1. Data controller
The controller for personal data handled through this website and communications with 1→10 is Simeon Gatev, developing the 1→10 initiative, Sofia, Bulgaria. Privacy contact: 1to10consult@gmail.com; +359 89 700 9919.
If a client project begins through a separate company, controller and processor roles and instructions for client data will be defined in the agreement and, where required, a data processing agreement.
2. Scope
This Policy applies to site visitors, people who enquire, book a call, communicate with us or represent a prospective or current business client. It does not govern third-party sites and services linked from this website.
3. Data we handle
We receive information you choose to provide and limited technical information needed to deliver the site securely.
- Identity and contact data: name, role, company, work email and phone.
- Business context: industry, revenue, team size, processes, bottlenecks, tools and growth plans.
- Communications: emails, call notes, proposals and follow-up actions.
- Contract and invoicing information during a client engagement.
- Technical data: IP address, approximate city/country, browser, device, timestamps and security logs when handled by hosting/CDN infrastructure.
- Consent preference in browser storage and a session setting for the promotional popup.
4. Sources
We receive information from you, the organisation you represent, public professional sources or suppliers providing hosting and communications.
When you submit the diagnostic form, the information is sent directly to our Notion workspace database, which we use to manage and follow up enquiries.
5. Purposes and legal bases
We process personal data only when an applicable GDPR legal basis is available.
- Pre-contract steps and contract performance: answering an enquiry, preparing a call or proposal and delivering a client engagement.
- Legitimate interests: B2B relationship management, site security, abuse prevention, service improvement and limited professional communication, after balancing our interests against your rights.
- Consent: optional analytics/marketing technology or a newsletter where expressly selected. Consent may be withdrawn at any time.
- Legal obligation: accounting, tax, regulatory or evidentiary requirements.
- Establishment, exercise or defence of legal claims where necessary.
6. Recipients and processors
We do not sell or rent personal data. Access is provided only where needed and appropriate.
- Hosting, CDN and technical infrastructure providers.
- Email, calendar, document and collaboration providers used for communications.
- Approved freelance specialists and subcontractors involved in a project and bound by confidentiality and instructions.
- Accountants, lawyers, insurers and professional advisers.
- Competent authorities where required by law or necessary to protect rights.
7. International transfers
Some technology providers may process data outside the EEA. Where applicable, we use an adequacy decision, the EU–US Data Privacy Framework, Standard Contractual Clauses or another valid safeguard, together with additional measures appropriate to risk.
Information about a relevant supplier and transfer mechanism can be provided on a justified request where this does not prejudice security or another person's rights.
8. Retention
We keep information only for as long as the purpose and applicable legal requirements justify it.
- Enquiries that do not become projects: normally up to 24 months after the last meaningful contact.
- Client communications and project records: for the relationship and up to 5 years afterwards unless a contract or claim requires longer.
- Accounting and tax documents: for the statutory period, which can reach 10 years for some records.
- Consent preference: up to 6 months before a fresh choice is requested.
- Security and hosting logs: for the period needed for security and under the infrastructure provider's applicable policy.
9. Your rights
Subject to the GDPR, you may request access, a copy, correction, erasure, restriction, portability and object to legitimate-interest processing or direct marketing. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing.
Email 1to10consult@gmail.com. We may request reasonable information to verify identity. We normally respond within one month unless the GDPR permits an extension.
10. Supervisory authority
You may complain to the Bulgarian Commission for Personal Data Protection or to the authority where you normally live, work or believe an infringement occurred. We encourage you to contact us first so we can try to resolve the concern promptly.
11. Security, AI and automated decisions
We apply reasonable organisational and technical safeguards, including access controls, appropriate permissions and risk-based supplier selection. No internet system can guarantee absolute security.
The website does not make solely automated decisions with legal or similarly significant effects. If AI helps draft or summarise business communications, we retain human oversight and avoid providing more personal data than necessary.
12. Children, changes and contact
Our services are B2B and not directed to anyone under 18. We do not knowingly collect children's data through this site.
We may update this Policy when processes, suppliers or law changes. Material revisions will carry a new update date. Questions and requests: 1to10consult@gmail.com.
1→10 · Simeon Gatev
Sofia, Bulgaria
1to10consult@gmail.com+359 89 700 9919Bulgarian data protection authority