Back to Home

Privacy Policy

Last updated: 21 September 2026. This policy explains how SAPUGO Technologies EOOD processes personal data on sapugo.com and in the SAPUGO Platform at sapugo.app. It complements Section E of our General Terms and Conditions (Edition October 2025). Processing of personal data follows Regulation (EU) 2016/679 (GDPR) and Bulgarian data protection law.

1. Who is responsible

The controller for this website and for account, billing, and support data is:

SAPUGO Technologies EOOD
Tzar Osvoboditel Blvd. 17A, Fl. 3, Apt. 6
1504 Sofia, Sredets District, Bulgaria
VAT ID: BG206196485
Email: hello@sapugo.com

We have not appointed a data protection officer. Privacy requests go to the address above. See also our Imprint.

2. Our role

SAPUGO is offered to enterprises. The Customer (the organization that holds the Platform Subscription) remains the controller of personal data it enters into the Platform or instructs us to process — including records, files, comments, workflows, authorized users, and test or cooperation data provided for Expert Services. SAPUGO acts as processor for that data and processes it only on the Customerʼs documented instructions (GTC E.1.2). Details are set out in a separate data processing agreement (DPA) to be concluded with the Customer (GTC E.1.5). Ask hello@sapugo.com if you do not yet have a signed DPA.

SAPUGO is the controller for this website and for data we need to run the business relationship itself: visitor and booking data, account authentication, organization metadata, billing and credit assessment, and our own support and security logs.

3. What we collect and why

We collect only what we need to run the site and the service.

  • Account and authentication — name, email, password (stored as a hash), and identifiers from the sign-in method you choose. Purpose: create and secure your account, send activation and password emails (contract, Art. 6(1)(b)).
  • Organization and members — organization name, region choice, members, roles, invitations. Purpose: provide the workspace you asked for (contract).
  • Billing and credit assessment — plan, invoices, VAT ID where you provide it, payment references handled by our payment processor, and, for new business customers, a credit check that may result in a credit limit (GTC F.1.1–F.1.2). We do not store full card numbers. Purpose: bill the subscription, Expert Credits, and keep tax records (contract; legal obligation, Art. 6(1)(c); legitimate interest in assessing credit risk).
  • Customer content — data your organization enters into tables, files, comments, and automations. Purpose: store and process it as instructed by that organization (processor; Art. 6(1)(b) / Art. 28).
  • Support and sales — emails, chat messages, and booking details if you contact us or schedule a call. Purpose: answer you (contract or legitimate interest, Art. 6(1)(f); optional chat/booking storage also needs consent under ePrivacy / TTDSG § 25).
  • Security and reliability — technical logs (time, IP address, user agent, request path) and error reports without session replay. Purpose: keep the service secure, prevent abuse, and fix faults (legitimate interest).
  • Cookie choice — a first-party cookie that stores whether you allowed optional chat and booking. Purpose: remember your choice (consent, Art. 6(1)(a)). Details: Cookie Policy.

4. Where data is stored

Operational organization databases are provisioned in the EU region chosen when the organization is created. Account, organization metadata, and supporting infrastructure are operated with EU-focused hosting.

Transfers of personal data to third countries outside the EU/EEA occur only if Art. 44 et seq. GDPR are met (GTC E.1.4) — typically an adequacy decision or standard contractual clauses (or an equivalent safeguard).

5. Who we share data with

We do not sell personal data. We may engage subcontractors and other providers to perform the service (GTC H). Sub-processors of Customer personal data are engaged only under an Art. 28 GDPR agreement; an up-to-date list will be provided (GTC E.1.7). Categories include:

  • Hosting and infrastructure providers (including commissioned subcontractors that operate the Platform)
  • Payment processing, for paid plans
  • Credit-assessment providers, where a credit check is performed
  • Transactional email (activation, invites, password reset, invoices)
  • Error monitoring, without session replay
  • Live chat and meeting scheduling, only after you allow those cookies or you open them yourself
  • The identity provider you choose when you sign in
  • Authorities, if we are legally required to disclose

The Customer may also grant access to authorized users, API credentials, and integrations it configures, and may allow its own customers, suppliers, or partners to use the Platform under the Customerʼs responsibility (GTC C.1.3). That sharing is under the Customerʼs control.

6. How long we keep data

  • Account, billing, and organization records — while the subscription is active, then for as long as tax, accounting, or dispute-handling law requires after closure (statutory retention remains unaffected, GTC C.3.3, G.7).
  • Customer content on the Platform — until the Customer deletes it. After the subscription ends we will, on the Customerʼs request, provide a machine-readable export of the data the Customer entered, within 30 days. That 30-day export period starts when the export capability is made available. After it ends we may delete the data, subject to statutory retention (GTC G.5–G.7). Access to the Platform is blocked after termination (GTC C.3.3).
  • Security and error logs — for a limited period needed to investigate incidents.
  • Support messages — for as long as needed to finish the request and keep a support history.
  • Cookie consent — 180 days, then we ask again.

7. Security

We implement appropriate technical and organizational measures to protect personal data (GTC E.1.3), in line with recognized industry standards. Each organization gets its own isolated database and credentials. Access to data goes through views and permissions the Customer configures. Connections use encryption in transit. Standard plans share infrastructure; exclusive hardware is an Enterprise option.

If we become aware of a personal data breach affecting Customer personal data we process as processor, we notify the Customer without undue delay and at the latest within 48 hours of becoming aware (GTC E.1.6).

8. Cookies

The marketing site sets a strictly necessary consent cookie. Chat and the booking calendar stay off until you allow them or you open them yourself. The product uses session and preference cookies that are required to keep you signed in and load the right workspace. See the Cookie Policy and Cookie settings in the footer.

9. Your rights

Under the GDPR you may request access, rectification, erasure, restriction, portability, and objection where those rights apply. You may withdraw consent at any time without affecting processing that was lawful before withdrawal.

Write to hello@sapugo.com. We will answer within one month, or tell you if we need more time. You may also lodge a complaint with your local supervisory authority, or with the Commission for Personal Data Protection (Комисия за защита на личните данни), Sofia, Bulgaria.

If we process your data as a processor for a Customer, we will forward your request to that Customer or tell you to contact them, unless we must handle it ourselves. Authorized users should usually contact their organization first.

10. Children

SAPUGO is a business service for enterprises within the meaning of the Bulgarian Commercial Act. It is not directed at consumers or at children under 16. We do not knowingly collect personal data from children.

11. Automated decisions

We do not make decisions based solely on automated processing that produce legal or similarly significant effects about you (Art. 22 GDPR). A credit assessment for a new business customer (GTC F.1.1) is not a solely automated decision of that kind.

12. Changes

If we change this policy in a material way, we will update the date above and, where required, notify account holders. The current version is always at sapugo.com/legal/privacy.

Related: Cookie Policy · Terms · Imprint.

We’re an enterprise software company. Passionate for technology and obsessed with great design. Ready to end digital frustration and help people work smarter.

All systems operational
Your digital ally.