Legal

Privacy Policy

Last updated 15 June 2026

This Privacy Policy explains how Deedy Labs (https://deedylabs.com), trading as Sgovr ("Sgovr", "we", "us"), collects, uses, discloses, and safeguards information when you use the Services or visit our website. We are committed to data minimisation and to processing only what is necessary to operate the platform securely. Where we act as a "controller" of personal data, this Policy describes our practices; where we process data on behalf of a customer, we do so as a "processor" under the applicable agreement. Deedy Labs is registered in the Republic of Bulgaria and processes personal data in compliance with Regulation (EU) 2016/679 (GDPR) and applicable Bulgarian data-protection law.

1. Information we collect

We collect information you provide directly, information generated through your use of the Services, and information from third parties such as payment partners.

  • Account and contact details you provide when registering (such as name, email, organization).
  • Provider data, including Capability Specifications, declared actions, pricing, and endpoints.
  • Mandate and transaction metadata, such as scopes, spend caps, amounts, currencies, timestamps, and outcomes recorded in the audit log.
  • Payment-related identifiers needed to settle transactions (handled primarily by our payment partners; we do not store full card numbers).
  • Technical data such as IP address, device and browser characteristics, and request and diagnostic logs.
  • Communications you send to us, such as support requests.

2. How we use information

  • To provide, operate, maintain, and secure the Services.
  • To verify Mandates and credentials, enforce scopes, spend caps, rate limits, and policy, and to prevent and investigate fraud and abuse.
  • To process, reconcile, and refund settlements.
  • To produce tamper-evident audit records for integrity, dispute resolution, and compliance.
  • To communicate with you about the Services, including service, security, and policy notices.
  • To comply with legal obligations and to establish, exercise, or defend legal claims.
  • To analyze and improve the Services, using aggregated or de-identified data where practicable.

3. Legal bases for processing

Where data-protection law such as the EU/UK GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Services you request); our legitimate interests (to operate, secure, and improve the Services and prevent abuse), balanced against your rights; compliance with legal obligations (such as accounting and anti-fraud rules); and consent where required (for example, certain non-essential cookies), which you may withdraw at any time.

4. Sharing and disclosure

We share personal data only as needed to operate the Services and as described here:

  • Service providers and processors (such as cloud hosting, payment partners, and analytics) acting on our instructions under appropriate contracts.
  • Providers and Principals, to the extent necessary to complete a discovery, action, or settlement they initiate.
  • Legal and safety recipients, where disclosure is required by law or reasonably necessary to protect rights, safety, or the integrity of the Services.
  • Successors, in connection with a merger, acquisition, or sale of assets, subject to this Policy.

We do not sell personal data, and we do not share it for cross-context behavioral advertising.

5. International transfers

We may process and store information in countries other than your own. Where we transfer personal data across borders, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms required by applicable law.

6. Data retention

We retain personal data for as long as necessary to provide the Services and to meet legal, accounting, audit, and dispute-resolution obligations, after which it is deleted or de-identified. Financial and settlement records are retained for seven (7) years in accordance with Bulgarian accounting law. Audit records are stored in append-only, tamper-evident storage and retained for the same period. Operational and diagnostic logs are retained for up to twelve (12) months unless a longer retention is required by law or an active investigation.

7. Your rights

Subject to applicable law, you may have the right to access, correct, delete, or port your personal data; to object to or restrict certain processing; and to withdraw consent. Where the GDPR applies, you also have the right to lodge a complaint with your local supervisory authority. To exercise your rights, contact us using the details below; we may need to verify your identity before responding.

8. Security

We use technical and organizational measures designed to protect personal data, including scoped, short-lived credentials, encryption in transit, access controls, and append-only, verifiable audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Children's privacy

The Services are not directed to children and are not intended for use by anyone under the age of majority in their jurisdiction. We do not knowingly collect personal data from children.

10. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified through the Services or by other reasonable means, and the date below reflects the latest revision.

11. Contact

Privacy questions and data-subject requests can be sent to privacy@sgovr.eu or through the contact form at https://deedylabs.com. The data controller is Deedy Labs, registered in the Republic of Bulgaria. As an EU-registered entity, no separate EU representative is required. If you are not satisfied with our response, you have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP) at cpdp.bg, or with the supervisory authority in your country of residence.