Privacy Policy
Effective from: 29 July 2026
This Privacy Policy describes how "BulGhar Homes" EOOD collects, uses, stores and protects the personal data of visitors to bulgharhomes.com, users of the client portal, and clients of the agency. The policy is drafted in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, GDPR) and the Bulgarian Personal Data Protection Act.
1. Data Controller
The controller of personal data is:
"BulGhar Homes" EOOD
Company ID (EIK): 208397562
Registered address: Varna, 20 Chataldzha Str., entr. A, apt. 7
Manager: Raffy Nikoghosyan
Email: [email protected]
Phone: +359 879 333 822
The company is not registered under the Bulgarian VAT Act.
2. What Personal Data We Collect
Depending on how you interact with us, we process the following categories of data:
a) Inquiry data. When you contact us through the contact form, by email or by phone, we collect your name, email address, phone number and the content of your inquiry.
b) Client portal data. For clients with a portal account, we process name, email, phone, deal status, deal-related documents, messages exchanged through the portal, and information about scheduled viewings.
c) Property transaction data. When entering into a brokerage agreement and when preparing property transactions, we process identification data, including national ID number (EGN) and identity-document data, where required by law (for example, for identification purposes under the Anti-Money Laundering Measures Act or for preparing transaction documents).
d) Technical data and cookies. When you visit the site, our analytics tools collect technical data such as IP address, device and browser type, pages visited, and approximate location. Details are described in Section 7.
3. Purposes and Legal Bases for Processing
We process personal data on the following bases under Art. 6 of the GDPR:
Performance of a contract (Art. 6(1)(b)): to enter into and perform a brokerage agreement for the purchase, sale or lease of real estate, to arrange viewings, communicate about deals and provide access to the client portal, including taking steps at your request prior to entering into a contract.
Legal obligations (Art. 6(1)(c)): real estate agencies are obligated entities under Art. 4 of the Anti-Money Laundering Measures Act and must identify and verify their clients, including collecting identity-document data. We also process data to fulfil accounting and tax obligations under the Accounting Act and the Tax and Social Insurance Procedure Code.
Legitimate interest (Art. 6(1)(f)): to protect legal claims, prevent abuse, ensure the security of the site and portal, and for internal business analysis.
Consent (Art. 6(1)(a)): to send marketing communications and to use non-essential cookies and analytics tools. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.
4. Retention Periods
We keep personal data only for as long as necessary for the purposes for which it was collected, or as required by law:
• Documents and data collected for AML purposes: 5 years from termination of the client relationship or from completion of the transaction;
• Accounting documents and records for tax control: up to 10 years under the Tax and Social Insurance Procedure Code and the Accounting Act;
• Data from inquiries that did not lead to a contract: up to 1 year from receipt of the inquiry;
• Client portal data: for the term of the contractual relationship and any applicable statutory periods thereafter.
After the relevant period expires, data is deleted or anonymized.
5. Recipients of Personal Data
We share personal data only when necessary to perform a contract, comply with a legal obligation, or for the purposes stated above, with the following categories of recipients:
• Notaries, when closing real estate transactions;
• Banks, when arranging payments and financing for transactions;
• Accountants servicing the company;
• DocuSign, for electronic signing of documents;
• Cloudflare, as our hosting and site-security provider;
• Resend, for sending email notifications from the portal;
• Google (Google Analytics), for web analytics;
• Meta (Meta Pixel), for measuring ad performance;
• Microsoft (Clarity), for analyzing on-site user behavior;
• Stripe, for processing payments for requested services;
• Invoice BG (inv.bg), for issuing invoices, including name, address and personal identification number where the invoice is issued to an individual.
We have data-processing agreements in place with providers who process data on our behalf, in accordance with Art. 28 of the GDPR. Data may also be disclosed to competent state authorities (e.g. the State Agency for National Security, the National Revenue Agency) where required by law.
6. Transfers of Data Outside the EU/EEA
Some of our providers (e.g. Google, Meta, Microsoft, DocuSign, Cloudflare, Resend) may process data on servers outside the European Union and the European Economic Area, including in the United States. In such cases, transfers take place under appropriate safeguards per Chapter V of the GDPR, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or an adequacy decision (including the EU-US Data Privacy Framework for certified providers). A copy of the applicable safeguards may be requested at the contact email above.
7. Cookies and Analytics Tools
The site uses cookies and similar technologies. Strictly necessary cookies provide the core functionality of the site and portal. Analytics and marketing tools load based on your consent and include:
| Tool | Provider | Purpose |
|---|---|---|
| Google Analytics 4 | Google Ireland Ltd. | Site traffic statistics: visitor counts, pages viewed, traffic sources. |
| Microsoft Clarity | Microsoft Corp. | Analysis of on-site user behavior (heatmaps, session recordings) to improve the site. |
| Meta Pixel | Meta Platforms Ireland Ltd. | Measuring the performance of Facebook and Instagram ads and showing relevant ads. |
You can manage cookies through your browser settings, including deleting or blocking them. Blocking some cookies may limit the site's functionality.
8. Your Rights
As a data subject, you have the following rights under the GDPR:
• the right to access your personal data and information about its processing;
• the right to rectify inaccurate or incomplete data;
• the right to erasure ("right to be forgotten"), where there is no legal basis for further retention;
• the right to restrict processing;
• the right to data portability, for data you provided and which is processed automatically on the basis of a contract or consent;
• the right to object to processing based on legitimate interest, including direct marketing;
• the right to withdraw your consent at any time.
To exercise your rights, contact us at [email protected]. We will respond within one month of receiving your request.
If you believe your rights have been violated, you have the right to file a complaint with the Commission for Personal Data Protection (CPDP): 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria; website: www.cpdp.bg.
9. Data Security
We apply appropriate technical and organizational measures to protect personal data, including encryption of the connection to the site and portal (HTTPS/TLS), encryption of stored documents, restricted access to data limited to persons who need it to perform their duties, and regular review of security measures. In the event of a security breach likely to result in a high risk to your rights, we will notify you in accordance with GDPR requirements.
10. Contact and Changes to This Policy
For questions about this policy and the processing of your personal data, you can contact us at [email protected] or by phone at +359 879 333 822.
We reserve the right to update this policy in the event of changes to our business or applicable law. The current version is always published on this page, together with its effective date. In the event of material changes, we will notify registered portal users in an appropriate manner.