Privacy Policy
Privacy Policy
Mandatory Information on the Rights of Individuals Regarding Personal Data Protection
This document constitutes a Privacy Policy and is intended to provide you with comprehensive information regarding the processing of your personal data by ROBEXA Ltd. in accordance with Regulation (EU) 2016/679 (GDPR) and the Personal Data Protection Act.
I. Data Controller Details
Company name: ROBEXA Ltd.
UIC/BULSTAT: 208809810
Registered office and management address: Varna, Primorski District, Knyaz Boris I Blvd. No. 124, Apt. 1
Correspondence address: Varna, Primorski District, Knyaz Boris I Blvd. No. 124, Apt. 1
Contact email: info@robexa.app
Telephone: +359 878 64 82 64
Mobile application: ROBEXA App (hereinafter referred to as "Controller" or "the Company").
The Company has assessed its obligations under Article 37 GDPR and has, as of the date of this Policy, not appointed a Data Protection Officer (DPO), as its activities do not fall within the scenarios set out in Article 37(1) GDPR. Enquiries relating to personal data protection may be addressed to: info@robexa.app.
II. Competent Supervisory Authority
Commission for Personal Data Protection (CPDP)
Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Telephone: 02 915 3 518
Website: www.cpdp.bg
III. Legal Bases for Processing Personal Data
The Controller collects, processes, and stores personal data on the basis of Article 6(1) GDPR, as follows:
the explicit consent of the data subject;
the performance of a contract or the taking of steps prior to entering into a contract;
compliance with a legal obligation;
the legitimate interests of the Controller or a third party.
IV. Purposes of Personal Data Processing
Personal data are processed for the following purposes:
creation and maintenance of a user account;
processing and fulfilment of orders;
conclusion and performance of distance contracts;
accounting and tax purposes;
sending of newsletters (subject to explicit consent);
protection of information security;
fulfilment of legal obligations to state authorities;
purchase, transfer, and validation of tickets;
maintenance of user balance;
user verification;
sending in-app notifications;
fraud and abuse prevention;
analysis and improvement of application performance;
support of chat functionality;
application security.
V. Categories of Personal Data
The Controller processes the following categories of personal data:
identification data – first name, last name;
contact data – email address, telephone number, postal address;
user account data;
technical data – IP address, cookies, logs;
marketing data (subject to explicit consent);
data on purchased tickets and transfers;
payment information and user balance data;
data on the device used;
technical application data;
account security information;
chat functionality data;
identity verification data;
photograph of identity document;
selfie image for verification;
data for fraud and abuse prevention.
The Controller does not process special categories of personal data within the meaning of Article 9 GDPR. The photograph of the identity document and the selfie image are used solely for the purposes of manual review by a ROBEXA staff member through visual comparison and are not processed using automated facial recognition technologies or used to create a biometric profile within the meaning of Article 9 GDPR.
VI. Cookies and Third-Party Services
ROBEXA App uses cookies, similar technologies, and third-party services for:
proper functioning of the application;
security;
usage analysis;
detection of technical issues;
service improvement;
sending notifications;
statistics and marketing.
ROBEXA App may use services such as:
Google Analytics;
Firebase;
Firebase Crashlytics;
Google Ads;
Facebook Ads;
Mailchimp;
notification and application usage analytics services.
These services may process anonymised, pseudonymised, or technical data.
The user may manage some of these settings through their device. Non-essential cookies (analytical and advertising) are activated only after the user's consent, given through the cookie banner in the application/website.
ROBEXA App may use SDKs, analytical, and technical technologies necessary for the operation, security, and improvement of the application.
The providers listed in Section VIII (ProCredit Bank, BORICA, Google LLC, Meta Platforms Inc., Mailchimp/Intuit Inc.) may process data outside the European Economic Area, including in the United States. In such cases, appropriate safeguards are applied in accordance with GDPR, such as Standard Contractual Clauses (SCCs) or other applicable transfer mechanisms under Articles 44–49 GDPR.
VII. Retention Periods
User profile data – until deletion of the profile;
Order data – up to 5 years;
Accounting data – in accordance with statutory retention periods;
Marketing data – until withdrawal of consent.
Access to the photograph of the identity document and the selfie image is restricted to authorised ROBEXA staff members involved in the verification process, who are bound by contractual confidentiality obligations. Following completion of the review, such images are retained only for the period necessary for security, fraud prevention, and compliance with legal obligations, as set out above.
VIII. Transfer of Personal Data
The Controller may transfer personal data to the following data processors and third parties, subject to a contract being in place and compliance with the requirements of GDPR:
ProCredit Bank (Bulgaria) EAD and BORICA AD — for the processing of card payments;
Google LLC (Firebase, Firebase Crashlytics, Google Analytics, Google Ads) — for application infrastructure, analytics, and advertising;
Meta Platforms, Inc. (Facebook Ads) — for advertising purposes;
Mailchimp / Intuit Inc. — for sending informational communications.
This list is updated whenever providers are added or changed.
IX. Chat and Moderation
ROBEXA may provide chat functionality between users and/or partners.
In cases of reports of harassment, fraud, abuse, spam, or violations of the platform's rules, ROBEXA reserves the right to review the relevant communication for the purpose of protecting users and the security of the platform.
X. Access to Device Features
ROBEXA App may request access to:
camera;
QR scanning;
internet connection;
push notifications;
files and photographs, where required for verification.
The user may manage these permissions through their device settings.
XI. Account Deletion
The user may request deletion of their account directly within the application, via the "Request Deletion" function, or by contacting ROBEXA at info@robexa.app. If, at the time of the request, the user has an available balance or active tickets, ROBEXA will contact the user to resolve the matter prior to finalising the deletion. The request is processed within 30 days of confirmation.
Certain data may be retained following account deletion where this is required by law or for protection against abuse.
XII. Rights of Data Subjects
You have the right to:
access your personal data;
rectification;
erasure ("right to be forgotten");
restriction of processing;
data portability;
objection;
withdrawal of consent at any time;
lodge a complaint with the CPDP.
To exercise the above rights, you may submit a written request to info@robexa.app. The Controller will respond within one month of receipt of the request. In complex cases, this period may be extended by up to two further months, in which case you will be notified within the first month, together with the reasons for the delay.
XIII. Data Security
The Controller implements appropriate technical and organisational measures for the protection of personal data.
In the event of a personal data breach, the Controller will notify the Commission for Personal Data Protection within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to the rights and freedoms of users, the Controller will notify the affected individuals without undue delay.
XIV. Changes to the Policy
This Privacy Policy may be updated, with all changes published within the ROBEXA App.