Privacy policy
This document sets out what personal data is collected through the windy.bg website and through the enquiry forms in WINDY BG Ltd.'s advertisements on Facebook and Instagram, the purposes for which it is processed, who it is disclosed to, and the rights you have in relation to it.
1. Data controller
The controller of personal data is WINDY BG Ltd., UIC 208295519, a training centre with its seat in Varna, Bulgaria.
Correspondence address: 73 Vasil Drumev Street, Varna 9026, Bulgaria. Email: office@windy.bg. Telephone: +359 88 263 5948.
2. Scope
This policy concerns the processing of personal data through the windy.bg website and through the enquiry forms in WINDY BG Ltd.'s advertisements on Facebook and Instagram.
It also covers the course review page — both the submission of a review and its publication on the page of the course concerned. That page is part of the windy.bg website, but it opens only through a QR code on a printed sheet handed out to participants at the end of a course, and no other page of the site links to it.
3. What data is processed, for what purposes and on what basis
3.1. Enrolment request. The form collects your name, email address and course as required data, and telephone, preferred period and message as optional data.
Purpose: to consider the request and to arrange participation in training. Legal basis: Article 6(1)(b) of Regulation (EU) 2016/679 — steps taken at the data subject's request prior to entering into a contract.
The request is sent by email to the WINDY BG Ltd. team. The website does not store it — no database of names, email addresses and telephone numbers is maintained.
3.2. Question to the team. The same window also offers a second form, for a question without enrolling. It collects your name, email address and message; telephone is optional and no course is stated.
Purpose: to answer the question. Legal basis: Article 6(1)(b) where the question concerns possible participation in training, and Article 6(1)(f) — the legitimate interest in answering enquiries addressed to the company — in all other cases.
3.3. Check that the request was not sent automatically. Before it is sent, the form passes a check by the Cloudflare Turnstile service. During that check the visitor's IP address is transmitted to Cloudflare. The form also contains a hidden field that a person does not fill in; filled in, it marks the request as automated.
Purpose: protecting the form and the mailbox from automatically sent messages. Legal basis: Article 6(1)(f) — the legitimate interest in network and service security (recital 49 of the Regulation).
3.4. Statistics record. When a request is sent successfully, one row is recorded containing: the date and time; the course; the stated period; the language; the place in the site from which the form was opened; the page address; the address of the initial visit; the advertising parameters from the address, including the advertising click identifier; and the two-letter country code determined by Cloudflare.
The row contains no name, email address, telephone number or message.
Purpose: to measure which courses and which channels lead to requests. Legal basis: to the extent that this record contains personal data — Article 6(1)(f): the legitimate interest in measuring the results of the company's own publications and advertising.
3.5. Technical data on visiting. When a page loads, Cloudflare processes the visitor's IP address in its capacity as provider of the website's hosting and protection. The website keeps no visit log of its own.
Legal basis: Article 6(1)(f) — the legitimate interest in network and information security.
3.6. Visit statistics. Cloudflare Web Analytics counts visits without setting a cookie and without creating a visitor identifier. It does not measure an individual person and does not track across sites.
Legal basis: Article 6(1)(f) — the legitimate interest in statistics about the company's own website.
3.7. A request submitted through an advertisement on Facebook or Instagram. WINDY BG Ltd. advertises its courses on Facebook and Instagram. Some of those advertisements contain an enquiry form that is filled in within the platform itself, without visiting the website. The form collects your name, telephone, email address and an answer to a question about the level of training you need; the contact fields may be offered by the platform pre-filled with the data from your profile.
The form is displayed and completed within Meta's platform. In respect of the completed request the controller is WINDY BG Ltd.; Meta Platforms Ireland Limited processes the data as the platform provider and makes it available to the controller. The processing Meta carries out for its own purposes — displaying the advertisement, selecting the audience and measuring its results — is governed by Meta's privacy policy, not by this document.
Purpose: to consider the request and to arrange participation in training. Legal basis: Article 6(1)(b) of the Regulation — steps taken at the data subject's request prior to entering into a contract.
The request is received in the company's advertising account and is handled by a member of staff, who contacts the sender by telephone or by email. Such requests are not written to the statistics record under clause 3.4 — that record is created only by the form on the website.
3.8. A course review submitted by a participant. At the end of a course participants are given a printed sheet with a QR code leading to a review page. The form collects the name the sender writes in the „Name“ field (free text), the text of the review and a rating from 1 to 5. The course and the date of the session come from the link itself, not from the sender; the language version the form was filled in on, and the date and time of submission, are recorded as well.
The form collects no email address, no telephone number and no other contact details, requires no registration and creates no account.
Purpose: to collect a participant’s opinion of a course they have attended and to publish it on the course page. Legal basis: Article 6(1)(a) of the Regulation — consent. It is given by submitting the form after the page has expressly stated that the review and the name given appear publicly on the course page. Nothing is pre-ticked and the name field stays freely editable until the form is sent.
The submitted review is written as a file in the private repository that holds the website’s content, at GitHub, Inc., and stays unpublished until it is approved. At the same time a notification containing the full text of the review and the name is sent to office@windy.bg.
The form contains a hidden field that a person does not fill in; filled in, it marks the review as automated.
3.9. Publication of the review. An approved review is shown on the course page — with the name, the rating, the text and the date of the session, exactly as submitted. The text is not edited: a review is published word for word or not at all. The average rating, calculated from the reviews that same page shows, is displayed as well.
The same data is also included in the page’s structured data, which makes it machine-readable. A published review is accessible to any visitor and may be copied, shown or retained by search engines and other automated readers. That is outside the controller’s control and remains possible after the review is taken down from the website.
Purpose: so that someone considering enrolling can read the opinion of a participant who has attended the same course. Legal basis: Article 6(1)(a) — the same consent as under clause 3.8.
A review that is not approved is shown nowhere on the website.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, email, telephone, course, period, message | Considering the request and arranging participation | Art. 6(1)(b) (and 6(1)(f) for a question without enrolment) | 12 months from the last correspondence |
| Name, telephone, email and level sought — from a form in an advertisement | Considering the request and arranging participation | Art. 6(1)(b) | 12 months from the last correspondence |
| Statistics row — no name, email, telephone or message | Measuring which course and which channel lead to a request | Art. 6(1)(f) | 24 months |
| IP address during the automated-access check and site protection | Service security | Art. 6(1)(f) | per the provider's periods |
| Visit statistics — no identifier | Website statistics | Art. 6(1)(f) | up to 6 months at the provider |
| Name, review text and rating — from the review form; course and session date — from the link | Considering and approving the review | Art. 6(1)(a) | 3 months if the review is not approved |
| Name, review text, rating and session date — published on the course page | Publishing a participant's opinion | Art. 6(1)(a) | until consent is withdrawn |
4. Cookies and storage in the browser
The website uses no cookies for tracking, profiling or advertising.
The visit statistics set no cookie and create no visitor identifier.
Advertising parameters from the address are held in the browser's temporary memory from the moment the page opens until the tab is closed, and are sent together with the request. This is not a cookie, is not read by any server, and does not survive the tab being closed.
For that reason the website displays no consent banner.
5. Recipients of the data
The data is processed by the following service providers, acting on the controller's instructions:
- Cloudflare, Inc. — website hosting, protection against automated access, email delivery and visit statistics;
- the email service provider for the windy.bg domain, through which correspondence is received;
- Meta Platforms Ireland Limited — in respect of requests submitted through a form in an advertisement on Facebook or Instagram (clause 3.7);
- GitHub, Inc. — the private repository that holds the website’s content and into which a submitted review is written (clause 3.8).
The data is not sold and is not disclosed to third parties for their own purposes.
A review published under clause 3.9 is not disclosed to any particular recipient: it is publicly accessible on the course page — to every visitor, to search engines and to other automated readers.
6. Transfers outside the European Union
Cloudflare, Inc. is a company with its seat in the United States of America. Processing by it may involve transferring personal data outside the European Economic Area. The transfer takes place on the basis of the data processing agreement concluded with the provider and of the safeguards provided for in Chapter V of the Regulation.
Requests under clause 3.7 are submitted within a platform operated by Meta Platforms Ireland Limited — a company established in Ireland that belongs to a group with companies outside the European Economic Area. The terms on which Meta processes and transfers data are governed by its own terms and privacy policy.
Reviews under clause 3.8 are written into a repository at GitHub, Inc. — a company with its seat in the United States of America. Processing by it involves transferring personal data outside the European Economic Area.
7. Retention periods
Requests and questions are kept for 12 months from the last correspondence relating to them — both those received in the office mailbox and those submitted through a form in an advertisement (clause 3.7).
The statistics record under clause 3.4 is kept for 24 months.
A review published under clause 3.9 stays on the course page for as long as consent is not withdrawn. A submitted but unapproved review is kept for 3 months and is then deleted. A review judged to be spam is deleted when it is recognised as such.
The website’s content is kept in an internal version history, which is not public. A review deleted under any of the rules above disappears from the website immediately; a copy of it remains in that history and is removed when the history is migrated or rewritten, which is not done on a schedule.
Technical data is kept by the respective provider for its own periods; the website maintains no archive of its own.
8. Automated decision-making
No automated decision-making within the meaning of Article 22 of the Regulation takes place, and no profiling is carried out.
The check under clause 3.3 automatically assesses whether the request was sent by a person and may reject it. It produces no legal effects and does not significantly affect anyone: enrolment is carried out by a member of staff, and a request may also be submitted by telephone or by email.
9. Your rights
You have the right of access to your personal data, and the rights to rectification, erasure, restriction of processing, data portability, and to object to the processing.
Where the processing is based on legitimate interest (clauses 3.3 – 3.6), you have the right to object to it at any time.
Where the processing is based on consent (clauses 3.8 and 3.9), you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it. If you want your review taken down, send a request to office@windy.bg.
Following a withdrawal the review is taken off the website, that is, it stops being visible and leaves the page’s structured data. A copy of it remains in the internal, non-public version history of the content and is removed when that history is migrated or rewritten, which is not done on a schedule.
Search engines, caches and automated readers may already have retained the published review. The company has no access to them and cannot delete them. In such cases it takes the reasonable steps required by Article 17(2) of the Regulation, having regard to available technology and the cost of implementation.
Where there is reasonable doubt as to the identity of the person making the request, further information may be requested in order to confirm it (Article 12(6) of the Regulation).
These rights are exercised by a request sent to office@windy.bg. A reply is given within one month of receipt of the request. Where the request is complex or where there are many of them, that period may be extended by a further two months, of which you will be informed.
10. Right to lodge a complaint
If you consider that the processing of your personal data infringes the law, you have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection — 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, cpdp.bg.
11. Changes to this policy
If this policy changes, a new version is published at this address.