Privacy Notice
Last updated: 24 December 2025
Who we are
This website is operated by Masaltov Ltd. (Bulgarian: „Мазалтов” ЕООД), company registration number 202163400, 17 Han Krum Street, fl. 1, 9000 Varna, Bulgaria.
What data we collect
1) Access requests
When you submit a request via Request Access, we may collect:
- Full name (mandatory)
- Company and registration/VAT number (optional)
- Email address (mandatory)
- Reason for request, phone/reference (optional)
- Technical metadata for security: IP address and browser user-agent
2) Approved user accounts
If you are approved and activate an account, we store:
- Email address and name
- Password hash (we do not store your plaintext password)
- Account status (pending/active/disabled) and timestamps
3) Secure messages (ciphertext only)
The Secure Messages feature encrypts messages in your browser before upload. The server stores ciphertext, plus technical encryption parameters (salt/IV) required for decryption in the browser.
Masaltov does not store your passphrase and cannot decrypt your messages without it.
How we use data
- To review access requests and decide whether to approve or reject
- To operate authentication (login/logout) for approved users
- To operate the encrypted messaging feature (storage and delivery of ciphertext)
- To protect the website against abuse (rate-limiting, logging, security analysis)
Legal basis
Depending on context, we process personal data based on legitimate interests (security, abuse prevention, and handling serious enquiries), and where applicable to take steps at your request prior to entering into a relationship or engagement.
This notice is intentionally concise and is not a substitute for legal advice.
Retention
- Access requests: retained for operational and security purposes, then periodically reviewed for deletion.
- User accounts: retained while the account remains relevant; disabled accounts may be retained for audit/security.
- Encrypted messages: retained to provide mailbox-style access unless a retention limit is later introduced.
If you require deletion, see “Your rights” below. Some data may be retained where necessary for legitimate security purposes or legal obligations.
Sharing
We do not sell personal data. We share data only where required to operate the service or comply with legal obligations.
Note: the Tuatara page may embed YouTube content. Loading embedded video may connect to YouTube servers and be subject to YouTube/Google policies.
Cookies
This site uses essential cookies for session management (login). These cookies are necessary for the secure area to function. We do not run advertising cookies.
Your rights
You may request access, correction, or deletion of personal data, and you may object to certain processing. Because Masaltov does not publish open contact details for initial enquiries, privacy-related requests should be initiated through the controlled access process described on the Contact page.
If you are already an approved user, you may initiate such requests via Secure Messages.