The site itself uses no cookies and collects no statistics. One of the demo applications, however, uses an external service — that is described separately below. This document explains what is processed and on what terms.
| Controller | Nikolay Nedelchev, a natural person practising a liberal profession |
|---|---|
| Activity | building websites and digital solutions under the name SAITORA |
| nikolay@nedelchevweb.com | |
| Phone | 0878 396 223 |
| Location | Sofia, Bulgaria |
The activity is carried out by a natural person. There is no registered company and no designated data protection officer, since the processing does not require one under Art. 37 of the General Data Protection Regulation (GDPR).
The site is static. There is no server-side processing, no database and no user accounts.
| Cookies | None are used — neither first-party nor third-party. |
|---|---|
| Analytics | None. Traffic is not counted, visits are not tracked. |
| External services | The site itself embeds no maps, fonts, videos, chats or social network buttons. For the demo applications see section 3. |
| Ad networks | None. No profiling and no automated decision-making take place. |
| Local storage | Only the page language you select is stored (Bulgarian, English or German). The entry stays in your browser, is not sent anywhere and disappears if you clear the site's data. |
The /demos/ section contains working applications you can try out. They are separate from the site and some of them work differently:
| Snake Luigi | Keeps a leaderboard of the best scores. When a score is saved, the game sends to Google Firebase the name you chose and your points. Do not enter a real name if you do not want it to be stored. The controller of this database is Nikolay Nedelchev, and Google Ireland Limited acts as processor. |
|---|---|
| Grave Knight, BO Calculator, Област·Демо | They run entirely in your browser. Nothing is sent out. |
| The remaining demos | Static mock-ups with no data processing. |
The leaderboard data is kept for as long as the game exists, and is deleted on request at the address given below.
The form on the site does not send data to a server. When you press the button it prepares a message and opens your own mail client. Until you press "Send" there, no information leaves your device and I receive nothing.
If you decide to send the message, I receive what you have written: usually a name, an email address and, at your discretion, a phone number, company name and a project description.
| What data | Names, email, phone, company and the content of the message — only what you have provided yourself. |
|---|---|
| Purpose | Replying to the enquiry, preparing a quote and, if it comes to that, performing a contract. |
| Legal basis | Art. 6(1)(b) GDPR — steps taken at the data subject's request prior to entering into a contract, and performance of a contract. For correspondence outside that scope — Art. 6(1)(f) GDPR, the legitimate interest in replying to messages received. |
| Retention | Enquiries with no follow-up — up to 12 months. Where a contract is concluded — up to 5 years after it ends, and accounting documents for the period set by the Accountancy Act (Закон за счетоводството). |
I do not sell personal data and do not provide it to third parties for their own purposes. Technically, it is accessible only to the providers I work through:
Some of these services may involve transfers of data outside the European Economic Area. Such transfers take place on the basis of European Commission adequacy decisions or standard contractual clauses.
Under the GDPR you have the right to:
Write to nikolay@nedelchevweb.com. I reply within one month. If the request is complex, that period may be extended by a further two months, of which I will notify you.
If you believe your rights have been infringed, you may lodge a complaint with the supervisory authority:
| Authority | Commission for Personal Data Protection (Комисия за защита на личните данни) |
|---|---|
| Address | Sofia 1592, bul. „Prof. Tsvetan Lazarov“ 2 |
| kzld@cpdp.bg | |
| Website | cpdp.bg |
Besides websites, I build ordering systems, booking systems, customer portals, internal business systems and automations. In such cases the system handles the data of my client's own customers.
| Where responsibility lies | The client is the controller of that data. I act as processor under Art. 28 GDPR and work only on their documented instructions. |
|---|---|
| What we sign | Before any access to real data, a separate data processing agreement is concluded, setting out the purposes, the types of data, the duration and the security measures. |
| During development | I work with synthetic or anonymised data wherever that is technically possible. |
| Sub-processors | I do not engage sub-processors with access to data without the client's prior written consent. |
| After the end | When the contract ends, the data is returned or deleted on the client's instructions. |
This policy governs my site only. Processing within a system already built is governed by the policy of the client concerned.
The site is served over HTTPS. Correspondence is stored in a mailbox protected by a password and two-factor authentication. I am the only one with access to it.
The services are aimed at business clients and are not intended for persons under 18. I do not knowingly collect children's data.
If the way I work changes, this document is updated. Material changes are announced on the home page.
Questions about this document: nikolay@nedelchevweb.com