Privacy Policy

Last updated: August 2026


1. Data Controller

This privacy policy applies to data processing carried out by:

Ямевео ЕООД (Yameveo EOOD)
UIC: 207973600
Registered address: Burgas, Bulgaria
Incorporated: 2024
Contact: hello@yameveo.ai

Yameveo EOOD is a single-member limited liability company (ЕООД) incorporated under Bulgarian law. It operates under the unified brand “Yameveo” at yameveo.ai.


2. Governing Law

Data processing by Yameveo EOOD is governed by:


3. What Data Is Processed and Why

Browsing this website does not require you to provide any personal information, and we do not maintain user accounts for visitors. We do, however, process personal data in four circumstances, each described below.

3.1 Server access logs

Our web server (nginx) automatically records a standard access log entry for every HTTP request. Each entry contains the requesting IP address, the requested URL, the HTTP status code, and the timestamp. These logs exist for one purpose: detecting and responding to security threats, abuse, and service errors.

Logs are deleted automatically by log rotation. No log data is exported, analysed for traffic patterns, or retained beyond what rotation leaves in place.

Legal basis: Legitimate interests (Article 6(1)(f) GDPR / ЗЗЛД). We have a legitimate interest in maintaining the security and operational integrity of the service.

3.2 AI advisor chat

This site offers an optional AI chat assistant. It is an artificial intelligence system, not a person, and the widget says so before you type. It is there to answer questions about our services; nothing obliges you to use it.

If you open the chat and send a message, the following is processed:

Please do not enter sensitive personal information, credentials, or confidential third-party details into the chat. It is a sales-enquiry tool and is not designed to receive such data.

The assistant can be wrong. Nothing it says is contractually binding, and it does not constitute legal, security, or financial advice.

Legal basis: Legitimate interests (Article 6(1)(f) GDPR / ЗЗЛД) — responding to enquiries about our services, and protecting the service from abuse. You may object to this processing at any time under Article 21 GDPR by not using the chat, or by writing to us.

3.3 Website analytics

We operate our own first-party analytics. It sets no cookies and never stores your IP address in our database.

To record which country a visit came from, we consult a database of published IP address ranges held on our own server. Your IP address is not sent anywhere for this purpose, and no third-party geolocation service is involved. The database contains only network ranges and country names — it holds no information about individuals — and it is refreshed monthly from a public dataset.

For each page view we record the URL and page title, the referring site, any campaign parameters in the link you followed, your device type, browser, operating system, country, and a timestamp. To distinguish one visitor from another without identifying anyone, we derive a hash from your IP address with the final octet removed, your browser’s user-agent string, the current date, and a secret site key. That hash cannot be reversed to recover your IP address, and because the date forms part of it, it changes every midnight — the same visitor returning tomorrow is a new, unlinkable entry.

Legal basis: Legitimate interests (Article 6(1)(f) GDPR / ЗЗЛД). We have a legitimate interest in understanding which content is useful. The measures above are specifically designed so that this does not override your rights.

3.4 Contact form

If you submit the contact form, the details you provide are sent to us by email and are not stored in any database on this website. To limit automated abuse, we hold a short-lived rate-limiting marker derived from your IP address with the final octet removed.

Legal basis: Steps taken at your request prior to entering into a contract (Article 6(1)(b) GDPR / ЗЗЛД), and legitimate interests for the abuse-prevention marker.


4. Cookies and Client-Side Storage

We do not set cookies for visitors. No analytics, advertising, or preference cookies are placed on your device. Our analytics is deliberately cookieless. WordPress sets session cookies for logged-in administrators only — these are never set for ordinary visitors.

There is one exception, and it applies only if you choose to use it. When you open the AI chat, a random session identifier is written to your browser’s sessionStorage so that your messages can be correlated within that single conversation. It is written only when you open the chat, never on page load; it is deleted by your browser when you close the tab; and it is never used for analytics, advertising, or tracking across visits. Because it is strictly necessary to provide a service you have explicitly requested, it is exempt from the consent requirement under Article 5(3) of Directive 2002/58/EC and чл. 4а(4) of the Bulgarian Electronic Commerce Act (ЗЕТ).

If you would rather it were not stored, do not open the chat, or clear your browser storage afterwards.


5. Where Data Is Stored and Transferred

Server logs, analytics records, and the AI chat’s rate-limiting data are stored exclusively on servers operated by Hetzner Online GmbH, located within the European Union (Germany). Hetzner acts as a data processor under a data processing agreement in compliance with GDPR Article 28.

One category of data leaves the EU/EEA. If you use the AI chat, the text of your conversation is transmitted to Anthropic PBC, 548 Market Street, San Francisco, California, United States, which operates the language model. Anthropic acts as a data processor under its Data Processing Addendum, and the transfer relies on the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 (Article 46(2)(c) GDPR).

Under our commercial agreement with Anthropic, conversation content is not used to train their models. Anthropic deletes inputs and outputs within 30 days of receipt, save where longer retention is required to investigate a breach of their usage policy.

One further transfer occurs outside the EU/EEA. Because our mail is relayed through Google (smtp.gmail.com), the contents of a contact-form submission pass through Google’s infrastructure on their way to our mailbox, and remain there as ordinary correspondence.


6. Retention

Data type Retention
Nginx server access logs (IP addresses) Deleted automatically by log rotation
AI chat rate-limiting records (IP address, session ID) Deleted automatically after 30 days
AI chat conversation content Not stored by us. Deleted by Anthropic within 30 days
AI chat session identifier in your browser Deleted by your browser when you close the tab
Analytics page-view records (no IP, daily-rotating hash) Currently retained indefinitely; a retention limit is being introduced
Contact form submissions Not stored on this website; held in our email as ordinary correspondence

7. Your Rights Under GDPR and the Bulgarian PDPA (ЗЗЛД)

As a data subject, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data (Articles 15–21 GDPR / ЗЗЛД). You also have the right to data portability where technically feasible (Article 20 GDPR).

To exercise any of these rights, write to hello@yameveo.ai. We will respond within 30 days as required by GDPR Article 12(3).

A practical note on what we can actually find. Server logs and analytics records are not linked to your identity — analytics deliberately so — which means we generally cannot isolate “your” records from anyone else’s, and Article 11 GDPR applies. For the AI chat we can locate and delete records if you supply the session identifier, which you can read from your browser’s sessionStorage under the key ym_session_id while the tab is still open. Failing that, all such records are deleted within 30 days in any event. To request deletion of conversation content held by Anthropic, contact us and we will pass the request on.


8. Supervisory Authority

The competent supervisory authority for data processing by Yameveo EOOD is:

Комисия за защита на личните данни (КЗЛД)
Commission for Personal Data Protection (CPDP)

2 Prof. Tsvetan Lazarov Blvd. — 1592 Sofia, Bulgaria
www.cpdp.bg

You have the right to lodge a complaint with the КЗЛД if you believe your data has been processed unlawfully. We would welcome the opportunity to resolve your concern directly first — contact us at hello@yameveo.ai.


9. Changes to This Policy

We will update this policy if our data processing practices change. The “last updated” date at the top reflects the most recent revision.


10. Contact

For all privacy-related enquiries and data subject requests:
Ямевео ЕООД (Yameveo EOOD) · Burgas, Bulgaria
hello@yameveo.ai