This policy explains what personal data TRENDY SUM LTD EOOD collects through the website trendysum.com, on what basis it is processed, and what rights you have. It applies to visitors from the European Union, the United Kingdom, the United States and anywhere else.
1. Who the data controller is
TRENDY SUM LTD EOOD, company number (EIK) 205172175, registered office at Krasna Polyana Distr., Bl. 329, Entr. B, Fl. 10, Apt. 69, 1330 Sofia, Bulgaria.
For any question about personal data, write to [email protected].
The company is not required to appoint a Data Protection Officer.
2. What data we process
Contact and support form data. When you write to us through the website, we process your name, email address, subject and the content of your message. You provide this voluntarily and decide what to include.
Technical server data. Every visit is recorded by the web server: IP address, date and time, the address requested, the response code, browser type and referring page. These records exist for security and for diagnosing technical faults.
Enquiry metadata. When a form is submitted we separately record the type of enquiry, the email address and the IP address, so that we can identify abuse of the form.
Theme preference. If you choose the light or dark theme, that choice is stored locally in your browser. It is never sent to us.
Analytics data (Google Analytics 4). Only if you consent through the cookie banner, Google Analytics 4 records aggregate data about your visit: the pages you viewed, approximate location at city level, device and browser type, where the visit came from, and an anonymous browser identifier. Your IP address is used only to derive that approximate location and is not stored by Google. Without your consent GA4 writes no cookies and sends no data. You can withdraw consent at any time via "Cookie preferences" in the footer of every page.
The website carries no advertising, performs no remarketing, builds no profiles, and makes no automated decisions with legal effect. We do not buy personal data and do not receive it from third parties. We do not process special categories of data (health, biometrics, origin, beliefs) and do not seek them in messages.
3. Legal basis for processing
This section applies to visitors in the EU, EEA and the United Kingdom (Art. 6 GDPR / UK GDPR).
| Purpose | Legal basis |
|---|---|
| Answering an enquiry or support request | Consent (Art. 6(1)(a)) and steps taken at your request prior to entering into a contract (Art. 6(1)(b)) |
| Traffic analysis via Google Analytics 4 | Consent (Art. 6(1)(a)), given through the cookie banner |
| Website security and abuse prevention | Legitimate interest (Art. 6(1)(f)) |
| Accounting and tax obligations where a contract is concluded | Legal obligation (Art. 6(1)(c)) |
4. How long we keep data
- Enquiry correspondence — up to 24 months from the last message, unless it leads to a contract.
- Server logs and enquiry metadata — up to 90 days.
- Analytics data in Google Analytics 4 — for the period configured in our GA4 property; the
_gaand_ga_*cookies expire up to 2 years after your last visit. - Accounting records — for the periods required by Bulgarian accounting and tax law.
Once the period expires the data is deleted or anonymised.
5. Who we share data with
We do not sell, rent or trade personal data. It may be accessible to:
- our hosting and email provider, acting as a processor under an Art. 28 GDPR agreement;
- Google Ireland Limited — for Google Analytics 4, acting as a processor and only where you have consented to analytics cookies;
- our accountants, where the data forms part of an accounting record;
- public authorities, where we are required by law to disclose it.
6. International transfers
Form messages, server logs and enquiry metadata are processed on servers located in the European Union and do not leave the European Economic Area. If you write to us from the United States or another country outside the EEA, your message is processed on a server in the EU.
Exception — analytics data. If you consent to analytics cookies, the data is collected through Google's European endpoints and processed by Google Ireland Limited, but Google may transfer part of it to Google LLC in the United States. For those transfers Google relies on the European Commission's Standard Contractual Clauses and is certified under the EU–U.S. Data Privacy Framework, so the Chapter V safeguards of the GDPR are in place. If you would rather no such transfer happened, simply do not consent to analytics cookies, or withdraw your consent — no data is then sent to Google.
7. Your rights — EU, EEA and United Kingdom
You have the right to request:
- access to the data we hold about you;
- rectification of inaccurate data;
- erasure of your data (the "right to be forgotten");
- restriction of processing;
- portability of your data in a machine-readable format;
- objection to processing based on legitimate interest;
- withdrawal of consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
Send requests to [email protected]. We respond within 30 days. If a request is complex the period may be extended, and we will tell you if that happens.
8. Your rights — United States
We extend the rights below to residents of every US state with a privacy statute — including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana — whether or not that statute formally applies to the company.
Categories collected in the last 12 months (using CCPA terminology):
| Category | What it covers | Source | Purpose |
|---|---|---|---|
| Identifiers | Name, email address, IP address | Directly from you; automatically from your device | Answering your enquiry; security |
| Internet or network activity | Addresses requested, request time, browser type | Automatically from your device | Security and technical diagnostics |
| Internet or network activity (analytics) | Pages viewed, where the visit came from, device type, approximate location at city level, anonymous browser identifier | Automatically from your device, only after explicit consent | Aggregate traffic statistics |
| Free text you supply | The content of your message | Directly from you | Answering your enquiry |
What we do not do:
- We do not sell personal information, and have not done so in the last 12 months.
- We do not share personal information for cross-context behavioural advertising, and we run no targeted advertising.
- We do not process sensitive personal information as defined by the CCPA, so the right to limit its use does not arise.
- We do not carry out profiling with legal or similarly significant effects.
Your rights: to know what we collect and how we use it; to receive a copy; to request correction; to request deletion; portability; to opt out of sale or sharing (not applicable, as we do neither); and not to be treated differently for exercising any of these rights.
How to make a request: email [email protected] from the address you contacted us with. We respond within 45 days, extendable once by a further 45 days if necessary, in which case we will tell you. An authorised agent may submit a request on your behalf with written permission.
Appeals: if we decline a request, you may ask us to reconsider by replying to our message with the word "appeal". We will review the decision and respond in writing with our reasons within 45 days. Several state laws additionally allow you to contact your state Attorney General afterwards.
Opt-out preference signals: the website carries no advertising and does not share data for cross-context behavioural advertising, so signals such as Global Privacy Control have no sale or sharing to switch off. Analytics, in turn, stays off until you give explicit consent — by default no data goes to Google.
9. Children's data
The website is not directed at children and we do not knowingly collect data from anyone under 16 (under 13 under COPPA in the United States). If we discover such data we delete it. If you believe a child has sent us their details, write to [email protected].
10. Complaint to a supervisory authority
If you believe we are processing your data unlawfully, you may lodge a complaint with:
Commission for Personal Data Protection (CPDP) 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria Email: [email protected] Website: cpdp.bg
If you are elsewhere in the EEA you may also contact the supervisory authority where you live. You also have the right to a judicial remedy.
11. Cookies
The website uses strictly necessary cookies and, with your consent, the analytics cookies of Google Analytics 4. No advertising cookies are used. Details are in the Cookie Policy.
12. Security
The website is served over an encrypted connection (HTTPS). Access to correspondence is limited to the people handling enquiries. We apply standard server security measures — updates, backups, restricted administrative access, and a strict Content Security Policy that prevents third-party code from running on the page.
13. Account and data deletion
Separate instructions are on the Account and Data Deletion page.
14. Changes
If this policy changes we publish the new version at this address and update the revision date. Material changes affecting data already held will be communicated by email where we have an address on file.