Privacy

Privacy policy

How CloudSource handles personal data - what we collect, why, how long we keep it, and your GDPR rights.

Last updated:

⚠️ Draft - DO NOT publish without lawyer review. This is a starter draft for a Bulgarian-registered AI studio operating under GDPR. Owner must pass it to a Bulgarian business / privacy lawyer (the engagement noted in PARTNER_PROGRAM.md §14) for review and adaptation before launch. Specific obligations vary by what we end up actually doing - partner program, hosted-LLM clients, cross-border transfers - so the lawyer's pass is not optional.

Last updated: [date] Version: 1.0 (draft)

CloudSource is a Bulgarian-registered AI studio (full company details below). This page explains what personal data we collect through this website and our services, why we collect it, how long we keep it, and what rights you have under the GDPR.

Who we are

  • Company: [LEGAL ENTITY NAME]
  • Address: [REGISTERED ADDRESS, SOFIA]
  • EIK / VAT: [TO FILL]
  • Data Protection Officer / Contact: [email protected]

We are the controller for the personal data described below.

What we collect through this website

Visitors (any page)

  • Server logs - IP address, user-agent, page accessed, timestamp. Kept 30 days, used for security and basic operational debugging.
  • Cookies - see /cookies/. We use first-party cookies for language preference and consent state. We do not use any cross-site or third-party tracking cookies.
  • Analytics - we use self-hosted Plausible to count pageviews and a small set of conversion events (chat opened, chat phase progressed, diagnostic booked, outbound product clicks). Plausible sets no cookies, stores no personal identifiers, hashes IP addresses, and never tracks you across sites. It runs unconditionally because cookieless analytics fall outside the scope of cookie consent rules - closer to a server access log than a tracking pixel.

Chatbot conversations

  • Conversation content - only if you opt in via the consent banner or in-chat prompt ("OK to keep a record"). If you don't opt in, conversations are answered in memory and not persisted.
  • Email + name - only if you provide them in the chat.
  • Booking metadata - when you book a 30-minute diagnostic call through the chat: your name, email, and (optionally) company are sent to our calendar (cPanel CalDAV) and our transactional email provider (Brevo) so we can confirm the call with you and add it to our calendar.
  • Security telemetry - for prompt-injection defence we keep a salted hash of your IP address (no plaintext IP) for 24 hours and log refused attempts to a separate injections table for 30 days. This is the legitimate-interest basis the rest of this policy describes.

Forms (contact, lead magnets)

  • Email + name + company + message - to reply to your enquiry, send the requested resource, and follow up with related work where you've consented.

Why we collect it (lawful basis)

  • Visitor logs: legitimate interest (security + operations).
  • Analytics (Plausible): legitimate interest (aggregated, anonymous statistics - cookieless and outside the scope of consent under ePrivacy).
  • Chatbot conversations: consent (you opt in via the banner or in-chat prompt).
  • Form submissions: consent (the checkbox you tick when submitting); pre-contractual measures (responding to your enquiry).
  • Newsletter / drip emails: consent (the opt-in when you download a lead magnet); easy unsubscribe in every email.

How long we keep it

  • Server logs: 30 days.
  • Chatbot conversations (consented): 24 months from last activity, then deleted unless you've become a client.
  • Form submissions: 24 months from last contact, unless an active client relationship is in place.
  • Client engagement records (contracts, invoices): as required by Bulgarian tax + commercial law (currently 10 years for accounting records, 5 years for contracts).

Who we share it with - sub-processors

We share only what's necessary, only with processors who've signed appropriate agreements. As of the date above, the active sub-processors for this site and the chatbot are:

Processor Role Location Transfer safeguard
Hetzner Online GmbH Site hosting (web app, Postgres, backups) Germany Intra-EU
Cloudflare, Inc. Authoritative DNS for cloudsource.bg (DNS-only mode - Cloudflare does not proxy site traffic; HTTP requests go directly to our Hetzner origin) United States Standard Contractual Clauses
Sanity Inc. Headless CMS + image CDN for site content (pages, services, case studies, products); no chat content, no leads, no form submissions United States Standard Contractual Clauses
Brevo (Sendinblue) Transactional email (booking confirmation, escalation) France Intra-EU
GoDaddy LLC (cPanel) Mailbox + CalDAV calendar for [email protected] (used by the chatbot's booking flow and operational mail) United States Standard Contractual Clauses
Tailscale Inc. Encrypted overlay network between our servers (control plane only - your traffic does not transit Tailscale infrastructure) United States Standard Contractual Clauses
Anthropic PBC Fallback path only - Claude Haiku invoked when (a) the local Gemma classifier returns unparseable output, or (b) OpenClaw's gateway runs context compaction; internal-only, never the user-facing reply United States Standard Contractual Clauses
Google LLC Embedding model used for semantic search across chat memory (Gemini embeddings - text only, no IP, no metadata) United States Standard Contractual Clauses

Local LLM (the user-facing chat reply) runs on hardware we own and operate in Sofia. Your message text and the bot's reply do not leave our infrastructure for the conversational reply itself. The sub-processors above are used for narrow secondary purposes (email delivery, calendar storage, internal classification, semantic memory).

For project engagements where you've contracted us specifically for a cloud-LLM build (Anthropic, OpenAI, Google), the DPAs of that engagement govern. We do not pass casual website-form data through cloud LLMs.

We do not sell personal data. Ever.

Cross-border transfers

Hetzner (our primary hosting) and Brevo (transactional email) are in the EU. The remaining sub-processors above are US-based and operate under the European Commission's Standard Contractual Clauses (and where applicable the EU-U.S. Data Privacy Framework). Any cloud LLM providers used as part of a client engagement are subject to that engagement's DPA, which includes SCCs for non-EU transfers when applicable.

Your rights

Under GDPR, you have the right to:

  • Access - ask what we hold about you.
  • Rectification - correct inaccurate data.
  • Erasure - request deletion (the "right to be forgotten"), subject to legal retention requirements above.
  • Restrict / object to processing.
  • Data portability - get your data in a machine-readable format.
  • Withdraw consent at any time, where consent is the basis.
  • Complain to the Bulgarian Commission for Personal Data Protection (CPDP) - https://www.cpdp.bg.

To exercise any of these, email [email protected]. We respond within 30 days.

Changes to this policy

When we change this policy materially, we'll update the version and date above and (where appropriate) notify users with active accounts or active enquiries.

Contact

Questions about how we handle data: [email protected]

Live · powered by Gemma-4 · running on our hardware in Sofia