Privacy Policy
Last updated: 20 July 2026
Controller: “SUPREME COMMERCE” OOD (СЮПРИЙМ КОМЕРС ООД), UIC 208832983, VAT BG208832983, based in Plovdiv, Bulgaria; [email protected]
1. Scope and roles
This Policy covers supremecommerce.eu, enquiries, proposals, contracts and digital services. We normally act as controller. Where we process data solely under a client’s documented instructions, the client is controller and we act as processor under the applicable agreement.
2. Data
- identity, company and contact details;
- enquiry, project, contract, invoice and correspondence data;
- website, device, IP, security and technical logs;
- payment status and transaction references from Stripe (we do not receive full card numbers);
- content, credentials or other data supplied for a project.
3. Purposes and legal bases
- Enquiries/proposals: pre-contract steps and legitimate interests in responding and preventing abuse.
- Projects/payments: contract performance and tax/accounting obligations.
- Security, fraud prevention and improvement: legitimate interests in secure and effective systems.
- Claims: legal obligations and legitimate interests in establishing, exercising or defending rights.
- Optional marketing/non-essential technologies: consent, withdrawable at any time.
Required information is necessary to answer an enquiry or perform a contract; without it we may not proceed.
4. Recipients
Where necessary, data may be shared with hosting, email, security, cloud, translation, collaboration and analytics providers; Stripe and financial institutions; advisers and confidentiality-bound contractors; and competent authorities. We do not sell personal data.
5. International transfers
Transfers outside the EEA use an adequacy decision, Standard Contractual Clauses, the EU–US Data Privacy Framework where applicable, or another lawful safeguard. Relevant safeguard information is available on request, subject to security and confidentiality limits.
6. Retention
- unsuccessful enquiries: normally up to 24 months;
- project/contract records: normally 5 years after completion or termination;
- accounting records: the statutory period, generally up to 10 years;
- security logs: normally up to 12 months unless an incident requires longer;
- consent evidence: while relied upon and as needed to prove compliance;
- backups: until overwritten under the backup cycle.
Longer retention may apply where law, fraud prevention or a legal claim requires it.
7. Security and client duties
We use proportionate safeguards, but no system is completely secure. Clients must protect credentials, control authorised users and provide only data they are entitled to disclose.
8. Rights
Subject to the GDPR and applicable law, you may request access, correction, deletion, restriction and portability, object to legitimate-interest processing, and withdraw consent without affecting earlier lawful processing. We may verify identity. You may complain to the Bulgarian Commission for Personal Data Protection at cpdp.bg or your competent EEA authority.
9. Automated decisions and AI
We do not make decisions producing legal or similarly significant effects solely by automated means. AI may support drafting, analysis, coding or automation, but material project decisions are subject to human review.
10. Third parties, children and changes
Third-party sites have their own policies. Our services are not directed to children. We may update this Policy prospectively; the date above identifies the current version.
11. Contact
Privacy requests: [email protected]