Data Controller
The data controller for personal data processed through the bakshish.bg platform is:
Deedy Labs (Дийди Лабс ЕООД)
UIC: 205325050
Data we collect
The platform serves two types of users, and different data is collected for each:
Tip givers (paying customers)
IP address, device type, and transaction data (amount, currency, date). Card details are processed directly by Stripe and never pass through or are stored on our servers. We do not store payment card data (PCI Compliant). Optionally: a rating of the visit and a comment.
Tip recipients
Name, email address, IBAN for payouts, business information, and an identity document for KYC verification (see the "Identity Verification" section).
Technical data (all users)
IP address, browser type, and access logs — collected automatically for the security and operation of the platform.
Messages from the contact form
Name, email address, optionally phone and company, and the text of the message — only to reply to it.
Purposes and legal basis
| Purpose | Legal basis |
|---|---|
| Processing and confirming payments | Contract performance |
| Managing business accounts and employees | Contract performance |
| Facilitating direct payments to recipients via Stripe Connect | Contract performance |
| Identity verification (KYC) | Contract performance / Legal obligation |
| Generating income reports | Contract performance |
| Sending transactional email notifications | Contract performance |
| Compliance with tax and financial requirements | Legal obligation |
| Security and fraud prevention | Legitimate interest |
| Replying to messages from the contact form | Legitimate interest / Steps prior to entering into a contract |
| AI analyses in the owner’s dashboard: comment sentiment, suggested amounts, AI assistant | Legitimate interest |
Identity Verification (KYC)
To prevent fraud and meet Stripe's requirements, tip recipients undergo a Know Your Customer (KYC) procedure.
- Data collected: A photo/copy of an official identity document (national ID card, passport, or driving licence).
- Process: Documents are uploaded to the platform's secure environment. An authorised administrator reviews them for authenticity and profile match. Upon approval, the data is transmitted via encrypted channel to Stripe for final verification and payment account opening.
- Retention: Documents are deleted from our servers within 30 days of Stripe's confirmation, unless a legal obligation requires longer retention.
- Security: Access is limited to a small number of authorised staff. Administrator accounts are protected with two-factor authentication (2FA). We apply encryption at rest and in transit.
Communication and system notifications
We use your email address to send:
- Tip receipt confirmations
- Verification status notifications (approval/rejection)
- Periodic income reports (on request or automatically)
- Important notices about changes to the Terms or account security
These notifications are transactional and a necessary part of the service — they are not unsolicited commercial messages. For delivery, we use an external email service provider to whom we share only the email address and message content.
Data recipients
We do not sell your data. To operate the platform, we share information only with the following trusted partners:
| Partner | Role |
|---|---|
| Stripe Payments Europe, Ltd. | Payment processing, fund transfers, and KYC verification. Stripe is PCI DSS certified and may act as an independent data controller for verification purposes. |
| Google Cloud (Google Ireland Limited) | Hosting infrastructure. Data is stored on servers within the European Economic Area (EEA). |
| Google Gemini API (Google Ireland Limited) | The AI features of the owner’s dashboard: sentiment analysis of guests’ comments, suggested tip amounts from a venue’s recent tips, and the AI assistant’s answers, built from the account’s tip data (amounts, dates, locations, employees’ names and job titles). We share no email addresses, phone numbers or card data. |
| Email service provider | Delivery of transactional notifications. We share only the email address and message content. |
| Public authorities (NRA, CPDP, etc.) | Only when legally required (e.g. tax audit or official order). |
Retention periods
- Transaction data: 5 years under accounting and tax law — even after account closure.
- Identity documents (KYC): deleted within 30 days of Stripe's confirmation.
- Other data: for the duration of the active account or until a deletion request (fulfilled within 30 days), unless a legal obligation requires longer retention.
Your rights under GDPR
As a data subject you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erasure ("right to be forgotten")
- Restriction of processing
- Data portability
- Object to processing
- Lodge a complaint with the Personal Data Protection Commission — www.cpdp.bg, Sofia, Blvd. "Prof. Tsvetan Lazarov" № 2
International transfers
Stripe Payments Europe, Ltd. is based in Ireland (EU). Transfers outside the EEA are possible when Stripe or Google use infrastructure in third countries, including when Google processes requests to the Gemini API — in such cases, Standard Contractual Clauses (SCCs) approved by the European Commission and/or the EU-US Data Privacy Framework apply.
Changes
We may update this policy periodically. For significant changes, we will publish the updated version with a new date.
Contact
For questions about personal data or to exercise your rights, contact us at info@bakshish.bg
