Skip to content

Privacy policy


Last updated: dd.mm.yyyy

1. Who we are

This policy explains how GenCloud Ltd. processes personal data in connection with the cardlink.bg website, the app.cardlink.bg platform and the CardLink service.

  • Data controller: GenCloud Ltd.
  • Company ID (UIC): fill in company ID
  • Address: Sofia 1510, Bulgaria, 47 Rezbarska Str., fl. 4
  • Email for data-related questions: card@cardlink.bg
  • Data Protection Officer: fill in name and email, if appointed

We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act.

2. In what capacity we process data

CardLink acts in two different capacities, and the difference matters:

  • As a controller – for the data of Site visitors and of our Clients (the companies using the Platform). We determine the purposes and means of processing.
  • As a processor – for the data of cardholders, which our Clients enter or collect through the Platform. In that case the respective Client is the controller and we act on its documented instructions under a data processing agreement (DPA).

If you are a cardholder with a question about your data, please contact first the company that issued your card.

3. What data we process

❂ Site visitors

  • technical data: IP address, browser and device type, language, operating system;
  • visit data: pages viewed, date and time, referrer;
  • preferences stored in cookies – language and light/dark theme.

❂ Feedback form

  • email address, phone number and the content of the message you send us.

❂ Platform Clients

  • company data: name, company ID, address, billing details;
  • contact person data: name, email, phone, position;
  • account data: username, hashed password, roles and permissions;
  • access and activity logs from the Platform;
  • payment data and issued documents.

❂ Cardholders (processed on behalf of the Client)

  • identification data: name, cardholder code;
  • contact data: email, phone;
  • at the Client's discretion – date of birth, gender, city and other fields configured in the card project;
  • card data: type, status, validity, accumulated bonus points, transaction and activation history.

We do not collect bank card data. Payments are handled by licensed payment service providers.

PurposeBasis under Art. 6 GDPR
Providing the Service and performing a contractArt. 6(1)(b) – performance of a contract
Account registration and supportArt. 6(1)(b)
Replying to enquiries via the feedback formArt. 6(1)(b) and (f) – legitimate interest
Issuing and updating cards in Apple/Google WalletArt. 6(1)(b) / Client instructions
Accounting and tax obligationsArt. 6(1)(c) – legal obligation
Security, abuse prevention, loggingArt. 6(1)(f) – legitimate interest
Functional cookies for language and themeArt. 6(1)(f) – legitimate interest
Marketing messages to ClientsArt. 6(1)(a) – consent

5. Recipients of the data

Data may be shared with:

  • Apple Inc. and Google LLC – to the extent necessary to issue and update the card in the respective wallet;
  • Cloudflare, Inc. – hosting and protection of the Site and the Platform;
  • email and SMS providers – for sending messages to cardholders;
  • payment service providers – when the payment subsystem is used;
  • accounting, legal and audit advisers;
  • public authorities – only where required by law.

All our providers are bound by agreements ensuring a level of protection consistent with the GDPR. We do not sell personal data.

6. Transfers outside the EU

Some of our providers (Apple, Google, Cloudflare) also process data outside the European Economic Area. Such transfers take place on the basis of the European Commission's standard contractual clauses or an adequacy decision.

7. Retention periods

  • feedback form data – up to 12 months after the communication ends;
  • Client account data – for the term of the contract and up to 12 months after its termination;
  • accounting documents – 10 years under the Bulgarian Accountancy Act;
  • access and security logs – up to 12 months;
  • cardholder data – as instructed by the Client acting as controller; upon termination of the contract it is returned or deleted within 60 days.

8. Your rights

As a data subject you have the right to:

  • access the data processed about you and receive a copy of it;
  • rectification of inaccurate or incomplete data;
  • erasure (the "right to be forgotten");
  • restriction of processing;
  • data portability in a structured, machine-readable format;
  • object to processing based on legitimate interest;
  • withdraw consent at any time, without affecting the lawfulness of processing carried out until then.

Exercise your rights at card@cardlink.bg. We respond within one month, which may be extended by a further two months in complex cases — we will notify you if so.

9. Complaints

If you believe your rights have been infringed, you may lodge a complaint with:

Commission for Personal Data Protection
Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd., Bulgaria
cpdp.bg · kzld@cpdp.bg

10. Security

We apply technical and organisational measures, including encryption of the connection (TLS), password hashing, role-based access to data, action logging, regular backups and access control over our infrastructure. Nevertheless, no method of transmission over the internet is completely secure.

11. Automated decision-making

We do not carry out automated decision-making producing legal effects for you, including profiling within the meaning of Art. 22 GDPR.

12. Children

The Service is not directed at persons under 16 years of age. If we learn that we have received a child's data without the consent of the holder of parental responsibility, we will delete it.

13. Changes to this policy

This policy may be updated. We publish the current version at this address with a new last-updated date, and we notify our Clients by email of material changes.

See also the Cookies policy and the Terms of use.