PRIVACY POLICY

“ЛИЙФ ГРУПА” ЕООД / LEAF GROUP Ltd.

Effective as of: 29 September 2026

This Privacy Policy explains how “ЛИЙФ ГРУПА” ЕООД (LEAF GROUP Ltd.) processes personal data when you use the website www.leaf-group.com, place orders, submit enquiries, communicate with the company, exercise your rights, participate in marketing activities, or otherwise interact with us. This Policy applies in accordance with Regulation (EU) 2016/679 (the “GDPR”), the Bulgarian Personal Data Protection Act and other applicable Bulgarian and European Union legislation.

1. WHO IS THE DATA CONTROLLER

The controller of your personal data is “ЛИЙФ ГРУПА” ЕООД (LEAF GROUP Ltd.), UIC 121827221, VAT No. BG121827221, with registered office and management address at: Sofia, Gotse Delchev residential district, 69 Bademova Gora St., Bulgaria.

Telephone: +359 2 962 35 16
E-mail: contact@leaf-group.com
Website: www.leaf-group.com

For questions and requests concerning personal data, you may use the contact details above or gdpr@leaf-group.com.

2. KEY DATA PROTECTION PRINCIPLES

We process personal data lawfully, fairly and transparently; for specified and legitimate purposes; only to the extent necessary for those purposes; and we keep the data accurate where necessary. We retain personal data no longer than necessary and apply appropriate technical and organisational measures to ensure its security. We apply the principles of purpose limitation, data minimisation, storage limitation, integrity, confidentiality and accountability.

3. WHAT PERSONAL DATA WE MAY PROCESS

Depending on your relationship with us, we may process:

  • identification and contact data – name, telephone number, e-mail address, delivery and/or correspondence address;
  • order and contractual data – products ordered, quantities, price, delivery details, order history and status, complaints, returns and correspondence;
  • invoicing and accounting data – information required under applicable accounting and tax legislation;
  • payment data – information about the selected payment method and transaction status. Where payment is processed by a bank or payment service provider, payment-card data are processed by the relevant provider in accordance with its terms and security measures;
  • website account data, where this functionality is available – registration information, settings and order history;
  • communications data – the content and metadata of enquiries, complaints, warranty or conformity claims, reports and other correspondence;
  • technical data – IP address, date and time, browser and device type, pages visited, technical and security logs and other information necessary for the operation and security of the website;
  • marketing preference data – for example, consent given or withdrawn for electronic marketing and cookie preferences;
  • data provided by a third party – for example, where another person provides your details as the recipient of a delivery.

We do not require special categories of personal data for the ordinary use of our online store. Please do not send us such data unless this is necessary and an applicable legal basis exists.

4. PURPOSES AND LEGAL BASES FOR PROCESSING

Purpose Examples of data Legal basis
Receiving, processing and fulfilling orders; delivery; contractual communication Name, contact details, address, order, delivery and payment information Article 6(1)(b) GDPR – steps at the data subject’s request prior to entering into a contract and performance of a contract
Issuing and retaining accounting and tax documents Invoicing, payment and transaction data Article 6(1)(c) GDPR – compliance with a legal obligation
Complaints, legal guarantees, withdrawal from contracts and other consumer rights Order and product information, correspondence, proof of purchase Performance of a contract and/or compliance with a legal obligation – Article 6(1)(b) and/or (c) GDPR
Responding to enquiries and correspondence Name, e-mail, telephone number, message content Depending on the circumstances – pre-contractual steps/performance of a contract or legitimate interests under Article 6(1)(b) or (f) GDPR
Website security, prevention of abuse, diagnostics and protection of systems IP address, technical and security logs, device information Article 6(1)(f) GDPR – legitimate interests in protecting our systems, users and business; where applicable – compliance with a legal obligation
Establishment, exercise or defence of legal claims Contractual, communications and technical data Article 6(1)(f) GDPR – legitimate interests
Sending marketing communications where consent is required Name, e-mail, telephone number and marketing preferences Article 6(1)(a) GDPR – consent, together with the applicable rules governing electronic communications
Analytics and advertising through non-essential cookies and similar technologies Online identifiers, events and information about interactions with the website Consent where required by applicable law; further details are provided in the Cookie Policy and consent-management platform

Where processing is based on our legitimate interests, we assess whether those interests are overridden by your interests, fundamental rights and freedoms.

5. WHEN PROVIDING DATA IS REQUIRED

Where certain personal data are necessary to enter into or perform a contract or to comply with a legal obligation, we may be unable to accept or fulfil an order, issue a required document or comply with your request without those data. Mandatory fields in electronic forms should be identified as such.

6. PAYMENTS

When paying by card or another electronic payment service, some data are provided directly to the relevant bank or payment service provider. LEAF GROUP processes only the information necessary to identify and administer the payment and which the relevant provider makes available to us. We do not claim to store full payment-card details where those details are not provided to LEAF GROUP by the payment operator.

7. COOKIES, GOOGLE, META AND OTHER ONLINE TECHNOLOGIES

The website uses essential technologies required for its operation and security and, depending on your choices, may also use non-essential analytics and advertising technologies.

As of the date of this Policy, the website may use Google services and technologies, including Google Analytics 4 and Google Tag Manager, as well as Meta technologies, including Meta Pixel and, where configured, Meta Conversions API. The specific technologies, cookie categories, retention periods and providers should be described in the current Cookie Policy and in the consent-management interface.

Non-essential analytics and advertising technologies are activated in accordance with applicable law and the choices you make through the consent-management mechanism. You may change or withdraw your choices using the mechanism provided on the website. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

Where the website uses embedded content from external platforms, such as YouTube, the relevant provider may also process data in accordance with its own privacy terms. Where prior consent is legally required for the relevant technology, it should be loaded in accordance with the choice you have made.

8. WHO MAY RECEIVE YOUR PERSONAL DATA

We disclose personal data only where necessary and where an applicable legal basis exists. Depending on the particular service, recipients or processors may include:

  • courier and transport companies – for delivery of orders;
  • banks and payment service providers – for payment processing;
  • accounting, legal and other professional service providers – insofar as necessary for the relevant service;
  • hosting, information-system, technical-support and cybersecurity providers;
  • analytics, advertising and communications service providers where their use is lawful and applicable consent requirements have been met;
  • subcontractors where necessary to perform a specifically requested service;
  • competent public, administrative, regulatory, law-enforcement or judicial authorities where we are legally required or otherwise have a lawful basis to disclose the data.

Where a service provider processes personal data on our behalf, the relationship is governed in accordance with Article 28 GDPR where that provision applies.

We do not sell your personal data.

9. TRANSFERS OF PERSONAL DATA OUTSIDE THE EEA

Some technology or service providers may process personal data outside the European Economic Area. Where an international transfer of personal data takes place, we apply the mechanisms provided for in Chapter V of the GDPR.

These may include an adequacy decision adopted by the European Commission under Article 45 GDPR, including the applicable EU–US Data Privacy Framework for participating and certified organisations in the United States, or appropriate safeguards under Article 46 GDPR, including the European Commission’s Standard Contractual Clauses, where applicable. Additional safeguards may also be implemented where necessary in light of the particular transfer.

You may contact us if you would like information about the mechanism applicable to a particular transfer and the possibility of obtaining a copy of the relevant safeguards where provided for by law.

10. RETENTION PERIODS

We do not retain personal data longer than necessary for the purposes for which they were collected, except where the law requires or permits a longer retention period. When determining retention periods, we take into account the nature of the relationship, statutory retention requirements, applicable limitation periods, the need to establish or defend legal claims, and the principle of data minimisation.

  • order and contract data – for the period necessary to perform the contract and thereafter insofar as necessary to comply with legal obligations and establish, exercise or defend legal claims;
  • accounting and tax documents – for the periods prescribed by applicable accounting and tax legislation;
  • complaints and legal/commercial guarantee documentation – for the period necessary to comply with applicable legal obligations and protect rights and claims;
  • correspondence and enquiries – for a period appropriate to the subject matter of the communication and the need to evidence and protect rights;
  • marketing data processed on the basis of consent – until consent is withdrawn or the relevant purpose ceases to exist, except insofar as it is necessary to retain evidence of consent or withdrawal;
  • technical and security logs – for a period appropriate to security, diagnostics and abuse-prevention purposes;
  • cookie and similar-technology data – according to the periods specified in the Cookie Policy and consent-management interface.

Where personal data are necessary for pending judicial, administrative or other proceedings or for the establishment, exercise or defence of legal claims, the relevant data may be retained until the matter is finally resolved and the applicable periods have expired.

11. DIRECT MARKETING

When we send electronic marketing communications, we comply with the applicable requirements of the GDPR and Bulgarian legislation governing unsolicited commercial communications. Where processing is based on your consent, you may withdraw that consent at any time. Where direct marketing is based on another permissible legal basis, you have the right to object at any time to the processing of your personal data for direct marketing purposes.

Where applicable, each marketing communication should provide an appropriate method for opting out of future communications.

12. AUTOMATED DECISION-MAKING AND PROFILING

We do not make decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you, unless the conditions of Article 22 GDPR and the applicable safeguards are met. Analytics and advertising technologies may involve the creation of audiences or assessment of interests for advertising purposes where this is permissible and consistent with the choices you have made.

13. CHILDREN'S DATA

The online store is not directed at children, and we do not intentionally seek to collect children's personal data for marketing purposes. If we become aware that we have received a child's personal data without an applicable legal basis, we will take appropriate action in accordance with the law.

14. YOUR RIGHTS

Subject to the conditions of the GDPR, you have the right:

  • to receive information and obtain access to your personal data;
  • to request rectification of inaccurate or incomplete data;
  • to request erasure where the statutory conditions are met;
  • to request restriction of processing;
  • to object to processing based on legitimate interests, including an unconditional right to object to processing for direct marketing purposes;
  • to data portability where the conditions of the GDPR are met;
  • to withdraw your consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;
  • not to be subject to a decision based solely on automated processing, including profiling, in the circumstances set out in Article 22 GDPR;
  • to lodge a complaint with a supervisory authority.

These rights are not absolute. In certain circumstances, the GDPR permits limitations or refusal where a lawful basis exists. If we are unable to comply with your request, we will inform you of the reasons where required by law.

15. HOW TO EXERCISE YOUR RIGHTS

You may send a request to contact@leaf-group.com, gdpr@leaf-group.com, or to the company's registered address.

Your request should contain sufficient information for us to understand which right you wish to exercise and which data it concerns. Where we have reasonable doubts concerning the identity of the person making the request, we may request additional information necessary to confirm the person's identity.

We respond without undue delay and, as a rule, within one month of receipt of the request. Where necessary, this period may be extended by a further two months, in which case you will be informed of the extension and the reasons for it within the first month.

Exercising your rights is generally free of charge. Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, the GDPR rules concerning a reasonable fee or refusal to act may apply.

16. RIGHT TO LODGE A COMPLAINT WITH THE SUPERVISORY AUTHORITY

If you believe that the processing of your personal data infringes the GDPR or applicable data-protection legislation, you have the right to lodge a complaint with the competent supervisory authority. In Bulgaria, this is:

Commission for Personal Data Protection (CPDP)
2 Prof. Tsvetan Lazarov Blvd.
1592 Sofia, Bulgaria
Website: www.cpdp.bg

Your right to lodge a complaint does not affect your right to other administrative or judicial remedies.

17. DATA SECURITY

We implement appropriate technical and organisational measures, taking into account the relevant risks, to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include access controls, rights management, backups, protection of communications and systems, organisational rules and other safeguards appropriate to the nature of the processing.

Access to personal data is granted only to persons who require it for their professional duties or for the provision of the relevant service and who are subject to applicable confidentiality obligations.

No information-transmission or storage system can be guaranteed to be absolutely secure. In the event of a personal data breach, we comply with our obligations concerning assessment, documentation and, where the legal conditions are met, notification of the CPDP and/or affected individuals.

18. DATA WE RECEIVE FROM OTHER PERSONS

If a person placing an order identifies another individual as the recipient of a delivery or otherwise provides us with another person's personal data, we process those data only to the extent necessary for the relevant purpose. A person providing another individual's data should have a lawful basis for doing so.

Where we obtain personal data other than directly from you, we provide the information required under Article 14 GDPR in the applicable circumstances and within the applicable periods, unless a statutory exception applies.

19. LINKS AND EXTERNAL PLATFORMS

The website may contain links to third-party websites and services. Once you follow a link to an external website, the processing of personal data by its operator is governed by that operator's own policies and is not under LEAF GROUP's control, except insofar as applicable law provides for joint or other responsibility in the particular circumstances.

20. CHANGES TO THIS POLICY

We may update this Policy following changes to legislation, technologies used, our services or the way in which personal data are processed. The current version will be published on the website together with its effective date. Where the nature of a change requires additional notice or renewed consent, we will take the necessary steps in accordance with applicable law.

21. CONTACT

“ЛИЙФ ГРУПА” ЕООД / LEAF GROUP Ltd.
UIC 121827221
VAT No. BG121827221
Sofia, Gotse Delchev residential district, 69 Bademova Gora St., Bulgaria
Tel.: +359 2 962 35 16
E-mail: contact@leaf-group.com
Personal data enquiries: gdpr@leaf-group.com