1. Controller and scope
Bultopia Ltd., BG205309052, 32 Yordan Nenov str., 4400 Pazardzhik, Bulgaria, is responsible as controller for the personal data described in this notice. MyBestClick is our trading brand. Privacy correspondence is handled by Petar Ivanov, CEO, through the Contact page’s form or protected email access, or by telephone on +359 885 644 339. You do not need a MyBestClick account to raise a question or exercise your rights.
This notice covers the public website at www.mybestclick.net and related business correspondence. Account administration, advertising delivery on publisher properties, push subscriptions and particular RTB, feed, x402 or MCP connections may involve additional data and different controller or processor roles. Read the notice and agreement for that service; a choice saved on this website does not control every other website or platform.
The public site does not request browser notification permission, run a live advertising auction or connect to your AI agent. Its diagrams are local demonstrations. Login and registration take place in the separate account portal.
2. Information we receive
Website connections: IP address, requested page or resource, date and time, browser and device information, and technical status or error information needed to serve and protect the website. A server request can contain a referring page and URL parameters. Do not place confidential or sensitive information in a URL.
Enquiries: your name, work email, website address, advertiser/publisher/partner role, selected interest and the message you choose to submit. Emails and telephone correspondence may also contain business contact details, the subject of your request and follow-up information you provide.
Privacy preferences: the choices you save for Analytics and Marketing, a configuration version and an expiry time in your browser’s localStorage. Optional providers can receive device, connection, usage and identifier data after the relevant consent, as explained below.
We do not ask for identity documents, card details, passwords, wallet private keys or special-category personal data in the public enquiry form. If you act for someone else, share only information you are entitled to provide and tell that person about the relevant processing.
3. Purposes and legal bases
Website delivery and security: we process necessary technical information to respond to page requests, diagnose errors and prevent misuse. The basis is our legitimate interest in operating a functional and secure business website (Article 6(1)(f) GDPR). We consider the impact on visitors and limit the information used to the relevant purpose.
Business enquiries: we use your contact details and message to respond, assess the requested service and handle related correspondence. Where you request steps toward a contract as an individual, the basis is Article 6(1)(b) GDPR. When you represent an organization, our basis is the legitimate interest in communicating with its representatives and managing that business relationship (Article 6(1)(f)).
Optional Analytics and Marketing: the basis is your separate consent (Article 6(1)(a)), together with the consent required for optional device storage or access. We do not treat a request for a quotation or acceptance of terms as permission for these services or as a newsletter subscription.
Legal duties and disputes: where necessary, information is used to meet a specific legal obligation (Article 6(1)(c)) or establish, exercise or defend legal claims (Article 6(1)(f)). Those purposes may require retaining particular correspondence after an ordinary enquiry has ended.
4. Enquiries, protected email access and security checks
When direct sending is available, submitting the form sends the enquiry to our server for validation and email delivery to the MyBestClick team. It is not stored in a website enquiry database. We use Gmail, provided by Google, for business correspondence and storage of delivered messages. Email processing is necessary to handle your message and is separate from optional Google Analytics consent. The form implementation does not include your message or contact fields in analytics or advertising events.
Cloudflare Turnstile protects enquiry submission and access to our email address. When these controls are used, Cloudflare receives connection and browser/device signals, including an IP address, to assess whether the request is automated. Our server verifies the resulting token, expected website and action before sending an enquiry or revealing the address. This security processing is separate from optional Google Analytics and Meta Pixel consent; it does not add your enquiry fields to their events.
If the form offers an email draft after a successful security check, preparation stays in the current page until you choose to open it in your email application or copy it. The website does not deliberately save unsent fields or prepared drafts beyond that page. Your browser may retain or restore information through autofill or navigation caching; your email application may retain drafts and sent messages under its own settings.
To limit abusive submissions, the application can temporarily process an IP address supplied by the configured server infrastructure and derive a keyed identifier for request counting. The application keeps the identifier, counters and expiry times in memory, not raw IP addresses or message contents in a rate-limit database. Separate server infrastructure can keep technical logs. We do not log Turnstile tokens or retain them in a website database. If verification is unavailable, the protected online action is unavailable; you can telephone us or write to our postal address.
5. Google Analytics 4 — optional Analytics
If you accept Analytics, the website loads Google Analytics 4 to help us understand visits, navigation and interest in our services. It measures page views, clicks to registration, email and telephone, and an enquiry event after our email server accepts a direct submission. A registration click is not recorded as a completed account registration; preparing a draft is not recorded as a submitted enquiry. Google receives usage events, browser/device information, analytics identifiers and connection data needed to receive the requests. Its infrastructure and applicable Google entities process those data under the relevant service terms.
Our manually configured events use the page origin, path and title, omit query strings and fragments, and send an empty page-referrer field. Interaction events use fixed categories such as advertiser/publisher, header/footer/content and email/phone. They do not include your name, email address, telephone number, supplied website, message, enquiry reference or email-draft contents. Our configuration disables Google signals and advertising personalization. Google’s service and account settings also affect processing; the manual event configuration does not define every technical datum received by Google.
Analytics cookies are configured with a maximum age of 180 days without extending that duration on each visit. That cookie duration is different from retention of event data in the Analytics property. You may decline Analytics or withdraw it using Cookie settings.
6. Meta Pixel — optional Marketing
If you accept Marketing, Meta Pixel sends PageView events for advertising measurement and audience creation. Meta receives page and browser signals, connection information and applicable identifiers. Unlike our manually configured Analytics events, the pixel can receive the current full page URL, including parameters, and referring-page information.
Meta may associate these signals with a Meta account or other information it holds. This is an advertising-related use, not solely anonymous site statistics. Our implementation does not explicitly send contact-form fields or advanced-matching values and disables automatic configuration in its initialization. Meta’s own processing and account-level settings are governed by its applicable terms.
For EEA services, the relevant provider includes Meta Platforms Ireland Limited and its affiliates. Meta also processes information for its own purposes under its privacy policy. Where the Meta Business Tools terms provide for joint responsibility for collection and transmission, the applicable Controller Addendum describes the allocation of those responsibilities. You can raise a request with us or use Meta’s privacy controls.
7. Choices and withdrawal
Analytics and Marketing start off and require separate category choices. You may accept all, reject optional services or save individual choices. Closing a notice, scrolling or continuing to browse does not activate either category. You can use the public content and contact channels without accepting them.
Open Cookie settings to withdraw or change your choice. The website disables its relevant integration and attempts to clear matching first-party cookies it can access. It cannot erase provider-held information, inaccessible cookies or cookies on another domain. Use the provider’s controls or contact us about information already processed. Withdrawal does not affect the lawfulness of processing before withdrawal.
Choices apply to this website and browser. Other devices, tabs, the account portal and publisher properties may require their own settings. Our cookie controls are not a network-wide advertising opt-out. The Cookies Policy explains the browser-storage inventory and how to remove it.
8. Who receives information
People authorized to handle your enquiry, support request, security issue or privacy request within Bultopia may access the relevant information. Google provides the Gmail service used for our business correspondence. Infrastructure, server administration and professional service providers may also process information to the extent needed for their role. The terms and data-protection arrangements applicable to each service govern its processing.
Cloudflare provides Turnstile for the security checks described above. Google receives data when Analytics is accepted; Meta receives data when Marketing is accepted. Their purposes are described above. Sending an enquiry does not authorize us to upload its contents as an advertising audience. This website has no contact-list sale or newsletter-registration function.
Information may be shared with advisers, competent authorities or other recipients where a legal obligation requires it or where necessary and lawful for a claim or security investigation. We limit any such disclosure to the relevant purpose. Contact us for details about recipients applicable to your enquiry.
9. Hosting in the United States and international processing
The public website is hosted on a server in the United States. Connecting to the site therefore involves processing necessary connection information there. If you submit an enquiry through the website’s direct-send mode, the enquiry passes through that server before email delivery. Hosting in the United States is separate from your optional Analytics or Marketing choice.
Cloudflare, Google’s Gmail and Analytics services, Meta and infrastructure providers may also process information outside the European Economic Area. The protection available in another country can differ from the protection in the EEA. A server being owned or managed by us does not by itself remove the international-data-processing considerations.
Where a restricted transfer to a recipient outside the EEA occurs, the arrangement must use a mechanism permitted by the GDPR, such as an applicable adequacy decision or appropriate contractual safeguards, with supplementary measures where required. An adequacy framework applies only to recipients and processing it covers; we do not claim that every US provider is certified. Contact us for the recipient and safeguards relevant to your data and, where applicable, a copy subject to necessary redactions.
10. How long information is kept
Unsent website form input and the site’s prepared draft are temporary page state. Our retention schedule for ordinary enquiry emails is seven days after the enquiry is resolved and the related follow-up is completed. While an enquiry remains open, we retain the correspondence needed to answer it.
Our adopted retention schedule calls for deletion of routine technical web-server logs seven days after recording. Specific records may be kept longer where needed for an unresolved security incident, a legal preservation obligation or a dispute. Contract and accounting records follow their applicable statutory requirements. Any extended retention is limited to the relevant record and purpose; it does not justify keeping every enquiry or log indefinitely.
This deletion schedule covers copies under our control, including email folders and retained exports. Google and Cloudflare may retain information under their own service obligations and policies; our seven-day schedule for enquiries and website logs is not a promise that every provider-held copy, verification record or technical record is erased on the same date. Contact us about the handling of a specific message or preservation exception.
The saved cookie preference is used for up to 180 days. An expired or incompatible record is ignored; browser storage may retain the unused entry until it is overwritten or you remove site data. The rate limiter uses short counting windows, and expired in-memory entries are cleared during later request processing or when the process restarts.
Analytics-cookie lifetime does not determine how long Google retains event data, and Meta sets its own cookie and service retention rules. Provider-held data and reports follow the relevant account settings, purposes and provider terms. You may ask us about the applicable setting or request deletion where the right applies.
11. Security and confidentiality
We limit enquiry handling to its business purpose and use measures appropriate to the information and processing. The form includes server-side validation, request limits and controls against cross-site submissions and abusive sending. Operational checks monitor website availability and technical delivery failures separately from optional visitor analytics. Our own operational alerts use fixed technical status codes without enquiry contents or contact fields. These measures reduce risk; they do not make internet communication or email storage risk-free.
Do not send passwords, payment credentials or unnecessary sensitive information. If you believe an enquiry or other website information has been accessed improperly, contact us with the relevant details. We assess incidents and make the notifications required by applicable law.
12. Your rights and how to request them
Subject to the conditions in data-protection law, you can request access to and a copy of your personal data, correction of inaccurate data, deletion, restriction of processing and portability of data processed automatically on the basis of consent or a contract.
You can object to processing based on legitimate interests on grounds relating to your situation. You can object to direct marketing at any time, including related profiling. You can also withdraw consent without affecting processing that was lawful before withdrawal.
Send your request using the Contact page’s form or protected email access, telephone us or write to the company address below. Explain which data or interaction your request concerns. We may ask for proportionate information to verify identity or authority; do not send an identity document unless we explain why it is needed and how to provide it securely.
We respond without undue delay and normally within one month. If the law permits an extension because of complexity or the number of requests, we will notify you within that first month and explain the reason. Requests are normally free. If we cannot act, we will explain the applicable reason and available complaint or judicial remedies.
13. Complaints, children and automated decisions
You may complain to the Bulgarian Commission for Personal Data Protection, or the competent supervisory authority in the country of your habitual residence, workplace or the alleged infringement. You do not have to contact us first. The Commission publishes current filing methods and requirements at the link below.
The public site is aimed at business audiences and does not knowingly seek personal data from children. If you believe a child has provided information, contact us so that we can assess and address it.
The public website and enquiry form do not make decisions based solely on automated processing that have legal or similarly significant effects. Advertising measurement and audience creation by Meta are described separately above. An animation of campaign optimization or an AI flow does not itself perform that processing on you.
14. Required information and notice updates
You can browse without sending an enquiry. The form identifies required fields and asks for the information needed to route and respond to a business request. A website or app link is optional for advertisers and billing or account-support enquiries. It is required for publisher and supply/demand partnership enquiries. Protected email access, telephone and our postal address are alternative contact channels. The form and email reveal require a successful security check; telephone and postal contact do not. If necessary information is missing, we may be unable to assess or answer that request. Optional tracking is not a condition for contacting us.
We update this notice when relevant processing changes and show the revision date above. Material changes will be explained through an appropriate notice before new processing begins where required. A revised Privacy Notice is information about processing; continued browsing is not consent to a new purpose or optional service.
MyBestClick account portal
This notice covers the public marketing website. For account services, also review the portal terms and portal privacy policy, together with any agreement specific to your account.
Contact and company details
Bultopia Ltd.
BG205309052
32 Yordan Nenov str., 4400 Pazardzhik, Bulgaria
Contact options and enquiry form. Email access uses a security check. You can also telephone us or write to the company address above.
Bulgarian Commission for Personal Data Protection — complaints ↗
