Version 26 August 2026

Professional contacts from public sources

This notice supplements the Privacy Policy when GDA TRUST Ltd., 11 Cherni vrah Blvd, 1421 Sofia, Bulgaria, VAT BG206736228, obtains a professional contact from a public source rather than directly from the individual.

1. Data and sources

Professional name, role, organisation, business email, country, source URL and collection date may be recorded. Sources may include company websites, professional registers and relevant public pages. Online availability does not constitute consent to marketing.

2. Purpose and legal basis

Data may be used to assess and initiate a relevant B2B contact on the basis of legitimate interests, only after a documented assessment of necessity, proportionality and reasonable expectations. Electronic promotional communications are sent only where permitted by applicable law, with consent where required or in full compliance with existing-customer exceptions.

3. Information provided to the individual

The information required by Article 14 GDPR, including the controller, source, categories, purposes, legal basis, retention, recipients and rights, is provided at first contact and no later than one month after collection, unless a documented legal exception applies.

4. Retention

Unqualified contacts are erased or anonymised within 90 days. Relevant contacts are reviewed at least every 12 months and erased after 24 months of inactivity, unless a contract, active negotiation or legal obligation requires longer retention.

5. Objection and suppression list

Marketing objections are applied immediately and without requiring a reason. The contact is removed from the active CRM; a separate cryptographic fingerprint may be retained solely to prevent accidental future contact.

6. Rights and contact

Individuals may exercise the rights described in the Privacy Policy by writing to marketing@gda-trust.com and may lodge a complaint with the competent supervisory authority.

7. CRM controls

The CRM blocks promotional exports by default where permission is unknown, a public source has not been verified or an objection is recorded. Passwords, API keys, feed payloads and irrelevant data must not be stored in the CRM.