OTPBlue EOOD (ОТПБлу ЕООД), UIC 208811476, VAT BG208811476, with registered address at 1000 Sofia, Sredets district, 4 Hristo Belchev Street, floor 1, Bulgaria, is the controller where it determines the purposes and means of processing.
We have not appointed a Data Protection Officer. Questions about privacy or the exercise of your rights can be sent to legal@otpblue.bg.
We act as controller for website visitors, business contacts, enquiries, and our own commercial and compliance records.
After service launch, where OTPBlue routes voice or delivers messages solely on a customer’s documented instructions, OTPBlue may act as that customer’s processor for the relevant traffic data. Those arrangements are governed by the customer contract and data-processing terms.
Contact and rate requests: full name, company, business email, selected area of interest, traffic details, the language used, and correspondence relating to the enquiry.
Technical and security data: IP address, user-agent information, timestamps, requested URLs, and diagnostic or security events processed through Cloudflare when you access the site or submit the form.
Cookie preference: whether this browser has dismissed the strictly necessary cookie information notice.
We do not use analytics, advertising, profiling, tracking pixels, or marketing cookies on this site.
4. Required and optional information
Full name, company, business email, area of interest, and traffic details are required to submit the form because we need them to understand and answer the request. If required information is not provided, the form cannot be submitted; you may instead email info@otpblue.bg.
Please do not include message content, call content, identity documents, payment-card data, special-category data, or other sensitive personal information in the traffic-details field.
5. Purposes and legal bases
We process enquiries and business correspondence to respond, prepare tailored rates, and pursue a potential business relationship. The legal basis is our legitimate interest in developing and managing B2B relationships and, where applicable, steps requested before entering a contract (GDPR Articles 6(1)(f) and 6(1)(b)).
We process technical and security data to deliver, protect, troubleshoot, and prevent abuse of the website. The legal basis is our legitimate interest in maintaining a secure and reliable service (Article 6(1)(f)).
We use a first-party preference cookie to remember when you dismiss the cookie notice so it is not repeatedly displayed. Storing this preference is exempt from consent under Article 5(3) of Directive 2002/58/EC and Article 4a(4) of the Bulgarian Electronic Commerce Act because it is necessary to provide the site preference you explicitly request by dismissing the notice. To the extent the preference constitutes personal data, our legal basis is our legitimate interest in respecting that preference and operating the site appropriately (GDPR Article 6(1)(f)).
We may process records to comply with tax, accounting, regulatory, or lawful authority requirements (Article 6(1)(c)), and to establish, exercise, or defend legal claims (Article 6(1)(f)).
Unsuccessful enquiries are retained for up to 12 months after the last meaningful contact, unless a longer period is needed for a legal claim or required by law. If a business relationship begins, related records are retained for the relationship and the applicable statutory accounting, tax, and limitation periods.
Resend retains email delivery records for 30 days. Cloudflare technical and security data is retained according to the configured service settings and only for as long as needed for delivery, security, diagnostics, or a legal obligation.
The cookie-notice preference expires after 180 days, unless you delete it sooner.
7. Traffic data after service launch
When services commence, messaging and voice traffic metadata will be retained for six months where Article 251b of the Bulgarian Electronic Communications Act applies, then destroyed unless another legal basis requires otherwise. Message content will not be stored beyond delivery, and voice calls will not be recorded.
The precise roles, instructions, data categories, retention, and security measures for customer traffic will be documented in the relevant customer and data-processing agreements.
Personal data may be handled by Cloudflare for hosting, delivery, and security; Resend for delivery of contact-form email; and professional advisers or service providers that support our business under appropriate confidentiality and data-processing terms.
After service launch, delivery suppliers and carriers may receive the minimum traffic data needed to provide the contracted service. We may disclose data to a competent authority when a valid legal requirement applies. We do not sell personal data.
9. International transfers
Cloudflare operates a global network, and Resend is a US-based provider. Where personal data is transferred outside the European Economic Area, we rely on an applicable adequacy decision, the European Commission’s Standard Contractual Clauses (Decision 2021/914), or another lawful transfer mechanism, together with supplementary safeguards where required.
After service launch, the same approach will apply where a non-EEA delivery supplier is necessary for an international route.
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction, or portability of your personal data; object to processing based on legitimate interests; and withdraw consent where consent is the legal basis. Withdrawal does not affect earlier lawful processing.
Email legal@otpblue.bg to exercise a right. We may need to verify your identity before acting on a request.
You may lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP): 2 Prof. Tsvetan Lazarov Boulevard, Sofia 1592, Bulgaria; kzld@cpdp.bg. You may also contact the supervisory authority where you live or work.
12. Automated decision-making
We do not use the website or contact form to make decisions based solely on automated processing that produce legal or similarly significant effects, and we do not profile website visitors.
13. Changes to this policy
We may update this policy when our services, providers, or legal obligations change. The effective date at the top identifies the current version.