Privacy Policy (CEE Centre for Digital Finance)

Last updated: 15 February 2026

This Privacy Policy explains how the CEE Centre for Digital Finance Foundation (“we”, “us”, “our”) collects, uses, shares, and protects personal data when you visit our website digitalfinancecentre.com (“Website”), contact us, subscribe to updates, register for events, or otherwise interact with our services and content.

We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Bulgarian data protection law.

1) Who we are (Data Controller) and how to contact us

Data Controller: CEE Centre for Digital Finance Foundation

Legal form: Foundation (Bulgaria)

Registered address: 9 Shar Planina, Pleven, Bulgaria

UIC/BULSTAT: 208622885

Contact email: dfc@digitalfinancecentre.com

If you have questions about this Policy or wish to exercise your rights, contact us using the details above.

2) Personal data we collect

Depending on how you use the Website and our services, we may collect:

  1. A) Data you provide directly
  • Contact requests / inquiries: name, email, organization, role/title, message content, and any information you choose to include.
  • Newsletter subscription: email address (and optionally name/organization).
  • Event registration / participation: name, email, organization, role, participation preferences, and any other information you submit via registration forms.
  • Partnership / sponsorship inquiries: contact details and information about your organization.

Optional information: If you voluntarily provide details such as dietary/accessibility needs for events, this may constitute sensitive information depending on content (see Section 3).

  1. B) Data collected automatically (online identifiers)

When you access the Website, we may automatically collect:

  • Technical data: IP address, browser type, device and operating system information, referral source, pages viewed, time stamps, and approximate location (derived from IP).
  • Usage data: interactions with pages, clicks, time spent, and aggregated metrics.
  • Cookie data: cookie identifiers and similar tracking technologies (see Section 4).

  1. C) Data from third parties (limited)

If the Website includes embedded third-party services (e.g., YouTube, LinkedIn), those providers may collect data under their own privacy policies.

We do not intentionally collect personal data from children. If you believe a child has provided personal data, please contact us to delete it.

3) Purposes of processing and legal bases (GDPR)

We process personal data for the purposes below, based on the corresponding legal bases:

  1. To respond to inquiries and provide requested information
    • Legal basis: Legitimate interests (GDPR Art. 6(1)(f)) and/or steps prior to entering a contract (Art. 6(1)(b)).
  2. To send newsletters and updates (when you subscribe)
    • Legal basis: Consent (Art. 6(1)(a)).
    • You can withdraw consent anytime via the unsubscribe link or by contacting us.
  3. To organize and administer events (registration, logistics, participation)
    • Legal basis: Contract/performance or steps prior to entering a contract (Art. 6(1)(b)) and/or legitimate interests (Art. 6(1)(f)).
  4. To maintain website security and prevent abuse
    • Legal basis: Legitimate interests (Art. 6(1)(f)).
  5. To measure and improve website performance (analytics)
    • Legal basis: Consent (Art. 6(1)(a)) for non-essential cookies/trackers where required.
  6. To comply with legal obligations (e.g., accounting, tax, statutory reporting where applicable)
    • Legal basis: Legal obligation (Art. 6(1)(c)).

Special categories of personal data

We do not request sensitive data (GDPR Art. 9). If you voluntarily provide information that reveals health status or other sensitive data (e.g., accessibility needs), we will process it only to the extent necessary and typically on the basis of explicit consent (Art. 9(2)(a)) or another applicable exception, with appropriate safeguards.

4) Cookies and similar technologies

We use cookies and similar technologies to operate and improve the Website. Cookies may include:

  • Strictly necessary cookies: required for core functionality and security.
  • Preferences/functional cookies: remember choices (if enabled).
  • Analytics cookies: help us understand usage and improve content (if enabled).
  • Third-party cookies: set by embedded content providers (if enabled).

Cookie choices: You can manage your preferences via our cookie banner/settings and through browser controls. Disabling cookies may affect the Website’s functionality.

Analytics (if used): If we use analytics tools (e.g., Google Analytics), these may process usage data and online identifiers. We configure analytics to the extent available to reduce data (e.g., IP truncation/anonymization, retention limits) and to respect consent signals where required.

5) Who we share your data with

We may share personal data only as needed for the purposes above with:

  • Service providers (processors) supporting website hosting, analytics, email delivery, event registration tools, CRM, and IT/security services. These providers process data under our instructions and subject to contractual safeguards.
  • Event/initiative partners only where necessary for joint delivery (e.g., co-hosted event attendee lists) and only for stated purposes.
  • Public authorities where required by law or to protect rights, safety, and security.

We do not sell personal data.

6) International transfers

Some providers may process data outside the European Economic Area (EEA). Where applicable, we rely on appropriate safeguards such as:

  • European Commission adequacy decisions, and/or
  • Standard Contractual Clauses (SCCs) plus supplementary measures where necessary.

7) Data retention

We retain personal data only for as long as necessary:

  • Inquiries/contact requests: typically up to 12 months after closure.
  • Newsletter subscriptions: until you unsubscribe or withdraw consent.
  • Event administration: typically up to 24 months (or longer if required for legal/financial compliance).
  • Security logs: typically 90 days, unless needed to investigate incidents.
  • Legal/financial records: as required by applicable law.

8) Your rights (GDPR)

You have the right to:

  • Access your personal data
  • Rectify inaccuracies
  • Erase data (in certain cases)
  • Restrict processing
  • Data portability (where applicable)
  • Object to processing based on legitimate interests
  • Withdraw consent at any time (where processing is based on consent)

To exercise rights, contact us at dfc@digitalfinancecentre.com. We may request verification.

You may also lodge a complaint with the Bulgarian supervisory authority:

Commission for Personal Data Protection (CPDP), Bulgaria (Комисия за защита на личните данни).

9) Security

We implement appropriate technical and organizational measures to protect personal data (e.g., access controls, secure hosting, backups, and monitoring). No method of transmission or storage is fully secure, but we maintain safeguards proportionate to risk.

10) Third-party links and embedded content

The Website may contain third-party links and embedded services (e.g., videos, social media widgets). These third parties may collect data independently. Their processing is governed by their own privacy policies.

11) Changes to this Policy

We may update this Policy from time to time. The “Last updated” date will be revised accordingly. If changes are significant, we will provide prominent notice on the Website.