Privacy Policy
Section I. General information
Art. 1 (1) The controller of your personal data is “Evebra” OOD (Evebra Ltd.), UIC 117625865, with registered office and mailing address at 14 Tsar Kaloyan Str., Ruse, Bulgaria, phone +359 877 977 737, email info@ecommercebg.com, operating the websites balkan.ecommercebg.com and balkanecommerce.com under the “eCommerce Academy” and “Balkan eCommerce Summit” brands (hereinafter “the Controller” or “the Company”).
(2) The Company has not designated a data protection officer, as its core activities do not consist of regular and systematic monitoring of data subjects on a large scale or of large-scale processing of special categories of data. All requests and questions concerning the processing of your personal data may be sent to info@ecommercebg.com or by post to the address under paragraph 1.
(3) The competent supervisory authority is the Commission for Personal Data Protection, with registered office and mailing address at 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, phone +359 2 915 3 518, email kzld@cpdp.bg, website www.cpdp.bg.
Art. 2 (1) The Company operates in accordance with the Personal Data Protection Act and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR). This Policy is intended to inform you about all aspects of the processing of your personal data by the Company and the rights you have in connection with this processing.
(2) This Policy forms an integral part of the General Terms and Conditions for participation in events organized by the Company and applies to website visitors, ticket holders, Merchant Pass applicants and holders, newsletter subscribers and all other persons who contact the Company.
Art. 3 When processing your personal data, the Company observes the following principles:
- Lawfulness, fairness and transparency: personal data are processed lawfully, fairly and in a transparent manner in relation to the data subject;
- Purpose limitation: personal data are collected for specified, explicit and legitimate purposes and are not further processed in a manner incompatible with those purposes;
- Data minimisation: personal data are adequate, relevant and limited to what is necessary for the purposes for which they are processed, and the Company applies anonymisation or pseudonymisation where possible to reduce the risks for the data subjects concerned;
- Accuracy: personal data are accurate and, where necessary, kept up to date, and inaccurate data are erased or rectified without delay, taking into account the purposes for which they are processed;
- Storage limitation: personal data are stored for no longer than is necessary for the purposes for which they are processed;
- Integrity and confidentiality: taking into account the state of the art, the cost of implementation and the likelihood and severity of the risks, the Company applies appropriate technical and organisational measures to ensure adequate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction, alteration, unauthorised access or disclosure;
- Accountability: the Company is responsible for, and able to demonstrate, compliance with the principles set out above.
Section II. Purposes, categories of data and legal grounds
Art. 4 (1) The Company processes your personal data on the following grounds under Art. 6(1) GDPR:
- your consent;
- the performance of a contract concluded with you by accepting the General Terms and Conditions, or steps taken at your request prior to entering into such a contract;
- compliance with a legal obligation to which the Company is subject, including obligations towards the National Revenue Agency, the Ministry of Interior and other public authorities;
- the legitimate interests of the Company or a third party, where such interests are not overridden by your interests or fundamental rights and freedoms;
(2) On these grounds, the Company processes personal data for the following purposes:
- Sale of tickets and registration for events; processing of Merchant Pass applications;
- Identification of the party to the contract and performance of the contract for the respective service;
- Accounting and tax purposes;
- Preparation of anonymised statistics;
- Documentation and promotion of the events;
- Protection of information security;
- Sending newsletters and emails with special offers, if you wish to receive them and responding to inquiries submitted through the contact form on the website.
Art. 5 (1) For the purchase of a ticket and registration for an event, the Company processes your name, email address, phone number, company and job title. The purpose is to conclude and perform the contract with you and to admit you to the event, and the legal ground is Art. 6(1)(b) GDPR.
(2) The website does not provide user profiles or registration through social network accounts. Attendees may, at their own choice, create a profile in the separate meeting-scheduling platform used for the event B2BMatch (or other similar), and the data entered there are processed under that platform’s terms and privacy policy. Creating such a profile is not required for attending the event.
(3) Card payments are processed by the payment service provider indicated at the time of payment, and the Company does not receive or store your full card data. Invoicing data (name or company name, UIC, VAT number and address) are processed to comply with the Company’s accounting and tax obligations on the ground of Art. 6(1)(c) GDPR.
(4) For Merchant Pass applications, the Company processes your full name, job title, contact phone number, online store domain, work email address, LinkedIn profile link and any other details marked as mandatory in the application questionnaire. Assessment of eligibility and issuance of the pass under Section VII of the General Terms and Conditions are carried out on the ground of Art. 6(1)(b) GDPR. Detection and prevention of misuse, including false, duplicate or third-party applications and resale of passes, are based on the Company’s legitimate interest under Art. 6(1)(f) GDPR. The Company does not use the data submitted in a Merchant Pass application for newsletters or other marketing communications unless you give separate consent under paragraph 7 of this Article, and neither the issuance of a pass nor admission to the event depends on such consent or on sharing your data with exhibitors or sponsors.
(5) For access control, the Company issues a badge containing your name, company, job title and a unique code, either in advance or at the registration desk at the venue. Admission takes place by scanning the code or by visual inspection of the badge, on the ground of Art. 6(1)(b) GDPR. Photographs and audio and video recordings made under Art. 14 of the General Terms and Conditions are used for documentation, media coverage and promotion of current and future editions of the event, on the ground of the Company’s legitimate interest under Art. 6(1)(f) GDPR.
(6) Requests for cancellation, refund or transfer of a ticket are processed together with your contact details, ticket data and, where a refund is due, the bank details you provide, for the performance of the contract on the ground of Art. 6(1)(b) GDPR.
(7) Newsletters and emails with special offers, promotions, news and new features are sent only to persons who have given their consent under Art. 6(1)(a) GDPR, using their name and email address.
(8) When you submit an inquiry through the contact form, the Company processes your name, email address and the content of the inquiry in order to respond. Where the inquiry concerns a ticket, a Merchant Pass or another contract with you, the ground is Art. 6(1)(b) GDPR. In all other cases, it is the Company’s legitimate interest in responding under Art. 6(1)(f) GDPR.
(9) Log file data (IP address, web browser used, time of visit and pages visited) are processed for the maintenance of the website, the security of personal data and the continuous security and operation of the website, including protection against cybercrime, on the ground of the Company’s legitimate interest under Art. 6(1)(f) GDPR.
(10) The Company has assessed the processing operations under this Article and, given the limited scope and nature of the data, has concluded that none of them is likely to result in a high risk requiring a data protection impact assessment under Art. 35 GDPR.
Art. 6 (1) The Company does not collect or process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data, data concerning health or data concerning a person’s sex life or sexual orientation.
(2) Personal data are collected directly from the persons to whom they relate. The only exception is the verification of Merchant Pass applications, during which the Company reviews the LinkedIn profile you have indicated and the publicly available website of the online store, using only the information on your current role and on the operation of the store.
(3) The Company does not take decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you. Every rejection of a Merchant Pass application is decided by an employee of the Company.
(4) The events and the services offered on the website are intended exclusively for persons who have reached the age of 18 and who act in a professional capacity. The Company does not knowingly collect or process personal data of minors, and where it establishes that such data have been provided, it erases them without undue delay and cancels the registration or the Merchant Pass concerned.
(5) Providing the data under Art. 5(1), (3), (4), (5) and (6) is a contractual or statutory requirement, and without it the Company cannot sell you a ticket, issue an invoice, process your Merchant Pass application or execute your request. Providing data for newsletters and inquiries is voluntary.
(6) The use of cookies and similar technologies on the website is governed by the Cookie Policy. Cookies that are not strictly necessary for the operation of the website are placed only with your consent, given through the cookie banner.
Section III. Retention periods
Art. 7 (1) The Company stores your personal data related to registration and participation for no longer than the end of the event for which you registered, unless a longer period applies under the following paragraphs. After that, the Company deletes and destroys the data without undue delay or anonymises them, bringing them into a form that does not reveal your identity.
(2) Data from approved Merchant Pass applications are stored under paragraph 1. Data from rejected or withdrawn applications are stored until the end of the respective edition of the event, and data evidencing misuse are stored until the expiry of the limitation period for the related claims. Data from applications placed on a waiting list are stored until the end of the respective edition.
(3) Data processed for newsletters are stored until you withdraw your consent or until 24 months have passed since your last interaction with the messages, whichever occurs first.
(4) For the protection of the Company’s legal interests in court or administrative disputes, data related to tickets and contracts are stored for the general limitation period of five years under Art. 110 of the Obligations and Contracts Act, counted from the end of the respective event. Accounting documents are stored for the periods set by the Accountancy Act.
(5) Where the applicable legislation requires the Company to keep certain data for a longer period, the data are stored for that period, which may exceed the end of the event. The Company notifies you if the retention period needs to be extended in order to fulfil a regulatory obligation or in view of its legitimate interests.
(6) Photographs and video recordings under Art. 5(5) are kept in the Company’s archive for a period of five years from the edition of the event at which they were made, after which they are deleted or anonymised. Materials that have already been published in the Company’s channels or in the media before the expiry of that period remain available there until you exercise your right to object under Art. 15.
(7) The Company keeps the personal data of the legal representatives of its business partners for the term of the respective contract and thereafter for as long as necessary to comply with its legal obligations and legitimate interests.
Section IV. Recipients and transfers of personal data
Art. 8 (1) The Company may transfer some or all of your personal data to processors acting on its behalf, for the purposes described in this Policy and under a data processing agreement meeting the requirements of Art. 28 GDPR.
(2) The list of recipients derives mainly from the services you use and the actions you take on the website, and includes the following categories:
- providers of technical support for the operation of the website, including email delivery and support in marketing campaigns;
- hosting, telephone and IT service providers;
- providers of ticketing, registration and badge printing software;
- payment service providers processing card payments on the website;
- the venue operator and security service providers, to the extent necessary for access control at the event;
- providers of accounting, legal and consulting services.
(3) Exhibitors and sponsors receive your personal data only when you choose to share it with them, in particular by presenting your badge for scanning at their stand, and they then process the data as independent controllers under their own privacy policies. Badge scanning by exhibitors is voluntary, and neither it nor any other sharing of data with them is a condition for attending the event or for obtaining a Merchant Pass.
(4) The Company provides personal data to the National Revenue Agency, the Ministry of Interior, courts and other public authorities only where it is required to do so by law.
Art. 9 (1) Art. 9 (1) Some of the tools the Company uses in its current activity may involve the transfer of your personal data to a country outside the European Economic Area, in particular to the United States of America. These are the analytics tools used on the website, the platform through which the Company sends newsletters and transactional emails, and the ticketing and registration software.
(2) Such transfers take place only on the basis of an adequacy decision of the European Commission, including the EU-US Data Privacy Framework adopted on 10 July 2023 for certified recipients, or of the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, which are incorporated into the terms of the respective provider.
(3) You may obtain a copy of the safeguards applied to a specific transfer by contacting the Company under Art. 1(2).
Section V. Your rights
Art. 10 (1) You may exercise your rights under this Section by a request sent under Art. 1(2), in any form that contains your request and identifies you as the data subject.
(2) Before acting on a request, the Company may ask you to verify your identity, including by presenting a unique identification code sent to the email address associated with your registration or to the address from which the request was submitted.
(3) The Company responds to your request within one month of its receipt. Where necessary, taking into account the complexity and number of requests, this period may be extended by two further months, and the Company informs you of the extension and the reasons for it within the first month.
(4) Exercising your rights is free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Company may charge a reasonable fee based on its administrative costs or refuse to act on the request.
Art. 11 (1) Where the processing is based on your consent, you may withdraw it at any time, in whole or for specific purposes, by a request in free text sent under Art. 1(2). Consent to newsletters and emails with special offers may also be withdrawn through the unsubscribe link included in each message.
(2) Withdrawal of consent does not affect the processing of data necessary for your ticket or Merchant Pass, which is based on the contract with you and continues for the periods under Art. 7.
(3) The withdrawal of consent does not affect the lawfulness of the processing carried out by the Company before the withdrawal.
Art. 12 (1) You have the right to obtain confirmation from the Company as to whether personal data concerning you are being processed and, where that is the case, to receive the information under paragraph 2.
(2) You have the right of access to your personal data and to information about the purposes, categories of data, recipients, retention periods, source of the data and your rights, which you may request under Art. 1(2).
(3) Upon request, the Company provides you with a copy of the personal data undergoing processing in electronic or other appropriate form, insofar as this does not adversely affect the rights of others.
(4) You may request the Company to correct or complete inaccurate or incomplete personal data concerning you, including the data printed on your badge.
(5) The Company communicates any rectification, erasure or restriction of processing to each recipient to whom your personal data have been disclosed, unless this proves impossible or involves disproportionate effort, and at your request informs you about those recipients.
Art. 13 (1) You have the right to request the erasure of some or all of your personal data, and the Company erases them without undue delay where one of the following grounds applies:
- the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
- you withdraw your consent on which the processing is based and there is no other legal ground for the processing;
- you object to the processing under Art. 15 and there are no overriding legitimate grounds for the processing, or you object to processing for direct marketing purposes;
- the personal data have been unlawfully processed;
- the personal data must be erased to comply with a legal obligation under EU law or the law of a Member State applicable to the Company;
- the personal data have been collected in relation to the offer of information society services directly to a child.
(2) The Company is not obliged to erase personal data to the extent that their processing is necessary:
- for exercising the right of freedom of expression and information;
- for compliance with a legal obligation under EU or Member State law applicable to the Company, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Company;
- for reasons of public interest in the area of public health;
- for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes;
- for the establishment, exercise or defence of legal claims.
(3) Upon erasure, the Company retains only the email address and the IP address from which the request was submitted, in order to certify that the request has been executed, for a period of one year from its execution, as well as technical information about the operation of the website that cannot be associated with you in any way.
(4) The request is submitted under Art. 1(2) and is executed after verification of your identity under Art. 10(2)
(5) Where a ticket or Merchant Pass has been issued to you for an upcoming event and you have not cancelled your participation, the data necessary for your admission are erased after the event.
(6) A profile created in the meeting-scheduling platform under Art. 5(2) is deleted directly in that platform or by a request to its provider, and the Company assists you where the deletion cannot be completed there.
Art. 14 (1) You have the right to request the Company to restrict the processing of your personal data where:
- you contest the accuracy of the personal data, for a period enabling the Company to verify their accuracy;
- the processing is unlawful, and you oppose the erasure of the data and request the restriction of their use instead;
- the Company no longer needs the personal data for the purposes of the processing, but you require them for the establishment, exercise or defence of legal claims;
- you have objected to the processing, pending verification of whether the legitimate grounds of the Company override your interests.
(2) Where the processing is based on your consent or on a contract with you and is carried out by automated means, you may receive your personal data in a structured, commonly used and machine-readable format and transmit them to another controller, or request the Company to transmit them directly to a controller designated by you where technically feasible. The request may be submitted under Art. 1(2).
Art. 15 You may object at any time, on grounds relating to your particular situation, to the processing of your personal data based on the legitimate interests of the Company, including the use of photographs and video recordings under Art. 5(5), in which case the Company stops the processing unless it demonstrates compelling legitimate grounds that override your interests, rights and freedoms or the processing is necessary for the establishment, exercise or defence of legal claims. Where your data are processed for direct marketing purposes, you may object at any time and the Company stops such processing without further assessment.
Section VI. Security, data breaches, complaints and final provisions
Art. 16 (1) The Company applies technical and organisational measures appropriate to the risks of the processing, including transmission of data through the website over an encrypted connection with deprecated protocols excluded, access to personal data granted to individually identified employees only to the extent required by their duties, and periodic backup copies whose integrity and recoverability are verified.
(2) Employees and contractors who have access to personal data are bound by confidentiality obligations and process the data only on the instructions of the Company. Processors under Art. 8(1) are selected on the basis of the guarantees they provide for the security of the processing, and their obligations are set out in the data processing agreement concluded with them.
(3) No measure eliminates every risk in the transmission of data over the internet. The Company cannot guarantee protection against attacks directed at your own device, email account or browser, and it recommends that the confirmation and the electronic ticket or Merchant Pass sent to you are not forwarded to third parties.
Art. 17 (1) Where the Company establishes a personal data breach that is likely to result in a high risk to your rights and freedoms, it notifies you without undue delay of the breach and of the measures taken or proposed to be taken.
(2) The notification under paragraph 1 is not required where:
- the Company has applied appropriate technical and organisational protection measures, such as encryption, that render the affected data unintelligible to any person not authorised to access them;
- the Company has subsequently taken measures ensuring that the high risk to your rights and freedoms is no longer likely to materialise;
- the notification would involve disproportionate effort, in which case the Company informs the affected persons through a public communication on the website.
Art. 18 If you consider that the processing of your personal data infringes this Policy or the applicable data protection legislation, you have the right to lodge a complaint with the Commission for Personal Data Protection at the contact details under Art. 1(3), without prejudice to your right to seek a judicial remedy.
Art. 19 (1) The Company may update this Policy. The current version is always published on the website, and persons registered for an upcoming event are notified by email of changes that affect the processing of their data.
(2) This version of the Policy is effective from 21.09.2026.

