The PhD Club
  • Home
  • Doctoral programmes
    • Overview
    • Leadership
    • Information management
    • Business communications
    • Computer sciences
    • National security
  • Learning platform
  • Mentorship
  • Courses
    • Research proposal
    • Research topic
    • Dissertation structure
    • Research methodology
  • Blog
The PhD Club
  • Home
  • Doctoral programmes
    • Overview
    • Leadership
    • Information management
    • Business communications
    • Computer sciences
    • National security
  • Learning platform
  • Mentorship
  • Courses
    • Research proposal
    • Research topic
    • Dissertation structure
    • Research methodology
  • Blog

Privacy Policy

1. Controller and Contact Details

The controller of your personal data under Article 4(7) GDPR is:

  • Company: EDUEARTH, Ltd.
  • Registered Seat & Management Address: 10 Nikolay V. Gogol Street, apt. 9, Yavorov Quarter, Sredets District, 1124 Sofia, Republic of Bulgaria
  • UIC (ЕИК): 203715136
  • Email: team@thephdclub.com
  • Website: thephdclub.com

We operate this website and the services offered through it, referred to below as "we", "us", "our", "EDUEARTH", or "The PhD Club". 

Data Protection Officer

We have not appointed a Data Protection Officer, as the criteria in Article 37(1) GDPR do not apply to our processing activities. Inquiries regarding this policy or data protection may be sent to the contact details above and will be addressed by our team member responsible for data protection.


2. Scope and Legal Framework

This policy applies to personal data processed through thephdclub.com, contact forms, and newsletters.

We process personal data in accordance with:

  • Regulation (EU) 2016/679 (GDPR)
  • Bulgarian Personal Data Protection Act (ЗЗЛД)
  • E-Commerce Act (ЗЕТ), Art. 4a (device storage and cookie access)
  • Electronic Communications Act (ЗЕС) (unsolicited commercial messages)
  • Consumer Protection Act (ЗЗП)
  • Accountancy Act and Tax and Social Insurance Procedure Code (ДОПК) (retention of financial records)

Where this policy conflicts with the GDPR, the GDPR prevails. This policy is published in English and Bulgarian. In case of discrepancies, the Bulgarian version governs.


3. Personal Data We Process

Personal data includes any information relating to an identified or identifiable natural person (Art. 4(1) GDPR). You may browse our website without disclosing your identity. Beyond automated server logs (see Section 3.1) and cookies (see Section 5), we process only data you voluntarily provide.

3.1 Data Collected Automatically

When accessing our site, server log files record:

  • IP address of the requesting device
  • Date, time, and time zone offset
  • Requested page or file, HTTP protocol, and status code
  • Data volume transferred
  • Referring URL, browser type, operating system, and language

We process log data to deliver site functionality, maintain system security, and investigate cyber incidents or misuse.

3.2 Data You Provide

  • Inquiries (Form, Email, Phone, Video Call): Name, email address, phone number, and message content.
  • Newsletter Subscription: Email address, signup date/time, and IP address.
  • Platform Account (when active): Username, hashed password, login timestamps, and platform submissions.

We do not request or process special categories of data under Article 9 GDPR (such as health data or biometric data). Please do not submit such data to us. 

We do not sell personal data or share it with third parties for their own marketing purposes.


4. Purposes and Legal Bases

We process personal data under the following legal bases:

  • Website Operation and Security: Server logs and strictly necessary cookies based on Art. 6(1)(f) GDPR (legitimate interest in a secure, functional site).
  • Answering Inquiries: Contact details and message content based on Art. 6(1)(f) GDPR (legitimate interest to process incoming requests).
  • Newsletter and Direct Marketing: Email address and engagement data based on Art. 6(1)(a) GDPR (consent for specific purposes) and applicable regulations.
  • Analytics and Advertising: Usage data and advertising identifiers based on Art. 6(1)(a) GDPR (consent for specific purposes).
  • Legal Claims: Relevant processing records based on Art. 6(1)(f) GDPR (legitimate interest in defending legal rights).

Consent may be withdrawn at any time with future effect without fee or detriment (Art. 7(3) GDPR). Legitimate interest processing may be objected to under Article 21 GDPR.


5. Cookies and Similar Technologies

Cookies and similar technologies (pixels, local storage) read or store data on your device. Under Art. 4a ЗЕТ and Directive 2002/58/EC, non-essential cookies require explicit prior consent. Strictly necessary cookies essential for website operation are set by default.

We use four categories of cookies: strictly necessary, functional, analytics, and advertising/remarketing. Non-essential cookies are consented to only upon active selection in the banner displayed on our website. Pre-ticked boxes or continued scrolling do not constitute consent.

Preferences can be modified or revoked at any time through browser settings.

More information on cookie usage can be found in our Cookie Policy.


6. Analytics and Advertising

6.1 Google Analytics 4

We use Google Analytics 4 (provided by Google Ireland Limited) strictly upon user consent to analytics cookies. Google Analytics 4 collects device identifiers, page views, file downloads, and user interactions. Google Analytics 4 does not log or store full IP addresses; IP data is used transiently for geolocation and discarded. Event-level data is retained for 14 months before automatic deletion.

6.2 Google Signals and Advertising Features

With consent for advertising cookies, we utilize Google Analytics advertising features (remarketing, demographic reports) and Google Signals. Google Signals aggregates cross-device usage data from users logged into Google accounts who have enabled ads personalization. We do not merge personally identifiable information with aggregated advertising data.

6.3 Opt-Out Options

  • Update consent via the "Cookie Settings" link in the website footer.
  • Install the Google Analytics Opt-out Browser Add-on.
  • Adjust Google account settings at adssettings.google.com.
  • Use industry opt-out tools such as youronlinechoices.eu.


7. Recipients and International Transfers

7.1 Data Recipients

We share data only where necessary with:

  • Processors: Hosting providers, IT infrastructure partners, email/newsletter platforms, and learning platform providers bound by Art. 28 GDPR processing agreements.
  • Professional Advisors: Accountants, auditors, and legal counsel bound by confidentiality obligations.
  • Public Authorities: Tax authorities, courts, or supervisory bodies (CPDP) where required by legal obligation.

7.2 International Transfers

Data transfers outside the European Economic Area (EEA), such as to the United States, rely on valid Chapter V GDPR safeguards:

  • Adequacy decisions under Art. 45 GDPR (including certified entities under the EU-US Data Privacy Framework).
  • European Commission Standard Contractual Clauses (SCCs) under Art. 46(2)(c) GDPR, 

These Chapter V GDPR safeguards are supplemented by technical safeguards (encryption, pseudonymization) where required. 

Copies of applicable transfer mechanisms are available upon request to team@thephdclub.com.


8. Data Retention

Personal data is retained only as long as necessary for its processing purpose or legal obligation, after which it is deleted or anonymized:

  • Server Log Files: 30 days (extended only for active security investigations).
  • Communication & Inquiries: 3 years from last contact.
  • Newsletter Subscription Data: Retained until consent is withdrawn.
  • Proof of Newsletter Consent: 3 years following consent withdrawal to demonstrate Art. 7(1) GDPR compliance.
  • Cookie Consent Records: 12 months.
  • Analytics Event Data: 14 months.
  • Accounting and Tax Records: Up to 10 years pursuant to Bulgarian tax legislation.
  • Platform Account Data: Retained for the duration of the active user account and deleted or anonymized within 30 days following an account deletion request or 24 months of continuous account inactivity, except where transaction records must be retained for up to 10 years under the Accountancy Act.

9. Security and Breach Notification

We implement technical and organizational measures under Article 32 GDPR, including TLS encryption, access controls, regular backups, and processor confidentiality obligations.

In the event of a personal data breach posing a risk to rights and freedoms, we notify the Commission for Personal Data Protection (CPDP) within 72 hours under Article 33 GDPR. High-risk breaches will be communicated to affected data subjects without undue delay (Article 34 GDPR).


10. Your Rights

Under the GDPR, you hold the following rights:

  • Access (Art. 15): Request confirmation and copies of processed data.
  • Rectification (Art. 16): Correct inaccurate or incomplete data.
  • Erasure (Art. 17): Request data deletion when statutory grounds apply.
  • Restriction (Art. 18): Limit processing during accuracy or lawfulness disputes.
  • Portability (Art. 20): Receive personal data in a structured, machine-readable format.
  • Objection (Art. 21): Object to legitimate interest processing or direct marketing.
  • Withdrawal of Consent (Art. 7(3)): Revoke consent at any time.

To exercise your rights, submit your requests to team@thephdclub.com. We respond within 1 month (2 months for complex or multiple requests). Identity verification may be required.


11. Regulatory Complaints and Legal Remedies

If you believe our data processing violates regulations, please contact us first. You also have the right to lodge a complaint with the Bulgarian supervisory authority:

Commission for Personal Data Protection (КЗЛД)

  • Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
  • Telephone: +359 2 915 3 518
  • Email: kzld@cpdp.bg
  • Website: www.cpdp.bg

Under Article 38(1) of the Bulgarian Personal Data Protection Act (ЗЗЛД), a complaint must be lodged within 6 months of your becoming aware of the violation, but no later than 2 years from its commission. Complaints submitted electronically must be signed with a Qualified Electronic Signature (QES).

You may also lodge a complaint in your EU member state of residence or work (Art. 77 GDPR) or seek judicial remedies under Art. 79 GDPR. Under Bulgarian law, you cannot pursue identical complaints simultaneously before the CPDP and a court.


12. Specific Disclosures and Policy Updates

12.1 Age Limit

Our services are directed at adults. Under Art. 25c ЗЗЛД, the legal age for digital consent in Bulgaria is 14 years. We do not knowingly collect personal data from individuals under 14 without parental consent.

12.2 Automated Decision-Making

We do not engage in automated decision-making or profiling producing legal or similarly significant effects under Article 22 GDPR.

12.3 External Links

Our site may link to third-party websites. We are not responsible for their privacy practices.

12.4 Policy Updates

Material changes to this policy will be announced on our website.


Effective Date: 6 October 2026

  • Privacy Policy
  • Cookie Policy

© 2014–2026 – The PhD Club – All rights reserved

This website uses cookies.

By continuing to use this site, you accept our use of cookies. Read our Cookie Policy and Privacy Policy to learn more about how we use cookies.

DeclineAccept