General Data Protection Regulation (GDPR) Compliance Declaration
Official institutional declaration of compliance under European data protection legislation (ELI: eli:reg/2016/679/oj) and the statutory mandates of the Bulgarian Personal Data Protection Act (LPPD).
1. Data Protection by Design & Default (Article 25)
The Mobikom Bulgaria consortium implements Data Protection by Design and by Default (Article 25 GDPR) as an unyielding architectural standard:
- Complete Absence of Tracking Cookies: The underlying static infrastructure physically lacks mechanisms to write state, cookies, or persistent storage keys (
localStorage) to client devices. - Zero Consent Overlay Mandate: Because behavioral tracking and marketing surveillance are mathematically absent, processing operates entirely outside the statutory scope of Article 6(1)(a) consent mandates, eliminating intrusive cookie banner dialogs.
2. Adherence to Core Processing Principles (Article 5)
All network endpoints strictly fulfill the core data protection principles set forth under Article 5 of the Regulation:
- Lawfulness & Transparency: Absence of covert background scripts, unauthorized cross-origin requests, and programmatic ad-tech brokers.
- Data Minimisation: Inbound connection metadata (IP addresses) is buffered exclusively in transient, volatile RAM at the Cloudflare Edge perimeter solely for DDoS threat mitigation.
- Storage Limitation: No persistent connection logs or profile databases are retained on non-volatile media. Closing the active user agent tab purges all transient state.
- Integrity & Confidentiality: Mandatory TLS 1.3 encryption across all connections, fortified by HSTS Preload headers and strict Content Security Policy directives.
3. Processing Classification of Diagnostic Tools (tools/)
All diagnostic utilities, spreadsheets, and document modules in the tools/ suite operate under a decentralized client-side execution model:
The normalization of source markup, manuscripts, images, and documents executes 100% locally within the client user agent's volatile memory (RAM). Mobikom Bulgaria does not function as a "Data Processor" under Article 28 of the GDPR, as no processed content or file payloads are ever transmitted over the network to our hosting infrastructure.
4. Data Subject Rights (Articles 15 – 22)
Every citizen of the European Union possesses statutory rights regarding the processing of their personal data:
- Right of Access & Rectification: Upon written request to our verified mailboxes (
desk@mobikom.bg), you hold the right to confirm any processing related to business correspondence. - Right to Erasure ("Right to be Forgotten"): You hold the right to demand the erasure of correspondence records at any time, except where statutory commercial retention requirements apply.
- Right to Object: You may object to any further communications at any point.