Public website and work portal. This website presents our company and contact details. The work portal is separate and accessible only via VPN. This site does not provide account sign-in, registration, document uploads or online payment. Enquiries are sent by email.
The public TBP Assistant is being prepared and does not yet provide model-generated answers. A separate assistant with a local language model is planned solely for company information and the visitor's conversation, without access to internal documents, email or work portal accounts. The processing and retention periods for public conversations will be specified before activation. A conversation does not automatically submit a request or activate a subscription. For business correspondence, use your assigned channel or the published email address.
Last updated: 28 September 2026
This policy describes how Trust Build Pro EOOD processes personal data of visitors to the website trustbuildpro.bg, representatives of our clients in the Client Portal, Request Portal subscribers and people with whom we correspond. We comply with the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Bulgarian Personal Data Protection Act.
1. Data controller
Trust Build Pro EOOD, UIC 206452103
Address: 73B Ralevitsa Street, Sofia 1404, Bulgaria
Phone: 0895 45 32 44 · Email: trustbuildbg@gmail.com
For all personal data enquiries, write to the email or postal address above with “Personal data” in the subject.
2. Data we process
2.1. Website visitors
- Technical data: IP address, request date and time, requested URL and browser type — in server logs and secure connection service logs (Cloudflare), for security and protection against attacks.
- Only technically necessary cookies — see the Cookie Policy. We do not use visitor analytics, advertising or profiling tools.
2.2. Client Portal
- Data about authorised users: name, position, business email, phone number, represented organisation and portal role.
- Client organisation data: name, UIC/BULSTAT number, address, representative and contact details.
- The contents of submitted and received documents: enquiries, letters, reports, records, payment requests, attachments and messages, and project data — address, identifier, ownership — where necessary for design or construction.
- Action history: who submitted, sent, accepted or downloaded what and when, together with the IP address — evidence of each document's date and contents.
- Login data: email and password. Passwords are stored only as hashes and are not known to anyone, including us.
2.3. Request Portal (subscription service)
- Subscriber data, submitted requests and files, processing results and subscription payment data.
2.4. Correspondence and contracts
- Data in letters, emails and contracts with us, and contact data for clients, subcontractors and partners.
3. Purposes and legal bases
- Entering into and performing a contract (Article 6(1)(b) GDPR) — quotations, contracts, design, construction, supervision, consultancy and portal operations.
- Legal obligations (Article 6(1)(c)) — accounting and taxes, documentation under the Bulgarian Spatial Development Act, and applicable funding programme and Public Procurement Act requirements.
- Legitimate interests (Article 6(1)(f)) — website and system security, evidence of submitted documents and met deadlines, defence in disputes and organisation of contract work.
- Consent (Article 6(1)(a)) — only where we explicitly request it for a specific purpose, such as publishing project photos as a reference. You may withdraw it at any time.
We do not make automated decisions with legal effects for you. The system may automatically suggest which staff member should receive an incoming message; a person makes the decision.
4. Recipients of data
- Our staff and subcontractors, designers and consultants engaged under the relevant contract — only as necessary for their work and subject to confidentiality obligations.
- State and municipal authorities, programme managing authorities and supervisory bodies — where required by law or necessary for contract performance, such as design coordination and approval.
- Technical service providers: public company content is prepared for delivery from our own server at the company's office in Bulgaria. The work portal and internal documents remain on our own server at the office in Bulgaria, accessible via VPN. Part of our business email is handled by Google (Gmail). When you visit the website, the serving server processes technical connection data; when you send email, its content is processed by email providers.
We do not sell personal data or provide it for advertising.
5. How long we retain data
- Portal accounts — while the organisation works with us. Access is suspended on request or when the person no longer represents the organisation.
- Contract documents and their history, including IP addresses — for the contract term and the retention periods under accounting, tax and spatial development legislation, generally up to 10 years; in a dispute, until it is resolved.
- Unconfirmed registration requests — up to 30 days.
- Technical server logs — up to 12 months.
- Backups — up to 12 months under the replacement cycle.
6. Your rights
You have rights of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, objection to processing based on legitimate interests and withdrawal of consent. Erasure does not apply to data we are legally required to retain.
We respond within one month, with a possible extension of two further months for complex requests, of which we will notify you. We may ask you to verify your identity.
You may lodge a complaint with the Bulgarian Commission for Personal Data Protection — 2 Prof. Tsvetan Lazarov Boulevard, Sofia 1592, Bulgaria, www.cpdp.bg.
7. Security
- Connections to the website and portals are encrypted (HTTPS).
- Portal access is role-based: users see only their organisation's documents, and our staff according to their assigned tasks.
- Files are stored in a protected folder and downloaded only after an access-rights check.
- Passwords have at least 12 characters and are stored only as hashes. Login is restricted after repeated failed attempts.
- The server has hourly backups and immutable data snapshots. Staff access to the server is via VPN.
8. Changes
When the policy changes, we publish the new version on this page with its update date. Portal users are notified of significant changes.