Privacy policy

PRIVACY POLICY
Koki Smoki EOOD — Last updated: 22 July 2026


This policy explains how КОКИ СМОКИ ЕООД (Koki Smoki EOOD) processes personal
data in connection with this website, our online store and our services, in
accordance with Regulation (EU) 2016/679 ("GDPR") and the Bulgarian Personal
Data Protection Act.

Our starting point is simple: we collect as little personal data as possible —
what is needed to run the store, deliver our services and meet our legal
obligations, and nothing more.


1. DATA CONTROLLER

Controller:        КОКИ СМОКИ ЕООД (Koki Smoki EOOD)
UIC / EIK:         207712194
Registered office: Bulgaria, Sofia 1330, Krasna Polyana district,
                   zh.k. Krasna Polyana III, bl. 333, ent. B, fl. 6, apt. 35
Represented by:    Ivan Stilyan Ivanov, Manager
Privacy contact:   support@kokismokieood.com

We are not required to appoint a Data Protection Officer; the contact above
handles all privacy matters.


2. WHAT DATA WE PROCESS, WHY, AND ON WHAT LEGAL BASIS

2.1 When you place an order in our store

We process the data needed to fulfil your order: your name, email address,
billing details, country, the products ordered, and payment status. Card and
payment credentials are processed by our payment service providers — we never
see or store your full card number.

- Purpose: concluding and performing the sales contract, delivering digital
  products, invoicing, fraud prevention.
- Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and
  Art. 6(1)(c) GDPR (accounting and tax obligations).
- Retention: order and invoicing records are kept for the statutory periods
  under Bulgarian accounting and tax law (as a rule up to 10 years plus the
  current year).

2.2 When you email or contact us

If you write to owner@kokismokieood.com or support@kokismokieood.com, we
process the data you provide: your name, email address, and the content of
your message.

- Purpose: answering your enquiry and any follow-up correspondence.
- Legal basis: Art. 6(1)(b) GDPR (steps prior to entering into a contract, at
  your request) or Art. 6(1)(f) GDPR (our legitimate interest in responding to
  correspondence addressed to us).
- Retention: routine correspondence is kept for up to 12 months after the
  matter is closed, unless it becomes part of a contractual relationship.

2.3 When you become a services client (or supplier)

We process the data needed to conclude and perform a contract: names and
business contact details of your representatives, contract and project
documentation, invoicing and payment details.

- Purpose: performing the contract, project communication, invoicing,
  accounting and tax compliance.
- Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and
  Art. 6(1)(c) GDPR (legal obligations under Bulgarian accounting and tax law).
- Retention: accounting documents and invoices are kept for the statutory
  periods under Bulgarian law; project documentation for the duration of the
  engagement plus the applicable limitation periods.

2.4 When you visit this website

Our website and store run on the Shopify platform. Shopify's infrastructure
automatically records technical server logs (IP address, date and time of
access, requested page, browser type) needed to deliver and secure the site.
The store also uses cookies that are strictly necessary for it to function —
for example to keep your cart and checkout session working. Details are in our
Cookie Policy.

- Purpose: operating the website securely, enabling cart and checkout,
  diagnosing faults and defending against attacks.
- Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in a secure,
  functioning website — and Art. 6(1)(b) GDPR for cart/checkout functions you
  request.
- Retention: log data is retained only for a short period unless needed to
  investigate a security incident.

We do not run advertising trackers or sell attention. If we ever introduce
analytics or marketing cookies, we will ask for your consent first.

2.5 Data of client-side users within projects

Where we develop or maintain software for a client and, in doing so, access
personal data controlled by that client (for example, data in a client's
database), we act as a processor under Art. 28 GDPR and process such data only
on the client's documented instructions, under a data processing agreement.


3. WHO RECEIVES YOUR DATA

We do not sell or rent personal data. Data is shared only with:

- Shopify — our e-commerce and hosting platform (Shopify International
  Limited, Ireland, and its affiliates), which processes store and order data
  on our behalf;
- Payment service providers, who process your payment independently as
  required to complete checkout;
- Service providers that help us run the business — email hosting and
  accounting services — bound by contract and confidentiality;
- Public authorities (e.g. the National Revenue Agency), where the law obliges
  us to disclose;
- Professional advisers (lawyers, auditors) where necessary to establish,
  exercise or defend legal claims.


4. INTERNATIONAL TRANSFERS

We keep personal data within the European Economic Area wherever possible.
Some of our processors (including Shopify) may process data outside the EEA —
for example in Canada, which benefits from an adequacy decision of the
European Commission, or in the United States. In such cases we rely on an
adequacy decision or on appropriate safeguards under Art. 46 GDPR (such as
Standard Contractual Clauses or the EU–US Data Privacy Framework), and will
tell you on request which safeguard applies.


5. YOUR RIGHTS

Under the GDPR you have the right to:

- access the personal data we hold about you (Art. 15);
- rectification of inaccurate data (Art. 16);
- erasure ("right to be forgotten") where the conditions of Art. 17 are met;
- restriction of processing (Art. 18);
- data portability for data you provided to us under a contract or consent
  (Art. 20);
- object to processing based on legitimate interests (Art. 21); and
- withdraw consent at any time, where processing is based on consent — without
  affecting processing before the withdrawal.

To exercise any of these rights, email support@kokismokieood.com. We respond
within one month; for complex requests the GDPR allows an extension of up to
two further months, in which case we will inform you. Exercising your rights
is free of charge, unless requests are manifestly unfounded or excessive.


6. RIGHT TO LODGE A COMPLAINT

If you believe we process your personal data unlawfully, you have the right to
lodge a complaint with the Bulgarian supervisory authority:

Commission for Personal Data Protection
(Комисия за защита на личните данни)
2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
www.cpdp.bg — kzld@cpdp.bg

If you live in another EU member state, you may also complain to your local
supervisory authority. We would, of course, appreciate the chance to resolve
any concern directly first.


7. HOW WE PROTECT DATA

We apply technical and organisational measures appropriate to the risk:
encrypted connections (HTTPS), access on a need-to-know basis, strong
authentication on our systems, separation of client environments, and regular
software updates. As a software company, security is part of our daily work,
not an afterthought.


8. OTHER THINGS YOU SHOULD KNOW

- No automated decision-making. We do not use automated decision-making or
  profiling within the meaning of Art. 22 GDPR.
- Children. Our website and services are addressed to businesses and adults;
  we do not knowingly process children's data.
- No obligation to provide data. Providing personal data is never a statutory
  requirement; however, without basic contact and order data we cannot answer
  enquiries, complete purchases or conclude contracts.


9. CHANGES TO THIS POLICY

We will update this policy when our processing or the law changes, and publish
the new version here with an updated date. Significant changes affecting
existing clients will be communicated by email.


10. CONTACT

Privacy questions and requests: support@kokismokieood.com