/ legal

Privacy Policy

Last updated: 13 June 2026

This Privacy Policy explains how Sima Tech Ltd (Сима Тек ООД), a company registered in Bulgaria under UIC 206762842, with registered office in Pernik, Bulgaria ("Simatech", "we", "us"), processes personal data in connection with the website simatech.bg and the services we provide.

We act as a data controller for personal data collected through our website and direct business relationships, and as a data processor when we process personal data on behalf of our clients under a Data Processing Agreement (DPA).

This Policy is issued in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation or "GDPR"), the Bulgarian Personal Data Protection Act, and Directive 2002/58/EC (the ePrivacy Directive) as implemented in Bulgaria.

1. Data controller and contact

Sima Tech Ltd · UIC 206762842 · VAT BG206762842 · Pernik, Bulgaria.
Email: privacy@simatech.bg

We have not appointed a statutory Data Protection Officer as we are not required to do so under Art. 37 GDPR; the email above reaches the person responsible for privacy matters.

2. Categories of personal data we process

  • Identification & contact data: name, business email, phone, employer, job title.
  • Communications: messages you send us by email, contact forms or scheduled calls.
  • Contract & billing data: legal entity details, purchase orders, invoices, payment references.
  • Recruitment data: CVs, certifications, work history and references submitted via job applications or scrumjobs.net.
  • Technical data: IP address, browser and device information, pages visited, referrer, timestamps, and limited analytics events (only with your consent).

3. Purposes and legal bases

  • Responding to enquiries and managing client relationships — Art. 6(1)(b) GDPR (performance of a contract or pre-contractual steps) and Art. 6(1)(f) (legitimate interest in conducting business).
  • Delivering services and providing nearshore teams — Art. 6(1)(b) GDPR.
  • Invoicing, accounting and statutory record-keeping — Art. 6(1)(c) GDPR (legal obligation under Bulgarian tax and accountancy law).
  • Recruitment — Art. 6(1)(b) GDPR (pre-contractual steps) and Art. 6(1)(a) (consent for talent pool retention beyond a single role).
  • Website security, fraud prevention and abuse monitoring — Art. 6(1)(f) GDPR.
  • Analytics and non-essential cookies — Art. 6(1)(a) GDPR (consent). See our Cookie Policy.
  • Marketing emails to existing clients — Art. 6(1)(f) GDPR (legitimate interest, soft opt-in under the ePrivacy Directive), with an opt-out in every message.

4. Recipients and processors

We share personal data only with carefully selected service providers acting as processors under GDPR-compliant data processing agreements, including: cloud and hosting providers (EU/EEA-based where possible), email and CRM platforms, accounting and payroll providers, and professional advisers (lawyers, auditors). We never sell personal data.

5. International transfers

Where a processor is located outside the EU/EEA, transfers are covered by an adequacy decision of the European Commission or by the EU Standard Contractual Clauses (Commission Decision 2021/914), with supplementary measures where required following the CJEU "Schrems II" judgment.

6. Retention

  • Contractual and accounting records: 10 years (Bulgarian Accountancy Act).
  • Client and prospect contact data: up to 3 years from last meaningful interaction.
  • Unsuccessful job applications: up to 6 months, or longer with your explicit consent.
  • Website logs: up to 12 months.

7. Your rights under the GDPR

You have the right to:

  • access your personal data (Art. 15);
  • request rectification (Art. 16) or erasure (Art. 17);
  • restrict (Art. 18) or object to (Art. 21) processing;
  • receive your data in a portable format (Art. 20);
  • withdraw consent at any time, without affecting prior lawful processing (Art. 7(3));
  • lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP) at cpdp.bg or with your local EU/EEA supervisory authority.

To exercise any of these rights, email privacy@simatech.bg. We will respond within one month (Art. 12(3) GDPR).

8. Security

We implement appropriate technical and organisational measures under Art. 32 GDPR, including encryption in transit and at rest, access controls on a need-to-know basis, audit logging, secure development practices and personnel confidentiality undertakings.

9. Automated decision-making

We do not carry out solely automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR.

10. Changes to this Policy

We may update this Policy from time to time. Material changes will be announced on this page with a new "Last updated" date.