Privacy Policy
Last updated: 29 May 2026 Controller: Pricex Ltd (EIK 206487271, 1 Petyofi Street, Plovdiv 4000, Bulgaria) Contact for data protection: [email protected]
This policy explains how we process personal data when you register and use the partners.fleetq.net affiliate platform ("the Service"). It applies to data subjects in the EU and is written to satisfy Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act (ЗЗЛД).
1. Who is the controller?
Pricex Ltd, EIK 206487271, registered office at 1 Petyofi Street, Plovdiv 4000, Bulgaria, is the data controller for the data described below.
We have not designated a Data Protection Officer — Article 37(1) thresholds (large-scale systematic monitoring; large-scale special categories) are not met. You may contact our privacy desk at [email protected] for any request under Articles 15–22 GDPR.
2. Data we process
| Category | Examples | Legal basis | Source |
|---|---|---|---|
| Partner contact (natural person acting for a legal entity) | name, email, phone, locale, password hash, last login | Art. 6(1)(b) — performance of the partner contract | self-registration |
| Partner legal entity data | company name, EIK/UIC, VAT number, registered address, contact person | Art. 6(1)(b) + Art. 6(1)(c) — legal obligation to keep invoicing records | self-registration |
| Authentication artifacts | OAuth provider tokens, passkey credentials, session cookies | Art. 6(1)(b) | provider callback / WebAuthn ceremony |
| Click telemetry | IP address (truncated by default in production — last IPv4 octet / last 80 bits of IPv6 zeroed before storage, per CJEU C-582/14 Breyer), user-agent, attribution token, landing path | Art. 6(1)(f) — legitimate interest in attributing referrals to the correct partner; data minimised under Art. 5(1)(c) | first-party /api/track/click endpoint |
| Payment ingest payload | external payment reference, amount, currency, customer ref, subscription ref, raw payload from the consuming project | Art. 6(1)(b) on our side; Art. 28 on behalf of the consuming project for any third-party PII inside raw_payload |
server-to-server HMAC API |
| Webhook audit log | tenant id, slug, signature validity, request hash, response status | Art. 6(1)(f) — legitimate interest in security monitoring | VerifyTenantHmac middleware |
| Admin staff account | name, email, password hash, role assignments | Art. 6(1)(b) employment / contractor relationship | invite |
| Error reports | exception type, stack trace, request URL, locale (no request body, no cookies, no user identifier — SENTRY_SEND_DEFAULT_PII=false) |
Art. 6(1)(f) — legitimate interest in service reliability | Sentry self-hosted at sentry.karlovo.net |
We do not knowingly process special categories (Art. 9) or criminal-conviction data (Art. 10).
3. Purposes
- Operate the partner programme — onboarding, dashboard, commission tracking, statement generation, payout processing.
- Attribute conversions — match clicks and promo codes to the correct partner for fair commission accrual.
- Comply with our accounting and tax obligations — preserve invoice-related records as required by Bulgarian law (typically 10 years for VAT-related records).
- Protect the service — detect and block invalid HMAC signatures, abuse, and fraud.
- Communicate with partners — transactional emails (application received, statement paid, account changes). We do not send marketing emails.
4. Recipients and processors
| Processor | Service | Location | Safeguard |
|---|---|---|---|
| Contabo GmbH | VPS hosting | Germany (EU) | Standard processor agreement; EU/EEA processing only. |
| Cloudflare, Inc. | CDN, DDoS, TLS termination | Global (EU edge nodes) | Standard Contractual Clauses (Modules 2 + 3) where applicable; EU traffic routed to EU PoPs. |
| Pricex Ltd (internal) | Self-hosted Sentry on sentry.karlovo.net |
Bulgaria (EU) | Internal — same controller. |
No data is transferred outside the EU/EEA for normal operations. Cloudflare may route a small fraction of edge traffic via non-EU PoPs for failover; in those cases the SCCs apply.
We do not sell, rent, or share your data for any other purpose.
5. Retention
| Data | Retention |
|---|---|
| Active partner accounts | for the duration of the partnership |
| Closed/deleted partner accounts | tombstone (email hash + last 4 of EIK) kept for 30 days to prevent re-registration loop, then purged |
Click telemetry (clicks) |
90 days, then hard-deleted (gdpr:purge-expired daily) |
Webhook audit log (webhook_log) |
180 days, then hard-deleted |
| Statements (frozen) | 10 years (Bulgarian Accounting Act, art. 12) |
| Sentry error events | 30 days (Sentry retention setting) |
6. Your rights
Under Articles 15–22 GDPR you may, at any time, request:
- Access (Art. 15) — a copy of all personal data we hold about you.
- Rectification (Art. 16) — correction of inaccurate or incomplete data. You can edit account-level data yourself at
/portal/settings; for legal-entity changes email us. - Erasure (Art. 17) — we anonymise your personal identifiers (name, email, phone, EIK, address) and the linked partner record so they no longer identify you. Financial records (conversions, statements, invoices) that we are legally required to keep under the Bulgarian Accounting Act remain in the system in pseudonymised form for 10 years. This is the lawful exception in Art. 17(3)(b) — compliance with a legal obligation.
- Restriction (Art. 18) — temporary freeze of processing.
- Portability (Art. 20) — your data in a structured, machine-readable JSON format.
- Objection (Art. 21) — to processing based on legitimate interest (click telemetry, webhook log).
- Withdraw consent — where processing is based on consent (currently: none on this service).
To exercise any right, email [email protected] with proof of identity (we may ask for a unique reference from your account). We respond within 30 calendar days (Art. 12(3)).
You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (КЗЛД) — https://www.cpdp.bg — or with the supervisor in your member state of residence.
7. Cookies
See the Cookie Policy for the full inventory.
Summary: we only use strictly necessary and functional cookies. No analytics cookies, no advertising cookies, no third-party trackers. No consent banner is required under ePrivacy Directive Art. 5(3) for the cookies we do set.
8. Security
- TLS 1.2+ at Cloudflare edge and origin (Cloudflare Origin Certificate, Full Strict).
- Passwords hashed with Laravel's default Argon2/bcrypt at cost 12.
- HMAC-SHA256 signature with replay window (300 s) on the server-to-server payment ingest API.
- Database accessible only on the docker bridge network; never exposed to the public internet.
- Application errors shipped to a self-hosted Sentry instance in Bulgaria with
SEND_DEFAULT_PII=false. - Statement PDFs and uploaded invoices stored on the application server filesystem; nightly off-host backups encrypted at rest.
9. Data breach procedure
If we become aware of a personal-data breach, we will notify the КЗЛД within 72 hours where the breach is likely to result in a risk to your rights and freedoms (Art. 33). Where the risk is high, we will also notify affected users without undue delay (Art. 34).
Internal runbook: see docs/legal/data-breach-procedure.md.
10. Changes to this policy
We may amend this policy as the service evolves. Material changes will be communicated by email to all active partners. The "Last updated" date at the top reflects the most recent revision.
The current version is always available at https://partners.fleetq.net/privacy.