Privacy Policy
Effective from: 10 August 2026 Last updated: 10 August 2026
This policy explains how NAVTECH GROUP EOOD processes your personal data when you visit dynamicsconnect.net, register or buy a ticket for the Dynamics Connect conferences, apply for a partnership, or contact us.
It is written in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and the Bulgarian Personal Data Protection Act.
1. Who processes your data
The data controller is:
- NAVTECH GROUP EOOD
- Company number (EIK): 200344206
- VAT number: BG200344206
- Registered office: GAMA Residence, ground floor, office 3, Vitosha district, 1700 Sofia, Bulgaria
- Phone: +359 2 439 6680
- Email: info@dynamicsconnect.net
For any question about data protection, write to info@dynamicsconnect.net with the subject "Personal data".
We are not required to appoint a Data Protection Officer under Article 37 GDPR. Requests are handled directly at the address above.
2. What data we collect, why, and on what legal basis
We collect only the data we need for a specific purpose. We do not buy or otherwise obtain contact lists from third parties.
2.1. Event registration
Data: first name, last name, email address, company, job title, chosen language, date and time of registration.
Purpose: to add you to the attendee list, issue your personal electronic ticket with a QR code, and admit you at the venue.
Legal basis: Article 6(1)(b) GDPR — performance of a contract, or steps taken at your request before entering into one.
2.2. Ticket purchase
Buyer data: first name, last name, email address, phone number (optional).
Attendee data: first name, last name, email address, company and job title for every ticket in the order.
Invoicing data (bank transfer orders only): company name, company number (EIK/BULSTAT), VAT number, registered address, accountable officer.
Order data: order number, number of tickets, unit price, discount and promo code used, total amount, VAT, payment method and status, Stripe payment references.
Purpose: to conclude and perform the ticket sale contract, issue proof of payment, and keep accounting records.
Legal basis: Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(c) GDPR (compliance with a legal obligation under the Bulgarian Accountancy Act and the VAT Act).
2.3. Card payments
Card payments are processed by Stripe Payments Europe, Ltd. Your card details are entered directly into Stripe's secure environment; they never pass through our servers and are not stored by us. We receive only a confirmation that the payment succeeded or failed, and a transaction reference.
2.4. Electronic ticket and check-in
Data: unique ticket identifier (token), date and time of check-in, the staff member who performed it.
Purpose: access control, preventing a single ticket from being used more than once, attendance statistics.
Legal basis: Article 6(1)(b) GDPR — performance of the attendance contract.
The ticket verification page at `/verify/<code>` is reachable without signing in, because it is opened by scanning the QR code on the ticket itself. It is excluded from search engine indexing. Treat your ticket the way you would treat an airline boarding pass.
2.5. Session ratings and feedback
Data: a rating from 1 to 5, a comment (optional), an email address (optional).
Purpose: improving the programme and the quality of future editions.
Legal basis: Article 6(1)(a) GDPR — your consent, given by submitting the form.
2.6. Partnership enquiries
Data: company name, website, industry, size, country, contact person's name, email, phone and role, desired partnership tier, goals and message.
Purpose: assessing the enquiry and conducting negotiations.
Legal basis: Article 6(1)(b) GDPR — steps taken before entering into a contract.
2.7. Marketing communications
Data: email address, name.
Purpose: news about future Dynamics Connect editions, open registrations and programme announcements.
Legal basis: Article 6(1)(a) GDPR — your explicit consent, given through a separate checkbox at registration. That checkbox is optional and leaving it unticked does not affect your participation.
You may withdraw your consent at any time by writing to info@dynamicsconnect.net. Withdrawal does not affect the lawfulness of processing carried out before it.
2.8. Event photography and video
We take photographs and video at our conferences and publish them in the site gallery, on our social channels, and in promotional material for future editions.
Legal basis: Article 6(1)(f) GDPR — our legitimate interest in documenting and presenting the event. Filming is general in nature and is not intended to identify individuals.
Your choice: if you prefer not to be filmed, tell the team at the registration desk. If an already published photograph shows you recognisably and you want it removed, write to info@dynamicsconnect.net and we will take it down promptly.
2.9. Technical security data
Data: IP address, request time, requested address, browser type, web server log entries.
Purpose: protection against abuse, rate limiting, detecting automated attacks, and troubleshooting.
Legal basis: Article 6(1)(f) GDPR — our legitimate interest in keeping the service secure and available.
2.10. Cookies and web analytics
The site uses strictly necessary cookies, and Google Analytics loads only after your explicit consent. The details are set out in our Cookie Policy.
Legal basis: Article 6(1)(a) GDPR for analytics; Article 6(1)(f) GDPR for strictly necessary cookies.
3. How long we keep data
- Registrations and tickets: up to 3 years after the relevant edition, so we can answer enquiries and complaints and keep a record of attendance.
- Orders, invoices and accounting records: 10 years from 1 January of the year following the year of issue, as required by Article 12 of the Bulgarian Accountancy Act. This period is set by law and cannot be shortened at your request.
- Check-in data: together with the registration it belongs to.
- Ratings and comments: up to 3 years; on request we remove the email address and keep the rating anonymous.
- Partnership enquiries: 2 years from the last correspondence, if no contract follows.
- Marketing consent and newsletter address: until consent is withdrawn.
- Server logs: up to 90 days.
- Photographs and video: no fixed period, for as long as they remain an archive of the event; we remove specific material on a justified request.
Once the relevant period expires, data is deleted or irreversibly anonymised.
4. Who we share data with
We do not sell or rent personal data. We share it only with providers who process it on our instructions under a contract meeting Article 28 GDPR:
- Our hosting provider — operation of the website's server and database, within the European Union.
- Stripe Payments Europe, Ltd. — card payment processing.
- Google Ireland Ltd. / Google LLC — delivery of transactional email through Gmail, and web analytics through Google Analytics (the latter only where consent has been given).
- Our accountants — for invoice handling and statutory accounting, under strict confidentiality.
- Partners and speakers — aggregated, anonymous statistics only (attendee counts, industries, ratings). We do not give attendee names or contact details to sponsors or partners unless you have explicitly consented.
- Competent authorities — where we are required to do so by law.
5. Transfers outside the European Economic Area
Our core infrastructure — server and database — is located in the European Union.
Google and Stripe also operate in the United States. Where a transfer outside the EEA takes place, it is made on the basis of:
- the European Commission's adequacy decision under the EU–US Data Privacy Framework, and/or
- the standard contractual clauses adopted by the European Commission, together with supplementary technical measures.
You may request a copy of the applicable safeguards at info@dynamicsconnect.net.
6. Your rights
Under the GDPR you have the following rights:
- Access — to confirmation of whether we process your data, and a copy of it.
- Rectification — to have inaccurate or incomplete data corrected.
- Erasure ("the right to be forgotten") — to have data deleted where it is no longer needed for the purpose, where you withdraw consent, or where you object on valid grounds.
- Restriction of processing — to have processing paused while we verify an objection or the accuracy of the data.
- Portability — to receive the data you provided to us in a structured, machine-readable format, or to have it transferred directly to another controller.
- Objection — to object to processing based on legitimate interest, including to the publication of your image.
- Withdrawal of consent — at any time, without affecting the lawfulness of processing carried out beforehand.
- Not to be subject to automated decision-making — we do not take decisions producing legal effects concerning you by automated means alone, and we do not carry out profiling.
How to exercise your rights: send a request to info@dynamicsconnect.net. We reply within one month of receipt. For complex or numerous requests, that period may be extended by a further two months, and we will tell you if it is. Exercising your rights is free of charge; for manifestly unfounded or excessive requests we may charge a reasonable fee or refuse to act.
To protect your data, we may ask for additional information to confirm your identity.
7. Right to lodge a complaint
If you believe we are processing your data unlawfully, you may lodge a complaint with:
- Commission for Personal Data Protection (Bulgaria)
- 2 Prof. Tsvetan Lazarov Blvd, 1592 Sofia, Bulgaria
- Phone: +359 2 915 3518
- Email: kzld@cpdp.bg
- www.cpdp.bg
You also have the right to complain to the supervisory authority in the country where you reside.
8. Data security
We apply technical and organisational measures appropriate to the risk, including:
- encryption of the connection with a valid TLS certificate (HTTPS) across the whole site;
- restricted access to the administration panel through individual accounts and roles, with the "Check-in" role seeing only the data needed at the door;
- hashed passwords for staff accounts;
- rate limiting and protection against automated form submissions;
- strict content security policies and browser protection headers;
- daily database backups kept separately;
- data minimisation — we collect only what is necessary and grant access only to staff who need it.
No system is completely secure. If a security breach is likely to result in a high risk to your rights, we will notify you without undue delay and the supervisory authority within 72 hours.
9. Children's data
Our services are aimed at professionals and are not directed at anyone under 16. We do not knowingly collect children's data. If we learn that we have received such data without the consent of a holder of parental responsibility, we delete it.
10. Changes to this policy
We may update this policy when our services, our providers or the law change. The current version is always available at this address, and the date of the last update is shown at the top. We will notify you by email or through a notice on the site if the changes are material.