PERSONAL DATA PROTECTION POLICY

"GROCERY RADAR" EOOD

 

POLICY AT A GLANCE

 

 

 

Who processes your data?
"GROCERY RADAR" EOOD, UIC 208655981
Yambol, Georgi Benkovski 2 Residential Complex, fl. 11, apt. 43

Why do we collect data?
Providing software services, contractual relations, accounting, communication

What data do we collect?
Names, contact details, financial information (business partners and employees only), as well as certain categories of anonymous user data (location
)

Legal basis for processing:
Performance of a contract, legal obligation, legitimate interest

How long do we keep the data?
3–50 years depending on the category (pursuant to the Accountancy Act and the Tax and Social Insurance Procedure Code)

Your rights:
Access, rectification, erasure, objection, complaint to the CPDP

Contact:
Email
for contacting the company: contact@groceryradar.com

CPDP: kzld@cpdp.bg | www.cpdp.bg


 

FULL VERSION OF THE POLICY

With this Personal Data Protection Policy (hereinafter the "Policy"), we would like to explain in a clear and accessible manner how "GROCERY RADAR" EOOD, UIC 208655981 (hereinafter the "Company") collects, processes, and stores your personal data when you apply for and/or commence employment with the Company, enter into contracts with the Company, use the Company's services, use the Company's price-comparison mobile application, visit the Company's website, and/or visit the Company's premises.

The Company complies with all requirements of the General Data Protection Regulation ("GDPR", "Regulation (EU) 2016/679"), the Bulgarian Personal Data Protection Act ("PDPA"), and all applicable Bulgarian legislation in the collection, processing, and storage of your personal data.

Important note: The Company's price-comparison mobile application does not collect, process, or store users' personal data. The application operates with a registration that does not require providing personal information. The application only uses Google/Apple identifiers for push notifications when the user expressly consents to this. If the user provides their name, personal identification number, or other personal data when registering in the application, these rules apply.

§ 1. What is important to know about this Policy?

This Policy has been adopted and approved by the Company.

As a person who is a party to or intends to enter into a relationship of any kind with the Company, it is your obligation to familiarise yourself with this Privacy Policy, as it contains information about the Company's obligations and your rights in relation to the collection, processing, and storage of your personal data, in accordance with the principles laid down in Article 5 of the GDPR.

Acceptance of this Policy is a precondition for entering into and maintaining any legal relationship with the Company. If you do not accept this Policy, you will not be able to enter into a legal relationship with and/or use the services of the Company.

If you have any questions or need additional information, you can always contact us using the contact details provided at the end of this Policy.

Business Model and GDPR Roles

Grocery Radar is a mobile application and web platform for comparing grocery prices across different retail chains. We monetise our services through advertisements via Google AdMob.

§ 2. Who is responsible for your data?

The controller of your personal data is "GROCERY RADAR" EOOD, a sole-owner limited liability company, established and existing under the laws of the Republic of Bulgaria, registered in the Commercial Register under UIC 208655981, with its registered office and management address at Yambol District, Yambol Municipality, Yambol, postal code 8600, Georgi Benkovski 2 Residential Complex, fl. 11, apt. 43.

The General Manager of the Company is Kaloyan Svetlozarov Valchev.

You may contact the Company's designated Data Protection Officer at the email address contact@groceryradar.com or at the registered management address stated above.

§ 3. Definitions

The terms used in this Policy have the following meanings:

Personal Data – any information relating to an identified or identifiable natural person ("data subject"); an identifiable person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, identification number, location data, an online identifier, or by reference to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.

Processing of Personal Data – any operation or set of operations performed on personal data, whether by automated or other means, such as collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

Data Subject – the natural person whose personal data are being processed.

Data Controller – a natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

Data Processor – a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.

Personal Data Recipient – a natural or legal person, public authority, agency, or other body to which personal data are disclosed, whether a third party or not.

Third Party – a natural or legal person, public authority, agency, or other body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

Consent of the Data Subject – any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

Personal Data Breach – a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed.

Special Categories of Personal Data (Sensitive Data) – data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data, health data, data concerning a person's sex life or sexual orientation.

Profiling – any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person.

Pseudonymisation – the processing of personal data in such a manner that the data can no longer be attributed to a specific individual without the use of additional information, which is kept separately.

Restriction of Processing – the marking of stored personal data with the aim of limiting their processing in the future.

§ 4. What data do we collect and why?

The Company adheres to the principle of processing only the minimum personal data necessary for the purposes of processing. The Company processes only those personal data that are necessary to provide you with quality services and to comply with our legal obligations.

The data we collect, process, and store may include:

      Your name, personal identification number (EGN, ЕГН) or foreigner personal number (LNCh, ЛНЧ), date of birth, and gender, if you have provided these to the Company;

      Contact information such as address, telephone number, email, and social media profiles, if you have provided these to the Company;

      Financial information necessary for issuing invoices and making payments to suppliers, employees, and clients;

      Data related to employee management and/or recruitment processes – training completed, tests, interview data, internal employee performance review meetings, and similar;

      Information from communications with us – for example, if you send us an email or call us by telephone;

      Data collected when you use our website, such as IP addresses, logs, information about your browser, operating system, device, and manner of use of the site (Articles 4(1) and 6 of the GDPR);

      Push notifications (if you have subscribed) – device token and anonymous identifier for delivering notifications via Apple Push Notification Service or Firebase Cloud Messaging;

      Anonymous data about mobile application usage – application version, device, operating system (without personally identifying information);

      Data related to the use of the Company's software products and services – registration information, user preferences, feature usage data, technical logs;

      Intellectual property data – information related to intellectual property transactions, copyrights, licences, and other rights;

§ 5. How we collect your data

In most cases, you provide data to us yourself – when you use our services, apply for a job, communicate with us, subscribe to our newsletter, visit our website or mobile application, provide us with financial information, or similar.

Sometimes we receive information and personal data automatically, for example when you visit our website or use the Grocery Radar mobile application (logs, technical data).

Data collected automatically when visiting the website:

      Device IP address

      Browser type and version

      Operating system

      Referring URL (where you came from to reach the site)

      Date and time of access

      Pages visited and duration of the visit

      Interactions with site elements

Data from the mobile application:

The mobile application does not collect personal data. The only technical data processed automatically are:

      Anonymous device identifier (Device ID) – only for push notifications with explicit consent

      Application version and operating system – for technical purposes

      Anonymous usage statistics – for improving functionality

      Advertising identifiers (IDFA for iOS, AAID for Android) – for personalised Google AdMob advertisements, only with explicit consent via CMP. Retention: up to 90 days or withdrawal.

      Location data: IP address (approximate location by region), GPS coordinates (precise location) – only with explicit consent for Google Maps features such as „stores nearby“. Retention: session or up to 30 days caching.

This data cannot identify you as a natural person.

In carrying out the described activities for the collection and processing of your personal data, the Company observes the principles set out in Article 5 of the GDPR, and in particular the principles of purpose limitation within the meaning of Article 5(1)(b) of the GDPR and data minimisation under Article 5(1)(c) of the GDPR.

3.5. Data processing through the mobile application

Grocery Radar processes additional data when using the iOS/Android applications: push device tokens (Apple Push Notification Service / Firebase Cloud Messaging), unique device ID (IDFA/AAID), app version, OS version, crash logs and session duration, Google Maps Platform, Google AdMob.

Purposes: personalised price alerts, functionality improvement (A/B tests for price filters), crash analysis.

Legal basis: Article 6(1)(b) and (f) GDPR. Retention period: 12 months for device tokens, 30 days for crash logs.

Users can manage push notifications from device settings (iOS: Settings > Notifications; Android: Settings > Apps > Notifications).

§ 6. For what purposes do we process your data

The Company processes your personal data only for specific, explicitly defined, and legitimate purposes, in accordance with the purpose limitation principle (Article 5(1)(b) GDPR), as follows:

Processing Purpose

Data Categories

Legal Basis

Providing software products, systems, and applications (development, implementation, maintenance)

Name, contact details, registration data, software usage data, location data

Performance of a contract (Art. 6(1)(b))

Creating and maintaining databases

Technical data, access data, logs

Performance of a contract (Art. 6(1)(b)), Legitimate interest (Art. 6(1)(f))

Communication and administration (enquiries, support, answering questions)

Name, telephone, email, communication history

Legitimate interest (Art. 6(1)(f)), Performance of a contract (Art. 6(1)(b))

Compliance with legal obligations (accounting, tax returns)

Name, personal identification number, financial information

Legal obligation (Art. 6(1)(c))

Marketing and service improvement (sending promotions, surveys, traffic analysis)

Name, email, website usage data (cookies)

Consent (Art. 6(1)(a)), Legitimate interest (Art. 6(1)(f))

Push notifications and personalised recommendations (with explicit consent)

Device token, anonymous identifier, preferences

Consent (Art. 6(1)(a))

Human resources management (hiring, employee evaluation, salary payments)

CVs, diplomas, employment contracts, salary, interview data, internal test data

Performance of a contract (Art. 6(1)(b)), Legal obligation (Art. 6(1)(c))

Advertising, marketing, and informational activities

Name, email, preferences, behavioural data

Consent (Art. 6(1)(a))

Intellectual property transactions

Name, contact details, contractual information, copyrights

Performance of a contract (Art. 6(1)(b))

Profiling for service improvement

Aggregated searched products, preferred retailers, frequently filtered prices

Legitimate interest (Art. 6(1)(f))

Monetisation via Google AdMob

Advertising ID (IDFA/AAID), IP, device info, location (with consent)

Consent Art. 6(1)(a) for personalised; Legitimate interest Art. 6(1)(f) for non-personalised

Maps and navigation (Google Maps Platform)

IP address, GPS coordinates (with consent), searched addresses

Legitimate interest Art. 6(1)(f) for basic maps; Consent Art. 6(1)(a) for GPS (precise location)

 

Note on profiling: Profiling for service improvement involves aggregating searched products, preferred retailers, and frequently filtered prices (low/high) to personalise offer lists and recommendations. This does not result in automated decisions with legal effects (Article 22 GDPR). Legal basis: Article 6(1)(f) GDPR (legitimate interest in service optimisation).

§ 7. On what basis do we process your data

The processing of your personal data is carried out only when one of the legal bases explicitly provided for in Article 6 of the GDPR applies. For each specific processing operation, only one valid legal basis applies, and no duplication or overlap of legal bases for the same activity is permitted.

Depending on the specific situation, processing may be based on any of the following alternative and equal legal bases:

      Consent – Where you have given your free, specific, informed, and unambiguous consent to the processing of your personal data for one or more specific purposes (Article 6(1)(a) GDPR). Consent may be withdrawn at any time without affecting the lawfulness of processing carried out prior to the withdrawal.

      Performance of a contract – Where processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract (Article 6(1)(b) GDPR).

      Compliance with a legal obligation – Where processing is necessary for compliance with a legal obligation to which the Company, as data controller, is subject (Article 6(1)(c) GDPR). This includes obligations arising from national or European law, such as accounting, tax, or employment obligations.

      Protection of vital interests – Where processing is necessary in order to protect the vital interests of you or of another natural person, for example in an emergency situation (Article 6(1)(d) GDPR).

      Performance of a task carried out in the public interest or in the exercise of official authority – where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Company, as controller, pursuant to European Union and Republic of Bulgaria law (Article 6(1)(e) GDPR).

      Legitimate interest – where processing is necessary for the purposes of the legitimate interests pursued by the Company (Article 6(1)(f) GDPR), as follows:

 

 

Legitimate Interest Category

Explanation

Fraud and crime prevention

Processing data for the prevention, investigation, and reporting of fraud, abuse, or criminal activity.

Network and information security

Protecting IT systems, preventing unauthorised access, cyberattacks, and security breaches.

Direct marketing

Sending marketing communications to existing clients (with the right to object/opt out).

Internal administrative purposes

Employee management, payroll processing, internal audit.

Improving services and products

Analysis of client behaviour, satisfaction surveys, process and quality optimisation.

Protection of legal claims

Storage and use of data for establishing, exercising, or defending legal rights and interests.

Public access to information

Maintaining public registers or providing information for public purposes, where justified.

 

 

Data subjects have the right to object to data processing on this basis. When processing on this basis, the Company carries out a balancing test between its interest and the interest of the data subject. If the conclusion is that the Company's interest overrides that of the data subject, the objection is rejected. If the conclusion is that the data subject's interest overrides, processing ceases immediately and the data are deleted.

 

§ 8. How long do we keep your data

We store your data only for the period required by law or for as long as is necessary to fulfil the purposes for which your data were collected, in accordance with the storage limitation principle (Article 5(1)(e) GDPR). Once the purpose has been achieved or the statutory period has expired, the data are deleted.

Personal Data / Documentation Category

Retention Period

Legal Basis

Job applicant data

Up to 6 months after completion of the procedure, unless there is explicit consent for a longer period

Art. 25k PDPA

Employment files, payroll records

50 years from 1 January of the reporting period following the reporting period to which they relate

Art. 12(1)(1) Accountancy Act

Accounting records and financial statements

10 years from 1 January of the reporting period following the reporting period to which they relate

Art. 12(1)(2) Accountancy Act

Other accounting information carriers

3 years from 1 January of the reporting period following the reporting period to which they relate

Art. 12(1)(3) Accountancy Act

Client and transaction data (commercial relations)

5 years from the beginning of the calendar year following the termination of the relationship or the completion of the transaction

Art. 171(1) Tax and Social Insurance Procedure Code

Tax and social insurance audit data

At least 5 years after expiry of the limitation period for the public receivable

Art. 38 Accountancy Act and Art. 38 Tax and Social Insurance Procedure Code

Website visit data (logs, IP addresses)

Up to 12 months

Legitimate interest

Technical logs and software usage data

Up to 12 months, unless needed for incident investigation

Legitimate interest

Push notifications (device tokens and consents)

Until withdrawal of consent or up to 6 months after last activity

Consent and technical requirements

Website usage data (IP addresses, logs)

Up to 12 months for statistical analysis, up to 7 days for technical logs

Legitimate interest (Art. 6(1)(f))

Intellectual property data

For the period of validity of the rights and 5 years after their expiry

Performance of a contract and legal obligation

Advertising identifiers IDFA/AAID (AdMob)

90 days or until withdrawal of consent

Consent

GPS coordinates (Google Maps – accuracy up to 1.1 km, two decimal places 0.00 km) – the information will be used together with aggregated information for statistical purposes

Up to 12 months

Consent

 

In some cases (e.g. recruitment), the retention period may be extended with the data subject's consent, which can be withdrawn at any time.

§ 9. To whom may we disclose your data

Sometimes it is necessary to share your data with third parties in order to provide you with the best service or to comply with legal requirements, in accordance with Article 13(1)(e) GDPR. Such third parties may include:

      IT specialists and technology service providers involved in the development and maintenance of software products;

      Hosting providers and cloud service providers (e.g. Amazon Web Services, Google Cloud);

      Push notification providers – Apple Push Notification Service (Apple Inc.) and Firebase Cloud Messaging (Google LLC) – device tokens only, no personal data;

      Map and location service providers – Google Maps

      Google AdMob – monetisation and advertisements

      Insurers, accountants, and IT support;

      State institutions and supervisory authorities (e.g. the National Revenue Agency, the Commission for Personal Data Protection);

      Service providers with whom we have a confidentiality agreement;

      Partners in joint projects or initiatives – only with your consent;

Cross-border data processing:

When we work with clients or partners from the European Union or the European Economic Area, we transfer personal data within the EU/EEA in compliance with Articles 45 and 46 of the GDPR. When transferring data outside the EU/EEA, we use Standard Contractual Clauses (SCCs) approved by the European Commission to ensure an adequate level of protection.

§ 10. Social media and external integrations

We may use social plugins (such as Facebook, Instagram, LinkedIn) on our website, and the processing of data on these platforms is carried out in accordance with their privacy policies. This is done in compliance with Articles 12 and 13 of the GDPR, which require transparency and information.

§ 10.1 Third-party integrations:

The website and mobile application may use the following external services:

Service

Provider

Purpose

Google Analytics

Google LLC/Google Ireland Limited

Traffic analysis and user behaviour (anonymised data)

Google Maps

Google LLC/Google Ireland Limited

Delivery of location services

Google AdMob

Google LLC/Google Ireland Limited

Personalised advertisements, monetisation

Firebase Cloud Messaging

Google LLC

Delivery of push notifications in the mobile application

Apple Push Notification Service

Apple Inc.

Delivery of push notifications for iOS devices

 

§ 10.2 Google AdMob

When using Google AdMob for personalised advertisements, data on approximate location (city/zip code) is combined with searched products to display local offers (e.g. "Milk on sale at Lidl nearby"). Location data is collected only when one of the following features is activated with explicit consent:

 

1) Searching for and adding stores

2) Displaying "Offers near me"

3) When searching for products from a shopping list

4) When creating price notifications

Google AdMob may be used for displaying advertisements. AdMob processes advertising identifiers (IDFA/AAID), approximate geolocation (city/zip code), searched products and categories, and anonymised IP addresses.

Legal basis: Consent (Art. 6(1)(a) GDPR). Retention: 13 months. Transfer: Google Ireland Ltd (EEA) / Google LLC (USA under the EU-US Data Privacy Framework).

Withdrawal: "Settings > Advertisements" or system settings.

AdMob requires UMP (User Messaging Platform) for consent in the EEA. Users may refuse personalised advertisements.

§ 10.3 Clarification regarding third-party policies

Important: All third-party integrations that process personal data (e.g. for marketing or behavioural analysis) require your explicit consent through the cookie banner on the website.

Third-party privacy policies:

      Google: https://policies.google.com/privacy

      Apple: https://www.apple.com/legal/privacy/

      Meta/Facebook: https://www.facebook.com/privacy/policy/

§ 11. Automated processing and profiling

The Company does not carry out:

      Automated decision-making producing legal or similarly significant effects on data subjects (Article 22 GDPR);

      Use of artificial intelligence (AI) technologies for processing personal data or decision-making.

All decisions affecting the rights and legitimate interests of natural persons are made with human intervention and judgment. If automated data analysis tools are used in the future, this will be only for internal organisational purposes and with appropriate safeguards for data subjects' rights.

§ 12. Your rights and how to exercise them

As a data subject, you have the following rights under Articles 15–22 of the GDPR:

      Right of access (Art. 15) – To obtain information as to whether and what personal data we process about you, for what purposes, on what basis, and how long they will be stored;

      Right to rectification (Art. 16) – To request the correction of inaccurate or incomplete data;

      Right to erasure (Art. 17) – To request the erasure of your data ("right to be forgotten"), where applicable and where there is no legal obligation to retain the data;

      Right to restriction of processing (Art. 18) – To request a temporary restriction on processing where data is contested or pending review of an objection;

      Right to data portability (Art. 20) – To receive a copy of your data in a structured, commonly used, and machine-readable format (XML, JSON, CSV);

      Right to object (Art. 21) – To object to the processing of your data based on legitimate interest (Article 6(1)(f)) or for direct marketing purposes. Upon receiving an objection, the Company will cease processing unless it demonstrates compelling legitimate grounds which override your interests, rights, and freedoms;

      Right to withdraw consent (Art. 7(3)) – To withdraw your consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out prior to the withdrawal;

      Right to lodge a complaint (Art. 77) – To lodge a complaint with the Commission for Personal Data Protection (www.cpdp.bg) or with the court.

You may exercise your rights by sending us a written request in person, by post, or by email: contact@groceryradar.com. We will respond within one month, unless an extension is required due to the complexity or volume of the request (Article 12(3) GDPR).

§ 13. How we protect your data

We take all necessary technical and organisational measures to ensure the security of your data – we restrict access to authorised persons only, use encryption and secure electronic systems, ensure physical security of premises, train our staff, and conduct regular inspections and audits, in accordance with Article 32 of the GDPR.

Cybersecurity measures:

      Regular software updates and patching;

      Protection against unauthorised access to systems and databases;

      Monitoring for suspicious activity and breach attempts;

      Incident response and data recovery procedures in case of technical problems;

      Periodic risk assessments for the security of processed data (DPIA for high-risk activities pursuant to Article 35 of the GDPR).

We apply standards corresponding to industry best practices in the IT sector to ensure the confidentiality, integrity, and availability of data.

§ 14. How we respond to incidents and breaches

In the event of a personal data breach, we will notify the Commission for Personal Data Protection and, if necessary, you – within the statutory timeframe, in accordance with Articles 33 and 34 of the GDPR. We will inform you of what happened, the potential consequences, and the measures we have taken to mitigate the risk.

§ 15. Electronic marketing and push notifications

The Company may send you email newsletters or other marketing communications only with your explicit consent, pursuant to Article 6(1)(a) of the GDPR. You can unsubscribe at any time via the available mechanisms in your email or by contacting us.

Push notifications in the mobile application

If you use the Company's mobile application, you may voluntarily subscribe to push notifications for promotions, new features, or price updates.

How push notifications work:

      They require your explicit consent when you first launch the application

      They use an anonymous device token (device identifier) provided by Apple or Google

      They do not collect personal data – the device token does not contain a name, email, or other identifying information

      They are stored until the withdrawal of consent or up to 6 months after last activity

Withdrawal of consent:

You can stop push notifications at any time by using:

      The application settings ("Notifications" button)

      Your device settings (iOS: Settings > Notifications; Android: Settings > Apps > Notifications)

Legal basis: Consent (Article 6(1)(a) GDPR and Article 25(1) of the Electronic Document and Electronic Certification Services Act).

Technical providers:

      Apple Push Notification Service – for iOS devices

      Firebase Cloud Messaging (Google) – for Android devices

The Company is not responsible for the processing of data by Apple or Google. Please review their privacy policies.

§ 16. Sharing data with other third parties

In some cases, we may share your data with partners or service providers who assist us in the provision of services. All such third parties are required to comply with the requirements of the GDPR and are bound by a confidentiality agreement.

Categories of recipients:

  1. IT infrastructure – hosting providers, cloud services (AWS, Google Cloud)
  2. Analytics and marketing – Google Analytics, Meta Pixel (with consent only)
  3. Push notifications – Apple Push Notification Service, Firebase Cloud Messaging
  4. Google AdMob/Google Maps Platform (Google Ireland Ltd/Google LLC) – for advertisements (IDFA/AAID, IP) and maps (coordinates with consent)
  5. Accounting and legal services – external accountants, lawyers
  6. State authorities – the National Revenue Agency, the CPDP, judicial authorities (where required by law)

Cross-border data transfers:

When transferring data outside the European Union (EU) or the European Economic Area (EEA), the Company ensures an adequate level of protection through:

      European Commission adequacy decisions (e.g. for Switzerland, the United Kingdom)

      Standard Contractual Clauses (SCCs) – EU Commission-approved model contracts

      EU-US Data Privacy Framework – for transfers to DPF DPF-certified companies in the USA (Google, Apple, Meta)

A full list of DPF-certified companies can be found at: https://www.dataprivacyframework.gov/list

Note: When using services from Google (Analytics, Firebase, AdMob, Maps), Apple (APNS), and Meta (Facebook Pixel), data may be transferred to the USA. These companies are certified under the EU-US Data Privacy Framework.

§ 17. Adoption and updates to the Policy

We periodically review and update this Policy to reflect changes in legislation or in our internal processes. The latest version is always available on our website. If material changes occur, we will inform you by appropriate means, in accordance with the transparency principle (Articles 12 and 13 of the GDPR).

The Policy was adopted by the Company on 06.03.2026 .

Last updated: 06.03.2026 .

§ 18. Contacts and complaints

If you have any questions, need assistance, or wish to lodge a complaint regarding the processing of your personal data, you may contact us at contact@groceryradar.com or at the Company's address: Yambol, postal code 8600, Georgi Benkovski 2 Residential Complex, fl. 11, apt. 43.

Complaints and disputes:

If you have questions about data processing, including concerns about unfair pricing or profiling, write to contact@groceryradar.com. You may also contact the CPDP.

If you are not satisfied with our response, you have the right to contact the Commission for Personal Data Protection:

Address: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd.
Tel.: +359 2/91-53-518
Email:
kzld@cpdp.bg
Website:
www.cpdp.bg

 

APPROVED BY:

Kaloyan Svetlozarov Valchev
Managing Director of "GROCERY RADAR" EOOD