This Privacy Policy describes how SNAPPY EOOD (trading as Digitap Pro) ("we", "our" or "us"), a Bulgarian single-member limited liability company (ЕООД) (Registration number: 207575190), collects, uses and protects your personal information when you use our review management platform and services.
Registered office: 18 Aleko Konstantinov St., Smolyan 4700, Bulgaria, European Union
We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR), UK GDPR and other applicable data protection laws.
2. Information We Collect
2.1 Information You Provide
Profile information (name, email, company details)
Contact information (phone numbers, physical addresses)
Customer data (names, email addresses, phone numbers and, where you collect them, dates of birth, used for review requests and marketing campaigns)
Team member details (names and email addresses of the people you invite to your account)
Messages you send to Digi AI, our in-app AI assistant
Payment information (processed securely through third-party providers)
Communications with us (support tickets, emails)
2.2 Automatically Collected Information
Device information (IP address, browser type, operating system)
Usage data (pages visited, features used, time spent)
Cookies and tracking technologies
Analytics data (Google Analytics, Facebook Pixel)
3. Legal Basis for Processing (GDPR Article 6)
We process your personal data on the basis of the following legal grounds:
Consent (Article 6(1)(a)): You have given clear consent to process your personal data for SMS/email review requests and marketing communications
Contract (Article 6(1)(b)): Processing is necessary to fulfill our contractual obligations to provide you with our services
Legal Obligation (Article 6(1)(c)): We must comply with tax law, anti-money laundering regulations and other legal requirements
Legitimate Interests (Article 6(1)(f)): We have legitimate business interests such as fraud prevention, security and analytics, which do not override your fundamental rights
Vital Interests (Article 6(1)(d)): In rare cases, to protect someone's life or physical safety
You have the right to withdraw your consent at any time, without affecting the lawfulness of processing before withdrawal. To withdraw consent, contact us at support@digitap.pro
4. How We Use Your Information
Provide and maintain our services
Send SMS and email review requests and marketing campaigns on your behalf
Process payments and manage subscriptions
Communicate with you regarding updates, promotions and support
Improve our platform and develop new features
Ensure security and prevent fraud
Comply with legal obligations
Analyze usage patterns and optimize performance
5. Third-Party Services and Data Transfers
We share your personal data with the following third-party service providers:
5.1 SMS Delivery
Provider: Mobica EOOD (Bulgaria, EU) for Bulgarian numbers; Twilio Inc. for international numbers
Location: Bulgaria (European Union) for Mobica; United States of America for Twilio
Purpose: SMS delivery, phone number management and delivery status tracking
Data Shared: Phone numbers, message content, delivery status, timestamps
Safeguards: PCI DSS Level 1 certified, Standard Contractual Clauses
5.4 AI Services
Provider: OpenAI
Location: United States of America
Purpose: AI-powered review responses, sentiment analysis, text summarization, and the Digi AI in-app assistant
Data Shared: Review text content, business information, customer feedback data, and the account performance statistics and messages involved in a Digi AI conversation
Safeguards: Standard Contractual Clauses (SCCs), data processing agreement
Opt-out: You can opt out of AI processing by contacting support@digitap.pro
5.5 Analytics
Google Analytics: Website analytics with IP anonymization enabled
Facebook Pixel: Marketing analytics with EU data processing addendum
All third-party service providers are contractually obligated to protect your data and use it only for specified purposes. We conduct due diligence to ensure they maintain adequate security measures.
6. Data Retention
We retain your personal data for as long as necessary to provide our services and comply with legal obligations. Retention periods:
Profile Data: Until account deletion + 30 days for recovery
Customer Contact Data: 12 months after last interaction or until consent withdrawal
Transaction Records: 10 years (Bulgarian Accountancy Act Art. 12; Tax and Social Insurance Procedure Code Art. 38)
Analytics Data: 26 months (Google Analytics standard setting)
Marketing Consent Records: 3 years after withdrawal (proof of GDPR compliance)
Support Tickets: 2 years after resolution
Upon requesting account deletion, your data is retained securely for a 30-day grace period to prevent accidental loss or malicious deletion, after which it is permanently destroyed.
When retention periods expire, we securely delete or anonymize your data so it can no longer be linked to you.
7. Your Rights Under GDPR (EU/EEA)
If you are located in the European Union or European Economic Area, you have the following rights under GDPR:
Right of Access (Article 15): Request a copy of your personal data we hold
Right to Rectification (Article 16): Correct inaccurate or incomplete data
Right to Erasure (Article 17): Request deletion of your data ("right to be forgotten")
Right to Restriction (Article 18): Restrict how we process your data
Right to Data Portability (Article 20): Receive your data in machine-readable format (CSV, JSON)
Right to Object (Article 21): Object to processing based on legitimate interests or direct marketing
Right to Withdraw Consent: Withdraw consent at any time, without affecting previous processing
Right to Lodge a Complaint: File a complaint with your national data protection authority
Subject: "Data Subject Access Request" or "GDPR Request"
Response Time: We will respond to your request within 30 days. In complex cases, we may extend this period by an additional 60 days and will notify you of the delay.
9. International Data Transfers
Your data may be transferred and processed in countries outside the European Economic Area (EEA) and United Kingdom. We ensure adequate protection through:
Standard Contractual Clauses (SCCs): EU-approved contract terms with third-party providers
Adequacy Decisions: Transfers to countries recognized by the European Commission as providing adequate protection
Data Privacy Framework: Transfers to certified US companies (e.g., Stripe)
10. Security Measures
We implement industry-standard security measures:
Encryption: Data encrypted in transit (TLS/SSL) and at rest (AES-256)
Regular Audits: Security assessments and penetration testing
Data Minimization: Collecting only necessary data
Staff Training: Regular privacy and security training
11. Cookies and Tracking
We use cookies and similar technologies to improve your experience. For detailed information, please see our Cookie Policy.
12. Children's Privacy
Our services are not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through a prominent notice on our platform. The "Last Updated" date at the top indicates the most recent revision.
14. Contact Us
For questions or concerns about this Privacy Policy or our data practices: