Website: https://sglogist.com/ Last updated: 21.07.2026
This Personal Data Processing Policy (“Policy”) is drawn up in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and the Bulgarian Personal Data Protection Act (PDPA). It sets out how personal data is processed and what security measures are taken by:
SEA GATE LOGISTICS BG EOOD (“Controller”) UIC (EIK): 205682375 Address: Bulgaria, Burgas 8000, 1 Demokratsiya Str., Entr. A, Fl. 3, Off. 8
1.1. The Controller regards respect for the rights and freedoms of individuals — including the right to privacy and the protection of personal and family secrets — as a fundamental condition of its activity.
1.2. This Policy applies to all information the Controller may obtain about visitors to the website https://sglogist.com/ (“Website”).
2.1. Automated processing — processing of personal data by means of computing technology.
2.2. Restriction of processing — temporary suspension of the processing of personal data (except where processing is necessary to correct the data).
2.3. Website — the collection of graphic and informational materials, and the computer programs and databases ensuring their availability online at https://sglogist.com/.
2.4. Personal data information system — a set of personal data contained in databases, together with the information technologies and technical means used to process them.
2.5. Anonymization/pseudonymization of personal data — actions that make it impossible, without additional information, to attribute personal data to a specific User or other data subject.
2.6. Processing of personal data — any operation or set of operations performed on personal data, whether by automated means or not, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure by transmission, dissemination, restriction, erasure, or destruction.
2.7. Controller — the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
2.8. Personal data — any information relating directly or indirectly to an identified or identifiable User of the Website.
2.9. Personal data made public by the data subject — personal data to which an unlimited number of persons has been granted access by the data subject’s consent, given in the manner provided for by applicable data protection law.
2.10. User — any visitor to the website https://sglogist.com/.
2.11. Provision of personal data — actions aimed at disclosing personal data to a specific person or specific group of persons.
2.12. Dissemination of personal data — any actions aimed at disclosing personal data to an indefinite group of persons (transfer of personal data) or at making personal data available to an unlimited group of persons, including publication in the media, posting on information/telecommunication networks, or otherwise providing access to personal data.
2.13. Cross-border transfer of personal data — the transfer of personal data to the territory of a state outside the European Economic Area, to a foreign public authority, foreign natural person, or foreign legal entity.
2.14. Destruction of personal data — any actions as a result of which personal data is irrevocably destroyed, with the content of the personal data no longer recoverable in the personal data information system, and/or the physical media containing personal data are destroyed.
3.1. The Controller has the right to:
3.2. The Controller is obliged to:
4.1. Data subjects have the right to:
4.2. Data subjects are obliged to:
4.3. A person who provides the Controller with inaccurate information about themselves, or information about another data subject without that person’s consent, bears responsibility in accordance with applicable EU and Bulgarian law.
5.1. Personal data is processed lawfully and fairly, in a transparent manner.
5.2. Processing is limited to specific, explicitly stated, and legitimate purposes. Processing incompatible with the purposes for which the data was collected is not permitted.
5.3. Databases containing personal data processed for incompatible purposes are not combined.
5.4. Only personal data that is relevant to the purposes of its processing is processed.
5.5. The content and volume of personal data processed corresponds to the stated purposes of processing. Excessive processing relative to the stated purposes is not permitted.
5.6. The Controller ensures the accuracy, adequacy, and, where necessary, up-to-date nature of personal data relative to the purposes of processing, and takes the necessary steps to erase or rectify incomplete or inaccurate data without delay.
5.7. Personal data is stored in a form permitting identification of the data subject for no longer than is necessary for the purposes for which it is processed, unless a longer retention period is required or permitted by applicable law or a contract to which the data subject is party. Processed personal data is destroyed or anonymized once the purposes of processing have been achieved, or if the need to achieve them has been lost, unless otherwise required by applicable law.
| Purpose | Personal data processed | Legal basis | Type of processing |
|---|---|---|---|
| Informing the User by sending email correspondence, responding to enquiries, and preparing quotes/Orders | Email address (and, where provided, name and phone number) | Consent (Art. 6(1)(a) GDPR) and, where an Order is placed, performance of a contract (Art. 6(1)(b) GDPR) | Sending informational and transactional emails to the address provided |
In accordance with Art. 6(1) GDPR, the Controller processes personal data where at least one of the following applies:
7.1. The data subject has given consent to the processing of their personal data for one or more specific purposes.
7.2. Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
7.3. Processing is necessary for compliance with a legal obligation to which the Controller is subject under EU or Bulgarian law.
7.4. Processing is necessary to protect the vital interests of the data subject or of another natural person.
7.5. Processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, except where such interests are overridden by the interests, rights, or freedoms of the data subject.
7.6. Processing concerns personal data manifestly made public by the data subject.
The security of personal data processed by the Controller is ensured by implementing the legal, organizational, and technical measures necessary to fully comply with applicable data protection law.
8.1. The Controller ensures the safekeeping of personal data and takes all reasonable measures to prevent access by unauthorized persons.
8.2. The User’s personal data will not be disclosed to third parties, except where required by applicable law, or where the data subject has consented to the Controller transferring the data to a third party for the performance of a contract.
8.3. If the User identifies inaccuracies in their personal data, they may update it themselves by sending a notice to the Controller’s email address, [insert contact email, e.g. privacy@sglogist.com], marked “Personal data update”.
8.4. Personal data is processed for as long as necessary to achieve the purposes for which it was collected, unless a different period is provided by contract or applicable law. The User may withdraw their consent to the processing of personal data at any time by sending a notice to the Controller’s email address, [insert contact email, e.g. privacy@sglogist.com], marked “Withdrawal of consent to personal data processing”.
8.5. Information collected by third-party services, including payment systems, communication tools, and other service providers, is stored and processed by those parties (as independent controllers or processors) in accordance with their own terms of use and privacy policies. The data subject should review those documents directly. The Controller is not responsible for the actions of such third parties.
8.6. The Controller ensures the confidentiality of personal data during processing.
8.7. Processing of personal data ceases upon achievement of the purposes of processing, expiry of the period for which consent was given, withdrawal of consent by the data subject, a request to stop processing, or a finding that processing is unlawful.
9.1. The Controller carries out the collection, recording, organization, accumulation, storage, adaptation (updating, amendment), retrieval, use, transmission (dissemination, provision, access), pseudonymization/anonymization, restriction, erasure, and destruction of personal data.
9.2. The Controller carries out automated processing of personal data, with or without transmission of the resulting information over information and telecommunication networks.
10.1. Where personal data is transferred to a country outside the European Economic Area, the Controller ensures that such transfer is subject to appropriate safeguards in accordance with Chapter V GDPR, such as an adequacy decision of the European Commission, Standard Contractual Clauses, or another mechanism permitted under Art. 46 GDPR.
10.2. Data subjects located in the EU have the right to lodge a complaint with a data protection supervisory authority. As the Controller is established in Bulgaria, the competent authority is:
Commission for Personal Data Protection (CPDP) Address: 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria Phone: +359 2 915 3580 Email: kzld@cpdp.bg Website: www.cpdp.bg
Data subjects may also contact the supervisory authority in their own EU member state of residence.
The Controller and any other persons who have gained access to personal data are obliged not to disclose to third parties, and not to disseminate, personal data without the consent of the data subject, unless otherwise required by applicable law.
12.1. Users may obtain clarification on any questions concerning the processing of their personal data by contacting the Controller at [insert contact email, e.g. privacy@sglogist.com.
12.2. Any changes to this Policy will be reflected in this document. This Policy is valid indefinitely until replaced by an updated version.
12.3. The current version of this Policy is freely available online at https://sglogist.com/privacy/.
This Policy is governed by Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act.