Updated 12.06.2025

 

We take care about your personal data protection

Who are we?

"Toplofikacia Sofia" EAD is a commercial company registered in the Commercial Register at the Registry Agency with UIC 831609046, with its principal office and registered address: Sofia 1680, Yastrebets Str. 23 B and is a personal data administrator, under the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27.04.2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) and the Personal Data Protection Act.

 

How to contact us?

Correspondence address: 23B Yastrebets Street, 1680 Sofia, Bulgaria;
Contact details of the personal data protection officer of "Toplofikacia Sofia" EAD: Galya Trencheva - Data Protection Officer;
Email address - dpo@toplo.bg.

This email is used solely for questions related to the processing of your personal data by “Toplofikacia Sofia” EAD in its capacity as a data controller, as well as for exercising your rights under Articles 15–22 of Regulation (EU) 2016/679, subject to the provisions of the Electronic Document and Electronic Authentication Services Act, the e-Government Act and the Electronic Identification Act.

After receiving your request, which meets the legal requirements, you will receive additional information about the registration number of the request from the personal data protection officer on your email. In this case, the date of application is considered the date of receipt of the application by e-mail within the working hours of „Toplofikacia Sofia “EAD.

Actions on consideration of the request in substance are taken only if the submitted request meets the requirements of Article 37b and Article 37c of the Personal Data Protection Act.

For any other general inquiries concerning the activities of “Toplofikacia Sofia” EAD, PLEASE use the customer service email address: - info@toplo.bg.

 

What is the Privacy Policy?

This privacy policy aims to give you comprehensive information in clear and accessible language about the processing of the personal data you provide to “Toplofikacia Sofia” EAD, including:

- What personal data do we collect about you?

- What is the purpose of their collection?
- For what period do we store your personal data?
- Whom can we disclose your personal data to?
- What are your rights regarding your personal data?
- How do we notify you about changes of our Privacy Policy?
- What types of cookies do we use for better experience on our website?

With this Privacy Policy „Toplofikacia Sofia“ EAD declares that it implements all technical and organizational measures to protect the personal data of natural persons/data subjects, which are prescribed by law or other normative act at the national and European level.

 

What is personal data?

Personal data means any information relating to an identified or identifiable natural person (“data subject”) who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

“Toplofikacia Sofia” EAD processes your personal data in lawful, fair and transparent manner. Where processing of personal data is not grounded on law or contractual relations, the data subject must have given previous consent to the processing of his or her personal data for one or more specific purposes. Processing is lawful where it is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.

 

What personal data does “Toplofikacia Sofia” EAD collect about you?

In order to provide effective access to our products/services, “Toplofikacia Sofia” EAD collects the following information about you:
- First and last name, phone number, email, town/city, address, bank account details, customer number, and other information when you fill out various forms on our website;
- The last four digits of your Personal Identification Number or Unique Identification Code (UIC), installation number, and contract account number – when registering in the My Portal service;
- Technical data automatically sent to us when you use our website or mobile application;
- IP address, information about the device you use to access the website and mobile app;
- Cookies used to identify your browser or device, among others.

 

On what Legal Basis does “Toplofikacia Sofia” EAD process your personal data?

Personal data processing includes collecting, storing, transmitting, correcting, updating, deleting, destroying, and all other actions performed on your personal data.

"Toplofikacia Sofia" EAD collects your personal data in order to fulfill its contractual obligations under service agreements concluded with you — on a contractual basis.

"Toplofikacia Sofia" EAD collects personal data after receiving your explicit, clear, free and unambiguous consent for specific processing purposes, such as marketing and receiving promotional newsletters.

Personal data is provided voluntarily by individuals and collected by "Toplofikacia Sofia” EAD in compliance with legal obligations, in relation to contract conclusion and/or the performance of obligations under a concluded contract in accordance with the Energy Act, Condominium Property Management Act, Public Procurement Act, Commercial Act, Obligations and Contracts Act, Value Added Tax Act, and others, as well as the conditions set out in the agreement with the respective customer, via: paper format – written documents (including powers of attorney, contracts, garnishment notifications, bank information, etc.); email – provided in relation to contract performance or by filling in a registration form.

"Toplofikacia Sofia” EAD also processes personal data in compliance with legal obligations, or when necessary to protect the life and health of the natural person the data refers to.

"Toplofikacia Sofia" EAD may also process personal data if there are legal (legitimate) interests, unless the interests of the natural person to whom the data refer override these interests.

 

For what purposes do we collect your personal data?

The personal data you provide will be used to enable us to fulfill our obligations to you, as well as to help you exercise your rights, including, but not limited to:

- To respond to your inquiries, feedback, and suggestions;
- To provide you with the services/products offered by "Toplofikacia Sofia" EAD;
- To give you access to our website by displaying content that is relevant, personalized, and tailored to the preferences you have set;
- To send you information related to special campaigns and new products and services.

In addition to the above, we have a legitimate interest in collecting your personal data, as we cannot deliver the services/products you are interested in without it. We also process your data to comply with legal obligations or to protect legitimate interests, except where such interests are overridden by your rights and freedoms as a data subject.

 

How do we process your personal data?

In order to provide products and services, "Toplofikacia Sofia" EAD processes the personal data you provide regarding your physical, economic, social and family identity in the following ways:

- by filling in applications, forms and declarations provided to you by employees of "Toplofikacia Sofia" EAD. The forms are provided and filled in at our offices in case you make a request for the provision of services;
- by visiting the web portal for using the services of our website;
- when updating data at your request and filling out an update form on paper or in an electronic environment.

 

How long do we store and process your data before it is destroyed?

The retention period of your personal data depends on the legal basis for processing.

Personal data is stored until the legal basis for processing under Art. 6 of Regulation (EU) 2016/679 no longer applies. The keeping terms are in accordance with Bulgarian legislation, as well as the Nomenclature of cases with keeping terms in "Toplofikacia Sofia" EAD, which is maintained under the National Archive Fund Act. Data are not stored longer than necessary.

According to the principles promulgated in Regulation (EU) 2016/679 and, in particular, Article 5(1)(b)(e) personal data may be lawfully retained in a form allowing identification of the data subject for a period that is not longer than is necessary (principle of limitation of the storing).

 

Whom can we disclose your personal data to?

„Toplofikacia Sofia “EAD undertakes to not provide your personal data to third parties without your explicit consent, unless where necessary to fulfil contractual obligations towards you.

In fulfilling its existing contractual and/or pre-contractual obligations towards you „Toplofikacia Sofia “EAD may disclose your personal data to the following persons:

- Companies providing courier services;
- Share distribution companies;
- Collector companies;
- The company maintaining the call center.

Disclosure of your personal data is possible only in cases where the information is requested by state authorities or officials authorized by law to request and collect information containing personal data, and in compliance with the legal procedure.

“Toplofikacia Sofia” EAD does not transfer your personal data to third countries (outside the European Union) or international organizations.

 

Are there other cases in which we may disclose your personal data?

Your personal data is disclosed to third parties also in the following cases:
- At the request of the individual who has provided the data and is the data subject;
- At the request of competent authorities under the current law of the Republic of Bulgaria and the European Union.

In all such cases, the persons to whom we disclose your personal data have declared that they provide an adequate level of protection of your personal data, including the foreign companies operating in the European Union and the European Economic Area.

 

What are your rights regarding your personal data?

According to Article 15 – Article 22 of Regulation (EU) 2016/679 regarding the protection of personal data, you may exercise the following rights:
- Right to access to your personal data processed by „Toplofikacia Sofia “EAD and to have a copy of them;
- Right to request that „Toplofikacia Sofia „AD rectified your personal data if you find inaccuracies or the need to update;
- Right to deletion (“right to be forgotten”) of personal data that is processed unlawfully or on terminated legal grounds (expired keeping term, withdrawn consent, fulfilled initial purpose for which they were collected, etc.);
- Right to request restriction of the processing of the personal data in the cases specified by the Regulation and by law:
- Right to object – at any time and on grounds relating to the particular situation of the individual provided that there are no compelling legal grounds for the processing that take precedence over your interests, rights and freedoms, or during a legal case;
- Right of portability of your personal data in a structured, commonly used and machine-readable form;
- The right to lodge a complaint for the protection of your rights with the competent authority for the protection of personal data, that is, the Commission for Personal Data Protection of the Republic of Bulgaria, if there are prerequisites for this;

You may exercise any of your rights at any time during the processing of your personal data.

 

What does each of the above rights mean?

Right of access to personal data.

This right allows you to obtain confirmation of whether your personal data is being processed, the purposes of processing, the recipients or categories of recipients (especially those in third countries or international organizations), and to request the rectification or erasure of your personal data or restriction of processing from “Toplofikacia Sofia” EAD.
Data will not be provided if you already possess it or if a legal provision explicitly prohibits its disclosure.

Right to rectification, erasure (“right to be forgotten”), restriction of processing
Right at any time to request from „Toplofikacia Sofia “EAD to rectify, delete or restrict the processing of your personal data that is not compliant with the requirements of the Regulation or of the Personal Data Protection Act.

Right to object

As a data subject, you have the right at any time and on grounds related to a specific situation to object to the processing of your personal data. “Toplofikacia Sofia” EAD terminates the processing of personal data unless he can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or for the establishment, exercise or defense of legal claims. Where personal data are processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing. Where you object to processing for direct marketing purposes, the processing of your personal data for such purposes is terminated.

Right of portability

Where the processing of personal data is carried out by automated means, you are allowed to receive personal data concerning you, which you have provided to the controller, in a structured, commonly used, machine-readable and interoperable format, and to transmit it to another controller.

That right should apply where the data subject provided the personal data on the basis of his or her consent or the processing is necessary for the performance of a contract. It should not apply where processing is based on a legal ground other than consent or contract. By its very nature, that right should not be exercised against controllers processing personal data in the exercise of their public duties. It should therefore not apply where the processing of the personal data is necessary for compliance with a legal obligation to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of an official authority vested in the controller. The data subject's right to transmit or receive personal data concerning him or her does not create an obligation for the controllers to adopt or maintain processing systems which are technically compatible. Where, in a certain set of personal data, more than one data subject is concerned, the right to receive the personal data should be without prejudice to the rights and freedoms of other data subjects in accordance with this Regulation.

The rights under Article 15-22 of the Regulation may be exercised personally or by a person explicitly authorized by you by submitting a written request. The request must include:
1. name, address, Personal Identification Number or personal number of a foreigner or other similar identifier, or other identification data of the natural person determined by the personal data controller in connection with the performed activity;
2. description of the request;
3. preferred form of obtaining information when exercising the rights under Articles 15-22 of Regulation (EU) 2016/679; 4. signature, date of submission of the request and address for correspondence.

The Personal Data Protection Act does not require notarization of the power of attorney to exercise the rights under Regulation (EU) 2016/679.

Requests are submitted on paper at the Administrative Service Centre of „Toplofikacia Sofia“ EAD at: 1680 Sofia, 23B Yastrebets St.(download it here in pdf format) or electronically (the request must be signed with a qualified electronic signature). The sample form for requesting the exercise of rights is only indicative. The rights may be exercised by the data subject also through a written request in free text, which contains sufficient and accurate information in compliance with the requirements specified in Regulation (EU) 2016/679 and the Personal Data Protection Act.

To facilitate the exercise of your rights under Articles 15-22 of Regulation (EU) 2016/679 “Toplofikacia Sofia” EAD provides you with paper requests in each of our customer service centers.

Right to approach the Personal Data Protection Commission

If your rights are violated, you may approach the Personal Data Protection Commission within 6 (six) months of becoming aware of the violation, but no later than 2 (two) years after the violation. If your rights are violated, you may appeal actions and acts of the personal data controller in court or before the Supreme Administrative Court. The court cannot be approached if there is a pending proceeding before the Commission for the same violation or if the Personal Data Protection Commission has ruled on the same violation with an effective court ruling.
Contacts of the Personal Data Protection Commission: Sofia 1592, 2 Professor 2 Professor Tsvetan Lazarov Blvd., email: kzld@cpdp.bg, website: www.cpdp.bg.

 

At „Toplofikacia Sofia “EAD, video surveillance is carried out for security purposes. The video recordings from the video surveillance cameras contain video images of the movement of employees and visitors around the approaches to the buildings of „Toplofikacia Sofia “EAD, and in the common and security areas. Data is stored for 2 (two) months under the Private Security Act. Certain employees have access to the data within the scope of their official duties. The collected data is provided to third parties only in cases where this is provided by law, for example to public authorities, in view of their powers and competence. „Toplofikacia Sofia “EAD provides appropriate technical and organizational measures to protect your personal data.

 

The processing of personal data of visitors to „Toplofikacia Sofia “EAD is carried out by employees managing the access. The purpose of collecting personal data is identification of natural persons visiting the building of „Toplofikacia Sofia “EAD and access control. Certain employees have access to the data within the scope of their official duties. The collected data is provided to third parties only in cases where this is provided by law, for example to public authorities, in view of their powers and competence. „Toplofikacia Sofia “EAD provides appropriate technical and organizational measures to protect your personal data.

 

“Toplofikacia Sofia” EAD records telephone conversations (incoming and outgoing) with call centers and lines (telephone numbers) intended for customer service. The recording of telephone conversations and the storage and processing of audio recordings (together with the personal data disclosed within the conversations) is carried out for the purposes of protecting the rights and the legitimate interests of the company. „Toplofikacia Sofia “EAD stores the records for a certain period, after which the earliest data are deleted automatically depending on the system settings. If you do not want the phone calls to be recorded, please let us know.

 

Changes to Security Policies – (Privacy Notice)

We declare that we will notify you about any changes of these Privacy Policies through the company's website and mobile application.

This Privacy Policy may be updated and supplemented without notice due to updates of laws or changes of our personal data processing policy. The new update will be effective from the date of the last change, indicated in the upper left part of the Privacy Policy. Using the website and mobile application after the publication of the update means you accept the changes.

 

Cookie Policy

GENERAL PROVISIONS

Cookies are small text files that are saved on your computer when you visit our website. If you access this website later, your browser sends back the contents of the cookies and thus allows the re-identification of the terminal device. Reading cookies allows us to design our website optimally for you and facilitates you in its use. The mobile application uses technologies analogous to cookies and applies the same data protection rules. These technologies support the functionality of the application, security and usage analytics. Users have the opportunity to manage their preferences and consents regarding data collection through the settings of the application or their device.

 

DISABLING AND DELETING COOKIES

The browser allows you to delete all cookies at any time.
In the mobile application, data collection can be restricted or refused through device settings.

 

REQUIRED COOKIES

Certain cookies are necessary securely provide our services through our website and mobile application. This category includes:
- Cookies that identify or authenticate our users;
- Cookies that temporarily store certain user data (e.g. content of an online form);
- Cookies that store certain user preferences (e.g. search settings or language settings);
- Cookies that store data to allow uninterrupted playback of video or audio content.

 

ANALYTICAL COOKIES

We use analytical cookies to log user behavior (e.g. clicks on ad banners and entered search queries) and to statistically evaluate these actions.

 

WEB ANALYTICS

We need statistical information about the use of our website to make it more accessible, to measure reach and to do market research. For this purpose, we use the web analysis tool Matomo - analytics tool, which creates anonymized user profiles using performance cookies or log files. These profiles contain no personal data.

You may object to the collection and processing of your data through the privacy settings on our site by disabling performance cookies.

If you do not want information about your application usage to be collected for analytical purposes, you can restrict this via your mobile device settings.

 

THIRD PARTY COOKIES

The website and mobile application may contain links to other sites or embedded content from third parties (e.g. from Facebook , YouTube , etc.). When you visit such other sites or when you open pages in which third-party content is embedded, there is a possibility that third-party cookies will be placed on your terminal device.

"Toplofikacia Sofia" EAD has no control over the generation and management of third-party cookies. For more information about the purpose of using third-party cookies and their content, please find and read the Privacy and Cookies Policies adopted by the relevant third parties.

Most commonly available browsing programs (browsers) by default allow the placement of cookies on the terminal device. If you prefer, you may change the settings of your browser to delete the existing cookies or to block automatically the placement of cookies (including third-party cookies). However, doing so may affect the accessibility or functionality of this website and mobile application.

More information about cookies, including the options for their management, can be found at: https://www.allaboutcookies.org/manage-cookies.

By visiting our website and mobile application, you agree to the use of cookies in accordance with the terms and conditions of this Privacy and Personal Data Protection Policy.

The site is protected with Google reCaptcha. You can read their Privacy Notice and Terms and Conditions.