Privacy Policy
What data we collect, why, and what your rights are.
Intreea is an online educational platform, available at www.intreea.com (the “Platform”), which is owned and administered by “Eto kak ucha” DPK, UIC 208219391, with registered office and address of management at 5 Filip Stanislavov St, Sofia, email address: hello@etokak.bg (the “Controller”).
I. Definitions
For the purposes of this Privacy Policy the following definitions are used:
- “Personal data” is any information by which a natural person is identified or can be identified;
- “Data subject” is a natural person who is identified or who can be identified on the basis of certain information. In the present case the data subjects are the users of the website located at www.intreea.com;
- “Processing” means any operation or set of operations performed on personal data or on a set of personal data, whether by automated or other means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- “Controller” means a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. In the present case the controller is “Eto kak ucha” DPK, UIC 208219391.
II. Types of personal data and the purposes for which they are collected; legal basis for collection
1. Users can access and use the Platform by registering and creating a profile. In connection with registration for and use of the Platform through a user profile, the Controller collects the following personal data:
- From students: first name and surname, email address, grade/class, school, unique identifier in the platform, data on learning activity and progress;
- From parents: first name and surname, email address, link to a child/children in the platform, data on activity in the platform;
- From teachers, pedagogical specialists and other school staff: first name and surname, email address, subject taught, data on activity in the platform.
2. When the Platform is used, the Controller receives information from log files (a set of system information about the user): IP address; ISP (Internet Service Provider); the browser the User uses when visiting the Platform (e.g. Google Chrome, Internet Explorer and Mozilla Firefox); the time the User has spent on the Platform, which internal pages were visited, and other data.
3. When a User visits the Platform, our web server automatically recognises and collects the User's IP address, which is assigned by the User's internet service provider and does not in itself identify the User personally. The IP address may be processed by the Controller for the purpose of establishing the identity of a specific User where this is necessary in compliance with the law or legal procedures, or in order to comply with this Privacy Policy, as well as for analysing traffic to the Platform, protecting against malicious attacks, blocking access by users acting in bad faith, and other legitimate purposes.
4. In order to send a request to the Controller for a demo version of the Intreea educational tool presented on the Website, Users must state their names and email address, and indicate whether they wish to receive the demo version in the capacity of a parent, a teacher or another capacity indicated in the registration form.
5. The Controller uses the personal data provided solely for the purposes of providing access to and use of the Intreea educational tool, including the demo version. Should the Controller wish to process the collected personal data for purposes other than those stated in this Privacy Policy, it will notify Users accordingly and will change the purposes of processing after obtaining the users' consent.
6. In connection with the use of the Platform, the Controller does not require Users to provide, and does not process, personal data revealing racial or ethnic origin; political, religious or philosophical beliefs or trade union membership; genetic and biometric data, or data concerning sex life or sexual orientation.
7. Access to the Platform at www.intreea.com can be obtained through Google Chrome, Internet Explorer and Mozilla Firefox and other search engines, as well as through social networks: Facebook and Instagram. The Website may integrate services related to social networks (e.g. social network messaging) through which Users can communicate with the Website.
8. The website www.intreea.com may maintain profiles on social networks. Each time a User accesses the Website through a social network, the provider of the respective social network may allow the User to share information with us. If the User chooses to share, the social media provider will notify them which information will be shared with us.
9. Social network buttons (Facebook, Instagram) are integrated on the website www.intreea.com. These buttons take Users directly to the provider's pages on those social media.
10. The website www.intreea.com uses Google Analytics, a web service provided by Google for compiling detailed statistics about website visitors. The statistics are collected on Google's server and are used by the Website's Administrator for the purposes of traffic analysis and improving the effectiveness of the Website.
11. The processing of the personal data of the Platform's Users is carried out on the basis of their voluntary, informed, freely given and clearly expressed consent, as well as on other grounds permitted by law, in particular for the purposes of fulfilling the Controller's obligations to Users, for compliance with a legal obligation to which the Controller is subject, and for the protection of the legitimate interests of the Controller or of a third party.
III. Automated decision-making and profiling
12. The Controller does not carry out automated decision-making using data, or profiling of Users.
IV. Provision of personal data to third parties; transfer
13. The Controller does not provide the personal data of Users, collected in connection with the use of the Website and the Platform, to third parties, except where such provision is required by law. Beyond that, the Controller/Processor uses cloud services for the purposes of the technological operation of the Platform, which presupposes access to the personal data of the Platform's users. The cloud service provider and the cloud services meet all applicable requirements for the territory of the European Union.
14. The Controller does not transfer personal data collected in connection with the use of the Website and the Platform to third countries outside the European Union.
V. Storage of personal data
15. Preserving the confidentiality and security of Users' personal information is of the highest priority for the Controller, which is why the Controller collects only the necessary amount of data by which Users can be identified.
16. The Controller will keep all personal information provided by Users confidential, except where its disclosure is required by law or for technical purposes.
17. The personal data collected from Users in connection with the use of the Platform will not be made available by the Controller to anyone, whether for consideration or free of charge, without the Users' personal consent.
18. Data retention periods vary and depend on the nature of the data. The criteria used to determine the retention periods for specific categories of personal data include:
- The need for the data to maintain and improve the Platform and the services provided through it;
- The need for the data to maintain the security of the systems and to keep the necessary commercial and financial (accounting, tax and other) documentation as required by applicable law;
- The period for which consent to the processing of the data has been given, if any;
- Withdrawal of consent to the processing of personal data;
- The need to retain personal data for the purposes of an investigation or legal dispute, or the handling of complaints and grievances;
- The existence of a statutory period obliging the Controller/Processor to retain personal data for a certain time;
- The existence of a legal basis for processing personal data other than consent.
VI. Measures to protect personal data
19. The Controller takes the necessary technical and organisational measures to protect the data against accidental or unlawful destruction, accidental loss, unauthorised access, alteration or dissemination, and against other forms of unlawful processing.
20. The technical and organisational measures taken by the Processor are:
- Data is stored within the territory of the European Union;
- Data is encrypted in transit (HTTPS / TLS);
- Sensitive data is encrypted at rest;
- Role-based restricted access to data (student / teacher / administrator);
- Strong authentication and password management;
- Regular backups;
- Logging and monitoring of access;
- Segregation of environments (production/test).
VII. Users' rights in connection with the processing of personal data
21. Users have certain rights under applicable law in relation to the personal data processed by the Controller. Users have the following rights in respect of the personal data processed by the Controller and may, insofar as applicable, exercise these rights at any time:
- to request access to and receive information about the personal data stored by the Controller, as well as information concerning the purposes of processing, the categories of personal data, the recipients to whom the personal data may be disclosed, and other matters;
- to request the rectification of inaccurate data collected about them, and the completion of incomplete data, where this is appropriate and/or necessary in view of the purpose for which the data is processed;
- to withdraw their consent to the use of the personal data they have provided (where such consent has been requested by the Controller). In that case, withdrawing consent to the use or processing of Users' personal data may make it impossible to use all the functionalities of the Website;
- the right to be “forgotten”, i.e. Users may at any time request that their personal data be erased on any of the following grounds:
- the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
- the User has withdrawn consent to the processing of their personal data;
- the personal data is being processed unlawfully;
- the User has objected to the processing of their personal data;
- in other cases provided for in the legislation governing the protection of personal data;
- to request, instead of erasure of their personal data, restriction of processing in the cases specified by applicable law;
- to object to the Controller against the processing of their personal data, where there is a legal basis for doing so.
22. Users may exercise all of the legal rights listed above by submitting a written request in free form to the following email address: hello@etokak.bg. The written request must contain at least the following: full name (three names), email and other details identifying the natural person concerned; a description of the request; the preferred form in which the information is to be provided. Submitting the request is entirely free of charge. The period for considering the request is one month from the date of its receipt.
23. In the event of a breach of the applicable European and national legislation on the protection of personal data and/or of this Privacy Policy, Users have the right to lodge a complaint with the Commission for Personal Data Protection.
This Privacy Policy enters into force on 19.02.2026.

