Privacy
Last updated: 16/7/2026 · Version: 1.0
1. Who We Are
This Privacy Policy explains how КОРКЛАУД ИНЖЕНЕРИНГ ЕООД (in English: CORECLOUD ENGENEERING LLC), a limited liability company registered in the Commercial Register of the Republic of Bulgaria under UIC (ЕИК) 206933948, with registered address at: Bulgaria, Plovdiv (4003), Severen district, 36 Brezovska Str., fl. 4 ("we", "us", the "Operator") collects and processes personal data when you use zipo.bg (the "Platform").
We are the data controller for the processing described in this Policy.
Contact for privacy matters: info@zipo.bg
2. What the Platform Is — and What That Means for Your Data
The Platform is an advertising and listing directory that connects clients looking for services with providers who advertise them. We do not facilitate, record, monitor, or have knowledge of any agreement, booking, or payment between users. All negotiations, agreements, scheduling, and payments happen entirely offline, outside our systems.
This has a direct privacy consequence: we deliberately collect the minimum data needed to publish advertisements and enable first contact — and nothing about what happens afterwards. We never ask whether a job took place, we never track outcomes, and our systems are built so that such information cannot be stored.
3. Personal Data We Collect
3.1 Account data (clients and providers)
- Phone number (verified by SMS one-time code) — the primary login credential; providers must register by phone.
- Email address (optional for phone-registered users; verified before use) — used for login, chat notifications, account recovery, and security notices.
- Display name (clients: optional, shown to providers in chat; providers: required, shown publicly).
- Preferred language (Bulgarian, English, or Russian) and notification preferences.
- Account status and technical timestamps (registration date, verification date).
3.2 Provider profile data (published by you as advertising)
Providers choose to publish: profile photo or company logo, bio, base town, service categories, coverage localities, reference hourly rate and/or a price list, a portfolio gallery, and optionally a public phone number and public email. Companies may additionally self-declare a registered legal name, UIC/Bulstat (ЕИК/Булстат) and business address. All of this is advertising content you publish voluntarily and control; it is visible to the public, including logged-out visitors and search engines.
3.3 Provider identity verification data (sensitive — short retention)
To obtain the verified badge, a provider (for companies: the account's representative) uploads a photo of a government ID and a selfie. These are reviewed by our staff solely to confirm that the account is operated by a real, identified person. They are stored in a restricted storage area and permanently deleted within 30 days of the verification decision. We retain only the decision itself and a one-way hashed identifier derived from the document, used exclusively to detect the reuse of the same identity across accounts (fraud and ban-evasion prevention). We do not verify qualifications, licenses, insurance, or quality of work, and we perform no biometric profiling.
3.4 Service request data (clients)
- The description of your problem, in your own words. If you typed or spoke it in another language, we store both the final Bulgarian description you approved and your original input text with its language tag — used only for internal quality assurance and audit, never shown to providers and never used for third-party AI model training.
- Voice recordings, if you use voice input: the audio is transcribed and then permanently deleted within 24 hours (immediately if you abandon the draft). We perform no voice or speaker analysis of any kind.
- Up to 3 photos of the problem. Location metadata (EXIF/GPS) is stripped from all uploaded images automatically.
- The locality scope of your request (region, optionally towns and city districts). We never collect or store a street address on a request.
- An optional urgency flag.
Important: if you choose to write your phone number or other contact details inside the request description, that text is published as-is and becomes visible to every matched provider and to anyone you share the request link with. This is your choice; the registered account phone number itself is never shown this way — it is disclosed only through the controlled contact-reveal mechanism described below.
3.5 Contact reveals
When a provider taps "Get Contact" on your request, we record that event (provider, request, timestamp) and disclose your account phone number to that provider. This record is the last event we ever store about a client–provider pairing and serves as our activity ledger and abuse-prevention chokepoint.
3.6 Chat messages
In-app chat messages (text and photos) are stored to deliver the conversation to its two participants. We do not read, analyze, scan, or run any language processing, OCR, or image recognition on chat content — not for analytics, not for advertising, not for any purpose. The single exception is automated hash-matching of uploaded images against databases of known illegal content (e.g., CSAM), which compares digital fingerprints and reads nothing about the image's meaning. A human moderator sees a specific conversation only if a participant reports it. Chat notifications (push and email) contain the sender's name only — never message content.
3.7 Reviews
Reviews are structured only: a recommend / don't recommend choice plus preset attribute chips. They are public, attached to the provider's profile, and linked to your client account internally (one review per provider, editable by you).
3.8 Technical and usage data
- Push notification subscriptions (endpoint, keys, browser/device identifier) — only if you enable notifications.
- Device geolocation — only if you grant browser permission, used momentarily to suggest your town during request creation; the coordinates are not stored on the request.
- IP address and browser data for security, rate limiting, and abuse prevention (e.g., access logs of shared request pages are kept for 30 days for rate-limiting purposes only).
- Product analytics events limited strictly to activity on the Platform up to the moment of contact (e.g., request posted, notification delivered, contact revealed). We collect no data about anything after contact — no conversions, no transactions, no job outcomes, because none exist in our systems. Chat content never enters analytics.
4. Purposes and Legal Bases (GDPR Art. 6)
| Processing | Legal basis |
|---|---|
| Creating and operating your account, publishing requests and profiles, matching, notifications, chat, contact reveals | Contract — Art. 6(1)(b) |
| SMS/email one-time codes, session security, rate limiting, anti-scraping controls, velocity and anomaly detection, ID-reuse fingerprinting, ban enforcement | Legitimate interest — Art. 6(1)(f): keeping the Platform and its users' contact data safe from fraud, scraping, and abuse |
| Provider ID verification | Contract (verification is a condition for revealing contacts) and legitimate interest (fraud prevention) |
| Device geolocation, optional email address, push notifications, chat email notifications | Consent — Art. 6(1)(a); withdrawable at any time |
| Automated content filtering against the Terms of Service, statements of reasons, appeal handling, responding to lawful requests from authorities | Legal obligation — Art. 6(1)(c), incl. Regulation (EU) 2022/2065 (Digital Services Act) |
| Retention of the original request text for audit and internal quality tuning | Legitimate interest — service quality and dispute audit trail |
5. Automated Content Filtering (Automated Decision-Making)
Every published text on the Platform (request descriptions, provider bios, price-list entries, gallery captions) passes an automated filter that matches it against the categories of content prohibited by our Terms of Service. This filter does not "review" or "approve" content — a pass simply means no prohibited-content match was found.
If content is withheld from publication, you receive a statement of reasons identifying the matched Terms clause, informing you that the decision was automated, and giving you an in-product appeal path to human review, as required by Art. 17 of the Digital Services Act. Uncertain cases are always routed to human review, never silently published or silently blocked.
Private 1:1 chat messages are not subject to this filter.
6. Who Receives Your Data
- Other users, as designed: matched providers see your request's anonymized content (description, photos, locality, urgency — never your name or account phone); a provider who reveals your contact receives your account phone number; chat participants see your display name and messages; the public sees provider profiles and structured reviews.
- People you share with: if you create a share link for your request, anyone holding the link can view the request's public content. You are warned before sharing, one link exists at a time, and you can revoke it at any moment.
- Processors under data processing agreements (Art. 28 GDPR):
- SMS delivery provider (one-time codes and fallback notifications);
- transactional email provider (codes, notifications, security notices — templates never contain chat content);
- cloud hosting and object storage providers;
- AI language and speech-transcription providers used solely to structure your request input (your data is not used to train their models).
- Authorities, where we are under a legal obligation to disclose.
We do not sell personal data, do not share it with advertisers, and do not use it for third-party marketing.
Where a processor operates outside the EEA, transfers are safeguarded by European Commission adequacy decisions or Standard Contractual Clauses. Details are available on request via the privacy contact above.
7. How Long We Keep Data
| Data | Retention |
|---|---|
| Voice recordings | Deleted within 24 hours of transcription; immediately on abandonment |
| Provider ID photo and selfie | Deleted within 30 days of the verification decision |
| Request description (including original-language text) and photos | Requests auto-archive on a per-category schedule; text and images are permanently deleted 12 months after creation |
| Chat messages and chat images | 6 months, then permanently deleted |
| Contact-reveal ledger | Retained for the life of the accounts (activity and anti-abuse ledger; contains no transaction data) |
| Share-link access logs (IP/browser) | 30 days |
| Provider gallery images | Until you remove them; deleted within 24 hours after an account ban |
| Account data | Until account deletion (see Section 8) |
Deletion is enforced by automated jobs with storage-lifecycle rules as a backstop.
8. Your Rights
Under the GDPR you have the right to:
- Access your data and receive a copy (Art. 15);
- Rectify inaccurate data (Art. 16) — most profile and request data is directly editable in the app;
- Erasure (Art. 17): you can delete your account from the app (a fresh login code is required, to protect you from deletion via a stolen session). Client data is hard-deleted; provider entries in the reveal ledger are anonymized so the anti-abuse ledger keeps no identity;
- Restriction of processing (Art. 18) and objection to processing based on legitimate interest (Art. 21);
- Data portability (Art. 20);
- Withdraw consent at any time (geolocation via browser settings; email/push notifications via one-click unsubscribe or the notification settings screen) without affecting prior processing;
- Not be subject to solely automated decisions with significant effect without safeguards — see Section 5 for the human-review appeal.
To exercise a right, contact info@zipo.bg. We respond within one month.
You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, www.cpdp.bg, or with your local EU supervisory authority.
9. Security
We protect your data through, among other measures: encrypted transport (TLS) everywhere; short-lived signed URLs for all user-uploaded images, accessible only to authorized viewers; automatic stripping of GPS/EXIF metadata from every uploaded photo; a restricted, access-controlled storage area for verification documents; token-based session security with rotation and revocation; strict rate limiting; and layered anti-scraping controls so that client contact data can only be obtained by identity-verified providers, one request at a time, under daily and weekly caps with anomaly detection.
Notification payloads (push, SMS, email) are designed to carry no request descriptions and no message content, so third-party delivery networks never receive that data.
10. Children
The Platform is intended for persons aged 18 and over. We do not knowingly collect data from minors; if you believe a minor has created an account, contact us and we will delete it.
11. What We Will Never Collect
By architecture, not just by policy, the Platform stores no data about: whether any service was agreed, performed, or paid for; prices agreed between users; bookings, schedules, or appointments; or the content of your private negotiations. If you mention such things in your own free text or chat, they remain your unanalyzed speech — we build no records from them.
12. Changes to This Policy
We may update this Policy as the Platform evolves (for example, if paid provider features are introduced, which would involve billing data processed between providers and us — never payments between users). Material changes will be announced in the app and, where required, notified to you in advance. The current version is always available on this page.
This document is the English version of the Privacy Policy. In case of discrepancy between language versions, the Bulgarian version prevails.