Effective from 11 September 2026.
English translation of the approved Bulgarian document. The Bulgarian original is available using the BG language switch.
Who this policy applies to
This policy explains the processing of personal data when using checkpointsofia.info, contacting CheckPoint Sofia and accessing its educational content. It distinguishes data from website visits from data needed for medical care. Additional information about a particular test, medical records or the use of an external patient system is provided with the relevant service.
Simply browsing the website does not require registration, a Bulgarian personal identification number (EGN), medical results or information about your sex life. Reading this policy does not constitute consent to marketing or a medical procedure.
Controller and contact
The controller for the activities described that we carry out on our own behalf is „ЧЕКПОЙНТ-АМБУЛАТОРИЯ ЗА ИНДИВИДУАЛНА ПРАКТИКА ЗА ЗДРАВНИ ГРИЖИ-ЕЛЕНА БИРИНДЖИЕВА“ ЕООД, ЕИК 206286329, referred to below as “CheckPoint Sofia” or “we”. Registered office and business address: 111 Tsar Samuil Street, Vazrazhdane District, Sofia 1000, Bulgaria. Manager: Elena Todorova Birindzhieva.
For questions and requests concerning personal data, contact info@checkpointsofia.info or write to the address above, addressed to the manager, with the subject “Personal data”. This email is the company's contact address; its designation does not mean that a data protection officer has been appointed. If identification is needed, we will request only what is necessary to respond securely.
What data we process
When you open a page, your browser sends technical data needed for the connection: IP address, requested address, time, browser and device information, and technical identifiers. Hosting, network protection and servers may process error and security logs. Visits to medical pages may reveal sensitive interests; we do not use them to create health profiles for advertising.
If you write to us or call, we receive the name, reply address, phone number, enquiry content and any attachments you provide. Do not send an EGN, photographs of documents, results or details of your intimate life in an initial general enquiry. When such data are needed for a service, we will explain an appropriate way to provide them.
For editors' and administrators' staff accounts, we process account details, permissions, authentication, materials created and edited, and versions. These are website management accounts, not patient records.
Search and interactive tools
In the current implementation, text entered in search and choices made in the risk, PrEP and testing questionnaires are processed in the memory of the open page. The application does not send them to the server as answers or save them in cookies, localStorage or a patient profile. A full reload resets the tool's state. Going back may restore the previous state depending on the browser.
This does not mean that the internet connection is completely anonymous. Opening a page or a subsequent link creates an ordinary network request. Your browser, device or an external service may keep its own history. On a shared device, close the page and consider history settings and active accounts.
Purposes and legal bases
Providing and protecting the website, diagnosing technical problems and preventing misuse are based on the legitimate interest under Article 6(1)(f) GDPR in a functioning and secure service. We assess necessity and the impact on visitors and limit data to what is needed for the purpose.
For a general enquiry, processing is based on our legitimate interest in responding. Where, at your request, we take specific steps to provide a service or perform a contract, Article 6(1)(b) applies. Where there is a legal obligation, Article 6(1)(c) applies.
Data concerning health, sex life and sexual orientation are special categories. An Article 6 basis alone is insufficient for them. Medical care also requires the relevant Article 9 condition, including paragraph 2(h), where processing is necessary for health care subject to professional secrecy requirements. Other purposes require a separately applicable condition; an ordinary website visit or voluntarily sending an email is not automatically treated as explicit consent to every use.
If we request consent for a particular optional purpose, we explain the purpose and how to withdraw consent. Refusal does not prevent access to the core informational content. Withdrawal does not affect the lawfulness of earlier processing.
Booking and results in an external system
Booking and results links lead to MedSoft. Entering data there is not entering it into a form on this website. Before providing information, check the domain and the privacy notice of the relevant system.
The distinction between controller and processor depends on the specific activity and arrangement. Using an external platform does not relieve CheckPoint Sofia of its responsibilities for medical data for which it determines the purposes and means of processing. Ask us for information about the particular service and data recipients; this policy does not automatically designate MedSoft as an independent controller for all data.
Who may receive data
Access may be available to authorised staff according to their duties, technical support, hosting and protection providers, an email service for correspondence, and competent authorities where there is a legal basis. Activities performed on our behalf are subject to the processor requirements of Article 28 GDPR. We do not publish patient data in the website's administrative editor or sell health data for advertising.
The website uses Cloudflare for network delivery and protection. Activating a video establishes a connection to YouTube/Google; opening a map or social network also brings the relevant external service's rules into play. Embedded video does not load before an explicit action by the visitor.
Processing outside the European Economic Area
International providers may process technical data outside the EEA, including in the United States. Using a Bulgarian domain or a local server does not rule out such processing. A transfer by us requires an applicable mechanism under Chapter V GDPR, such as an adequacy decision or standard contractual clauses, and additional measures where needed. Information about specific recipients, countries and applicable safeguards can be requested using the contact above. External services' policies are available on their websites.
How long data are retained
The period depends on the category and purpose. Technical logs are retained for the period necessary for operation, security and investigation of a specific incident; they should not be kept indefinitely simply because they are available. Correspondence is retained until the enquiry is handled and to the extent that a subsequent need arises from a service, legal obligation or specific claim. Where such a need exists, access and use are limited to the relevant purpose.
Medical records have separate retention periods depending on the type of document and applicable regulatory requirements. For a specific document, you may request the period or the criteria used to determine it; a cookie's lifetime is not the retention period for a medical record. A separate retention period and replacement procedure must be defined for backups; data in them must not be returned to ordinary use following justified erasure. Exact operational periods are determined in the controller's record of processing activities and retention rules.
Your rights
Subject to the applicable conditions, you have the right of access and a copy, rectification of inaccurate data, erasure, restriction of processing, and portability of data you have provided where processing is automated and based on a contract or consent. You may object to processing based on legitimate interests on grounds relating to your particular situation. You may object to direct marketing at any time.
These rights are not absolute: for example, a legal obligation concerning medical records may prevent immediate erasure. If a request is refused or restricted, we explain the basis and complaint options. We do not use decisions based solely on automated processing that produce legal or similarly significant effects; the educational tools do not decide whether you receive a medical service.
How to make a request or complaint
Write to info@checkpointsofia.info or the registered business address. Describe your request and provide a way to contact you; do not send an identity document by default. Where there are reasonable doubts about identity, we may request additional, proportionate information. An authorised representative must establish their authority to act.
We respond without undue delay and normally within one month of receipt. Depending on the complexity or number of requests, this may be extended by a further two months, with the reasons communicated within the first month. Requests are normally free of charge; statutory exceptions for manifestly unfounded or excessive requests are applied with reasons.
You have the right to lodge a complaint with the Commission for Personal Data Protection: 2 Prof. Tsvetan Lazarov Boulevard, Sofia 1592, kzld@cpdp.bg, https://cpdp.bg. Follow the Commission's current instructions for valid submission. You do not need to obtain our permission first. Your right to a judicial remedy is also preserved.
Children and changes to this policy
Educational content can be read without an account. Conditions for medical care for minors are determined by law and the particular service; the website does not replace them with general online consent. If purposes, providers or functions change, we update the policy before the relevant new processing where necessary and indicate the date of the current version.
