Privacy Policy

of Exceed BG OOD
UIC: 207496889
Registered address: Sofia 1756, Studentski District, Perperikon Str. 2, Floor 2, Apt. 8
VAT Registration: BG207496889


1. Introduction

This Privacy Policy (“Policy”) governs the relationship between you, the Users of the website and services provided by Exceed BG OOD (“Exceed”, “Administrator”, “We/Us”), and our company as a Data Controller.

Exceed BG OOD, registered in the Commercial Register under UIC 207496889, is licensed to provide employment mediation services. We process personal data in compliance with Bulgarian legislation, the Personal Data Protection Act, and the General Data Protection Regulation (EU) 2016/679 (“GDPR”).

The purpose of this Policy is to inform you about:

  • what personal data we collect;

  • how and why we process it;

  • how long we store it;

  • what rights you have regarding your personal data.

Any changes to this Policy will be reflected on our website, and where applicable, we will notify users. If you do not agree with any part of this Policy, please discontinue the use of our services.


2. Definitions

For the purposes of this Policy:

  • “Data Controller” – Exceed BG OOD

  • “Personal Data” – any information relating to an identified or identifiable natural person

  • “Processing” – any operation performed on personal data

  • “Recipient” – any entity to which personal data is disclosed

  • “Personal Data Breach” – a breach leading to accidental or unlawful destruction, loss, alteration, disclosure, or unauthorized access to personal data


3. Data Controller

Exceed BG OOD acts as an independent Data Controller when processing personal data.

Employers who receive candidate data from us act as separate, independent Data Controllers.

We process personal data of the following categories of individuals:

  • job applicants;

  • users who submit CVs through our website;

  • applicants from third-party job platforms (jobs.bg, zaplata.bg, rabota.bg, etc.);

  • clients (employers);

  • website visitors;

  • office visitors (where video surveillance is applicable).


4. What personal data do we collect?

Depending on the services used, Exceed may collect and process:

Identification and contact data

  • Full name

  • Email address

  • Telephone number

  • Address (when relevant)

Professional information

  • Education and qualifications

  • Language skills

  • Employment history

  • Work permits or eligibility documentation

  • Information provided in CVs, cover letters, assessments

Other data

  • Communication history

  • Data submitted via contact forms

  • System logs, IP address, profile actions (if account-based services exist)

  • Video recordings (if visiting an office under CCTV monitoring)

We do not collect sensitive personal data unless voluntarily provided and only when necessary.


5. Purposes of Processing

Exceed processes personal data exclusively for purposes related to recruitment and employment mediation, including:

  • matching candidates with employers;

  • conducting preliminary selection;

  • forwarding candidate CVs to employers;

  • managing contracts between Exceed and candidates;

  • fulfilling legal obligations under employment mediation regulations;

  • maintaining communication between parties;

  • improving and evaluating our recruitment services;

  • providing additional career services (training, consulting);

  • accounting and administrative purposes.


6. Legal Bases for Processing

We process personal data on the following legal grounds under GDPR:

  • Contractual necessity (Art. 6(1)(b))

  • Legal obligation (Art. 6(1)(c))

  • Legitimate interest (Art. 6(1)(f))

  • Consent (Art. 6(1)(a)), for example:

    • international data transfers (outside the EU)

    • marketing communications


7. Use of AI-based tools (if applicable)

If Exceed does NOT use AI interviews, tell me and I will remove this section entirely.

Exceed may use AI-based voice or interview tools for early-stage structured assessments. Participation is voluntary, and collected data is used solely for recruitment purposes.

All AI processing complies with GDPR, and only after obtaining clear user consent.


8. Automated Decision-Making

Exceed does not use automated decision-making that produces legal or similarly significant effects on individuals.


9. Methods of Data Collection

We collect personal data through:

  • our website’s application forms

  • third-party job platforms

  • social media channels

  • email and phone communication

  • participation in events

  • direct contact with candidates and clients

  • ongoing business relationships


10. Data Storage and Security

Personal data is stored only for the necessary period, in accordance with:

  • 5 years – applicant data (as required by employment mediation regulations)

  • up to 3 years – for internal recruitment by Exceed

  • 10 years – accounting and financial documents

  • 30 days – CCTV recordings (if applicable)

We apply technical and organizational measures to protect data, including:

  • access control

  • encryption and pseudonymization

  • staff training and confidentiality obligations

  • secure data storage and backup procedures

  • physical and IT security controls


11. Data Deletion

Data is deleted once the retention period expires, unless retention is required by law, court order, or legitimate business need (e.g., legal claims).


12. Your Rights

Under GDPR, you have the right to:

  • access your personal data;

  • request correction;

  • request deletion (“right to be forgotten”);

  • restrict processing;

  • object to processing;

  • data portability;

  • withdraw consent at any time;

  • lodge a complaint with a supervisory authority.

To exercise these rights, contact us at:

📧 info@exceedbg.com
(If you prefer a different email, let me know.)

We will respond within the statutory deadlines.


13. Data Sharing

We may share personal data with:

13.1. Employers

For recruitment and placement purposes.

13.2. Service providers

(e.g., IT support, accountants, legal consultants)
Only under contractual safeguards ensuring GDPR compliance.

13.3. Public authorities

When required by law (e.g., NRA, police, regulators).

13.4. International transfers

If data is transferred outside the EU, Standard Contractual Clauses (SCCs) or other GDPR-approved safeguards are used.

13.5. Legal protection

We may share data to prevent fraud, comply with legal obligations, or protect the rights and safety of Exceed or third parties.


14. Changes to This Policy

Updates to the Policy will be published on our website. Continued use of our services after updates constitutes acceptance of the revised Policy.


15. Supervisory Authority

Commission for Personal Data Protection (CPDP)
2 Prof. Tsvetan Lazarov Blvd., Sofia 1592
Website: https://www.cpdp.bg
Email: kzld@cpdp.bg