Privacy Policy
Last updated: March 2026
This Privacy Policy explains how NESTRA processes personal data in connection with the use of this website.
We process personal data in accordance with applicable data protection legislation, including Regulation (EU) 2016/679 (GDPR) and the laws of the Republic of Bulgaria.
1. Controller of personal data
The controller of personal data within the meaning of the GDPR is:
NESTRA (НЕСТРА)
Legal form: EOOD
Registered office and management address: Bulgaria, 8000 Burgas, Aleksandar Stamboliyski 46, 1st Floor
UIC: 208786151
Email: [email protected]
2. Categories of personal data
Depending on how you use the Website, we may process the following categories of personal data:
- Identification data (e.g., name)
- Contact data (e.g., email address, phone number)
- Information related to a property, provided voluntarily through the inquiry forms
- Data related to referrals
- Technical data (e.g., IP address, browser type, device information, time of access)
We do not knowingly process special categories of personal data within the meaning of Art. 9 GDPR.
3. Purposes and legal basis for processing
a) Handling inquiries and contact
For responding to inquiries submitted through contact forms, referral forms, email, or other communication channels.
Legal basis: Art. 6(1)(b) GDPR (steps prior to entering into a contract) and Art. 6(1)(f) GDPR (legitimate interest).
b) Processing of referrals
For evaluating and managing referrals that may lead to a real estate transaction.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
c) Website analytics (Google Analytics)
For analyzing the use of the Website and improving its functionality and content.
Legal basis: Art. 6(1)(a) GDPR (consent). Analytical cookies are used only after consent has been given.
d) Website operation and security
To ensure the technical functioning, security, and stability of the Website.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
e) Compliance with legal obligations
When processing is necessary for compliance with legal obligations (e.g., accounting, tax, regulatory).
Legal basis: Art. 6(1)(c) GDPR (legal obligation).
4. Google Analytics
The Website uses Google Analytics 4 (GA4) — a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics configuration:
- IP address anonymization is enabled
- No advertising or marketing features are enabled
- No profiling or cross-site tracking is carried out
Data may be transferred to Google servers outside the EU only where applicable data protection safeguards are in place.
5. Recipients of personal data
Personal data may be provided only where necessary to:
- Independent real estate agents working with NESTRA
- Technical service providers (hosting, IT, email services)
- Public authorities, where required by law
All recipients are bound by confidentiality obligations.
6. Transfer of data outside the EU
As a rule, personal data is processed within the European Union. Any transfer of data outside the EU/EEA is carried out only in compliance with GDPR requirements and with appropriate safeguards in place.
7. Retention period
Personal data is stored only for the period necessary to achieve the purposes for which it was collected, or as required by law.
Indicative timelines:
- Data from inquiries and contacts: up to 24 months
- Data related to contracts: in accordance with statutory retention periods
After the expiration of the retention period, data is deleted or anonymized.
8. Rights of data subjects
You have the following rights under the GDPR:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
- Right to object
Where processing is based on consent, you can withdraw it at any time with future effect.
You also have the right to lodge a complaint with the supervisory authority: the Commission for Personal Data Protection (CPDP).
10. Data security
We apply appropriate technical and organizational measures to protect personal data. However, complete security in transmitting data over the internet cannot be guaranteed.
11. Provision of personal data
Providing personal data is voluntary. Not providing certain data may prevent us from responding to inquiries.
12. Amendments to the Policy
We reserve the right to update this Policy at any time. The version published at the time of use of the Website shall apply.
13. Contact
For questions regarding this Policy, please contact us at: [email protected]