PERSONAL DATA PROCESSING POLICY
Information about the personal data controller:
Srednogorska Roza Ltd. is a company registered in the Commercial Register with reg no: 200488053, and with registered office: Bunovo, 2074, Mirkovo Municipality, Sofia region, e-mail: firstname.lastname@example.org
We process your personal data on the following grounds:
Any contracts concluded between us and you in order to fulfil our obligations;
Explicit consent from you - the purpose is indicated for each specific case;
In case of an obligation under law.
In the following paragraphs, you will find information about the processing of your personal data depending on the basis on which we process them.
FOR PERFORMANCE OF A CONTRACTOR IN THE CONTEXT OF PRE-CONTRACTUAL RELATIONS
We process your personal data in order to fulfil the contractual and pre-contractual obligations and to enjoy the rights under the contracts concluded with you.
Purposes of processing:
· establishing your identity;
· management and execution of your request and execution of a concluded contract;
· preparing and sending an invoice for the services you use with us;
· keeping correspondence in connection with orders, processing requests, reporting problems, etc.
· preparation of a user profile;
Based on the contract concluded between us and you, we process information about the type and content of the contractual relationship, as well as any other information related to the contractual relationship, including:
· personal contact details - contact address, email, phone number;
· identification data - the three names, unique civil number or personal number of a foreigner, permanent address;
· Data on the orders made through the user profile;
· e-mail, letters, information about your requests for troubleshooting, complaints, requests, grievances;
· credit or debit card information, bank account number or other banking and payment information in connection with the payments made;
The processing of the specified personal data is obligatory for us so that we can conclude the contract with you and fulfil it.
We may provide your personal data to third parties, and our main goal is to offer you quality, fast and comprehensive service.
We provide personal data to the following categories of recipients (data controllers):
· postal operators and courier companies;
· persons performing consulting services in various fields.
We delete the data collected on this basis 5 years after the termination of the contractual relationship, regardless of whether due to the expiration of the contract, cancellation or other grounds. The term is determined by the 5-year limitation period for possible claims under the contract.
FOR FULFILLMENT OF REGULATORY OBLIGATIONS
The law may provide for an obligation for us to process your personal data. In these cases, we are obliged to perform the processing, such as:
· obligations under the Anti-Money Laundering Measures Act;
· fulfilment of obligations in connection with the distance selling, the sale outside the commercial site provided for in the Consumer Protection Act;
· providing information to the Consumer Protection Commission or third parties provided for in the Consumer Protection Act;
· providing information to the Commission for Personal Data Protection in connection with obligations provided for in the legislation for personal data protection;
· obligations provided for in the Accounting Act and the Tax and Social Security Procedure Code and other related normative acts, in connection with the keeping of lawful accounting;
· provision of information to the court and third parties, in a framework of proceedings before a court, in accordance with the requirements of the normative acts applicable to the proceedings;
· age verification when shopping online.
The data collected in accordance with an obligation provided by law are deleted after the obligation for collection and storage is fulfilled or ceases to exist. For example:
· under the Accounting Act for storage and processing of accounting data (11 years),
· obligations to provide information to the court, competent state authorities, etc. grounds provided for in the current legislation (5 years).
When there is an obligation for us by law, it is possible for us to provide your personal data to the competent state body, natural or legal person.
AFTER YOUR CONSENT
We process your personal data on this basis only after your explicit, unambiguous and voluntary consent. We will not foresee any adverse consequences for you if you refuse to process personal data.
Consent is a separate basis for the processing of your personal data and the purpose of the processing is stated in it and is not covered by the purposes listed in this policy. If you give us the relevant consent and until its withdrawal or termination of any contractual relationship with you, we prepare suitable proposals for products/services.
On this basis, we only process data for which you have given us your express consent. The specific data are determined for each individual case. Usually, the data include:
On this basis, we may provide your data to marketing agencies and third parties.
Concessions granted may be withdrawn at any time. Withdrawal of consent does not affect the performance of contractual obligations. If you withdraw your consent to the processing of personal data in any or all of the ways described above, we will not use your personal data and information for the purposes set out above.
We delete the data collected on this basis at your request or 1 year after their initial collection.
PROCESSING OF ANONYMIZED DATA
We process your data for statistic purposes, ie for analyzes in which the results are only summary and therefore the data is anonymous. It is not possible to identify a specific person from this information.
How we protect your personal data
To ensure adequate data protection of the company and its customers, we apply all necessary organizational and technical measures provided for in the Personal Data Protection Act. For maximum security in the processing, transmission and storage of your data, we may use additional security mechanisms such as encryption, pseudonymization and more.
Each user of the site enjoys all rights to personal data protection under Bulgarian law and European Union law.
Each user has the right to:
· Awareness (in connection with the processing of his personal data by the administrator);
· Access to your own personal data;
· Correction (if the data is inaccurate);
· Deletion of personal data (right to be "forgotten");
· Restricting the processing by the controller or the processor of personal data;
· Portability of personal data between individual administrators;
· Objection to the processing of his personal data;
· The data subject has the right not to be the subject of a decision based solely on automated processing, including profiling, which has legal consequences for the data subject or similarly affects him significantly;
· Right to judicial or administrative protection in case the data subject's rights have been violated.
The user may request deletion if one of the following conditions are true:
· Personal data is no longer needed for the purposes for which it was collected or otherwise processed;
· The user withdraws his consent on which the data processing is based and there is no other legal basis for the processing;
· The data user objects to the processing and there are no legal grounds for the processing to take precedence;
· Personal data has been processed illegally;
· Personal data must be deleted in order to comply with a legal obligation under Union law or the law of a Member State that applies to the controller;
· Personal data has been collected in connection with the provision of information society services to children and the consent has been given by the parent responsible for the child.
The user has the right to restrict the processing of his personal data by the administrator when:
· Dispute the accuracy of personal data. In this case, the restriction of processing is for a period that allows the administrator to verify the accuracy of personal data;
· The processing is illegal, but the User does not want the personal data to be deleted, but instead requires restricting their use;
· The administrator no longer needs the personal data for the purposes of processing, but the User requires them for the establishment, exercise or protection of legal claims;
· Objects to the processing pending verification of whether the legal grounds of the administrator take precedence over the interests of the User.
Right of portability
The data subject has the right to receive personal data concerning him and which he has provided to the controller, in a structured, widely used and machine-readable format and has the right to transfer this data to another controller without hindrance from the controller. data are provided when the processing is based on consent or a contractual obligation and processing are carried out in an automated manner. When exercising its right to data portability, the data subject shall also have the right to receive a direct transfer of personal data from one controller to another where this is technically feasible.
Right to object
Users have the right to object to the controller against the processing of their personal data. The controller of personal data shall be obliged to terminate the processing, unless he proves that there are convincing legal grounds for the processing, which take precedence over the interests, rights and freedoms of the data subject, or for the establishment, exercise or protection of legal claims. In the event of an objection to the processing of personal data for the purposes of direct marketing, the processing should be stopped immediately.
Complaint to the supervisory authority
Each user has the right to file a complaint against illegal processing of his personal data to the Commission for Personal Data Protection or to the competent court.