Scope of the Policy
This Privacy Policy explains how personal data is processed when visiting the Oditor AI website, sending an enquiry, requesting a demo, registering and using the platform, communicating with the team, using support and other related services.
The Policy applies to natural persons whose personal data is processed in connection with the website and the services, including representatives, employees and contact persons of business clients.
Who is the data controller
The controller of the personal data processed through the “Oditor AI” website and platform is „Централна Консултантска Компания“ ЕООД (Central Consulting Company EOOD), UIC 204305396, Sofia, 12 Byalo Pole. The controller operates and provides “Oditor AI” and determines the purposes and means of processing personal data.
Contact for questions about personal data: office@oditor.ai. If a data protection officer (DPO) is appointed, their contact details will be published separately.
What categories of personal data we may process
- Identification and contact data: first name and surname, business e-mail, telephone and other data which the individual provides voluntarily.
- Data from the website forms: subject of the enquiry, text of the message, demo request, interest in a plan, package, service or integration.
- User account data: login data, role, access rights, settings and history of actions in the account, where such functionalities are used.
- Business relationship data: information about the organisation, position/role and business correspondence, where necessary for the performance of a contract or for taking steps prior to a contract.
- Technical data: IP address, date and time of access, browser/device type, system and security logs, identifiers and information necessary for the security and the normal operation of the service.
- Support data: content of tickets, correspondence, technical diagnostic data and history of case resolution.
- Payment and invoicing data, where applicable: information necessary for administering payment and for accounting records. Payment card data should not be described as stored by Oditor AI if it is in fact processed directly by a payment provider.
- Data and documents entered into the platform by the client: these may contain personal data. The role of the parties (controller/processor) is determined according to the specific processing and, where necessary, is governed by a personal data processing agreement.
For what purposes and on what legal basis we process the data
Purpose Examples Legal basis Responding to enquiries Contact form, question about price, demo, integration or service Steps prior to a contract; legitimate interest; consent where applicable Registration and provision of the service Account, access, management of subscription and features Performance of a contract Support Tickets, technical cases, communication Performance of a contract and/or legitimate interest Security Logs, access control, prevention of abuse Legitimate interest and legal obligations Invoicing and accounting Payments, accounting documents Performance of a contract and legal obligation Improvement of the service Performance analysis, diagnostics and quality Legitimate interest; consent for technologies where the law requires it Marketing communications News, offers and campaigns Consent or another applicable legal basis; right to object/unsubscribe Legal claims and compliance Protection of rights, inspections and fulfilment of legal requirements Legal obligation and/or legitimate interest Enquiry and demo forms
When you submit a form via the website, we process the data you have entered in order to respond to your request, to arrange a demonstration, to provide pricing information or to take the steps you have requested prior to a possible conclusion of a contract.
The fields in the forms must be limited to what is necessary for the specific purpose. Sensitive personal data, or personal data unrelated to the purpose, must not be requested.
Data processed within the platform itself
Oditor AI may process financial, accounting, documentary and other business data provided by the client. Where such data contains personal data of employees, clients, suppliers, counterparties or other persons, the specific role and responsibility of the parties are determined according to the actual processing.
Where the provider processes such personal data solely on the documented instructions of the business client, a separate personal data processing agreement under Art. 28 GDPR is normally required. It should govern the subject matter, duration, nature and purposes of the processing, the categories of data and of data subjects, the security measures, the sub-processors and the rules upon termination.
AI analyses and automated processing
The platform may use automated methods and artificial intelligence models for analysis, checks, anomaly detection, summaries, alerts, forecasts or support of financial control.
Unless a specific functionality has been expressly designed and legally assessed for this, Oditor AI should not be presented as a system that takes decisions based solely on automated processing producing legal or similarly significant effects for a natural person.
If processing falling within the scope of Art. 22 GDPR is introduced in the future, the policy and the interface must be updated with the necessary information about the logic involved, the significance and the envisaged consequences, as well as the applicable rights of the individual.
Recipients and categories of recipients
Personal data may be disclosed only where this is necessary and subject to appropriate safeguards, including to:
- providers of hosting, cloud infrastructure and data centres;
- providers of e-mail, communication and support/ticketing services;
- providers of analytics and security technologies, where their use is lawful;
- payment and accounting providers, where they are necessary for the specific service;
- providers of AI/technical services, only if they actually take part in the processing and are contractually governed;
- professional advisers, auditors and legal representatives, where necessary;
- competent state and judicial authorities, where disclosure is required by law.
International transfers
If personal data is transferred outside the European Economic Area, the transfer is carried out only where an applicable mechanism and safeguards under the GDPR are in place - for example an adequacy decision, standard contractual clauses or another permissible mechanism.
Upon request, the data subject may obtain information about the applicable safeguards, where this right is applicable.
Retention periods
Personal data is not stored for longer than necessary for the purposes for which it was collected, except where the law requires a longer period.
- Enquiries and correspondence: for the period necessary to process the enquiry and a reasonable subsequent period according to the nature of the relationship.
- Contractual and subscription data: for the term of the contract and, thereafter, for the applicable statutory limitation, accounting and evidentiary periods.
- Accounting and payment documents: for the periods provided for in the applicable accounting and tax legislation.
- Account and technical data: according to what is necessary for the provision of the service, for security and for the contractual relationship.
- Marketing data based on consent: until consent is withdrawn or until the purpose lapses earlier, unless another legal basis exists.
Cookies and similar technologies
The website may use strictly necessary cookies and, where a legal basis/consent exists, analytics, functional or marketing technologies.
Detailed information about the categories of cookies, the providers, the purposes, the periods and the way to manage preferences is to be published in a separate Cookie Policy and in the corresponding consent management mechanism.
Security
Appropriate technical and organisational measures are applied, taking into account the risk, the nature of the data and the service. They may include access control, separation of roles and rights, encryption where applicable, back-ups, logging, incident monitoring, vulnerability management and response procedures.
No information system can be guaranteed to be absolutely secure. In the event of a security breach, the procedures and obligations under the GDPR and the applicable national legislation apply.
Your rights
Under the GDPR, where the statutory preconditions are met, you have the right:
- to information and transparency regarding the processing;
- to access your personal data;
- to rectification of inaccurate or incomplete data;
- to erasure (the “right to be forgotten”), where the preconditions are met;
- to restriction of processing;
- to data portability, where that right is applicable;
- to object to processing based on legitimate interest, and at any time to direct marketing;
- to withdraw consent at any time where the processing is based on consent, without this affecting the lawfulness of the processing carried out beforehand;
- not to be subject to a decision based solely on automated processing, where the conditions of Art. 22 GDPR are met;
- to lodge a complaint with the competent supervisory authority.
How to exercise your rights
A request to exercise rights may be sent via the privacy contact office@oditor.ai or by another means determined by the controller. In order to protect the data, additional information necessary to confirm identity may be requested.
Requests are considered within the time limits provided for by the GDPR. As a rule, information on the action taken is provided without undue delay and within one month of receipt of the request, and where the statutory preconditions exist that period may be extended.
Complaint to the Commission for Personal Data Protection
If you consider that the processing of your personal data infringes Regulation (EU) 2016/679 or the applicable Bulgarian legislation, you have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP) or to seek protection by another procedure provided for by law.
Children's data
Oditor AI is a business/professionally oriented service and is not specifically intended for children. There is no intention to knowingly collect personal data from children through the standard business forms and functionalities.
If a specific future service is directed at children or processes their data, the additional requirements of the GDPR and of national legislation will be applied.
Direct marketing
Where marketing electronic messages are sent, this is done where an applicable legal basis exists. The recipient has an easy way to unsubscribe or to object to direct marketing.
The withdrawal of consent or an objection to direct marketing does not affect the necessary business communication under an existing contract, or relating to security, payment or support.
External links and third-party services
The website may contain links to external services. Their privacy practices are governed by their own policies. Before analytics, advertising, video, chat, social or other external components are added, an assessment must be carried out of the data they receive and of the need for consent.
Changes to the Policy
The Policy may be updated upon a change in the service, the technologies, the providers or the applicable requirements. The current version is published on the website with the date of the last update.
Where the change is substantial and the law or the nature of the processing requires it, the affected individuals are informed in an appropriate manner.
Privacy contact
For questions regarding this Policy, the processing of personal data or the exercise of rights, the official privacy contact should be used: office@oditor.ai.
Do not send, through the general contact form, unnecessary special categories of personal data, identity documents or other sensitive information, unless this is expressly necessary and has been requested through a secure channel.
Legal basis and official sources
The document is structured in accordance with the transparency requirements and the rights of data subjects under Regulation (EU) 2016/679 (GDPR), including Art. 13-22, as well as the applicable Bulgarian framework under the Personal Data Protection Act (Закон за защита на личните данни).
Official sources:
- EUR-Lex – Regulation (EU) 2016/679: https://eur-lex.europa.eu/eli/reg/2016/679
- Commission for Personal Data Protection – https://cpdp.bg/
- Personal Data Protection Act (Закон за защита на личните данни) – published on the official website of the CPDP.
Privacy Policy
This Policy explains how personal data is processed when you visit the Oditor AI website, send an enquiry, register and use the platform.
Last updated: 21.09.2026