Skip to content

Privacy Policy

Updated 24 September 2026. This notice explains how Fylvo Digital handles personal data. Reading it is not consent to advertising or a contract.

Who is responsible?

The controller is Mariyan Asenov, trading as Fylvo Digital, Laurentiusstraße 20, 68167 Mannheim, Germany. Contact: contact@fylvodigital.com or +49 1522 2350601.

Visiting the website

Our WordPress website is hosted with Hostinger. Requests involve technical data such as IP address, request time, requested page, browser information and response status. Hosting, security and caching support reliable delivery and investigation of errors or abuse. The legal basis is our legitimate interest in running a secure website, Article 6(1)(f) GDPR. Elementor displays the pages, Polylang supplies language versions and LiteSpeed supports caching. These tools are not used here as advertising trackers.

We do not currently run Google Analytics, advertising pixels, a newsletter service or CookieYes cloud tracking on this website. Images and fonts are served locally. Details of necessary browser storage are in our Cookie Policy.

Enquiries and contractual notices

We use the name, email address, optional company, selected service and message you provide to answer enquiries and prepare or perform a contract. Cancellation or withdrawal notices also contain the contract reference, your declaration and its receipt time. Article 6(1)(b) GDPR applies to steps requested by you and your contract; Article 6(1)(f) covers communication with business representatives and other correspondence. Required legal records and confirmations are handled under Article 6(1)(c). Required fields are marked. Without the necessary contact or contract details, we may be unable to handle your request.

Client portal, where access is provided

The portal is for invited accounts. It handles account and organisation details, project requests, messages, assignments, timestamps and billing status. Files are processed only where the upload function is available and you use it. Authorised staff receive access according to their role and project assignment. This supports contractual work and secure administration under Article 6(1)(b) or, for business contacts and security, Article 6(1)(f) GDPR. The portal does not store full card numbers or independently charge a payment method.

Payments, providers and external links

Where you pay through a Stripe-hosted link, Stripe processes the payment details you enter. We receive the information needed for invoicing, payment status, tax and subscription administration. Our purposes are contractual payment processing and legal bookkeeping obligations under Article 6(1)(b) and (c) GDPR. Stripe also processes some information for its own regulated and security purposes; see Stripe’s privacy information.

Hosting, email delivery and payment providers receive data needed for their respective tasks. Authorities or professional advisers may receive records where legally required or necessary to protect legal claims. Hostinger publishes its privacy information and data processing terms. Providers may process data outside the EEA. Where this requires a transfer safeguard, an adequacy decision or appropriate safeguards such as EU standard contractual clauses must apply; you can request information about the safeguards relevant to your data from us.

Social profiles, review sources and partner sites are ordinary external links. The locally stored Hostinger badge does not itself load Hostinger tracking. Following a partner link sends Hostinger the request and referral code; we may receive a commission if a purchase is attributed to that code.

How long we keep data

We retain enquiry and project records while needed for the request, agreed work and applicable limitation periods. Tax, invoice and business records are retained for their applicable statutory periods. Portal access can be disabled before shared contract records are erased. Security counters are short-lived; account-level portal audit entries are normally removed after 90 days. Backups are removed or overwritten through the applicable backup cycle. We restrict retained records to their remaining purpose and review deletion when it ends.

Your rights

Subject to the GDPR’s conditions, you can request access, correction, erasure, restriction and data portability. You may object to processing based on legitimate interests for reasons relating to your situation. Where processing relies on consent, you may withdraw that consent for the future. Contact us using the details above; we may request proportionate information to verify your identity.

You may complain directly to a competent supervisory authority without first contacting us. For our location, this includes the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg. We update this notice when the actual processing changes.