1. Data controller
The data controller is the operator of UGCBG.eu (legal entity details to be updated after incorporation). This policy explains how and why we process your personal data, in accordance with Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act.
Data Protection Officer (DPO): dpo@ugcbg.eu
2. Data we collect
| Category | Specific data |
|---|---|
| Registration | name, email, password (bcrypt-hashed), user type, registration date |
| Profile | avatar, bio, city, phone, website, social-network links, niches, rate card |
| KYC / Verification | name from ID, document type, selfie (for creators with high payouts) |
| Payments | IBAN, account holder, company code/personal ID for invoicing (brands), Stripe Customer ID |
| Activity | campaigns, applications, messages, ratings, portfolio |
| Technical | IP address, user-agent, login log, cookies, pages |
| Analytics | Google Analytics (anonymised IP), page views |
3. Purposes and legal bases
- Registration and service provision — basis: performance of a contract (Art. 6(1)(b) GDPR).
- Payment processing and invoicing — basis: performance of a contract + legal obligation (accounting, VAT).
- KYC and anti-fraud — basis: legal obligation + legitimate interest.
- Marketing emails (newsletter) — basis: consent; you may withdraw at any time with one click in the email.
- Analytics and product improvement — basis: consent (for non-essential cookies) or legitimate interest.
- Security / incident reports — legitimate interest.
- Featuring public creator profiles on UGCBG's social media pages (the Facebook page and other official UGCBG pages, see § 9a of the Terms of Service) — basis: consent (Art. 6(1)(a) GDPR). Consent is voluntary and is given with the checkbox at registration (it is not pre-ticked) or later in your Profile → „Представяне в социалните мрежи" ("Featuring on social media"). Nobody is featured without consent. We only use data that is already public in the profile: display name, profile photo, city, niches, a short excerpt from the description (up to 200 characters), the profile link and a share card generated from these data. You can withdraw your consent at any time (Art. 7(3) GDPR) with the same switch or by emailing office@ugcbg.eu. Withdrawal does not affect the lawfulness of processing before it. After the withdrawal we make no new posts and remove the posts already published within 7 days.
- Promoting the platform and active campaigns on UGCBG channels (the website, the Facebook page and other official UGCBG pages on social networks, see § 9a of the Terms of Service; for existing brands — from 26 October 2026) — basis: legitimate interest (Art. 6(1)(f) GDPR) in promoting the platform and the campaigns published on it. We only use the data in the public campaign listing. If you represent a brand, you can object at any time (Art. 21 GDPR) by emailing office@ugcbg.eu.
4. Recipients (third parties)
- Stripe Inc. (USA) — payment processing and escrow. Under Standard Contractual Clauses (SCC).
- SMTP / email provider (EU) — sending transactional and marketing emails.
- Hosting (Hetzner Online GmbH) — Germany, EU.
- Google Analytics (USA) — anonymised analytics, only after cookie consent. SCC.
- Meta Platforms Ireland Ltd. (Ireland, EU) — Facebook, where UGCBG runs its page. Receives the data we publish for promotion (§ 3). For the page statistics (Page Insights), UGCBG and Meta are joint controllers under Art. 26 GDPR, as set out in Meta's Page Insights Controller Addendum. For any other processing Meta is an independent controller and applies its own privacy policy.
- Other social networks where UGCBG has an official page — only for the data published there for promotion (§ 3).
- Lawyers, accountants, auditors — when necessary, under NDA.
- Government authorities — only on explicit legal request (NRA, CPDP, court, prosecutor).
5. International transfers
Stripe and Google Analytics process data in the USA. We rely on the EU Commission's Standard Contractual Clauses (SCC) and the Data Privacy Framework (DPF) where applicable. Meta Platforms Ireland Ltd. may transfer data to Meta Platforms, Inc. in the USA on the basis of the Data Privacy Framework and Standard Contractual Clauses. Request more information at dpo@ugcbg.eu.
6. Retention periods
- Active account: for the lifetime of the account.
- Deleted account: profile data — up to 30 days after deletion request (backup window).
- Accounting documents (invoices, payments): 10 years (Bulgarian tax law).
- Login logs and failed attempts: 90 days.
- Chat / messages: 5 years after the last message (dispute resolution).
- Marketing emails: until consent withdrawal.
- Cookie consent record: 12 months.
- Posts on UGCBG social media pages: they stay on the page until we remove them. After consent is withdrawn (the „Представяне в социалните мрежи" ("Featuring on social media") setting is switched off), after a brand's objection, or after an account deletion request, we remove the posts that contain your data within 7 days.
7. Your rights
You have the right to:
- Access the data we hold about you (Art. 15).
- Rectification of inaccurate data (Art. 16).
- Erasure ("right to be forgotten") in the cases listed in Art. 17.
- Restriction of processing (Art. 18).
- Data portability in a machine-readable format (Art. 20).
- Object to processing based on legitimate interest or direct marketing (Art. 21).
- Withdraw consent at any time (without retroactive effect).
- Lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP), www.cpdp.bg.
Send requests to dpo@ugcbg.eu. We reply within one month.
You can withdraw your consent to being featured on UGCBG's social media pages at any time and without giving reasons: switch off the „Представяне в социалните мрежи" ("Featuring on social media") setting in your Profile, or write to office@ugcbg.eu or dpo@ugcbg.eu. If you represent a brand, you can object to the promotion of your campaigns at the same addresses. After that we make no new posts with your data and remove the existing ones within 7 days.
8. Security
We apply technical and organisational measures: HTTPS/TLS, bcrypt password hashing, CSRF protection, rate limiting, isolated KYC storage, periodic backups, access logging.
9. Cookies
See the Cookie Policy.
10. Changes to this policy
We may update this policy. Material changes will be announced by email with 30 days' notice.
11. Contact
DPO: dpo@ugcbg.eu
Supervisory authority: Commission for Personal Data Protection — Sofia, 2 Tsvetan Lazarov Blvd, Bulgaria.