Privacy policy
Effective: 29 May 2026
This Privacy Policy explains how Finhold Advisory ("Finhold", "we", "us") collects, uses and protects personal data when you interact with us through our website at finhold.eu, our contact channels, or as part of an engagement.
We are committed to transparency and to your rights under the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Bulgarian Personal Data Protection Act (Закон за защита на личните данни).
1. Who we are
The data controller is:
Finhold Advisory
UIC (ЕИК): 208406492
VAT: BG208406492
Registered office: Sofia, Bulgaria
Email: contact@finhold.eu
We have not appointed a Data Protection Officer as we do not meet the criteria under Article 37 GDPR. For all privacy-related queries please use the email address above.
2. Personal data we collect
We process the following categories of personal data:
- Contact-form submissions — name, email address, company name and the content of your message, which you provide voluntarily when you contact us.
- Engagement data — for prospective and existing clients: business contact details, role and organisation information, billing details, and any data shared in the course of our advisory work.
- Technical data — IP address, browser user-agent and basic request metadata, captured for security, fraud prevention and rate-limiting purposes.
- Communications — email correspondence and records of meetings or calls relating to an enquiry or engagement.
We do not knowingly collect data from children. Our services are directed at businesses and professionals only.
3. How we use your data and our legal basis
We process personal data only where we have a lawful basis under Article 6 GDPR:
- To respond to your enquiry — performance of pre-contractual steps at your request (Art. 6(1)(b) GDPR) or our legitimate interest in responding to business contacts (Art. 6(1)(f)).
- To provide advisory services — performance of our engagement contract with you or your organisation (Art. 6(1)(b)).
- To meet legal and regulatory obligations — tax, accounting, anti-money-laundering and professional record-keeping duties under Bulgarian and EU law (Art. 6(1)(c)).
- To secure our website and prevent abuse — our legitimate interest in maintaining the integrity of our systems (Art. 6(1)(f)).
4. Disclosure to third parties
We do not sell, rent or trade your personal data. We may share limited personal data with:
- Our infrastructure providers (web hosting, transactional email) acting as data processors under Article 28 GDPR and bound by contractual confidentiality obligations.
- Our accounting and legal advisors where necessary to discharge regulatory or contractual duties.
- Competent public authorities where we are required to do so by law.
5. International transfers
We process data principally within the European Economic Area. Where any processor or sub-processor is located outside the EEA, we ensure transfers are subject to appropriate safeguards under Chapter V GDPR — typically EU Commission Standard Contractual Clauses or an adequacy decision.
6. How long we keep your data
- Contact-form submissions without follow-up engagement — up to 24 months from your last communication, after which we delete or anonymise the record.
- Engagement records — for the duration of our engagement and for the period required by Bulgarian commercial, tax and AML law (typically up to 10 years after the engagement ends).
- Technical logs — generally up to 90 days, retained longer only where required for an active security investigation.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected (rectification);
- have your data deleted in certain circumstances (erasure);
- restrict or object to certain processing;
- receive your data in a structured, machine-readable format (data portability) where applicable;
- withdraw consent at any time where we rely on consent as our legal basis.
To exercise any of these rights, email contact@finhold.eu. We will respond within one month, as required by Article 12 GDPR.
If you consider that our processing infringes the GDPR, you have the right to lodge a complaint with a supervisory authority — for Bulgaria, the Commission for Personal Data Protection (Комисия за защита на личните данни, КЗЛД, cpdp.bg).
8. Cookies
Our website uses only strictly necessary cookies required to maintain a session (e.g. for the contact form and CSRF protection). We do not use analytics, advertising, profiling or third-party tracking cookies. Because our use is limited to strictly necessary cookies, no consent banner is required under the EU ePrivacy Directive.
9. Data security
We apply organisational and technical safeguards proportionate to the data we handle: TLS encryption in transit, role-based access controls, the principle of least privilege, audit logging, and encrypted backups. No internet transmission can be guaranteed fully secure, but we maintain processes to detect and contain incidents and will notify affected individuals and the supervisory authority where required under Articles 33–34 GDPR.
10. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. The "Effective" date at the top of this page indicates when it was last revised. Material changes will be communicated through our website.
11. Contact us
For any questions about this policy or our handling of your personal data, please write to:
Finhold Advisory
contact@finhold.eu