Scope, controller and who is protected by this policy
This Privacy Policy explains how Trendcodd processes information that constitutes personal data or personal information under applicable law. It applies to visitors to trendcodd.com, people who submit enquiries, book meetings, use Trend AI, subscribe to marketing communications, communicate with us by email or another channel, and representatives, employees, owners and other contact persons of prospective and current business clients.
For our own activities in which Trendcodd determines the purposes and essential means of processing, Trendcodd acts as a controller. This includes, for example, operating and securing the website, handling incoming business enquiries, arranging meetings, operating our own marketing channels, providing Trend AI, administering client relationships and meeting legal obligations. For certain services carried out inside a client’s systems or using data made available by a client, Trendcodd may instead act as a processor acting on the client’s documented instructions.
Trendcodd for the processing activities for which we determine the purposes and essential means.
[email protected] for privacy questions, requests and complaints.
Visitors, business contacts, prospective and current clients and other individuals whose data we process.
Where our client is a company, organisation or another legal entity, privacy law remains relevant to the natural persons acting on its behalf. A name, business email address, telephone number, job title, account identifier, correspondence and activity in a system can still be personal data where an individual is directly or indirectly identifiable.
Trendcodd provides services and communicates with visitors, prospective clients, clients, organisational representatives and business partners in multiple countries. Depending on the processing, European, national, state, provincial or sector-specific privacy rules may apply where their territorial and material criteria are met. Applicability depends on the facts, including where the parties and affected individuals are located, the type and source of the data, the services being offered, the technologies involved, whether a particular market is being targeted and any statutory thresholds.
This Policy does not limit rights that cannot lawfully be restricted by contract or by a privacy notice. Where an applicable mandatory rule grants a higher level of protection or an additional right, that rule prevails for the affected processing.
Principles and international legal framework
Core processing principles
We apply principles common to modern privacy regimes and expressly reflected in European data-protection law: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Under the GDPR these principles are set out in Article 5, including the requirement in Article 5(2) that a controller be able to demonstrate compliance.
Where the GDPR applies, processing is based on a specific legal basis under Article 6. Consent is handled under Article 7; special categories of data are subject to Article 9; transparency duties arise principally under Articles 12–14; individual rights are addressed in Articles 15–22; processor relationships in Article 28; security and personal-data breaches in Articles 32–34; and transfers outside the European Economic Area in Articles 44–49. The official consolidated text is available through EUR-Lex.
Other privacy regimes that may apply
Depending on the interaction, market, affected individuals, Trendcodd’s role and the legal tests for applicability, processing may also be governed by other privacy regimes alongside, or for particular issues instead of, European rules. Examples include the UK GDPR and Data Protection Act 2018, the revised Swiss Federal Act on Data Protection, PIPEDA and relevant provincial laws in Canada, the California Consumer Privacy Act / CPRA and other US state privacy laws, Brazil’s LGPD, Mexico’s LFPDPPP, Australia’s Privacy Act 1988, New Zealand’s Privacy Act 2020, Japan’s APPI, Korea’s PIPA, Singapore’s PDPA, China’s PIPL, India’s Digital Personal Data Protection Act 2023 and implementing rules, South Africa’s POPIA, and other national or sector-specific regimes.
These laws do not automatically apply merely because a website is technically accessible from a country. Different regimes use different connecting factors and thresholds, such as establishment, offering goods or services, targeting people in a jurisdiction, monitoring behaviour, processing volume, revenue, type of activity, category of individual or data, or other statutory conditions. We therefore determine relevant requirements by reference to the facts of a particular international engagement rather than assuming that every privacy law applies in the same way to every project.
National rules supplementing the European framework
Where the GDPR applies to Trendcodd, it operates together with national rules that supplement or particularise it. For processing connected with the controller’s establishment in Bulgaria, this includes the Bulgarian Personal Data Protection Act and applicable national rules relating to electronic communications, cookies and similar technologies. In cross-border activities, mandatory rules of other competent jurisdictions may also be relevant where their criteria for applicability are satisfied.
Where more than one mandatory regime applies to the same processing, we comply with the applicable requirements for transparency, legal basis, data minimisation, security, retention, individual rights, international transfers and consent or opt-out mechanisms. Additional regional information or controls are provided where required by the law applicable to the specific processing.
Controller, processor and roles when working with clients
When Trendcodd determines the purposes
We act as controller where we independently decide why personal data is needed and the essential means by which it is processed. Typical examples include operating trendcodd.com; security and diagnostics; answering an enquiry; evaluating a potential business relationship; arranging a meeting; maintaining client contacts; billing and record keeping; our own marketing and analytics; Trend AI; handling privacy rights; managing complaints; and establishing, exercising or defending legal claims.
When the client determines the purposes
For services such as CRM integrations, email marketing, campaign management, lead generation, audience work, web analytics, website management, maintenance, systems integration and other digital services, the client may determine the business purposes, the categories of affected individuals and the main context in which personal data is used. If Trendcodd processes that personal data solely on the client’s documented instructions, Trendcodd generally acts as processor for that activity and the client acts as controller.
Where the GDPR applies, Article 28 requires the controller–processor relationship to be governed by a contract or another binding legal act. That arrangement must cover, as applicable, the subject matter and duration of processing, its nature and purposes, the types of personal data and categories of data subjects, the controller’s rights and obligations, confidentiality, security, subprocessors, assistance with individual rights and breaches, deletion or return of data, and information necessary to demonstrate compliance.
Joint and independent roles of platforms
Some external platforms may act as processors for certain operations and as independent or joint controllers for others. The role depends on the product, configuration, contract and purpose; it is not determined simply by the provider’s name. Where a configuration creates independent purposes for a provider, joint determination of purposes and means, or another specific allocation of responsibilities, we assess the need for additional notices, contractual arrangements or controls.
Client responsibilities where Trendcodd acts as processor
Where we act as processor, the client remains responsible for its decisions as controller, including identifying an appropriate legal basis, providing required notices to individuals, defining lawful purposes, avoiding unlawful instructions and ensuring that data made available to us may lawfully be processed for the agreed work. Trendcodd processes the data within documented instructions, applies appropriate security measures and informs or assists the client where required by law or contract.
Personal data we process and the sources from which we receive it
We do not collect the same data from every person. The categories depend on how you interact with us, your role, the functionality you use and the services involved.
Identification and contact information
We may process a name, business or personal email address, telephone number, job title, organisational role, company or brand name and other information used to identify yourself in communications with us. If you communicate on behalf of an organisation, we may also process your relationship with that organisation where relevant to the business interaction.
Business, project and communication information
This can include the service requested, project objectives, markets, business context, descriptions of a need or problem, preferences, timeframes, correspondence, meeting notes and other information voluntarily provided or reasonably required to prepare a proposal, enter into an agreement or perform services.
Meeting and booking information
When arranging a meeting we may process a name, email address, selected services or topics, time zone, selected or preferred time and project context needed to organise and conduct the conversation. Calendar invitations and online meetings may involve providers such as Google Calendar and Google Meet.
Trend AI information
When you use Trend AI, we process the content of the messages you submit and limited technical or conversational context needed to provide a response, maintain continuity, operate the feature securely and, where you choose, progress to booking a meeting or another business action. Trend AI uses OpenAI as a technology provider. Information about OpenAI’s applicable practices and terms is available through its official policies.
Technical, network and security information
When the website or an API function communicates with your browser, our servers and infrastructure providers may process an IP address, date and time, requested URL, referrer, browser type and version, device and operating-system information, language and time-zone settings, session identifiers, technical logs, request status and similar metadata. Such information is used only to the extent needed for service delivery, security, preventing or investigating abuse, diagnostics and reliability.
Analytics, advertising and marketing identifiers
Where the relevant consent has been given, we may process cookie and device identifiers, viewed pages, interactions, campaign parameters, referring pages, advertising click identifiers, events and conversions. For these purposes we use Google Analytics 4, Google Ads, Meta Pixel, Meta Conversions API and Klaviyo. The categories, browser-storage names, purposes and durations are described in our Cookie Policy and are controlled through Cookie Settings.
Contractual, accounting and administrative information
Where an actual business relationship exists, we may process details of representatives and contacts, proposals, agreements, orders, invoices, payment status, accounting records, communication history and information necessary for service delivery, administration, risk management and legal claims. The public website is not intended to collect or store full payment-card details.
Data made available by clients for service delivery
Depending on the engagement, a client may provide limited access to a CRM, advertising accounts, analytics systems, e-commerce environments, email-marketing platforms, lead records, customer lists or other systems. Where we act as processor, we access and use only the data needed for the agreed task, apply least-privilege access principles and do not repurpose client data for unrelated Trendcodd purposes.
Sources
The primary source is usually you or the organisation you represent. Data may also be received from a client in connection with commissioned services; from a provider where its service returns information needed to perform a requested function; from publicly available business sources where lawful and relevant to a legitimate business purpose; or automatically from the browser and infrastructure when the website is used. Where data is obtained indirectly and applicable law requires a separate notice, we provide the required information within the applicable timeframe unless a lawful exception applies.
Special categories, sensitive information and children
Trendcodd’s standard public features are not designed to collect special categories of personal data under Article 9 GDPR or comparable categories of sensitive personal information under other laws. We do not ask users to send health, biometric, genetic, religious, political or other unnecessary sensitive information through general contact functions or Trend AI, and we do not ask for passwords, secret keys, API credentials or full payment-card data through those channels. If a specific client engagement requires sensitive information, the legal basis, purpose, access model and safeguards are assessed separately before access is provided.
The website and our standard services are directed primarily to a business audience and are not intended for children. We do not knowingly seek personal data from children through standard B2B processes. If we become aware that such information has been received without an appropriate legal basis, we take reasonable steps to delete it or otherwise handle it lawfully under the applicable regime.
Purposes, legal bases and specific processing activities
Under the GDPR, each processing activity must have a valid basis under Article 6. Where another privacy law applies, we rely on the lawful mechanism required by that regime. The same type of data can be used for different purposes on different legal bases; for example, an email address may be used to answer an enquiry, send a meeting invitation, issue an invoice or deliver a marketing communication, but those activities are legally distinct.
| Process | What we do | Typical data | Legal basis / condition |
|---|---|---|---|
| Website delivery and security | Serve pages, maintain sessions, diagnose faults, protect infrastructure and investigate suspicious activity. | IP address, requests, URLs, technical and session data. | Legitimate interests, necessary functionality and/or legal obligations depending on context. |
| Contact enquiries | Respond, understand the project, assess whether we can help and prepare a next step or proposal. | Name, email, company, service and message. | Pre-contractual steps and/or legitimate interests in reasonable B2B communication. |
| Bookings and meetings | Check availability, arrange the meeting, send a calendar invitation and conduct the online meeting. | Name, email, time zone, date/time and project context. | Pre-contractual steps and/or legitimate interests. |
| Trend AI | Provide interactive information about Trendcodd and its services, maintain conversation continuity and support a requested next business step. | Message content and limited technical/session data. | Legitimate interests and/or pre-contractual steps; another basis where a specific function requires it. |
| Newsletter and direct marketing | Send marketing communications, administer subscription status and measure interaction where permitted. | Email, name, subscription status/evidence and interactions. | Consent or another lawful basis only where applicable law permits, together with the required unsubscribe or opt-out mechanism. |
| Analytics | Understand website usage, measure traffic and events, and improve content and user experience. | Cookie/device identifiers, pages, events, referrer and campaign parameters. | Consent for optional analytics technologies where required; Trendcodd uses a consent-first model as the baseline for optional tracking. |
| Advertising measurement | Measure conversions, attribution and campaign effectiveness and use advertising functions according to selected settings and applicable law. | Advertising identifiers, click IDs, events and conversions. | Consent or another applicable opt-out/permission mechanism depending on jurisdiction; consent before optional tracking in the EEA. |
| Client relationships | Negotiate and perform agreements, coordinate teams, maintain business communication and manage quality and scope. | Contact, contractual, correspondence, project and administrative data. | Contract, pre-contractual steps, legitimate interests and legal obligations as applicable. |
| Finance, accounting and tax | Issue and retain required documents, administer payments and meet accounting and tax obligations. | Representative details, invoice and payment-status records. | Contract and legal obligation. |
| Legal claims and compliance | Protect rights, respond to lawful requests, maintain necessary records and handle disputes or investigations. | Information connected with the relevant agreement, request, incident or dispute. | Legal obligation and/or legitimate interests; establishment, exercise or defence of legal claims. |
| Client data as processor | Perform specifically commissioned operations in the client’s systems. | Depends on the DPA, scope of work and specific service. | Documented client instructions and the processing agreement; the client determines its own lawful basis as controller. |
Legitimate interests
When relying on legitimate interests under Article 6(1)(f) GDPR, we consider whether there is a real and lawful purpose, whether the processing is necessary for that purpose and whether the interests or fundamental rights and freedoms of the individual override our interest. Examples can include system security, prevention of fraud or abuse, reasonable B2B communication, management of client relationships and protection of legal claims.
Consent
Where we rely on consent, it must be freely given, specific, informed and unambiguous. Silence or a pre-enabled optional setting is not treated as consent. Consent can be withdrawn for the future without affecting the lawfulness of processing performed before withdrawal. Cookie and tracking choices are managed through Cookie Settings.
Contract, pre-contractual steps and legal obligations
Where processing is objectively necessary to take steps at your request before entering into a contract, or to perform a contract with you as an individual, Article 6(1)(b) GDPR may apply. Where a contract is with a company, processing the personal data of its representatives often relies on legitimate interests, a legal obligation or another appropriate basis rather than automatically on a contract with the individual. Accounting, tax, regulatory and other mandatory duties are handled on the legal basis required by the applicable law.
Website, business enquiries, meetings, Trend AI and marketing technologies
Contact forms and business communication
When you send an enquiry, we use the information provided to respond, understand the need and determine whether and how Trendcodd can provide a service. If you communicate on behalf of a company, we process your business contact details in the reasonable context of that communication. Submitting an enquiry does not automatically subscribe you to a marketing newsletter.
Meeting scheduling and Google services
When you book a meeting, we process the information needed to check availability, create the calendar event and conduct the online meeting. We use Google Calendar and Google Meet for the organisational part of that process. Information reasonably required for the invitation and meeting may be transmitted to Google, such as a name, email address, date/time, time zone and limited project context. Google’s practices are described in the Google Privacy Policy.
Trend AI and OpenAI
Trend AI is Trendcodd’s conversational website functionality. The content you submit is processed to generate an answer related to Trendcodd, our services and any next step you request. OpenAI is used as a technology provider for this functionality. A Trend AI response does not by itself constitute the conclusion of a contract, a final binding offer or an automated individual decision producing legal or similarly significant effects.
Do not use Trend AI to send information that is unnecessary for the conversation, particularly passwords, secret keys, payment credentials or unnecessary sensitive personal data. Where a conversation progresses into a concrete business relationship, relevant information can be used to respond or organise a requested next step in accordance with this Policy.
Klaviyo and marketing communications
Klaviyo is used for subscription administration, marketing campaigns and automations. Depending on the chosen settings and consent, this may involve an email address, name, subscription status, delivery, opening, clicking and website interaction information. Marketing messages include the applicable unsubscribe mechanism. Following an unsubscribe, a minimal suppression or opt-out record may be retained where necessary to make sure the preference continues to be respected.
Google Analytics 4, Google Ads, Meta Pixel and Meta Conversions API
The consent structure is designed to manage Google Analytics 4 for website measurement, Google Ads for advertising measurement and related advertising features, and Meta Pixel together with Meta Conversions API for browser- and server-side event measurement, attribution and related advertising functions in Meta’s advertising ecosystem. Optional analytics, advertising and marketing technologies are controlled through Cookie Settings and, for the EEA, follow a consent-first model.
For Meta, the current Trendcodd implementation records PageView, BookingStart, PhoneClick, EmailClick, SocialClick, CTAClick and Lead after Advertising consent. Meta Pixel sends browser events and Conversions API sends corresponding server events using the same event ID for deduplication. Depending on the event and the information available, Meta may receive the event name and time, event ID, event-source URL, event parameters, the Meta browser identifier (_fbp), the Meta click identifier (_fbc) when present, user agent and a public IP address when available. For Lead events, the current server integration also sends the submitted email address and first and last name only after normalization and SHA-256 hashing. Meta Pixel Automatic Advanced Matching is currently limited to email and first and last name, which are hashed before transmission.
Some jurisdictions define terms such as “sale”, “sharing”, “targeted advertising” or “cross-context behavioural advertising” more broadly than an ordinary sale of data for money. Trendcodd does not operate a business model in which visitor personal data is sold as a standalone product. If the use of an advertising technology falls within a broader statutory definition of sharing or targeted advertising, the applicable consent or opt-out control must be respected for that processing.
Cookies and similar technologies
The inventory of cookies, localStorage, sessionStorage and similar technologies used by the public website is set out in the Cookie Policy. Optional categories can be changed through Cookie Settings. Deleting browser data may also remove the stored preference, in which case the site may request a new choice.
Personal data when providing services to clients
Trendcodd provides digital services in which access to a client’s systems or data can sometimes be necessary for real service delivery. This does not mean every project involves personal data or that Trendcodd receives unrestricted access. Access is determined by the specific task and the principles of need-to-know and least privilege.
Typical client environments
Depending on the service, we may work in CRM systems, email-marketing platforms, advertising accounts, web-analytics systems, e-commerce platforms, content-management systems, lead-management tools or other business applications. Data can include contact records, user identifiers, website events, interaction histories, audiences, orders, marketing preferences or other categories lawfully used by the client for its business.
Instructions and purpose limitation
Where Trendcodd acts as processor, client data is not used for unrelated Trendcodd purposes. We follow documented instructions, the service agreement and any applicable data-processing agreement. An instruction does not itself authorise unlawful processing; where an instruction appears to conflict with mandatory law, the issue is handled under the applicable contractual and legal process.
Subprocessors and access
Where a service requires another technology provider to process data on behalf of the client, the applicable subprocessor terms and approval mechanisms are followed. Access should be role-based and limited to the task, and temporary access should be removed when no longer needed. Clients should provide appropriate business accounts and permissions rather than unnecessary sharing of personal passwords.
International client projects
Where a project spans more than one jurisdiction, the relevant roles, categories of data, affected individuals, processing locations, service providers, transfer mechanisms and local rights or restrictions are assessed in light of the actual engagement. This is especially relevant in CRM, email marketing, advertising and e-commerce work because the client’s place of establishment may differ from the locations of its customers or other affected individuals.
Recipients, service providers, subprocessors and disclosure
Trendcodd does not disclose personal data to third parties without a purpose. Access is limited to recipients that have a lawful and genuine need in connection with the relevant functionality, service, agreement or legal obligation. Depending on the context, recipients may include:
- hosting, infrastructure, database, backup and security providers needed to deliver and protect the website and related systems;
- Google for Calendar and Meet and, where enabled with the relevant permissions, Google Analytics and Google Ads;
- OpenAI for the provision of Trend AI;
- Klaviyo for newsletter and marketing automation and related tracking where permitted;
- Meta Platforms for Meta Pixel, Meta Conversions API, advertising measurement, attribution and related advertising functions where permitted;
- business email and communication providers used to send and receive business communications;
- professional advisers, such as accountants, lawyers, auditors and similar professionals where necessary and subject to appropriate confidentiality;
- the client on whose behalf data is processed where results, reports or data are returned as part of the commissioned service;
- competent authorities, courts and law-enforcement bodies where disclosure is legally required or lawfully necessary to protect rights, security or legal claims;
- parties to a permitted corporate transaction such as restructuring, merger, acquisition or sale of a business, subject to applicable confidentiality and notice obligations.
Where a provider processes personal data on our behalf, we use contractual terms appropriate to the relevant processor requirements. Where a provider acts as an independent controller for its own purpose, its own legal terms and privacy notice govern that separate processing.
We do not sell personal data as a standalone business product
Trendcodd does not operate a business model in which visitor personal data is sold for monetary consideration as a separate product. This statement does not override special statutory definitions. Certain US state privacy laws, for example, may classify some advertising disclosures as a “sale” or “sharing” even where there is no conventional cash sale. Where such a definition applies to a specific advertising technology, the corresponding statutory rights and controls must be provided.
International transfers, processing locations and security
Transfers outside the European Economic Area
Some service providers and their subprocessors may process data outside Bulgaria or outside the EEA. Where the GDPR applies and personal data is transferred to a third country, Trendcodd applies Articles 44–49 GDPR. Depending on the recipient and country, safeguards can include an adequacy decision of the European Commission, Standard Contractual Clauses (SCCs), an applicable adequacy or certification framework, a permitted derogation for a specific situation or another valid transfer mechanism. Official information on the SCCs is available from the European Commission.
Where required, we also assess circumstances in the recipient country and the need for supplementary technical or organisational measures. The use of a global technology provider is not treated as sufficient legal justification for an international transfer by itself.
Transfers under other national regimes
Other privacy laws can impose their own cross-border requirements, such as contractual clauses, equivalence assessments, local storage requirements, separate consent, notification or another statutory condition. Such requirements are considered where the relevant law actually applies to the engagement. China’s PIPL, for example, has its own cross-border rules, while regimes such as LGPD, PIPEDA, APPI and privacy laws in the Middle East use different mechanisms.
Technical and organisational measures
Security measures are selected according to risk, data type and system context. They may include access controls and least privilege, protected network connections and encryption in transit, account protection and authentication, restricted administrative access, separation of environments, backup and recovery arrangements, updates and vulnerability management, logging and monitoring, contractual security requirements for providers and incident-response procedures. Exact controls depend on the system, and we do not publish implementation detail that would reduce security.
Personal-data breaches
Where a personal-data breach is suspected, we take steps to contain and investigate the incident, assess scope and risk, document relevant facts and restore secure operation. Where the GDPR applies, notification to the supervisory authority is handled under Article 33, including the requirement to notify without undue delay and, where feasible and required, within 72 hours after becoming aware of the breach. Where a breach is likely to result in a high risk to individuals’ rights and freedoms, Article 34 may also require communication to affected individuals. Other jurisdictions may use different thresholds, deadlines and authorities; the mandatory rule applicable to the incident is followed.
Retention periods, archives and deletion
Trendcodd does not use one universal retention period for all personal data. Retention depends on the purpose, legal basis, contractual relationship, type of data, risk, applicable accounting or tax rules, limitation periods, requirements to demonstrate consent or opt-out choices and the need to establish, exercise or defend legal claims. When there is no longer a valid purpose or lawful basis, data is deleted, anonymised or access is restricted as appropriate.
| Category | Retention approach | What can extend retention |
|---|---|---|
| Enquiries that do not become a contract | Kept for a reasonable period needed to respond, follow up and manage a potential business relationship; our usual reference period is up to 24 months after the last substantive contact. | Active negotiations, a legal obligation, a dispute or the need to protect a legal claim. |
| Bookings and meetings | Kept for meeting administration and reasonable follow-up; if a meeting leads to a client relationship, relevant information becomes part of the client record. | Contractual relationship, ongoing communication, dispute or legal requirement. |
| Trend AI | Only state and history required for the selected functionality and configuration are retained; technology providers may apply their own contractual retention rules. | Selected configuration, security requirements, legal obligations or contractual terms. |
| Marketing subscription | Until unsubscribe or until the relevant lawful basis ends. A minimal suppression/opt-out record can be retained after unsubscribe to respect the choice. | Need to demonstrate or honour consent/opt-out and applicable law. |
| Cookie and consent records | According to the duration of the relevant record and the current consent-mechanism version described in the Cookie Policy. | A new purpose/version or legal requirements to demonstrate the choice. |
| Contracts, invoices and accounting data | For the duration of the relationship and afterwards for periods required by applicable accounting, tax, regulatory and limitation rules. | Audit, inspection, dispute, legal obligation or legal claim. |
| Client data processed as processor | According to the DPA, service agreement and client instructions; at the end of the service data is returned, deleted or access is terminated according to the agreed process and applicable law. | Law, a valid client instruction or a legally required retention obligation. |
| Security and technical logs | For the period necessary for security, diagnostics and investigation, generally shorter than long-term contractual records. | Incident, investigation, abuse or legal obligation. |
Backups may contain data for a limited additional period because of backup rotation and recovery architecture. Where technically necessary, deletion from active systems is reflected in backup copies as those copies rotate out, unless a mandatory law requires a different approach.
Your rights and how to exercise them
Your rights depend on the law applicable to the processing and do not exist in exactly the same form in every jurisdiction. Where the GDPR applies, Articles 15–22 provide rights including access, rectification, erasure, restriction, portability in the circumstances provided by law, objection, withdrawal of consent and safeguards relating to certain automated decisions. Other regimes may provide similar or additional rights.
Examples of additional regional rights
Mexico’s privacy framework commonly refers to ARCO rights: acceso, rectificación, cancelación y oposición. Brazil’s LGPD includes rights relating to confirmation of processing, access, correction, certain forms of deletion, anonymisation or blocking, information about sharing and other controls. California’s CCPA/CPRA includes rights to know/access, correction, deletion and opt out of certain “sale” or “sharing” practices, together with specific controls for certain sensitive information. Other US states use similar but not identical categories and may provide an appeal right after a consumer request is denied. Privacy laws in Canada, Australia, New Zealand and Asian jurisdictions also provide their own access, correction, complaint and related rights.
How to submit a request to Trendcodd
Send your request to [email protected] with a subject line that makes clear that the request concerns privacy. Describe what you want us to do and, where relevant, the context in which you interacted with Trendcodd. Do not send a copy of an identity card or passport unless we specifically ask for an appropriate form of verification. Where necessary to prevent disclosure or deletion of data belonging to another person, we may request the minimum additional information needed to verify identity or a representative’s authority.
We respond within the timeframe required by applicable law. Under the GDPR, the standard deadline is without undue delay and in any event within one month, subject to the extension conditions in Article 12(3). Other laws can set different deadlines, procedures and appeal rights. We do not charge a fee unless applicable law specifically permits it in the circumstances, such as for manifestly unfounded or excessive requests.
Privacy rights are not absolute. A request may be refused or limited only where there is a lawful reason, for example the rights of other people, a mandatory retention obligation, legal claims, professional secrecy or another applicable exception. Where required, we explain the reason and the available complaint or appeal routes.
International rules, supervisory authorities, complaints and legal remedies
The competent privacy authority depends on the applicable law, the establishment of the organisations involved, the residence or location of the individual, the place of an alleged infringement, the type of processing and any special jurisdictional rules. The table below links to official regulatory channels for major international privacy regimes and markets. Inclusion of a country or regulator does not mean that its law automatically applies to every interaction with Trendcodd and does not exclude another competent authority or remedy provided by applicable law.
European Union, EEA and Bulgaria
Where the GDPR applies, Article 77 GDPR provides the right to lodge a complaint with a supervisory authority, in particular in the Member State of the individual’s habitual residence, place of work or place of the alleged infringement. For processing connected with the controller’s establishment in Bulgaria, the local supervisory authority is the Commission for Personal Data Protection (CPDP / КЗЛД). You can use the official CPDP website and its complaints and alerts channel. Contact details for all national supervisory authorities in the EU and EEA are available through the European Data Protection Board directory.
Under the GDPR, Article 77 covers complaints to a supervisory authority; Article 78 provides an effective judicial remedy against a supervisory authority; Article 79 provides an effective judicial remedy against a controller or processor; and Article 82 provides a right to compensation for material or non-material damage where the legal requirements are met. These rights exist independently of the option to contact Trendcodd first.
Major international privacy regimes and authorities
| Region / country | Principal framework | Authority / official channel | Note |
|---|---|---|---|
| EU / EEA | GDPR, national supplementary rules and ePrivacy framework | EDPB – national supervisory authorities | Competence depends on the GDPR rules, including the cross-border cooperation mechanism. |
| Bulgaria | GDPR and the Personal Data Protection Act | Commission for Personal Data Protection – complaints | Supervisory authority in the Member State of Trendcodd’s establishment. |
| United Kingdom | UK GDPR, Data Protection Act 2018 and PECR | Information Commissioner's Office (ICO) | UK applicability is assessed separately from the EU GDPR regime. |
| Switzerland | Federal Act on Data Protection (FADP) | Federal Data Protection and Information Commissioner (FDPIC) | Swiss law contains its own supervision and transfer rules. |
| United States | Federal sector rules, FTC Act and applicable state privacy laws | Federal Trade Commission (FTC); California Privacy Protection Agency | Rights and thresholds vary by state and sector; CCPA/CPRA is a major California regime. |
| Canada | PIPEDA and applicable provincial regimes | Office of the Privacy Commissioner of Canada | Federal or provincial competence can apply depending on the activity. |
| Brazil | Lei Geral de Proteção de Dados (LGPD) | Autoridade Nacional de Proteção de Dados (ANPD) | LGPD covers rights, lawful bases, security and international transfers. |
| Mexico | Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) | Secretaría Anticorrupción y Buen Gobierno; official law text | The private-sector framework includes ARCO rights and its own rights-protection procedures. |
| Argentina | Ley 25.326 de Protección de los Datos Personales | Agencia de Acceso a la Información Pública (AAIP) | The official channel accepts complaints concerning rights under the law. |
| Australia | Privacy Act 1988 and Australian Privacy Principles | Office of the Australian Information Commissioner (OAIC) | OAIC publishes the applicable privacy-complaint process. |
| New Zealand | Privacy Act 2020 | Office of the Privacy Commissioner | The authority handles privacy complaints under New Zealand law. |
| Japan | Act on the Protection of Personal Information (APPI) | Personal Information Protection Commission (PPC) | APPI regulates use, security, rights and cross-border provision of personal information. |
| Republic of Korea | Personal Information Protection Act (PIPA) | Personal Information Protection Commission / KISA channel | Official infringement reporting is linked to PIPC and KISA. |
| Singapore | Personal Data Protection Act (PDPA) | Personal Data Protection Commission (PDPC) | PDPC accepts data-protection concerns relating to private-sector organisations. |
| Hong Kong | Personal Data (Privacy) Ordinance (PDPO) | Privacy Commissioner for Personal Data (PCPD) | The official process explains how privacy complaints are made. |
| Philippines | Data Privacy Act of 2012 | National Privacy Commission (NPC) | NPC publishes the official complaint procedure. |
| India | Digital Personal Data Protection Act 2023 and applicable rules | Ministry of Electronics and Information Technology / Data Protection Board of India | Applicability and procedure depend on the operative phases and rules of the local regime. |
| China | Personal Information Protection Law (PIPL) | official text – National People's Congress | PIPL includes extraterritorial criteria, individual rights, sensitive information rules and cross-border requirements. |
| South Africa | Protection of Personal Information Act (POPIA) | Information Regulator – complaints | The regulator accepts complaints concerning POPIA, including direct-marketing matters. |
| Israel | Protection of Privacy Law and applicable rules | Privacy Protection Authority | The authority provides an official public-inquiries channel. |
| Saudi Arabia | Personal Data Protection Law (PDPL) | SDAIA – PDPL complaints | The official channel accepts reports and complaints concerning PDPL. |
| United Arab Emirates | Federal Decree-Law No. 45 of 2021 on Personal Data Protection | UAE Legislation / UAE Data Office framework | The federal law addresses controllers, processors, rights and cross-border processing. |
Global directory of privacy authorities
For jurisdictions not listed above, or if you are unsure which regulator is relevant, the Global Privacy Assembly list of accredited members provides links to national and regional privacy authorities from many jurisdictions. For EU and EEA matters, the EDPB directory is the primary reference for national supervisory authorities.
Contact Trendcodd and the right to complain directly
You may contact us at [email protected] if you believe your personal data has been handled incorrectly, if a process is unclear or if you want to exercise a privacy right. Contacting Trendcodd first is not a condition that removes a statutory right to contact a competent regulator or court directly. Some authorities recommend first raising the issue with the organisation; others accept direct complaints. The official procedure of the competent authority should be followed.
Automated decision-making and profiling
The public website and Trend AI are not used by Trendcodd to make a decision based solely on automated processing that by itself produces legal effects concerning a visitor or similarly significantly affects that person within the meaning of Article 22 GDPR. Analytics and advertising platforms may perform measurement, segmentation, attribution or audience-building where the relevant configuration and permission exist; Trendcodd does not use those activities as a standalone automated decision with a significant individual legal effect on the visitor.
Changes to this Privacy Policy
We update this Policy when there are material changes to the way personal data is processed, the providers used, the services offered, legal requirements or the geographic scope of relevant processing. The last-updated date is shown at the beginning of the page. Where a change affects processing based on consent and applicable law requires a new choice, a new consent is requested rather than assuming that an earlier consent covers a materially different purpose.
If you have a question about a particular jurisdiction, your complaint rights, an international transfer, a client project or the way Trendcodd handles your personal data, contact [email protected].