← Back to homepage

Privacy policy

Updated: 2026-10-08

Provider and data controller

FuguLabs is operated by Padialle LTD (ПАДИАЛЛЕ ЕООД), UIC 204120110. Registered contact address: 16 Bratya Miladinovi St., floor 2, office 3, Sofia 1301, Bulgaria. Contact: +359 879 334 732, +49 151 401 96 204, or the customer portal chat.

Data we process

We process account email, a salted password hash (not the plain password), profile name and phone; company and billing details; inquiries, orders, messages, uploaded documents, receipt/approval history and checklist activity; payment and invoice references and statuses; and technical security information necessary to operate the service. Do not upload unnecessary identity documents, health data or other sensitive information. Card details are entered on Stripe, not stored by FuguLabs.

Purposes and legal bases

Account, project and support processing is necessary to take steps at your request and perform the contract (GDPR Article 6(1)(b)). Billing records are processed to meet applicable legal duties (6(1)(c)). Security, misuse prevention and establishing or defending legal claims rely on legitimate interests (6(1)(f)), subject to your rights. Optional Google Maps loading uses consent (6(1)(a)); you may withdraw it in cookie settings. Accepting terms is not blanket consent for marketing or unrelated processing. We do not send marketing newsletters from this portal or make automated decisions with legal or similarly significant effects.

Recipients, hosting and transfers

Authorised staff receive access according to their role. The application and documents are hosted on our OVHcloud VPS in Germany. Stripe processes payments and may act as an independent controller for its own purposes. Google receives your IP and browser information only when you allow the embedded map or open its external link. WhatsApp and Telegram operate their own services when you follow their links. These providers may process data outside the EEA; their privacy notices describe their processing and transfer safeguards. We do not sell your personal data.

Retention and security

The login session expires after seven days. Profile, project and conversation records are retained while needed for the customer relationship, delivery, support, applicable accounting duties or legal claims. Retention is assessed by record type and applicable law; a deletion request does not erase records we must legally retain. Access uses HTTPS, password hashing and role/ownership checks. Keep credentials private. Uploaded files are private downloads; files are not automatically scanned for malware, so recipients should scan them before opening.

Your rights and requests

You may request access, correction, erasure, restriction, portability where applicable, object to legitimate-interest processing, and withdraw consent without affecting earlier lawful processing. The Profile section offers a data export and privacy-request form; you can also contact us by phone or post. We may need proportionate identity verification. We normally respond within one month; a lawful extension will be explained. You may complain to the Bulgarian Commission for Personal Data Protection (cpdp.bg) or your local EEA supervisory authority. Providing account/billing data is necessary for those services; without it we cannot provide the relevant account or invoice.

FuguLabs Portal · Stripe Privacy · Google Privacy · CPDP