GET SCORED™ — AI-SEO

Privacy Policy

GET SCORED™ (operated by EVA DAVA EOOD) · Last updated: 27 July 2026

In plain terms: We're a B2B practice. We only get your personal data when you book a call, email us, or visit the site (basic technical data). We use it to reply and run our services, we don't sell it, and we don't use it to train AI. We use Cal.com (booking), Vercel (hosting) and Google Workspace (email). We keep contact/booking data ~24 months. You can access, correct or delete your data any time — email ceo@evadava.com. The full policy is below.

1. Introduction and Scope

This Privacy Policy explains how EVA DAVA EOOD, operating under the trade name GET SCORED™ ("GET SCORED", "we", "us" or "our"), collects, uses, shares and protects personal data in connection with our website at https://getscored.eu (the "Website") and the related services we provide, including our booking and consultation services.

We are committed to protecting your personal data and respecting your privacy. This Policy applies to personal data we process about business contacts, prospective clients, clients, and visitors to our Website. Because we are established in the European Union and offer services to individuals located in the European Economic Area (EEA), our processing of personal data is governed by Regulation (EU) 2016/679 (the General Data Protection Regulation, or "GDPR") and applicable Bulgarian data protection law.

Our services are directed at businesses and their representatives (B2B). We do not offer a consumer-directed or child-directed service.

This Policy does not apply to third-party websites, platforms or services that we do not operate, even where we link to them. Those third parties have their own privacy policies, which we encourage you to review.

2. Data Controller

The data controller responsible for your personal data is:

EVA DAVA EOOD (trading as GET SCORED™)
Registered address: ul. "Gen. Gurko" No. 9, et. 1, Burgas 8000, Bulgaria
Company number (EIK): 207945177  ·  VAT number: BG207945177
Email for privacy requests: ceo@evadava.com
Website: https://getscored.eu

We have not appointed a statutory Data Protection Officer (DPO), as we are not required to do so under Article 37 GDPR. For all data protection matters, questions and requests concerning your personal data, please contact us at ceo@evadava.com.

3. What Personal Data We Collect

CategoryExamples
Contact detailsYour name, email address, company or organisation name, and job role or title.
Booking dataInformation you provide when scheduling a call or meeting with us, such as the meeting date and time, time zone, and any notes, questions or context you add to the booking.
CommunicationsThe content of emails, messages and other correspondence you send to us, and our replies, together with related metadata (such as dates and times).
Usage and technical dataInformation collected automatically when you visit the Website, such as your IP address, browser type and version, device and operating system information, referring pages, and the pages you view. This data is collected by our hosting provider and through strictly necessary (essential) cookies.

We do not intentionally collect special categories of personal data (such as data revealing health, ethnicity, religion or political opinions), and we ask that you do not provide such data to us.

Children's data. Our Website and services are intended for businesses and professional users. We do not knowingly collect or process personal data relating to children. If you believe a child has provided us with personal data, please contact us at ceo@evadava.com and we will take appropriate steps to delete it.

4. How We Collect Personal Data

(a) Directly from you. We receive personal data that you provide when you book a call or meeting with us through our scheduling tool at cal.com/evadava/intro, when you email us, or when you otherwise communicate with us or engage our services.

(b) Automatically. When you visit the Website, certain usage and technical data (such as your IP address and browser information) is collected automatically by our hosting infrastructure and through essential cookies necessary for the Website to function and remain secure.

(c) From publicly available business sources. For business-to-business outreach we collect limited professional contact details — a work email address, a name, a job title and the employing company — from sources the company itself has published, such as its own website, its published team or contact pages, its job listings, or public professional directories. We record the exact URL at which each address was published and the date we collected it. We do not buy contact lists, and we do not collect personal or private addresses.

5. Purposes and Lawful Bases for Processing

Under Article 6 GDPR, we must have a lawful basis for each processing activity. We rely on the following:

(a) To respond to your enquiries, deliver our services, and take pre-contract steps. When you contact us or book a call, we process your contact, booking and communications data to respond to you, arrange and hold meetings, and provide the services you request.
Lawful basis: performance of a contract or steps taken at your request prior to entering into a contract — Article 6(1)(b) GDPR.

(b) To operate, maintain and secure the Website. We process usage and technical data to run the Website, ensure it functions correctly, prevent and detect fraud or misuse, protect against security threats, and keep our systems safe.
Lawful basis: our legitimate interests — Article 6(1)(f) GDPR.

(c) To contact businesses about our services (B2B outreach). We send a small number of individually written emails to named professionals at companies we believe our service is relevant to, using work addresses those companies have published themselves. Each message states who we are, why we are writing to that specific company, and how to stop hearing from us. We do not send bulk newsletters on this basis, and we stop immediately on request.
Lawful basis: our legitimate interests in promoting a business-to-business service — Article 6(1)(f) GDPR. Where local law requires prior consent for such messages, we do not send them at all: we currently exclude Germany, Austria, Switzerland, Denmark and Italy for this reason, and in the United Kingdom we write only to incorporated entities.

(d) To send an ongoing newsletter or marketing list. If you ask to receive our updates, we process your address on the basis of your consent, which you may withdraw at any time without affecting the lawfulness of processing before withdrawal.
Lawful basis: consent — Article 6(1)(a) GDPR.

(e) To comply with legal obligations. We may process personal data where necessary to comply with obligations under applicable law, such as accounting, tax and record-keeping requirements, or to respond to lawful requests from competent authorities.
Lawful basis: compliance with a legal obligation — Article 6(1)(c) GDPR.

Legitimate-interests balancing. Where we rely on legitimate interests, we have carried out a balancing assessment.

For operating the Website (paragraph (b)): the processing is limited to running and protecting the Website, involves no profiling or advertising, and we consider it does not override your rights.

For B2B outreach (paragraph (c)): we process only professional contact details that the employing company has chosen to publish, in a professional context, about a service relevant to the recipient's stated role. The volume is low and each message is individually written rather than broadcast. We hold no special-category data, we build no behavioural profile, and we act on any objection immediately and permanently. Set against a reasonable expectation that a published work address may receive relevant professional correspondence, we consider our interest is not overridden. You can ask us for a copy of this assessment.

You have the right to object to processing based on legitimate interests, as described in Section 11. Where you object to direct marketing, we stop without exception and add your address to a permanent suppression record kept for that purpose alone.

6. Cookies

By default, our Website uses only strictly necessary (essential) cookies — those required for the Website to operate correctly and securely. Essential cookies do not require your consent under applicable law.

We do not currently use analytics, advertising, tracking or other non-essential cookies. If, in the future, we introduce any non-essential cookies or similar technologies (for example, analytics), we will request your consent before setting them, and we will provide clear information and controls to enable you to accept or decline them.

7. Recipients and Processors

We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.

We share personal data only with trusted service providers who process it on our behalf ("processors"), under written data-processing agreements that require them to process personal data only on our documented instructions and to apply appropriate security measures. Our current processors are:

We may also disclose personal data where required to do so by law, to comply with legal process, or to protect our rights, safety or property or those of others.

8. International Data Transfers

Some of our processors are located outside the EEA, including in the United States (for example, Vercel Inc. and Google LLC). Where we transfer personal data outside the EEA, we ensure that appropriate safeguards are in place as required by Chapter V of the GDPR. Depending on the recipient, these safeguards may include:

You may request further information about the transfer safeguards we rely on, or a copy of the relevant mechanism, by contacting us at ceo@evadava.com.

9. Data Retention

We keep personal data only for as long as necessary for the purposes for which it was collected, including to provide our services, maintain our business records, and comply with legal obligations.

As a general rule, we retain contact and booking data for approximately 24 months from our last meaningful interaction with you, unless a longer period is required or permitted by law (for example, to meet accounting or tax obligations, or to establish, exercise or defend legal claims). When personal data is no longer needed, we securely delete it or irreversibly anonymise it.

10. If We Contacted You and You Never Gave Us Your Details

This section is the notice required by Article 14 GDPR, which applies when personal data is obtained from a source other than the person it concerns. If you received an email from us and never gave us your address, this explains where it came from.

We are not obliged to keep you on any list to exercise these rights, and using them costs you nothing.

11. Your Rights Under the GDPR

Subject to the conditions and exceptions set out in the GDPR, you have the following rights in relation to your personal data:

To exercise any of these rights, please contact us at ceo@evadava.com. We will respond in accordance with applicable law, normally within one month. We may need to verify your identity before acting on your request.

Right to lodge a complaint. If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. In Bulgaria, this is the Commission for Personal Data Protection (CPDP) (Комисия за защита на личните данни):

Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
Website: https://www.cpdp.bg
Email: kzld@cpdp.bg

You may also lodge a complaint with the supervisory authority in your country of residence or place of the alleged infringement.

12. Data Security

We implement reasonable technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. These measures include using reputable service providers, access controls, and encryption in transit where appropriate. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.

13. Automated Decision-Making

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. When we make changes, we will revise the "Last updated" date at the top of this Policy. Where changes are material, we will take appropriate steps to inform you. We encourage you to review this Policy periodically.

15. Contact Us

If you have any questions about this Privacy Policy or how we handle your personal data, or if you wish to exercise your rights, please contact us:

EVA DAVA EOOD (GET SCORED™)
Email: ceo@evadava.com
Address: ul. "Gen. Gurko" No. 9, et. 1, Burgas 8000, Bulgaria