GDPR Compliance
This page explains how "Connectix" ood ("Connectix", "we") supports compliance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") when businesses use the Connectix platform to send Viber and SMS messages to their customers.
1. Roles: controller and processor
When you use Connectix to message your customers, you are the data controller for the recipient data you upload (names, phone numbers, order details used in templates), and Connectix acts as a data processor, processing that data only on your documented instructions — i.e. to deliver the messages you send. For the account data of registered platform users (your company and team members), Connectix is an independent controller as described in our Privacy Policy.
2. Lawful basis and consent
As the controller, you are responsible for having a lawful basis for messaging your customers — typically performance of a contract for transactional messages (order confirmations, delivery updates) and consent or legitimate interest for marketing messages. Connectix provides the tooling to honour that basis in practice: message-type separation (transactional vs. promotional) and a per-recipient opt-out state enforced on every send.
3. Built-in opt-out
Every promotional message can carry an unsubscribe mechanism. Recipients can opt out at any time — by replying with a stop keyword or through the hosted opt-out page — and can choose a permanent block. Opt-outs are enforced automatically at send time, before a message leaves the platform, and each opt-out is recorded so you can demonstrate compliance.
4. Data subject rights
We assist you in fulfilling data subject requests under Articles 15–22 GDPR (access, rectification, erasure, restriction, portability, objection). Contact data and message history for a given recipient can be exported from the platform; for erasure requests, contact us at office@connectix.bg and we will assist you as the processor. Where a request reaches Connectix directly, we forward it to you as the controller without undue delay.
5. Data location and transfers
Personal data processed through the platform is stored and processed within the European Union. Where message delivery requires routing through telecommunications providers (mobile operators, Rakuten Viber), data is shared only to the extent necessary to deliver the message, and any transfer outside the EU takes place only with appropriate safeguards under Chapter V GDPR.
6. Retention
Message content and delivery metadata are retained for the period necessary for billing, dispute resolution and legal obligations, after which they are deleted or anonymised.
7. Security
Technical and organisational measures protecting personal data are described on our Security page — encryption in transit, role-based access control, environment separation and delivery logging.
8. Sub-processors
Connectix uses a limited set of sub-processors (hosting, e-mail delivery, telecommunications routing) bound by data processing terms consistent with the GDPR. A current list is available on request.
9. Data processing agreement
A data processing agreement pursuant to Article 28 GDPR is available to all customers — see Data Processing Agreement.
10. Supervisory authority and contact
The competent supervisory authority for Connectix is the Bulgarian Commission for Personal Data Protection (www.cpdp.bg). For any GDPR matter, contact us at office@connectix.bg.