Legal
Privacy Policy
LAST UPDATED: AUGUST 2026
1. Who we are
NSIGNIS FORUM is the crisis management, strategic communications and intelligence advisory division of NSIGNIS LTD, Sofia, Bulgaria ("NSIGNIS", "we"). NSIGNIS LTD is the data controller for personal data processed through this website under Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act. You can contact us about this policy through the contact form.
2. What we collect, and where it comes from
We collect only the data you provide to us and the minimum technical data required to operate this website securely:
- Enquiry data name, organization, email address, telephone number, subject and message content submitted through the contact form.
- Application data name, surname, email address, country of residence, telephone number, position of interest and your CV, submitted through the application form.
- Emergency channel data when an access code is entered in the Message panel, we process the code entry and its outcome for security purposes. Codes are client-specific and are stored by us only in hashed form.
- Assessment activation data if you use the preliminary assessment, the email address and activation code you enter, verification outcomes and timestamps. Codes are stored only in hashed form.
- Technical and security data standard web server logs (IP address, timestamp, requested resource, browser identifier) and our own security audit records, in which IP addresses are stored only as pseudonymised hashes. We also keep short-lived, IP-derived rate-limiting records to prevent abuse of our forms and endpoints.
- Consent record your cookie choice, stored in your browser (see the Cookie Policy).
We do not collect data from third-party sources about visitors to this website, and we do not use advertising or cross-site tracking technologies.
3. Why we process it, and on what legal basis
- Responding to enquiries and consultation requests — legitimate interest and steps prior to entering a contract (Art. 6(1)(f) and 6(1)(b) GDPR).
- Recruitment — steps prior to entering a contract and your consent to the processing of your application and CV (Art. 6(1)(b) and 6(1)(a)). You may withdraw consent at any time.
- Operating the emergency channel and assessment access — performance of our engagement with the client to whom the code was issued (Art. 6(1)(b)) and our legitimate interest in strictly controlling access (Art. 6(1)(f)).
- Security, abuse prevention and audit — legitimate interest in protecting this website, our clients and our infrastructure (Art. 6(1)(f)).
- Legal compliance — where processing is necessary to comply with a legal obligation (Art. 6(1)(c)).
4. Confidentiality and who receives your data
The nature of our work requires discretion. Enquiry and application data is accessible only to the NSIGNIS FORUM advisory and recruitment team. We do not sell personal data and we do not share it for marketing. Data is disclosed only to service providers who help us operate this website, and where required by law:
- Hosting our web hosting provider stores website data, including submitted forms and server logs, on our behalf.
- Cloudflare, Inc. this website is delivered through Cloudflare's network for security and performance. Cloudflare processes visitor IP addresses and request metadata and may set strictly technical cookies (see the Cookie Policy).
- Google Fonts some typefaces on this website are loaded from Google's servers. When a page loads, your browser requests font files from Google, which involves the transmission of your IP address to Google. No cookies are set by this request.
- Email delivery form submissions are delivered to us by email through our mail infrastructure.
5. International transfers
Cloudflare and Google may process data outside the European Economic Area (EEA), including in the United States. Such transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses, together with supplementary technical measures. Data you submit through our forms is stored on our own hosting within our control.
6. How long we keep it
- Enquiries for as long as necessary to handle the enquiry and any engagement that follows, and no longer than 24 months after our last exchange unless an engagement requires otherwise.
- Applications and CVs for the duration of the recruitment process and up to 6 months after its close, unless you consent to a longer retention or request earlier deletion.
- Security and audit logs up to 12 months, in pseudonymisation manner.
- Rate-limiting records hours, rolling.
- Assessment activation records for the lifetime of the client relationship to which the code belongs.
7. How we protect it
All data is transmitted over encrypted connections (TLS). Uploaded CVs are validated on receipt, renamed and stored in access-restricted private storage outside the public web root. Access codes are stored only as cryptographic hashes and are never displayed in page source. Endpoints are rate limited, submissions are protected by anti-abuse controls, and security events are logged with pseudonymised identifiers.
8. Your rights
Under the GDPR you may request access to, rectification or erasure of your personal data, restriction of or objection to processing, and data portability. Where processing is based on consent, you may withdraw it at any time without affecting prior processing. To exercise any right, contact us through the contact form; we will respond within one month. You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP, cpdp.bg) or with the supervisory authority of your EEA country of residence.
9. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means. The VUAH preliminary assessment is an informational tool; its outputs are preliminary, are subject to the disclaimers shown alongside it, and any advisory engagement proceeds through human review and conversation.
10. Children
This website and our services are directed at organizations and professionals. We do not knowingly collect personal data from anyone under 18. If you believe a minor has submitted data to us, contact us and we will delete it.
11. Changes to this policy
We may update this policy as our services or legal requirements change. The date above reflects the latest revision; material changes will be indicated clearly on this page.