Legal

Privacy Policy

Effective date: 7 August 2026

This Privacy Policy explains how Space2F (“Space2F”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal data when you visit our public website and submit information through our online contact forms.

This notice applies only to this website and related online inquiry channels. It does not replace any separate engagement letter, service agreement, data processing agreement, or confidentiality terms that may apply if you become a client.

By using this website, you acknowledge that you have read this Privacy Policy. If you do not agree with this Policy, please do not use the website or submit personal data through our forms.

1. Introduction

Space2F operates a professional marketing and information website describing accounting, interim CFO, payroll and HR administration, and public procurement / EU funding services.

We are committed to handling personal data lawfully, fairly, and transparently. This Policy is designed to help you understand what data we process in connection with the website, why we process it, and what choices and rights you have.

For the purposes of applicable data protection law in the European Economic Area (including the EU General Data Protection Regulation, “GDPR”), Space2F is the controller of personal data processed as described in this Policy, unless stated otherwise.

2. Scope and role

This Policy covers personal data processed through: (a) browsing pages on this website; (b) submitting any of our online contact or inquiry forms; and (c) related technical operations required to deliver, secure, and maintain the website.

If you engage Space2F for professional services, additional personal data may be processed under separate contractual terms and, where applicable, under a different controller or processor arrangement. Those arrangements control to the extent of any conflict with this website notice.

This website is intended for business and professional users. It is not directed at children.

3. Information we collect

We collect personal data that you choose to provide and limited technical data generated when you use the website.

3.1 Information you submit through contact forms

Depending on the form you use, we may collect some or all of the following: name; position/title; company name; email address; message content; and service-related details you elect to provide (for example annual turnover indicators, VAT registration status, employee counts, bank-account counts, payroll frequency, countries of operation, currency, or requested service options).

Please do not submit special categories of personal data (such as health data), payment card numbers, government ID numbers, or confidential third-party data through these forms unless we expressly ask for a specific field and you are authorized to provide it.

3.2 Technical and usage data

When you visit the website, our hosting environment and security infrastructure may automatically process technical data such as IP address, browser type and version, device/os indicators, referring URL, requested pages, timestamps, and diagnostic or security logs. This data is used to operate, protect, and troubleshoot the website.

3.3 Cookies and similar technologies

We use essential cookies and similar technologies needed for core website functionality (for example session continuity and security). See Section 6 for more detail.

4. How we use information

We use personal data for the following purposes:

  • To receive, review, and respond to your inquiries and service requests.
  • To communicate with you about your submission, including follow-up questions and scheduling.
  • To operate, maintain, secure, and improve the website and related infrastructure.
  • To detect, prevent, and investigate fraud, abuse, spam, or security incidents.
  • To comply with legal obligations and enforce our rights, including defending legal claims.
  • To keep internal business records of inquiries for operational continuity and accountability.

We do not sell your personal data. We do not use contact-form submissions for unrelated third-party advertising networks.

6. Cookies and similar technologies

Cookies are small text files stored on your device. Similar technologies may include local storage or server-side session identifiers.

This website uses essential cookies and session mechanisms required for core functionality and security (including framework session cookies used by the website application). These technologies are necessary for the website to function as requested.

Our hosting, CDN, and security providers (for example Cloudflare or equivalent infrastructure) may also set or process technical cookies or similar identifiers for network security, performance, and abuse prevention.

We do not currently operate a marketing analytics cookie suite or advertising pixel program on this website. If that changes, we will update this Policy and, where required by law, obtain appropriate consent or provide required notices.

You can control cookies through your browser settings. Blocking essential cookies may cause parts of the website (including forms) to stop working correctly.

7. Processors and disclosures

We may share personal data with service providers that process data on our behalf and under instructions, including:

  • Transactional email providers used to deliver inquiry notifications (for example Resend or a successor provider).
  • Website hosting, reverse-proxy, CDN, and security providers (for example infrastructure used to serve and protect the site).
  • Professional advisers (such as legal, accounting, or IT consultants) where disclosure is reasonably necessary.

We may also disclose personal data if required by law, regulation, legal process, or governmental request; to protect the rights, property, or safety of Space2F, our users, or others; or in connection with a corporate transaction (such as a merger, acquisition, or asset transfer), subject to appropriate safeguards.

Service providers are expected to implement appropriate security and confidentiality measures and to process personal data only for the purposes we specify, except where they process data as independent controllers under their own legal obligations (for example certain security or abuse-prevention logs).

8. International transfers

Space2F is based in Bulgaria. Some processors or subprocessors may be located outside the European Economic Area (EEA) or may process data in multiple regions.

Where personal data is transferred outside the EEA to a country that has not been recognized as providing an adequate level of protection, we take steps designed to ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission, or another lawful transfer mechanism available under applicable law.

You may contact us for more information about relevant safeguards applicable to a specific transfer, subject to any necessary redactions for confidentiality or security.

9. Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including responding to inquiries, maintaining business records, resolving disputes, and complying with legal obligations.

Contact-form submissions are typically retained for a period needed to handle the inquiry and related follow-up, and thereafter for a limited archival period consistent with ordinary business practice, unless a longer period is required or permitted by law, or you request earlier deletion where applicable.

Technical logs are retained according to operational, security, and provider configurations, generally for short to medium periods unless needed for investigations or legal compliance.

When retention is no longer necessary, we delete or anonymize personal data, or securely archive it in a manner consistent with applicable requirements.

10. Security

We implement technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures may include access controls, encrypted transport (HTTPS), provider security features, and operational practices appropriate to the nature of the data and the risks involved.

No method of transmission over the Internet or method of electronic storage is completely secure. Accordingly, we cannot guarantee absolute security. You use the website and submit information at your own risk to the maximum extent permitted by law.

If we become aware of a personal data breach affecting your data and notification is required by law, we will take steps to notify competent authorities and/or affected individuals as required.

11. Your rights

Subject to applicable law (including the GDPR where it applies), you may have the right to:

  • Request access to personal data we hold about you.
  • Request rectification of inaccurate or incomplete personal data.
  • Request erasure of personal data in certain circumstances.
  • Request restriction of processing in certain circumstances.
  • Object to processing based on legitimate interests, including profiling where applicable.
  • Receive personal data in a portable format and/or request transmission to another controller where technically feasible and legally required.
  • Withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
  • Lodge a complaint with a competent supervisory authority. In Bulgaria, this is typically the Commission for Personal Data Protection (CPDP). You may also contact the authority in your place of residence or work within the EEA.

To exercise these rights, contact us using the details in Section 16. We may need to verify your identity before fulfilling a request. Some rights are subject to legal limitations and exceptions.

We will respond within the timeframes required by applicable law. If we cannot fulfill a request, we will explain the reasons where we are permitted to do so.

12. Children

This website is not directed to individuals under 16 years of age, and we do not knowingly collect personal data from children under 16 through this website.

If you believe a child has provided personal data to us through the website, please contact us and we will take appropriate steps to delete such information where required.

14. Disclaimer and Limitation of liability

This website and all content are provided on an “as is” and “as available” basis for general informational and marketing purposes. Nothing on this website constitutes legal, tax, accounting, investment, or other professional advice tailored to your circumstances, and no client relationship is created solely by browsing the website or submitting an inquiry form.

To the maximum extent permitted by applicable law, Space2F disclaims all warranties, whether express or implied, including warranties of accuracy, completeness, merchantability, fitness for a particular purpose, and non-infringement regarding the website and its content.

To the maximum extent permitted by applicable law, Space2F shall not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of profits, revenue, data, goodwill, or business opportunities, arising out of or related to your use of the website or reliance on any content, even if advised of the possibility of such damages.

To the maximum extent permitted by applicable law, Space2F’s aggregate liability arising out of or relating to this website or this Privacy Policy shall not exceed the greater of (a) EUR 100 or (b) the amount (if any) you paid to Space2F specifically for using this website in the twelve (12) months preceding the claim. Because this website is generally provided free of charge, liability may be limited to the minimum amount permitted by law.

Nothing in this Policy excludes or limits liability that cannot be excluded or limited under applicable law, including liability for death or personal injury caused by negligence where such limitation is prohibited, or for fraud or fraudulent misrepresentation.

Some jurisdictions do not allow certain limitations. In such jurisdictions, our liability is limited to the fullest extent permitted by law.

15. Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons.

The “Effective date” at the top of this page indicates when this version took effect. Material changes will be indicated by updating that date and posting the revised Policy on this page.

Your continued use of the website after an updated Policy is posted constitutes your acknowledgment of the updated Policy, to the extent permitted by law. If you do not agree with an updated Policy, discontinue use of the website and contact us regarding any outstanding data requests.

16. Contact

For questions about this Privacy Policy, or to exercise privacy rights, contact Space2F at:

  • Space2F
  • 31 Petar Protich str. ap.19, Sofia, Bulgaria
  • Email: milena@space2f.com
  • Phone: +359 8888 31935

Please include enough detail for us to understand and verify your request. We may request additional information to confirm your identity and to locate relevant records.

If you are unsatisfied with our response, you may lodge a complaint with the Commission for Personal Data Protection (Bulgaria) or another competent supervisory authority.