Privacy Policy

FoodBase (foodbase.dev) — Effective date: 7 July 2026 · Last updated: 7 July 2026

1. Controller

The controller of your personal data within the meaning of Regulation (EU) 2016/679 (“GDPR”) is Datalog Ltd. (Даталог ЕООД), UIC (ЕИК) 208878176, registered office: ul. Shar Planina 8, Fl. 5, 2700 Blagoevgrad, Bulgaria. Contact: [email protected] or the contact form at https://foodbase.dev/contact.

This Policy explains what personal data we process when you visit foodbase.dev, create an account, subscribe to a paid plan or use the FoodBase API, and what your rights are. We have not appointed a Data Protection Officer, as we are not required to; privacy enquiries should be sent to the contact above.

2. What data we process

  • Account data: email address, name (if provided), hashed password, account settings, plan type.
  • Billing data: subscription history, invoices, billing name and address, VAT number (if provided), and the last four digits and brand of your card. Full payment card details are collected and processed directly by our payment provider, Stripe — we never receive or store your full card number.
  • API and usage data: API keys, request logs (endpoint, timestamp, response status, request volume), IP addresses, user-agent and similar technical data, used for authentication, rate limiting, security, billing and service analytics.
  • Website data: server logs (IP address, browser, pages visited) and cookies as described in our Cookie Policy.
  • Communications: the content of your messages when you contact support or use our contact form.

We do not knowingly process special categories of personal data and do not direct the Service at children. Note that the food products in our database are not personal data.

3. Purposes and legal bases

  • Providing the Service (account management, API access, support) — performance of a contract (Art. 6(1)(b) GDPR).
  • Billing and invoicing — performance of a contract and compliance with legal obligations, including Bulgarian accounting and tax law (Art. 6(1)(b) and (c) GDPR).
  • Security, abuse prevention and rate limiting — our legitimate interest in protecting the Service (Art. 6(1)(f) GDPR).
  • Service analytics and improvement — our legitimate interest in understanding aggregate usage and improving the Service (Art. 6(1)(f) GDPR).
  • Service emails (e.g. billing notices, quota alerts, changes to terms) — performance of a contract. Marketing emails, if any, are sent only with your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time via the unsubscribe link.
  • Non-essential cookies/analytics — your consent (Art. 6(1)(a) GDPR); see the Cookie Policy.

4. Recipients of data

We share personal data only with service providers (processors) that help us operate the Service, under data processing agreements, and with authorities where legally required. Our main providers are:

  • Stripe — payment processing (Stripe also acts as an independent controller for certain fraud-prevention and regulatory purposes; see Stripe’s privacy policy).
  • Cloudflare — content delivery network (CDN), DNS, security/DDoS protection and privacy-first, cookieless web analytics; Cloudflare processes visitor IP addresses and technical request data to deliver and protect the website.
  • Hosting and infrastructure providers — hosting of the website, API and databases.
  • Email delivery providers — sending transactional emails.

We do not sell personal data and do not share it with third parties for their own advertising. If Datalog Ltd. is involved in a merger, acquisition, reorganisation or sale of all or part of its business or assets, personal data may be transferred to the successor or acquiring entity as part of that transaction, subject to the same protections; where required, we will notify you of such a transfer.

5. International transfers

Where our providers process data outside the European Economic Area (for example, Stripe entities in the United States), transfers are protected by appropriate safeguards under Chapter V GDPR, such as the European Commission’s adequacy decision for the EU–US Data Privacy Framework or Standard Contractual Clauses. You may contact us for further information about the safeguards applied.

6. Retention

  • Account and usage data: for the duration of your account and up to 12 months after closure, unless a longer period is needed for security or legal claims.
  • API request logs: retained for up to 12 months, unless a longer retention period is necessary for fraud prevention, the investigation of security incidents, or compliance with legal obligations; identifiable data is kept only as long as needed for billing, security and abuse prevention.
  • Billing and invoicing records: as required by Bulgarian accounting and tax legislation (generally up to 10 years).
  • Support correspondence: up to 24 months after resolution.

7. Your rights

Under the GDPR you have the right to:

  • access your personal data and receive a copy of it;
  • rectify inaccurate or incomplete data;
  • erasure (“right to be forgotten”), where the conditions of Art. 17 GDPR are met;
  • restriction of processing;
  • data portability of data you provided to us, in a structured, commonly used, machine-readable format;
  • object to processing based on legitimate interests, and to object at any time to direct marketing;
  • withdraw consent at any time, without affecting the lawfulness of prior processing.

To exercise your rights, contact us at [email protected]. We will respond within one month. You also have the right to lodge a complaint with a supervisory authority — in Bulgaria, the Commission for Personal Data Protection (Комисия за защита на личните данни), 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, www.cpdp.bg — or with the authority in your EU member state of residence.

8. Security

We apply appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS), hashed passwords, access controls and logging. No system is completely secure; if a personal data breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority and, where required, affected users in accordance with Articles 33–34 GDPR.

9. Automated decision-making

We do not carry out automated decision-making producing legal or similarly significant effects for you. Automated rate limiting and fraud screening by our payment provider are technical measures necessary for operating and securing the Service.

10. Changes to this Policy

We may update this Policy from time to time. The current version is always available at foodbase.dev, with the “Last updated” date above. For material changes we will notify registered users by email or dashboard notification.