Privacy policy
Last updated: dd.mm.yyyy
1. Who we are
This policy explains how GenCloud Ltd. processes personal data in connection with the cardlink.bg website, the app.cardlink.bg platform and the CardLink service.
- Data controller: GenCloud Ltd.
- Company ID (UIC): fill in company ID
- Address: Sofia 1510, Bulgaria, 47 Rezbarska Str., fl. 4
- Email for data-related questions: card@cardlink.bg
- Data Protection Officer: fill in name and email, if appointed
We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act.
2. In what capacity we process data
CardLink acts in two different capacities, and the difference matters:
- As a controller – for the data of Site visitors and of our Clients (the companies using the Platform). We determine the purposes and means of processing.
- As a processor – for the data of cardholders, which our Clients enter or collect through the Platform. In that case the respective Client is the controller and we act on its documented instructions under a data processing agreement (DPA).
If you are a cardholder with a question about your data, please contact first the company that issued your card.
3. What data we process
❂ Site visitors
- technical data: IP address, browser and device type, language, operating system;
- visit data: pages viewed, date and time, referrer;
- preferences stored in cookies – language and light/dark theme.
❂ Feedback form
- email address, phone number and the content of the message you send us.
❂ Platform Clients
- company data: name, company ID, address, billing details;
- contact person data: name, email, phone, position;
- account data: username, hashed password, roles and permissions;
- access and activity logs from the Platform;
- payment data and issued documents.
❂ Cardholders (processed on behalf of the Client)
- identification data: name, cardholder code;
- contact data: email, phone;
- at the Client's discretion – date of birth, gender, city and other fields configured in the card project;
- card data: type, status, validity, accumulated bonus points, transaction and activation history.
We do not collect bank card data. Payments are handled by licensed payment service providers.
4. Purposes and legal bases
| Purpose | Basis under Art. 6 GDPR |
|---|---|
| Providing the Service and performing a contract | Art. 6(1)(b) – performance of a contract |
| Account registration and support | Art. 6(1)(b) |
| Replying to enquiries via the feedback form | Art. 6(1)(b) and (f) – legitimate interest |
| Issuing and updating cards in Apple/Google Wallet | Art. 6(1)(b) / Client instructions |
| Accounting and tax obligations | Art. 6(1)(c) – legal obligation |
| Security, abuse prevention, logging | Art. 6(1)(f) – legitimate interest |
| Functional cookies for language and theme | Art. 6(1)(f) – legitimate interest |
| Marketing messages to Clients | Art. 6(1)(a) – consent |
5. Recipients of the data
Data may be shared with:
- Apple Inc. and Google LLC – to the extent necessary to issue and update the card in the respective wallet;
- Cloudflare, Inc. – hosting and protection of the Site and the Platform;
- email and SMS providers – for sending messages to cardholders;
- payment service providers – when the payment subsystem is used;
- accounting, legal and audit advisers;
- public authorities – only where required by law.
All our providers are bound by agreements ensuring a level of protection consistent with the GDPR. We do not sell personal data.
6. Transfers outside the EU
Some of our providers (Apple, Google, Cloudflare) also process data outside the European Economic Area. Such transfers take place on the basis of the European Commission's standard contractual clauses or an adequacy decision.
7. Retention periods
- feedback form data – up to 12 months after the communication ends;
- Client account data – for the term of the contract and up to 12 months after its termination;
- accounting documents – 10 years under the Bulgarian Accountancy Act;
- access and security logs – up to 12 months;
- cardholder data – as instructed by the Client acting as controller; upon termination of the contract it is returned or deleted within 60 days.
8. Your rights
As a data subject you have the right to:
- access the data processed about you and receive a copy of it;
- rectification of inaccurate or incomplete data;
- erasure (the "right to be forgotten");
- restriction of processing;
- data portability in a structured, machine-readable format;
- object to processing based on legitimate interest;
- withdraw consent at any time, without affecting the lawfulness of processing carried out until then.
Exercise your rights at card@cardlink.bg. We respond within one month, which may be extended by a further two months in complex cases — we will notify you if so.
9. Complaints
If you believe your rights have been infringed, you may lodge a complaint with:
Commission for Personal Data Protection
Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd., Bulgaria
cpdp.bg · kzld@cpdp.bg
10. Security
We apply technical and organisational measures, including encryption of the connection (TLS), password hashing, role-based access to data, action logging, regular backups and access control over our infrastructure. Nevertheless, no method of transmission over the internet is completely secure.
11. Automated decision-making
We do not carry out automated decision-making producing legal effects for you, including profiling within the meaning of Art. 22 GDPR.
12. Children
The Service is not directed at persons under 16 years of age. If we learn that we have received a child's data without the consent of the holder of parental responsibility, we will delete it.
13. Changes to this policy
This policy may be updated. We publish the current version at this address with a new last-updated date, and we notify our Clients by email of material changes.
See also the Cookies policy and the Terms of use.