Privacy Policy
Last updated: 1 August 2026
Version: 2.0
This policy describes how we process your personal data when you use the website dealz.bg, in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR), the Bulgarian Personal Data Protection Act (ЗЗЛД) and the Bulgarian Electronic Commerce Act (ЗЕТ).
1. Controller
Company: „ДР ИТ & Медия" ЕООД (DR IT & Media EOOD)
Company registration number (ЕИК): 206769559
Registered seat and management address: bul. Parva 22, k.k. Sveti Sveti Konstantin i Elena, Primorski District, 9000 Varna, Varna Region, Republic of Bulgaria
Managing director: Dimitri Roschkowski
Telephone: +49 176 81147999
E-mail for data protection enquiries: privacy@dealz.bg
Data protection officer: We have not appointed a data protection officer, as the conditions of Article 37(1) GDPR are not met. Our core activities consist neither of regular and systematic monitoring of data subjects on a large scale nor of large-scale processing of special categories of personal data. Please address data protection enquiries to the address stated above.
The controller is established in the Republic of Bulgaria. Processing is governed by Regulation (EU) 2016/679 on the basis of its Article 3(1).
2. General principles
We process personal data only where a legal basis under Article 6(1) GDPR exists, only for the purposes set out below, and only to the extent necessary for those purposes (Article 5(1)(c) GDPR — data minimisation).
We do not process special categories of personal data under Article 9 GDPR — health data, ethnic origin, political opinions, religious beliefs, sex life and others — and we do not ask you to provide them.
We do not carry out automated decision-making, including profiling, producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR. Price alerts are triggered by a threshold you set yourself and do not constitute such a decision.
We do not sell personal data to third parties.
Browsing leaflets, prices and products is possible without registration.
3. Processing operations in detail
3.1 Visiting the website — server logs
Data: IP address, date and time of the request, requested URL, HTTP status, volume of data transferred, referrer URL, browser type and version, operating system, browser language.
Purpose: provision and stability of the service, detection and correction of technical faults, protection against abuse and attacks, rate limiting.
Legal basis: Article 6(1)(f) GDPR — legitimate interest in a secure and functioning service.
Retention period: 14 days.
Recipients: Cloudflare (content delivery network and protection), server infrastructure provider with data centres in Germany.
3.2 User account
Data: name, e-mail address, password (stored solely as a cryptographic hash using bcrypt — the plaintext password is not known to us), e-mail confirmation status, preferred language, user role, registration date, session data (session identifier, IP address, device and browser type, timestamp).
Purpose: creation and administration of the account, sign-in, maintaining the session, account recovery, separation of permissions in the user area and the business portal.
Legal basis: Article 6(1)(b) GDPR — performance of the terms of use. As regards the storage of IP address and device data in sessions: Article 6(1)(f) GDPR — legitimate interest in detecting unauthorised access.
Retention period: until you delete your account. Sessions expire automatically — the access token after 15 minutes, the refresh token after 7 days.
3.3 Two-factor authentication, recovery codes and passkeys
Data: one-time password secret (TOTP), recovery codes, public keys and identifiers of registered passkeys (WebAuthn), device name and date added.
Purpose: protection of the account against unauthorised access.
Legal basis: Article 6(1)(b) GDPR — a function requested by you, in conjunction with Article 32 GDPR on security of processing.
Retention period: until you deactivate the respective method or delete your account.
3.4 Newsletter
Data: e-mail address, date and time of sign-up, IP address at sign-up, date and time of confirmation, subscription status, preferred language.
Purpose: sending a regular newsletter with new leaflets, offers and content.
Legal basis: Article 6(1)(a) GDPR — your consent given via a double opt-in procedure, in conjunction with Article 6(4) ЗЕТ. The logging of sign-up and confirmation is based on Article 6(1)(c) GDPR in order to meet the burden of proof under Article 7(1) GDPR.
Retention period: until you withdraw your consent. Unconfirmed sign-ups are deleted after 30 days. Following an unsubscribe, we keep your address on a suppression list so that you are not contacted again by mistake; this entry remains until you expressly request its deletion.
Withdrawal: at any time via the unsubscribe link in every newsletter or by message to privacy@dealz.bg. Withdrawal does not affect the lawfulness of processing carried out beforehand (Article 7(3) GDPR).
3.5 Wishlists and price alerts
Data: user identifier, product and merchant identifiers, price threshold set, creation date, history of notifications sent.
Purpose: saving selected products and notifying you of price drops.
Legal basis: Article 6(1)(b) GDPR — provision of a service requested by you.
Retention period: until you delete them or delete your account.
3.6 Browser push notifications
Data: endpoint URL of the push service, public cryptographic keys of the subscription, browser and device type.
Purpose: notifying you of price drops and new leaflets directly in your browser.
Legal basis: Article 6(1)(a) GDPR — your explicit consent given via the browser permission, in conjunction with Article 4a ЗЕТ on access to information on a terminal device.
Recipients: delivery takes place via the push service of the respective browser vendor — Google, Mozilla, Apple or Microsoft. The content of the messages is encrypted (VAPID).
Retention period: until you withdraw the browser permission or deactivate notifications in your account. Invalid subscriptions are removed automatically.
Withdrawal: via your browser settings or in the "Notifications" section of your account.
3.7 Internal view counting
Data: number of views of a product, merchant or leaflet per day. No IP addresses and no user or device identifiers are stored — only an aggregated numeric counter per object and date exists.
Purpose: identifying popular content, internal planning and prioritisation.
Legal basis: as the data is fully aggregated and does not permit identification of a natural person, this counting does not fall within the scope of the GDPR. We list it here for the sake of transparency.
3.8 Click tracking on redirects to merchants
Data: identifier of the offer, product and merchant; user identifier if you are signed in; referrer URL; browser identifier; truncated cryptographic hash of the IP address (SHA-256, truncated); timestamp.
Purpose: measuring referrals to merchants, accounting for affiliate commissions, detecting automated and repeated clicks, statistics for business partners.
Legal basis: Article 6(1)(f) GDPR — legitimate interest in performance measurement, correct accounting and protection against abuse.
Note: the IP hash is pseudonymised but still personal information within the meaning of Recital 26 GDPR, since it is theoretically attributable to you. We therefore treat it as personal data and grant you all the rights set out in section 8 in respect of it.
Retention period: 12 months; thereafter only the aggregated statistics remain, without any link to individual records. Short-term counters in the cache are deleted after 48 hours, and duplicate-click detection entries after 30 seconds.
Right to object: you may object to this processing at any time pursuant to Article 21(1) GDPR.
3.9 Blog comments
Data: name or username, comment content, timestamp, user identifier, IP address.
Purpose: publication of the comment, moderation, prevention of spam and abuse, compliance with our obligations under Regulation (EU) 2022/2065.
Legal basis: Article 6(1)(b) GDPR for publication; Article 6(1)(f) GDPR for moderation and storage of the IP address.
Note: published comments are visible to all visitors and may be indexed by search engines. Please do not disclose personal data in comments that you do not wish to be publicly accessible.
Retention period: until the comment is deleted by you or by us, or until your account is deleted.
3.10 Business portal for merchants
Data: contact details of contact persons at the merchant (name, business e-mail address, telephone, function), company data, API access keys, uploaded files and usage statistics.
Purpose: performance of the contractual relationship with business partners.
Legal basis: Article 6(1)(b) GDPR; as regards the partner's employees, Article 6(1)(f) GDPR.
Retention period: for the duration of the contractual relationship plus the statutory retention periods under the Bulgarian Accountancy Act and tax legislation.
3.11 Enquiries, reports and support
Data: name, e-mail address, content of the enquiry, IP address, browser identifier, user identifier if you are signed in, and the correspondence on the matter.
Purpose: handling and tracking the enquiry.
Legal basis: Article 6(1)(b) GDPR for contract-related enquiries, otherwise Article 6(1)(f) GDPR.
Retention period: 24 months after the matter is closed.
3.12 Administrative audit log
Data: user identifier, action performed, object affected, timestamp.
Purpose: traceability of administrative changes, investigation of security incidents, compliance with the accountability principle.
Legal basis: Article 6(1)(f) GDPR in conjunction with Article 5(2) and Article 32 GDPR.
Retention period: 24 months.
4. Cookies and similar technologies
We use cookies and similar technologies to store information on your terminal device. The legal basis is Article 4a ЗЕТ in conjunction with Article 5(3) of Directive 2002/58/EC and Article 6(1)(a) GDPR.
4.1 Technologies not requiring consent
These are technically necessary for a service expressly requested by you (Article 4a(4)(2) ЗЕТ):
| Name | Purpose | Duration |
|---|---|---|
| Session and authentication cookies | maintaining your sign-in | access token 15 minutes; refresh token 7 days |
i18n_locale |
stores the language you have chosen; set only when you change the language yourself | 365 days |
cookie_consent (in the browser's local storage) |
documents your cookie decision | until browser data is cleared |
4.2 Technologies used only after your consent
| Name | Provider | Purpose | Duration |
|---|---|---|---|
dealz_visits |
dealz.bg | recognition of returning visitors and visit counter | 30 days |
_ga, _ga_* |
audience measurement (Google Analytics 4) | up to 2 years | |
| Advertising cookies | delivery and measurement of advertisements (Google AdSense) | in accordance with Google's policy |
4.3 Managing your consent
On your first visit, a notice appears with two buttons — "Accept" and "Reject". It covers the statistics and advertising technologies under section 4.2 together. If you choose "Reject", they are not activated and no data is transmitted to Google. Your decision is stored in your browser's local storage.
Withdrawing consent: You can withdraw consent already given by clearing the site data in your browser settings — this removes the cookie_consent entry, and you will be offered the choice again on your next visit. You may also send us a message at privacy@dealz.bg and we will act on your request. Withdrawal does not affect the lawfulness of processing carried out beforehand.
5. External service providers and recipients
5.1 Processors
These providers act solely on our instructions on the basis of a contract under Article 28 GDPR:
| Provider | Function | Place of processing |
|---|---|---|
| Cloudflare | content delivery network, reverse proxy, attack protection, DNS | global network, including the USA |
| Amazon Web Services | storage of leaflet images and PDF files (Amazon S3) | region eu-central-1, Frankfurt, Germany |
| Server infrastructure provider | hosting of application, database and cache servers | data centres in Germany |
| Google Ireland Limited | audience measurement (Google Analytics 4) | European Union, with Google's global infrastructure |
5.2 Independent controllers
| Provider | Function | Note |
|---|---|---|
| Google Ireland Limited and Google LLC | Google AdSense | Google acts as an independent controller for its own purposes. Details: https://policies.google.com/privacy and https://policies.google.com/technologies/partner-sites |
| Merchants and affiliate networks | partner links | When you click a merchant link, you leave dealz.bg. From that point onwards, the privacy policy of the respective merchant or network applies. |
| Google, Mozilla, Apple, Microsoft | delivery of push messages | only if you have activated notifications |
5.3 Own infrastructure
E-mails — confirmations, price alerts and the newsletter — are sent via our own mail server. The content is not passed to an external marketing service provider.
5.4 Use of artificial intelligence
For the automated recognition of products, prices and text from the images of advertising leaflets, as well as for translation and preparation of editorial content, we use the OpenRouter service and the language models available through it, including models from Google, Anthropic and OpenAI.
Only the content of publicly available advertising leaflets and editorial texts is processed. Personal data of dealz.bg users is not transmitted to these services. We state this for full transparency about how the content of this website is produced.
6. Transfers to third countries
Cloudflare and Google also process data outside the European Economic Area, including in the United States. The legal basis is:
- for transfers to companies certified under the EU-US Data Privacy Framework, the European Commission's adequacy decision of 10 July 2023 pursuant to Article 45 GDPR;
- additionally and in the alternative, standard contractual clauses pursuant to Article 46(2)(c) GDPR (Implementing Decision (EU) 2021/914), together with supplementary technical and organisational measures.
Despite these safeguards, it cannot be entirely ruled out that access by US public authorities may not in every case correspond to European standards. If you do not wish this, decline your consent to the statistics and advertising technologies under section 4.2 — the functioning of the website does not depend on them.
Beyond the above, we do not transfer personal data to third countries. The controller is established in the Republic of Bulgaria and all principal servers are located within the territory of the European Union.
7. Data security
We take appropriate technical and organisational measures pursuant to Article 32 GDPR, in particular:
- encryption of all traffic via TLS (HTTPS);
- storage of passwords solely as a cryptographic hash (bcrypt with 12 rounds) — the plaintext password is not stored;
- optional two-factor authentication and passkey support;
- rate limiting for sign-in, registration and password recovery;
- role-based separation of permissions — user, business, staff and administrator;
- logging of administrative actions;
- regular updating of the software used.
No system is absolutely secure. In the event of a personal data breach, we will notify the КЗЛД within the period laid down in Article 33 GDPR and, where there is a high risk to you, we will also notify you in accordance with Article 34 GDPR.
8. Your rights
Under Regulation (EU) 2016/679 you have the following rights:
| Right | Provision | Content |
|---|---|---|
| Access | Art. 15 | confirmation as to whether we process your data, a copy of that data and information about the processing |
| Rectification | Art. 16 | correction of inaccurate and completion of incomplete data |
| Erasure | Art. 17 | erasure of data where it is no longer necessary, where you withdraw consent or where you object on legitimate grounds |
| Restriction | Art. 18 | temporary restriction of processing, for example while the accuracy of the data is verified |
| Data portability | Art. 20 | receipt of the data you provided in a structured, commonly used and machine-readable format, and transmission to another controller |
| Objection | Art. 21 | objection to processing based on legitimate interests. Where you object to direct marketing, we cease processing immediately and unconditionally. |
| Automated decisions | Art. 22 | not applicable — we do not carry out such processing |
| Withdrawal of consent | Art. 7(3) | withdrawal at any time with effect for the future |
Exercising your rights. Pursuant to Article 37b(3) ЗЗЛД, a request may also be submitted through the user interface once you have identified yourself. To do so, use the "Download my data" and "Delete account" functions in the "Profile" section of your account. Alternatively, send your request to privacy@dealz.bg or to the postal address in section 1.
We respond without undue delay and in any event within one month of receipt of the request. Where requests are complex or numerous, the period may be extended by a further two months, of which we will inform you (Article 12(3) GDPR). Exercising your rights is free of charge; where requests are manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act (Article 12(5) GDPR).
9. Right to lodge a complaint with a supervisory authority
You have the right under Article 77 GDPR to lodge a complaint with a supervisory authority if you consider that the processing of your personal data infringes Regulation (EU) 2016/679.
Commission for Personal Data Protection (Комисия за защита на личните данни, КЗЛД)
bul. „Prof. Tsvetan Lazarov" 2, 1592 Sofia, Bulgaria
Telephone: +359 2 915 3 518
E-mail: kzld@cpdp.bg
Website: https://cpdp.bg
Pursuant to Article 38(1) ЗЗЛД, a complaint must be lodged within one year of becoming aware of the infringement, but no later than five years after it was committed. The Commission informs you of the progress or outcome within three months (Article 38(2) ЗЗЛД).
Independently of this, you may seek judicial protection before the competent administrative court (Article 39(1) ЗЗЛД) and claim compensation for damage suffered (Article 82 GDPR and Article 39(2) ЗЗЛД). Please note that under Article 39(4) ЗЗЛД you may not bring the same matter before a court while proceedings on it are pending before the КЗЛД.
If you reside in another Member State of the European Union, you may also lodge a complaint with the supervisory authority of your habitual residence or place of work.
10. Children
The services of dealz.bg are not directed at children.
Pursuant to Article 25c ЗЗЛД, in the case of the direct offering of information society services, the processing of personal data of a person under the age of 14 on the basis of consent is lawful only if consent is given by the parent exercising parental rights or by the guardian or custodian of that person.
We do not knowingly create accounts for persons under 14. If we become aware that data of a child below this age has been provided to us without the necessary consent, we will delete it without delay. If you are a parent or guardian and believe that a child has provided us with data, please contact us at privacy@dealz.bg.
11. Whether provision of data is required
The provision of personal data is neither a statutory nor a contractual requirement. However, without certain data we cannot provide the respective service: without an e-mail address, registration and newsletter subscription are not possible, and without session data, signing in is not possible. Browsing leaflets, prices and products is possible without registration.
12. Changes to this policy
We update this policy when our services or the legal framework change. The version published here applies in each case. In the case of material changes affecting consent-based processing, we will inform you in advance and, where necessary, obtain fresh consent.
13. Authoritative language version
This text was drawn up in Bulgarian. The German, English and Russian translations are provided for information purposes only. In the event of discrepancies in content or interpretation, the Bulgarian version prevails.