Privacy
Privacy policy
What we collect, why, how long we keep it and how you have it deleted. No generalities — one line for each thing that is actually stored.
Last revised: 6 August 2026
1. Who processes your data
The data controller is 3D Code EOOD. The statutory details and the correspondence address are on the Company page. For data protection matters, write to the official email published there.
2. Data from the site forms
When you submit the contact, demo, quote or readiness form, we store one row containing:
- Name and email — required, because without them we cannot reply.
- Phone, company and company number — when you fill them in; the fields are not required everywhere.
- The message and the questionnaire answers.
- The page you submitted from, where you arrived from, and any campaign parameters in the address (utm_source and similar).
- IP address and browser details — to defend against automated spam and to limit the number of submissions.
- The exact wording of the consent you accepted, and the moment of acceptance.
3. Why we keep the consent wording
We record verbatim the wording that stood next to the tick box on the day you submitted. Site text changes; proving consent means proving what was accepted then, not what the page says today.
4. The chat assistant on this site
Every page carries a chat assistant in the bottom right corner. If you write to it, we store the conversation — including:
- The full text of your questions and of the answers — so do not type passwords, other people’s personal data, or anything you would not send by email.
- IP address and details of the browser, the device and the operating system.
- The approximate location (city and country), derived from the IP address.
- The language of the conversation and a technical identifier tying the turns into one conversation.
5. How the chat assistant works
The answers come from an Anthropic language model, to which we send only your question, the earlier turns of the same conversation and publicly available information about our services. The assistant has no access to your account, your payments or your enquiries. The basis is our legitimate interest in answering questions quickly and in checking that the assistant answers correctly. Using it is optional — the same questions can be asked by email or by phone.
6. Account data
On registration we store email, name, password (only as an irreversible hash, never in readable form) and the organisations you belong to. We also keep a technical record of sign-ins and of administrator actions — who changed what, and when.
7. Payment data
Card payments are processed by Stripe. Your card number never passes through our systems and is not stored with us. From Stripe we receive a payment confirmation and a transaction identifier, in order to credit your balance.
8. Legal bases
Each of the above rests on one of the following bases:
- Consent — for enquiries from the forms. You may withdraw it at any time, with one message.
- Performance of a contract — for the account, the credits and the delivery of the service.
- Legal obligation — for accounting and tax records.
- Legitimate interest — for spam and abuse defence (IP address, submission counts), for platform security and for the chat assistant conversations.
9. How long we keep it
We do not keep data "just in case". The periods are:
- Form enquiries — up to 24 months from the last communication, then deleted.
- Rows identified as spam — up to 6 months, only so that they are not accepted again.
- Chat assistant conversations — 90 days, then deleted automatically.
- Account data — while the account exists, and up to 6 months after it is closed.
- Accounting records — 10 years, as Bulgarian law requires.
- Technical security logs — up to 12 months.
10. Who we share it with
We do not sell personal data and do not give it to third parties for advertising. We use the following providers, each under contract and only for what is stated:
- A provider of AI infrastructure and hosting — storage and processing of the data in the platform. Data at rest is held in the European Union (Frankfurt).
- Language model providers — OpenAI, Anthropic and Google. Only the text you submit for processing goes to them, and only so that the answer can be produced.
- Stripe — processing of card payments.
- An email service provider — sending confirmations, notifications and replies.
- Where processing takes place outside the European Economic Area — as it may during language model inference — it relies on the European Commission standard contractual clauses.
- If a subprocessor handling personal data changes, we tell you at least 14 days in advance.
11. Your data does not train models
Nothing you submit or create in the platform is used to train or fine-tune artificial intelligence models — neither by us nor by the infrastructure provider, which has given us that undertaking in writing. It is processed only to produce the answer you asked for.
12. Your rights
Under the General Data Protection Regulation (GDPR) you have the right to:
- obtain access to the data we hold about you;
- have inaccurate data corrected;
- request erasure;
- request restriction of processing;
- object to processing based on legitimate interest;
- receive your data in a machine-readable form in order to move it elsewhere;
- withdraw consent at any time, without affecting the lawfulness of processing before that.
13. How to exercise them
Send a request to the official email or the correspondence address on the Company page. We answer within one month. If you believe we process your data unlawfully, you may lodge a complaint with the Commission for Personal Data Protection (CPDP), Sofia, cpdp.bg.
14. Cookies
The site sets no tracking cookies and shows no consent banner, because there is nothing to ask consent for. The full inventory of what your browser stores is on the Cookies page.
15. Automated decisions
The readiness questionnaire score is indicative and does not lead to an automated decision with legal effect for you. No account is approved, refused or restricted automatically on the basis of profiling.
16. Security
We apply technical and organisational measures proportionate to the risk: encrypted connections, access separated by role, a log of administrative actions, and passwords stored only as an irreversible hash. On a personal data breach we notify the supervisory authority and the people affected as the GDPR requires; the infrastructure provider has undertaken to inform us within 72 hours. We hold no certification of our own — the ISO/IEC 27001 and SOC 2 certificates belong to the cloud provider, not to us. The full description of the measures, including what we do not yet have, is on the Data security page. If you use the platform to process personal data of your own customers or staff, the Data processing agreement applies as well.
17. Children
The service is not intended for people under 18 and we do not knowingly collect their data. If we learn that we have received a minor's data, we delete it.
18. Changes to this policy
When processing changes — for example if we ever add analytics — this document is updated before the change, not after it. The date of the last revision is at the top of the page.