GDPR · ZZLD
Notice on the processing of personal data
Notice given pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and to the Zakon za zashtita na lichnite danni (ZZLD, the Personal Data Protection Act) of the Republic of Bulgaria.
1. Data controller
The data controller is Sauron 2024 Ltd / САУРОН 2024 ЕООД, UIC 207660705, with registered office at гр. София 1797, р-н Студентски, ж.к. Мусагеница, бл. 105, вх. В, ет. 1, оф. 1, Bulgaria (in Latin script: gr. Sofia 1797, r-n Studentski, zh.k. Musagenitsa, bl. 105, vh. V, et. 1, of. 1, Bulgaria).
Contact point for any matter concerning personal data: info@sauronltd.com — telephone +39 391 763 1415.
The company has not appointed a data protection officer (DPO), as the conditions set out in Article 37 of the GDPR are not met.
2. Data processed and its source
The company processes only the data that the data subject provides voluntarily, together with the minimum technical data required for the security of the service.
- Contact form data — first name and surname, e-mail address, company name where given, the content of the message and the language in which it was completed.
- Correspondence data — the data contained in communications sent by e-mail or given by telephone.
- Technical security data — IP address in truncated or pseudonymised form, the date and time of the request, and its outcome. These serve to prevent abuse and automated submissions.
- Data not collected — the website uses no third-party statistical analytics, carries out no profiling, does not track browsing and does not obtain data from third-party sources or from lists.
3. Purposes and legal bases
- Responding to enquiries — Processing necessary to act on the data subject's request and to take steps at their request prior to entering into a contract — Article 6(1)(b) GDPR.
- Website security — Prevention of abuse, automated submissions and unauthorised access attempts, on the basis of the controller's legitimate interest in protecting its own infrastructure — Article 6(1)(f) GDPR.
- Legal obligations — Retention of communications where required by accounting, tax or other obligations — Article 6(1)(c) GDPR.
- Any commercial communications — Only with prior consent, freely given, specific and revocable at any time — Article 6(1)(a) GDPR. Consent is never a condition for submitting the form.
4. Nature of the provision of data
Providing the data marked as mandatory in the form is necessary in order to respond to the enquiry: without it, no reply is possible. Providing any other data is optional.
5. Recipients and processors
The data is not disseminated, is not passed to third parties for marketing purposes and is not sold.
It may be accessed, as processors appointed under Article 28 of the GDPR, by the providers of the technical services strictly necessary for the operation of the website:
- Cloudflare, Inc. — provider of the hosting infrastructure, the distribution network, the database in which messages are stored and the security services. The relationship is governed by the Cloudflare Customer Data Processing Addendum.
- E-mail service provider — used for the delivery of notifications and correspondence, strictly to the extent necessary.
- Appointed professional advisers — lawyers, accountants and consultants, solely where necessary to act on the enquiry and within the limits of their respective engagements.
6. Transfers to third countries
The infrastructure is configured to keep the data within the European Union. It cannot be ruled out, however, that certain technical operations involve a transfer to third countries.
Such transfers take place subject to appropriate safeguards under Chapter V of the GDPR, and in particular on the basis of the standard contractual clauses adopted by the European Commission and incorporated into the Cloudflare Customer Data Processing Addendum, as well as — where applicable — the adequacy decision on the EU–U.S. Data Privacy Framework. A copy of the safeguards may be requested by writing to info@sauronltd.com.
7. Retention period
- Messages received through the form — 12 months from receipt. Deletion is carried out automatically by a scheduled routine: the period is applied, not merely stated.
- Correspondence giving rise to a contractual relationship — for the duration of the relationship and for the subsequent limitation and retention periods laid down by law.
- Technical security data — the period strictly necessary for the security purpose, and in any event no longer than 12 months.
- Data processed on the basis of consent — until consent is withdrawn.
8. Rights of the data subject
The data subject may exercise the rights under Articles 15 to 22 of the GDPR at any time, free of charge and without formality.
- Access — to obtain confirmation that processing is taking place and a copy of the data processed.
- Rectification — to obtain the correction of inaccurate data and the completion of incomplete data.
- Erasure — to obtain the erasure of the data in the cases provided for in Article 17.
- Restriction — to obtain the restriction of processing in the cases provided for in Article 18.
- Portability — to receive the data in a structured, commonly used format and to transmit it to another controller.
- Objection — to object at any time to processing based on legitimate interest.
- Withdrawal of consent — to withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.
9. How to exercise your rights and complaints to the supervisory authority
Requests should be addressed to info@sauronltd.com. The controller replies without undue delay and in any event within one month of receipt; that period may be extended by two months where the matter is complex, with reasons given.
A data subject who considers that their rights have been infringed may lodge a complaint with the Bulgarian supervisory authority — Komisiya za zashtita na lichnite danni (KZLD, the Commission for Personal Data Protection), whose current contact details are published on cpdp.bg — or with the supervisory authority of the Member State of their habitual residence. The right to bring proceedings before the courts is unaffected.
10. Automated decision-making and minors
The controller carries out no profiling and takes no automated decisions producing legal effects concerning the data subject or similarly significantly affecting them, within the meaning of Article 22 of the GDPR.
The services offered through this website are not directed at children under 14, in accordance with Article 25v of the ZZLD. The controller does not knowingly collect data relating to children of that age; should it become aware of any such data, it will delete it.
11. Security and amendments
The controller applies appropriate technical and organisational measures under Article 32 of the GDPR: encrypted transmission over TLS, access to the restricted area protected by authentication, minimisation of the data collected, and automatic deletion once the retention period expires.
This notice may be updated. The version in force is always the one published on this page.
Last updated: 2026-09-06