Privacy Policy
Startklar. Complete business websites at a fixed price.
1. Data Controller
Zone 2 Technologies Ltd, a Bulgarian single-member limited liability company, registered in the Bulgarian Commercial Register under UIC 206921440 and VAT number BG206921440, with seat and management address at Bulgaria, Sofia 1000, Izgrev region, Iztok district, 6 Dr. Lyuben Rusev Str., fl. 5, ap. 81 (“Zone 2 Technologies”, “We”, “Us”, or “Our”).
Through the website startklar.site, Zone 2 Technologies offers a productized website service under the Startklar brand: complete business websites at a fixed price, built within five working days of the kickoff and delivered on a preview link.
Zone 2 Technologies is a Data Controller within the meaning of Article 4(7) of the GDPR and, as such, is responsible for processing Your data in a fair, transparent, and secure manner, as required by the Regulation and national legislation.
This Privacy Policy relates to the activities of Zone 2 Technologies (“the Controller”) in connection with the management of the website startklar.site and the provision of services through it. To fulfill legal requirements, this Privacy Policy provides You with information about Your rights, the types of personal data collected, the basis for their processing, how they are stored and used, and when they are disclosed to third parties.
In accordance with the Controller’s obligations under Regulation 2016/679 of the European Parliament and of the Council (“General Data Protection Regulation” or “GDPR”), the Controller guarantees that the processing of Your personal data will always comply with the Regulation and applicable Bulgarian data protection legislation.
Contact Information:
Zone 2 Technologies Ltd
Email: hello@startklar.site
Website: startklar.site
2. Personal Data We Collect
As the Controller of the website startklar.site (“the Website”), Zone 2 Technologies determines the purposes, collects, and processes personal data of website users necessary for their identification, contact, and service delivery.
According to Article 4 of EU Regulation 2016/679, “personal data” means any information relating to an identified natural person or to a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or by one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
The Website has no user accounts. Cookies are set only with Your consent (Section 13), and the Website’s analytics run without cookies on aggregated data. Personal data reaches Us only in the following ways:
Contact Data (when You send Us an inquiry through the contact form on the Website or by email):
- Name
- Email address
- The content of Your message
Inquiries submitted through the contact form are delivered to Us by email and are not stored in a database on the Website. You receive a confirmation email for Your inquiry.
Bot Protection Data:
- To verify that a contact form submission comes from a person and not an automated bot, Vercel BotID runs an invisible check in the browser and processes technical signals such as IP address and browser characteristics (Section 8). BotID shows no puzzle and, according to Vercel, does not store user behavior or personally identifiable information
Consent Data (when You make a choice in the cookie banner):
- Your consent choice per category and the time of the decision. The consent tool stores this in Your browser (local storage and, where needed, a cookie) so Your choice stays saved, and records it with Our consent management provider (Section 8) so that We can demonstrate consent was obtained
- When the banner configuration is loaded, the consent service processes technical data of the request, such as IP-derived country information, to determine which consent rules apply
Usage Data (while You browse the Website):
- Aggregated, cookieless usage statistics collected by Vercel Web Analytics (Section 8), such as pages viewed, referrer, browser and device type, and country. No cookies are set for this, no cross-site identifiers are used, and no personal profiles are built
Advertising Data (only if You have consented to marketing cookies, Section 13):
- If You reach the Website through an advertisement, the link contains click identifiers and campaign parameters (such as the Google Ads click ID). With Your marketing consent, the Website stores them in Your browser for up to 90 days and attaches them to an inquiry You send through the contact form, so We know which advertisement led to Your inquiry. Withdrawing Your marketing consent removes this stored click data
- When You send an inquiry with marketing consent given, a conversion event is reported to the advertising service described in Section 8, and the email address You submitted is transmitted to it in hashed (pseudonymized) form for conversion measurement. Your consent status is recorded together with the inquiry
Booking and Project Data (when You book Our service):
- Business name, address, and, where applicable, VAT number
- The information You share in the questionnaire and the kickoff about Your business, customers, and goals
- Materials You provide for Your website, which may include names and photos of You or Your team
- Scheduling data for the intro call and the kickoff
Billing Data:
- Invoicing and payment records We are legally required to keep. Where a third-party payment provider is used, Your card details are handled directly by that provider and never reach Our servers
Technical Data:
- To deliver the Website and keep it secure, Our hosting provider processes technical data in server logs, such as IP address, browser type, requested pages, and the date and time of access
Providing Your contact data (name, email) and billing data (name of the representative, address, company registration number) is a mandatory contractual requirement, necessary for concluding and performing the service contract. Without this data, We cannot send You an offer, conclude a contract with You, or issue a lawful invoice.
Providing data for marketing and analytics purposes (through optional cookies and technologies) is voluntary. Declining to provide this data does not affect Your ability to use the Service.
3. Personal Data We Do NOT Collect
Zone 2 Technologies does not collect or process personal data that:
- Reveals racial or ethnic origin
- Reveals political opinions, religious or philosophical beliefs, or trade union membership
- Consists of genetic or biometric data
- Concerns health or medical conditions
- Concerns sex life or sexual orientation
IMPORTANT: if such information is shared by users of the Website, it will not be subject to processing and will be destroyed immediately.
The Controller does not use Your personal data for automated individual decision-making, including profiling, within the meaning of Article 22 of EU Regulation 2016/679.
4. Purpose of Data Processing
Zone 2 Technologies collects and uses Your personal data for the following activities and purposes:
- To receive and respond to Your inquiries, send You a confirmation email, and hold the free intro call
- To protect the contact form from spam and automated abuse
- To remember Your cookie choices and to demonstrate that consent was obtained where processing is based on consent
- To understand aggregate use of the Website through cookieless statistics
- To measure the effectiveness of Our advertising and attribute inquiries and orders to the advertisements that led to them, where You have consented (Sections 8 and 13)
- To provide the service You have booked: evaluating the questionnaire, preparing and holding the kickoff, building and handing over Your website, applying the revision round, and taking the website live after Your go-ahead
- To provide monthly services You have booked, such as hosting, content, reporting, and advertising management
- To issue invoices and meet accounting and tax obligations
- For communication purposes, including scheduling and project updates
- To identify parties to contracts and maintain records
- To comply with legal requirements, settle potential disputes, and protect against fraud
- To ensure the security of the Website and Our infrastructure
Your personal data may also be processed if a government authority requests Zone 2 Technologies’ cooperation in connection with official procedures, including pre-trial, judicial, and administrative proceedings related to claims, fraud, etc. In such cases, Zone 2 Technologies discloses only the amount of data requested by the authorities, not exceeding the scope of the specific request.
| Data category | Processing purpose | Legal basis |
|---|---|---|
| Contact data (name, email, phone) | Communication on inquiries and order fulfillment | Contract performance / Steps taken toward a contract |
| Billing data (name, address, company registration number) | Issuing accounting documents | Legal obligation (Bulgarian Accountancy Act, VAT Act) |
| Technical data (IP address, browser) | Security and technical maintenance | Legitimate interest |
| Marketing and analytics data (cookies, Vercel Analytics data) | Measuring advertising effectiveness and analyzing traffic | Consent |
5. Retention Period
We retain Your data for the following periods:
- Correspondence and inquiry data: up to 6 months after the communication ends
- Contract and invoice data: for 5 years after the end of the contract, in line with the general limitation period under the Bulgarian Obligations and Contracts Act; accounting documents are kept for the periods under the Bulgarian Accountancy Act
- Cookie consent data: until consent is withdrawn or for the validity period of the respective cookie
You may request deletion of Your personal data at any time by contacting Us at hello@startklar.site. We will process deletion requests in accordance with applicable law, subject to any legal obligations requiring Us to retain certain data.
6. Legal Basis for Processing
We collect Your data on the following legal bases:
- Contract performance (Article 6(1)(b) GDPR): processing necessary to provide the service You have requested, including steps taken at Your request before entering into a contract
- Legal obligation (Article 6(1)(c) GDPR):
- Where processing is required to comply with applicable laws, such as accounting and tax legislation
- To demonstrate consent given for the use of cookies and other technologies pursuant to Article 7(1) of the GDPR
- Legitimate interests (Article 6(1)(f) GDPR):
- Ensuring the technical soundness and security of the Website, including protection against DDoS attacks and malicious software (through server logs)
- Protecting the contact forms from automated abuse and spam (through Vercel BotID)
- Establishing, exercising, or defending legal claims arising from the Agreement or the use of the Website
- Consent (Article 6(1)(a) GDPR): where You have given explicit consent for specific processing activities, such as analytics and marketing cookies and advertising conversion measurement (Sections 8 and 13)
7. Technical Security
The Controller has implemented all technical and organizational measures necessary for the processing and protection of personal data in accordance with EU Regulation 2016/679 and applicable Bulgarian legislation.
The measures taken correspond to the specific risks associated with the processing and storage of personal data. Organizational and technical measures are in place to protect Your data from loss, alteration, theft, or unauthorized access by third parties.
These measures include:
- Encryption of data in transit
- Access controls and authentication
- Secure hosting infrastructure
- Data minimization: the Website collects no data it does not need
However, no internet transmission is completely secure, and We cannot guarantee absolute security of data transmitted to Us online.
8. Recipients of Personal Data
8.1. Data Processors
The Controller provides personal data to providers who act on its behalf and on its instructions under a written contract pursuant to Article 28 of EU Regulation 2016/679. These parties may not use the data for their own purposes and include:
a) Vercel Inc. (USA): hosting and cloud infrastructure provider, ensuring the technical operation and security of the Website.
Hosting:
- Vercel hosts the Website and processes the technical data described in Section 2 as part of delivering it. For more information, see https://vercel.com/legal/privacy-policy
Bot Protection:
- Vercel also provides the BotID check on Our contact form, which verifies that submissions come from real people, not automated bots. BotID runs invisibly in the browser and may process IP address, browser characteristics, and interaction signals to assess whether a visitor is human; according to Vercel, it does not store user behavior or personally identifiable information. This is a security measure necessary to protect the Service from abuse. For more information, see https://vercel.com/legal/privacy-policy
Analytics:
- Vercel also provides the Website’s cookieless Web Analytics. It processes technical data such as pages viewed, referrer, browser and device type, and country in aggregated form; it sets no cookies and uses no cross-site identifiers. For more information, see https://vercel.com/legal/privacy-policy
b) Postmark (Wildbit LLC, USA): email delivery provider for inquiry-related communication.
Email Delivery:
- Postmark delivers the emails triggered by the contact form: Your inquiry to Us and the confirmation email to You. Your name, email address, and message are shared with this provider for email delivery purposes. For more information, see https://postmarkapp.com/privacy-policy
- Direct email correspondence is processed by the email service provider that operates Our mailboxes, as part of normal email delivery
c) CookieYes (CookieYes Limited, United Kingdom): provider of software solutions for cookie consent management.
Consent Management:
- CookieYes hosts the consent management service behind the cookie banner. It delivers the banner configuration, determines from technical request data (such as IP-derived country) which consent rules apply, and stores the consent records described in Section 2 and Section 13.4 on Our behalf. For more information, see https://www.cookieyes.com/privacy-policy
8.2. Joint Controllers
In certain cases, the Controller determines the purposes and means of processing jointly with third parties pursuant to Article 26 of the GDPR:
a) Google Ireland Limited (Ireland): when using conversion measurement tools (Google Ads). The Controller and Google are joint controllers for the phase of collecting and transmitting the data to Google. More information on the allocation of responsibilities is available in Google’s terms: https://business.safety.google/controllerterms/
Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) provides the Google Ads conversion measurement on the Website. The Google tag is loaded only after Your marketing consent (Section 13) and receives Your consent choices via Google Consent Mode. When You send an inquiry through the contact form with marketing consent given, a conversion event is transmitted to Google together with a hashed (pseudonymized) form of Your email address (“enhanced conversions for leads”) and, where present, the ad click identifiers described in Section 2. If Your inquiry later becomes an order, We may report this outcome to Google Ads together with the stored click identifier and hashed email address, to measure which advertisements lead to actual clients. Google may transfer data to Google LLC in the United States; Google LLC is certified under the EU-U.S. Data Privacy Framework (Section 12). For more information, see https://policies.google.com/privacy
8.3. Independent Controllers
The Controller discloses data to third parties who carry independent responsibility for Your data:
- Professional advisors (accountants and lawyers): to fulfill legal obligations or protect legitimate interests
- Banks and payment institutions: to handle payments
- State authorities (the Bulgarian National Revenue Agency, the Commission for Personal Data Protection): where a legal obligation exists
The Controller will share personal data with third parties only after explicitly ensuring the technical and legal mechanisms under which the processing of shared personal data will be carried out in accordance with the requirements of Regulation 679/2016 and Bulgarian legislation. We do not sell personal data.
9. Data Processing Principles
The Controller guarantees that the personal data it processes are:
a) Processed lawfully, fairly, and in a transparent manner in relation to You (“lawfulness, fairness, and transparency”);
b) Collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes (“purpose limitation”);
c) Adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed (“data minimization”);
d) Accurate and, where necessary, kept up to date; all reasonable steps are taken to ensure that inaccurate personal data are erased or rectified without delay (“accuracy”);
e) Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed (“storage limitation”);
f) Processed in a manner that ensures appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures (“integrity and confidentiality”).
10. Your Data Protection Rights
Under the GDPR, You have the following rights:
Right of Access
Upon Your request, You have the right to access the personal data stored about You. You also have the right to request a copy of the personal data being processed.
Right to Rectification
You have the right to request correction of incorrect, inaccurate, or incomplete personal data. Depending on the purposes of processing, You may have the right to supplement incomplete personal data, including by providing an additional statement.
Right to Erasure (“Right to Be Forgotten”)
You have the right to request the deletion of personal data when they are no longer necessary or if their processing is unlawful. Please note that Article 17 of the GDPR defines the cases in which We are obliged to delete Your data. Please also note that We may be required to retain Your data even if You have requested their deletion (for example, to comply with a legal obligation under EU or Bulgarian law).
Right to Restriction of Processing
Under certain circumstances, You have the right to request restriction of the processing of Your personal data. For example, You may exercise this right when We no longer need Your personal data for processing purposes, but We must keep them in Our systems for use in situations such as exercising rights or defending claims.
Right to Data Portability
Under certain circumstances, You have the right to receive the personal data You have provided to Us in a structured, commonly used, and machine-readable format (i.e., in digital form), and You may have the right to request the transfer of such data to another person without hindrance from Us, if such transfer is technically feasible.
Right to Object
Under certain circumstances, You have the right to object to the processing of Your personal data, and We may be required to stop processing them in the future. You may exercise this right, for example, if We use Your email address for direct marketing purposes. In this case, after Your objection, We will no longer be able to send You marketing materials.
Right to Withdraw Consent
When the processing of Your personal data is based on Your consent, You may withdraw Your consent at any time without giving Us a reason. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
How to Exercise Your Rights
Given the scope and nature of Our activities, We are not required to appoint a Data Protection Officer and have not appointed one. To exercise Your rights, You may contact Us with a written request at hello@startklar.site. We will respond to Your questions and requests without undue delay and within 1 month at the latest. You may be asked to provide information to verify Your identity in order to exercise Your rights.
11. Complaint to Supervisory Authority
If for any reason You are not satisfied with the way We process Your personal data, please first inform Us so that We can understand the cause of the problem and try to resolve it. We will carefully review Your request and answer all Your questions.
If You believe You have not received adequate assistance from Zone 2 Technologies or that Your right has been violated, You have the right to lodge a complaint with a supervisory authority. This authority in the Republic of Bulgaria is:
Commission for Personal Data Protection:
Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
Phone: 02/915 35 18
Email: kzld@cpdp.bg
Website: www.cpdp.bg
12. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including:
- United States (where some of Our service providers are located)
- Other countries where Our infrastructure providers maintain servers
When We transfer Your data outside the EEA, We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Transfers to countries with an adequacy decision
- Other legally recognized transfer mechanisms
13. Cookies and Tracking Technologies
13.1. What Are Cookies?
The Website uses cookies and other similar technologies (e.g., local storage, scripts, pixels). These are small data files stored on Your device that allow Us to collect certain information during Your visit. These technologies help Us ensure the security and proper functioning of the Website, remember Your preferences, and analyze its effectiveness. In this Policy, “cookies” means any technology that falls within the scope of Article 4a of the Bulgarian Electronic Commerce Act.
13.2. Types of Cookies We Use
We classify the technologies used into the following categories:
- Required: These technologies are strictly necessary for the basic functioning and security of the Website (e.g., protecting the contact forms or storing Your consent). They cannot be switched off
- Analytics: These technologies help Us collect aggregated statistics about traffic and how the Website is used, in order to improve its operation
- Marketing: These technologies are used to measure the effectiveness of Our advertising campaigns
13.3. List of Technologies Used
We do not load non-required technologies without Your prior, explicit consent. You can change Your choice at any time via the “Cookie settings” link at the bottom of the page.
| Name | Provider | Purpose | Type | Retention period | Legal basis |
|---|---|---|---|---|---|
| cookieyes-consent | CookieYes | Store Your consent choice and the consent ID under which the record of it is kept (in cookies and in local storage). | Required | 1 year | Legal obligation (Article 7(1) GDPR) |
| NEXT_LOCALE | The Website | Remembers the chosen language of the Website. | Required | Session (until the browser closes) | Legitimate interest |
| Vercel BotID | Vercel | Protects the contact form from automated attacks. | Required | Session (stores no data on the device) | Legitimate interest |
| Vercel Analytics | Vercel | Aggregated traffic statistics. | Analytics | Session (stores no data on the device) | Consent |
| startklar.ad-click | The Website | Stores ad click identifiers (GCLID and UTM parameters) to attribute an inquiry to the advertisement that led to it (Section 2). | Marketing | 90 days | Consent |
| _gcl_au, _gcl_aw, _gcl_gs | Measures advertising effectiveness (Google Ads). | Marketing | 90 days | Consent | |
| test_cookie | Checks whether Your browser accepts cookies. | Marketing | 15 minutes | Consent |
13.4. Demonstrating Consent
To meet Our accountability obligation under Article 7(1) of the GDPR, We keep a record (log) of every consent You give. This record includes the domain on which the consent was given, a partially masked (pseudonymous) IP address, the country derived from it, the date and time in UTC, a consent ID, and the categories You accepted or rejected. We keep this record for 5 years from the last change or withdrawal of the consent, for defense against potential legal claims.
14. Policy Updates
To keep this Privacy Policy up to date, it may be changed in whole or in part at any time without special notice. Please check this Policy periodically for updates. The date of the last update will be indicated below.
This Privacy Policy was adopted on July 18, 2026.
Last Updated: August 12, 2026.