Privacy Policy
Effective from
This policy explains what personal data is processed when you use the obc-ruse.org website and when you make a donation, for what purpose and on what legal basis, and sets out your rights under Regulation (EU) 2016/679 (GDPR).
1. Data controller
United Church of God – 1 – Ruse (Обединена Божия Църква – 1 – Русе), UIC 117079284, registered office: 8 Aksakov St, 7012 Ruse, Bulgaria. Contact for data protection matters: [email protected].
2. Data when visiting the site
The site requires no registration and uses no analytics or advertising tools. The site’s server keeps no record of visits. To protect against abuse, the visitor’s IP address is processed automatically and briefly, solely to limit the number of requests, without being recorded or stored.
3. Cookies and local storage
- The site sets no tracking, analytics or advertising cookies; consent for cookies is therefore not required.
- Our network security provider, Cloudflare, may set a technical cookie (e.g. “__cf_bm”) to distinguish visitors from automated requests. It is strictly necessary for the security of the site and is kept for up to 30 minutes.
- Your choice of light or dark theme is stored only in your browser (local storage) and is not transmitted to us.
- The payment page is provided by Stripe on the stripe.com domain, where Stripe’s cookie rules apply.
4. Donations
Card donations. Payment is made entirely through the Stripe platform (Stripe Payments Europe, Ltd., Ireland). Card details are entered directly with Stripe and are not received, processed or stored by us. Through its Stripe account the church receives the amount, the date of the donation, and the name and email address you provided.
Bank transfer. For a bank transfer, we receive the payer’s name, the amount and the payment reference from our bank.
Because the gift is to a church, it may hint at your religious belief. Information about donations therefore stays within the church and is not shared with anyone outside it (Art. 9(2)(d) GDPR).
5. Purposes and legal bases
- Processing the donation and issuing a receipt — performing the action you requested (Art. 6(1)(b) GDPR).
- Accounting for donations received — compliance with a legal obligation (Art. 6(1)(c) GDPR).
- Protecting the site against abuse — legitimate interest (Art. 6(1)(f) GDPR).
6. Recipients and transfers outside the EU
Data may be processed by the following providers, each within its own service:
- Cloudflare — delivery and network security of the site (Cloudflare’s policy).
- Stripe — card payment processing (Stripe’s policy).
Where data is transferred to affiliates in the USA, these providers rely on the EU–US Data Privacy Framework and standard contractual clauses approved by the European Commission.
7. Retention
Donation records are kept for the period required by accounting law. Visitors’ IP addresses and other personal data are not stored.
8. Security
The site is served exclusively over a secure connection (HTTPS). The site’s server is separated from the church’s other information systems and has no access to them. Only authorised persons can access the site’s settings.
9. Your rights
You have the right to access your personal data, to have it corrected or erased (insofar as this does not conflict with a legal retention obligation), to restrict its processing and to object to it. To exercise your rights, contact us at [email protected].
10. Right to complain
If you believe your personal data is processed in breach of the law, you have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (cpdp.bg).
11. Changes to this policy
This policy may be updated. The current version is published on this page with the date from which it applies.