Privacy Policy

    Last updated: August 2026

    1. Introduction

    This Privacy Policy describes how SNAPPY EOOD (trading as Digitap Pro) ("we", "our" or "us"), a Bulgarian single-member limited liability company (ЕООД) (Registration number: 207575190), collects, uses and protects your personal information when you use our review management platform and services.

    Registered office: 18 Aleko Konstantinov St., Smolyan 4700, Bulgaria, European Union

    We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR), UK GDPR and other applicable data protection laws.

    2. Information We Collect

    2.1 Information You Provide

    • Profile information (name, email, company details)
    • Contact information (phone numbers, physical addresses)
    • Customer data (names, email addresses, phone numbers and, where you collect them, dates of birth, used for review requests and marketing campaigns)
    • Team member details (names and email addresses of the people you invite to your account)
    • Messages you send to Digi AI, our in-app AI assistant
    • Payment information (processed securely through third-party providers)
    • Communications with us (support tickets, emails)

    2.2 Automatically Collected Information

    • Device information (IP address, browser type, operating system)
    • Usage data (pages visited, features used, time spent)
    • Cookies and tracking technologies
    • Analytics data (Google Analytics, Facebook Pixel)

    3. Legal Basis for Processing (GDPR Article 6)

    We process your personal data on the basis of the following legal grounds:

    • Consent (Article 6(1)(a)): You have given clear consent to process your personal data for SMS/email review requests and marketing communications
    • Contract (Article 6(1)(b)): Processing is necessary to fulfill our contractual obligations to provide you with our services
    • Legal Obligation (Article 6(1)(c)): We must comply with tax law, anti-money laundering regulations and other legal requirements
    • Legitimate Interests (Article 6(1)(f)): We have legitimate business interests such as fraud prevention, security and analytics, which do not override your fundamental rights
    • Vital Interests (Article 6(1)(d)): In rare cases, to protect someone's life or physical safety

    You have the right to withdraw your consent at any time, without affecting the lawfulness of processing before withdrawal. To withdraw consent, contact us at support@digitap.pro

    4. How We Use Your Information

    • Provide and maintain our services
    • Send SMS and email review requests and marketing campaigns on your behalf
    • Process payments and manage subscriptions
    • Communicate with you regarding updates, promotions and support
    • Improve our platform and develop new features
    • Ensure security and prevent fraud
    • Comply with legal obligations
    • Analyze usage patterns and optimize performance

    5. Third-Party Services and Data Transfers

    We share your personal data with the following third-party service providers:

    5.1 SMS Delivery

    • Provider: Mobica EOOD (Bulgaria, EU) for Bulgarian numbers; Twilio Inc. for international numbers
    • Location: Bulgaria (European Union) for Mobica; United States of America for Twilio
    • Purpose: SMS delivery, phone number management and delivery status tracking
    • Data Shared: Phone numbers, message content, delivery status, timestamps
    • Privacy Policy: https://www.twilio.com/legal/privacy
    • Safeguards: Standard Contractual Clauses (SCCs) for GDPR compliance

    5.2 Email Delivery

    • Provider: Resend (Plus Five Five Inc.)
    • Location: United States of America
    • Purpose: Delivery of transactional and marketing emails
    • Data Shared: Email addresses, email content, open/click rates, engagement metrics
    • Privacy Policy: https://www.twilio.com/legal/privacy
    • Safeguards: Standard Contractual Clauses (SCCs)

    5.3 Payment Processing

    • Provider: Stripe Inc.
    • Location: United States of America (with EU data storage options)
    • Purpose: Subscription billing, payment processing, fraud prevention
    • Data Shared: Name, email, billing address, payment card data (tokenized)
    • Privacy Policy: https://stripe.com/privacy
    • Safeguards: PCI DSS Level 1 certified, Standard Contractual Clauses

    5.4 AI Services

    • Provider: OpenAI
    • Location: United States of America
    • Purpose: AI-powered review responses, sentiment analysis, text summarization, and the Digi AI in-app assistant
    • Data Shared: Review text content, business information, customer feedback data, and the account performance statistics and messages involved in a Digi AI conversation
    • Privacy Policy: https://openai.com/policies/privacy-policy
    • Safeguards: Standard Contractual Clauses (SCCs), data processing agreement
    • Opt-out: You can opt out of AI processing by contacting support@digitap.pro

    5.5 Analytics

    • Google Analytics: Website analytics with IP anonymization enabled
    • Facebook Pixel: Marketing analytics with EU data processing addendum

    All third-party service providers are contractually obligated to protect your data and use it only for specified purposes. We conduct due diligence to ensure they maintain adequate security measures.

    6. Data Retention

    We retain your personal data for as long as necessary to provide our services and comply with legal obligations. Retention periods:

    • Profile Data: Until account deletion + 30 days for recovery
    • Customer Contact Data: 12 months after last interaction or until consent withdrawal
    • Transaction Records: 10 years (Bulgarian Accountancy Act Art. 12; Tax and Social Insurance Procedure Code Art. 38)
    • Analytics Data: 26 months (Google Analytics standard setting)
    • Marketing Consent Records: 3 years after withdrawal (proof of GDPR compliance)
    • Support Tickets: 2 years after resolution

    Upon requesting account deletion, your data is retained securely for a 30-day grace period to prevent accidental loss or malicious deletion, after which it is permanently destroyed.

    When retention periods expire, we securely delete or anonymize your data so it can no longer be linked to you.

    7. Your Rights Under GDPR (EU/EEA)

    If you are located in the European Union or European Economic Area, you have the following rights under GDPR:

    • Right of Access (Article 15): Request a copy of your personal data we hold
    • Right to Rectification (Article 16): Correct inaccurate or incomplete data
    • Right to Erasure (Article 17): Request deletion of your data ("right to be forgotten")
    • Right to Restriction (Article 18): Restrict how we process your data
    • Right to Data Portability (Article 20): Receive your data in machine-readable format (CSV, JSON)
    • Right to Object (Article 21): Object to processing based on legitimate interests or direct marketing
    • Right to Withdraw Consent: Withdraw consent at any time, without affecting previous processing
    • Right to Lodge a Complaint: File a complaint with your national data protection authority

    8. How to Exercise Your Rights (DSAR)

    To exercise any of these rights, contact us at:

    Response Time: We will respond to your request within 30 days. In complex cases, we may extend this period by an additional 60 days and will notify you of the delay.

    9. International Data Transfers

    Your data may be transferred and processed in countries outside the European Economic Area (EEA) and United Kingdom. We ensure adequate protection through:

    • Standard Contractual Clauses (SCCs): EU-approved contract terms with third-party providers
    • Adequacy Decisions: Transfers to countries recognized by the European Commission as providing adequate protection
    • Data Privacy Framework: Transfers to certified US companies (e.g., Stripe)

    10. Security Measures

    We implement industry-standard security measures:

    • Encryption: Data encrypted in transit (TLS/SSL) and at rest (AES-256)
    • Access Controls: Role-based access, multi-factor authentication
    • Regular Audits: Security assessments and penetration testing
    • Data Minimization: Collecting only necessary data
    • Staff Training: Regular privacy and security training

    11. Cookies and Tracking

    We use cookies and similar technologies to improve your experience. For detailed information, please see our Cookie Policy.

    12. Children's Privacy

    Our services are not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

    13. Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through a prominent notice on our platform. The "Last Updated" date at the top indicates the most recent revision.

    14. Contact Us

    For questions or concerns about this Privacy Policy or our data practices:

    • Email: support@digitap.pro
    • Address: 18 Aleko Konstantinov St., Smolyan 4700, Bulgaria, European Union

    Supervisory Authority (Bulgaria): Commission for Personal Data Protection (CPDP)
    Website: https://www.cpdp.bg

    UK Supervisory Authority: Information Commissioner's Office (ICO)
    Website: https://ico.org.uk