Skip to main content

Website Privacy Notice

MTRC - European Med Tech and IVD Reimbursement Consulting Ltd.

Last updated: 13 July 2026

This privacy notice governs the collection and use of personal data by European Med Tech and IVD Reimbursement Consulting Ltd. in connection with website visits, enquiries, communications, subscriptions, and service provision. It is issued in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Bulgarian data protection legislation.

 

1. Data Controller

The data controller is European Med Tech and IVD Reimbursement Consulting Ltd., a company established in Bulgaria.

Registered office: 10 Stefan Karadzha Street, floor 3-4, Sredets District, Sofia, 1000, Bulgaria Email: [email protected] Website: https://mtrconsult.com/

All privacy-related inquiries and requests to exercise GDPR rights should be directed to [email protected].

 

2. Categories of Personal Data Collected

The categories of personal data collected depend on the nature of the interaction with MTRC and may include:

  • Identification and contact details: name, business email address, telephone number, job title, company name, and business address.

  • Enquiry and correspondence data: information provided via contact forms, email, meeting requests, or other communications.

  • Client and service data: information necessary for proposal preparation, consulting service delivery, contract management, invoicing, payment collection, and business record maintenance.

  • Marketing preference data: newsletter subscription status, consent records, opt-out requests, and communication preferences.

  • Technical and usage data: IP address, browser type, device information, pages visited, approximate location (derived from IP address), visit timestamps, cookie identifiers, and similar online identifiers.

  • Other information voluntarily provided.

     

3. Means of Collection

Personal data is collected directly from the data subject upon contact, subscription, information request, or client engagement. Limited technical and usage data is also collected automatically via cookies, server logs, and similar technologies during website visits, subject to cookie preferences where required.

 

4. Sources of Personal Data

Personal data is primarily obtained directly from the data subject. In limited circumstances, information may be derived from publicly available sources, business partners, or professional networking platforms (e.g., LinkedIn) where relevant to a business relationship or enquiry.

 

5. Purposes of Processing and Lawful Bases

Processing of personal data is conducted only where a lawful basis under the GDPR exists. The principal purposes and corresponding lawful bases are as follows:

Purpose

Data Used

Lawful Basis

Notes

Responding to enquiries and contact requests

Name, business email, phone, company, message content

Legitimate interests; pre-contractual steps

Data is used to respond and manage business communications.

Provision of consulting services and client relationship management

Contact details, company details, correspondence, service-related information

Performance of a contract; pre-contractual steps

Encompasses proposals, service delivery, meetings, and client administration.

Invoicing, accounting, and payment administration

Billing details, payment status, invoices, business records

Legal obligation; performance of a contract

Accounting and tax records are retained for legally mandated periods.

Marketing communications

Email address, name, company, preferences, consent records

Consent; or legitimate interests/soft opt-in where permitted

Subscriptions can be unsubscribed from or objected to at any time.

Website analytics and improvement

Cookie identifiers, IP address, browser/device data, usage information

Consent (for non-essential cookies); legitimate interests (for necessary security/technical logs)

Analytics and advertising cookies are activated only in accordance with cookie choices.

Website security, fraud prevention, and legal protection

Technical logs, IP address, correspondence, relevant records

Legitimate interests; legal obligation where applicable

Data is used for website security and to establish, exercise, or defend legal claims.

Compliance with legal and regulatory requests

Relevant personal data requested by authorities, courts, or regulators

Legal obligation; legitimate interests where applicable

Disclosure may occur where required by law or lawful order.

 

6. Cookies, Analytics, and Advertising Technologies

The website employs cookies and similar technologies. Strictly necessary cookies for website functionality may be used without consent. Non-essential cookies (e.g., analytics, advertising, remarketing) are used only following the obtainment of consent via the website's cookie banner or settings tool. Further information is available at www.aboutcookies.org and www.allaboutcookies.org.

Cookie consent may be modified or withdrawn at any time. Browsers may also be configured to block or delete cookies, though disabling strictly necessary cookies may impact website functionality.

The website utilizes Google Analytics 4, Google Search Console, Google Ads, and Google Tag Manager.

 

7. Marketing Communications

Marketing communications regarding services, events, or updates may be sent where a lawful basis exists, such as consent or another permitted basis. Withdrawal of consent or opt-out from marketing is possible at any time via the unsubscribe link in emails or by contacting [email protected]. Such withdrawal does not affect the lawfulness of processing prior to the action, nor does it impact service-related communications necessary for existing client relationships.

 

8. Data Sharing

Personal data may be shared with the following categories of recipients as necessary for the purposes outlined in this notice:

  • IT hosting, website maintenance, email, cloud storage, and cybersecurity providers.

  • Analytics, cookie, and advertising technology providers (subject to cookie choices where enabled).

  • Professional advisers, including accountants, auditors, legal advisers, and consultants.

  • Payment, invoicing, and administrative service providers (where applicable).

  • Public authorities, courts, regulators, law enforcement bodies, or other third parties where disclosure is required by law, lawful order, or is necessary to establish, exercise, or defend legal claims.

  • A buyer, successor, or professional adviser in connection with a proposed or actual restructuring, merger, acquisition, or transfer of all or part of the business, subject to appropriate confidentiality and data protection safeguards.

Personal data is not shared with any parties beyond those listed above, nor is it made available for unrelated or unsolicited commercial purposes.

 

9. International Data Transfers

Personal data is processed within the European Economic Area (EEA) where possible. Certain service providers (e.g., cloud, analytics, advertising) may process data outside the EEA. For such transfers, a lawful mechanism is relied upon, including an adequacy decision by the European Commission, Standard Contractual Clauses approved by the European Commission, or another permitted GDPR mechanism. Supplementary safeguards are assessed where appropriate.

 

10. Data Retention Periods

Personal data is retained only as long as necessary for the purposes described, to comply with legal, accounting, and reporting obligations, to resolve disputes, and to enforce agreements. Specific retention periods include:

  • Website technical logs: up to 12 months, unless a longer period is required for security investigations, fraud prevention, troubleshooting, or legal purposes.

  • Contact form and enquiry data: up to 24 months after the last contact, unless an enquiry transitions into a client relationship or a longer period is needed for legal claims.

  • Client and service records: for the duration of the client relationship, and thereafter up to 5 years, unless a longer period is mandated by law, accounting/tax rules, contractual obligations, or legal claims.

  • Accounting, invoicing, and tax records: generally, 10 years from the end of the financial year to which they relate, or any longer period required by applicable Bulgarian accounting, tax, or audit law.

  • Marketing subscription records: until the data subject unsubscribes, withdraws consent, objects to processing, or is removed under retention rules. Limited suppression records may be retained to prevent future contact.

  • Cookie consent records and analytics data: cookie consent records are kept for up to 12 months or until consent is modified or withdrawn. Analytics data is retained for up to 14 months, unless otherwise configured.

When data is no longer required, it is deleted, anonymized, or securely archived where legal retention obligations apply.

 

11. Mandatory Provision of Personal Data

Browsing the website does not require provision of personal data, except for limited technical data necessary for functionality and security. For enquiries, information requests, subscriptions, or client engagement, certain personal data is required to respond, provide services, manage the relationship, and fulfill legal obligations. Failure to provide such data may preclude response or service provision.

 

12. Automated Decision-Making and Profiling

Automated decision-making that produces legal or similarly significant effects concerning the data subject is not conducted. Should this policy change, this notice will be updated accordingly.

 

13. Data Protection Measures

Technical and organizational measures are implemented to safeguard personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Such measures include access controls, secure systems, confidentiality obligations, backups, malware protection, and administrative safeguards. While no transmission or storage method is completely secure, safeguards are proportionate to the risks involved.

 

14. GDPR Rights of Data Subjects

Subject to applicable conditions and limitations under the GDPR, data subjects have the following rights:

  • Right of access: to obtain confirmation of processing and a copy of the personal data.

  • Right to rectification: to request correction of inaccurate or incomplete data.

  • Right to erasure: to request deletion of data in certain circumstances.

  • Right to restriction: to request restriction of processing in certain circumstances.

  • Right to data portability: to receive certain data in a structured, commonly used, and machine-readable format and to transmit it to another controller.

  • Right to object: to object to processing based on legitimate interests (including profiling) and to object to direct marketing at any time.

  • Right to withdraw consent: to withdraw consent where processing is based on consent, without affecting the lawfulness of processing prior to withdrawal.

Requests to exercise these rights should be submitted to [email protected]. Identity verification may be required before responding. Responses are generally provided within one month, subject to GDPR-allowed extensions. No fee is usually charged, though a reasonable fee may be applied or a request refused if manifestly unfounded or excessive.

 

15. Complaints

Concerns regarding data processing should first be directed to MTRC at [email protected]. Data subjects also retain the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP) or the supervisory authority in their EU Member State of habitual residence, place of work, or the location of the alleged infringement.

 

16. Third-Party Websites

The website may contain links to external third-party websites or services. This privacy notice applies solely to MTRC's website and processing activities. Responsibility for the privacy practices of third parties is not accepted, and users are advised to review the privacy notices of any external sites visited.

 

17. Changes to This Privacy Notice

This privacy notice may be updated periodically. The current version will be posted on this webpage with the "Last updated" date. Material changes will be communicated with additional notice where appropriate.

 

18. Contact Information

For questions, requests, or complaints concerning this privacy notice or data processing practices, please contact:

European Med Tech and IVD Reimbursement Consulting Ltd. Email: [email protected] Registered office: 10 Stefan Karadzha Street, floor 3-4, Sredets District, Sofia, 1000, Bulgaria