Skip to content
Oditor AI

Personal Data Protection Policy (GDPR)

This policy governs the processing of personal data when visiting the website, sending an enquiry, requesting a demo, creating and using a user account, using the functionalities of Oditor AI, subscription and additional services, support and other communication.

Last updated: 21.09.2026

  1. Controller of personal data

    The controller of the personal data processed through the Oditor AI website and platform is "Tsentralna Konsultantska Kompania" EOOD, UIC 204305396 (the "Controller").

    For questions relating to the protection of personal data and the exercise of rights under the GDPR, data subjects may use the official business e-mail/contact published on the Oditor AI website.

    Where the law requires the publication of additional identification details and contact particulars of the Controller, these shall be provided in the relevant section of the website.

  2. Subject matter and scope

    This policy governs the processing of personal data when visiting the website, sending an enquiry, requesting a demo, creating and using a user account, using the functionalities of Oditor AI, subscription and additional services, support and other communication.

    The policy applies to website visitors, platform users, representatives, employees and contact persons of clients and prospective clients, as well as other natural persons whose data is processed in connection with the service.

  3. Principles of processing

    • lawfulness, fairness and transparency;
    • purpose limitation;
    • data minimisation;
    • accuracy and currency;
    • storage limitation;
    • integrity and confidentiality;
    • accountability of the Controller.
  4. Categories of personal data

    • Identification and contact data: first name, last name, business e-mail, telephone.
    • Data from contact forms: subject, message, interest in a product, plan, demo, price, package, integration or support.
    • Account data: account identifier, role, access rights, settings and activity history, where the functionality requires it.
    • Business contact data: organisation, position/role and business correspondence.
    • Technical data: IP address, logs, date and time, browser, device, security and system events.
    • Support data: tickets, correspondence and technical information necessary to resolve a case.
    • Data necessary for a contract, invoicing and payment, to the extent actually processed by the Controller.
    • Personal data contained in documents and business data entered by clients into the platform.
  5. Purposes and legal bases

    PurposeExamplesLegal basis
    Enquiries and demosResponse to a contact request, offer, price, demonstrationArt. 6(1)(b) and/or (f) GDPR; consent, where applicable
    Provision of the platformAccount, access, subscription, functionalitiesArt. 6(1)(b) GDPR
    SupportTechnical and functional casescontract and/or legitimate interest
    SecurityLogs, protection against abuse and unauthorised accessArt. 6(1)(f) GDPR and applicable statutory obligations
    Invoicing and reportingAccounting and payment documentscontract and statutory obligation
    MarketingNews and offersconsent or another applicable legal basis; right to object
    Legal claimsEstablishment, exercise or defence of rightslegitimate interest and/or statutory obligation
  6. Contact forms and enquiries

    When a form is submitted through the website, the Controller processes the data provided in order to respond to the enquiry, arrange a demo, prepare a proposal or take steps requested prior to entering into a contract.

    Forms shall collect only the data necessary for the specific purpose. Special categories of personal data shall not be requested unless a clear legal basis and necessity exist for the specific processing.

  7. Data processed through Oditor AI

    The platform may process financial, accounting, document-related and other business data provided by the client. Some of it may contain personal data of employees, clients, suppliers, counterparties or other persons.

    Where "Tsentralna Konsultantska Kompania" EOOD processes such personal data on behalf of and on the documented instructions of a business client, the relationship shall be governed by a data processing contract/agreement under Art. 28 GDPR, where applicable.

  8. Use of artificial intelligence

    Oditor AI may use automated technologies and artificial intelligence models for analysis, checks, anomaly detection, alerts, summaries, forecasts and support of financial control.

    The results of the AI functionalities are of an assisting nature. The platform shall not be presented as carrying out solely automated decision-making producing legal or similarly significant effects for a natural person, unless the specific functionality has been expressly assessed and the requirements of Art. 22 GDPR have been met.

    Should such functionality be introduced, data subjects must receive the necessary information about the logic involved, the significance and the envisaged consequences, and the applicable safeguards.

  9. Recipients and processors

    • providers of hosting, cloud infrastructure and technical support;
    • providers of e-mail, communication and ticketing services;
    • payment and accounting providers, where applicable;
    • providers of analytics and security technologies where a legal basis exists;
    • external AI/technology providers, only if they are actually involved in the processing and are contractually governed;
    • professional advisers and legal representatives where necessary;
    • competent state, administrative and judicial authorities, where required by law.
  10. Transfers outside the European Economic Area

    Where personal data is transferred outside the EEA, the Controller applies a permissible mechanism under the GDPR, for example an adequacy decision, standard contractual clauses or another applicable mechanism, as well as additional safeguards where necessary.

  11. Retention periods

    Personal data is stored only for the period necessary for the relevant purpose, except where the law requires a longer period. The specific period is determined according to the type of data, the contractual relationship, the statutory periods for accounting reporting, limitation periods, security and the need to defend legal claims.

    • Enquiries: until the communication is concluded and for a reasonable subsequent period depending on the relationship.
    • Contractual data: for the term of the contract and the applicable statutory/limitation periods after its termination.
    • Accounting documents: for the periods established by law.
    • Account and technical data: for the period necessary to provide and protect the service.
    • Marketing data based on consent: until consent is withdrawn or the purpose ceases to exist.
  12. Cookies and similar technologies

    The website may use strictly necessary cookies, as well as analytics, functional or marketing technologies where the applicable legal requirements are met.

    Technologies that require prior consent shall not be activated before a valid choice by the user. The details shall be governed by a separate Cookie Policy and a consent management mechanism.

  13. Security

    The Controller applies appropriate technical and organisational measures commensurate with the risk, including access control, roles and permissions, protection of communications, backups, logging, vulnerability management and incident response procedures, where applicable.

    In the event of a personal data breach, the obligations under Art. 33 and 34 GDPR apply where the statutory conditions are met.

  14. Rights of data subjects

    • right to information and transparency;
    • right of access;
    • right to rectification;
    • right to erasure where the statutory conditions are met;
    • right to restriction of processing;
    • right to data portability, where applicable;
    • right to object to processing based on legitimate interest;
    • right to object at any time to direct marketing;
    • right to withdraw consent where the processing is based on consent;
    • rights in relation to decisions based solely on automated processing, where Art. 22 GDPR applies;
    • right to lodge a complaint with the Commission for Personal Data Protection.
  15. Exercising rights

    Requests for the exercise of rights are submitted through the official personal data protection contact published on the website. The Controller may request additional information where this is necessary to confirm identity and prevent unauthorised access.

    The Controller responds without undue delay and, as a rule, within one month of receipt of the request. Where the conditions under the GDPR are met, the period may be extended and the person is notified accordingly.

  16. Complaints to the supervisory authority

    Data subjects have the right to lodge a complaint with the Commission for Personal Data Protection (Комисия за защита на личните данни, CPDP) if they consider that the processing infringes the GDPR or applicable Bulgarian legislation. The current contact details and procedures should be taken from the official website of the CPDP.

  17. Direct marketing

    Marketing communications are sent only where an applicable legal basis exists. The recipient must have an easy way to unsubscribe or object. Unsubscribing from marketing does not terminate the necessary service messages relating to the contract, security, payment or support.

  18. Children's data

    Oditor AI is a professional and business-oriented service and is not specifically intended for children. There is no intention to knowingly collect personal data from children through the standard business functionalities.

  19. Changes to the policy

    The policy may be updated in the event of changes to the services, technologies, providers or legislation. The current version is published on the website with the date of the last update. In the event of a material change, the affected persons are informed in an appropriate manner where this is required.

  20. Contact

    For questions regarding privacy, the processing of personal data and the exercise of rights, the current contact details published on the Oditor AI website are to be used.

    • Controller: "Tsentralna Konsultantska Kompania" EOOD
    • UIC: 204305396
    • Address: Sofia, 12 Byalo Pole
    • Privacy e-mail: office@oditor.ai
  21. Regulatory framework

    The policy is structured in accordance with Regulation (EU) 2016/679 (GDPR), the Bulgarian Personal Data Protection Act (Закон за защита на личните данни) and the applicable rules of Bulgarian law. For specific electronic communications, cookies, marketing and contractual relationships, the relevant special regulatory requirements also apply.