MSOFTMAYABack to website ↗

Legal centre

Terms & ConditionsPrivacy PolicyGDPR PolicyCookie PolicyAcceptable Use

Legal

GDPR Policy

Effective: 30 July 2026 · Last updated: 30 July 2026

Softmaya is committed to responsible personal-data processing in accordance with the EU General Data Protection Regulation and applicable Bulgarian data-protection law.

1. Data-protection principles

  • Lawfulness, fairness and transparency.
  • Purpose limitation and data minimisation.
  • Accuracy and appropriate retention limitation.
  • Integrity, confidentiality and accountability.
  • Privacy by design and by default where appropriate.

2. Roles and customer programmes

For our own website, sales, supplier and corporate operations, Softmaya normally acts as controller.

For personal data processed through a customer’s white-label programme, the customer will generally determine the purposes and means of processing and act as controller, while Softmaya may act as processor. The precise roles, instructions, categories of data, security requirements and assistance duties are defined in the applicable service agreement and data processing agreement.

Customers remain responsible for ensuring that their programme, notices, consents, reward rules and data collection have a valid legal basis.

3. Governance

  • Maintain records and policies proportionate to processing risk.
  • Limit personal-data access according to role and business need.
  • Use confidentiality obligations and data-protection awareness measures.
  • Assess relevant service providers and contractually protect entrusted data.
  • Review higher-risk processing and carry out impact assessments where required.

4. Data-subject requests

Softmaya maintains a process for receiving, verifying and responding to requests within applicable time limits. When acting as a processor, we assist the relevant customer controller in accordance with the service agreement and do not independently determine the outcome of a request.

5. Security and incidents

We use risk-appropriate technical and organisational measures intended to protect confidentiality, integrity, availability and resilience. Measures may include access controls, encryption where appropriate, monitoring, backups, change controls and incident procedures.

Suspected personal-data breaches are assessed without undue delay. Where Softmaya acts as processor, we notify the controller in accordance with the agreed process. Controllers remain responsible for regulator and data-subject notification decisions unless the parties agree otherwise.

6. Sub-processors and transfers

Where processors or sub-processors are engaged, we use written terms that impose appropriate data-protection obligations. Restricted international transfers are supported by a valid transfer mechanism and supplementary measures where required.

7. Contact

GDPR questions, requests and incident notifications relating to Softmaya’s own processing may be directed to info@softmaya.com. Requests about a customer-branded programme should normally be sent first to the relevant programme operator.

Softmaya LTDStefan Verkovich str. 10, Plovdiv 4000, Bulgariainfo@softmaya.com
© 2026 Softmaya LTD. All rights reserved.