Legal
Privacy Policy
This is a standard-form GDPR privacy policy template, not legal advice. It requires review by qualified legal counsel and completion of all bracketed placeholders before launch.
Last updated: 16 August 2026. This policy explains what personal data Fera Tartufi collects when you use this website or place an order, why we collect it, and what rights you have over it.
1. Data Controller
The data controller responsible for your personal data is [COMPANY LEGAL NAME — TBD], registered in Bulgaria under company number [EIK NUMBER — TBD], with registered address at [REGISTERED COMPANY ADDRESS — TBD].
For any question about this policy or to exercise your data protection rights, contact our data protection contact at [DPO / DATA PROTECTION CONTACT EMAIL — TBD] (in the meantime, general enquiries can be sent to hello@feratartufi.com).
2. What Personal Data We Collect
Account and order data: name, email address, phone number, billing and shipping address, and order history, provided when you place an order or contact us.
Payment data: we do not collect or store your card details. Payments are processed directly by our payment processor, Stripe, Inc. Stripe collects and processes your payment card information under its own privacy policy and security standards (PCI-DSS compliant).
Technical and usage data: IP address, browser type, device information, and pages visited, collected automatically via standard web server and hosting logs (see Section 6, Hosting).
Marketing data: your email address, if you opt in to our newsletter, used solely to send you marketing communications you have consented to receive.
3. Purpose and Legal Basis for Processing
Order fulfilment (name, address, order details): processed under Art. 6(1)(b) GDPR — necessary for the performance of a contract with you.
Customer service and dispute handling: processed under Art. 6(1)(b) GDPR and, where applicable, Art. 6(1)(f) — our legitimate interest in resolving issues and maintaining accurate records.
Marketing communications: processed under Art. 6(1)(a) GDPR — your explicit, opt-in consent, which you may withdraw at any time by unsubscribing.
Legal and accounting obligations (e.g. invoicing, tax records): processed under Art. 6(1)(c) GDPR — necessary for compliance with a legal obligation.
4. Data Retention
We retain order and invoicing data for the period required by Bulgarian accounting and tax law (generally [RETENTION PERIOD — TBD, typically 10 years for accounting records under Bulgarian law]).
Marketing consent data is retained until you unsubscribe or withdraw consent. Technical/log data is retained for a limited period for security and troubleshooting purposes before being deleted or anonymised.
5. Your Rights (GDPR Art. 15–22)
Subject to certain conditions and exceptions under GDPR, you have the right to: access the personal data we hold about you; request correction (rectification) of inaccurate data; request erasure ("right to be forgotten"); request restriction of processing; receive your data in a portable format (data portability); and object to processing based on legitimate interest or for direct marketing purposes.
To exercise any of these rights, contact us at [DPO / DATA PROTECTION CONTACT EMAIL — TBD]. We will respond within the timeframe required by GDPR (generally one month).
6. Third-Party Processors
Stripe, Inc. — payment processing. Stripe acts as an independent data controller for the payment data it collects; see Stripe's own privacy policy for details.
Vercel Inc. — website hosting and infrastructure. Vercel processes technical data (such as server logs and IP addresses) on our behalf as part of delivering this website.
We do not sell your personal data to third parties, and we only share data with processors to the extent necessary to operate this website and fulfil your orders.
8. International Data Transfers
Some of our processors (including Stripe and Vercel) may process data outside the European Economic Area. Where this occurs, it is carried out under appropriate safeguards, such as the European Commission's Standard Contractual Clauses or an equivalent adequacy mechanism.
9. Right to Complain
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни, "CPDP"), the supervisory authority for data protection in Bulgaria: https://www.cpdp.bg. You may also complain to the supervisory authority in your own EU member state of residence.