Legal
Privacy notice
This notice explains what personal data we process when you use mithrilguard.com, why we process it, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Bulgarian Personal Data Protection Act.
Last updated . See also Terms of use.
What this notice covers
This notice covers mithrilguard.com, enquiries, bookings, SRID Quick Scan and demos, and the Builder and Editor provided for our work and authorised paid client use. Product descriptions and risk scores are not necessarily personal data; this notice applies where information identifies or relates to a person. Where we process personal data on a client's behalf within an assessment, the client determines the purposes and our processing is governed by the applicable service agreement and data-processing terms. This notice does not replace those terms.
This site does not run advertising, marketing pixels or our own analytics. We do not sell personal data.
What we process and why
We process only what is needed to run the site and respond to you:
- Website hosting and security: our host may record technical server logs such as IP address, date and time, requested URL, browser type and similar connection data. Purpose: operate, secure and debug the website. Legal basis: legitimate interests (GDPR Art. 6(1)(f)).
- Contact form and email: the form prepares a message in your own email application; it does not submit the fields to our server. If you send it, we receive your email address, message, any name or company you include, and correspondence metadata. We use these to answer you and discuss or deliver services. Article 6(1)(b) applies to steps you request towards your own contract and its performance. For general enquiries and contacts representing a business client, we rely on Article 6(1)(f): our legitimate interest in responding to requests and managing business relationships.
- Direct email: if you write to contact@mithrilguard.com, we process the content and metadata of that correspondence for the same purposes and legal bases.
- Calendly booking: opening “Book a Call” connects your browser to Calendly, which receives connection data and the booking details you provide, such as name, email, meeting time and notes. We use the booking to arrange and follow up on your requested conversation, on the same contractual or legitimate-interest grounds described above. See Calendly’s privacy notice.
- SRID Quick Scan: inputs and calculations remain in your browser. CSV, JSON and print/PDF exports are generated on your device. “Email me a copy” prepares a message to your chosen address; it does not copy us. “Share my results” prepares a message to us. We receive the results only if you send that message, and then treat it as an enquiry or client correspondence. The public demos use example assessments.
- SRID Builder and Editor: when you generate a report, or import an assessment into the Editor, the assessment data is sent to our hosting service for validation and calculation and the report is returned to your browser. The application does not save assessments or generated reports in a server-side database or file archive. Downloads are generated on your device. This processing delivers the requested service; Article 6(1)(b) applies to your own contract and Article 6(1)(f) to administering access and services for business-client representatives. Client-controlled personal data within assessments is processed on the client's instructions under the applicable data-processing terms.
- Client administration: we use the necessary contact, contractual and billing information to administer an engagement. The contractual and business-contact grounds above apply; mandatory accounting and tax processing is based on Article 6(1)(c).
Your choices and information
You can browse and use Quick Scan without giving us your name or email. Contacting us and booking a call are voluntary. The contact form requires an email address; other fields are optional. Without usable contact details we may be unable to reply or arrange a meeting. Assessment fields needed to calculate a report must be completed to use that function. Please avoid including personal data about other people, sensitive personal data, passwords or access credentials in enquiries or assessments unless separately agreed and necessary for the service.
We do not use website data to make solely automated decisions about people that produce legal or similarly significant effects. SRID scores assess product components and test coverage; they are not scores about individuals.
Who receives the data
We do not share personal data with third parties for their own marketing. Recipients are limited to:
- Vercel Inc., which hosts this website. See Vercel’s privacy policy.
- Calendly LLC, which provides the booking widget when you open it. See Calendly’s privacy notice.
- Business email and connected calendar providers, which transmit and store correspondence, invitations and meeting details for communication and scheduling.
- Professional advisers or public authorities where the law requires or allows disclosure.
Transfers outside the EEA
Vercel Inc. and Calendly LLC are US providers, and their services can involve processing outside the European Economic Area. Their published data-processing terms describe the transfer mechanisms, including the EU–US Data Privacy Framework where applicable and Standard Contractual Clauses with the relevant safeguards. See Vercel’s data-processing terms and Calendly’s data-processing terms. Email and calendar processing locations depend on the provider. Contact contact@mithrilguard.com for information about the providers and safeguards relevant to your data, or to request a copy of applicable safeguards.
How long we keep data
- Enquiries that do not lead to paid work, including emailed Quick Scan results: retained for follow-up for up to 12 months after the last substantive correspondence. We review these monthly and remove expired records during the next review, within one additional month, or earlier when no longer needed.
- Initial-call booking records, including cancelled meetings and no-shows: removed in our monthly review after three months from the meeting or cancellation, within one additional month. This includes copies we control in Calendly, our calendar and email. Necessary correspondence that continues beyond scheduling follows the enquiry or client-record period instead.
- Paid-client correspondence and working materials: kept while needed to deliver the agreed work and support, then reviewed for deletion or return under the engagement's scope and data-processing terms. We retain only records still needed for contractual obligations, applicable legal retention duties or establishing, exercising or defending claims. Mandatory accounting records follow the relevant Bulgarian statutory periods for each document category.
- Quick Scan: the application holds inputs in browser memory and does not persist them in browser storage. Builder and Editor: assessment data is processed to return the requested report, without an application database or server-side report archive. Files you export remain under your control. Information you email us follows the correspondence periods above.
- Technical and security logs: retained according to the hosting service's applicable log-retention settings and the time needed to diagnose faults, investigate security incidents and protect the service. These are separate from assessment storage. We do not deliberately log assessment contents. Relevant incident evidence may be retained while an investigation or related claim remains active.
Your rights
You may request access to your personal data, correction, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing. Write to contact@mithrilguard.com. We may need to verify your identity before we act.
Rights depend on the processing and legal basis: for example, portability applies to eligible automated processing based on consent or contract. We normally respond without charge within one month of receiving your request. If a request is complex or there are multiple requests, we may extend this by up to two further months and will explain why within the first month. Some records must be retained to meet legal obligations or establish, exercise or defend claims. For data we process on a client's behalf, we assist that client in handling requests.
How to complain
You can complain to the Commission for Personal Data Protection, 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria, kzld@cpdp.bg. If you are in another EU or EEA country, you may also contact your local supervisory authority. We would appreciate the chance to resolve the matter first at contact@mithrilguard.com.
Children
This website is aimed at professional users. We do not knowingly collect personal data from children. If you believe a child has sent us personal data, contact us and we will delete it where required.
Changes to this notice
We will update this page if our processing changes, for example if we add analytics, accounts or another third-party service. The “Last updated” date at the top shows the current version.
Who is responsible
The data controller for website operation, enquiries and client administration is QAmbarev TY Ltd, a Bulgarian single-member limited liability company, trading as Mithril Guard.
- Registered office: 7B Bademova Gora Street, block 7B, entrance B, Strelbishte, Triaditsa district, 1404 Sofia, Bulgaria
- Bulgarian Commercial Register — UIC / EIK: 208592118
- VAT: BG208592118
For privacy requests, email contact@mithrilguard.com. Postal correspondence can be sent to QAmbarev TY Ltd at the registered office above.
