Last updated: June 2026
Introduction
This notice explains how Alpha Bulgaria AD processes personal data in connection with this website, in accordance with Regulation (EU) 2016/679 (GDPR) and Bulgarian data-protection law.
1. Controller
Alpha Bulgaria AD, UIC 200845765, 133 Vitosha Blvd., Triaditsa District, 1408 Sofia, Republic of Bulgaria. Privacy enquiries may be addressed via the contact page of this website.
2. Scope
This notice covers visits to this website and correspondence with the Company initiated through it, including investor-relations enquiries. It does not cover processing carried out by third-party websites linked from here.
3. Data we process and how we obtain it
Directly from you: identification and business contact details you provide when contacting us (name, organisation, role, business email or telephone) and the content of your correspondence. Automatically: technical server logs maintained by our hosting provider (IP address, browser and device information, pages accessed, timestamps), used for security and operation of the website.
4. Purposes and legal bases
Responding to enquiries and investor-relations correspondence — Art. 6(1)(b) GDPR (steps taken at your request) and Art. 6(1)(f) (legitimate interest in communicating with investors, counterparties and the public). Compliance with legal obligations applicable to a public company — Art. 6(1)(c). Website security, record-keeping and the establishment or defence of legal claims — Art. 6(1)(f).
5. Recipients
Personal data may be shared with service providers acting as processors on our documented instructions — the website hosting and publishing platform, and IT providers — and with competent authorities where required by law. We do not sell personal data.
6. International transfers
Our hosting and publishing platform may process technical data outside the European Economic Area. Any such transfer takes place only subject to appropriate safeguards under Chapter V GDPR, including the European Commission's Standard Contractual Clauses.
7. Retention
Correspondence is retained for five years from the conclusion of the relevant interaction, or for such longer period as the law requires, and is then deleted. Technical logs are retained for the period set by the hosting provider for security purposes.
8. Security
The Company applies appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, loss or disclosure.
9. Your rights
You have the rights of access, rectification, erasure, restriction of processing, data portability and objection, and — where processing is based on consent — the right to withdraw consent at any time with future effect. Requests may be submitted via the contact page of this website; the Company responds within the deadlines set by the GDPR.
10. Supervisory authority
You may lodge a complaint with the Commission for Personal Data Protection of the Republic of Bulgaria (CPDP), Sofia — www.cpdp.bg — or with the supervisory authority of your habitual residence.
11. Automated decision-making
The Company does not use personal data collected through this website for automated decision-making or profiling.
12. Cookies
Details of the cookies used by this website are set out in the Cookie Policy.
13. Changes
This notice may be updated from time to time; the version published on this page applies from the date stated above.
