Last updated: 19 July 2026 · Language: English (primary). This notice governs the website tissoftware.dev and the TIS Software product ("Build with AI", "Ask AI" and related account features).
Introduction
TIS Software is an AI-native software development studio. This Privacy Notice explains what personal data we collect when you visit tissoftware.dev, sign in to an account, use the AI features, or contact us; why we collect it; the legal basis on which we rely; who we share it with; how long we keep it; and the rights you have under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Bulgarian Personal Data Protection Act (Закон за защита на личните данни, "ЗЗЛД"). The "Build with AI" engine, the "Ask AI" chat, user accounts and paid subscriptions are all live services today; this notice describes the data flows that actually take place now.
1. Who we are (controller)
The controller responsible for processing your personal data is ТИС КОМЕРСИАЛ ЕООД / TIS COMMERSIAL EOOD (trading under the brand "TIS Software"), Unified Identification Code (ЕИК / UIC) 206011226, registered seat: ул. „Дилянка" № 41, ж.к. „Театър на мечтите", р-н Северен, 4003 Пловдив, България. Managing director: Тино Радостинов Цанев. Data-protection contact e-mail: contact@tissoftware.dev. Because the controller is established in the EU (Bulgaria), we are not required to designate an EU representative under Art. 27 GDPR. A Data Protection Officer is not mandatory at our current scale (Art. 37 GDPR); privacy requests are handled by management at the contact address above.
2. What personal data we collect
When you use the Site and the product, we process the following categories of personal data:
- Contact / "Build with AI" enquiry form — when you submit the form, we collect the name, e-mail address, and free-text project description you provide, delivered to us by e-mail. Please avoid including sensitive personal data in the free-text field.
- Account registration and sign-in data — your e-mail address and authentication data. Sign-in is by a one-time e-mail code, or by Google sign-in (OAuth); if you use Google, we receive the basic profile fields Google returns for sign-in (e-mail, name, and a stable user identifier). We do not store passwords.
- Prompts and instructions you enter — the text you send to the "Build with AI" builder and to the "Ask AI" chat, together with related inputs (chosen model, language).
- AI-generated code, previews and app artefacts — the output the AI returns to you (HTML/code, chat replies, project versions, hosted-app metadata), which we store against your account so you can return to your projects.
- Personalization memory — to make the AI features more helpful, we may automatically derive and store a small set of durable facts and preferences from your prompts and chats (for example, the kind of projects you build, your audience, or a style you prefer), and use them to personalise future responses. You can view and delete these at any time on your account page. We do not use them for advertising and do not sell them.
- Subscription and payment status — your plan, credit balance and usage, plus billing metadata returned by our payment processor (customer ID, subscription ID, invoice status, last-four card digits and card country as provided by Stripe). We never see or store your full card number.
- Language preference — stored locally in your browser (localStorage); it stays on your device and is not transmitted to us as an identified record.
- Server / CDN and security logs — our infrastructure and security provider (Cloudflare) automatically records standard technical data such as IP address, date/time, the resource requested, referrer, and browser/device information (user agent), to deliver the site, ensure security, and prevent abuse. Cloudflare Turnstile is used on the sign-in step for bot protection.
- Error diagnostics — our error-monitoring provider (Sentry) receives technical error data (stack traces, route, browser/device information) so we can investigate failures. It is configured to scrub personal data and prompt content from reports.
We operate user accounts (sign-in by one-time e-mail code or Google). We process subscription payments through Stripe and we never see or store your full card number — Stripe handles card data as a PCI-compliant payment processor.
3. Why we collect it and our lawful basis (Art. 6 GDPR)
| What we process | Purpose | Lawful basis (Art. 6(1) GDPR) |
|---|---|---|
| Contact / enquiry form (name, e-mail, description) | Respond to your enquiry, take steps at your request prior to a contract | (b) pre-contract steps; (f) legitimate interest in answering enquiries |
| Account & authentication data | Create and secure your account, verify your e-mail, let you sign in | (b) performance of a contract; (f) security |
| Prompts and generated output | Operate the "Build with AI" and "Ask AI" features you asked for | (b) performance of a contract |
| Subscription & payment status | Provide and bill the paid plan, manage credits, apply refunds | (b) performance of a contract; (c) legal obligation (accounting/tax) |
| Personalization memory | Personalise and improve the AI features you use | (f) legitimate interest in a helpful, personalised service — you may object, and can delete entries anytime |
| Server / CDN logs, Turnstile, Sentry | Deliver the site, prevent abuse, investigate errors, keep the service secure | (f) legitimate interest in security, integrity and reliability |
| Language preference (localStorage) | Remember your interface language | (f) legitimate interest in a functioning site (strictly necessary) |
| Non-essential cookies or marketing e-mails (if introduced) | Analytics or service updates | (a) consent, withdrawable |
Where we rely on legitimate interests, we have balanced them against your rights; you may object (section 8). Where we rely on consent, you may withdraw it at any time.
4. How we use your data
To receive and respond to project enquiries; to create and secure your account and let you sign in; to operate the "Build with AI" and "Ask AI" features, including sending your prompt to an AI model provider and returning the generated output to you; to manage your subscription, credits and refunds; to deliver, maintain, secure and improve the site; to detect abuse and fraud; and to comply with legal obligations (e.g. accounting/tax). We do not sell your personal data and we do not use your prompts or generated output to build advertising profiles.
5. Who we share it with
We share data only with service providers who process it on our behalf and on our instructions (processors under Art. 28 GDPR), each bound by a data-processing agreement.
- Google (Gemini API), Anthropic (Claude API) and OpenAI (GPT / ChatGPT API) — AI sub-processors for the "Build with AI" and "Ask AI" features. The model you select determines which provider receives your prompt; your prompt and related inputs are transmitted to that provider to generate the code / chat reply you asked for. All three are live model providers today.
- Google (Sign-in / OAuth) — where you choose Google sign-in, Google authenticates you and returns basic profile fields.
- Stripe — payment processor for subscriptions and refunds; handles card data as a PCI-compliant processor. We receive billing metadata only, never the full card number.
- Supabase — application backend: authentication, database, edge functions and file storage.
- Resend — sending transactional e-mails (one-time sign-in codes, receipts, service messages).
- Cloudflare — DNS, e-mail routing, CDN, bot/abuse protection (including Turnstile on the sign-in step).
- Sentry — error monitoring; configured to scrub personal data and prompt content from reports.
- Our external accountant / bookkeeper — where an enquiry becomes a paying engagement, contact and billing details are shared for statutory bookkeeping and tax.
We may add, replace, update or remove AI model providers and models over time — including new third-party providers and any AI models we develop or operate ourselves. Where we do, we will update this notice with the specific provider and safeguards, and — where the model is user-selectable — the choice is visible in the product before you spend anything on it.
5.1 Authorities and legal claims
We may disclose data where legally required, or to establish/exercise/defend legal claims, or in a business reorganisation or succession.
5.2 International transfers
Some providers (Cloudflare, Supabase, Stripe, Resend, Google, Anthropic, OpenAI, Sentry) may process data outside the EEA, including in the United States. Such transfers are safeguarded under Chapter V GDPR, in particular the European Commission's Standard Contractual Clauses (SCCs) and/or the provider's certification under the EU–U.S. Data Privacy Framework, plus supplementary measures where required. Request a copy at contact@tissoftware.dev.
6. How long we keep it (retention)
- Contact / enquiry form: kept only as long as needed to handle it and any resulting engagement, and thereafter for a limited period to defend potential claims; unconverted enquiries are deleted once no longer needed (guideline: 12 months).
- Account, prompts, generated output and projects: kept while your account is active, so you can return to your work. If you delete a project it is soft-deleted and purged from active storage within a reasonable period; if you close your account we delete or anonymise the associated data, except records we must keep for legal reasons.
- Subscription and billing records: retained for the statutory period under the Bulgarian Accountancy Act — as a rule up to 10 years.
- Personalization memory: kept while your account is active; removed when you delete the entries or when you close your account.
- Server / CDN security logs and Sentry error data: retained for a short period (guideline: up to 12 months), then deleted or anonymised.
- Language preference: on your device until you clear browser storage; not retained server-side.
7. How we keep it safe
We take technical and organisational measures appropriate to the risk (Art. 32 GDPR): transport encryption (TLS/HTTPS), access controls, row-level security on the database, bot/abuse protection at the network edge (Cloudflare + Turnstile), data minimisation, error-report scrubbing, and contractual security obligations on our processors. No system is perfectly secure, but we work to protect your data against unauthorised access, loss or misuse.
8. Your rights
Under the GDPR and ЗЗЛД you have the right to: access (Art. 15); rectification (Art. 16); erasure (Art. 17); restriction (Art. 18); data portability (Art. 20); object to processing based on legitimate interests, and to direct marketing at any time (Art. 21); and withdraw consent where we rely on it (Art. 7(3)). To exercise a right, contact contact@tissoftware.dev; we may verify your identity first and will respond within the statutory time limit (as a rule, one month). Right to complain: you may lodge a complaint with the Bulgarian supervisory authority, the Commission for Personal Data Protection (Комисия за защита на личните данни, КЗЛД), Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd., www.cpdp.bg — or with the supervisory authority in your EU country of residence.
9. Cookies
The site currently uses only strictly necessary storage (such as the localStorage entry remembering your language preference, the session token that keeps you signed in, and the Cloudflare Turnstile challenge on sign-in). These do not require consent. We do not currently use analytics or marketing cookies. If we introduce any non-essential cookies in future, we will request consent through a cookie banner beforehand. See our Cookie Notice for details.
10. AI-interaction disclosure (EU AI Act Art. 50)
The "Build with AI" and "Ask AI" features are AI systems: they use third-party generative-AI models to produce code, previews and chat replies from your text prompts. In line with the transparency obligation under Article 50 of the EU AI Act (Regulation (EU) 2024/1689), which applies to this type of AI interaction from 2 August 2026, we make clear within the product that you are interacting with an AI system. When you use these features, your prompts and related inputs are sent to and processed by a third-party AI model provider (Google / Gemini, Anthropic / Claude or OpenAI / GPT, depending on the model you select) to generate the output. AI-generated output can contain errors and should be reviewed before use. The model powering each feature — and its per-request credit cost — is shown to you inside the product before you spend anything.
11. Changes to this notice
We may update this notice from time to time — e.g. when we add a processor or a new AI model provider. The current version is the one published on tissoftware.dev. Where changes are material we will take reasonable steps to notify you. The English version is the reference version.
12. How to contact us
ТИС КОМЕРСИАЛ ЕООД / TIS COMMERSIAL EOOD (brand: TIS Software) · ЕИК 206011226 · Plovdiv, Bulgaria · contact@tissoftware.dev