Privacy Policy

Last updated: 28 June 2026 · Version 1.0

1. Who we are

This Privacy Policy explains how Booka LTD (in Bulgarian: „Буука" ЕООД), a company registered in Bulgaria, trading as Alter Nine, collects, uses, stores and shares personal data when you visit www.alternine.co (the "Website") or use the Alter Nine booking platform and related services (together, the "Services").

  • Controller: Booka LTD / „Буука" ЕООД
  • Registered office: ul. General Kiselov 10, 9000 Varna, Bulgaria
  • Company ID (ЕИК): 208363525
  • Contact: hello@mail.alternine.co
  • Supervisory authority: Commission for Personal Data Protection (CPDP / КЗЛД), 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria — www.cpdp.bg

We act as a data controller for personal data we collect directly about visitors to the Website, our business clients (account holders) and prospects. We act as a data processor for personal data that our business clients upload to or generate within the Alter Nine booking platform about their own end customers — in that case the business client is the controller and a separate Data Processing Agreement (DPA) governs that relationship.

2. Scope of this Policy

This Policy applies to:

  • Visitors to the Website and any of its subdomains and marketing pages;
  • Prospects who request demos, contact us, or sign up for newsletters or trial accounts;
  • Account holders ("Business Clients") — service businesses subscribing to the Alter Nine platform;
  • End customers ("Bookers") who book appointments through a Business Client's Alter-Nine-powered website — but only in respect of data we process directly as controller (for example, browser-level analytics on alternine.co). Data Bookers provide while booking with a Business Client is processed by us on behalf of that Business Client under a DPA, and the Business Client's own privacy policy governs the primary use of that data.

3. What personal data we collect

3.1 Information you provide

  • Account & billing: name, business name, email, phone, billing address, VAT number, payment details (handled by our payment processor — we do not store full card numbers);
  • Communications: messages you send us via email, contact forms, chat or social channels, including the content and any attachments;
  • Demo / sales requests: name, email, company, role, country, and anything you choose to write in free-text fields.

3.2 Information collected automatically

  • Device & connection: IP address (truncated where possible), browser type and version, operating system, device type, screen size, language, referring URL;
  • Usage: pages viewed, time on page, navigation paths, clicks, interactions with embedded media, timestamps;
  • Performance: page load metrics, Core Web Vitals (LCP, INP, CLS), error reports;
  • Cookies & similar technologies: see Section 7.

3.3 Information from third parties

  • Authentication providers if you sign in via a third-party identity provider;
  • Payment processors (transaction status, last 4 digits of card, currency, country);
  • Publicly available business information used to verify legitimacy of subscription accounts.

3.4 Sensitive data

We do not knowingly collect special categories of personal data (e.g. health, religion, political opinions). Where Business Clients in regulated sectors (e.g. clinics) process such data through the platform, they do so as controller under a DPA and are responsible for the corresponding legal basis.

4. Why we use your data & legal bases

PurposeLegal basis (GDPR Art. 6)
Providing the Website and Services; account creation and loginPerformance of a contract (Art. 6(1)(b))
Processing payments, invoicing, debt collectionContract; legal obligation (Art. 6(1)(b), (c))
Customer support and responding to enquiriesContract; legitimate interests (Art. 6(1)(b), (f))
Security, fraud prevention, abuse detection, audit logsLegitimate interests; legal obligation (Art. 6(1)(f), (c))
Service improvement and analyticsConsent (analytics cookies) or legitimate interests for aggregated data
Marketing emails to existing customers about similar servicesLegitimate interests with opt-out (Art. 6(1)(f); ePrivacy "soft opt-in")
Marketing to prospects, newslettersConsent (Art. 6(1)(a))
Tax, accounting and statutory record keepingLegal obligation (Art. 6(1)(c))
Defending or asserting legal claimsLegitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we balance our interests against your rights and freedoms. You may object to such processing at any time (see Section 9).

5. How long we keep your data

CategoryRetention
Account dataFor the life of the account + 12 months after closure
Billing & accounting records10 years (Bulgarian Accountancy Act, Art. 12)
Support tickets and emails24 months from last contact
Marketing consents and withdrawals5 years from withdrawal (to evidence compliance)
Analytics data (Google Analytics)14 months (default GA4 retention)
Server & security logs90 days, longer if part of an active investigation
BackupsRolling 30 days, then overwritten

6. Who we share data with

We do not sell personal data. We share it only with the categories of recipients below, and only as needed for the purposes described in Section 4.

  • Business Clients — when you book through a website powered by Alter Nine, the relevant Business Client receives your booking data as controller;
  • Sub-processors — vetted vendors that process data on our instructions (see Section 7);
  • Professional advisors — lawyers, auditors, accountants, insurers, bound by confidentiality;
  • Authorities — when we are legally required to disclose data (court order, valid subpoena, tax authority requests);
  • Successors — in connection with a merger, acquisition, financing or sale of assets, subject to confidentiality safeguards.

7. Cookies, analytics and sub-processors

The Website uses cookies and similar technologies. Non-essential cookies (including analytics) load only after you grant consent through our cookie banner. We implement Google Consent Mode v2, which means tracking is denied by default until you actively accept.

7.1 Cookies and tracking technologies we use

Name / providerPurposeTypeRetention
an_cookie_consent_v1 (first-party)Stores your cookie choiceStrictly necessary12 months
_ga, _ga_* (Google Analytics 4)Audience measurement, traffic source analysisAnalytics — consent requiredUp to 13 months
Vercel Speed Insights (first-party beacon)Core Web Vitals telemetry; no cross-site identifiersPerformance — anonymousPer request
Session / authentication cookiesKeep you signed in to your accountStrictly necessarySession or up to 30 days

7.2 Sub-processors

ProviderServiceLocation / safeguards
Google Ireland Ltd. (Google Analytics 4)Web analyticsEU / USA — Standard Contractual Clauses + EU-US Data Privacy Framework
Vercel Inc.Hosting, edge delivery, Speed InsightsUSA / global edge — SCCs + DPA
Resend (Resend, Inc.)Transactional email delivery (account, booking notifications)USA — SCCs + DPA
Stripe Payments Europe Ltd.Payment processing, fraud screeningEU (Ireland) — independent controller for payment data

A current and complete list of sub-processors is available on request at hello@mail.alternine.co. We notify Business Clients in advance of material sub-processor changes through the platform or by email.

7.3 Managing your cookie preferences

You can withdraw or change your consent at any time by clearing the an_cookie_consent_v1 entry in your browser storage, which will redisplay the banner, or by adjusting your browser settings to block cookies. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

8. International data transfers

Some of our sub-processors are located outside the European Economic Area (mainly in the United States). When personal data is transferred outside the EEA, we rely on one or more of the following safeguards under GDPR Chapter V:

  • European Commission adequacy decisions (e.g. EU-US Data Privacy Framework);
  • Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) with supplementary measures where required;
  • Encryption in transit (TLS) and at rest where supported by the provider.

A copy of the relevant safeguards can be requested at hello@mail.alternine.co.

9. Your rights under GDPR

Subject to applicable conditions and exemptions, you have the right to:

  • Access — obtain confirmation of whether we process your data and a copy of it (Art. 15);
  • Rectification — request correction of inaccurate or incomplete data (Art. 16);
  • Erasure — request deletion in defined circumstances (Art. 17);
  • Restriction — limit processing during disputes about accuracy or lawfulness (Art. 18);
  • Portability — receive your data in a structured, commonly used, machine-readable format (Art. 20);
  • Object — to processing based on legitimate interests, including profiling, and at any time to direct marketing (Art. 21);
  • Withdraw consent — at any time, without affecting prior lawful processing (Art. 7(3));
  • Not be subject to solely automated decisions producing legal or similarly significant effects (Art. 22). We do not currently carry out such automated decision-making.

How to exercise your rights

Email hello@mail.alternine.co with the subject "GDPR request". We will respond within one month, extendable by a further two months for complex requests, in which case we will inform you of the extension within the first month. Requests are free of charge; manifestly unfounded or excessive requests may attract a reasonable fee or be refused.

If you booked an appointment with one of our Business Clients, please address requests about that booking data directly to the Business Client, who is the controller. We will assist them as processor.

Right to complain

You may lodge a complaint with the Bulgarian Commission for Personal Data Protection (КЗЛД), 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, www.cpdp.bg, kzld@cpdp.bg, or with the data protection authority in your country of residence.

10. Security

We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, including:

  • TLS encryption in transit and encrypted storage at rest;
  • Hashed and salted passwords; strong-password requirements for administrative access;
  • Principle of least privilege, role-based access control, periodic access reviews;
  • Vulnerability scanning, dependency monitoring and timely patching;
  • Audit logs, intrusion detection, rate limiting and brute-force protection;
  • Vendor due diligence and contractual data protection terms (DPAs, SCCs);
  • Documented incident response and breach notification procedures.

In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and the CPDP within 72 hours of becoming aware of the breach, in accordance with GDPR Articles 33–34.

11. Children

The Website and Services are not directed at children under 14. We do not knowingly collect personal data from children without parental consent. If you believe a child has provided us with personal data, please contact us and we will delete it.

12. Marketing communications

Where required, we will ask for your consent before sending marketing emails. Existing customers may receive emails about similar services we provide, in line with the ePrivacy "soft opt-in", with an opt-out in every message. You can unsubscribe at any time using the link in any email or by contacting us.

13. Automated decision-making and profiling

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you. We may use aggregated, non-identifying analytics to improve the Website and platform.

14. Third-party links

The Website may contain links to third-party sites and services. We are not responsible for their privacy practices. Please review their privacy policies before submitting any personal data.

15. Changes to this Policy

We may update this Policy from time to time. The "Last updated" date at the top reflects the most recent revision. If changes are material, we will notify account holders by email or through a prominent notice on the Website at least 14 days before they take effect.

16. Contact us

Booka LTD / „Буука" ЕООД
ЕИК 208363525
ul. General Kiselov 10, 9000 Varna, Bulgaria
Email: hello@mail.alternine.co
Website: www.alternine.co

For data protection matters, please use the subject line "Privacy" or "GDPR request" so we can route your message correctly.