Privacy Policy — GrafixHost
Last updated: 2026-05-08
⚠️ The document below is a structural placeholder. Final content requires review by a licensed attorney before production cutover. Until finalized, this document is NOT legally binding.
This Privacy Policy describes how Grafix Solutions Ltd ("GrafixHost", "we") collects, processes, and protects the personal data of users of our services, in accordance with EU Regulation 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act.
1. Data Controller
Grafix Solutions Ltd, headquartered in Sofia, Bulgaria, EIK [placeholder], is the controller of your personal data. Contact: privacy@grafixhost.bg.
2. Data We Collect
Identification data (name, email, phone), payment data (processed by payment processors), billing data (address, registration number, VAT number), technical data (IP address, browser fingerprint, log files), service usage data (cPanel logs, resource metrics).
3. Legal Basis for Processing
We process personal data on the following grounds: (a) contract performance — to provide the Service; (b) legal obligation — for invoicing and accounting; (c) legitimate interest — for security, fraud prevention, and service quality; (d) consent — for marketing communication.
4. Retention Period
Data of active customers — for the duration of the contract + 30-day grace period. Invoice data — 10 years (accounting requirement). Log files — 90 days. Backup data of terminated accounts — 30 days.
5. Your Rights
You have the right to: (a) access your data; (b) correct inaccurate data; (c) erasure ("right to be forgotten"); (d) restriction of processing; (e) data portability; (f) object to processing; (g) lodge a complaint with the CPDP. Requests via privacy@grafixhost.bg, response within 30 days.
7. Third Parties
We share data with the following processors: Vercel (frontend hosting), Cloudflare (CDN), Stripe (payments), Resend (transactional email), Anthropic (AI chat — anonymized requests only). The list is maintained in /dpa.
8. Data Protection Officer (DPO)
Contact the DPO: dpo@grafixhost.bg. For complaints, you can also contact the Commission for Personal Data Protection (CPDP), Sofia, Bulgaria.
9. Changes to the Policy
Changes are published at /privacy with the last-updated date. Material changes are announced via email with at least 30 days notice.