Mashkov logo
SIGN IN

Legal · GDPR

Privacy Policy & Personal Data Protection

Last updated: August 2026

This Policy governs the way in which "Polimed AI" EOOD, acting as Data Controller (hereinafter “the Controller”, “we” or “us”), collects, uses, stores and protects the personal data of users and business partners on the platform mashkov.app.

1. Controller details

  • Company name: "Polimed AI" EOOD
  • UIC / BULSTAT: 206251634
  • VAT No.: BG206251634
  • Registered office and management address: 36 Paisiy Hilendarski St., Madan, Bulgaria
  • Email for GDPR inquiries: mehmed.mashkov@gmail.com
  • Contact phone: +359 876 600 667
  • Manager: Mehmed Mashkov

2. Processing matrix (purposes, legal bases and retention periods)

Personal data processing matrix on mashkov.app
PurposeData categoriesLegal basisRetentionRecipients
Registration and profileName, email, hashed passwordArt. 6(1)(b) (Contract)Until account deletionSupabase, AWS
Wardrobe digitization (AI)Uploaded photos of clothingArt. 6(1)(b) (Contract)Until deleted by the userBackground-removal AI software
B2B brand dataRepresentative, company ID, paymentsArt. 6(1)(c) (Legal obligation)10 years (Accounting Act)NRA, Accounting, Stripe
Marketing and newsletterEmail addressArt. 6(1)(a) (Separate consent)Until consent is withdrawnEmail service providers

3. Specific processing of images and algorithms (AI)

  • 3.1. Background removal: Photos of clothing uploaded by the User are processed automatically by AI algorithms solely to cut out the background and categorize the item in the personal digital wardrobe.
  • 3.2. Protection of likeness and biometrics: Images are NOT used for biometric identification of individuals. If the User's face appears in an uploaded photo, the AI algorithm cuts out only the garment, and the original photo is not shared publicly.
  • 3.3. Copyright on photos: The User retains the rights to their uploaded photos but grants the Controller a non-exclusive license for their technical processing within the functionalities of mashkov.app.

4. Recipients and transfers of data

Personal data is processed by the following categories of recipients:

  1. Software and hosting providers: Supabase, AWS, Google Cloud, Lovable – providing database and AI infrastructure.
  2. Payment processors: Stripe Payments Europe Ltd. – for processing B2B subscriptions.
  3. International transfers: Where data is processed outside the EEA (e.g. in the USA), the transfer is carried out under the EU-U.S. Data Privacy Framework or Standard Contractual Clauses (SCCs).

5. Your rights under GDPR

You have the right to:

  1. Access, rectification and erasure (“right to be forgotten”) of your personal data and uploaded photos.
  2. Restriction and objection to the processing.
  3. Withdrawal of consent for marketing communications at any time.
  4. Portability of the data from your digital wardrobe.

Procedure for exercising rights: Send a written request to: mehmed.mashkov@gmail.com. Response time: up to 1 (one) month.

6. Right to complain and judicial protection

  • Complaint to the CPDP: If you suspect a violation, you have the right to file a complaint with the Commission for Personal Data Protection (2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, www.cpdp.bg) within 6 months of becoming aware, but no later than 2 years of the violation.
  • Judicial protection: You have the right to appeal the Controller's actions under the Administrative Procedure Code before the court and to claim compensation for damages suffered.