Scope and Purpose of the Policy
The protection of personal data, as well as the security of our customers’ personal and financial information, is of essential importance to us. We therefore process your personal data lawfully, fairly and in accordance with the applicable legislation, including Regulation (EU) 2016/679 (GDPR), the Bulgarian Personal Data Protection Act and the Electronic Commerce Act.
This Policy governs the processing of personal data in connection with the website teorema.bg, telephone enquiries, e-mail enquiries, bookings, the online booking system and voucher ordering system integrated into teorema.bg, as well as visits to and participation in the games and the related goods and services.
The Policy applies to the activities of the following companies (collectively, the “Companies”, and each individually, a “Company”), insofar as the respective Company determines the purposes and means of the relevant processing:
“Teorema Bulgaria” EOOD, UIC 203352731;
“Teorema Adventures” EOOD, UIC 205222245;
“Club Teorema” EOOD, UIC 208877455.
Where two or more of the Companies jointly determine the purposes and means of a particular processing activity, they act as joint controllers within the meaning of Article 26 GDPR and allocate their respective responsibilities by means of an internal arrangement. The essence of this allocation is made available to data subjects upon request.
Services, Games and Locations
The Companies provide and administer the following entertainment services:
| Game/service | Type | Location |
|---|---|---|
| Atlantis | escape game | 11 Kraka St., Sofia |
| Trotil | escape game | 11 Kraka St., Sofia |
| The Lost Ark | escape game | 28 Damyan Gruev St., Sofia |
| Tavern Lambda | role-playing game | 28 Damyan Gruev St., Sofia |
| Party Zone | venue hire and events | 28 Damyan Gruev St., Sofia |
Controllers and Contact Details
For a specific booking, voucher or participation, the controller is the Company that provides/invoices the relevant service or on whose behalf the booking was made. Where this is not clear from the interface, booking confirmation or payment document, you may obtain information at contact@teorema.bg.
“Teorema Bulgaria” EOOD – UIC 203352731; registered office: 11 Kraka St., Sofia;
“Teorema Adventures” EOOD – UIC 205222245; registered office: 27 Ami Boué St., floor 4, apartment 12, Sofia;
“Club Teorema” EOOD – UIC 208877455; registered office: 28 Damyan Gruev St., Sofia;
General e-mail for personal data enquiries: contact@teorema.bg;
Website: teorema.bg.
Who This Policy Applies To
persons who make a booking by telephone or online;
participants in the games, including persons for whom a booking is made by another person;
purchasers, recipients and users of vouchers;
representatives and employees of corporate customers;
persons who contact the Companies by telephone, e-mail, form or another channel;
visitors to teorema.bg and users of the embedded enquiry/booking/voucher forms;
persons who have consented to marketing.
Sources and Methods of Collection
Personal data are collected directly from you or from a person making a booking/order on your behalf or for your benefit:
by telephone – during a conversation with our employee; as a rule, telephone calls are not recorded unless you have been expressly informed otherwise in advance;
through the online booking system developed and provided by “Keyhowl” OOD, UIC 208775176 (keyhowl.com) (“Keyhowl”);
through the voucher ordering and management system and through the enquiry system on teorema.bg;
through teorema.bg, including technical logs and cookies;
on site when making a booking; ordering a voucher or another good/service; submitting an enquiry; or participating in a game/event where it is necessary to sign a declaration or process data for performance of a service, responding to an enquiry, organisation of a game or event, or safety;
from a corporate customer when it organises participation by its employees, guests or representatives.
The data you provide are necessary for us to perform our pre-contractual and/or contractual obligations towards you. If a booking, enquiry or voucher request submitted by you does not contain all necessary data, we reserve the right to request the missing information or refuse to provide the service.
Categories of Personal Data
6.1. Bookings
name; e-mail; telephone number; date and time; selected game; number of participants; participants’ age; notes voluntarily provided by you; changes/cancellations; booking status; voucher information; payment status and reference, without storing full payment card details unless expressly stated otherwise.
6.2. Vouchers
purchaser’s name and contact details – telephone and e-mail; recipient details, if provided; voucher value/type; code/identifier; purchase date, validity and use; payment and accounting status; correspondence relating to the order.
6.3. Telephone and Written Communications
name; telephone; e-mail; content of the enquiry; communication history; data voluntarily provided by you.
6.4. Participation and Declarations
We process only data genuinely necessary for participation, safety and the protection of legal claims, such as name, age and contact details. We may inspect your identity document and record data from it in the event of doubts regarding the age of players or representative authority, claims for damage to the games, unacceptable conduct contrary to the General Terms and Conditions, or conduct endangering the safety of persons or property.
6.5. Video Surveillance
Real-time video and audio monitoring is carried out in the game premises for the purposes of running the game and ensuring safety. Video recordings may also be made and stored for the purpose of proving participation and asserting legal claims. Recordings are retained for up to 1 year or until the storage capacity of the recording device is full, whichever occurs first.
6.7. Photographs
With your knowledge and consent, we may photograph you before, during or after a game on the basis of Article 6(1)(a) GDPR. We may display photographs at the Companies’ premises for the purpose of promoting our services. Your photographs may also be used on teorema.bg and on social media channels such as Facebook, TripAdvisor and Instagram for the purpose of promoting our services, unless you object at the time the photograph is taken.
6.6. Technical Data
IP address; date and time; browser and device; operating system; technical identifiers; security logs; pages visited and interactions; source of the visit; cookie preferences.
Purposes and Legal Bases
| Purpose | Main data | Legal basis |
|---|---|---|
| Acceptance, confirmation, amendment and performance of a booking | contact details, game, date/time, participants – name, age, status | Article 6(1)(a) and (b) GDPR – contract/pre-contractual steps, consent |
| Sale and fulfilment of vouchers | contact details, names, voucher, payment | Article 6(1)(a) and (b) GDPR – contract/pre-contractual steps, consent |
| Payment, invoicing and accounting | identification and payment/accounting data | Article 6(1)(a), (b) and (c) GDPR – contract/pre-contractual steps, consent, compliance with legal obligations |
| Communication and customer service | contact details, names and correspondence | contract/pre-contractual steps; legitimate interest |
| Safety, prevention of abuse and protection of property | bookings, logs and, where necessary, recordings | Article 6(1)(a), (b) and (f) GDPR – contract/pre-contractual steps, consent, legitimate interest |
| Legal claims and disputes | relevant data and evidence | legitimate interest; legal obligation where applicable |
| Optional analytical/marketing cookies | online identifiers and usage data | prior consent where required |
| Direct electronic marketing | name, e-mail/telephone | consent or another expressly permitted basis under applicable law; always with an easy opt-out |
Keyhowl – Booking and Voucher System
For online bookings, enquiries and voucher functionalities, the Companies use the Keyhowl system. According to Keyhowl’s publicly available terms, the platform is a B2B service for escape room operators and the embedded booking form interacts with the Keyhowl API. For bookings, Keyhowl states that it collects at least a name, e-mail address and telephone number and shares them with the relevant operator for booking management.
For customer data processed by Keyhowl solely on the instructions of the relevant Company, Keyhowl acts as a processor under Article 28 GDPR pursuant to a data processing agreement (DPA) covering the subject matter, duration, categories of data, data subjects, instructions, confidentiality, security, subprocessors, assistance with rights/incidents, deletion/return and audits.
Where Keyhowl processes data for its own independent purposes (e.g. security of its own platform, its own B2B administration or other purposes determined independently by it), it may act as a separate controller for the relevant processing.
Keyhowl’s public policy provides for the collection of personal data supplied by customers and visitors to teorema.bg, website usage data and cookies, processing in Bulgaria and other locations, possible international transfers, GDPR rights and a cookie banner allowing acceptance/refusal of optional cookies. The public terms for players also refer to automated confirmations, reminders, surveys and possible follow-up messages. For further information, please read Keyhowl’s privacy policy at keyhowl.com/legal/privacy-policy.
Automated Messages
Confirmations, reminders, change/cancellation notices, participation instructions, payment information and other messages objectively necessary for a booking or voucher are sent as part of the performance of the service and are not treated as marketing merely because they are automated.
Satisfaction surveys, invitations to visit again, promotions, engagement campaigns and other commercial communications are configured separately. Where the law requires consent, they are not sent without prior consent and each message provides an easy mechanism to opt out/unsubscribe.
Cookies and Similar Technologies
Our website uses so-called “cookies” – small text files stored through the internet browser on the device from which you visit the website. When using the website, you can manage your cookie preferences in accordance with this Policy and the available cookie settings.
Cookies help us ensure the normal operation of the website and make it easier to use. Depending on their purpose, some cookies are deleted when the session ends, while others may remain stored on your device for a specified period or until deleted.
Cookies may, for example, enable the website to recognise the browser you use on a subsequent visit, remember certain preferences such as your selected language or other settings, and adapt certain functionalities to your choices.
Cookies may also be used to compile statistics on visits and the way users interact with the website. This information helps us analyse its use and improve its structure, content, functionality and user experience.
Cookies usually contain information such as the name or domain of the website that created them, their lifetime and a unique identifier.
Types of Cookies and Third-Party Services
Depending on the functionalities used at the relevant time, our website may use:
strictly necessary cookies required for the proper and secure operation of the website and the provision of a service requested by you;
functional cookies which may remember certain settings and preferences;
analytical cookies, including where Google Analytics is used, through which we analyse website traffic and usage;
cookies and similar technologies of third parties where external services or content are integrated into the website.
Strictly necessary cookies may be used without prior consent where permitted by applicable law. Cookies that are not necessary for the operation of the website, including analytical cookies, are activated after obtaining your prior consent where such consent is required.
Detailed information about the specific cookies used, their provider, purpose and duration may be provided through the website’s cookie settings.
Website Traffic Analysis
To better understand how visitors use the website and to improve its content and functionality, we may use Google Analytics, a website traffic analysis service provided by Google.
When Google Analytics is enabled, cookies and similar technologies may be used to collect information about website use, such as pages visited, duration and approximate time of visits, interaction with content, technical characteristics of the device and browser, and other information necessary for statistical analysis.
Information collected through Google Analytics may be processed by Google in accordance with the provider’s applicable terms and policies. Depending on the technical infrastructure and subprocessors used, certain data may also be processed outside the European Union and the European Economic Area. In such cases, the relevant mechanisms and safeguards for international transfers of personal data under applicable law are applied.
Where the law requires prior consent for the use of Google Analytics, the service is activated only after you have made the relevant choice through the cookie management mechanism.
Cookie Management and Opt-Out
On your first visit to the website, you can choose whether optional cookies may be used. You may refuse their use and subsequently change your preferences or withdraw your consent through the cookie settings available on the website.
You may also manage cookies through your internet browser settings, including restricting or blocking their storage and deleting cookies already stored.
Please note that blocking strictly necessary cookies through your browser settings may result in certain parts of the website not functioning correctly or becoming unavailable. Refusing analytical and other optional cookies should not in itself restrict access to the website’s core functionalities.
Recipients and Processors
“Keyhowl” OOD – booking system, CRM/operational management, vouchers, declarations, e-mails and automated messages;
hosting, IT support and information security providers;
payment institutions/providers – only insofar as they are used for a particular payment;
accountants, auditors, lawyers and other professional advisers;
e-mail/SMS service providers, if enabled;
competent public authorities and courts where required or permitted by law.
Data are not “sold” or disclosed to third parties without a legal basis or necessity. Each processor receives only the access necessary and is bound by contractual and statutory requirements.
International Transfers
In connection with the provision of the Companies’ services, certain personal data may be processed or stored outside the European Union (“EU”) and the European Economic Area (“EEA”).
Such transfers may arise in particular through the use of providers and their subprocessors supplying cloud and server hosting, data storage and backup, information security, e-mail, SMS and other electronic communications, technical support, booking and voucher systems, and other technology services necessary for the Companies’ activities.
In certain cases, a provider may be established in the EU/EEA but use infrastructure, affiliated companies or subprocessors located in third countries. Processing outside the EU/EEA may therefore also occur where the primary service provider is a European company.
Where personal data are transferred or otherwise made available for processing in a country outside the EU/EEA, the Companies take the necessary measures to ensure the lawfulness of the transfer in accordance with Chapter V GDPR.
Depending on the particular recipient and the country in which the data are processed, the transfer may be based on:
an adequacy decision of the European Commission;
Standard Contractual Clauses approved by the European Commission;
other appropriate safeguards provided for in the GDPR; or
another applicable legal basis for an international transfer where the conditions for its use are met.
Where necessary, the Companies or the relevant provider assess the circumstances of the transfer and apply additional contractual, technical or organisational measures to protect personal data.
The Companies require processors to ensure an appropriate level of protection and, where they use subprocessors, to apply the relevant data protection and international transfer requirements to them as well.
Retention Periods
| Category | Criterion/period |
|---|---|
| Bookings | for performance of the booking and thereafter for the period necessary for accounting, contractual and evidentiary purposes, but not less than 5 years |
| Vouchers | until expiry/use and settlement of related rights, and thereafter for the period necessary for accounting, contractual and evidentiary purposes, but not less than 5 years |
| Accounting documents | in accordance with applicable statutory periods (10 years) |
| Correspondence | until the enquiry is completed and for a reasonable period for the protection of rights (up to 5 years) |
| Marketing lists | until consent is withdrawn/an objection is made or the purpose ceases to apply; a minimal suppression record (minimal entry in a direct-marketing opt-out list) may be retained to evidence the opt-out |
| Video/audio recordings | up to 1 year or until the storage capacity of the recording device is full, whichever occurs first, unless separated for an incident/dispute |
| Technical logs | for a period appropriate to security and diagnostic purposes |
| Cookie consent records | for the period necessary to evidence and manage the choice, after which they are renewed/deleted |
Rights of Individuals
access to personal data and information about the processing;
rectification of inaccurate and completion of incomplete data;
erasure where the statutory conditions are met;
restriction of processing;
data portability where applicable;
objection to processing based on legitimate interests;
unconditional objection to direct marketing;
withdrawal of consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
lodging a complaint with the Commission for Personal Data Protection (CPDP).
Requests may be sent to contact@teorema.bg. We respond without undue delay and within 1 month of receipt, except where the GDPR permits an extension. Additional information to identify the person making the request may be required only to the extent necessary.
Children and Minors
Where minors participate in the games, the rules of the relevant game and the General Terms and Conditions on teorema.bg apply. Their data are limited to what is necessary, but in all cases include names and age. Where a specific processing activity relies on consent and the law requires the involvement of a parent/guardian/custodian, the relevant procedure for obtaining the consent of the person responsible for the minor is applied. Children are not subject to marketing profiling.
Security and Data Breaches
The Companies implement appropriate technical and organisational measures according to the risk, including access controls, individual user profiles, device protection, backups, logging, training, contractual requirements for providers and incident procedures.
In the event of a personal data breach, an assessment is carried out. Where the conditions under the GDPR are met, the CPDP is notified within 72 hours of becoming aware of the breach and the affected individuals are informed without undue delay.
Regulation (EU) 2022/2065 on Digital Services (DSA)
teorema.bg is a website for presenting and directly selling/booking the Companies’ own services. The mere provision of information and acceptance of bookings for the Companies’ own services does not automatically make the website an “online platform” within the meaning of the DSA, and Regulation (EU) 2022/2065 on Digital Services is not applicable.
Information Provided When Personal Data Are Collected
This Personal Data Policy is the general information document concerning the personal data controllers, the data collected, how they are processed and the rights of the persons to whom the data relate. At the points where data are collected, brief information and/or a link to this Policy is provided. Booking and voucher forms clearly identify mandatory fields and provide a link to this Policy. Marketing consent is not a condition for making a booking or purchase.
For telephone bookings, the employee identifies teorema.bg as the place where full information about the processing is available.
Complaint to the Supervisory Authority
If you believe that your rights have been infringed in any way, please contact us. You may also lodge a complaint with the Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria.
Amendments to the Policy
The Policy is updated when there are changes to the services, Companies, providers, technologies, legal bases or applicable legislation. The current version is published on teorema.bg together with the date of the latest update.
Contact
For questions and requests concerning personal data: contact@teorema.bg. Where the request relates to a specific booking, please provide sufficient information (for example date, game, name and the e-mail/telephone number used).