With us, your business is always on the move!

With us, your business
is always on the move!

Personal Data Processing Policy

Website: https://sglogist.com/ Last updated: 21.07.2026

1. General Provisions

This Personal Data Processing Policy (“Policy”) is drawn up in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and the Bulgarian Personal Data Protection Act (PDPA). It sets out how personal data is processed and what security measures are taken by:

SEA GATE LOGISTICS BG EOOD (“Controller”) UIC (EIK): 205682375 Address: Bulgaria, Burgas 8000, 1 Demokratsiya Str., Entr. A, Fl. 3, Off. 8

1.1. The Controller regards respect for the rights and freedoms of individuals — including the right to privacy and the protection of personal and family secrets — as a fundamental condition of its activity.

1.2. This Policy applies to all information the Controller may obtain about visitors to the website https://sglogist.com/ (“Website”).

2. Basic Terms Used in this Policy

2.1. Automated processing — processing of personal data by means of computing technology.

2.2. Restriction of processing — temporary suspension of the processing of personal data (except where processing is necessary to correct the data).

2.3. Website — the collection of graphic and informational materials, and the computer programs and databases ensuring their availability online at https://sglogist.com/.

2.4. Personal data information system — a set of personal data contained in databases, together with the information technologies and technical means used to process them.

2.5. Anonymization/pseudonymization of personal data — actions that make it impossible, without additional information, to attribute personal data to a specific User or other data subject.

2.6. Processing of personal data — any operation or set of operations performed on personal data, whether by automated means or not, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure by transmission, dissemination, restriction, erasure, or destruction.

2.7. Controller — the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

2.8. Personal data — any information relating directly or indirectly to an identified or identifiable User of the Website.

2.9. Personal data made public by the data subject — personal data to which an unlimited number of persons has been granted access by the data subject’s consent, given in the manner provided for by applicable data protection law.

2.10. User — any visitor to the website https://sglogist.com/.

2.11. Provision of personal data — actions aimed at disclosing personal data to a specific person or specific group of persons.

2.12. Dissemination of personal data — any actions aimed at disclosing personal data to an indefinite group of persons (transfer of personal data) or at making personal data available to an unlimited group of persons, including publication in the media, posting on information/telecommunication networks, or otherwise providing access to personal data.

2.13. Cross-border transfer of personal data — the transfer of personal data to the territory of a state outside the European Economic Area, to a foreign public authority, foreign natural person, or foreign legal entity.

2.14. Destruction of personal data — any actions as a result of which personal data is irrevocably destroyed, with the content of the personal data no longer recoverable in the personal data information system, and/or the physical media containing personal data are destroyed.

3. Rights and Obligations of the Controller

3.1. The Controller has the right to:

  • receive from the data subject accurate information and/or documents containing personal data;
  • where the data subject withdraws consent to processing, or requests that processing be stopped, continue processing without consent where a legal basis for doing so exists under applicable data protection law (e.g. a legal obligation, or the establishment, exercise, or defence of legal claims);
  • independently determine the composition and scope of measures necessary and sufficient to comply with its obligations under applicable data protection law, unless otherwise specified by that law.

3.2. The Controller is obliged to:

  • provide the data subject, upon request, with information concerning the processing of their personal data;
  • organize the processing of personal data in accordance with applicable EU and Bulgarian law;
  • respond to requests and enquiries from data subjects (or their legal representatives) within the timeframes required by the GDPR (generally within one month, extendable by two further months for complex requests);
  • cooperate with, and provide information to, the competent supervisory authority (see Section 3.8 of the [Privacy Policy] / Section 10 below) upon lawful request;
  • notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it, where required by Art. 33 GDPR, and notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Art. 34 GDPR);
  • publish, or otherwise ensure unrestricted access to, this Policy;
  • take legal, organizational, and technical measures to protect personal data against unlawful or accidental access, destruction, alteration, blocking, copying, provision, dissemination, and other unlawful actions;
  • cease the transfer (dissemination, provision, access), stop the processing of, and destroy personal data in the circumstances provided for by applicable data protection law;
  • maintain records of processing activities as required by Art. 30 GDPR;
  • perform any other obligations provided for by applicable data protection law.

4. Rights and Obligations of Data Subjects

4.1. Data subjects have the right to:

  • obtain information concerning the processing of their personal data, provided in an accessible form and free of personal data relating to other data subjects, except where there is a lawful basis for disclosing such data;
  • require the Controller to rectify, restrict, or erase their personal data where it is incomplete, outdated, inaccurate, unlawfully obtained, or is not necessary for the stated purpose of processing, and to take other measures provided by law to protect their rights;
  • object to the processing of their personal data for marketing purposes, including requiring prior consent before such processing takes place;
  • withdraw consent to the processing of personal data at any time, and request that processing be stopped;
  • lodge a complaint with the competent supervisory authority (Section 10 below) or seek judicial remedy in respect of unlawful actions or omissions of the Controller in processing their personal data;
  • exercise any other right afforded by applicable EU or Bulgarian data protection law, including the right to data portability (Art. 20 GDPR).

4.2. Data subjects are obliged to:

  • provide the Controller with accurate information about themselves;
  • notify the Controller of any updates or corrections to their personal data.

4.3. A person who provides the Controller with inaccurate information about themselves, or information about another data subject without that person’s consent, bears responsibility in accordance with applicable EU and Bulgarian law.

5. Principles of Personal Data Processing

5.1. Personal data is processed lawfully and fairly, in a transparent manner.

5.2. Processing is limited to specific, explicitly stated, and legitimate purposes. Processing incompatible with the purposes for which the data was collected is not permitted.

5.3. Databases containing personal data processed for incompatible purposes are not combined.

5.4. Only personal data that is relevant to the purposes of its processing is processed.

5.5. The content and volume of personal data processed corresponds to the stated purposes of processing. Excessive processing relative to the stated purposes is not permitted.

5.6. The Controller ensures the accuracy, adequacy, and, where necessary, up-to-date nature of personal data relative to the purposes of processing, and takes the necessary steps to erase or rectify incomplete or inaccurate data without delay.

5.7. Personal data is stored in a form permitting identification of the data subject for no longer than is necessary for the purposes for which it is processed, unless a longer retention period is required or permitted by applicable law or a contract to which the data subject is party. Processed personal data is destroyed or anonymized once the purposes of processing have been achieved, or if the need to achieve them has been lost, unless otherwise required by applicable law.

6. Purposes of Personal Data Processing

PurposePersonal data processedLegal basisType of processing
Informing the User by sending email correspondence, responding to enquiries, and preparing quotes/OrdersEmail address (and, where provided, name and phone number)Consent (Art. 6(1)(a) GDPR) and, where an Order is placed, performance of a contract (Art. 6(1)(b) GDPR)Sending informational and transactional emails to the address provided

7. Legal Bases for Processing Personal Data

In accordance with Art. 6(1) GDPR, the Controller processes personal data where at least one of the following applies:

7.1. The data subject has given consent to the processing of their personal data for one or more specific purposes.

7.2. Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.

7.3. Processing is necessary for compliance with a legal obligation to which the Controller is subject under EU or Bulgarian law.

7.4. Processing is necessary to protect the vital interests of the data subject or of another natural person.

7.5. Processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, except where such interests are overridden by the interests, rights, or freedoms of the data subject.

7.6. Processing concerns personal data manifestly made public by the data subject.

8. Procedure for Collecting, Storing, Transferring, and Otherwise Processing Personal Data

The security of personal data processed by the Controller is ensured by implementing the legal, organizational, and technical measures necessary to fully comply with applicable data protection law.

8.1. The Controller ensures the safekeeping of personal data and takes all reasonable measures to prevent access by unauthorized persons.

8.2. The User’s personal data will not be disclosed to third parties, except where required by applicable law, or where the data subject has consented to the Controller transferring the data to a third party for the performance of a contract.

8.3. If the User identifies inaccuracies in their personal data, they may update it themselves by sending a notice to the Controller’s email address, [insert contact email, e.g. privacy@sglogist.com], marked “Personal data update”.

8.4. Personal data is processed for as long as necessary to achieve the purposes for which it was collected, unless a different period is provided by contract or applicable law. The User may withdraw their consent to the processing of personal data at any time by sending a notice to the Controller’s email address, [insert contact email, e.g. privacy@sglogist.com], marked “Withdrawal of consent to personal data processing”.

8.5. Information collected by third-party services, including payment systems, communication tools, and other service providers, is stored and processed by those parties (as independent controllers or processors) in accordance with their own terms of use and privacy policies. The data subject should review those documents directly. The Controller is not responsible for the actions of such third parties.

8.6. The Controller ensures the confidentiality of personal data during processing.

8.7. Processing of personal data ceases upon achievement of the purposes of processing, expiry of the period for which consent was given, withdrawal of consent by the data subject, a request to stop processing, or a finding that processing is unlawful.

9. Actions Performed by the Controller with Personal Data

9.1. The Controller carries out the collection, recording, organization, accumulation, storage, adaptation (updating, amendment), retrieval, use, transmission (dissemination, provision, access), pseudonymization/anonymization, restriction, erasure, and destruction of personal data.

9.2. The Controller carries out automated processing of personal data, with or without transmission of the resulting information over information and telecommunication networks.

10. Cross-Border Transfer of Personal Data and Supervisory Authority

10.1. Where personal data is transferred to a country outside the European Economic Area, the Controller ensures that such transfer is subject to appropriate safeguards in accordance with Chapter V GDPR, such as an adequacy decision of the European Commission, Standard Contractual Clauses, or another mechanism permitted under Art. 46 GDPR.

10.2. Data subjects located in the EU have the right to lodge a complaint with a data protection supervisory authority. As the Controller is established in Bulgaria, the competent authority is:

Commission for Personal Data Protection (CPDP) Address: 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria Phone: +359 2 915 3580 Email: kzld@cpdp.bg Website: www.cpdp.bg

Data subjects may also contact the supervisory authority in their own EU member state of residence.

11. Confidentiality of Personal Data

The Controller and any other persons who have gained access to personal data are obliged not to disclose to third parties, and not to disseminate, personal data without the consent of the data subject, unless otherwise required by applicable law.

12. Final Provisions

12.1. Users may obtain clarification on any questions concerning the processing of their personal data by contacting the Controller at [insert contact email, e.g. privacy@sglogist.com.

12.2. Any changes to this Policy will be reflected in this document. This Policy is valid indefinitely until replaced by an updated version.

12.3. The current version of this Policy is freely available online at https://sglogist.com/privacy/.


This Policy is governed by Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act.

Калькулятор

Заказать звонок

    Заказать доставку груза