Legal · GDPR
Privacy Policy & Personal Data Protection
Last updated: August 2026
This Policy governs the way in which "Polimed AI" EOOD, acting as Data Controller (hereinafter “the Controller”, “we” or “us”), collects, uses, stores and protects the personal data of users and business partners on the platform mashkov.app.
1. Controller details
- Company name: "Polimed AI" EOOD
- UIC / BULSTAT: 206251634
- VAT No.: BG206251634
- Registered office and management address: 36 Paisiy Hilendarski St., Madan, Bulgaria
- Email for GDPR inquiries: mehmed.mashkov@gmail.com
- Contact phone: +359 876 600 667
- Manager: Mehmed Mashkov
2. Processing matrix (purposes, legal bases and retention periods)
| Purpose | Data categories | Legal basis | Retention | Recipients |
|---|---|---|---|---|
| Registration and profile | Name, email, hashed password | Art. 6(1)(b) (Contract) | Until account deletion | Supabase, AWS |
| Wardrobe digitization (AI) | Uploaded photos of clothing | Art. 6(1)(b) (Contract) | Until deleted by the user | Background-removal AI software |
| B2B brand data | Representative, company ID, payments | Art. 6(1)(c) (Legal obligation) | 10 years (Accounting Act) | NRA, Accounting, Stripe |
| Marketing and newsletter | Email address | Art. 6(1)(a) (Separate consent) | Until consent is withdrawn | Email service providers |
3. Specific processing of images and algorithms (AI)
- 3.1. Background removal: Photos of clothing uploaded by the User are processed automatically by AI algorithms solely to cut out the background and categorize the item in the personal digital wardrobe.
- 3.2. Protection of likeness and biometrics: Images are NOT used for biometric identification of individuals. If the User's face appears in an uploaded photo, the AI algorithm cuts out only the garment, and the original photo is not shared publicly.
- 3.3. Copyright on photos: The User retains the rights to their uploaded photos but grants the Controller a non-exclusive license for their technical processing within the functionalities of mashkov.app.
4. Recipients and transfers of data
Personal data is processed by the following categories of recipients:
- Software and hosting providers: Supabase, AWS, Google Cloud, Lovable – providing database and AI infrastructure.
- Payment processors: Stripe Payments Europe Ltd. – for processing B2B subscriptions.
- International transfers: Where data is processed outside the EEA (e.g. in the USA), the transfer is carried out under the EU-U.S. Data Privacy Framework or Standard Contractual Clauses (SCCs).
5. Your rights under GDPR
You have the right to:
- Access, rectification and erasure (“right to be forgotten”) of your personal data and uploaded photos.
- Restriction and objection to the processing.
- Withdrawal of consent for marketing communications at any time.
- Portability of the data from your digital wardrobe.
Procedure for exercising rights: Send a written request to: mehmed.mashkov@gmail.com. Response time: up to 1 (one) month.
6. Right to complain and judicial protection
- Complaint to the CPDP: If you suspect a violation, you have the right to file a complaint with the Commission for Personal Data Protection (2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, www.cpdp.bg) within 6 months of becoming aware, but no later than 2 years of the violation.
- Judicial protection: You have the right to appeal the Controller's actions under the Administrative Procedure Code before the court and to claim compensation for damages suffered.
