This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy
I agree

Privacy Policy

This policy explains how SofiaOffices.com handles personal data. It covers our website, our office at 66 Vitosha Blvd. in Sofia, and every service we provide: virtual office and registered address, office rental, company registration, legal work, accounting, payroll, and residence permit support.

At a glance:

  • We are a business services provider. Almost everyone whose data we hold is a client, a client's representative, a client's employee, or someone who contacted us.
  • Three areas carry most of the risk, so we describe them in detail: anti-money-laundering files, client mail received at our address, and payroll we run for client companies.
  • For payroll and most bookkeeping, we act on our clients' instructions. The client company is the controller (the one who decides why and how data is used) and we are the processor (the one who acts on those instructions). Section 2.6 explains what that means for you.
  • Some records we can't delete on request. Bulgarian law sets retention periods of 5, 10 and 50 years depending on the document. Section 6 lists each one and its legal source.
  • We don't sell personal data, we don't profile you, and no software decides anything about you.
  • You can reach us about any of this at [email protected].

Jump to: Who we are · What we do with personal data · Cookies · Who we share data with · International transfers · How long we keep data · Your rights · Do you have to provide data · Security and breaches · Automated decisions · Children · Changes · Contact and complaints

1. Who we are and what this policy covers

SofiaOffices.com is the controller of the personal data described in this policy, except where section 2 says we act as a processor for a client.

You can reach us here:

  • Address: 66 Vitosha Blvd., 4th floor, Sofia 1463, Bulgaria
  • Email: [email protected]
  • Telephone: +359 888 350 643
  • Office hours: Monday to Friday, 09:00 to 18:00

Our Sofia address is a staffed office with in-house accounting and legal departments. It isn't a mail-forwarding-only address. Full registration details of the operating entity behind the SofiaOffices.com brand are available on request at the contact address above.

We have not appointed a Data Protection Officer. Article 37(1) of the GDPR requires one in three cases only. Public authorities need one, and so do organisations whose core activity is large-scale regular monitoring of individuals, or large-scale processing of special-category or criminal-offence data.

None of those describes us. Privacy questions go to the contact details above and are handled by our legal department.

This policy covers both language versions of the site, the English pages and the Bulgarian ones. If the two ever differ on a point of substance, tell us and we'll fix the translation rather than argue about which version wins.

This policy is governed by Regulation (EU) 2016/679 (the GDPR) and the Bulgarian Personal Data Protection Act. Several other Bulgarian statutes decide what we must collect and how long we must keep it, and we name each one where it applies rather than referring vaguely to "legal requirements".

2. What we do with personal data

Each activity below states who the data is about, what we collect and why. It also gives our legal basis, the source where the data did not come from you, the retention period, and the recipients.

2.1 Website enquiries

  • Who: people who complete the contact form, email us, or telephone us.
  • Data: full name, business email, telephone number, and whatever you write in the message field. All four form fields are required. There is no newsletter signup, no live chat, no user account and no payment function on this website.
  • Purpose: to answer your enquiry and, if it leads somewhere, to prepare a quotation.
  • Legal basis: Article 6(1)(f), our legitimate interest in responding to business enquiries. Where your enquiry becomes a request for a specific quotation, Article 6(1)(b) also applies, because the work is a step before a contract.
  • Source: you.
  • Retention: 12 months from our last exchange, if the enquiry does not become a client relationship. If it does, the file moves under section 2.2.
  • Recipients: the relevant department internally, and our email provider (see section 4).

Our contact form uses a numeric image CAPTCHA that we host and serve ourselves. It isn't Google reCAPTCHA or hCaptcha, so solving it sends nothing to a third party.

2.2 Client onboarding and performing the contract

  • Who: clients who are individuals, and the directors, shareholders, employees and authorised representatives of corporate clients.
  • Data: name, position, business contact details, signature, correspondence with us, contract and billing details, and the instructions you give us.
  • Purpose: to deliver the service you engaged us for, whether that is a registered address, an office lease, company registration, legal advice, accounting, payroll or residence permit support.
  • Legal basis: Article 6(1)(b) where you contract with us personally. Article 6(1)(f) where our client is a company and we process the data of its people, our legitimate interest being the performance of that contract.
  • Source: you, your company, or public registers such as the Commercial Register.
  • Retention: see section 6. Contract records are kept for 5 years after the relationship ends, matching the general limitation period in Article 110 of the Obligations and Contracts Act.
  • Recipients: depends on the service, and section 4 lists the categories.

2.3 Anti-money-laundering identification and checks

This is the part where we have the least discretion, so it's worth reading even if you skip the rest.

Bulgarian law makes us an obliged entity. Article 4 of the Measures Against Money Laundering Act lists who must apply anti-money-laundering measures, and three of its items describe what we do. Item 13 covers accounting services and tax advice. Item 15 covers legal advice on transactions such as real estate transfers, managing funds, and raising capital for a company. Item 16(a) names the service directly: providing a registered address, a correspondence address or an office for the registration or functioning of a legal entity.

  • Who: clients, their authorised representatives, and their beneficial owners.
  • Data: identity document data including the document number, issuing authority and date, names, personal or national identification number, date and place of birth, citizenship, address, ownership and control structure, source of funds, and the results of screening for sanctions listings, adverse media, and politically exposed person status (whether someone holds or held a senior public office, which the law treats as higher risk).
  • Purpose: customer due diligence, ongoing monitoring, and reporting where the law requires it.
  • Legal basis: Article 6(1)(c), compliance with a legal obligation under the Measures Against Money Laundering Act and its implementing regulation. Where screening returns information about criminal convictions or offences, that is Article 10 data, and we process it because Bulgarian anti-money-laundering law authorises and requires the check.
  • Source: you, your representatives, public registers, and commercial screening databases.
  • Retention: 5 years. Article 67(1) of the act sets the period, and Article 67(2) starts it running from the date the business relationship ends, not from the date we collected the document. The Director of the Financial Intelligence Directorate at the State Agency for National Security can extend that period in writing by no more than two further years under Article 67(6).
  • Recipients: the Financial Intelligence Directorate, supervisory authorities and auditors. Article 68 requires us to store this material so that it can be produced to them on request, in the format and within the deadline they set.

One consequence is unusual enough to state plainly. If we ever report a suspicion about a transaction, we are forbidden from telling you. Article 80(1) of the act prohibits us from notifying a client or any third party that information has been disclosed under Articles 68, 72, 74, 76 to 78 or 88. Article 72(1) requires that report to be made before the transaction is carried out.

Two limits on that silence are worth knowing. It binds us towards you and towards third parties, but Article 80(2) lifts it towards our supervisory authority, so the regulator can always be told. And a request under section 7 of this policy will not reveal whether such a report exists. That's a legal duty rather than a choice we make, and every regulated provider in Bulgaria works under the same rule.

2.4 Mail and correspondence received at our address

Clients using our registered address or correspondence address service receive post at 66 Vitosha Blvd. So who is responsible for that post, us or the client? Our role splits in two, and the answer matters for your rights.

For the contents of client mail, we act as a processor on the client's documented instructions. The client company decides what happens to its correspondence. We don't decide to read, copy or act on it independently.

For our own record of what arrived and when, we act as a controller. We log the sender, the date of receipt, the type of item and its delivery, because we need that record to prove we delivered the service and because anti-money-laundering supervision can require it.

  • Who: our clients, and the individuals who send them post, including named senders at authorities, banks, courts and counterparties.
  • Data: sender name and address, addressee, postmark and delivery data, item type, and, where the client instructs us to scan or open items, the personal data contained in them.
  • Purpose: receiving, logging, notifying, forwarding and, on instruction, scanning correspondence.
  • Legal basis: Article 6(1)(b) or 6(1)(f) for the handling itself, and Article 6(1)(c) for the receipt log where anti-money-laundering rules require us to keep it.
  • Source: the senders, and postal and courier operators.
  • Retention: the receipt log follows the 5-year anti-money-laundering period. Scanned contents are kept only as long as the client instructs.
  • Recipients: the client, and the postal or courier operator used for forwarding.

If you sent post to a company at our address and want to know what we hold about you, write to us. We'll tell you what our own log contains. For anything inside the envelope we will refer you to the addressee company, because that company, not us, decides how its correspondence is used.

2.5 Filings with Bulgarian authorities

  • Who: clients, their representatives, their beneficial owners, and their employees.
  • Data: whatever the specific filing requires, which is set by the authority and not by us.
  • Purpose: submitting declarations, registrations and returns to the National Revenue Agency, the National Social Security Institute, the Registry Agency and other authorities.
  • Legal basis: Article 6(1)(c) for our own statutory duties. Where we file for a client company, we act as its processor and the legal basis is the client's.
  • Source: the client, and the client's employees through the client.
  • Retention: see section 6.
  • Recipients: the authority concerned.

2.6 Payroll and social security for client companies

When we run payroll for a client company, we don't decide anything about that company's employees. The employer decides who is on the payroll, what they are paid, and why. We process on documented instructions.

In GDPR terms the client company is the controller and SofiaOffices.com is the processor. Article 28 of the GDPR requires a written data processing agreement between us before that work starts. It covers the subject matter, duration, purposes, and the categories of data and data subjects. It also sets our obligations on security, sub-processors, assistance and deletion. We put that agreement in place with every payroll and bookkeeping client.

  • Who: employees and contractors of our client companies.
  • Data: names, personal identification number, address, bank account, position, salary, hours, leave, sick leave certificates, social security and tax data, and family circumstances where a statutory relief depends on them.
  • Purpose: calculating pay, making statutory deductions, and filing with the revenue and social security authorities.
  • Legal basis: the controller's, which is normally Article 6(1)(b) and Article 6(1)(c). Sick leave data is health data, and the employer relies on Article 9(2)(b), which permits processing needed to carry out obligations in employment and social security law.
  • Source: the employer, and the employee through the employer.
  • Retention: set by the employer and by statute. Payroll sheets carry a 50-year period, explained in section 6.
  • Recipients: the National Revenue Agency, the National Social Security Institute, and the employer's bank.

If you are an employee of one of our client companies and want to exercise a right, contact your employer. We will pass your request to them and assist them in answering it, which is what Article 28(3)(e) requires of us. We can't decide the request ourselves, because it isn't ours to take.

2.7 Residence permit and visa support

  • Who: applicants for Bulgarian type C and type D visas and residence permits, and their family members where the application covers them.
  • Data: passport data and copies of the relevant pages, visa and entry stamp data, address and proof of accommodation, evidence of means of subsistence, medical insurance documents, and a criminal record certificate.
  • Purpose: preparing and supporting an application to Directorate "Migration" of the Ministry of Interior or to a Bulgarian diplomatic mission.
  • Legal basis: Article 6(1)(b) for the service you engaged us for, and Article 6(1)(c) where we must supply specific documents. The criminal record certificate is Article 10 data. Bulgarian immigration law requires it from first-time applicants aged 18 and over, and that statutory requirement is what authorises us to handle it. We collect it to submit it, and we do not use it for any other purpose.
  • Source: you, and authorities in your country of nationality or residence.
  • Retention: 5 years after the engagement ends, unless a longer accounting or anti-money-laundering period applies to the same file.
  • Recipients: Directorate "Migration", Bulgarian diplomatic missions, and sworn translators where a document must be translated.

Medical insurance documents prove that cover exists. They aren't normally health data, because they don't say anything about your health. If an application ever requires an actual medical document, we will ask for your explicit consent under Article 9(2)(a) before we handle it. You can refuse without affecting the rest of our work.

2.8 Invoicing and statutory bookkeeping

  • Who: clients, and individuals named on invoices and payment records.
  • Data: billing name and address, tax identification data, bank details, invoice contents and payment records.
  • Purpose: issuing invoices, keeping the statutory accounts, and meeting our tax obligations.
  • Legal basis: Article 6(1)(c), under the Accountancy Act, the Tax-Insurance Procedure Code and the VAT Act.
  • Source: you.
  • Retention: see section 6.
  • Recipients: our bank, the National Revenue Agency, and auditors where an audit applies.

Our invoices are issued in euro. Bulgaria adopted the euro on 1 January 2026, at the fixed conversion rate of EUR 1 to BGN 1.95583 set by the Council of the European Union on 8 July 2025. Records created before that date stay in lev, so older documents in your file will show lev amounts. We don't retrospectively convert them (and nobody should).

2.9 Visitors to our office

  • Who: people who visit 66 Vitosha Blvd.
  • Data: name, company, the person visited, and the date and time of the visit, where a visit is recorded.
  • Purpose: building access and security.
  • Legal basis: Article 6(1)(f), our legitimate interest in knowing who is in the premises.
  • Retention: 3 months.

2.10 Business development and follow-up

  • Who: business contacts at existing and prospective corporate clients.
  • Data: name, position, company, business contact details, and our correspondence.
  • Purpose: following up on an enquiry or a past engagement, and telling business contacts about services relevant to them.
  • Legal basis: Article 6(1)(f), our legitimate interest in direct marketing to businesses, which Recital 47 of the GDPR recognises. Every message carries an opt-out and we act on it immediately.
  • Retention: until you object, and in any case no more than 24 months after our last contact.

Bulgarian e-commerce law treats business and consumer addresses differently, and it is worth knowing which one protects you. Article 6(4) of the Electronic Commerce Act bans unsolicited commercial messages to consumers without prior consent.

For legal entities, Article 6(2) and 6(3) run the other way. The Consumer Protection Commission maintains a register of company email addresses that do not want such messages, and sending to an address on that register is prohibited. We check that register, and we honour a direct objection whether or not the address appears on it.

3. Cookies and similar technologies

A cookie is a small file a website stores on your device. Some are needed for the site to work. Others measure how the site is used.

These are the cookies this website sets:

  • PHPSESSID. Set by SofiaOffices.com. Keeps your session while you move between pages and lets the contact form work. Strictly necessary. Expires when you close your browser.
  • _ga. Set by Google Analytics. Distinguishes one visitor from another. Analytics, not strictly necessary. Lasts up to 400 days.
  • _ga_C6XLQ6L3V6. Set by Google Analytics for this website's measurement property. Keeps session state for the statistics. Analytics, not strictly necessary. Lasts up to 400 days.

Our contact page embeds a Google Map. Loading that map sends your IP address to Google, which is how any embedded map works. If you'd rather not load it, our address is written out in plain text on the same page and in section 1 of this policy. No map required.

We do not use advertising or social media tracking. There is no Meta Pixel, no Google Ads tag, no remarketing pixel and no cross-site advertising identifier on this website.

The legal rule in Bulgaria sits in Article 4a of the Electronic Commerce Act, headed "Storage of information in the user's terminal equipment and access to it". It permits storage or access only where you have been given, in the words of the provision, "clear and comprehensive information" under Article 13 of the GDPR, and a way to refuse. Two categories are exempt under Article 4a(4): storage needed to transmit a communication, and storage needed for a service you explicitly requested. PHPSESSID falls in the second category, which is why it is set without asking you.

Analytics cookies are not exempt. They need your consent, and consent under Article 4(11) and Article 7 of the GDPR has to be a freely given, specific, informed and unambiguous act. In practice that means four things:

  • Nothing non-essential is set before you choose.
  • Refusing is as easy as accepting.
  • Silence, scrolling and continued browsing are not consent.
  • Withdrawing is as easy as giving.

You can change your choice at any time through the cookie settings on this site, and you can delete or block cookies in your browser settings. Blocking PHPSESSID will stop the contact form from working. Blocking the analytics cookies changes nothing at all for you. Nothing breaks and nothing nags you about it afterwards.

4. Who we share personal data with

We do not sell, rent or trade personal data. We share it only where a service, a contract or a law requires it, and only with these categories of recipient:

  • Bulgarian authorities. The National Revenue Agency, the National Social Security Institute, the Registry Agency, Directorate "Migration" of the Ministry of Interior, and the Financial Intelligence Directorate of the State Agency for National Security for anti-money-laundering reports.
  • Banks and notaries, where an engagement involves opening an account, a notarised signature or a deed.

Providers in the fifth category act as our processors under written contracts that meet Article 28 of the GDPR. They may use the data only on our instructions.

5. Transfers outside the European Economic Area

Our own operations are in Bulgaria and we do not transfer client files abroad as a matter of course.

Three of the providers above are US companies whose processing can involve access from outside the EEA: Cloudflare, Google Workspace and Google Analytics. Where the provider is certified under the EU-US Data Privacy Framework, those transfers rest on the European Commission's adequacy decision for it, Implementing Decision (EU) 2023/1795 of 10 July 2023. Otherwise they rest on Standard Contractual Clauses under Article 46(2)(c) of the GDPR.

The status of that framework is worth stating accurately, because it is contested. The General Court of the European Union dismissed a challenge to the adequacy decision on 3 September 2025, in case T-553/23. An appeal against that judgment is pending before the Court of Justice as case C-703/25 P. The decision remains in force unless the Commission repeals it or the EU courts annul it.

Sometimes a document has to go to an authority or counterparty outside the EEA on your instructions. A criminal record certificate requested from your country of nationality is the usual example. That transfer happens under Article 49(1)(b), because it is necessary to perform the contract you asked us to carry out.

You can ask us for a copy of the safeguards for any transfer by writing to [email protected].

6. How long we keep personal data

Bulgarian law fixes most of these periods, so they are not ours to shorten. Where a statute sets the period, we name it. Where we chose the period ourselves, we say so, because you are entitled to know which is which.

  • Payroll sheets: 50 years. Article 12(1)(1) of the Accountancy Act, counted from 1 January of the reporting period following the one the records relate to. Article 5(10) of the Social Insurance Code sets the same period and extends it to employment contracts, appointment and reassignment orders, termination orders, and orders for unpaid leave exceeding 30 working days in a calendar year.
  • Accounting registers and statements: 10 years, including documents needed for tax control, audit and subsequent financial inspections. Article 12(1)(2) of the Accountancy Act, counted the same way. Article 38(1) of the Tax-Insurance Procedure Code mirrors it.
  • Anti-money-laundering files: 5 years from the date the business relationship ends, under Article 67(1) and 67(2) of the Measures Against Money Laundering Act. The Director of the Financial Intelligence Directorate can extend this in writing by up to two further years under Article 67(6).
  • Contracts and engagement records: 5 years after the relationship ends. Article 110 of the Obligations and Contracts Act sets that as the general limitation period for claims. Some claims, including rent and contractual penalties, run out after 3 years under Article 111, so this period is the outer limit rather than the only one.
  • Other accounting records: 3 years. Article 12(1)(3) of the Accountancy Act.
  • Unconverted website enquiries: 12 months from the last exchange. Our own choice, not a statutory period.
  • Business development contacts: 24 months from last contact, or until you object. Our own choice.
  • Office visitor records: 3 months. Our own choice.
  • Analytics data: up to 400 days, which is how long the cookies last.

Fifty years for a payroll sheet sounds absurd until you ask what it's actually for. It's the evidence a pension gets calculated from, decades after the employer has gone. That's why the law won't let anyone, including us, agree to a shorter period.

The periods for payroll and accounting records start from 1 January of the year after the one the record belongs to, not from the date on the document. A payroll sheet for March 2026 therefore starts its 50 years on 1 January 2027.

When a period expires we delete or destroy the records. Two exceptions apply. The Accountancy Act can require records to pass to the National Archive Fund. Payroll sheets of a dissolved company without a successor go to the National Social Security Institute, under Article 12(4) of that act.

7. Your rights

Under Articles 15 to 22 of the GDPR you can ask us to:

  • Give you access to the personal data we hold about you, and a copy of it.
  • Correct data that is wrong or incomplete.
  • Erase data, where one of the grounds in Article 17 applies.
  • Restrict processing while a dispute about accuracy or legal basis is resolved.
  • Port data you gave us, in a machine-readable format, where the processing is based on consent or contract and is automated.
  • Object to processing based on our legitimate interests. If you object to direct marketing we stop, with no balancing test and no questions.
  • Withdraw consent at any time, where we relied on consent. Withdrawing does not affect processing that already happened.

Two limits apply, and we'd rather set them out here than have you discover them in our reply.

Erasure does not reach records we are legally required to keep. Article 17(3)(b) of the GDPR says the right does not apply where processing is necessary to comply with a legal obligation. A payroll sheet, an anti-money-laundering file and a statutory accounting record all fall in that category. We can stop using such a record for anything beyond the legal purpose, and we can correct it if it is wrong, but we cannot delete it before its period expires.

Where we act as a processor, the decision is not ours. Requests about payroll or bookkeeping data belonging to a client company go to that company. We will forward your request and help the client answer it.

One more thing you're entitled to ask for. This policy leans on legitimate interests in five places, and that basis only works if our interest genuinely outweighs your privacy. We write that assessment down. Ask for the balancing test behind any of the five and we'll send it.

To exercise a right, write to [email protected] or to our postal address. We answer within one month of receiving the request, as Article 12(3) requires. If the request is complex or you have sent several, we can extend that by two further months, and we will tell you within the first month if we do. We don't charge for this. We may ask for proof of identity where we can't otherwise be sure who's asking.

8. Do you have to provide your data

It depends on what you're asking us to do, and Article 13(2)(e) of the GDPR requires us to tell you which.

  • Website enquiries. Entirely voluntary. Nothing follows from not filling in the form except that we cannot reply.
  • Entering a contract. Contractually necessary. Without the identification and billing data we cannot open an engagement.
  • Anti-money-laundering identification. A statutory requirement. If you decline to provide the identification data or we cannot complete due diligence, the law does not permit us to establish or continue the relationship, and we must refuse or end it.
  • Payroll and filings. A statutory requirement of the employer or the taxpayer. Missing data means the filing cannot be made and statutory deadlines are missed.
  • Residence permit support. The authority sets the document list. An incomplete application is refused by Directorate "Migration", not by us.

9. Security and personal data breaches

We apply technical and organisational measures appropriate to the risk, as Article 32 of the GDPR requires. In general terms these cover access control on a need-to-know basis and encryption of data in transit. Paper files are held in locked physical storage. Staff are under confidentiality obligations, the providers listed in section 4 are vetted, and access to client files is logged and backed up.

If a personal data breach is likely to result in a risk to your rights, we notify the Commission for Personal Data Protection under Article 33. The deadline is 72 hours from the moment we become aware of it. Where the breach is likely to result in a high risk to you, we tell you as well, under Article 34, without undue delay and in plain language. Where we act as a processor, we notify the client company without undue delay so it can meet its own deadline, as Article 33(2) requires.

10. Automated decision-making and profiling

We take no decisions about you by automated means alone, and we do not profile you. Article 22 of the GDPR therefore does not apply to anything in this policy.

Anti-money-laundering screening deserves a word, because screening software is involved. A database check can return a possible match against a sanctions list, a politically exposed person list or adverse media. That result is a flag, not a decision. A person in our legal department reviews every flag and decides what follows. No client relationship is refused or ended by software.

11. Children

Our services are sold to businesses and to adults acting for businesses. This website is not directed at children and we do not knowingly collect their data through it. Children's data reaches us in one situation only: where a residence permit application covers an applicant's family members, or where a statutory payroll relief depends on an employee's children. In both cases the data comes from the adult applicant or employer and is used only for that filing.

12. Changes to this policy

We review this policy at least once a year, and whenever we add a service, change a provider, or a relevant law shifts under us.

The version number and date at the top of this page change with every revision. Where a change materially affects how we handle your data, we tell affected clients directly by email rather than relying on you noticing a new date here. Earlier versions are available on request.

13. Contact us, or complain

Start with us. Most problems turn out to be a mix-up about which role we're in, and those are quick to sort out.

  • Email: [email protected]
  • Post: 66 Vitosha Blvd., 4th floor, Sofia 1463, Bulgaria
  • Telephone: +359 888 350 643

If you are not satisfied, you can complain to the Bulgarian supervisory authority:

  • Commission for Personal Data Protection
  • 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
  • Email: [email protected]
  • Telephone: +359 2 915 3519
  • Website: www.cpdp.bg

Bulgarian law puts a deadline on that complaint. Article 38(1) of the Personal Data Protection Act requires it within 6 months of the day you learned of the infringement, and in any event within 2 years of the infringement itself. Missing either deadline is one of the most common reasons a complaint never gets examined, so don't sit on it. You can also take the matter to the courts under Article 79 of the GDPR, either instead of or after a complaint.

Questions we are asked about this policy

Can I ask SofiaOffices.com to delete my data after I close my company?

Partly. Marketing data and enquiry records go straight away on request. The anti-money-laundering file can't go for 5 years from the date the relationship ended, under Article 67(2) of the Measures Against Money Laundering Act, and accounting records run to 10 years. Closing the company starts those clocks rather than stopping them.

Who is the controller for payroll data, my company or SofiaOffices.com?

Your company. You decide who's employed and what they're paid, so you're the controller and we're your processor under Article 28. That's why we sign a data processing agreement before payroll work starts, and why an employee's access request goes to you rather than to us.

Does SofiaOffices.com read the mail sent to my registered address?

Only if you tell us to. We log the sender, the date and the item type for every delivery, because we need that record to show the service was performed. Opening or scanning what's inside happens only where your package includes it or you ask for it.

Will you tell me if you report me to the authorities?

No, and the law doesn't let us. Article 80(1) of the Measures Against Money Laundering Act forbids us from telling a client or a third party that a disclosure has been made to the Financial Intelligence Directorate. Every regulated provider in Bulgaria is under the same prohibition, so treat anyone who promises otherwise with suspicion.

Does this website use advertising trackers?

No. The site sets one session cookie and two Google Analytics cookies, all three listed in section 3. There's no Meta Pixel, no Google Ads tag and no remarketing pixel. The one thing worth knowing is the Google Map on the contact page, which sends your IP address to Google when it loads.

How do I get the registration details of the company behind SofiaOffices.com?

Ask us at [email protected] and we'll send them. They're also filed with the Bulgarian Commercial Register, which anyone can search for free.

Related pages. Our terms and conditions govern the services themselves, and the virtual office and registered address pages explain the mail handling in section 2.4.

Payroll services and accountancy services cover the work where we act as your processor, and visa and residence support covers the applications in section 2.7. Questions about any of it go through our contact page.