Privacy Policy

Last Updated: [23/07/2025]

This Privacy Policy describes how “Trustvestor Ltd.”, a company registered in the Republic of Bulgaria (“Trustvestor”, “We”, “Us”, “Our”), collects, uses, stores, discloses, and protects your personal data when you access and use the Trustvestor.com website, as well as all related services (collectively, the “Platform”).

We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679 – GDPR) and other applicable laws and regulations.


1. Data Protection Officer (DPO)

Our Data Protection Officer is Andon Lucien, who can be contacted at: andon.lucien@trustvestor.com for all matters related to the processing of your personal data and the exercise of your rights.


2. Fundamental Principles for Personal Data Processing

We adhere to the following fundamental principles when processing your personal data:

  • Lawfulness, Fairness, and Transparency: Your data is processed lawfully, fairly, and in a transparent manner.
  • Purpose Limitation: Your data is collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
  • Data Minimisation: We collect only adequate, relevant, and limited data to what is necessary in relation to the purposes for which they are processed.
  • Accuracy: Personal data is accurate and, where necessary, kept up to date.
  • Storage Limitation: Data is kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
  • Integrity and Confidentiality: Data is processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures.
  • Accountability: We are responsible for and able to demonstrate compliance with all the aforementioned principles.

3. Categories of Personal Data, Purposes, and Legal Basis for Processing

We collect and process your personal data for the following purposes and on the following legal bases:

3.1. Account Registration (for Creators and Backers)

  • Categories of Data: First name, last name, email address, phone number, date of birth, address, nationality, as well as bank account/payment method details (for Project Creators only).
  • Purposes of Processing: Creating and managing your user account, communicating with you, verifying your identity, preventing fraud, and complying with anti-money laundering and know-your-customer (AML/KYC) requirements.
  • Legal Basis:
    • Performance of a Contract: For creating and maintaining your account and providing the services described in the Terms of Use.
    • Legal Obligation: For identity verification and AML/KYC purposes, as required by Regulation (EU) 2020/1503.
    • Legitimate Interest: For fraud prevention and maintaining platform security.

3.2. Project Creation

  • Categories of Data: Business information (if applicable), identification numbers (e.g., EIK/VAT number), project details, including videos and photos that may contain personal data of the Creator or other individuals.
  • Purposes of Processing: Project validation and approval, execution of the fundraising campaign, disbursement of collected funds, and public presentation of the project on the platform.
  • Legal Basis:
    • Performance of a Contract: For executing your campaign and related services.
    • Legitimate Interest: For promoting the project and the platform.

3.3. Project Support

  • Categories of Data: Support amount, chosen reward, delivery details (name, address, phone), if applicable.
  • Purposes of Processing: Payment processing, ensuring reward delivery, and communication with the Project Creator regarding the reward.
  • Legal Basis:
    • Performance of a Contract: For processing your support and linking it to your chosen project.

3.4. Automatically Collected Data (via Cookies and Tracking Technologies)

  • Categories of Data: IP address, browser type, pages visited, time spent, referral URL.
  • Purposes of Processing: Ensuring website functionality, performing analytics to improve user experience and services, marketing, and content personalization.
  • Legal Basis:
    • Legitimate Interest: For platform operation and security, as well as for aggregated analytics.
    • Consent: For non-essential cookies and tracking technologies used for marketing and personalization.
  • Cookie Policy: Please see our separate Cookie Policy [ADD LINK HERE] for more detailed information on the use of cookies and your control options.

3.5. Communication Data

  • Categories of Data: Content of emails, chat accounts, mobile phone numbers, messages sent through the platform’s messaging system.
  • Purposes of Processing: Customer service, dispute resolution, responding to inquiries.
  • Legal Basis:
    • Performance of a Contract: For providing support and services.
    • Legitimate Interest: For improving service and resolving disputes.

4. Legal Basis for Data Processing (GDPR Summary)

We only process your personal data when we have a lawful basis to do so, which includes:

  • Performance of a Contract: When processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract (e.g., account creation, project support).
  • Legal Obligation: When processing is necessary for compliance with our legal obligation (e.g., AML/KYC requirements under Regulation (EU) 2020/1503, accounting and tax obligations).
  • Legitimate Interest: When processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms (e.g., improving services, fraud prevention, platform security).
  • Consent: When you have given your explicit consent to the processing of your data for one or more specific purposes (e.g., for marketing communications, non-essential cookies). You have the right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

5. Disclosure and Sharing of Personal Data

We may disclose your personal data to the following categories of recipients:

  • Payment Service Providers: For processing payments and transactions.
  • Identity Verification (KYC) Partners: For fulfilling our legal obligations under AML/KYC.
  • Hosting and IT Service Providers: For supporting the platform’s infrastructure.
  • Analytics Service Providers: For analyzing platform usage and improving services.
  • Marketing Partners: For marketing activities, if you have given consent.
  • Competent Authorities: When required by law (e.g., court orders, fraud investigations).

Specific to the Crowdfunding Platform:

  • For Backers: When you support a project, your name and delivery address (if a physical reward requiring delivery is chosen) will be shared with the Project Creator to enable them to fulfill their reward delivery obligation.
  • For Project Creators: Certain information about you or your company, including name/company name, photo, and location, may be publicly visible on your campaign page for the purpose of promoting the project.

Data Transfer Outside the EU/EEA: We do not transfer personal data outside the European Union / European Economic Area.


6. Data Security

We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction. These measures include, but are not limited to: data encryption, access control to systems, regular security audits, and staff training on data protection.


7. Data Retention

We retain your personal data only for the period necessary to fulfill the purposes for which it was collected, or as required by applicable law. Account and transaction data are stored in accordance with legal requirements arising from financial, accounting, and AML/KYC regulations, which may impose longer retention periods. Upon expiry of these periods, your data will be deleted or anonymized.


8. Data Subject Rights

As a data subject, you have certain rights under the GDPR. To exercise these rights, please contact us at support@trustvestor.com or via the contact form on the Platform.

Your rights include:

  • Right of Access: To obtain confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to the personal data.
  • Right to Rectification: To request the rectification of inaccurate personal data or the completion of incomplete data.
  • Right to Erasure (“Right to be Forgotten”): To request the erasure of your personal data under certain conditions, e.g., if the data is no longer necessary for the purposes for which it was collected.
  • Right to Restriction of Processing: To request the restriction of processing of your personal data if you contest its accuracy, or if the processing is unlawful but you do not want erasure.
  • Right to Data Portability: To receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format and to transmit those data to another controller.
  • Right to Object: To object to the processing of your personal data based on legitimate interest.
  • Right to Lodge a Complaint with a Supervisory Authority: You have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP) in the Republic of Bulgaria if you believe that the processing of your personal data infringes the GDPR.

9. Children

The Trustvestor.com Platform is not intended for individuals under 19 years of age, and we do not knowingly collect personal data from individuals under this age. If we become aware that we have collected personal data from a person under 19 without parental consent, we will take steps to delete that data.


10. Changes to the Privacy Policy

We reserve the right to update this Privacy Policy at any time. All changes will be effective immediately upon publication of the updated policy on the Platform. We recommend that you periodically review this Policy to stay informed about how we protect your data.


11. Contact Information

If you have any questions or concerns about this Privacy Policy or our data protection practices, please contact us at:

Email: support@trustvestor.com