MAS IMPORT EOOD

Government & Public Authority Data Request Policy

Applies to: CreateFor.Me and ShopThePost
Policy owner: MAS IMPORT EOOD
Version: 1.0
Effective date: 10 August 2026

1. Purpose

MAS IMPORT EOD is committed to protecting personal data processed through CreateFor.Me and ShopThePost, including data received through third-party platforms such as Meta and Instagram.

This policy establishes the procedure MAS IMPORT EOOD will follow if a government, law-enforcement agency, national-security authority, regulatory body, or other public authority requests access to personal data under the company’s control.

2. Review of legality

All government or public-authority requests for personal data must be reviewed before any information is disclosed.

MAS IMPORT will assess whether:

  • the requesting authority has appropriate legal authority;
  • the request is valid and sufficiently specific;
  • the request follows applicable legal procedures;
  • MAS IMPORT EOOD is legally required to comply; and
  • the requested disclosure is permitted under applicable data-protection law.

MAS IMPORT will not voluntarily disclose personal data merely because a public authority requests it.

Where appropriate, professional legal advice may be obtained before responding.

3. Challenging unlawful or excessive requests

MAS IMPORT reserves the right to question, reject, narrow, or challenge requests that it reasonably considers unlawful, invalid, excessively broad, disproportionate, or outside the requesting authority’s jurisdiction.

Where legally and reasonably possible, MAS IMPORT will seek clarification or request that the authority narrow an excessive request before any data is disclosed.

4. Data minimization

If MAS IMPORT is legally required to disclose personal data, only the minimum amount of information reasonably necessary to satisfy the valid legal request will be provided.

A valid request for specific information will not be treated as authorization to disclose unrelated account information, Platform Data, authentication credentials, access tokens, customer information, or other data.

Credentials, access tokens, encryption keys, passwords, and security information will receive particular protection and will not be disclosed unless disclosure is specifically and lawfully required.

5. Documentation

MAS IMPORT will maintain an internal record of public-authority requests where legally permitted.

The record should include, as applicable:

  • date the request was received;
  • requesting authority;
  • jurisdiction;
  • nature and legal basis of the request;
  • categories of information requested;
  • person responsible for reviewing the request;
  • assessment of the request’s validity;
  • whether clarification or narrowing was requested;
  • whether the request was challenged;
  • final response;
  • categories of data disclosed, if any;
  • date of disclosure; and
  • relevant legal reasoning or professional advice.

Records will be protected against unauthorized access and retained only as long as reasonably necessary for legal, security, accountability, and compliance purposes.

6. User notification

Where legally permitted and reasonably appropriate, MAS IMPORT may notify an affected user that their information has been requested.

Notification may be delayed or withheld where MAS IMPORT is legally prohibited from notifying the user or where notification would conflict with a binding legal requirement.

7. Platform Data

This policy also applies to Platform Data received through third-party services, including Meta and Instagram APIs.

Access to such data must remain limited to what is necessary to operate the applicable CreateFor.Me or ShopThePost functionality.

A public-authority request does not override MAS IMPORT’s obligation to protect Platform Data unless MAS IMPORT determines that disclosure is legally required.

8. Security

Any approved disclosure must be performed using a reasonably secure method appropriate to the sensitivity of the information.

MAS IMPORT will not intentionally provide unnecessary passwords, API credentials, encryption keys, access tokens, or other security credentials as part of a disclosure.

9. Responsibility

MAS IMPORT EOOD is responsible for applying this policy.

Anyone acting on behalf of MAS IMPORT who receives a government or public-authority request concerning user information must ensure that the request is reviewed under this policy before responding.

10. Review

This policy should be reviewed periodically and updated when necessary to reflect changes in applicable law, MAS IMPORT’s services, or its data-processing activities.

Approved by: MAS IMPORT EOOD
Effective: 10 August 2026


With this policy actually adopted and followed by MAS IMPORT EOOD, your Meta requests-4 answers can accurately be:

  • ✓ Required review of the legality of these requests
  • ✓ Provisions for challenging requests considered unlawful
  • ✓ Data minimization
  • ✓ Documentation of requests, responses, legal reasoning and actors involved

Keep a dated copy internally with your ShopThePost/CreateFor.Me compliance documentation. You don’t need to publish this page on CreateFor.Me unless you decide you want it public.

This is an operational policy rather than legal advice; for binding Bulgarian/EU compliance requirements, a lawyer or DPO can review the final policy.