FREE DELIVERY on orders of more than 1 item!
Mega Menu
Promotions N New Products
Information

Privacy Policy

PRIVACY POLICY

Protection of personal data when using www.mega-device.com

Version 2.0 | Adopted on 20.08.2026 | In force as of 20.08.2026

In brief: We do not sell personal data. Optional analytics and advertising technologies are activated only after your valid choice via the cookie banner. This policy is an informational notice, not a contract — reading it does not constitute consent to processing.


This policy explains how "Mega Device" EOOD processes personal data when you visit and use www.mega-device.com (the "Platform"), register an account, place an order, submit an enquiry or a warranty claim, converse with the virtual assistant, apply for a job, and interact with our official social media profiles. It provides the information required under Art. 13 and — where the data has not been obtained directly from you — under Art. 14 of Regulation (EU) 2016/679 (the "Regulation", GDPR).

1. Controller and contact details

The controller of personal data is "Mega Device" EOOD, UIC 147130699, with registered office and management address: Burgas, "Izgrev" residential district, block 203, shop 6. Questions and requests concerning personal data: info@mega-device.com; telephones +359 885 076 776 and +359 879 022 363; website: www.mega-device.com.

Given the nature and volume of the data processed, the Controller is not required to designate a data protection officer under Art. 37 of the Regulation. Where a specific notice applies to a particular activity — for example, video surveillance on retail premises or employment relations — that notice supplements this policy.

2. Core principles

We process only data that is relevant and necessary for a specific, predetermined purpose, on a separate legal basis for each purpose. Acceptance of the General Terms and Conditions does not constitute blanket consent to all processing operations. We do not request special categories of data under Art. 9 of the Regulation (health, biometric, genetic, religious or political); if such data is provided unsolicited in a free-text field, chat or CV, we restrict its use and delete it, unless the law permits or requires otherwise. We do not use the data for an incompatible new purpose without providing further information and, where necessary, establishing a new legal basis. Passwords are stored solely as a cryptographic hash.

3. What data we process

  • Identification and contact data: names, telephone, email, delivery address (or courier locker/office), locality and preferred method of contact.
  • Account: email, secured form of the password, settings and order history.
  • Orders and deliveries: products, value, chosen payment and delivery method, recipient, status and related communication.
  • Payment and accounting data: amount, payment status and transaction identifier, invoicing details; in the case of a bank transfer — the name of the payer.
  • Warranty claims and guarantees: product, proof of purchase, description of the issue, return address and correspondence.
  • Communication: the content of enquiries, reviews and messages sent via the site, email, telephone, social network or a conversation with the virtual assistant "Megi".
  • Job applications: curriculum vitae (CV), contact details, education, qualifications, experience and other voluntarily provided information.
  • Technical and security data: IP address, date and time, browser, device, session and technical events necessary for security and functioning.
  • Analytics and advertising data: identifiers from cookies and similar technologies, pages visited and campaign measurement — only with valid consent.
  • Data from business customer enquiries: company, UIC, address, authorised representative, contact person and telephone, device models and quantities.

4. Purposes and legal bases

Purpose How we use the data Legal basis
Order and delivery Acceptance, confirmation, payment, delivery and communication regarding performance of the specific order Art. 6(1)(b) GDPR — contract and pre-contractual steps
User account Creation, authentication and management of a voluntarily requested account Art. 6(1)(b) GDPR
Invoicing and accounting Accounting and tax records, including electronic receipts and the audit file under Ordinance N-18 Art. 6(1)(c) GDPR — legal obligation
Warranty claims and guarantees Examination of requests and fulfilment of statutory and contractual obligations Art. 6(1)(b) and (c) GDPR; for the defence of claims — (f)
Enquiries and customer service, including via the assistant "Megi" Reply, correspondence and resolution of the specific case Art. 6(1)(b) where connected to a contract; otherwise (f) — legitimate interest
Security and protection against abuse Protection of the site, accounts and systems; prevention and investigation of incidents Art. 6(1)(f) GDPR — legitimate interest
Job applications Assessment of the application, contact and selection for the advertised position Art. 6(1)(b) GDPR and Art. 25k of the Personal Data Protection Act (PDPA); for claims — (f)
Direct marketing Offers via the channel you have chosen Consent — Art. 6(1)(a) GDPR and Art. 261(1) of the Electronic Communications Act (ECA); for our own similar products — only where all the conditions of Art. 261(2) ECA are met
Analytics and advertising Measurement of visits and campaigns, remarketing and personalisation Prior consent — Art. 6(1)(a) GDPR and Art. 4a of the Electronic Commerce Act, where information from the terminal device is used
Business enquiries Preparation of a quotation and performance of the requested service for corporate devices Art. 6(1)(b) GDPR for pre-contractual steps; (f) when contacting a representative of a legal entity
Enquiry via the contact form Name, email, phone (optional), subject, message text and IP address — in order to answer your enquiry Art. 6(1)(f) GDPR — legitimate interest in replying to an enquiry addressed to us; (b) where the enquiry concerns an order

Where we rely on legitimate interest, we document the purpose, the necessity and the balance with the rights of the individuals concerned; you may object in accordance with Section 13.

5. Where we obtain the data and which data is mandatory

We obtain data: directly from you (account, order, form, CV, email, telephone, chat or a visit to a store); from a person who places an order and names you as the recipient; from a courier, payment operator or bank in connection with a specific service; automatically from your device where this is technically necessary or where you have made the corresponding choice; from a social network when you interact with our official profile, subject to the platform's settings.

Providing your names, delivery address, telephone and email is a contractual requirement — without this data the order cannot be accepted and fulfilled. Invoicing data is a statutory requirement. All other data, including marketing preferences and optional technologies, is provided voluntarily and refusal entails no adverse consequences. When you provide us with the data of another recipient, you must have a basis for doing so and must inform that person; this does not release the Controller from its own obligations under Art. 14 of the Regulation.

6. Virtual assistant "Megi"

A virtual assistant (a "chatbot") operates on the Platform and answers questions about products and orders. We advise you not to enter personal data into the chat beyond what is necessary for your enquiry. The content of conversations is processed technically through a language model provider (Google Ireland Ltd. / Google LLC — Gemini API) acting as a processor; conversations are not used by the provider to train models, in accordance with the applicable terms for enterprise API services. Records are retained for up to 6 months for service quality purposes, after which they are deleted or anonymised.

7. Recipients and roles

We do not sell personal data and do not provide it to third parties for their own marketing purposes. A recipient may act as a processor, an independent controller or a joint controller depending on the specific operation; where a recipient processes data solely on our instructions, it is bound by a contract under Art. 28 of the Regulation.

Recipient Data transferred and role
Couriers: Econt Express OOD (UIC 117047646), Speedy AD (UIC 131371780) and "BOX NOW" OOD / BoxNow (UIC 206892501) Names, delivery address (or locker/office) and telephone — for the delivery of the specific consignment; in the case of cash on delivery, the courier collects the amount due on our behalf. For its own statutory obligations and subsequent processing, the courier acts as an independent controller.
Payment operators: "DSK Bank" AD (virtual POS for card payments) and PayPal (Europe) S.à r.l. et Cie, S.C.A. Card data and PayPal account data are processed entirely within the secure environment of the respective operator and do not pass through our systems; we receive only the payment status and the transaction identifier.
Take a NAP (takeanap.bg) — system for electronic receipts and the audit file under Ordinance N-18 Order data, value, customer name and email — for issuing and sending an electronic receipt and generating the audit XML file for the National Revenue Agency (Art. 52t of Ordinance N-18); a processor under Art. 28, acting solely on our instructions.
Hosting: "SuperHosting.BG" OOD, UIC 131449987, with servers in Bulgaria (EU) Technical storage of the data; access is limited to infrastructure maintenance, under a contract pursuant to Art. 28.
Accountants, auditors, lawyers and other professional advisers Data to the extent required by the relevant legislation or necessary for the defence of legal claims; the accounting firm acts as a processor under Art. 28.
Google (Analytics, Ads, Gemini API, Maps), Meta Platforms (Pixel) Technical and behavioural data — the analytics and advertising tools are activated in accordance with Section 10; the Google Maps map loads when a store page is opened; for their own processing, the providers are independent controllers.
Competent authorities (National Revenue Agency, Consumer Protection Commission, Commission for Personal Data Protection, courts) and a potential acquirer in the event of a transformation or transfer of business Only where there is a legal obligation, for the defence of legal claims, or subject to appropriate data protection safeguards, to the extent necessary.

With regard to the collection and transmission of event data via the Meta Pixel, the Controller and Meta Platforms Ireland Ltd. may act as joint controllers within the meaning of Art. 26 of the Regulation (judgment of the Court of Justice of the EU in Case C-40/17 Fashion ID); Meta's own privacy policy applies to its subsequent independent processing.

8. International transfers

Where analytics or marketing tools are activated, data may be transferred to servers of Google LLC, Meta Platforms Inc. and affiliated companies in the USA. These transfers are based on the European Commission's adequacy decision regarding the EU–U.S. Data Privacy Framework, in which the aforementioned providers are certified participants, and additionally on the standard contractual clauses under Decision (EU) 2021/914, with supplementary measures where necessary. Beyond this, we do not transfer personal data to third countries. The applicable mechanism depends on the specific company and service; information about, or a copy of, the relevant safeguards may be requested at info@mega-device.com.

9. Retention periods

Data category Period or criterion
Accounting registers and financial statements; tax documents under the Tax and Social Insurance Procedure Code 10 years, counted from 1 January of the reporting period following the one to which they relate (Art. 12 of the Accountancy Act; Art. 38 of the Tax and Social Insurance Procedure Code)
Data on orders, deliveries and warranty claims of a non-accounting nature Up to 5 years from performance — the general limitation period for legal claims (Art. 110 of the Obligations and Contracts Act); in the event of a pending dispute — until its conclusion
User account For as long as the account is active or until a deletion request; inactive accounts are reviewed periodically, while data required by law is separated and kept for the relevant period
Marketing consents and records of consents given/withdrawn Until withdrawal or objection; a minimal record of the choice — up to 3 years, as evidence under Art. 7(1) of the Regulation and to ensure the refusal is respected
Job applicants' documents Up to 6 months after the final conclusion of the selection process (Art. 25k PDPA); for future positions — only with explicit separate consent, up to 1 year
Conversations with the virtual assistant "Megi" Up to 6 months
Technical and security logs For the shortest period necessary for security; in the event of an incident or a claim — until final resolution
Cookies and similar technologies According to the duration of the specific technology, as stated in the Cookie Policy
Messages from the contact form 1 year from receipt

Once all grounds have lapsed, the data is deleted or irreversibly anonymised without undue delay; backup copies are purged as part of routine maintenance, but no later than 90 days after the deletion of the operational data. In the event of pending judicial, administrative or enforcement proceedings, an inspection or a statutory request, the data concerned is retained until conclusion.

10. Cookies and external services

Strictly necessary technologies (session, shopping cart, authentication, security, payment processing) do not require consent, but we provide information about them. Google Analytics, Google Ads, Meta Pixel and the other optional analytics or advertising technologies are activated only after a valid choice via the cookie banner — separately by category, with no pre-ticked boxes (Art. 4a of the Electronic Commerce Act; judgment of the Court of Justice of the EU in Case C-673/17 Planet49). Optional categories are switched off by default; the options "Accept all", "Reject all" and "Settings" are equally accessible, and scrolling or continuing to browse does not constitute consent. Your choice may be changed at any time via the permanent "Privacy settings" link, accessible from every page. Refusal does not restrict browsing or ordering.

The pages of our physical stores contain an embedded Google Maps map for directions; when it loads, Google receives an IP address and technical data as an independent controller (policies.google.com/privacy). On product pages the map loads only after an explicit action on your part. Forms are protected against automated abuse by our own technical measures — a hidden control field, a check on the time taken to complete the form, and a limit on the number of submissions from one address — on the basis of our legitimate interest in ensuring security. These measures do not transfer data to third parties. Detailed information on each technology — provider, purpose, type, duration and third-party access — is set out in the Platform's Cookie Policy.

11. Direct marketing

As a rule, we send marketing communications only after valid prior consent for the chosen channel. Consent is separate from the General Terms and Conditions and from the order and may be withdrawn as easily as it was given. Where we use an existing customer's data for our own similar products without new consent, we do so only where the conditions of Art. 261(2) ECA are simultaneously met: the data was obtained in the course of a sale, the offer concerns our own similar products, and a free and easy opt-out is provided both at the point of collection and in every message, and we also document the applicable legitimate interest. To opt out — follow the instructions in each message or write to info@mega-device.com; this does not affect service messages regarding an order, payment, delivery, warranty claim or security. An objection to direct marketing is actioned immediately and unconditionally.

12. Your rights

Under Art. 15–22 of the Regulation you have the right to: information and access to your data and a copy of it; rectification of inaccurate data and completion of incomplete data; erasure (the "right to be forgotten") where the statutory conditions are met; restriction of processing; data portability in a structured, machine-readable format where processing is automated and based on consent or a contract; objection to processing based on legitimate interest; unconditional objection to direct marketing; withdrawal of consent at any time, without retroactive effect; a complaint to a supervisory authority and judicial remedy. These rights are not absolute — we may restrict a request only where the law requires or permits it (for example, statutory retention, the rights of others, or legal claims), and we will state the reasons.

13. How to exercise a right and how to file a complaint

Send a request to info@mega-device.com or in writing to our management address, describing the action you wish to take. Where necessary to prevent unlawful disclosure, we may request limited additional information to verify your identity. We respond free of charge and, as a rule, within one month; in the case of complexity or a large number of requests, the period may be extended by a further two months, of which we will notify you within the initial period, stating the reasons. In the case of manifestly unfounded or excessive requests, we may charge a reasonable fee or refuse with reasons in the cases permitted by the Regulation.

You may file a complaint with the Commission for Personal Data Protection — Sofia 1592, 2 "Prof. Tsvetan Lazarov" Blvd., kzld@cpdp.bg, www.cpdp.bg — without prejudice to your right to judicial remedy.

14. Security and breaches

We apply technical and organisational measures under Art. 32 of the Regulation, appropriate to the nature of the data and the risk: HTTPS/TLS encryption of the connection, password hashing, differentiated access levels granted only on a need-to-know basis and confidentiality obligations, regular backups in a separate environment, and contractual security obligations for all processors. No system guarantees absolute security. In the event of a breach we limit the consequences, document the case and notify the Commission for Personal Data Protection without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk; where a high risk is likely, we also notify the individuals concerned, save for the exceptions provided by law (Art. 33 and 34 of the Regulation).

15. Automated decision-making and profiling

We do not take decisions based solely on automated processing which produce legal or similarly significant effects for you within the meaning of Art. 22 of the Regulation. Advertising audience grouping may constitute profiling, but does not in itself produce such effects. Should such mechanisms be introduced in the future, this policy will be updated in advance and explicit consent will be obtained where necessary.

16. Children's data

The Platform is not directed at persons under 16 years of age. Where processing in connection with an information society service is based on consent and the individual is under 14, the consent of the holder of parental responsibility is required (Art. 25c PDPA). Transactions by minors are carried out in accordance with the rules on their legal capacity. If processing is found to be in breach of these rules, the data is deleted immediately.

17. Changes and current version

The current version and its effective date are published on this page. In the event of material changes affecting your rights, registered users are notified in advance by email or via a message displayed prominently on the Platform. A change to the text does not in itself create a new legal basis; where new consent is required, processing does not begin before it is obtained. This version 2.0 was adopted on 20.08.2026 and takes effect from 20.08.2026.


Legal sources

Regulation (EU) 2016/679 (GDPR); Personal Data Protection Act (including Art. 25c and Art. 25k); Electronic Commerce Act — Art. 4a; Electronic Communications Act — Art. 261; Accountancy Act — Art. 12; Tax and Social Insurance Procedure Code — Art. 38; Obligations and Contracts Act — Art. 110; Ordinance No. N-18 — Art. 52t; EDPB Guidelines 05/2020 on consent; judgments of the Court of Justice of the EU in Cases C-673/17 Planet49 and C-40/17 Fashion ID.