OMÀYA / LEGAL
Privacy Policy
Effective from 16 September 2026.
1. Controller
The controller of personal data processed through https://omaya-sleep.com/ (the “Website”) is “MAKIYAVELI EM 24” EOOD, Unified Identification Code 208144245, (“OMÀYA”, “we”).
For questions and rights requests, email hello@omaya-sleep.com or use the contact form. We have not appointed a data protection officer because, to our assessment, mandatory appointment criteria do not apply. This Policy provides information under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”).
2. Who and what this Policy covers
This Policy applies to visitors, registered users, customers, parcel recipients, people contacting us, newsletter subscribers and people exercising withdrawal or complaint rights. It does not govern independent processing by an external website reached through a link.
3. Principles
We process data lawfully, fairly and transparently; for specified purposes; in the amount necessary; with measures supporting accuracy, storage limitation, integrity and confidentiality. We do not rely on consent where processing is objectively necessary for a contract or legal obligation.
4. Categories of data
- Account: name, email, phone, cryptographically protected password, language, marketing choice, order history, saved delivery details and settings;
- Order and delivery: name, email, phone, ordered items, size, price, discount, payment method, status, order reference, city, postal code, address or selected Speedy office/locker, and delivery note;
- Payment and refunds: cash-on-delivery information, amounts paid and refunded and, only where necessary and voluntarily supplied, IBAN/account-holder name for a bank refund. We do not collect payment-card details for cash on delivery;
- Support: enquiries, correspondence, purchase evidence, photographs and return or complaint documents;
- Newsletter and marketing: email, supplied name, language, subscription date and source, status, unsubscribe date and message delivery information;
- Technical data: IP address, date and time, URL, referrer, device type, browser, operating system, session identifiers, security and error logs;
- Reviews: display name, optional city, rating, review title and text, the size or colour purchased, and an irreversibly hashed email used only to verify the purchase and prevent duplicate reviews;
- Statistics (Umami): pages and products viewed, searches, cart and checkout actions, where the visit came from (e.g. an ad campaign), language, device type, browser, operating system, country and page loading speed. Umami sets no cookies, does not keep your IP address and never receives your email, phone, address, password, messages or names;
- Advertising data (Meta): only if you accept marketing cookies — the data described in section 5.9 and in the Cookie Policy.
We do not seek special-category data under Article 9 GDPR. Please do not send health or other sensitive data unless strictly necessary for a specific request and supported by a lawful basis.
5. Purposes and legal bases
5.1. Orders, delivery, payment, returns and complaints
We process data to take requested steps and perform the contract: create and confirm an order, check stock, arrange Speedy delivery, communicate status, accept payment, and handle withdrawal, return, exchange or complaint. Basis: Article 6(1)(b) GDPR. Fields marked as required to complete an order are required for the contract; without them the order or delivery cannot be completed.
5.2. Accounting, tax and consumer-law duties
We retain sales and payment records, maintain the complaint register, respond to valid requests and comply with supervisory authorities. Basis: Article 6(1)(c) GDPR and applicable accounting, tax and consumer law.
5.3. Account and order history
We create and maintain an account, authenticate access, show order history and save delivery details. Basis: contract or pre-contractual steps under Article 6(1)(b) GDPR. An account is voluntary where ordering without an account is available.
5.4. Enquiries and customer service
We process contact-form and correspondence data to respond, resolve an issue and maintain case history. Basis: Article 6(1)(b) GDPR for contract-related requests and our legitimate interest in customer service and proving communications under Article 6(1)(f) otherwise.
5.5. Security, fraud prevention and legal claims
We use technical logs and order data to protect accounts and the Website, detect abuse, maintain stock integrity, establish or defend rights, and demonstrate performance. Basis: legitimate interests under Article 6(1)(f) GDPR and legal obligation where applicable. We assess necessity and effects on individual rights.
5.6. Newsletter and direct marketing
We send news, campaigns and personalised commercial messages following an express subscription action or another basis permitted by law. Basis: consent under Article 6(1)(a) GDPR or, where the law permits similar-product messages to an existing customer, our legitimate interest with a clear, free opportunity to object when details are collected and in every message. Unsubscribe through the link in each marketing email or contact us. Withdrawal does not affect prior lawful processing.
5.7. Product reviews
After checking them, we publish product reviews with the display name and city you provide, so other visitors can read genuine experience. We compare your email with the email of collected orders to mark a verified purchase, and keep only its irreversibly hashed form, which prevents duplicate reviews. Basis: Article 6(1)(b) GDPR for a review following a purchase and our legitimate interest under Article 6(1)(f) in the integrity of published content. You may ask for your review to be corrected or removed.
5.8. Analytics and Website improvement
We count visits and actions in the store (pages and products viewed, cart, checkout) with Umami, without cookies and without keeping your IP address, for statistics, diagnosis and improvements to navigation, catalogue and the order process. Legal basis: legitimate interest under Article 6(1)(f) GDPR.
5.9. Advertising on Meta
Only if you accept marketing cookies do we use the Meta Pixel and Conversions API to measure and target our ads on Facebook and Instagram. When you order, Meta receives the order value and products, your IP address and browser, and your email, phone, name, city and postcode in hashed form. Legal basis: consent under Article 6(1)(a) GDPR, which you can withdraw from “Cookie settings”. Details are in the Cookie Policy. We do not make solely automated decisions producing legal or similarly significant effects.
6. Sources
We receive data mainly from you. Technical data is generated when the Website is used. We may receive delivery or payment status from Speedy and other fulfilment participants, and information from public authorities where required by law.
7. Recipients
Where necessary, we share the minimum required data with:
- Speedy for quoting, creating, tracking and delivering parcels and processing cash on delivery;
- hosting, cloud infrastructure, media storage, maintenance, cybersecurity and backup providers;
- email and communications providers;
- a statistics provider (Umami) — without cookies or IP addresses;
- Meta Platforms Ireland Ltd. — only with consent to marketing cookies;
- banks or payment providers where a refund is made or a relevant method is enabled;
- accountants, auditors, lawyers and professional advisers under confidentiality duties;
- courts, the Bulgarian Consumer Protection Commission, data-protection authority, revenue authority, police and other competent authorities where a valid legal basis exists.
We do not sell personal data. A processor acts under contract and documented instructions unless legally acting as an independent controller.
8. Transfers outside the EEA
We aim to keep primary processing in the European Economic Area. Some technical or communication providers may process data outside the EEA — for example Meta Platforms, Inc. in the United States, with consent to marketing cookies, under the EU–US Data Privacy Framework. We then use an applicable Chapter V GDPR mechanism: an adequacy decision, standard contractual clauses with supplementary measures, or another valid safeguard. Information on the relevant mechanism can be requested from us.
9. Retention
- Orders and contracts: for performance and applicable limitation periods, usually up to 5 years, unless a dispute requires longer retention;
- Accounting and tax records: for mandatory statutory periods, which may reach 10 years for relevant records;
- Complaints and returns: until the case is closed and applicable claim and supervisory periods expire;
- Account: while active and, after a deletion request, only where data must remain for orders, security, legal duties or claims;
- Non-contract enquiries: normally up to 2 years after closure unless required for a dispute;
- Marketing: until consent is withdrawn or an objection is made; a minimal preference/suppression record may remain up to 5 years to demonstrate compliance and prevent further messages;
- Technical logs: for the shortest period compatible with security and diagnosis, normally up to 12 months unless an incident occurs;
- Reviews: while the review is published and until the applicable claim periods end, after which the hashed email is deleted;
- Statistics: aggregated data without identifiers, for as long as it serves statistics; Meta cookies: up to 90 days, and data sent to Meta under Meta’s terms.
After expiry, data is deleted, anonymised or access-restricted unless law requires otherwise.
10. Security
We apply appropriate technical and organisational measures, including encrypted HTTPS transport, password hashing, access controls, request-forgery protection, validation and rate limiting, backups, logging and least-privilege access. No system is absolutely secure; where a personal-data breach occurs, we perform the applicable assessment and notification.
11. Your rights
Subject to GDPR conditions, you have rights:
- to information, access and a copy;
- to rectify inaccurate and complete incomplete data;
- to erasure where no overriding lawful basis requires retention;
- to restriction;
- to portability of data supplied by you where automated processing is based on consent or contract;
- to object to legitimate-interest processing; an objection to direct marketing is unconditional;
- to withdraw consent at any time;
- not to be subject to a solely automated decision under Article 22 GDPR;
- to complain to a supervisory authority.
Send a request using the contact in section 1. We may request additional information only to verify identity and protect data. We respond without undue delay and normally within one month. For complex or numerous requests, this may be extended by two months with notice. Requests are normally free unless manifestly unfounded or excessive and repetitive.
12. Complaint to the supervisory authority
You may complain to the Bulgarian Commission for Personal Data Protection: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria, https://cpdp.bg/, without limiting judicial remedies. We encourage you to contact us first so we can try to resolve the matter.
13. Children
The Website is not directed to children and we do not knowingly collect a child’s data without valid parental or guardian involvement. Notify us if you believe such data was supplied unlawfully.
14. Changes
We update this Policy when processing or law changes. Material changes will be communicated appropriately. The date at the top identifies the current version.
