Privacy policy
This policy explains what personal data we collect when you order food through our site, why we collect it, on what legal basis, how long we keep it, who we share it with and what rights you have. We process only the data we need in order to make and deliver your order.
1. Who processes your data
1.1. The controller within the meaning of Article 4(7) GDPR is:
| Controller | „Ив Корект 69“ ООД |
|---|---|
| Company number (EIK) | 204403142 |
| Registered seat and address | България, гр. Бургас 8000, ж.к. „Меден рудник“, бл. 601, вх. 1, ет. 4, ап. 16 |
| Establishment | RUM Rezvaya, Meden Rudnik, Burgas |
| Phone | 0875 40 45 45 |
| Email for data protection matters | contact@pizza-rezvaya.bg |
| Website | https://pizza-rezvaya.bg |
1.2. The controller is not required to appoint a data protection officer under Article 37 GDPR, as it does not carry out large-scale systematic monitoring and does not process special categories of data on a large scale. All data protection matters should be addressed to the contacts above.
1.3. This policy applies to the processing of personal data when using the online ordering platform, when ordering by phone, when communicating with us about an order or a complaint, and to the optional game on the site (clause 2.4). Cookie information is in the Cookie policy.
2. What personal data we process
2.1. We process only data you provide to us, plus a limited set of technical data generated when you use the site. We do not process special categories of personal data under Article 9 GDPR. Information about dietary preferences or intolerances, which may in itself concern health, is processed only if you expressly tell us, and solely in order to fulfil that specific order.
| Category | Specific data | Source |
|---|---|---|
| Account and sign-in data | email address; one-time sign-in code; records of acceptance of the terms | from you |
| Contact data | name, phone number | from you |
| Delivery data | delivery address (street, number, entrance, floor, flat) and its geographic coordinates; saved addresses, if you chose to save them | from you, via address search |
| Order data | order number, contents (items, sizes, added and removed ingredients), total amount, fulfilment method (delivery or pickup), chosen time, status, payment method and status | generated by the order |
| Loyalty programme data | points accrued and the events crediting them, where the programme is active | generated by the order |
| Correspondence | the content of messages and complaints you send us, and our replies | from you |
| Technical data | session identifier (the rz_session cookie); irreversibly hashed IP address; a truncated browser identifier (user agent); sign-in date and time | generated automatically |
| Consent records | date, time, email address, type and version of the document accepted — for acceptance of the terms at registration and for each order, and for marketing consent | generated by the action |
| Marketing data | email address and consent status, only if you ticked the box | from you |
2.2. Phone orders. When you order by phone, a member of staff enters your name, phone number and delivery address into the system so that the order can be fulfilled. This data is stored linked to your phone number so that you do not have to dictate it again next time. Phone calls are not recorded.
2.3. We do not store passwords — sign-in uses a one-time email code only. We do not store bank card data — for payment on receipt, card data is handled by the acquiring bank’s POS terminal, and for online payment, where active, by a licensed payment service provider.
2.4. Game and leaderboard on the public pages. An optional game is available on the public pages of the site. It is unrelated to ordering and requires no account. If you choose to save a score, the nickname you enter and your points are stored in a separate database hosted by Supabase and shown in a public leaderboard. The legal basis is your consent — Article 6(1)(a) GDPR, expressed by voluntarily entering a nickname. Please do not enter your real name or other identifying details, as the nickname is publicly visible. The record is kept for as long as the leaderboard is maintained and is deleted on your request using the contacts in Section 1. If you do not enter a nickname, nothing is stored.
3. Purposes, legal bases and retention periods
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Accepting, preparing, delivering and settling the order; contacting you about it | name, phone, email, address and coordinates, order contents | Art. 6(1)(b) — performance of a contract | until the order is fulfilled; thereafter in order history — until you delete your account, or until the accounting periods below expire |
| Creating and maintaining an account; sign-in by one-time code; saved addresses | email, name, phone, saved addresses, session | Art. 6(1)(b) — performance of a contract | until you delete your account; the session — up to 365 days from the last sign-in; the sign-in code expires on use or after 10 minutes |
| Handling complaints and settling claims | order data, correspondence, evidence supplied | Art. 6(1)(b) and (c); Art. 6(1)(f) — defence of legal claims | up to 5 years from closure of the case (the general limitation period) |
| Issuing and keeping payment documents; accounting and tax reporting | data in the sales document, invoicing details where requested | Art. 6(1)(c) — legal obligation | for the periods set by the Accountancy Act and the Tax and Social Insurance Procedure Code — up to 10 years for accounting registers and financial statements |
| Security of the service: rate limiting, preventing abuse of sign-in codes and preventing fake orders | hashed IP address, session identifier, user agent, number of attempts | Art. 6(1)(f) — legitimate interest in protecting the service and our customers | until the session expires; rate-limiting records for a short technical period, usually up to 24 hours |
| Demonstrating acceptance of the terms and consents given | consent records | Art. 6(1)(c) read with Art. 7(1) GDPR — obligation to demonstrate consent | up to 5 years after the last interaction |
| Sending promotional messages by email | email, name | Art. 6(1)(a) — consent | until consent is withdrawn |
| Loyalty programme, where active | account identifier, points, accrual events | Art. 6(1)(b) — performance of the programme terms | until the account is deleted or the programme ends |
3.1. Once the applicable period expires, data is deleted or irreversibly anonymised. Where data serves more than one purpose, it is kept until the longest applicable period expires.
3.2. When you delete your account we erase your sign-in data, saved addresses and the link between the account and previous orders. The orders themselves remain in the system with the data needed to meet accounting and tax obligations, but without any link to the deleted account. Access by one-time code ends immediately.
4. Whether providing data is mandatory
4.1. Providing an email address, name and phone number — and, for delivery, an address — is necessary to conclude and perform the contract. If you do not provide this data we cannot accept and fulfil your order. Providing it is not a statutory obligation but a contractual requirement.
4.2. Consent to receive promotional messages is entirely voluntary. Refusing or withdrawing it does not affect your ability to order and has no adverse consequences.
5. Recipients and processors
5.1. We do not sell or rent personal data. We do not provide data to third parties for their own marketing purposes. Data is disclosed only to the following categories of recipient and only to the extent necessary:
| Recipient | Role | Data |
|---|---|---|
| Staff at the establishment — kitchen, counter, delivery | under our authority | name, phone, address, order contents — for current orders only |
| Hosting and database provider in the EU | processor | all data stored on the platform |
| Resend — transactional email provider | processor | email address and message content — sign-in code, confirmations |
| Google — Places service (address search and validation) | independent controller for its own services | the address text you enter, sent from our server; the request does not include your name, phone or email |
| Google — embedded map and web fonts loaded by your browser | independent controller for its own services | your IP address and browser data, provided directly by your device |
| Supabase — game leaderboard database | processor | nickname and score, only if you chose to save a score (clause 2.4) |
| Accounting services | processor | data in sales and invoicing documents |
| Courier company — only where delivery is by courier | independent controller or processor, as the case may be | name, phone, address, amount payable on cash on delivery |
| Payment service provider — only where online payment is active | independent controller for the payment transaction | amount, order identifier and the data you enter in its secure environment |
| Competent authorities, lawyers, courts | recipients under the law | only where legally required or to defend rights, to the extent necessary |
5.2. Data processing agreements under Article 28 GDPR are in place, or are being put in place, with our processors, requiring them to process data only on our instructions, to ensure an appropriate level of security and not to use the data for their own purposes.
6. Transfers outside the EU/EEA
6.1. Platform data is stored on servers in the European Union. Some of the services we use, however, are provided by companies established in third countries, mainly the United States — our transactional email provider and Google’s services.
6.2. Where a transfer to a third country takes place, it is made under Chapter V GDPR — on the basis of a European Commission adequacy decision, including the EU–U.S. Data Privacy Framework for organisations certified under it, and/or on the basis of standard contractual clauses under Article 46 GDPR, accompanied where necessary by supplementary technical and organisational measures.
6.3. A copy of the applicable safeguards can be requested using the contacts in Section 1.
7. Security measures
7.1. We apply technical and organisational measures under Article 32 GDPR, appropriate to the risk to data subjects’ rights. The main ones are:
- encrypted transmission between your browser and our server (HTTPS/TLS);
- the session cookie is inaccessible to scripts (HttpOnly), sent only over a secure connection (Secure) and restricted by origin (SameSite);
- no passwords — sign-in uses a short-lived one-time code with a limited number of attempts;
- irreversible hashing of IP addresses used for security purposes — we do not store IP addresses in clear;
- rate limiting of sign-in code requests and of orders, to prevent abuse;
- protection against cross-site request forgery by verifying the origin of each request;
- role-based staff access through separate staff accounts with a shorter session lifetime;
- data minimisation — we do not collect dates of birth, national identity numbers, card data or other unnecessary data;
- audit logs of administrative actions;
- storage with providers in the EU and regular backups.
7.2. No measure provides absolute security. In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify you and the Bulgarian Commission for Personal Data Protection (CPDP) within the periods set by Articles 33 and 34 GDPR.
8. Automated decision-making and profiling
8.1. We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. We do not carry out profiling for advertising purposes.
8.2. The only automated checks are the following technical ones, which do not constitute a decision under Article 22 GDPR: whether the address entered falls within the delivery zone, whether the establishment is open and which delivery slots are available, and rate limiting. If such a check produces a negative result you can order by phone and receive assistance from a member of staff.
9. Your rights
9.1. As a data subject you have the following rights:
- Right of access — Article 15 GDPR
- to obtain confirmation whether we process your data, a copy of it and information about the processing.
- Right to rectification — Article 16 GDPR
- to correct inaccurate and complete incomplete data. You can edit your name, phone, email address and saved addresses yourself in the Account section.
- Right to erasure (right to be forgotten) — Article 17 GDPR
- to request erasure where the data is no longer necessary for the purposes for which it was collected, where you withdraw consent and there is no other basis, or where the data has been processed unlawfully. You can delete your account yourself at any time. The right does not extend to data we are required by law to retain — such as accounting documents — or where the data is needed to defend legal claims.
- Right to restriction of processing — Article 18 GDPR
- to have processing restricted while the accuracy of the data is verified, in cases of unlawful processing instead of erasure, or while your objection is being considered. Restricted data is stored but not otherwise used.
- Right to data portability — Article 20 GDPR
- to receive the data you provided to us in a structured, commonly used and machine-readable format and to transmit it to another controller, where processing is based on consent or on a contract and is carried out by automated means.
- Right to object — Article 21 GDPR
- to object to processing based on legitimate interests. Where you object to processing for direct marketing, we stop immediately and unconditionally.
- Right to withdraw consent — Article 7(3) GDPR
- to withdraw consent at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of processing before it.
- Right to lodge a complaint — Article 77 GDPR
- to lodge a complaint with the supervisory authority — see Section 11.
- Right not to be subject to an automated decision — Article 22 GDPR
- as stated in Section 8, we do not take such decisions.
10. How to exercise your rights
10.1. You can exercise your rights:
- yourself in your account — viewing and editing your data, managing saved addresses, deleting your account;
- by email — contact@pizza-rezvaya.bg;
- by phone — 0875 40 45 45;
- in person at the establishment: RUM Rezvaya, Meden Rudnik, Burgas;
- by post to the registered address in Section 1.
10.2. We respond without undue delay and no later than one month of receiving your request. For complex or numerous requests the period may be extended by a further two months, in which case we will inform you of the extension and the reasons for it — Article 12(3) GDPR.
10.3. Exercising your rights is free of charge. For manifestly unfounded or excessive requests, including repetitive ones, we may charge a reasonable fee or refuse to act, giving our reasons.
10.4. To protect your data against unauthorised disclosure, where there is reasonable doubt about the identity of the person making the request we may ask for additional identifying information — for example confirmation with a code sent to the email address linked to the account.
11. Right to lodge a complaint
11.1. If you believe that the processing of your personal data infringes the law, you have the right to lodge a complaint with:
| Supervisory authority | Bulgarian Commission for Personal Data Protection (CPDP) |
|---|---|
| Address | 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria |
| Phone | 02 915 3 518 |
| kzld@cpdp.bg | |
| Website | www.cpdp.bg |
11.2. You also have the right to a judicial remedy before the competent Bulgarian court, regardless of any complaint to the supervisory authority.
12. Children’s data
12.1. The service is intended for individuals aged 18 or over. We do not knowingly collect children’s data. If we establish that an account was created by a child, we will delete the associated data. A parent or guardian may request deletion of such data using the contacts above.
13. Cookies
13.1. Information on the cookies and similar technologies used, their lifetimes and how to manage and withdraw consent is available in the Cookie policy.
14. Changes to this policy
14.1. We may update this policy following changes to our services, our providers or applicable law. The current version is published at this address, stating its effective date.
14.2. Where changes materially affect the processing of your data we will notify you by an appropriate means — a notice on the site or an email. Where a change requires your consent we will request it separately, before the relevant processing begins.
14.3. This version is effective from 30 August 2026.