Skip to main content

Privacy Policy

Last updated: 2 September 2026

Last updated: 2 September 2026 · Version: 2.0
Website: https://experiential-academy.com

1) Who we are (data controller)

Приключенска Академия ЕООД (EXPERIENTIAL ACADEMY LTD), UIC 208445883, registered at 33 Chavdar Voivoda Str., entrance A, floor 2, Ruse 7000, Bulgaria, is the controller of the personal data described in this policy.

Privacy contact: galena.robeva@ragina.net (please write "Personal data" in the subject line) or +359 885 980 971.

We have not appointed a Data Protection Officer. Our processing is small-scale and does not meet the conditions of Article 37 GDPR that would require one. The privacy contact above is monitored by the person responsible for data protection in our organisation.

2) What this policy covers

This policy explains what personal data we collect through this Website, why we collect it, on what legal basis, how long we keep it, who receives it and what your rights are. The Website is informational: visitors do not create accounts or publish content. Only our own staff log in to an internal administration area.

3) The data we process, why, and on what legal basis

A. Contact form and email enquiries

  • Data: name, email address, enquiry category, subject and message text. Together with the message we store the IP address, browser identification (user agent) and the page you came from.
  • Required fields: name, email, category, subject and message are required so that we can identify your enquiry and reply to you. If you do not provide them, the form cannot be sent. Nothing else is required, and you decide what to write in the message.
  • Purpose and legal basis: answering your enquiry and taking the steps you ask for before any contract is concluded — Article 6(1)(b) GDPR. The IP address and browser data are used to prevent spam and abuse of the form — our legitimate interest in keeping the Website secure, Article 6(1)(f) GDPR.
  • Retention: 6 months from receipt. Messages are deleted automatically; the email notification copy in our mailbox is deleted by our team within the same period.

B. Staff accounts (administration area)

  • Data: name, email address, role, login and password-reset activity. We never store passwords; Google Firebase Authentication holds a salted hash.
  • Purpose and legal basis: giving our staff access to manage the Website — Article 6(1)(b) GDPR (the staff member's engagement with us) and Article 6(1)(f) GDPR (security of the Website).
  • Retention: for as long as the person works with us. The account is deleted when the role ends or at the person's request. Login sessions expire after 5 days; password-reset codes after 15 minutes.

C. Cookies and cookie-choice records

  • We use only strictly necessary cookies. Each one is listed, with its purpose and lifetime, in our Cookie Policy. We do not use analytics or marketing cookies.
  • When you make a choice in the cookie banner we keep a record of it (your choice, the banner version, your language, a shortened IP address that no longer identifies you, and your browser type) so that we can demonstrate what you chose — Article 6(1)(c) together with Article 7(1) GDPR. Retention: 3 years.

D. Technical logs

  • Our hosting provider (Google Cloud) keeps standard server logs — IP address, requested page, time and browser type — for security, troubleshooting and abuse prevention: Article 6(1)(f) GDPR. Retention: 30 days.

We do not collect special categories of data, we do not use automated decision-making or profiling, and we do not sell personal data.

4) Who receives your data

Your data is seen by the members of our team who handle enquiries and manage the Website. To run the Website we use the following service providers (processors), all operated by Google (Google Cloud EMEA Ltd., Dublin, Ireland, and Google LLC, USA) under Google's Cloud Data Processing Addendum:

  • Firebase App Hosting (Cloud Run) — runs the Website. Location: European Union.
  • Cloud Firestore — database that stores contact messages, staff accounts and cookie-choice records. Location: European Union (multi-region "eur3": Belgium and the Netherlands).
  • Firebase Authentication — staff login. A global service; data may be processed in the United States.
  • Firebase Storage — images uploaded by our team. Location: European Union.
  • Gmail (SMTP) — sends the email notification of your enquiry to our team. Global Google infrastructure.
  • Cloud Logging — technical logs. Location: European Union.

No analytics, advertising, CRM or marketing providers receive your data. We may also disclose data where the law requires it, for example to a court or a supervisory authority.

5) Transfers outside the EU/EEA

Our data is stored in the European Union. Firebase Authentication and Gmail may process data in the United States. These transfers are covered by Google's certification under the EU-U.S. Data Privacy Framework and by the European Commission's Standard Contractual Clauses, both included in Google's Cloud Data Processing Addendum (cloud.google.com/terms/data-processing-addendum). You can ask us for more information about these safeguards using the contact details above.

6) How long we keep data

  • Contact messages and the technical data stored with them: 6 months.
  • Cookie-choice records: 3 years.
  • Staff accounts: until the role ends. Login sessions: 5 days. Password-reset codes: 15 minutes.
  • Server logs: 30 days.
  • Cookies: see the Cookie Policy (up to 12 months).

Deletion of contact messages and cookie-choice records runs automatically and is recorded in our internal audit log.

7) Your rights and how to exercise them

Under Articles 15 to 21 GDPR you have the right to: access your data and receive a copy of it; have inaccurate data corrected; have your data erased; restrict processing; object to processing that is based on our legitimate interests; receive the data you gave us in a portable format; and withdraw any consent at any time (this does not affect processing that already took place).

How to ask: email galena.robeva@ragina.net with "Personal data" in the subject line, or write to our registered address. Tell us which right you want to exercise and the email address you used with us. You do not have to give a reason.

Identity check: we normally reply to the email address we already hold for you, which is sufficient verification. We ask for additional proof only if we have reasonable doubts about who is asking, and only for what is needed to resolve that doubt.

Timing and cost: we confirm receipt promptly and answer within one month. For complex or numerous requests we may extend this by up to two further months; we will tell you why within the first month. Requests are free of charge unless they are manifestly unfounded or excessive.

Complaints: you have the right to lodge a complaint with the Bulgarian supervisory authority, the Commission for Personal Data Protection (Комисия за защита на личните данни): 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria; phone +359 2 915 3518; email kzld@cpdp.bg; website www.cpdp.bg. If you live in another EU/EEA country you may complain to the authority there instead. We would welcome the chance to resolve your concern first, but you are not required to contact us before complaining.

8) Children and young people

Our programmes involve young people, but this Website and its contact form are intended for adults: teachers, youth workers, representatives of organisations, and parents or guardians. We do not knowingly collect personal data from children under 14 through the Website. If you are under 14, please ask a parent or guardian to contact us on your behalf. If we learn that a child has sent us personal data through the Website, we will delete it, and a parent or guardian may ask us to do so at any time.

Photographs and videos from our programmes that show participants, including young people, are published on the Website only with the prior consent of the participant or, for minors, of a parent or guardian, collected as part of the programme. Consent can be withdrawn and removal requested at any time using the contact details above.

9) Security and data breaches

We protect data with encrypted connections (HTTPS), encryption at rest, role-based access limited to authorised staff, rate limiting against abuse, and an audit log of administrative actions and automatic deletions. If a personal data breach occurs, we will notify the Commission for Personal Data Protection within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms. Where the breach is likely to result in a high risk to you, we will also inform you directly without undue delay.

10) Changes to this policy

We may update this policy when our processing or the law changes. Each version carries a version number and date at the top. Substantial changes will be highlighted on the Website.