Skip to content

Legal & Compliance

Last updated: July 2026

Overview

Vancore Systems operates as a boutique business analysis and development consultancy. We process personal data solely to deliver our services — bookings, document workflows, AI-assisted reporting, and client portal access. We do not sell data. We do not use data for advertising. We do not share data with unauthorized third parties.

Data Protection

We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Bulgarian law.

Lawful basis for processing

  • Contract performance: bookings, client communications, invoicing, and service delivery.
  • Legitimate interest: operational analytics, security logging, and service improvement.
  • Consent: optional marketing communications, non-essential cookies. Consent can be withdrawn at any time.

Data minimization

We collect only the personal data strictly necessary to perform the requested service. Account, booking, and document data are limited to operational fields required for delivery.

Retention periods

  • Account data: retained for 12 months after last activity, then eligible for deletion.
  • Booking data: retained for 36 months, unless a longer statutory period applies.
  • Document metadata and audit logs: retained for 24 months.
  • Support tickets / chat logs: retained for 12 months.

Your rights

You may request access, correction, restriction, portability, or deletion of your personal data. To exercise any of these rights, email hello@vancoresys.com or use the contact form on our Contact page.

Data Processing

We work with processors that support our ability to deliver the Service securely and reliably. All listed processors operate under data processing terms consistent with GDPR Article 28.

Processors

  • Supabase — authentication and database services, EU region.
  • Vercel — frontend hosting and edge delivery.
  • DigitalOcean — backend API hosting and file storage, Frankfurt region.

We maintain Data Processing Agreements with these providers where available. Subprocessor lists are reviewed periodically.

Data residency

Primary data processing is performed within the EU. Authentication and database operations are hosted in the EU region; backend storage is hosted in Frankfurt.

Security

We design and operate our systems using established security practices. No method of transmission or storage is 100% secure, but we apply layered controls to reduce risk.

  • Encryption in transit: All external connections use TLS 1.2 or higher.
  • Authentication: JWT-based authentication for API and portal access. Optional role-based access control for team environments.
  • Access control: Scoped access for authenticated users; administrative actions require authorization.
  • Audit logging: Administrative actions, booking changes, and document interactions are logged with timestamp, actor, and action type.
  • Backup and recovery: System backups are stored according to retention settings. Backup integrity is verified periodically to support restoration where feasible.
  • Security headers: The site uses security headers including HSTS, CSP, and X-Frame-Options where applicable by deployment layer.

Cookies

We use cookies and similar technologies to operate the Service, remember authentication, support analytics, and deliver technical functionality. Marketing cookies are only used with explicit consent. For details, see our Cookie Policy.

Children’s Privacy

The Service is not directed to individuals under 16. We do not knowingly collect personal data from children under 16.

Changes to This Page

We may update this Legal & Compliance page when our practices, processors, or technical controls change. Updated content will be reflected by the “Last updated” date.

Contact

For legal, privacy, or compliance questions, contact us at hello@vancoresys.com or via our Contact page.