Legal Document

Privacy Policy

Updated: 3/2/2026ID: LGL-002

1) Who we are (Controller)

Carica Trading EOOD, UIC 207080428, VAT BG207080428, address: zh.k. Belite brezi, bl. 11, fl. 13, ap. 55, Bulgaria. Trading names: Carica Web, Carica Finance. Covered websites/apps: www.carica.website and finance.carica.website. Main establishment: Bulgaria (EU). Data protection contact: support@carica.website. No Data Protection Officer (DPO) appointed.

#2) Scope and roles (Controller/Processor)

We act as a Controller for: our marketing websites, sign-up/login and central account, correspondence/support, our own invoicing and accounting, security and audit logs.

We act as a Processor within Carica Finance for our business clients’ end-customer data. The client is the Controller for such data and provides instructions. Our access is limited to what is necessary for support or upon the client’s explicit request and is logged. A Data Processing Agreement (DPA) is available on request.

#3) Who our services are for

Our services are B2B and not intended for individuals under 18. We do not knowingly collect children’s data.

#4) What data we process

Account & authentication: email and password (or SSO where available), roles (user, active subscriber, administrator), subscription status, log/audit records.

Billing & customer profiles (as Controller): names, company details, UIC, VAT No., addresses, country, contact details. Payments and subscriptions are processed by Stripe; we do not store full card details.

Carica Finance (as Processor): data contained in documents (invoices, credit notes, quotes, etc.) such as names, addresses, VAT/registration numbers, line item descriptions, quantities, amounts, IBAN where present, dates, and aggregated document statistics. We perform VIES VAT checks sending only the necessary attributes.

Support & meetings: content and metadata from email/ticket correspondence; meetings by default via Google Meet (or another channel chosen by the client).

Technical & security data: IP addresses, session/device identifiers, browser and OS information, time zone, error/crash logs. Used for authentication, security, and limiting spam or attacks. We do not request or aim to process special categories of data under Art. 9 GDPR. If a client enters such data in free text, this is at their discretion and responsibility as Controller.

#5) Purposes and legal bases

We process data to: provide and maintain the service, accounts and access - performance of a contract and/or our legitimate interests; communicate and provide support — performance of a contract and/or legitimate interests; billing, accounting and tax — compliance with legal obligations; security, abuse and incident prevention — legitimate interests; analytics — only with valid consent in EEA countries.

#6) Cookies, local storage and analytics

We use strictly necessary cookies for secure sign-in and session maintenance. For analytics we use Google Analytics (GA4), which loads only after explicit consent in EEA countries. You can withdraw consent at any time via the cookie settings. We do not run behavioural advertising and do not “share” personal data for such purposes.

#7) Processing and storage location

Our infrastructure runs on Google Cloud/Firebase. We aim to process and store data within the EU/EEA. We maintain separate environments (dev/test/prod) and backups as needed for the service.

#8) Recipients and subprocessors

We do not sell personal data and do not “share” it for targeted advertising. We disclose data only when necessary to: cloud infrastructure and related service providers (e.g. Google Cloud/Firebase) for hosting, databases, file storage and authentication; payment provider (Stripe) for subscriptions and payments; email/support tooling providers when needed for correspondence and ticket handling; consultants/legal and accounting partners where legally required; and competent authorities where required by law. We sign Art. 28 GDPR agreements with each subprocessor and require appropriate technical and organisational measures. An up-to-date list is available on request.

#9) International transfers

We strive to process data within the EU/EEA. In certain cases limited transfers outside the EEA may occur (e.g. to a vendor’s group entity for 24/7 support). In such cases we rely on recognised safeguards such as Standard Contractual Clauses (SCCs) and/or the vendor’s participation in the EU–US Data Privacy Framework, together with supplementary technical and organisational measures.

#10) Security

We apply technical and organisational measures, including: encryption in transit and at rest; least-privilege access control; MFA and/or SSO for staff; endpoint protection; logging and monitoring; vulnerability management and periodic penetration testing; staff training; incident response procedures; environment segregation and backups.

#11) Your rights

You have the right of access, rectification, erasure (“right to be forgotten”), restriction, objection, data portability, and the right to withdraw consent (where processing is based on consent). To exercise your rights: contact us at support@carica.website or submit a verified request after signing in. We may request additional verification for certain requests. We generally respond within 30 days, extendable in line with the GDPR for complex requests.

#12) Retention periods

Accounts and profiles are kept for the duration of the contract/active account and up to 24 months after deactivation for rights protection and audit, unless earlier deletion is requested and does not conflict with legal obligations.

Content in Carica Finance (as Processor) is retained per the client-Controller’s instructions; for terminated or unpaid plans we may delete data within up to 12 months after deactivation, providing reasonable notice and an opportunity to request an export.

Accounting and tax records (as Controller) are retained per applicable law, typically 10 years. Security/access logs are kept 12–24 months. Support tickets and correspondence are kept up to 24 months after closure unless needed longer to establish, exercise or defend legal claims. Marketing lists are kept until you unsubscribe; we then keep your address in a suppression list for a limited period to honour your choice.

#13) Communications and marketing

We send transactional, service-related emails (e.g. security, invoices and notifications). Marketing emails are sent with valid consent or under permitted “soft” legitimate interest to existing customers, always with an easy opt-out. New subscriptions use double opt-in confirmation.

#14) Automated decision-making

We do not carry out automated decision-making with legal or similarly significant effects on data subjects, and we do not perform profiling beyond aggregated analytics to improve the services.

#15) Disclosures required by law

We may disclose personal data when required by applicable law or a competent authority, limiting the scope to the minimum necessary.

#16) Complaints to a supervisory authority

You have the right to lodge a complaint with the Bulgarian data protection authority - the Commission for Personal Data Protection (CPDP) — or with your local supervisory authority in the EU.

#17) Changes to this policy

We reserve the right to update this policy. For material changes, we will notify you via a clear notice on the site and/or by email. The current version and effective date are published at the top of this page.

#18) Contact

For questions about this policy or our processing of personal data, contact us at support@carica.website.