← Back to home

Legal

Privacy Policy

Protecting your personal information is one of our highest priorities. This policy explains, in plain language, what we collect, why we collect it, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR).

Last updated:

Language:
On this page
  1. 1. Introduction
  2. 2. Definitions
  3. 3. Data We Collect
  4. 4. How We Use Your Data
  5. 5. Legal Basis for Processing (GDPR)
  6. 6. Data Retention
  7. 7. Data Security
  8. 8. Sharing Data
  9. 9. Your GDPR Rights
  10. 10. Cookies
  11. 11. Children's Privacy
  12. 12. Changes to this Policy
  13. 13. Contact Us

1. Introduction

Health In Box OOD, trading as Chill&Bite ("Chill&Bite", "we", "us" or "our"), is a Bulgarian company operating on-site food, beverage and workplace commerce services — including Smart Micro Markets, Micro Kitchen services, Smart Coffee Solutions, a DOOH Media Network, and Corporate Catering & Events. This Privacy Policy applies to personal data we process through our website, mobile application, in-market payment terminals, QR feedback system, support center, contact forms, newsletter and analytics.

We act as the data controller for the personal data described here. By using our services, you acknowledge that you have read and understood this Policy.

2. Definitions

  • "Personal data" — any information relating to an identified or identifiable natural person.
  • "Processing" — any operation performed on personal data (collection, storage, use, disclosure, deletion, etc.).
  • "Data controller" — the entity that determines the purposes and means of processing. For this Policy, that is Chill&Bite.
  • "Data processor" — a third party that processes personal data on our behalf under a written agreement.
  • "Service" — our website, mobile app, Smart Micro Markets, QR feedback system, support center, contact forms, newsletter and any related tools.

3. Data We Collect

3.1 Personal information

When you contact us, request an assessment, subscribe to our newsletter, register a payment method in a Smart Micro Market, or open a support ticket, we may collect: full name, business email, phone number, company name, job title, site address, and any information you choose to include in a free-text message.

3.2 Usage data

We collect limited technical data required to operate and secure the Service: timestamp, requested URL, HTTP status, referrer, browser type and version, operating system, device type, and — where relevant — anonymised interaction events within our website and mobile app.

3.3 Transaction data (Smart Micro Markets)

Purchases in our Smart Micro Markets are processed by regulated payment providers. Chill&Bite receives transaction metadata (amount, currency, location, item categories, timestamp, masked card token) but does not store full payment card numbers.

3.4 Location data

We use the physical location of the market or kitchen where a service is delivered. We do not collect continuous background GPS data from your device. Our mobile app may request coarse location only to help you find the nearest active market; this permission can be denied or revoked at any time.

3.5 Camera and photos

Our mobile app and QR feedback flow may request access to your camera to scan QR codes or to attach a photo to a support ticket (for example, a photo of a product issue). Camera access is triggered only by an explicit user action and can be denied without loss of core functionality.

3.6 Event enquiries (Corporate Catering & Eventora AI™)

When you submit an event enquiry through our Corporate Catering & Events planner, we collect the details you provide: company name, contact name, business email, optional phone number, event type, requested date, time and duration, guest count, delivery location, service preferences (food, drinks, dietary requirements, staffing, equipment), an optional budget note and free-text notes. Eventora AI™ is used only to structure your enquiry into a draft configuration; it does not confirm availability, does not produce pricing and does not make any automated decision that produces legal or similarly significant effects for you. Every enquiry is reviewed by a member of our team before any response is sent.

Enquiries submitted through this planner are stored on Chill&Bite infrastructure inside the EU. To protect the form against automated abuse we also process a short-lived, non-reversible technical fingerprint derived from your IP address and browser user agent; we do not store your raw IP address for this purpose. Enquiry data is not sold, and is not shared with any third party for advertising or model-training purposes.

3.7 Cookies and similar technologies

This website uses strictly necessary cookies to operate and to remember your cookie preferences. Analytics and marketing cookies are OFF by default and only activate after you grant consent through the cookie banner. See Section 10 (Cookies) and our Cookie Policy for the full list.

4. How We Use Your Data

  • To deliver our services (Smart Micro Markets, Micro Kitchens, Coffee, DOOH, Catering) and operate the payment, ordering and feedback flows.
  • To reply to your assessment requests, support tickets and general enquiries.
  • To send transactional communications (order confirmations, incident updates, invoices).
  • To send the newsletter — only where you have explicitly opted in.
  • To operate and secure the website, mobile app and back-office systems (fraud prevention, abuse detection, incident response).
  • To measure aggregate service quality and improve our products through anonymised analytics.
  • To comply with legal, accounting and tax obligations under Bulgarian and EU law.

6. Data Retention

We keep personal data only for as long as needed for the purpose it was collected, and thereafter for the periods required by law:

  • Assessment and contact requests — for the duration of the sales conversation and any subsequent contract.
  • Contract, invoice and accounting records — for the retention period required by Bulgarian accounting and tax law (typically up to 10 years).
  • Support tickets — up to 24 months after resolution.
  • Newsletter data — until you unsubscribe.
  • Website server logs — up to 12 months.
  • Event enquiries submitted through the Corporate Catering & Events planner — up to 24 months after the last contact, unless a contract is concluded, in which case contract retention applies. Anti-abuse technical fingerprints are deleted within 30 days.
  • AI Advisor session messages — for the active browser session, unless submitted as part of an assessment request.

7. Data Security

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration or destruction. Measures include encryption in transit (TLS), least-privilege access controls, MFA on administrative accounts, regular backups, patched infrastructure, and vendor security review. No system is 100% secure; we work continuously to reduce and manage risk.

8. Sharing Data

8.1 Third-party providers

We share personal data only with vendors that support the operation of our Service, under a written data processing agreement:

  • Cloud hosting and edge infrastructure (website and mobile app backend).
  • Payment processing partners (Smart Micro Market transactions).
  • Transactional email delivery (Microsoft 365 / equivalent).
  • AI Advisor language model, accessed via a managed gateway.
  • Support ticketing and CRM tooling used by our customer success team.
  • Analytics tooling — only where analytics cookies have been accepted.

8.2 International transfers

Some of our processors are located outside the European Economic Area. Where this is the case, we rely on GDPR-approved safeguards — most commonly the European Commission's Standard Contractual Clauses (SCCs) — and, where relevant, supplementary measures to ensure an essentially equivalent level of protection.

8.3 We do not sell your data

We do not sell personal data. We do not share personal data for third-party advertising purposes.

9. Your GDPR Rights

Under the GDPR you have the following rights in relation to your personal data:

  • Right of access — obtain a copy of the personal data we hold about you.
  • Right to rectification — ask us to correct inaccurate or incomplete data.
  • Right to erasure ('right to be forgotten') — ask us to delete your personal data, subject to legal retention requirements.
  • Right to restriction — ask us to pause processing while a query is resolved.
  • Right to data portability — receive your data in a structured, commonly used, machine-readable format.
  • Right to object — object to processing based on legitimate interest.
  • Right to withdraw consent — where processing is based on consent (e.g. newsletter, non-essential cookies), you can withdraw it at any time without affecting the lawfulness of processing performed before withdrawal.
  • Right to lodge a complaint with a supervisory authority — in Bulgaria, the Commission for Personal Data Protection (CPDP, www.cpdp.bg).

To exercise any of these rights, email info@chillandbite.com. We respond within one month, extendable by two further months for complex requests as permitted by GDPR.

10. Cookies

We use a minimal set of strictly necessary cookies to operate this website and to remember your cookie choice. Analytics and marketing cookies are disabled by default and are only set after you grant consent through the cookie banner. You can change your choice at any time by clearing your browser storage or by using the cookie preferences link, when available, in the site footer.

For a full description of each cookie, please read our Cookie Policy.

11. Children's Privacy

Our services are directed to businesses and adult end-users in workplace environments. We do not knowingly collect personal data from children under the age of 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

12. Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in law, in our services, or in the way we operate. The "Last updated" date at the top of this page always shows the current version. For material changes, we will provide a prominent notice on our website and — where appropriate — notify affected users directly.

13. Contact Us

Data Controller: Health In Box OOD (Chill&Bite), UIC 206247237, VAT BG206247237, ул. Пъстър свят 9, 1000 Sofia, Bulgaria.

Email: info@chillandbite.com — Phone: +359 888 887 698.

For any privacy-related question or to exercise your GDPR rights, please contact us at the address above.