Privacy policy
Last edited 24.07.2026
1. Introduction
This Policy explains how we collect and process your personal data in our capacity as data controller (Administrator).
Your responsibilities:
- Please read this Policy.
- If you are in a contractual relationship with us, also check the related terms and policies — they may contain further detail about how we process your data.
- Please pay attention to any additional information we give you at different stages of our interaction.
- If you provide us with personal data about other people, you must have a lawful basis for doing so, and you should inform those people how we will process their data. We will use such data only for the specific purpose it was provided.
- By providing us with data, you confirm that you are over 18 years of age.
2. Who we are and how to reach us
We, CyberXperts AD, are the controller responsible for your personal data. Our main activity is the provision of cybersecurity and information-security services.
Contact details:
CyberXperts AD, UIC (EIC): 208137120
Registered office: Sofia, Mladost district, Business Park Sofia, Building 14, Floor 3
Email: [email protected]
We have appointed a Data Protection Officer, who can be reached at [email protected].
It is important that the information we hold about you is accurate and current. Please tell us of any changes or errors.
3. What data we process, for what purpose, and on what basis
We process personal data for specific purposes and on the corresponding legal grounds, depending on your relationship with us.
3.1 When you are a visitor or user of our website (cyberxperts.com)
- Information collected automatically. You can browse the website without submitting personal data. Even so, some information is processed automatically — server log files and cookies — to keep the site secure and working and, where you have consented, to measure how it is used. Our website uses a consent management platform (Complianz) to obtain and record your cookie choices. Non-essential cookies — including analytics — are not set until you accept them via the cookie banner, and you can change or withdraw your choice at any time through the cookie settings link on the site. A full, current list of the cookies we use and their durations is maintained in our Cookie Policy.
- Analytics (Google Analytics 4). Where you consent, we use Google Analytics 4, loaded through Google Tag Manager, a service of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) and Google LLC. It uses cookies to help us understand, in aggregate, how visitors use the site so we can improve it. Google Analytics 4 does not log or store your IP address; it uses the address only momentarily to derive an approximate location and then discards it. We do not use analytics to build advertising profiles of you.
- Legal basis: your consent (Article 6(1)(a) GDPR). Analytics does not run before you accept it, and you may withdraw consent at any time via the cookie settings, without affecting processing that took place beforehand.
- Google acts as our processor. Where data is transferred outside the EEA, the transfer is covered by the EU-US Data Privacy Framework (to which Google is certified) and/or Standard Contractual Clauses. See §6.
- Social media plugins. Our website may include buttons or plugins from social networks such as LinkedIn, Facebook/Instagram (Meta), or others. Where these set cookies or transmit data to the provider, they do so only after you consent through our cookie banner, and the provider processes that data under its own privacy policy, for which we are not responsible. We include them to make our content easy to share and to promote our services.
- Legal basis: your consent (Article 6(1)(a) GDPR).
- Links to other websites. Our site may link to third-party websites. If you follow those links, please read the privacy policy of each site — we are not responsible for how third parties process your data.
- Data you provide through our contact form or other website services. When you contact us or use a service on the website, we process the data you provide for the purpose you provided it — that is, to respond to your request. The mandatory fields are the minimum we need for that purpose; please do not send us data that is not necessary. We also process the content of your messages to us.
- Legal basis: our legitimate interest in responding to your enquiry (Article 6(1)(f) GDPR); or, where your request is a step toward entering into a contract, the pre-contractual basis (Article 6(1)(b) GDPR).
- When you complete our NIS2 Readiness Assessment. Our website offers a self-assessment questionnaire that helps you gauge your organisation’s readiness against the risk-management measures in the NIS2 Directive (Article 21). This subsection explains what happens to the information you enter.
- _What we collect._ When you complete and submit the assessment, we receive:
- Contact details you provide — organisation name, your name, email address, telephone number, company size, and sector. Which of these are mandatory is shown on the form; the rest are optional.
- Your answers to the assessment questions, which describe your organisation’s current security arrangements (for example, whether you have an approved information-security policy, how you would detect a compromise, or whether multi-factor authentication is in place).
- Anything you type into the free-text field, if you use it.
- A risk score and service recommendations that our system calculates from your answers. This is derived data — we generate it; you do not supply it.
- We also record whether you ticked the optional marketing-consent box.
- _What we do not collect._ The assessment sets no cookies, does not track you across websites, and does not profile you for advertising. Please do not enter special categories of personal data (Article 9 GDPR), nor any credentials, passwords, IP addresses, hostnames, or other technical details that could be used to attack your systems. To limit automated abuse of the form, our server temporarily stores a keyed one-way hash of your IP address for one hour; the hash is computed with a secret key held on our server, so the original address cannot be recovered from it without that key. The IP address itself is never stored, and the hash is deleted automatically once the hour elapses.
- _Why we process it, and on what basis:_
- Purpose | Legal basis | |—|—| | Producing your risk score and recommendations, and sending you the result | Steps taken at your request before entering into a contract — Article 6(1)(b) GDPR | | Contacting you to discuss the results and whether our services are relevant | Our legitimate interest in responding to a commercial enquiry you initiated — Article 6(1)(f) GDPR | | Sending you marketing emails, if you ticked that box | Your consent — Article 6(1)(a) GDPR | Submitting the form is how you accept this Policy. Ticking the marketing box is optional and never a condition of receiving your results. If you consent, you may withdraw at any time via the unsubscribe link in any email or by writing to us; withdrawal does not affect the lawfulness of anything sent beforehand.
- _Automated processing._ Your score and recommended services are generated automatically from your answers. This is not automated decision-making producing legal or similarly significant effects under Article 22 GDPR: the output is an indicative guide and a prompt for a conversation, and every submission is reviewed by a person before we respond. Ask us and we will explain how a particular score was reached.
- _AI-generated summary._ To prepare a written summary of your results, we send your assessment answers and calculated scores to our AI provider, which generates the report text on our instructions and does not use your data to train its models. What we send is de-identified — it does not include your name, email, telephone number, or organisation name, only the answers, scores, and your stated sector and company size. Your submission is held on our server only for as long as it takes to generate the summary — at most one hour — and is then deleted. The AI provider acts as our processor under a written agreement. If you would prefer we not use an automated tool to prepare your summary, tell us and we will write it manually. We do not sell your data or share it with third parties for their own marketing.
- Sensitive data (special categories). We do not collect special categories of data about you (data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, health, sex life, or sexual orientation). Please do not provide such data — doing so exposes your rights to unnecessary risk.
- Combining information. Sometimes we combine information collected through the website with information you give us through other channels (email, phone) or from public sources such as the Commercial Register. When we do, we do not use it for any purpose we have not told you about.
3.2 If you are our business contact (or a potential one)
This means you represent an organisation that is our partner, client, supplier, or prospect, or are its employee. To build or maintain the relationship we may process your name, position, telephone, email, business card, and our correspondence with you. For potential contacts, we may hold contact details obtained from a public professional register, a mutual contact who referred you, your business card, or a meeting, and we will assess the purpose and basis before contacting you.
- Legal basis: our legitimate interest in managing and developing our business relationships (Article 6(1)(f) GDPR); where relevant, performance of a contract (Article 6(1)(b)). You may object to processing based on legitimate interest at any time (see §9).
3.3 If you attend our event, webinar, or training
- We collect the information needed to register you and manage your participation, and we may keep basic contact details to tell you about similar future events. Events may be recorded or photographed; if you would prefer we not publish information about you or your image, tell us in advance. You may object to marketing-style follow-ups at any time.
- Legal basis: performance of a contract or steps at your request (Article 6(1)(b)); our legitimate interest in promoting our activities (Article 6(1)(f)); or your consent where required.
3.4 If you visit our office
- We may ask you to identify yourself and note your name, the organisation you represent, and the date and time of your visit, in our legitimate interest in controlling access and security.
3.5 If you apply for a job with us
- If you send us a CV or cover letter — for a specific vacancy or speculatively — we process it to consider your application. If we decide you are not suitable for a current role, we delete your data within a reasonable period unless we ask for, and you give, your consent to keep it on file for future roles. If you applied speculatively, we may retain your details to consider you for future openings, on the basis of our legitimate interest, for the period you request or, absent that, up to 3 years. Please do not send us information that is not necessary for your application.
- Legal basis: steps at your request prior to a possible employment contract (Article 6(1)(b)); our legitimate interest in recruitment (Article 6(1)(f)); or your consent for retention on file (Article 6(1)(a)).
3.6 Other purposes
- We may also process your data to administer our business (internal reporting and analysis); to prevent fraud and other unlawful activity; to establish, exercise, or defend legal claims; to comply with legal obligations (accounting, tax, and others); and to improve our services — each on the basis of our legitimate interest, our legal obligation, or the performance of a contract, as applicable.
3.7 The legal bases we rely on
- Legal obligation — where processing is necessary to comply with a law that applies to us.
- Legitimate interest — where processing is necessary for an interest of ours or a third party, and your interests and rights do not override it. You may always object (see §9).
- Pre-contractual or contractual necessity — where we must take steps at your request to enter into, or to perform, a contract with you.
- Consent — a freely given, specific, informed, and unambiguous indication of your wishes. Consent is a separate basis from the others (signing a contract is not the same as giving consent), and you may withdraw it at any time (see §9).
If you are unsure which basis applies to a particular purpose, contact us.
4. Do you have to provide your data?
You must provide your data where a contractual or legal obligation requires it; if you do not, we may be unable to enter into or perform the contract or achieve the relevant purpose, and we will tell you so. Elsewhere, providing data is voluntary.
5. Who we share your data with
We may share your data with:
- Our IT and service providers acting as processors — for example our website hosting provider Hetzner, Germany and our email provider Microsoft. Each acts on our instructions under a written agreement.
- Google (analytics), as described in §3.1-B, where you have consented.
- AI-generated assessment summaries, as described in §3.6.
- Other controllers who provide us professional services — banks, auditors, lawyers, insurers — where necessary.
- Public authorities, where we are legally required to disclose.
- A buyer or successor, if we sell, transfer, or merge part of our business.
We conclude agreements with our processors that require them to protect your data and use it only on our instructions.
6. International data transfers
Your personal data is normally processed within the EU/EEA. Where a transfer to a country outside the EEA is necessary, we ensure an adequate level of protection by relying on one of the following:
- European Commission adequacy decision for the destination country; or
- the EU-US Data Privacy Framework, where the recipient in the United States is certified to it (for example, Google); or
- the European Commission’s Standard Contractual Clauses, together with any additional safeguards required.
We will provide further information about the safeguards applied on request.
7. Information security
We have implemented technical and organisational measures to protect your data against accidental loss and unauthorised access, use, alteration, or disclosure. We limit access to your personal data to those of our staff and partners who have a genuine need for it.
8. How long we keep your data
We keep your personal data only as long as necessary for the purposes for which we collected it, including any legal, accounting, tax, or reporting requirement. For tax purposes we are required to keep certain customer information (contact, identity, financial, and transaction data) for 5 years after the relevant year, plus the current year.
For NIS2 assessment submissions: where an assessment does not lead to a commercial relationship, we retain it for 12 months from submission and then delete it; where it leads to a contract, we retain it within the client record under the rules above; marketing-consent records are kept for as long as the consent stands plus 3 months as proof it was validly obtained. Because submissions are delivered by email rather than stored in the website database, deletion means deleting the message and any copies.
When deciding retention we consider the volume, nature, and sensitivity of the data, the risk of harm from misuse, the purposes, and legal requirements. We may anonymise data for statistical purposes and keep it in that form indefinitely.
9. Your rights
Subject to the conditions in law, you have the right to:
- Access — obtain a copy of the personal data we hold about you and confirmation that we process it lawfully.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted where there is no overriding reason for us to keep it.
- Object — object to processing based on our legitimate interest on grounds relating to your situation, and object at any time to processing for direct marketing (including profiling).
- Restriction — ask us to suspend processing, for example while its accuracy or basis is checked.
- Portability — receive certain data in a portable format or have it transmitted to another controller.
- Withdraw consent — where we rely on your consent, withdraw it at any time, without affecting processing carried out beforehand.
To exercise any right, email us at [email protected] or write to us at our registered address. Access is free; we may charge a reasonable fee or decline where a request is manifestly unfounded, repetitive, or excessive. We may ask you to verify your identity before acting, as a security measure. We aim to respond within one month; if we need longer, we will tell you.
10. Your right to complain
If you are unhappy with how we handle your data you may complain to the supervisory authority. In Bulgaria this is the Commission for Personal Data Protection (CPDP):
Address: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd.
Tel: +359 2 915 3519
Email: [email protected]
Web: cpdp.bg
We would appreciate the chance to resolve your concern first, so please consider contacting us before you complain.
11. Changes to this Policy
We may update this Policy from time to time and will publish any changes at https://cyberxperts.com. Where changes are material, we will also notify you by email or another appropriate means.