Privacy policy
Last updated: April 18, 2026
1. Introduction
This policy describes how Mnemoza (“we”, “us”, “the operator”) processes personal data when you use the web application and related services — registration, research and comparison requests, in-platform communication, attachments, and delivery of reports. It is intended to help you understand our processing in line with Regulation (EU) 2016/679 (GDPR) and applicable Bulgarian law. This policy is not a substitute for individual legal advice.
2. Data controller
The controller of your personal data is the entity operating the Mnemoza service under this name. For exercising rights and enquiries: contact@mnemoza.com.
3. What data we process
Depending on how you use Mnemoza, categories may include:
- Account and identification: username, password (hashed), technical identifiers, role (client/administrator), and any other fields we explicitly collect at registration or in your profile.
- Request content and communications: text, messages, metadata, attachments, needs descriptions, and correspondence needed to prepare a report or clarify a task.
- Technical and log data: IP address, timestamps, browser/OS type, error identifiers, and security events — limited to what is proportionate for the purposes in Section 4.
- Privacy preferences: a record in browser local storage reflecting your choice in the consent banner (e.g. “Accept” / “Necessary only”) so we can respect future non-essential technologies if introduced.
4. Purposes and legal bases
We process data to:
- Provide the service and perform a contract (Art. 6(1)(b) GDPR) — requests, reports, account, in-platform communication.
- Legitimate interests (Art. 6(1)(f) GDPR) — security, abuse prevention, reliability improvements, and dispute evidence, balanced against your rights.
- Legal obligations (Art. 6(1)(c) GDPR) — where the law requires processing.
- Consent (Art. 6(1)(a) GDPR) — only for non-essential cookies or marketing if we introduce them and request separate consent.
5. Retention and deletion
We keep data for as long as needed for the purposes above: while your account is active and for a reasonable grace/archival period afterwards; for requests and reports, according to the agreed scope or statutory accounting/tax retention where applicable. On a deletion request, unless the law requires retention, we will erase or anonymise data within a reasonable time.
6. Recipients and processors
We do not sell personal data. Access may be provided to hosting/cloud providers, email providers, or IT support who process data on our instructions under appropriate agreements. For transfers outside the EEA we rely on GDPR safeguards (e.g. standard contractual clauses), unless an adequacy decision applies.
7. Cookies, local storage, and the consent banner
We use browser localStorage for an authentication token — this is strictly necessary for signed-in functionality. We may also store your banner choice (e.g. “Accept” or “Necessary only”) so we do not ask repeatedly and can respect future non-essential technologies. You can clear site data in your browser or use “Consent settings” on the site to show the banner again.
8. Your rights
You may have rights of access, rectification, erasure, restriction, portability, and objection where applicable. You may lodge a complaint with a supervisory authority (in Bulgaria: KZLD). Requests: contact@mnemoza.com. Withdrawing consent for consent-based processing does not affect lawfulness before withdrawal.
9. Security
We apply appropriate technical and organisational measures proportionate to risk. No online service is risk-free; we do not guarantee perfect security. You are responsible for protecting your password and device.
10. Automated decision-making and profiling
We do not make solely automated decisions with legal or similarly significant effects under Article 22 GDPR. Reports involve human work within the service; recommendations are informational.
11. Children
The service is not directed to children under 16. If you are under 16, do not use the service without parental consent where required by law.
12. External links
The site may link to third parties. We do not control their policies and are not responsible for their content or data practices. Review their terms before providing data.
13. Informational nature of this policy
This policy is provided for transparency in connection with Mnemoza. It is not legal or tax advice. To the extent permitted by law, we are not liable for reliance on this text outside the scope of personal data processing in the service.
14. Changes
We may update this policy. Material changes will be reflected with a new date and, where required, additional notice. Continued use after publication may constitute acceptance of updates, without prejudice to your mandatory rights.
15. Contact
Questions about personal data processing: contact@mnemoza.com.