Privacy Policy
This policy explains how personal data is processed through the StitchOne website, trial environment, support channels, and developing ERP service.
Effective date: 20 August 2026
Controller identity
Nikolay Petrov, operating the pre-incorporation StitchOne project, is the controller for personal data collected through this website, contact forms, partner-program applications, and direct business correspondence.
Controller address: Bulgaria, Sofia, ul. Lerin 24A, appt. 10. Privacy contact: privacy@stitchone.eu.
StitchOne is currently a project and trade name, not an incorporated legal entity.
Scope and business audience
The website and service are intended for business users and adults acting in a professional capacity.
The policy covers website visitors, contacts, demo applicants, partner-program applicants, trial users, customer representatives, support contacts, and authorized ERP users.
Personal data we may process
- Identity and contact data, including name, business email, telephone number, company, role, and country.
- Inquiry, demo, support, and partner-application content.
- Account data, user roles, access permissions, authentication and security records.
- Customer-provided ERP content, including production, employee, order, material, warehouse, OCR, and barcode-related data.
- Images submitted for OCR processing and the structured values extracted from them.
- AI-assistant prompts, responses, and relevant business context where the feature is used.
- Technical information such as IP address, browser, device, request time, language, security events, and application logs.
- Consent choices and permitted analytics or advertising identifiers.
Purposes and legal bases
- Responding to inquiries and taking requested pre-contractual steps — Art. 6(1)(b) GDPR.
- Providing and securing trial accounts and requested ERP functionality — Art. 6(1)(b) GDPR.
- Preventing fraud, spam, unauthorized access, and service abuse — legitimate interests under Art. 6(1)(f) GDPR.
- Operating, troubleshooting, and improving the service — legitimate interests under Art. 6(1)(f) GDPR.
- Complying with accounting, tax, court, and regulatory obligations — Art. 6(1)(c) GDPR.
- Analytics and advertising measurement — consent under Art. 6(1)(a) GDPR where required.
- Direct business communication may rely on consent or legitimate interests, depending on the context and applicable law.
Customer data and processor role
For personal data entered into the ERP by a business customer, the customer normally determines the purposes and means of processing and acts as controller. The StitchOne operator normally acts as processor.
Customers must have a lawful basis for the data they upload, configure suitable user permissions, provide required notices to their personnel, and avoid uploading unnecessary sensitive data.
Where required, the processing relationship will be governed by a separate Data Processing Agreement before production use.
Service providers and website technologies
- Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg provides application hosting, database infrastructure, storage, backups, email delivery, OCR processing, AI processing, and logging infrastructure in eu-central-1, Frankfurt, Germany.
- Google Analytics is loaded only after Analytics or Marketing consent.
- Google Ads measurement is loaded only after Marketing consent.
- Google reCAPTCHA is used on contact forms to prevent spam and abuse. Google may receive IP address, browser, device, and interaction data when reCAPTCHA is loaded.
- Essential cookies include the consent preference and language preference. Optional campaign parameters are stored only after Analytics or Marketing consent.
- Google services are subject to Google's privacy terms: https://policies.google.com/privacy.
Gumlet video delivery
Gumlet is used only to deliver and play public training and demonstration videos.
No customer ERP records, production documents, OCR uploads, or customer-provided personal data are intentionally uploaded to Gumlet.
The Gumlet player is loaded only after the visitor chooses to load a video. At that point Gumlet may receive technical visitor data such as IP address, browser information, request time, video identifier, and referrer.
Gumlet's privacy information is available at https://www.gumlet.com/privacy-policy/.
Data location, transfers, and retention
Primary application data, backups, OCR processing, AI processing, and logs are configured in AWS eu-central-1, Frankfurt, Germany.
Google and Gumlet may process technical visitor information outside Bulgaria or the EEA under their own contractual safeguards. Where required, providers rely on adequacy decisions, Standard Contractual Clauses, or other lawful transfer mechanisms.
- Contact inquiries: up to 24 months.
- Partner-program applications: up to 24 months.
- Support correspondence: up to 36 months.
- Security and application logs: up to 12 months, unless an incident requires longer retention.
- Trial data: normally deleted or anonymized within 30 days after final expiry or termination.
- Deleted data may remain in protected backups for up to 90 additional days.
- Analytics event data should be configured for a maximum of 14 months.
- Data may be retained longer where required for legal obligations, disputes, fraud prevention, or establishment of legal claims.
Security measures
- TLS encryption for data in transit.
- Role-based access controls and least-privilege principles.
- Tenant and user authorization controls.
- Application and security logging.
- Backups stored in the Frankfurt AWS region.
- Administrative and technical measures intended to protect confidentiality, integrity, and availability.
Your data-protection rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability, or object to processing. Where processing is based on consent, consent may be withdrawn at any time without affecting earlier lawful processing.
Requests should be sent to privacy@stitchone.eu. Identity verification may be required before a request is completed.
You may also complain to the Bulgarian Commission for Personal Data Protection: https://www.cpdp.bg/.
Changes and future incorporation
This policy may be updated when the service, providers, or legal structure changes.
If a company is incorporated and becomes the website operator, supplier, controller, or processor, the legal documents will be updated and affected users will be informed where required.
Until such an update takes effect, Nikolay Petrov remains the identified operator and website controller.
Privacy contact
Privacy requests and questions may be sent to privacy@stitchone.eu.
Privacy request
Contact the controller to exercise a data-protection right or ask a privacy question.
Send privacy request