Skip to content
Oditor AI

Privacy Policy

This Policy explains how personal data is processed when you visit the Oditor AI website, send an enquiry, register and use the platform.

Last updated: 21.09.2026

  1. Scope of the Policy

    This Privacy Policy explains how personal data is processed when visiting the Oditor AI website, sending an enquiry, requesting a demo, registering and using the platform, communicating with the team, using support and other related services.

    The Policy applies to natural persons whose personal data is processed in connection with the website and the services, including representatives, employees and contact persons of business clients.

  2. Who is the data controller

    The controller of the personal data processed through the “Oditor AI” website and platform is „Централна Консултантска Компания“ ЕООД (Central Consulting Company EOOD), UIC 204305396, Sofia, 12 Byalo Pole. The controller operates and provides “Oditor AI” and determines the purposes and means of processing personal data.

    Contact for questions about personal data: office@oditor.ai. If a data protection officer (DPO) is appointed, their contact details will be published separately.

  3. What categories of personal data we may process

    • Identification and contact data: first name and surname, business e-mail, telephone and other data which the individual provides voluntarily.
    • Data from the website forms: subject of the enquiry, text of the message, demo request, interest in a plan, package, service or integration.
    • User account data: login data, role, access rights, settings and history of actions in the account, where such functionalities are used.
    • Business relationship data: information about the organisation, position/role and business correspondence, where necessary for the performance of a contract or for taking steps prior to a contract.
    • Technical data: IP address, date and time of access, browser/device type, system and security logs, identifiers and information necessary for the security and the normal operation of the service.
    • Support data: content of tickets, correspondence, technical diagnostic data and history of case resolution.
    • Payment and invoicing data, where applicable: information necessary for administering payment and for accounting records. Payment card data should not be described as stored by Oditor AI if it is in fact processed directly by a payment provider.
    • Data and documents entered into the platform by the client: these may contain personal data. The role of the parties (controller/processor) is determined according to the specific processing and, where necessary, is governed by a personal data processing agreement.
  4. For what purposes and on what legal basis we process the data

    PurposeExamplesLegal basis
    Responding to enquiriesContact form, question about price, demo, integration or serviceSteps prior to a contract; legitimate interest; consent where applicable
    Registration and provision of the serviceAccount, access, management of subscription and featuresPerformance of a contract
    SupportTickets, technical cases, communicationPerformance of a contract and/or legitimate interest
    SecurityLogs, access control, prevention of abuseLegitimate interest and legal obligations
    Invoicing and accountingPayments, accounting documentsPerformance of a contract and legal obligation
    Improvement of the servicePerformance analysis, diagnostics and qualityLegitimate interest; consent for technologies where the law requires it
    Marketing communicationsNews, offers and campaignsConsent or another applicable legal basis; right to object/unsubscribe
    Legal claims and complianceProtection of rights, inspections and fulfilment of legal requirementsLegal obligation and/or legitimate interest
  5. Enquiry and demo forms

    When you submit a form via the website, we process the data you have entered in order to respond to your request, to arrange a demonstration, to provide pricing information or to take the steps you have requested prior to a possible conclusion of a contract.

    The fields in the forms must be limited to what is necessary for the specific purpose. Sensitive personal data, or personal data unrelated to the purpose, must not be requested.

  6. Data processed within the platform itself

    Oditor AI may process financial, accounting, documentary and other business data provided by the client. Where such data contains personal data of employees, clients, suppliers, counterparties or other persons, the specific role and responsibility of the parties are determined according to the actual processing.

    Where the provider processes such personal data solely on the documented instructions of the business client, a separate personal data processing agreement under Art. 28 GDPR is normally required. It should govern the subject matter, duration, nature and purposes of the processing, the categories of data and of data subjects, the security measures, the sub-processors and the rules upon termination.

  7. AI analyses and automated processing

    The platform may use automated methods and artificial intelligence models for analysis, checks, anomaly detection, summaries, alerts, forecasts or support of financial control.

    Unless a specific functionality has been expressly designed and legally assessed for this, Oditor AI should not be presented as a system that takes decisions based solely on automated processing producing legal or similarly significant effects for a natural person.

    If processing falling within the scope of Art. 22 GDPR is introduced in the future, the policy and the interface must be updated with the necessary information about the logic involved, the significance and the envisaged consequences, as well as the applicable rights of the individual.

  8. Recipients and categories of recipients

    Personal data may be disclosed only where this is necessary and subject to appropriate safeguards, including to:

    • providers of hosting, cloud infrastructure and data centres;
    • providers of e-mail, communication and support/ticketing services;
    • providers of analytics and security technologies, where their use is lawful;
    • payment and accounting providers, where they are necessary for the specific service;
    • providers of AI/technical services, only if they actually take part in the processing and are contractually governed;
    • professional advisers, auditors and legal representatives, where necessary;
    • competent state and judicial authorities, where disclosure is required by law.
  9. International transfers

    If personal data is transferred outside the European Economic Area, the transfer is carried out only where an applicable mechanism and safeguards under the GDPR are in place - for example an adequacy decision, standard contractual clauses or another permissible mechanism.

    Upon request, the data subject may obtain information about the applicable safeguards, where this right is applicable.

  10. Retention periods

    Personal data is not stored for longer than necessary for the purposes for which it was collected, except where the law requires a longer period.

    • Enquiries and correspondence: for the period necessary to process the enquiry and a reasonable subsequent period according to the nature of the relationship.
    • Contractual and subscription data: for the term of the contract and, thereafter, for the applicable statutory limitation, accounting and evidentiary periods.
    • Accounting and payment documents: for the periods provided for in the applicable accounting and tax legislation.
    • Account and technical data: according to what is necessary for the provision of the service, for security and for the contractual relationship.
    • Marketing data based on consent: until consent is withdrawn or until the purpose lapses earlier, unless another legal basis exists.
  11. Cookies and similar technologies

    The website may use strictly necessary cookies and, where a legal basis/consent exists, analytics, functional or marketing technologies.

    Detailed information about the categories of cookies, the providers, the purposes, the periods and the way to manage preferences is to be published in a separate Cookie Policy and in the corresponding consent management mechanism.

  12. Security

    Appropriate technical and organisational measures are applied, taking into account the risk, the nature of the data and the service. They may include access control, separation of roles and rights, encryption where applicable, back-ups, logging, incident monitoring, vulnerability management and response procedures.

    No information system can be guaranteed to be absolutely secure. In the event of a security breach, the procedures and obligations under the GDPR and the applicable national legislation apply.

  13. Your rights

    Under the GDPR, where the statutory preconditions are met, you have the right:

    • to information and transparency regarding the processing;
    • to access your personal data;
    • to rectification of inaccurate or incomplete data;
    • to erasure (the “right to be forgotten”), where the preconditions are met;
    • to restriction of processing;
    • to data portability, where that right is applicable;
    • to object to processing based on legitimate interest, and at any time to direct marketing;
    • to withdraw consent at any time where the processing is based on consent, without this affecting the lawfulness of the processing carried out beforehand;
    • not to be subject to a decision based solely on automated processing, where the conditions of Art. 22 GDPR are met;
    • to lodge a complaint with the competent supervisory authority.
  14. How to exercise your rights

    A request to exercise rights may be sent via the privacy contact office@oditor.ai or by another means determined by the controller. In order to protect the data, additional information necessary to confirm identity may be requested.

    Requests are considered within the time limits provided for by the GDPR. As a rule, information on the action taken is provided without undue delay and within one month of receipt of the request, and where the statutory preconditions exist that period may be extended.

  15. Complaint to the Commission for Personal Data Protection

    If you consider that the processing of your personal data infringes Regulation (EU) 2016/679 or the applicable Bulgarian legislation, you have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP) or to seek protection by another procedure provided for by law.

  16. Children's data

    Oditor AI is a business/professionally oriented service and is not specifically intended for children. There is no intention to knowingly collect personal data from children through the standard business forms and functionalities.

    If a specific future service is directed at children or processes their data, the additional requirements of the GDPR and of national legislation will be applied.

  17. Direct marketing

    Where marketing electronic messages are sent, this is done where an applicable legal basis exists. The recipient has an easy way to unsubscribe or to object to direct marketing.

    The withdrawal of consent or an objection to direct marketing does not affect the necessary business communication under an existing contract, or relating to security, payment or support.

  18. External links and third-party services

    The website may contain links to external services. Their privacy practices are governed by their own policies. Before analytics, advertising, video, chat, social or other external components are added, an assessment must be carried out of the data they receive and of the need for consent.

  19. Changes to the Policy

    The Policy may be updated upon a change in the service, the technologies, the providers or the applicable requirements. The current version is published on the website with the date of the last update.

    Where the change is substantial and the law or the nature of the processing requires it, the affected individuals are informed in an appropriate manner.

  20. Privacy contact

    For questions regarding this Policy, the processing of personal data or the exercise of rights, the official privacy contact should be used: office@oditor.ai.

    Do not send, through the general contact form, unnecessary special categories of personal data, identity documents or other sensitive information, unless this is expressly necessary and has been requested through a secure channel.

  21. Legal basis and official sources

    The document is structured in accordance with the transparency requirements and the rights of data subjects under Regulation (EU) 2016/679 (GDPR), including Art. 13-22, as well as the applicable Bulgarian framework under the Personal Data Protection Act (Закон за защита на личните данни).

    Official sources:

    • EUR-Lex – Regulation (EU) 2016/679: https://eur-lex.europa.eu/eli/reg/2016/679
    • Commission for Personal Data Protection – https://cpdp.bg/
    • Personal Data Protection Act (Закон за защита на личните данни) – published on the official website of the CPDP.