startklar.site

Language: DEBG

Book an intro callBook an intro call

LanguageENDEBG

Privacy Policy

Startklar. Complete business websites at a fixed price.

1. Data Controller

Zone 2 Technologies Ltd, a Bulgarian single-member limited liability company, registered in the Bulgarian Commercial Register under UIC 206921440 and VAT number BG206921440, with seat and management address at Bulgaria, Sofia 1000, Izgrev region, Iztok district, 6 Dr. Lyuben Rusev Str., fl. 5, ap. 81 (“Zone 2 Technologies”, “We”, “Us”, or “Our”).

Through the website startklar.site, Zone 2 Technologies offers a productized website service under the Startklar brand: complete business websites at a fixed price, built within five working days of the kickoff and delivered on a preview link.

Zone 2 Technologies is a Data Controller within the meaning of Article 4(7) of the GDPR and, as such, is responsible for processing Your data in a fair, transparent, and secure manner, as required by the Regulation and national legislation.

This Privacy Policy relates to the activities of Zone 2 Technologies (“the Controller”) in connection with the management of the website startklar.site and the provision of services through it. To fulfill legal requirements, this Privacy Policy provides You with information about Your rights, the types of personal data collected, the basis for their processing, how they are stored and used, and when they are disclosed to third parties.

In accordance with the Controller’s obligations under Regulation 2016/679 of the European Parliament and of the Council (“General Data Protection Regulation” or “GDPR”), the Controller guarantees that the processing of Your personal data will always comply with the Regulation and applicable Bulgarian data protection legislation.

Contact Information:

Zone 2 Technologies Ltd
Email: hello@startklar.site
Website: startklar.site

2. Personal Data We Collect

As the Controller of the website startklar.site (“the Website”), Zone 2 Technologies determines the purposes, collects, and processes personal data of website users necessary for their identification, contact, and service delivery.

According to Article 4 of EU Regulation 2016/679, “personal data” means any information relating to an identified natural person or to a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or by one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

The Website has no user accounts. Cookies are set only with Your consent (Section 13), and the Website’s analytics run without cookies on aggregated data. Personal data reaches Us only in the following ways:

Contact Data (when You send Us an inquiry through the contact form on the Website or by email):

Inquiries submitted through the contact form are delivered to Us by email and are not stored in a database on the Website. You receive a confirmation email for Your inquiry.

Bot Protection Data:

Consent Data (when You make a choice in the cookie banner):

Usage Data (while You browse the Website):

Advertising Data (only if You have consented to marketing cookies, Section 13):

Booking and Project Data (when You book Our service):

Billing Data:

Technical Data:

Providing Your contact data (name, email) and billing data (name of the representative, address, company registration number) is a mandatory contractual requirement, necessary for concluding and performing the service contract. Without this data, We cannot send You an offer, conclude a contract with You, or issue a lawful invoice.

Providing data for marketing and analytics purposes (through optional cookies and technologies) is voluntary. Declining to provide this data does not affect Your ability to use the Service.

3. Personal Data We Do NOT Collect

Zone 2 Technologies does not collect or process personal data that:

IMPORTANT: if such information is shared by users of the Website, it will not be subject to processing and will be destroyed immediately.

The Controller does not use Your personal data for automated individual decision-making, including profiling, within the meaning of Article 22 of EU Regulation 2016/679.

4. Purpose of Data Processing

Zone 2 Technologies collects and uses Your personal data for the following activities and purposes:

Your personal data may also be processed if a government authority requests Zone 2 Technologies’ cooperation in connection with official procedures, including pre-trial, judicial, and administrative proceedings related to claims, fraud, etc. In such cases, Zone 2 Technologies discloses only the amount of data requested by the authorities, not exceeding the scope of the specific request.

5. Retention Period

We retain Your data for the following periods:

You may request deletion of Your personal data at any time by contacting Us at hello@startklar.site. We will process deletion requests in accordance with applicable law, subject to any legal obligations requiring Us to retain certain data.

6. Legal Basis for Processing

We collect Your data on the following legal bases:

7. Technical Security

The Controller has implemented all technical and organizational measures necessary for the processing and protection of personal data in accordance with EU Regulation 2016/679 and applicable Bulgarian legislation.

The measures taken correspond to the specific risks associated with the processing and storage of personal data. Organizational and technical measures are in place to protect Your data from loss, alteration, theft, or unauthorized access by third parties.

These measures include:

However, no internet transmission is completely secure, and We cannot guarantee absolute security of data transmitted to Us online.

8. Recipients of Personal Data

8.1. Data Processors

The Controller provides personal data to providers who act on its behalf and on its instructions under a written contract pursuant to Article 28 of EU Regulation 2016/679. These parties may not use the data for their own purposes and include:

a) Vercel Inc. (USA): hosting and cloud infrastructure provider, ensuring the technical operation and security of the Website.

Hosting:

Bot Protection:

Analytics:

b) Postmark (Wildbit LLC, USA): email delivery provider for inquiry-related communication.

Email Delivery:

c) CookieYes (CookieYes Limited, United Kingdom): provider of software solutions for cookie consent management.

Consent Management:

8.2. Joint Controllers

In certain cases, the Controller determines the purposes and means of processing jointly with third parties pursuant to Article 26 of the GDPR:

a) Google Ireland Limited (Ireland): when using conversion measurement tools (Google Ads). The Controller and Google are joint controllers for the phase of collecting and transmitting the data to Google. More information on the allocation of responsibilities is available in Google’s terms: https://business.safety.google/controllerterms/

Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) provides the Google Ads conversion measurement on the Website. The Google tag is loaded only after Your marketing consent (Section 13) and receives Your consent choices via Google Consent Mode. When You send an inquiry through the contact form with marketing consent given, a conversion event is transmitted to Google together with a hashed (pseudonymized) form of Your email address (“enhanced conversions for leads”) and, where present, the ad click identifiers described in Section 2. If Your inquiry later becomes an order, We may report this outcome to Google Ads together with the stored click identifier and hashed email address, to measure which advertisements lead to actual clients. Google may transfer data to Google LLC in the United States; Google LLC is certified under the EU-U.S. Data Privacy Framework (Section 12). For more information, see https://policies.google.com/privacy

8.3. Independent Controllers

The Controller discloses data to third parties who carry independent responsibility for Your data:

The Controller will share personal data with third parties only after explicitly ensuring the technical and legal mechanisms under which the processing of shared personal data will be carried out in accordance with the requirements of Regulation 679/2016 and Bulgarian legislation. We do not sell personal data.

9. Data Processing Principles

The Controller guarantees that the personal data it processes are:

a) Processed lawfully, fairly, and in a transparent manner in relation to You (“lawfulness, fairness, and transparency”);

b) Collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes (“purpose limitation”);

c) Adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed (“data minimization”);

d) Accurate and, where necessary, kept up to date; all reasonable steps are taken to ensure that inaccurate personal data are erased or rectified without delay (“accuracy”);

e) Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed (“storage limitation”);

f) Processed in a manner that ensures appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures (“integrity and confidentiality”).

10. Your Data Protection Rights

Under the GDPR, You have the following rights:

Right of Access

Upon Your request, You have the right to access the personal data stored about You. You also have the right to request a copy of the personal data being processed.

Right to Rectification

You have the right to request correction of incorrect, inaccurate, or incomplete personal data. Depending on the purposes of processing, You may have the right to supplement incomplete personal data, including by providing an additional statement.

Right to Erasure (“Right to Be Forgotten”)

You have the right to request the deletion of personal data when they are no longer necessary or if their processing is unlawful. Please note that Article 17 of the GDPR defines the cases in which We are obliged to delete Your data. Please also note that We may be required to retain Your data even if You have requested their deletion (for example, to comply with a legal obligation under EU or Bulgarian law).

Right to Restriction of Processing

Under certain circumstances, You have the right to request restriction of the processing of Your personal data. For example, You may exercise this right when We no longer need Your personal data for processing purposes, but We must keep them in Our systems for use in situations such as exercising rights or defending claims.

Right to Data Portability

Under certain circumstances, You have the right to receive the personal data You have provided to Us in a structured, commonly used, and machine-readable format (i.e., in digital form), and You may have the right to request the transfer of such data to another person without hindrance from Us, if such transfer is technically feasible.

Right to Object

Under certain circumstances, You have the right to object to the processing of Your personal data, and We may be required to stop processing them in the future. You may exercise this right, for example, if We use Your email address for direct marketing purposes. In this case, after Your objection, We will no longer be able to send You marketing materials.

Right to Withdraw Consent

When the processing of Your personal data is based on Your consent, You may withdraw Your consent at any time without giving Us a reason. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

How to Exercise Your Rights

Given the scope and nature of Our activities, We are not required to appoint a Data Protection Officer and have not appointed one. To exercise Your rights, You may contact Us with a written request at hello@startklar.site. We will respond to Your questions and requests without undue delay and within 1 month at the latest. You may be asked to provide information to verify Your identity in order to exercise Your rights.

11. Complaint to Supervisory Authority

If for any reason You are not satisfied with the way We process Your personal data, please first inform Us so that We can understand the cause of the problem and try to resolve it. We will carefully review Your request and answer all Your questions.

If You believe You have not received adequate assistance from Zone 2 Technologies or that Your right has been violated, You have the right to lodge a complaint with a supervisory authority. This authority in the Republic of Bulgaria is:

Commission for Personal Data Protection:
Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
Phone: 02/915 35 18
Email: kzld@cpdp.bg
Website: www.cpdp.bg

12. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including:

When We transfer Your data outside the EEA, We ensure appropriate safeguards are in place, including:

13. Cookies and Tracking Technologies

13.1. What Are Cookies?

The Website uses cookies and other similar technologies (e.g., local storage, scripts, pixels). These are small data files stored on Your device that allow Us to collect certain information during Your visit. These technologies help Us ensure the security and proper functioning of the Website, remember Your preferences, and analyze its effectiveness. In this Policy, “cookies” means any technology that falls within the scope of Article 4a of the Bulgarian Electronic Commerce Act.

13.2. Types of Cookies We Use

We classify the technologies used into the following categories:

13.3. List of Technologies Used

We do not load non-required technologies without Your prior, explicit consent. You can change Your choice at any time via the “Cookie settings” link at the bottom of the page.

13.4. Demonstrating Consent

To meet Our accountability obligation under Article 7(1) of the GDPR, We keep a record (log) of every consent You give. This record includes the domain on which the consent was given, a partially masked (pseudonymous) IP address, the country derived from it, the date and time in UTC, a consent ID, and the categories You accepted or rejected. We keep this record for 5 years from the last change or withdrawal of the consent, for defense against potential legal claims.

14. Policy Updates

To keep this Privacy Policy up to date, it may be changed in whole or in part at any time without special notice. Please check this Policy periodically for updates. The date of the last update will be indicated below.

This Privacy Policy was adopted on July 18, 2026.

Last Updated: August 12, 2026.