Privacy Policy
Last updated: 21 April 2026
Overview
This Privacy Policy explains how FinDaS Ltd ("we", "us", or "our") collects, uses, stores, shares, and protects personal data when you visit our website at findas.org, engage our services, or otherwise interact with us. It also explains the rights you have in relation to your personal data under the EU General Data Protection Regulation (GDPR), the Bulgarian Personal Data Protection Act, and other applicable data protection laws.
We take your privacy seriously. Please read this Privacy Policy carefully. By using our website or engaging our services, you confirm that you have read and understood this Privacy Policy. If you do not agree with any part of this Privacy Policy, please do not use our website or services.
This Privacy Policy should be read together with our Terms of Service. Where there is a conflict between this Privacy Policy and a signed engagement letter or data processing agreement in relation to data protection matters, the signed document prevails to the extent of the conflict.
Who We Are
FinDaS Ltd is the controller of the personal data processed under this Privacy Policy. Our registered details are:
FinDaS Ltd
Lagera 41A, Sofia, Bulgaria
VAT: BG206266006
Email: tokenomics@findas.org
For any questions about this Privacy Policy, how we handle your personal data, or to exercise any of your rights, you may contact us at the email address above. We do not currently have a designated Data Protection Officer, as we are not required to appoint one under Article 37 of the GDPR. Privacy matters are handled directly by our management.
Information We Collect
We collect personal data in the following ways.
Information you provide to us
You may provide personal data when you:
- Contact us through our website contact form, email, LinkedIn, Telegram, or other communication channels
- Book a call through our meeting scheduling page
- Engage our services, including the information required for invoicing (company name, registration number, VAT number, business address, and where applicable, beneficial ownership details)
- Sign up for our newsletter, download a report, or register for a course
- Participate in our referral program
- Submit testimonials, feedback, comments, or other voluntary submissions
- Correspond with us in the course of an engagement, including email exchanges, shared documents, and project-related materials
The personal data collected this way typically includes your name, email address, job title, company name, phone number, and any other information you voluntarily provide in the course of the interaction.
Information collected automatically
When you visit our website, we and our service providers may automatically collect certain information, including:
- IP address and approximate geographic location derived from it
- Device information, such as device type, operating system, and browser type and version
- Pages viewed, time spent on pages, referring URL, and clickstream data
- Date and time of access
- Cookies and similar tracking identifiers (see the Cookies section below)
This information is collected through standard web technologies and through our analytics providers, described in the Cookies section.
Information from third parties
We may receive personal data about you from third parties, including:
- Referral sources, where a partner or client refers you to us
- Publicly available sources, such as LinkedIn, company websites, or business registries, where we verify a prospective client's business or assess a potential engagement
- Service providers that support our operations, such as payment processors or scheduling tools
- Sanctions-screening and compliance tools, where applicable, to verify that engagement does not breach applicable sanctions regimes
Special categories of personal data
We do not ordinarily collect or process special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning a person's sex life or sexual orientation). Please do not provide such information to us unless specifically requested and justified.
Legal Bases for Processing
Under the GDPR, we must have a lawful basis for processing your personal data. We rely on the following bases, depending on the processing activity:
Performance of a contract (Article 6(1)(b))
Where we process personal data to enter into or perform a contract with you, such as delivering engaged services, issuing invoices, or providing deliverables, the legal basis is the performance of that contract or steps taken prior to entering into it.
Legitimate interests (Article 6(1)(f))
We rely on our legitimate interests for activities such as:
- Operating, maintaining, and improving our website and services
- Business development, including responding to enquiries and pursuing prospective engagements
- Understanding how our website is used through analytics
- Protecting our network, systems, and intellectual property against security threats and unauthorized use
- Compliance screening and conflict checks before accepting an engagement
- Marketing to existing or prospective business clients in a B2B context, where your interests and fundamental rights do not override this interest
You have the right to object to processing based on legitimate interests (see Your Rights below).
Consent (Article 6(1)(a))
We rely on consent for certain activities, such as sending electronic marketing communications where required by law, setting non-essential cookies, or processing any information where consent is specifically requested. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Legal obligation (Article 6(1)(c))
We process personal data where necessary to comply with a legal obligation, such as tax and accounting record-keeping under Bulgarian law, responding to lawful requests from regulatory or judicial authorities, or compliance with anti-money laundering, counter-terrorism financing, and sanctions obligations.
How We Use Your Information
We use personal data for the following purposes:
- To respond to your enquiries, communications, and requests
- To assess, negotiate, and enter into engagements with you or the organization you represent
- To deliver the services you have engaged us for, including producing deliverables, running models, and providing consulting support
- To issue invoices and administer payments
- To maintain accounting, tax, and other legally required records
- To send you service-related communications, including project updates, scheduling confirmations, and administrative notices
- To send newsletters, research updates, or marketing communications where you have subscribed or where permitted under applicable B2B marketing rules
- To improve our website, services, and content, including through analytics
- To protect our rights, property, and interests, and those of our clients and third parties
- To comply with our legal obligations, including tax, accounting, anti-money laundering, counter-terrorism financing, and sanctions requirements
- To operate our referral program, where applicable
Cookies and Tracking Technologies
Our website uses cookies and similar technologies to provide essential functionality and, with your consent where required, to understand how visitors use the site.
Types of cookies we use
Strictly necessary cookies. These cookies are essential for the operation of our website and cannot be disabled in our systems. They are usually set in response to actions made by you, such as setting your privacy preferences or filling in forms.
Analytics cookies. These cookies allow us to count visits and traffic sources, so we can measure and improve the performance of our site. They help us understand which pages are most and least popular and see how visitors move around the site. All information these cookies collect is aggregated.
Functional cookies. These cookies enable enhanced functionality and personalization, such as remembering your preferences.
Marketing cookies. Where applicable, these cookies may be set by our marketing partners to build a profile of your interests and show you relevant content on other sites.
Specific tools and providers
We use the following third-party services on our website:
Google Analytics (provided by Google LLC). We use Google Analytics to understand how visitors use our website. Google Analytics may set cookies and collect information such as your IP address (in anonymized form), device and browser type, pages viewed, and time spent on the site. Data is transferred to Google servers in the United States under Standard Contractual Clauses. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on, or by declining analytics cookies in our cookie banner where applicable.
Google Calendar (provided by Google LLC). Our meeting scheduling page uses Google Calendar to manage bookings. When you book a call, information you provide (such as your name, email address, and any meeting details) is processed by Google as part of the calendar booking. Data is transferred to Google servers in the United States under Standard Contractual Clauses.
Softr (provided by Softr, Inc.). Our website is built on the Softr platform. Softr may set cookies necessary for site functionality and platform operation. Please refer to Softr's privacy policy for details.
Each of these providers operates under its own privacy policy, which we encourage you to review.
Managing cookies
You can manage your cookie preferences through our cookie banner when you first visit the site, or through the cookie settings link available in the website footer. You can also control cookies through your browser settings by blocking or deleting them. Please note that blocking strictly necessary cookies may affect the functionality of our website.
How We Share Your Information
We do not sell personal data. We share personal data only in the following circumstances.
Service providers (processors)
We share personal data with third-party service providers who process data on our behalf to support our operations. These typically include:
- Website hosting and infrastructure providers
- Analytics and website performance providers
- Email, customer relationship management, and marketing automation providers
- Payment processors and banking partners
- Accounting, bookkeeping, and tax compliance providers
- Meeting and scheduling tools
- Cloud storage and collaboration tools
- Professional advisors, including lawyers, accountants, and auditors
These providers are bound by contractual obligations to process personal data only for the purposes specified by us, to implement appropriate security measures, and to comply with applicable data protection laws, including the requirements of Article 28 of the GDPR where applicable.
Named service providers
The principal service providers we currently use to deliver our services and operate our business include:
- Google LLC (Google Workspace). We use Google Workspace for email, calendar, cloud storage, and document collaboration in the course of client engagements and internal operations. Personal data processed through Google Workspace, including email correspondence and shared project documents, is subject to Google's data processing terms and may be transferred to Google servers in the United States under Standard Contractual Clauses.
- Google LLC (Google Analytics and Google Calendar). See the Cookies section above.
- Softr, Inc. Website platform and hosting. See the Cookies section above.
This list covers our principal processors but is not exhaustive. Additional service providers, such as banking partners, accounting and tax providers, or professional advisors, may process limited personal data as necessary for specific operational purposes.
Legal and regulatory disclosures
We may disclose personal data where required to do so by law, court order, or lawful request from a regulatory, judicial, or governmental authority. We may also disclose personal data where necessary to investigate, prevent, or take action regarding suspected illegal activity, fraud, threats to personal safety, or violations of our Terms of Service, or as otherwise required or permitted by law.
Business transfers
In the event of a merger, acquisition, reorganization, sale of assets, bankruptcy, or similar transaction, personal data may be transferred as part of the transaction. We will take reasonable steps to ensure that personal data continues to be protected in line with this Privacy Policy.
With your consent or at your direction
We may share personal data with other third parties where you have expressly consented or directed us to do so.
International Data Transfers
We are based in Bulgaria, a member state of the European Union. Some of our service providers, however, are located outside the European Economic Area (EEA), including in the United States and other third countries. Where personal data is transferred outside the EEA to a country that has not been deemed to provide an adequate level of protection by the European Commission, we rely on appropriate safeguards to protect that data, such as:
- Standard Contractual Clauses approved by the European Commission
- Binding Corporate Rules, where applicable
- Derogations under Article 49 of the GDPR in limited circumstances
You may request a copy of the relevant safeguards by contacting us at the email address above.
Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law. Specifically:
- Engagement records. Retained for the duration of the engagement and for a period of up to ten (10) years after its completion, in line with Bulgarian accounting, tax, and commercial record-keeping requirements.
- Enquiry and prospect data. Retained for up to twenty-four (24) months after the last meaningful interaction, unless an engagement is entered into or you opt out earlier.
- Newsletter and marketing data. Retained until you unsubscribe or withdraw consent, after which we retain a minimal record of your opt-out for suppression purposes.
- Analytics data. Retained in accordance with the settings of the analytics provider, typically between fourteen (14) and twenty-six (26) months.
- Records required by law. Retained for the minimum period required by applicable law, including tax, accounting, anti-money laundering, and sanctions compliance obligations.
Once the applicable retention period expires, personal data is deleted, anonymized, or archived in line with our internal retention schedule.
Data Security
We implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include access controls, encryption in transit, secure hosting, regular backups, and staff training on data protection and confidentiality.
However, no method of transmission over the Internet or method of electronic storage is fully secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of any credentials you use to access our services, and for notifying us promptly of any suspected unauthorized access.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of affected individuals, we will notify the Bulgarian Commission for Personal Data Protection within seventy-two (72) hours of becoming aware of the breach, and, where required, notify affected individuals without undue delay.
Your Rights
Under the GDPR and applicable Bulgarian law, you have the following rights in relation to your personal data:
- Right of access. You may request confirmation of whether we process personal data about you, and obtain a copy of that data together with information about how it is processed.
- Right to rectification. You may request correction of inaccurate or incomplete personal data.
- Right to erasure ("right to be forgotten"). You may request deletion of your personal data in certain circumstances, for example where the data is no longer necessary for the purposes for which it was collected.
- Right to restriction of processing. You may request that we restrict the processing of your personal data in certain circumstances, for example while a request for rectification is being considered.
- Right to data portability. Where processing is based on consent or on the performance of a contract and is carried out by automated means, you may request that we provide your personal data in a structured, commonly used, machine-readable format, or transmit it to another controller.
- Right to object. You may object to processing based on our legitimate interests, including profiling. You may also object to processing for direct marketing purposes at any time.
- Right to withdraw consent. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, please contact us at tokenomics@findas.org. We may request additional information to verify your identity before responding to your request. We will respond within one month of receipt of a valid request, subject to extension by up to two further months where necessary given the complexity and number of requests. We will inform you of any such extension within the initial one-month period.
We do not charge a fee for exercising your rights. However, where a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act on the request, in accordance with the GDPR.
Lodging a Complaint
If you believe that our processing of your personal data infringes the GDPR or applicable Bulgarian data protection law, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement.
In Bulgaria, the competent supervisory authority is:
Commission for Personal Data Protection (Комисия за защита на личните данни)
2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria
Email: kzld@cpdp.bg
Website: www.cpdp.bg
We would appreciate the opportunity to address your concerns directly before you contact the supervisory authority, so we encourage you to reach out to us first.
Children's Privacy
Our services are directed to businesses and professionals, not to children. We do not knowingly collect personal data from individuals under the age of sixteen (16). If you believe that a child has provided us with personal data, please contact us and we will take steps to delete that information.
Third-Party Links
Our website may contain links to third-party websites, services, or applications that are not operated by us. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you interact with. We are not responsible for the privacy practices or content of third-party services.
Automated Decision-Making
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal requirements, or for other operational reasons. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or through a notice on our website.
We encourage you to review this Privacy Policy periodically to stay informed about how we handle your personal data. Your continued use of our website or services after the revised Privacy Policy takes effect constitutes your acceptance of the changes.
Contact Information
Questions, comments, or requests regarding this Privacy Policy should be sent to us at tokenomics@findas.org.
FinDaS Ltd
tokenomics@findas.org
Lagera 41A, Sofia, Bulgaria
VAT: BG206266006