# Information on Data Export and Provider Switching Procedures (Data Act Compliance)

This page sets forth the information required pursuant to Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data, and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (the **"Data Act"**), concerning:

1) a detailed specification of all categories of data and digital assets that may be transferred during the provider switching process, including, at a minimum, all exportable data;
2) an exhaustive specification of the categories of data specific to the internal operation of the service that are excluded from exportable data;
3) information regarding the available procedures for switching data processing service providers and transferring data, including available switching methodologies, transfer formats, and any technical or other limitations known to the service provider;
4) data structures and data formats, as well as the applicable standards and open interoperability specifications;
5) information concerning the jurisdiction(s) governing the information and communication technology infrastructure used for data processing;
6) a general description of the technical, organisational, and contractual measures implemented by the Provider to prevent unlawful international access by governmental authorities to non-personal data.

> [!NOTE]
> The rights described herein shall apply if and to the extent that the Service constitutes a data processing service within the meaning of the Data Act. To the extent that the provision of the Service does not fall within the definition of a data processing service under the Data Act, the Customer shall not be entitled to such rights.


## 1. Categories of Exportable Data and Digital Assets

### Account Information

**Data provided during registration and profile configuration:**

- first name, surname
- email address
- telephone number
- billing details
- company registration number, VAT identification number

**Additional data available for export:**

- time zone, language preference, country
- registration IP address, date of registration
- user agent/browser information, most recent IP address
- alternative authentication methods
- country-specific permission settings for global messaging
- records of consent to terms and conditions


### Contacts and Address Books

All telephone numbers and associated data (including names and custom fields) uploaded by the Customer to BulkGate.

**Additional data available for export:**

- contact groups
- interaction records
- performance metrics
- order records
- application settings
- blacklist entries
- opt-out list entries
- business page configuration


### Campaign and Message History

Content of transmitted messages, recipient lists for individual campaigns, and detailed delivery reports directly attributable to the Customer's account activity.

> [!WARNING]
> BulkGate retains this data for a period of twelve (12) months only. Data older than this retention period cannot be exported.


### Settings and Configuration

Account configuration data, including API keys, sender ID settings, and message templates.

**Data available for export:**

- inbox configuration
- API rate limits
- low credit notification settings
- message templates
- URL shortener configurations
- shortened link records


## 2. Categories of Non-Exportable Data

The following categories of data are deemed specific to the internal operation of the Service and are therefore excluded from exportable data, as disclosure thereof would constitute a risk of breach of the Provider's proprietary trade secrets:

**Routing and Telecommunications Partner Information**

Information regarding the telecommunications operators and routing paths utilised for message delivery, including pricing structures and performance metrics of such partners. This information constitutes proprietary trade secrets of BulkGate.


## 3. Available Data Transfer Procedures

The data export process from BulkGate shall be conducted as follows:

1) **Submission of Request** — The Customer shall submit an export request directly through their BulkGate user account (via "Settings > Data Protection"). This method provides automatic identity verification. Alternatively, requests may be submitted via email to privacy@bulkgate.com; however, additional identity verification procedures shall be required in such cases.

2) **Request Processing** — Upon receipt of a valid request, the system shall automatically initiate the data export preparation process, or a BulkGate representative shall process the request manually.

3) **Data Delivery** — Upon completion of the export preparation, the Customer shall receive an email notification containing a secure download link for the archived data (.zip file), accessible directly from their account. For security purposes, the download link shall remain valid for a limited period (e.g., seven (7) days).


## 4. Data Structures and Formats

BulkGate provides data exports in the following formats:

**CSV (.csv)** — Suitable for tabular data, including contact lists, address books, and delivery reports. CSV is a universally accepted format that facilitates seamless import into a wide range of systems.

**JSON (.json)** — Appropriate for structured data with complex hierarchies, including account settings, API configurations, message templates, and detailed campaign structures.

All exported files (CSV, JSON) shall be consolidated into a single .zip archive to facilitate efficient download.


## 5. Technical and Other Known Limitations

Whilst BulkGate endeavours to ensure that provider switching and data portability processes are as seamless as possible, the following limitations may apply:

**Service-Specific Data Structures and Semantics**

Certain data elements (e.g., internal telemetry, proprietary models, or platform-specific logic) are intrinsically linked to the BulkGate platform and are not designed for export or utilisation outside our operating environment. Such data may not qualify as "exportable data" under applicable legislation and are therefore excluded from standard export procedures.

**Third-Party Service Dependencies**

Where the Customer utilises integrations with third-party tools, data processed by such tools may be subject to the respective third party's own export restrictions, format limitations, or API availability constraints. BulkGate cannot warrant the portability of data processed exclusively within third-party environments.

**Performance and Capacity Constraints**

High-volume or frequent bulk export requests may be subject to rate limiting, scheduling requirements, or batch processing protocols to maintain Service stability and performance for all customers.

**Customer Configuration and Target Environment Compatibility**

Successful data import into the target environment (whether an alternative service provider or on-premises system) is contingent upon the technical capabilities, configuration parameters, and data model of such target environment. BulkGate bears no responsibility for, and has no control over, any limitations inherent to the target system.


## 6. ICT Infrastructure and Applicable Jurisdiction

All data is stored within the Czech Republic and is subject to Czech jurisdiction.


## 7. Safeguards Against Unlawful International Governmental Access

BulkGate is committed to ensuring that any international access by governmental authorities to non-personal data stored within the European Union is conducted in strict compliance with applicable EU and Member State legislation. We have implemented a comprehensive framework of technical, organisational, and contractual measures designed to prevent unauthorised access and to challenge any access requests that may contravene EU law or national legislation.


### Technical Measures

**Logical and Physical Environment Segregation**

Data stored within the EU is hosted exclusively in EU-based data centres and is logically segregated from other operational environments.

**Access Controls and Principle of Least Privilege**

Access to production systems is strictly controlled, comprehensively logged, and restricted to authorised personnel on a role-based, need-to-know basis.

**Encryption**

Data is protected both in transit and at rest using industry-standard encryption protocols, to the extent permitted by the applicable infrastructure and services deployed.

*These measures mitigate the risk of foreign governmental authorities obtaining direct access to data through infrastructure providers without recourse to appropriate legal channels.*


### Organisational and Contractual Measures

**Contractual Obligations of Service Providers**

We require our cloud and infrastructure providers to comply with applicable EU legislation and to notify us—to the extent legally permissible—of any legally binding requests from governmental authorities for data access. Where applicable, Standard Contractual Clauses (SCCs) have been executed between BulkGate and the relevant infrastructure providers.

**Internal Request Handling Procedures**

In the event that BulkGate receives a request from a governmental authority outside the EU/EEA seeking access to data stored within the EU, BulkGate shall:

- conduct a thorough assessment of the legal basis underlying such request;
- verify whether the request is compatible with EU law and applicable national legislation; and
- challenge or oppose the request where BulkGate reasonably determines that it conflicts with applicable legal requirements or exceeds the requesting authority's jurisdiction.

**Customer Transparency**

Unless prohibited by law, BulkGate shall notify affected customers without undue delay of any such requests and the data concerned, thereby enabling customers to take appropriate measures to protect their interests.
