Free delivery across Europe Secure checkout — 100% protected Summer launch offer — up to 67% off 30-day free returns
0

Privacy Policy

Last updated: 3 July 2026

This Privacy Policy explains how Trilium EOOD, operating Trilium Marketplace (“Trilium”, “we”, “us” or “our”), collects, uses, stores and protects personal data when you visit our website, create an account, place an order, contact us or otherwise interact with our services.

We process personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – “GDPR”), applicable Bulgarian data protection legislation and, where relevant, other applicable privacy and data protection laws.

1. Data Controller

The data controller responsible for personal data processed through Trilium Marketplace is:

Trilium EOOD (ЕООД)
EIK/UIC: 131461587
VAT Number: BG131461587
Registered office: 31 Alabin Street, 1000 Sofia, Bulgaria
Email: info@trilium-bg.com
Telephone: +359 899 665 200

For privacy-related requests or to exercise your data protection rights, please contact us at info@trilium-bg.com.

2. Personal Data We Collect

Depending on how you use Trilium Marketplace, we may collect and process the following categories of personal data.

Identity and contact data may include your first and last name, email address, telephone number, billing address, shipping address and other contact information you provide to us.

Account data may include your login credentials, account preferences and information associated with your customer account. Passwords are not stored in plain text and are protected using appropriate cryptographic security mechanisms.

Order and transaction data may include products purchased, order number, order value, quantities, discounts, shipping method, payment status, transaction references, returns, refunds and other information necessary to manage your purchase.

Payment-related data may include limited information concerning your payment transaction, such as payment status, payment method and transaction identifiers. Full card details are processed by the relevant payment provider and are not intended to be stored by Trilium Marketplace.

Shipping and fulfilment data may include your name, delivery address, telephone number, email address where necessary, order contents and other information required to deliver or return an order.

Technical and device data may include your IP address, browser type, device type, operating system, language, timestamps, diagnostic information, security logs and other technical information generated when you access our website.

Usage data may include pages viewed, interactions with the website, cart activity and other information about how visitors use our services, where collected lawfully.

Communications data includes information contained in emails, contact forms, customer-support requests, complaints, return requests or other communications you send to us.

Cookie and similar technology data may include identifiers and information collected through cookies or comparable technologies. Non-essential technologies are used subject to applicable consent requirements. Please refer to our Cookie Policy for additional information.

We do not intentionally request special categories of personal data, such as information concerning health, biometric data, religious beliefs or political opinions, through the ordinary operation of our marketplace.

3. How We Collect Personal Data

We primarily collect personal data directly from you, for example when you:

  • create or manage an account;
  • place or manage an order;
  • enter information during checkout;
  • request a return or refund;
  • contact customer support;
  • complete a contact form;
  • subscribe to marketing communications;
  • manage your cookie preferences; or
  • otherwise interact with our website.

Certain technical information may be collected automatically when you use the website.

We may also receive limited personal data from service providers involved in completing your transaction, such as payment providers, where necessary to confirm or manage payments, refunds, fraud prevention or related services.

4. Purposes and Legal Bases for Processing

We process personal data only where we have an appropriate legal basis under applicable data protection law.

4.1 Orders and performance of our contract

We process personal data to:

  • receive and process orders;
  • process checkout;
  • arrange delivery;
  • provide order confirmations;
  • provide shipping-related communications;
  • manage returns, cancellations and refunds;
  • provide customer support relating to purchases; and
  • administer customer accounts where necessary for our services.

Legal basis: performance of a contract or steps taken at your request before entering into a contract — Article 6(1)(b) GDPR.

4.2 Legal, tax and accounting requirements

We may process and retain information where necessary to:

  • maintain accounting records;
  • issue and retain invoices;
  • comply with tax requirements;
  • comply with consumer protection requirements;
  • respond to legally valid requests from competent authorities; and
  • establish, exercise or defend legal claims where applicable.

Legal basis: compliance with a legal obligation — Article 6(1)(c) GDPR and, where applicable, our legitimate interests under Article 6(1)(f) GDPR.

4.3 Customer service and communications

We process information submitted through customer service channels to answer questions, resolve problems, manage complaints and provide assistance.

Depending on the nature of the request, the legal basis may be:

  • Article 6(1)(b) GDPR where the communication relates to an existing or prospective transaction; or
  • Article 6(1)(f) GDPR where processing is necessary for our legitimate interest in communicating with customers and operating our business.

4.4 Website security and fraud prevention

We may process technical, transaction and account information to:

  • protect customer accounts;
  • secure our website and infrastructure;
  • detect suspicious activity;
  • prevent abuse and fraud;
  • investigate security incidents; and
  • establish, exercise or defend legal claims.

Legal basis: our legitimate interests in maintaining the security and integrity of our services, protecting our customers and preventing fraudulent or abusive activity — Article 6(1)(f) GDPR.

4.5 Website operation and improvement

We may process technical and usage information necessary to operate, troubleshoot and improve our services.

Where the processing is strictly necessary for operation or security, it may be based on our legitimate interests or another applicable legal basis.

Where information is collected through non-essential analytics technologies requiring consent, processing takes place only after the required consent has been obtained.

4.6 Marketing communications

Where you have subscribed or otherwise provided the required consent, we may use your contact information to send marketing communications about products, offers or other commercial information.

Legal basis: consent — Article 6(1)(a) GDPR, where consent is required.

You may withdraw your consent at any time, including by using the unsubscribe mechanism provided in marketing communications or by contacting us.

Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

4.7 Analytics, advertising and non-essential cookies

Where we use analytics, advertising or other non-essential tracking technologies requiring consent, those technologies will be activated only in accordance with your cookie choices.

Legal basis: consent — Article 6(1)(a) GDPR, where applicable.

You can change or withdraw your choices through the cookie preference mechanism available on the website.

5. Whether You Are Required to Provide Personal Data

Certain information is necessary for us to enter into and perform a contract with you.

For example, without sufficient contact, billing, payment and delivery information, we may be unable to process or deliver an order.

Other information is optional. Where processing is based on consent, you are free to refuse or withdraw that consent, subject to any processing that is strictly necessary for the service you requested.

6. Payment Information

Payments may be processed through third-party payment providers, including:

  • PayPal — payment processing.
  • BORICA AD — card payment processing, including VPOS and 3-D Secure services where applicable.

Payment providers process payment information according to their respective roles and privacy terms.

Trilium Marketplace does not intend to collect or store your complete payment-card number, CVV/CVC or other full card credentials where these are submitted directly to the payment provider.

We may nevertheless receive and retain limited transaction information such as transaction references, payment method, payment status, refund information or other information necessary for accounting, order management, fraud prevention and customer support.

7. Service Providers and Other Recipients

We disclose personal data only where reasonably necessary for the purposes described in this Privacy Policy.

Depending on the services used, recipients may include:

  • Supabase — application infrastructure, database and authentication services.
  • PayPal — payment processing.
  • BORICA AD — payment processing and card-payment services.
  • Migadu — email infrastructure and communications.
  • Cloudflare — content delivery, DNS, website performance and security services.
  • Google — where Google services such as an embedded map are used on the website.

We may also disclose the minimum information necessary to shipping, courier, logistics and fulfilment providers in order to deliver orders and manage returns.

Depending on the particular processing activity, a recipient may act as our processor, sub-processor or as an independent data controller. The applicable role depends on the service and the provider’s responsibilities under data protection law.

We may also disclose personal data to professional advisers, auditors, accountants, insurers, courts, regulatory bodies, law-enforcement authorities or other competent public authorities where required or permitted by law.

We do not sell personal data.

8. International Transfers

Some of our service providers or their infrastructure may process personal data outside the European Economic Area (EEA).

Where personal data is transferred to a country outside the EEA, we use an appropriate transfer mechanism where required by Chapter V of the GDPR.

Depending on the circumstances, this may include:

  • an adequacy decision adopted by the European Commission;
  • Standard Contractual Clauses approved by the European Commission; or
  • another legally permitted transfer mechanism.

Where required, supplementary measures may also be implemented taking into account the nature of the processing and the destination of the data.

You may contact us for further information about the safeguards applicable to relevant international transfers.

9. Cookies and Similar Technologies

Our website may use cookies and similar technologies.

Strictly necessary technologies may be used where required for core website functionality, including security, authentication, shopping-cart functionality, checkout and other services requested by the user.

Other technologies, including certain analytics, advertising or marketing technologies, are used only in accordance with applicable consent requirements.

Where consent is required, you can accept, reject or manage these technologies through our cookie consent interface.

You may withdraw or change your consent at any time through the available cookie settings.

For further information about the technologies used, their purposes, providers and duration, please refer to our Cookie Policy.

10. Embedded Third-Party Content

Certain pages may contain functionality or content supplied by third parties, such as an embedded Google map.

Such third-party services may process information such as your IP address or device information when they are loaded.

Where applicable law requires consent before such third-party content or associated technologies are activated, we will seek the appropriate consent before loading them.

11. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected and to satisfy applicable legal, tax, accounting, contractual and dispute-resolution requirements.

Retention periods may therefore vary according to the category of information and the reason it is processed.

In particular:

  • Account information is generally retained while the account remains active and thereafter for an appropriate period where necessary for legal, security, fraud-prevention or dispute-resolution purposes.
  • Order, invoice, tax and accounting records may be retained for the period required by applicable Bulgarian and EU legislation. Where a specific statutory retention period requires records to be retained for 10 years, we will retain the relevant records for that period.
  • Customer-support and contact communications are retained for the time necessary to handle the request and, where appropriate, for an additional period necessary to establish, exercise or defend legal claims.
  • Marketing information based on consent is processed until consent is withdrawn or the information is no longer necessary, subject to the retention of limited suppression information where necessary to respect an opt-out.
  • Cookie and analytics information is retained according to the applicable technology and the periods disclosed through our Cookie Policy or consent interface.

At the end of the applicable retention period, personal data will be deleted, anonymised or otherwise securely disposed of unless further retention is required or permitted by law.

12. Data Security

We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Depending on the relevant system, these measures may include:

  • encryption of data in transit;
  • access controls;
  • authentication mechanisms;
  • database access restrictions;
  • Row Level Security where applicable;
  • infrastructure and network security measures;
  • logging and monitoring; and
  • restriction of access according to operational necessity.

However, no internet-based service or electronic storage system can be guaranteed to be completely secure.

13. Your GDPR Rights

Subject to the conditions and limitations provided by applicable law, you may have the right to:

  • Access — obtain confirmation as to whether we process your personal data and request access to that information.
  • Rectification — request correction of inaccurate or incomplete personal data.
  • Erasure — request deletion of your personal data in circumstances provided by Article 17 GDPR.
  • Restriction — request restriction of processing in circumstances provided by the GDPR.
  • Data portability — receive certain personal data in a structured, commonly used and machine-readable format and, where applicable, have it transmitted to another controller.
  • Object — object to processing based on legitimate interests, subject to the conditions established by the GDPR.
  • Object to direct marketing — object at any time to the processing of your personal data for direct marketing purposes.
  • Withdraw consent — where processing relies on consent, withdraw that consent at any time without affecting processing lawfully carried out before withdrawal.
  • Lodge a complaint — submit a complaint to a competent data protection supervisory authority.

These rights are subject to the conditions and exceptions contained in applicable law. The GDPR expressly provides rights including access, rectification and erasure, among others.

14. Exercising Your Rights

To exercise your rights or make a privacy-related request, contact:

info@trilium-bg.com

Please provide sufficient information for us to understand your request.

Where we have reasonable doubts concerning the identity of the person making a request, we may request additional information necessary to confirm identity, as permitted by the GDPR.

We will respond within the periods required by applicable data protection law.

15. Right to Lodge a Complaint

As Trilium EOOD is established in Bulgaria, you may lodge a complaint with the Bulgarian supervisory authority:

Commission for Personal Data Protection (CPDP)
2 Prof. Tsvetan Lazarov Blvd.
Sofia 1592
Bulgaria

The CPDP provides an official procedure for complaints concerning infringements of GDPR/data-protection rights.

You may also have the right to complain to the competent supervisory authority in the EU/EEA Member State of your habitual residence, place of work or the place of the alleged infringement, as provided by applicable law.

16. Children

Trilium Marketplace is intended for a general adult shopping audience and is not designed as a service directed specifically at children.

We do not knowingly seek to collect personal data from children through the ordinary operation of our marketplace.

If you believe that a child has provided personal data to us in circumstances where it should not have been collected, please contact us at info@trilium-bg.com so that we can assess the situation and take appropriate action.

17. Automated Decision-Making

Unless expressly stated otherwise at the relevant point of collection, we do not use personal data to make decisions based solely on automated processing that produce legal effects or similarly significantly affect you within the meaning of Article 22 GDPR.

Automated security or fraud-detection tools may assist us or our service providers in identifying potentially suspicious activity. Where applicable, such processing is subject to appropriate safeguards and applicable law.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time, for example when our services, service providers, technologies or legal obligations change.

The current version will be published on this page together with the applicable “Last updated” date.

Where required by law, we will provide additional notice or request renewed consent before materially changing processing that depends on consent.

19. Contact Us

For questions concerning this Privacy Policy or the processing of your personal data, please contact:

Trilium EOOD (ЕООД)
EIK/UIC: 131461587
VAT Number: BG131461587
Registered office: 31 Alabin Street, 1000 Sofia, Bulgaria
Email: info@trilium-bg.com
Telephone: +359 899 665 200

Scroll to Top