
Privacy Notice and Data Processing Terms
Privacy Policy for GESTLABS Bulgaria
Introduction
GESTLABS Bulgaria (website www.gestlabs-bg.com) is committed to protecting the personal data of users of our website and mobile application. This Privacy Policy explains what personal data we collect, why we process it, with whom we share it, and what rights you have. The policy applies to all services provided by GESTLABS Bulgaria, including course registration, payments, communications, and app usage.
What data we collect
Data you provide directly
-
Name; email address; phone number; company information (company name, registration number, address) when registering or requesting a quote.
-
Professional information: job title, certification level, preferred courses, experience and qualifications.
-
Payment and billing data: billing details and identifiers required for invoicing; full card details are not stored if payments are processed by a third party.
-
Communications: correspondence with us via email, phone, or in-app messages.
Technical and automatically collected data
-
Device data: device model, operating system, unique identifiers, language settings.
-
Logs and analytics: IP address, usage data, errors, session duration and feature usage to improve the service.
-
Files and materials: training materials you upload for training purposes, if applicable.
Why we use your data
-
Contract performance: registration and participation in courses, issuing certificates and invoices.
-
Communication: confirmations, reminders, administrative messages and responses to inquiries.
-
Payments and accounting: processing payments, issuing and storing invoices, tax reporting.
-
Service improvement: usage analysis, app optimization and feature development.
-
Security and fraud prevention: protecting systems and users.
-
Legal compliance: fulfilling regulatory and legal obligations.
Legal bases for processing
-
Contract performance: when processing is necessary to provide the requested service.
-
Consent: when processing is based on explicit consent for marketing or specific features.
-
Legal obligation: when we must retain data for accounting or regulatory reasons.
-
Legitimate interest: for protecting our rights, improving services and preventing fraud, balanced against your rights.
Data sharing and third parties
-
Service providers: we use external providers for hosting, payment processing, email services, analytics and support. They access data only as needed and only to perform services.
-
Partners and subcontractors: for corporate training or joint projects we may share limited data with partners who comply with data protection requirements.
-
Legal requests: we may disclose data to comply with legal obligations or to protect our rights and security.
-
No sale of personal data: GESTLABS Bulgaria does not sell personal data to third parties.
Storage and security
-
Retention period: we retain personal data for as long as necessary for the purposes collected, unless law requires a longer retention (e.g., accounting records).
-
Security measures: we implement technical and organizational measures such as encryption in transit, access controls, firewalls and regular backups. Only authorized personnel and providers have access to personal data.
-
Incidents: in case of a security breach we will take necessary steps to mitigate harm and notify affected individuals and authorities when required.
Data subject rights
-
Access: request a copy of your personal data.
-
Rectification: correct inaccurate or incomplete data.
-
Erasure: request deletion of your data under certain conditions.
-
Restriction: request restriction of processing.
-
Objection: object to processing based on legitimate interest or for direct marketing.
-
Portability: receive your data in a structured, commonly used, machine-readable format.
-
Withdraw consent: if processing is based on consent, you may withdraw it at any time without affecting prior processing. To exercise your rights, send a request to gestlabs.bulgaria@gestlabs.it or use the contact form on our website.
Cookies and tracking technologies
-
We use cookies and similar technologies for site functionality, analytics and personalization. You can manage cookie preferences via your browser settings or the site’s cookie mechanism.
Children’s data
-
Our services are not intended for persons under 18 years old. We do not knowingly collect personal data from children under this age. If we become aware that we have collected such data, we will delete it promptly.
Links to third party sites
-
Our website and app may contain links to external sites. GESTLABS Bulgaria is not responsible for the privacy practices of those sites. We recommend reviewing their privacy policies.
Changes to this policy
-
We may update this Privacy Policy as needed. Material changes will be published on www.gestlabs-bg.com and in the app with an effective date.
Contact
GESTLABS Bulgaria Email: gestlabs.bulgaria@gestlabs.it Website: www.gestlabs-bg.com For questions, access requests, corrections or deletion requests, please contact us.
