Privacy Policy

odochecker.com

Last updated: March 2026

Article 1 - Identity of the Data Controller

The data controller for personal data collected via the website odochecker.com (hereinafter "the Website") is:

  • Company name: INOVATECH SOLUTIONS LTD, a company incorporated under Bulgarian law, registration number 207787211
  • Registered office: Jawaharlal Neru n.28, Silver Center, fl.2, office 64. 1324 Sofia, Bulgaria
  • Contact: contact form available on the Website

For any questions regarding the processing of personal data or the exercise of the rights described in this policy, the User may contact the data controller via the contact form.

Article 2 - Personal Data Collected

Personal data means any information relating to an identified or identifiable natural person, within the meaning of Article 4 of the General Data Protection Regulation (GDPR - Regulation EU 2016/679).

The Website collects the following personal data, depending on the User's interactions:

2.1 Contact Form

Last name, first name, email address.

2.2 Account Creation and Subscription

Last name, first name, email address, phone number, postal address, billing address.

2.3 Browsing Data

IP address, connection data, behavioural data (pages visited, clicks, visit duration), cookie identifiers.

Article 3 - Purposes and Legal Bases for Processing

Personal data is collected and processed for the following purposes:

  • Managing contact requests: processing User contact requests.

Legal basis: User consent (Article 6.1.a of the GDPR).

  • Account management and provision of Services: creating and managing the User's account, providing Services related to the subscription, ensuring maintenance and support.

Legal basis: performance of the contract between the Customer and INOVATECH SOLUTIONS LTD (Article 6.1.b of the GDPR).

  • Payment management: validating orders, managing direct debits, and processing refunds.

Legal basis: performance of the contract (Article 6.1.b of the GDPR).

  • Statistical analysis: analysing Website traffic and improving the user experience.

Legal basis: User consent for analytical cookies (Article 6.1.a of the GDPR).

  • Targeted advertising: delivering targeted advertisements and measuring their performance.

Legal basis: User consent (Article 6.1.a of the GDPR).

  • Security and fraud prevention: preventing and combating computer fraud.

Legal basis: legitimate interest of the data controller (Article 6.1.f of the GDPR).

The data controller undertakes not to process data for purposes other than those mentioned above. In the event of new processing, the User's consent will be obtained beforehand.

Article 4 - Data of Minors

In accordance with Article 8 of the GDPR, the Website's Services are intended for persons aged 15 or over. Minors under the age of 15 must obtain the consent of their legal representative to use the Website.

Article 5 - Data Retention Period

Personal data is retained for the period strictly necessary for the purposes for which it was collected:

  • User data (contact form): 3 years from the last contact.
  • Customer data (account and subscription): 5 years from the last subscription.
  • Billing data: 10 years in accordance with legal and tax obligations.
  • Connection data and cookies: 13 months maximum.

Upon expiry of these periods, data is deleted or anonymised. The data controller may retain certain data beyond these periods to fulfil its legal or regulatory obligations.

Article 6 - Data Recipients

6.1 Hosting Provider

The Website is hosted by Amazon Web Services, Inc. (AWS) on servers located within the European Union. The hosting provider has limited access to data within the scope of its hosting services.

6.2 Sub-processors

The Website uses the following sub-processors:

Sub-processor Purpose Accessible Data Transfer outside EU
AWS (Amazon) Hosting User data hosted on the Website No (EU servers)
Google Analytics Traffic analysis Browsing data, IP address, approximate location Yes (USA - standard contractual clauses)
Google Ads Customer acquisition Connection data, conversions Yes (USA - standard contractual clauses)
Meta (Facebook Ads) Customer acquisition Behavioural data, user ID Yes (USA - standard contractual clauses)
Snapchat Ads Customer acquisition Behavioural data, user ID Yes (USA - standard contractual clauses)
TikTok Ads Customer acquisition Behavioural data, user ID Yes (USA/Singapore - standard contractual clauses)
Taboola Customer acquisition Behavioural data, IP address Yes (USA - standard contractual clauses)
Outbrain Customer acquisition Behavioural data, IP address Yes (USA - standard contractual clauses)
Cookiebot Consent management IP address, consent preferences No (EU servers)

Each sub-processor is contractually bound to process data in compliance with the GDPR.

6.3 Transfers Outside the European Union

Certain sub-processors are located outside the European Union (notably in the United States). These transfers are governed by standard contractual clauses adopted by the European Commission, ensuring an adequate level of protection for personal data.

6.4 Legal Obligations

Data may be disclosed to competent authorities in response to legal, judicial, or regulatory obligations.

The data controller does not sell, rent, or transfer any personal data to third parties.

Article 7 - Data Security

The data controller implements appropriate technical and organisational measures to ensure the security and confidentiality of personal data, in accordance with Article 32 of the GDPR.

However, no method of transmission over the Internet or method of electronic storage can guarantee absolute security. In the event of a personal data breach likely to result in a high risk to the rights and freedoms of data subjects, the data controller will inform the affected Users and the competent supervisory authority within the timeframes provided by the GDPR.

Article 8 - User Rights

In accordance with the GDPR (Articles 15 to 22), the User has the following rights over their personal data:

  • Right of access: to know what data has been collected and obtain a copy (Article 15).
  • Right to rectification: to correct inaccurate or incomplete data (Article 16).
  • Right to erasure: to request the deletion of data under the conditions set out in Article 17.
  • Right to restriction: to request the restriction of processing (Article 18).
  • Right to data portability: to receive data in a structured format and transmit it to another data controller (Article 20).
  • Right to object: to object to the processing of data, particularly when processing is based on legitimate interest (Article 21).
  • Right to withdraw consent: to withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal (Article 7.3).
  • Right relating to automated decisions: not to be subject to a decision based solely on automated processing producing legal effects (Article 22).

Article 9 - Exercising Rights

The User may exercise their rights by the following means:

  • via the contact form available on the Website;
  • by post to: INOVATECH SOLUTIONS LTD, Jawaharlal Neru n.28, Silver Center, fl.2, office 64. 1324 Sofia, Bulgaria.

The request must include the User's last name, first name, and email address, and be accompanied by proof of identity. Requests are processed within one (1) month of receipt. This period may be extended by two (2) months in the event of complexity or a high number of requests, in accordance with Article 12.3 of the GDPR.

In the event of difficulty in exercising their rights, the User may lodge a complaint with the competent supervisory authority (for France: CNIL - www.cnil.fr; for Bulgaria: CPDP - www.cpdp.bg).

Article 10 - Cookie Policy

10.1 What is a Cookie?

A cookie is a small text file placed on the User's device (computer, tablet, phone) when browsing the Website. It is used to store certain information relating to the User's browsing.

10.2 Categories of Cookies Used

The Website uses the following categories of cookies:

  • Strictly necessary cookies: cookies required for the operation of the Website and consent management (Cookiebot). These cookies do not require the User's consent.
  • Analytical cookies: cookies enabling the analysis of traffic and User behaviour on the Website (Google Analytics). Subject to prior consent.
  • Advertising cookies: cookies enabling the delivery of targeted advertisements and measurement of their performance (Google Ads, Meta, Snapchat, TikTok, Taboola, Outbrain). Subject to prior consent.

10.3 List of Cookies

Cookie Purpose Provider Category Duration
_ga Traffic statistics Google Analytics Analytical 13 months
_gid User behaviour analysis Google Analytics Analytical 24 hours
_gads Advertising performance Google Ads Advertising 13 months
_fbp Interaction tracking Meta Advertising 90 days
fr Conversion tracking Meta Advertising 90 days
sc_at Advertising performance Snapchat Ads Advertising 1 year
ttclid Click and conversion attribution TikTok Ads Advertising 13 months
taboola_usg Advertising targeting Taboola Advertising 1 year
obuid Advertising targeting Outbrain Advertising 90 days

10.4 Consent

In accordance with CNIL guidelines and Directive 2002/58/EC (ePrivacy), the placement of analytical and advertising cookies is subject to the User's prior consent, collected via the cookie management banner (Cookiebot) displayed upon the first visit. This consent is valid for 13 months.

The absence of action by the User (simply continuing to browse) does not constitute valid consent. No non-essential cookies are placed before consent has been obtained.

10.5 Management and Objection

The User may modify their cookie preferences at any time:

  • via the cookie management widget accessible on the Website;
  • via their browser settings (Edge, Safari, Chrome, Firefox, Opera).

Refusing analytical and advertising cookies does not prevent access to the Website but may limit certain features.

Article 11 - Amendments to this Policy

The data controller reserves the right to amend this policy in order to comply with legislative developments or to adapt its practices. Any amendment will be published on the Website. In the event of a substantial amendment affecting User rights, new consent will be obtained.

Article 12 - Applicable Law

This policy is governed by the General Data Protection Regulation (GDPR - Regulation EU 2016/679), Directive 2002/58/EC (ePrivacy) and, subsidiarily, by Bulgarian data protection legislation.

In the event of a dispute, the User may lodge a complaint with the supervisory authority of their habitual residence, place of work, or the place where the alleged infringement occurred, in accordance with Article 77 of the GDPR.

INOVATECH SOLUTIONS LTD - Jawaharlal Neru n.28, Silver Center, fl.2, office 64. 1324 Sofia, Bulgaria - No. 207787211