service.
The Guide is responsible for ensuring that the data provided by them are accurate, up to date and do not infringe the rights of third parties. The Guide must not publish in their profile a telephone number, email address, payment details, social media profiles or other information intended to circumvent the Platform.
The Operator may also process the Guide’s device or notification-related data to deliver push notifications concerning the status of payments and payouts. In particular, the Guide may receive a push notification when a payout to the Guide has been successfully processed or transferred.
For Clients, the Operator processes data necessary for registration, selection of a Guide, selection of a destination, route request, booking, payment, participation in a session, chat, rating, complaint and communication with the Operator.
The Operator may process information about the selected destination, city, route, date and time of the session, duration, Client preferences, free text describing the Client’s wishes for the tour, messages to the Guide, payment data such as amount, currency, status and payment identifier, as well as data relating to submitted complaints.
The Client should not enter into the Platform unnecessary personal data, data of third parties, sensitive data, identity documents, bank details or other information that is not necessary for the specific service.
When a session is requested and conducted, the Operator processes data about the participants in the session, who participates with whom, the date and time, duration, type of booking, start and end time, selected Guide, selected destination, city or route, as well as data indicating whether the session was completed, interrupted, cancelled or subject to a complaint.
These data are necessary for performance of the service, control of duration, administration of payment, payout to the Guide, handling of complaints and protection against abuse.
The Platform may process the full text of the chat within a session, the sender of the message, the date and time of the message, messages relating to route requests, price offers from Guides and free text describing the Client’s wishes regarding a city, date, route, event, place or experience.
Chats and messages are used for performance of the requested service, clarification of the route, communication between the Client and the Guide, proof of performance, handling of complaints, fraud prevention and protection against circumvention of the Platform.
Users must not send through the chat bank card data, identity documents, sensitive information, data of third parties or content that is unlawful, offensive, discriminatory, threatening or infringes the rights of other persons.
The main service of the Platform involves processing of real time video and audio between the Client and the Guide. The video and audio stream may be processed through the external provider Agora, which provides the technical connection between the participants.
When the recording functionality is enabled, a session recording may be created. The recording may include video, audio, technical data about the session, Agora resource or sid, recording status and a file key stored in AWS S3. A recording is made only when this is provided for in the functionality of the Platform and the participants are notified before or at the start of the recording.
Session recordings are stored in AWS S3 for a period of 30 days following the completion of the relevant session. During this period, the Client may access the recording and replay the video of the completed session through the Platform. After the expiry of the 30-day retention period, the recording will be deleted or made inaccessible, unless a longer retention period is required for compliance with a legal obligation, the establishment, exercise or defence of legal claims, or another lawful purpose.
Recordings may be used as proof of performance, for handling complaints, protection against fraud, technical support, quality control, security and protection in relation to legal claims. Where the recording is not necessary for the main service or for the protection of a legitimate interest, the Operator may request separate consent.
The Guide may not deliberately direct the camera towards persons, children, private spaces, documents, bank details, vehicle registration numbers, security systems or other objects that are not necessary for the tour or whose filming is prohibited by law, by the rules of the location or by the rights of third parties.
After completion of a session, the Client may rate the Guide. The Operator processes the rating from 1 to 5, information about who rated whom, the date and time of the rating and the average rating of the Guide. If text reviews are enabled, the Operator may also process the content of the review.
The rating is used for ranking Guides, improving quality, informing Clients and preventing abuse The Operator may restrict, hide or remove a rating or review if it contains offensive, unlawful, false, manipulative or advertising content, personal data or information that infringes the rights of third parties.
When a complaint or dispute is submitted, the Operator processes the reason for the complaint, the free text of the issue, session data, chats, technical connection data, payment data, the decision on the complaint, information about which administrator made the decision and administrative notes.
These data are used to verify the factual circumstances, temporarily suspend or release payment to the Guide, provide a partial or full refund, handle the dispute, protect the Client, protect the Guide, protect the Operator and prevent fraud.
Clients pay for the services in advance through the payment infrastructure of Stripe. The Operator does not store bank card numbers, security codes, expiry dates or other sensitive card data.
The Operator’s systems store only the data necessary to administer the payment, such as amount, currency, payment status, Stripe PaymentIntent identifier, additional fees or surcharges where applicable, as well as information necessary for refunds, complaint handling and accounting.
Stripe Connect Express is used for payouts of remuneration to Guides. The Guide’s bank and tax data are collected and processed by Stripe during the registration and onboarding process. The Operator does not store the Guide’s bank and tax data in its own database. The Operator stores only the stripe_account_id and information whether the onboarding process has been completed.
For the provision of part of the Platform’s functionalities, the Operator uses external providers of technology, payment, communication, email and infrastructure services. In such cases, certain data are collected and processed directly by the relevant external provider, while the Operator stores only the minimum necessary information required for the relevant functionality, such as a status, technical identifier, link, file key or other limited record.
For Guide verification, the Platform uses Stripe Identity. Within this verification, a photo of an official identity document and a selfie of the Guide may be processed. The scanning is performed through Stripe’s SDK on the device, including com.stripe:identity. The verification itself is carried out in Stripe’s environment. The Operator’s database does not store a photo or copy of the identity document, nor the selfie image. The Operator receives and stores only the result of the verification, such as verified or failed, and the identifier of the relevant Stripe Identity session. This processing is used to confirm the identity of the Guide, reduce the risk of fraud, protect Clients and ensure the security of the Platform.
For registration of Guides for receiving payments and for subsequent payouts of remuneration, the Platform uses Stripe Connect Express. The Guide’s bank and tax data required for payments are collected by Stripe during the registration and onboarding process. These bank and tax data are not stored in the Operator’s database. The Operator’s system stores the Guide’s stripe_account_id together with information relating to the status of the Stripe account and onboarding process, including the transfer status, information about requirements awaiting action by the Guide, and related status-change and notification timestamps. These data are necessary so that the Platform can connect the Guide’s profile with Stripe’s payment infrastructure, monitor the status of the payment account and administer the payouts due.
For accepting payments from Clients, the Platform uses Stripe PaymentSheet. The Client’s bank card data are entered directly through Stripe’s SDK and do not reach the Operator’s backend. The Operator does not store card data. The application uses Stripe’s publishable key, which serves to initiate the payment process and does not constitute storage of card information by the Operator. The Operator’s system stores only data necessary for administering the payment, such as amount, currency, payment status and Stripe PaymentIntent identifier.
For real-time video and audio connection during sessions, the Platform uses Agora. Through Agora, the video and audio stream between the Client and the Guide is processed, together with technical data necessary to establish, maintain and terminate the connection. Agora RTM may also be used to enable real-time text communication between the participants during a session. The text messages exchanged during sessions may also be stored in the Operator’s systems as described in Section 8 of this Policy. When the recording functionality is enabled, Agora may also be used to create cloud recordings of sessions.
For storage and delivery of file content, the Platform uses AWS S3 in the eu-central-1 region. Through this infrastructure, profile photos of Guides, introductory videos of Guides and session recordings may be stored and delivered when such recordings are enabled. The Operator’s system may store a link, file key or other technical identifier that enables the relevant file to be located and loaded. Access to session recordings may be provided through signed S3 URLs or other access mechanisms implemented by the Platform.
For sending transactional emails, the Platform uses Amazon Simple Email Service (AWS SES). AWS SES may process the email address of the relevant user and the content and technical information necessary to deliver transactional messages, including account verification codes, password reset messages, notifications concerning Stripe requirements and operational or security alerts. Such emails are sent for the functioning, security and administration of the Platform and are not marketing communications.
For sending push notifications, the Platform uses Firebase Cloud Messaging (Firebase FCM). Through Firebase FCM, notifications related to the functioning of the Platform are delivered, including notifications about sessions, bookings, changes, messages, complaints, technical events, payment or payout events, security or other actions connected with the use of the service. For this purpose, the device push token, the device platform and notification settings are processed.
The Platform also uses Firebase Crashlytics for crash and diagnostic reporting in the application. Crashlytics may process technical information relating to the application installation, device and application failures and other diagnostic information necessary to identify, investigate and improve the stability and security of the application.
If real-time transcription, live captions or translation functionality is enabled in the Platform, Agora may process audio-derived speech data from both the Client and the Guide for the purpose of generating transcriptions, captions or translations. Where translation is enabled, the translation functionality may operate in both directions between the languages selected for the Client and the Guide.
The available languages depend on the languages supported by Agora at the relevant time and may vary depending on the selected language combination, technical availability or changes made by Agora. Such functionality is disabled by default and may be enabled only where the relevant feature is made available in the Platform.
The Operator does not store the caption or translation text generated through this functionality. The underlying speech may nevertheless be transmitted to and processed by Agora as necessary to provide the enabled functionality. Machine-generated translation is provided on a beta basis and may contain inaccuracies.
Where required by applicable law, the Operator will provide the relevant information and obtain consent or rely on another appropriate legal basis before enabling or using such functionality.
The Operator does not store the sensitive payment data of Clients, the bank and tax data of Guides, photos of identity documents, selfie images from the verification process or card data entered through Stripe. These data are processed by the relevant external providers in accordance with their technical, contractual and legal terms. The Operator stores only the technical identifiers, statuses, links, file keys and other records necessary for providing the service, performing the contract with users, administering payments and payouts, protecting the Platform, handling complaints, providing technical support and complying with legal obligations.
The Platform does not collect geolocation data. Geolocation is not used either in the backend or in the mobile application. The Guide’s city is entered manually by the Guide as free text.
In the current Android configuration, only internet access permission is requested. No permissions are requested for access to contacts or device storage. Where video or audio functionality is enabled, the application may request access to the camera and microphone solely for the purpose of conducting the session.
As of the date of this Policy, the Operator does not use analytics tools, advertising SDKs, advertising trackers or marketing tracking technologies, including Firebase Analytics, Google Analytics or Sentry. The Platform does, however, use Firebase Crashlytics for crash and diagnostic reporting as described in Section 13 of this Policy. Crashlytics is not used for advertising, marketing or behavioural tracking.
As of the date of this Policy, the Operator does not send email newsletters or marketing emails. The Platform may use service push notifications related to the course of sessions, bookings, messages, complaints, security or other functional events.
The Operator processes personal data for creating and managing user accounts, logging into accounts, maintaining sessions, restoring access, blocking accounts in case of violations, and providing the functionalities of the Platform, including destination search, Guide selection, bookings, route requests, chat, real-time video and audio sessions, ratings and service notifications.
The data are also processed for verification of Guides, monitoring the status of Guide payment accounts, reducing the risk of fraud, protecting Clients and Guides, accepting and administering payments, processing additional charges, administering payouts to Guides, calculating and deducting the Operator’s commission, processing refunds and handling complaints and disputes.
The Operator processes data for security, technical support, protection against unauthorised access, rate limiting in connection with login attempts, audit trails, prevention of abuse, crash and diagnostic reporting, and protection against attempts to circumvent the Platform.For the protection against circumvention, automated technical checks may be used to detect telephone numbers, email addresses, payment links, social media profiles, bank details or other information that may indicate an attempt to move communication, negotiation or payment outside the Platform.
The data may also be processed for sending transactional and service communications, including account-related emails, password reset communications, notifications concerning payment or payout requirements, operational alerts and push notifications.
The data may also be processed for compliance with legal obligations, accounting and tax reporting, assistance to competent authorities in response to lawful requests, protection in relation to legal claims and fulfilment of obligations relating to platform operators, where such obligations apply to the Operator’s activity.
Where additional functionalities such as real-time transcription, live captions or translation are enabled, the relevant audio-derived or other data may also be processed for the purpose of providing those functionalities, subject to the applicable legal basis and any information or consent requirements.
Where the data are necessary for registration, account management, route requests, bookings, chat, conducting a session, payment or payout to a Guide, the processing is carried out for the performance of a contract or for taking steps at the request of the data subject prior to entering into a contract.
Where the data are necessary for accounting, tax reporting, storage of payment records, assistance to competent authorities or compliance with other legal obligations, the processing is carried out for compliance with a legal obligation.
Where the data are necessary for security, fraud prevention, protection against circumvention of the Platform, handling of complaints and disputes, technical support, protection of rights, prevention of abuse, quality and security of the service or protection of the Operator’s legitimate interests, the processing may be carried out on the basis of the Operator’s legitimate interests, provided that such interests are not overridden by the rights and freedoms of the data subjects.
Where data are processed for marketing, for a session recording or other additional functionality for which the applicable law requires consent, or for another processing activity for which consent is the appropriate legal basis, the processing is carried out on the basis of consent. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before the withdrawal.
The Platform may use automated technical tools to detect attempts to circumvent the Platform. Such checks may cover chats, route requests, offers, profile information, service descriptions, administrative alerts and technical logs.
The automated checks may detect telephone numbers, email addresses, payment links, bank details, social media profiles, keywords or other information indicating an attempt by the Client or Guide to move communication, negotiation or payment outside the Platform.
An automated detection may result in a warning, temporary restriction, marking for review, temporary withholding of payment or referral of the case for manual review.Automated detection is used as a technical and risk-management measure and does not by itself constitute a final decision concerning the user.
Final decisions with significant consequences, such as permanent blocking of an account or final refusal of a payout in a dispute, are reviewed by an authorised person, unless the applicable law permits otherwise.
The Platform may rank or display Guides based on criteria relevant to the selection and presentation of available services to Clients. Such criteria may include average rating, number of completed sessions, availability, language, city or destination, price, session completion information, number of complaints, frequency of cancellations, verification status, technical information relating to session quality and compliance with the Terms and Conditions.
These criteria are used to display more relevant offers to Clients, improve the quality of the service and maintain the security and proper functioning of the Platform.
The ranking and presentation of Guides do not constitute decisions that automatically produce legal effects concerning the Guide or similarly significantly affect the Guide.
The Platform may send push notifications related to the functioning of the service. Such notifications may concern an upcoming session, changes to a booking, a new message, a complaint, a payment or payout, a technical event, security, account status or another functionality of the Platform.
For this purpose, the device push token, device platform and notification settings are processed. Push notifications are not used for marketing messages unless such functionality is introduced in the future on a valid legal basis and with an option to opt out.
The Platform may use cookies, local storage, session tokens, refresh tokens or similar technologies where this is necessary for logging into an account, maintaining a session, security, remembering settings, functioning of the website or application and provision of the service.
As of the date of this Policy, the Operator does not use analytics, advertising or tracking cookies or SDKs. If analytics, advertising or marketing technologies are introduced in the future, the Operator will provide additional information and, where necessary, request prior consent.
The user may manage cookies and local storage through the settings of the browser or device. Restricting certain functional technologies may result in inability to log in, book, pay or use certain functions of the Platform.
As of the date of this Policy, the Operator does not send email newsletters or marketing communications. Service messages related to an account, booking, session, payment, complaint, security or changes to the terms are not marketing communications and may be sent where necessary for provision of the service.
If marketing communications are introduced in the future, they will be sent only where there is a valid legal basis. Where the law requires consent, marketing communications will be sent only after prior consent, which may be withdrawn at any time.
The Operator does not request and does not aim to process special categories of personal data, including data concerning health, political opinions, religion, philosophical beliefs, trade union membership, genetic data, biometric data for our own identification purposes, sex life or sexual orientation.
Users should not enter such data in chats, requests, profiles, reviews or complaints. If such data are voluntarily provided by a user, the Operator will process them only to the extent necessary for the specific purpose, protection of rights, compliance with a legal obligation or another applicable legal basis.
The Platform is not intended for independent use by persons under 18 years of age. A Guide may only be an adult.
If a person under 18 uses the Platform, this should be done through an account and under the control of a parent, guardian or legal representative. If the processing of data of a person under 14 is based on consent, the consent must be given by the parent exercising parental responsibility or by the guardian.
If the Operator establishes that it has received data of a child without the necessary legal basis, it will take steps to delete, restrict or otherwise lawfully resolve the processing.
Users may not provide personal data of third parties through the Platform unless they have the right to do so. The Client may not require the Guide to film persons, private spaces, documents, security systems or other sensitive objects in breach of the law or the rights of third parties.
The Guide must avoid deliberately filming random persons and must comply with the applicable rules on filming, access, public order and protection of private life in the relevant country or location.
Access to personal data is granted only to persons and providers for whom this is necessary in connection with the provision of the service, maintenance and operation of the Platform, payments, payouts to Guides, security, handling of complaints, accounting, legal protection or compliance with a legal obligation.
Data may be accessible to Platform administrators, the technical team, persons handling complaints, accountants, lawyers, and third-party service providers supporting the Platform, including: Amazon Web Services (AWS), for hosting and system infrastructure, database services, cloud storage and transactional email services; Stripe, for payment processing, Guide payouts and identity verification; Agora, for real-time video and audio sessions, in-session text messaging through Agora RTM and, where enabled, live captions, speech transcription and translation; Firebase, including Firebase Cloud Messaging (FCM) for push notifications and Firebase Crashlytics for crash and diagnostic reporting; other providers supporting the operation, security and maintenance of the Platform; and competent public authorities where disclosure is required or permitted by applicable law.
Clients and Guides have access only to personal data that are necessary for a specific booking, session, chat, rating, payment or complaint. Guides may not use Client data outside the Platform or for purposes unrelated to the provision of the relevant service.
The Platform uses third-party infrastructure and service providers that may process personal data outside the European Economic Area (EEA).
The main production infrastructure operated through Amazon Web Services (AWS), including hosting, database services and file storage, is located in the eu-central-1 region. Transactional email services provided through AWS SES are also configured in the relevant AWS region.
Session recordings are generated through Agora Cloud Recording and are stored directly in the Operator’s Amazon S3 bucket in the eu-central-1 region. Agora therefore does not serve as the Operator’s storage provider for session recordings; its processing may involve the routing and processing of the relevant real-time audio and video streams.
Certain external providers, including Stripe, Agora and Firebase, may process personal data outside the EEA. In particular, the geographic location of certain processing performed by Firebase services, including FCM and Crashlytics, may not be determined or controlled by the Operator.
Where personal data are transferred outside the EEA, the Operator relies on an applicable lawful transfer mechanism, where available and applicable, including an adequacy decision, the European Commission’s Standard Contractual Clauses, other appropriate contractual safeguards, technical and organisational measures, or another transfer mechanism permitted under applicable data protection law.
The Operator stores personal data only to the extent necessary for the purposes for which they were collected or to the extent required by law, contract, accounting rules, tax obligations, protection in relation to claims, security or prevention of abuse.
Account data are stored while the account is active and thereafter for the period necessary for protection in relation to claims, security, accounting or compliance with a legal obligation. Payment data are stored for the period necessary for accounting and tax purposes, refunds, disputes and proof of completed transactions.
Chats, route requests, session data, recordings, technical logs, audit records and complaint data are stored for the period necessary for performance of the service, handling of complaints, protection against fraud, security and legal protection. As of the date of this Policy, specific automatic deletion periods for session recordings, correspondence and technical logs may not have been technically configured. When specific periods or automatic deletion are introduced, this Policy will be updated.
Data provided without a legal basis or in breach of the principles of processing are returned, deleted or destroyed where applicable. Deletion or destruction is documented where required by law.
The user may request closure or deletion of their account by email to the Operator. If an independent account deletion functionality is introduced in the application, it will be indicated in the Platform interface.
Upon a deletion request, the Operator will delete or anonymise personal data where and to the extent applicable. Some data may be retained after a deletion request where this is necessary for accounting and tax obligations, proof of payments, protection in relation to claims, investigation of abuse, prevention of repeated registration after a serious violation or compliance with a legal obligation.
Payment identifiers, payment records and data processed by Stripe may be stored by Stripe in accordance with its legal and contractual obligations.
The Operator applies technical and organisational measures for the protection of personal data, taking into account the nature of the data, the scope, context, purposes of processing and the risk to the rights and freedoms of natural persons.
The measures may include hashing of passwords through bcrypt, storage of tokens as hashes, role based access restrictions, control of administrative actions, technical logs, protection against failed login attempts, use of external providers for sensitive payment and identification operations, encrypted transmission of data, contractual confidentiality obligations, control of access to recordings, chats and complaints, and measures against unauthorised access, loss, destruction, alteration or disclosure.
Access to identifiers, links, file keys, recordings, payment statuses, verification statuses and other data related to external providers is granted only to persons for whom this is necessary in connection with maintenance of the Platform, payments, payouts to Guides, handling of complaints, security, fraud prevention or compliance with a legal obligation.
In the event of a personal data breach, the Operator takes measures to limit the consequences, investigate the causes, document the incident and prevent future breaches.
Where required by law, the Operator notifies the competent supervisory authority and the affected persons. When assessing an incident, the Operator takes into account the type of affected data, the number of affected persons, the possible consequences, the measures applied to limit the risk and the need for notification.
If the Operator’s activity falls within the scope of rules for platform operators relating to the collection and provision of information for tax purposes, the Operator may process and provide to the competent authorities certain data about Guides, payments received, remuneration, identifiers and other information required by law.
In such case, the affected natural persons will be informed in advance and in a timely manner about the collection and provision of their personal data for tax purposes, to the extent applicable to the activity of the Platform.
Each user has the right to obtain confirmation as to whether the Operator processes their personal data, to obtain access to such data, to request correction of inaccurate or incomplete data, to request deletion of data where legal grounds exist, to request restriction of processing, to receive their data in a structured, commonly used and machine readable format where applicable, and to object to processing based on legitimate interests.
Where processing is based on consent, the user has the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
The user has the right not to be subject to a decision based solely on automated processing, including profiling, where such decision produces legal effects concerning the user or similarly significantly affects the user, unless such processing is permitted by law and the necessary safeguards are provided.
The user may exercise their rights by submitting a request to the Operator at the following email address: support@travelfromyourcouch.com
For data protection purposes, the Operator may request additional information where reasonably necessary to verify the identity of the requester, particularly where there are reasonable doubts about the identity of the person making the request.
The Operator responds to requests within the time limits provided for in applicable data protection legislation.
The Operator may refuse or restrict the fulfilment of a request where it cannot identify the requester, where the request is manifestly unfounded or excessive, where the data must be retained to comply with a legal obligation, where the data are necessary for the establishment, exercise or defence of legal claims, where deletion would adversely affect the rights of other persons, or where another lawful ground for refusal or restriction applies.
If the user considers that the processing of their personal data infringes the applicable legislation, the user has the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection.
Commission for Personal Data Protection
Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
Website: https://www.cpdp.bg
Email: kzld@cpdp.bg
The user also has the right to judicial protection in accordance with the applicable law.
The Guide’s profile may be visible to Clients or visitors of the Platform. The visible information may include name, city, languages, rate, profile photo, introductory video, biography, rating and availability status.
Client profiles are not public, except to the extent that certain data are necessary for a specific session, request, chat, payment, complaint or rating. Users should not publish in their profiles information that they do not want to be visible to other users.
Users may enter free text in chats, route requests, complaints, biographies, offers and reviews. The user is responsible for not entering unnecessary personal data, data of third parties, sensitive data, identity document data, bank details, unlawful content or information that infringes the rights of other persons.
The Operator may remove, restrict or block content that violates the Terms and Conditions, this Policy, the law or the rights of third parties.
The Platform may contain links to websites, applications or services operated by third parties. This Privacy Policy applies only to the Platform and services operated or controlled by the Operator and does not apply to third-party websites, applications or services.
Users should review the privacy policies and terms of the relevant third-party providers when accessing or using their websites, applications or services, including where applicable Stripe, Agora, Amazon Web Services (AWS) and Firebase.
The Operator is not responsible for the privacy practices, content or security of third-party websites, applications or services that are not operated or controlled by the Operator.
As of the date of this Policy, the Operator does not send email newsletters or marketing communications. Service messages related to an account, booking, session, payment, complaint, security or changes to the terms are not marketing communications and may be sent where necessary for provision of the service.
If marketing communications are introduced in the future, they will be sent only where there is a valid legal basis. Where the law requires consent, marketing communications will be sent only after prior consent, which may be withdrawn at any time.
For questions regarding this Policy or the processing of personal data, users may contact the Operator at the following contact details.