"Galin Atanasov", Attorneys-at-law
www.galin-atanasov.com
This Privacy Policy (hereinafter referred to as the "Policy") explains how Galin Atanasov, Attorneys-at-law ("Law Firm") collects, processes, and stores your personal data when processing inquiries, concluding contracts with the Law Firm, using the services of the Law Firm, visiting the Law Firm's website (www.galin-atanasov.com) and/or the Law Firm's premises.
The Law FIrm complies with all requirements of the General Data Protection Regulation ("GDPR", "Regulation (EU) 2016/679"), the Personal Data Protection Act ("PDPA") and applicable Bulgarian legislation when collecting, processing, and storing your personal data.
§ 1. What is important to know about this Policy?
This Policy was adopted and approved by the Law Firm on June 26, 2025.
As a person who is a party to or intends to enter into a relationship with the Law Firm of any nature, you are required to familiarize yourself with this Privacy Policy, as it contains information about the Law Firm's obligations and your rights in relation to the collection, processing, and storage of your personal data, in accordance with the principles set out in Article 5 of the GDPR.
Consent to the terms of this Policy is a condition for entering into and implementing legal relations with the Law Firm. If you do not agree with this policy, you will not be able to enter into legal relations and/or use the services of the Law Firm.
If you have any questions or need additional information, you can always contact us using the contact details provided at the end of the Policy or on the Website.
§ 2. Who is responsible for your data?
The administrator of your personal data is Galin Atanasov, attorney-at-law, member of the Sofia Bar Association, with personal attorney number in the Register of the Supreme Bar Council No. 1500746210, with address: Sofia 1000, Positano Square No. 3, Office 12.
You can send any questions regarding the processing of your personal data to the following email address: office@galin-atanasov.com
§ 3. Definitions
The terms used in this Policy shall mean, as follows:
Personal data – any information relating to an identified or identifiable natural person ("data subject"); an identifiable person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Processing of personal data – any operation or set of operations performed on Personal data by automated or other means, such as collection, recording, organization, structuring, storage, adaptation, modifying, retrieving, consulting, using, disclosing by transmission, dissemination or otherwise making available, aligning or combining, restricting, erasing, or destroying.
Data subject – the natural person whose personal data is being processed.
Personal data controller – a natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data.
Personal data processor – a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.
Recipient of Personal data – a natural or legal person, public authority, agency, or other body to which the personal data is disclosed, whether a third party or not.
Third party – a natural or legal person, public authority, agency, or other body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data.
Consent of the data subject – any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
Personal data breach – a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.
Special categories of personal data (sensitive data) – data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data, health data, data concerning sex life or sexual orientation.
Profiling – any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person.
Pseudonymization – processing personal data in such a manner that the data cannot be attributed to a specific individual without the use of additional information, which is stored separately.
Restriction of processing – marking stored personal data for the purpose of restricting its processing in the future.
§ 4. What types of data are we gathering and why?
The Law Firm adheres to the principle of processing the minimum personal data necessary for the purposes of processing. The Law Firm processes only those personal data that are necessary to provide you with quality services and to comply with our legal obligations.
The data we collect, process, and store may include:
- Your names, personal identification number (PIN) or foreigner's personal number (FPN), date of birth, and gender;
- Contact details such as address, telephone number, email address, social media profiles, if you have provided such details to the Law Firm;
- Financial information necessary for issuing invoices and payments to suppliers, employees, and customers;
- Information from communications with us – for example, if you email or call us;
- Data collected when using our website, such as cookies, IP addresses, and logs (Art. 4, para. 1 and Art. 6 of the GDPR), in accordance with the Cookies Policy adopted by the Law Firm;
§ 5. How do we gather your data?
In most cases, you provide us with your data yourself – when you book a legal consultation, when you use our services, when you communicate with us, visit our website, provide us with financial information, or similar. Sometimes we receive information and personal data automatically, for example when you visit our website (so-called cookies).
When performing the described activities related to the collection and processing of your personal data, the Law Firm complies with the principles set out in Article 5 of the GDPR, and in particular those relating to the limitation of the purposes of collection and processing within the meaning of Article 5(1)(b) of the GDPR and the minimization of data within the meaning of Article 5(1)(c) of the GDPR. b) of the GDPR and minimising data in accordance with Article 5(1)(c) of the GDPR.
§ 6. Purposes of data processing
The law firm processes your personal data only for specific, explicitly defined and legitimate purposes, in accordance with the principle of purpose limitation (Art. 5, para. 1, item "b" of the GDPR), as follows:
| Purpose of processing | Types of data | Legal grounds |
| Communication and administration (booking appointments, reminders, responding to inquiries) | - Name, phone number, email address - Visit history | - Legitimate interest (Art. 6, para. 1, item "e") - Performance of a contract (Art. 6, para. 1, item "b") |
| Compliance with legal obligations (accounting, tax returns) | - Name, personal identification number - Financial information | - Legal obligation (Art. 6, para. 1, item "c") |
| Security and fraud prevention (protection of persons/property) | -Website access logs | - Legitimate interest (Article 6(1)(f)) |
§ 7. Grounds for data processing
The processing of your personal data is carried out only when one of the grounds expressly provided for in Article 6 of the GDPR is present. Only one valid ground applies to each specific processing operation, and no duplication or overlap of grounds for the same activity is permitted.
Depending on the specific situation, processing may be based on any of the following alternative and equally valid legal grounds:
- Consent – When you have freely given specific, informed, and unambiguous consent to the processing of your personal data for one or more specific purposes (Article 6(1)(a) of the GDPR). Consent may be withdrawn at any time without affecting the lawfulness of processing prior to withdrawal.
- Performance of a contract – When processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract (Article 6(1)(b) of the GDPR).
- Compliance with a legal obligation – When processing is necessary for compliance with a legal obligation to which the Law Firm is subject as a data controller (Article 6(1)(c) of the GDPR). This includes obligations arising from national or European law, such as accounting, tax, health, or labor obligations.
- Protection of vital interests – When processing is necessary to protect your vital interests or those of another natural person, for example in the case of emergency medical care (Article 6(1)(d) of the GDPR).
- Performance of a task carried out in the public interest or in the exercise of official authority – when processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Law Firm, as a controller, under European Union and Bulgarian law (Article 6(1)(f) of the GDPR).
- Legitimate interest – when processing is necessary for the purposes of the legitimate interests pursued by the Law Firm (Article 6(1)(f) of the GDPR), as follows:
| Legitimate Interest Category | Meaning |
| Fraud and Crime Prevention | Processing of data for the prevention, investigation, and reporting of fraud, abuse, or crime. |
| Information and Network Security | Protecting IT systems, preventing unauthorized access, cyberattacks, and security breaches. |
| Direct Marketing | Sending marketing communications to existing customers (with the right to object/opt out). |
| Internal Purposes | Employee management, payroll processing, internal audit. |
| Protection of Property | Video surveillance and other measures for the security of buildings, premises, and property. |
| Product and Services Improvement | Customer behavior analysis, satisfaction surveys, process and quality optimization. |
| Defense of Legal Claims | Storage and use of data for establishing, exercising, or defending legal rights and interests. |
| Public Access to Information | Maintaining public records or providing information for public purposes where justified. |
Data subjects have the right to object to data processing on this basis. When processing on this basis, the Law Firm performs a balancing test between its interest and the interest of the data subject. If it is concluded that the interests of the Law Firm outweigh those of the data subject, the objection is rejected. If it is concluded that the interests of the data subject outweigh those of the Law Firm, the processing is stopped immediately and the data is deleted.
§ 8. Data Retention Periods
We store your data only for the period required by law or as long as necessary to fulfill the purposes for which your data was collected, in accordance with the principle of storage limitation (Article 5, paragraph 1, point "e" of the GDPR). Once the purpose has been achieved or the legal period has expired, the data is deleted.
| Category of personal data / documentation | Retention Period | Legal grounds |
| Job Applicants Data | Up to 6 months after completion of the procedure, unless there is explicit consent for a longer period | Art. 25k Law on Personal Data Protection (LPDP) |
| Employment records, payroll records | 50 years from January 1 of the reporting period following the reporting period to which they relate | Art. 12, para. 1, item 1 Law on Accounting (LA) |
| Accounting records and financial statements | 10 years from January 1 of the reporting period following the reporting period to which they relate | Art. 12, para. 1, item 2 LA |
| Other accounting data | 3 years from January 1 of the reporting period following the reporting period to which they relate | Art. 12, para. 1, item 3 LA |
| Client and Transaction Data (commercial relations) | 5 years from the beginning of the calendar year following the termination of the relationship or the execution of the transaction | Art. 171, para. 1 Tax and Social Security Code (TSSC) |
| Tax and Social Security Control Data | At least 5 years after the expiry of the limitation period for the repayment of the public claim | Art. 38 LA and Art. 38 TSSC |
| Website Visit Access | Period Varies depending on Data Type | In accordance with Cookies Policy |
In some cases (e.g., when hiring), the time limit can be extended with the data subject's consent, which can be withdrawn at any time.
§ 9. Who we may share your data with
Sometimes we need to share your data with third parties in order to provide you with the best service or to comply with legal requirements, in accordance with Article 13, paragraph 1, point (f) of the GDPR. Such third parties may be:
- Insurance companies, accounting service providers and IT support;
- Government institutions and controlling authorities (for example, NZOK, NRA, Ministry of Health, Data Protection Commission)
- Service Providers under Privacy Protection Agreements / NDAs
- Partners in joint events or initiatives – only with your consent.
§ 10. How we use cookies and social media
The website uses cookies to facilitate your work with it, analyze traffic, and provide you with relevant information. The use of cookies is regulated in detail in the Cookie Policy adopted by the Law Firm, located at the following address: https://galin-atanasov.com/en/politika-biskvitki/
§ 11. Automated processing and profiling
We do not make automated decisions and do not profile our customers in a way that could have significant consequences for you, in accordance with Article 22 of the GDPR. If we use automated analysis or marketing tools, it is only for the purpose of improving our services and does not lead to decisions that affect you personally without human intervention.
§ 12. Your rights and how to invoke them
As a personal data subject, you have the following rights under Art. 15-22 GDPR:
- To obtain information about whether and what data we process about you (right of access);
- To request correction of inaccurate or incomplete data (right to rectification);
- To request the deletion of your data ("right to be forgotten") where applicable (Article 17 of the GDPR);
- To restrict the processing of your data;
- To receive a copy of your data in a structured, commonly used, and machine-readable format (right to portability);
- To object to the processing of your data;
- To withdraw your consent when the data processing is based on consent;
- Submit a complaint to the Personal Data Protection Commission (www.cpdp.bg).
You can invoke your rights by sending us a written request in person, by mail, or by email: office@galin-atanasov.com.
We will respond within one month, unless an extension is necessary due to the complexity or volume of the request (Article 12, paragraph 3 of the GDPR).
§ 13. How do we protect your data
We take all necessary technical and organizational measures to ensure the security of your data – we restrict access to authorized persons only, use encryption and secure electronic systems, provide physical protection of the premises, train our staff, and conduct regular checks and audits. We have procedures in place for responding to incidents and restoring data in the event of technical problems, in accordance with Article 32 of the GDPR.
§ 14. How we respond to incidents and data breaches
In the event of a data breach, we will notify the Personal Data Protection Commission and, if necessary, you - within the statutory period, in accordance with Articles 33 and 34 of the GDPR. We will inform you what has happened, what the possible consequences are, and what measures we have taken to mitigate the risk.
§ 15. Adoption and updates to this Policy
The Policy has been adopted by the Law Firm and is valid as of 26.06.2025. The Law Firm may update the Policy at its discretion, in case of changes in legislation or for other reasons.
§ 16. Contact and Appeal Details
If you have any questions, need assistance, or wish to file a complaint regarding the processing of your personal data, you can contact us at office@galin-atanasov.com.
If you are not satisfied with our response, you have the right to contact the Personal Data Protection Commission:
Address: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd.
Tel.: 02/91-53-518
Email: kzld@cpdp.bg
Website: www.cpdp.bg
