Legal
Privacy Policy
Protecting your personal information is one of our highest priorities. This policy explains, in plain language, what we collect, why we collect it, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR).
On this page
1. Introduction
Health In Box OOD, trading as Chill&Bite ("Chill&Bite", "we", "us" or "our"), is a Bulgarian company operating on-site food, beverage and workplace commerce services — including Smart Micro Markets, Micro Kitchen services, Smart Coffee Solutions, a DOOH Media Network, and Corporate Catering & Events. This Privacy Policy applies to personal data we process through our website, mobile application, in-market payment terminals, QR feedback system, support center, contact forms, newsletter and analytics.
We act as the data controller for the personal data described here. By using our services, you acknowledge that you have read and understood this Policy.
2. Definitions
- "Personal data" — any information relating to an identified or identifiable natural person.
- "Processing" — any operation performed on personal data (collection, storage, use, disclosure, deletion, etc.).
- "Data controller" — the entity that determines the purposes and means of processing. For this Policy, that is Chill&Bite.
- "Data processor" — a third party that processes personal data on our behalf under a written agreement.
- "Service" — our website, mobile app, Smart Micro Markets, QR feedback system, support center, contact forms, newsletter and any related tools.
3. Data We Collect
3.1 Personal information
When you contact us, request an assessment, subscribe to our newsletter, register a payment method in a Smart Micro Market, or open a support ticket, we may collect: full name, business email, phone number, company name, job title, site address, and any information you choose to include in a free-text message.
3.2 Usage data
We collect limited technical data required to operate and secure the Service: timestamp, requested URL, HTTP status, referrer, browser type and version, operating system, device type, and — where relevant — anonymised interaction events within our website and mobile app.
3.3 Transaction data (Smart Micro Markets)
Purchases in our Smart Micro Markets are processed by regulated payment providers. Chill&Bite receives transaction metadata (amount, currency, location, item categories, timestamp, masked card token) but does not store full payment card numbers.
3.4 Location data
We use the physical location of the market or kitchen where a service is delivered. We do not collect continuous background GPS data from your device. Our mobile app may request coarse location only to help you find the nearest active market; this permission can be denied or revoked at any time.
3.5 Camera and photos
Our mobile app and QR feedback flow may request access to your camera to scan QR codes or to attach a photo to a support ticket (for example, a photo of a product issue). Camera access is triggered only by an explicit user action and can be denied without loss of core functionality.
3.6 Event enquiries (Corporate Catering & Eventora AI™)
When you submit an event enquiry through our Corporate Catering & Events planner, we collect the details you provide: company name, contact name, business email, optional phone number, event type, requested date, time and duration, guest count, delivery location, service preferences (food, drinks, dietary requirements, staffing, equipment), an optional budget note and free-text notes. Eventora AI™ is used only to structure your enquiry into a draft configuration; it does not confirm availability, does not produce pricing and does not make any automated decision that produces legal or similarly significant effects for you. Every enquiry is reviewed by a member of our team before any response is sent.
Enquiries submitted through this planner are stored on Chill&Bite infrastructure inside the EU. To protect the form against automated abuse we also process a short-lived, non-reversible technical fingerprint derived from your IP address and browser user agent; we do not store your raw IP address for this purpose. Enquiry data is not sold, and is not shared with any third party for advertising or model-training purposes.
3.7 Cookies and similar technologies
This website uses strictly necessary cookies to operate and to remember your cookie preferences. Analytics and marketing cookies are OFF by default and only activate after you grant consent through the cookie banner. See Section 10 (Cookies) and our Cookie Policy for the full list.
4. How We Use Your Data
- To deliver our services (Smart Micro Markets, Micro Kitchens, Coffee, DOOH, Catering) and operate the payment, ordering and feedback flows.
- To reply to your assessment requests, support tickets and general enquiries.
- To send transactional communications (order confirmations, incident updates, invoices).
- To send the newsletter — only where you have explicitly opted in.
- To operate and secure the website, mobile app and back-office systems (fraud prevention, abuse detection, incident response).
- To measure aggregate service quality and improve our products through anonymised analytics.
- To comply with legal, accounting and tax obligations under Bulgarian and EU law.
5. Legal Basis for Processing (GDPR)
- Contract (Art. 6(1)(b) GDPR) — to deliver services you or your employer have engaged us to provide.
- Legitimate interest (Art. 6(1)(f) GDPR) — to operate the Service securely, prevent fraud, and improve product quality through anonymised analytics.
- Consent (Art. 6(1)(a) GDPR) — for the newsletter, marketing communications, and any non-essential cookies.
- Legal obligation (Art. 6(1)(c) GDPR) — to satisfy accounting, tax and regulatory retention requirements.
6. Data Retention
We keep personal data only for as long as needed for the purpose it was collected, and thereafter for the periods required by law:
- Assessment and contact requests — for the duration of the sales conversation and any subsequent contract.
- Contract, invoice and accounting records — for the retention period required by Bulgarian accounting and tax law (typically up to 10 years).
- Support tickets — up to 24 months after resolution.
- Newsletter data — until you unsubscribe.
- Website server logs — up to 12 months.
- Event enquiries submitted through the Corporate Catering & Events planner — up to 24 months after the last contact, unless a contract is concluded, in which case contract retention applies. Anti-abuse technical fingerprints are deleted within 30 days.
- AI Advisor session messages — for the active browser session, unless submitted as part of an assessment request.
7. Data Security
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration or destruction. Measures include encryption in transit (TLS), least-privilege access controls, MFA on administrative accounts, regular backups, patched infrastructure, and vendor security review. No system is 100% secure; we work continuously to reduce and manage risk.
9. Your GDPR Rights
Under the GDPR you have the following rights in relation to your personal data:
- Right of access — obtain a copy of the personal data we hold about you.
- Right to rectification — ask us to correct inaccurate or incomplete data.
- Right to erasure ('right to be forgotten') — ask us to delete your personal data, subject to legal retention requirements.
- Right to restriction — ask us to pause processing while a query is resolved.
- Right to data portability — receive your data in a structured, commonly used, machine-readable format.
- Right to object — object to processing based on legitimate interest.
- Right to withdraw consent — where processing is based on consent (e.g. newsletter, non-essential cookies), you can withdraw it at any time without affecting the lawfulness of processing performed before withdrawal.
- Right to lodge a complaint with a supervisory authority — in Bulgaria, the Commission for Personal Data Protection (CPDP, www.cpdp.bg).
To exercise any of these rights, email info@chillandbite.com. We respond within one month, extendable by two further months for complex requests as permitted by GDPR.
11. Children's Privacy
Our services are directed to businesses and adult end-users in workplace environments. We do not knowingly collect personal data from children under the age of 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
12. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in law, in our services, or in the way we operate. The "Last updated" date at the top of this page always shows the current version. For material changes, we will provide a prominent notice on our website and — where appropriate — notify affected users directly.
13. Contact Us
Data Controller: Health In Box OOD (Chill&Bite), UIC 206247237, VAT BG206247237, ул. Пъстър свят 9, 1000 Sofia, Bulgaria.
Email: info@chillandbite.com — Phone: +359 888 887 698.
For any privacy-related question or to exercise your GDPR rights, please contact us at the address above.