Privacy Policy
Last updated: 2026-07-23
1. Who we are
YouthOS (the admin/staff panel and the visitor app, together "the platform") is operated by Radoslav Ivanov ("the platform provider"). Each youth center that uses the platform to run its programs ("the center") is the data controller for its own visitors' personal data described in this policy — it decides what data is collected and why. The platform provider is a data processor: it processes that data only on the center's instructions and under a data processing agreement with the center (Art. 28 GDPR), and does not use it for its own purposes.
For questions about how a specific center uses your data, or to exercise your rights (Section 7), contact that center directly. For platform-level questions, contact the platform provider at: privacy@youthcenter.bg
2. What data we collect
Depending on how you interact with us, we may collect:
- Identity and contact data: full name, phone number, email address, Instagram handle, date of birth, home address.
- Program and activity data: event sign-ups and attendance, borrowed inventory items, volunteering hours and certificates, hotel/accommodation bookings and related notes.
- Custom profile fields: additional fields a specific center may ask for (for example, city of residence) to run its programs.
- Account and technical data: your visitor code/QR code, login method (phone verification), push-notification token, and basic access records of when staff view your profile.
- Consent records: a timestamped record of when you agreed to this policy and our Terms of Use, and which version you agreed to.
We do not knowingly collect more data than we need to run youth-center programs and keep participants safe.
3. Why we process your data (legal basis)
- Consent (Art. 6(1)(a) GDPR): for account creation, communications, and any optional profile fields, based on the consent you give at sign-up.
- Legitimate interest (Art. 6(1)(f) GDPR): running events, tracking attendance and inventory loans, and administering volunteer programs, where this doesn't override your rights and freedoms.
- Legal obligation (Art. 6(1)(c) GDPR): where record-keeping is required by applicable law (for example, certain financial records for accommodation bookings).
4. Children's data
Youth centers serve minors. Under GDPR and Bulgarian law, the age at which a person can consent to data processing on their own behalf is 16. Visitors under 16 register and use the platform under the responsibility of their parent or legal guardian, who is expected to be aware of and to have agreed to this policy on the minor's behalf. We aim to collect no more personal data from minors than is necessary to run our programs safely.
5. Who we share data with
- The platform provider operates the YouthOS infrastructure and processes all data described in this policy as a data processor on behalf of the center, under a data processing agreement — it does not use your data for its own purposes and does not share it with other centers.
- Twilio (SMS/phone verification provider) processes your phone number to deliver one-time verification codes.
- We do not sell personal data, and we do not share it with third parties for their own marketing purposes.
- We may disclose data where required by law or to protect the safety of visitors or staff.
6. How long we keep your data
- Visitor records are kept while you remain an active participant. After a configurable period of inactivity (currently 3 years with no event registration, booking, volunteering activity, or loan), your record is anonymized.
- Consent records are kept as evidence that consent was obtained, even after your other data is anonymized.
- You can request earlier deletion at any time — see Section 7.
7. Your rights
You have the right to:
- Access the personal data we hold about you.
- Export your data in a portable format.
- Erase your data (we anonymize your profile and remove identifying fields; some records tied to organizational history, like event attendance counts, are kept in anonymized form so they don't corrupt other people's records).
- Rectify inaccurate data.
- Object to or restrict certain processing.
You can exercise access and erasure rights directly from the app (visitor app: Profile → Data & Privacy), or by contacting us at the address in Section 1. For step-by-step deletion instructions, see the Account Deletion page.
If you believe your rights have not been respected, you can lodge a complaint with Bulgaria's data protection authority, the Commission for Personal Data Protection (Комисия за защита на личните данни, CPDP), or your local supervisory authority.
8. Security
We take reasonable technical and organizational measures to protect your data, including access controls on staff accounts and restricting who can view visitor details. No system is perfectly secure; if we become aware of a data breach affecting your personal data, we will notify you and the relevant authority as required by law.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected in the "Last updated" date and version above, and, where required, we will ask you to re-confirm your consent.