Privacy Policy
Last updated: 16 August 2026
This Privacy Policy explains how Reset Recovery collects and uses personal data through this website and when arranging or providing physiotherapy, rehabilitation, sports recovery, massage and related services.
1. Who is responsible for your data
The data controller is [LEGAL COMPANY NAME], EIK/company registration number [EIK / COMPANY REGISTRATION NUMBER], VAT number [VAT NUMBER, IF APPLICABLE], registered address [REGISTERED ADDRESS], trading as Reset Recovery.
Clinic address: 24 Lerin St., Belite Brezi, 1000 Sofia, Bulgaria. General contact: contact@resetrecovery.bg; telephone: [PHONE NUMBER]. Privacy enquiries and requests: [PRIVACY CONTACT EMAIL].
2. What this policy covers
This policy applies to visitors, people who contact us, people who request or attend an appointment, parents or guardians acting for a minor, and other persons whose data is provided to us for these purposes. It does not replace the information and consent process used before any assessment or treatment.
3. Personal data we may collect
- Contact and identity data: name, telephone number, email address and, where necessary, age or information about a parent or guardian.
- Appointment data: requested service, preferred date and time, confirmation status, reminders, cancellations, rescheduling and attendance history.
- Messages: the subject and content of enquiries and our correspondence with you.
- Service and health data: information discussed or recorded during an appropriate consultation, assessment or treatment. Health data is a special category of personal data and receives additional protection.
- Payment and transaction data: amount, payment status, refund status and transaction reference. We do not intend to receive or store full payment-card details; these are handled by [ONLINE PAYMENT PROVIDER — TO BE CONFIRMED] if online payment is introduced.
- Technical and security data: IP address, device/browser information, timestamps, security events, consent choices and limited server logs. The contact form uses Cloudflare Turnstile to prevent abuse.
- Marketing preferences: whether you have separately opted in to receive marketing messages and any later withdrawal.
No customer account is required for the standard appointment-request process. The standard form is intentionally designed not to request a diagnosis, medical history or symptom description. Please do not include health information in a general message unless it is necessary. If you voluntarily include it, we will limit its use to responding to the enquiry, arranging appropriate care and protecting health and safety.
4. Why we use personal data and our legal bases
- To answer enquiries, take steps requested before a contract, review appointment requests, confirm appointments and provide the requested service: Article 6(1)(b) GDPR.
- To meet accounting, tax, healthcare, record-keeping and other legal duties: Article 6(1)(c) GDPR.
- To operate, secure and improve the website, prevent fraud or abuse, manage complaints and establish, exercise or defend legal claims: our legitimate interests under Article 6(1)(f) GDPR, balanced against your rights.
- To send optional marketing communications: your consent under Article 6(1)(a) GDPR. You may withdraw it at any time without affecting earlier lawful processing.
- Where health data is necessary for assessment or care, the applicable Article 9 GDPR condition may include Article 9(2)(h), subject to applicable law and professional confidentiality. Where appropriate, we may instead request explicit consent under Article 9(2)(a). We do not use health data for advertising.
An online appointment request is reviewed manually. Submitting it does not guarantee a time slot, treatment or clinical suitability.
5. Recipients and service providers
Access is limited to the therapist and authorised persons who need the information. We may also use carefully selected providers for website hosting and administration, email and communications, appointment management, security and anti-spam, professional advice, accounting and, if introduced, online payments. The website currently embeds Google Maps only after the relevant consent choice is made. We may disclose data to public authorities where required by law or necessary to protect legal rights or safety.
We do not sell personal data. We do not use health data for marketing, profiling or automated clinical decisions. Mailchimp is not currently connected, and no newsletter data is transferred to it unless and until the service is deliberately enabled and a person has opted in.
6. International transfers
Some technology providers, including Google or Cloudflare, may process data outside Bulgaria or the European Economic Area. Where this occurs, we rely on an applicable adequacy decision or appropriate safeguards such as the European Commission’s standard contractual clauses, together with supplementary measures where required. Provider privacy information is linked in our Cookie Policy.
7. How long we keep data
- General enquiries that do not lead to an appointment: normally up to 12 months after the enquiry is closed.
- Appointment administration, attendance, service and health records: for the period required by applicable healthcare and record-keeping rules and, where relevant, for the period needed to establish, exercise or defend legal claims.
- Invoices, payments and refunds: for the statutory accounting and tax retention period.
- Marketing preferences: until consent is withdrawn or the information is no longer needed; evidence of consent or withdrawal may be kept as needed to demonstrate compliance.
- Security and technical logs: for the shortest period reasonably needed for security, troubleshooting and abuse prevention, subject to the hosting and security providers’ retention settings.
We may keep data longer where a law, dispute, investigation or safeguarding need requires it. We securely delete or anonymise data when it is no longer needed.
8. Your rights
Subject to the conditions in the GDPR, you may request access, correction, deletion, restriction, portability or objection to processing, and you may withdraw consent at any time. Where processing is based on legitimate interests, you may object for reasons relating to your particular situation. We do not make solely automated decisions that produce legal or similarly significant effects.
Send a request to [PRIVACY CONTACT EMAIL]. We may need to verify your identity. You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria, or through the current complaint channels published at cpdp.bg.
9. Children and minors
Website appointment requests for a minor should be made by, or with the involvement of, a parent or legal guardian. Consent and attendance requirements are applied according to the minor’s age, the service and applicable Bulgarian law. We do not knowingly use children’s data for marketing.
10. Security
We apply proportionate technical and organisational measures, including access controls, data minimisation, secure hosting and anti-spam protection. No internet transmission or storage system is completely secure; please avoid sending unnecessary health or payment information through general website messages.
11. Cookies and third-party content
Our Cookie Policy explains the technologies used on the site and how to manage consent. Optional third-party content, including Google Maps, should not load until the relevant consent is given. You can change your choice later through the site’s consent settings.
12. Changes and contact
We may update this policy when our services, providers or legal obligations change. The latest version and update date will remain on this page. Questions may be sent to [PRIVACY CONTACT EMAIL].
