PRIVACY POLICY
This document contains the Personal Data Security Policy (“Policy”) and is related to the General Terms and Conditions, but is not an integral part of them, as it does not regulate rights and obligations. Instead, its purpose is to explain to users what personal data we process, in what manner, for what purpose, and what the applicable security measures are. It also provides information regarding the rights that you—our customers and users—have in relation to the processing of personal data by us. In the event of changes to the Policy, the updates will be published here.
Effective from: August 1, 2024
Your privacy is extremely important to us. This security policy discloses what personal data we collect from you through our mutual interactions and how we use that data.
DATA CONTROLLER
Bulgarian Rose Plc, UIC 115009344, VAT No. BG 115009344, with registered office and address for management and correspondence: Karlovo, Industrial Zone, Bulgarian Rose Plc building, contact telephone: +359 33 59 53 28, e-mail: contact@bulgarianrose.bg (hereinafter referred to for brevity as "Bulgarian Rose Plc", "We", "online store", "Site", "Website", "Controller") is a controller of data, including personal data, regarding information collected or provided while browsing the website www.bulgarianrose.bg or when making a purchase through it, as well as when browsing or purchasing goods or services through our Facebook page (collectively referred to for brevity as the "Site", "Website").
This Policy also applies in cases where you, as natural persons (for brevity "Data Subjects"), voluntarily provide us with personal data electronically (via e-mail), by telephone, or through other means, including on-site at our retail outlet or office. We also process personal data from inquiries made by you to us, as well as for marketing and advertising purposes, profiling, participation in games, promotions, and raffles organized by us, and for any other purposes not prohibited by law.
In the processing of personal data, Bulgarian Rose Plc complies with all regulatory acts applicable to its activities regarding personal data protection, including, but not limited to, Regulation (EU) 2016/679 ("the Regulation") and the Personal Data Protection Act, because the security of our customers' personal data is of paramount importance to us. Therefore, this Policy applies in these instances as well.
SCOPE OF THE POLICY
This Policy applies to all our customers—natural persons using our services by placing an order through the Site or expressing interest in them by sending inquiries (hereinafter referred to as "Data Subjects", "Users").
Partners and third parties who work with or for Bulgarian Rose Plc, as well as those who have or may have access to personal data, are expected to familiarize themselves with, understand, and comply with this policy. No third party may have access to personal data stored by Bulgarian Rose Plc without the company having previously entered into a data confidentiality agreement. Such an agreement imposes obligations on the third party that are no less burdensome than those undertaken by Bulgarian Rose Plc and grants Bulgarian Rose Plc the right to conduct audits to verify compliance with the obligations imposed by the agreement.
This policy applies to all employees/workers (and stakeholders) of Bulgarian Rose Plc, as well as to external suppliers of products and services with whom Bulgarian Rose Plc has concluded contracts. Any violation of the General Regulation (GDPR) will be considered a breach of labor discipline or, respectively, a failure to fulfill contracts with partners. In the event of a suspected criminal offense, the matter will be referred to the relevant state authorities for consideration as soon as possible.
For visitors to the Site who do not place orders or send inquiries but only browse our website, the Cookies Policy adopted and published on the Site shall apply.
DEFINITIONS
"Regulation" – General Data Protection Regulation (EU) 2016/679 of April 27, 2016, referred to as GDPR. The purpose of this European legislative act is to protect the "rights and freedoms" of natural persons and to ensure that personal data is not processed without their knowledge and, whenever possible, is processed with their consent.
"Personal Data" – any information relating to an identified or identifiable natural person ("Data Subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
"Special Categories of Personal Data" – personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation.
"Processing" – any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
"Controller" – any natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
"Data Subject" – any living natural person who is the subject of personal data stored by the Controller.
"Consent of the Data Subject" – any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
"Child" – The General Regulation defines a child as anyone under the age of 16. The processing of a child's personal data is lawful only if a parent or guardian has given consent. The Controller shall make reasonable efforts to verify in such cases that the holder of parental responsibility for the child has given or authorized the consent.
"Profiling" – any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
"Personal Data Breach" – a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
"Recipient" – a natural or legal person, public authority, agency, or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.
"Third Party" – a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data.
PRINCIPLES
In the collection and processing of personal data, we are guided by the following principles: lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability.
DATA SUBJECTS WHOSE DATA WE PROCESS
In connection with its activities, Bulgarian Rose Plc concludes and executes distance purchase-sale agreements, reviews job applications and proposals, processes forms for exercising the rights of consumer-buyers, as well as requests from data subjects, responds to inquiries, issues and receives invoices, processes statistical data, manages the user panel on the site, and carries out advertising activities through advertising campaigns (promotions, games, etc.). In the course of these activities, Bulgarian Rose Plc processes information regarding the following Data Subjects:
(a) Natural persons, users of the site without registration, who do not leave any data (in this case we process data, but not personal data), and natural persons, users of the site without registration, who have provided a limited amount of personal data voluntarily (e.g., telephone number and/or e-mail address);
(b) Natural persons, users of the site registered as "Registered Users"—in these cases, we process data for the user that they have entered during registration: e-mail address, delivery address, names, billing data, order details, and other data entered by the user;
(c) Natural persons who have made inquiries (including via telephone calls), requests, initiatives, reports, complaints, or other correspondence to us, including via the website, telephone, e-mail, or other means;
(d) Natural persons whose information is contained in inquiries (including via telephone calls), requests, initiatives, reports, complaints, or other correspondence addressed to us;
(e) Natural persons with whom we conclude contracts (civil, including commercial or labor, most notably distance contracts) electronically (via the website or social networks, as well as via electronic correspondence) or on-site at our office or retail outlet;
(f) Natural persons whose data we have received through third parties (for example, in the case of an order intended as a gift).
PERSONAL DATA WE PROCESS
Depending on the reason necessitating the processing of personal data, the type of such data may vary. The functionalities provided on the Site are not intended for the storage and processing of special categories of data within the meaning of Art. 9 and Art. 10 of the Regulation. (NB! Read Art. 9 and Art. 10 of the Regulation here). We request only those personal data that are necessary for us to provide the activity/service/product requested from us. In the course of the use of the site by natural persons, we may also process other data that do not contain personal data but concern the subject, such as their IP address, data regarding their activity on the site, and other similar information.
Data provided when placing an order
To excecute a distance purchase-sale agreement (order) concluded between you and Bulgarian Rose Plc, we require certain information from your side. You decide whether and how to use the options for concluding a distance sale agreement provided through the Site or the Facebook page. In the forms used for entering personal data, we clearly indicate the mandatory or voluntary nature of the data provision. Data marked as mandatory are those without which it is impossible for us to conclude the respective agreement. These include: names, email address, delivery address, contact telephone number, your payment information (e.g., bank card), and billing data, including a Personal Identification Number (EGN) if you wish to receive an invoice as a natural person. If you provide data belonging to third parties who will receive the order (for example, in the case of gift orders or other types of donations), you bear the responsibility for providing such data to these third parties.
Data provided during registration on the site
In the event that you have chosen to store your information on the Site by registering a profile, we store the aforementioned data as well as a history of the orders placed from each account registered on the Site. The required data match those requested when placing an order. Along with them, we also process IP addresses and activity data (time and date of registration, acceptance of the Security Policy and General Terms and Conditions, account logins, etc.).
Data provided upon conclusion of other agreements
In cases where Bulgarian Rose Plc concludes other agreements with natural persons, distinct from distance sales, we require the person's full name, Personal Identification Number (EGN), address, and email address.
Data provided by, through, and to other websites and applications (Third Parties)
In certain cases, you have the opportunity to share information with social networks or use their sites to create your profile or link your profile on our website with the respective social network. In such instances, the social network may provide us with automatic access to certain personal information they have collected about you (e.g., content you have viewed, content you like, and information about advertisements shown to you or that you have clicked on, etc.). By linking your social network profile to your account on our website, you authorize us to access your personal data processed by the respective social network and to collect, use, and retain this information in accordance with this Privacy Policy. This linking of a social network profile to a registration on our website occurs if you click on a link provided to create a Registration on our website through social media integration, thereby voluntarily establishing a connection with the respective social media site. Should you choose to register on our site via a social network, we may process data such as your name, telephone number, email, gender, marital status, age, photo, education, place of birth, place of residence, and other data you have provided to those platforms that are visible to us when you log in through them.
If you provide your personal data to Bulgarian Rose Plc via Viber, Skype, Facebook, or any other platform/social network, please be informed that these platforms/websites/social networks have their own privacy policies. We do not accept any responsibility or liability for these policies, as their processing activities cannot be controlled by Bulgarian Rose Plc. In this regard, we recommend that you check these policies before sending us your personal data through these websites/applications.
Data provided when posting a comment, review, or post
If you leave a post or a comment on this website, your IP address will be stored along with your name, if you have provided this information. This is for the safety of the website operator. If your text violates the law, the operator would need to be able to trace your identity.
Separately, Bulgarian Rose Plc is obligated to store such data (referred to as "traffic data") for specific periods and for the purposes outlined below. Due to the fact that sending comments, inquiries, and other messages to the site, the Facebook page/group, or their administrators constitutes sending an electronic statement, pursuant to the Electronic Document and Electronic Trust Services Act ("EDETSA"), the controller is obligated to maintain logs of the fact that the statement was sent for a period of 1 year. The log contains the date of the statement, the name, and the email address of the sender.
Employee data and data collected during job application processing
We process data upon the conclusion of employment contracts and during the assessment and processing of job applications. When concluding employment contracts, we require full name, Personal Identification Number (EGN), address, age, gender, educational background, professional experience, and banking details; subsequently, we also process health-related data. When processing curriculum vitae (CVs), we process names, address, email address, age, gender, education, professional experience, photos, and any data voluntarily provided by the candidate during an interview or within their CV.
Data provided in connection with correspondence, complaints, and reports
For the purpose of resolving submitted complaints, reports, disputes, inquiries, requests, or other matters addressed in communication to Bulgarian Rose Plc received via electronic forms on the Site, through telephone calls, or sent via regular or electronic mail, Bulgarian Rose Plc stores and processes this information, as well as the outcome of such processing. This may include names, email addresses, telephone numbers, and physical addresses.
Furthermore, as the sending of comments, inquiries, and other messages to the site, the Facebook page, or their administrators constitutes the sending of an electronic statement, pursuant to the Electronic Document and Electronic Trust Services Act ("EDETSA"), we are obligated to maintain a log of the fact that the statement was sent (excluding its content) for a period of 1 (one) year. The log contains the date of the statement, the name and email address of the sender, and the identification of the sender.
If you provide us with personal information regarding someone else, you must do so only with that person's authorization. You must inform them how we collect, use, disclose, and store personal information in accordance with this Personal Data Security Policy.
Technical data collected in the course of using the site
In addition, we collect information from your computer, phone, tatblet, or any other devise you use. This information may include the following:
We may choose to minimize the volume of data we store and process, in accordance with the purposes of the processing.
We do not request, nor will we collect or process, personal data that reveal: racial or ethnic origin; political, religious, or philosophical beliefs; trade union membership; genetic and biometric data; health data; or data concerning a person's sex life or sexual orientation. If a data subject provides such categories of data on their own initiative and at their own discretion, Bulgarian Rose Plc shall not be held liable for the provision thereof, and only undertakes to provide the same protection measures for them as those provided for the requested personal data. We do not transfer data to third countries. Furthermore, we do not make automated decisions regarding personal data and we do not process the data of persons under the age of 16. In the event that you are under the age of 16, you should not provide us with any personal data about yourself.
PURPOSES FOR WHICH WE PROCESS YOUR DATA
The primary purpose for which WE process your personal data is generally related to the provision of services through the Site and social networks—specifically, the conclusion of distance sale agreements and the delivery of the goods and services you have ordered, as well as the accounting of revenues. We also use your personal information to provide and improve our Services, to offer you a personalized experience on our Site, to contact you regarding your account and our Services, to provide customer support, to deliver personalized advertising and marketing tailored to your interests, to conduct raffles and games organized by us, and, in certain cases, to detect and investigate fraudulent or illegal activities.
Bulgarian Rose Plc collects, uses, and processes the information described above for the purposes provided in this Policy, which may be related to:
Your data may be processed on the basis of your explicit consent, in which case the processing is specific nd within the extent nd scope profived for in the respective consent. Typically, we request such consent when we wish to offer you information regarding new promotions, products, etc.
RETENTION PERIOD OF YOUR PERSONAL DATA
When storing data, WE apply the general principle of storing data in minimum volume and for a period no longer than necessary for providing the Services, executing agreements, ensuring their security and reliability, and meeting legal requirements. We will retain your personal information for the period necessary to fulfill the purposes set out in this "Personal Data Protection Policy," unless a longer retention period is required by law or based on our legitimate interest. A retention period is determined according to the type of data and the purposes for which they were collected; upon its expiration, the information is permanently deleted.
|
Data type |
Retention Period Legal Basis for Processing |
Explanatory Notes |
|
Registration Data (First and last name, email, phone, address) and information regarding registration and acceptance of Terms (date, time, IP address). |
For the entire duration of the account and up to 5 (five) years after termination of registration. Performance of a contract; Compliance with legal obligations; Protection of legitimate interest. |
These data identify you as a registered user. To resolve potential disputes and in connection with EDETSA, data is kept for 5 years after account closure. NB! Under EDETSA, activity and IP logs must be kept for 1 year from account closure. |
|
Order Data, invoices, payment documents (orders, statements), and other accounting or financial documents. Also includes Personal data from employee records. |
For the duration of rights and obligations under the relationship, and up to 5 years after termination. Certain accounting data (transactions, billing) are kept for 5 to 50 years as required by law. Compliance with legal obligations and protection of the controller's legitimate interests. |
Identifies you as a party to a distance sale contract. Under Art. 38 of the TIPC, payrolls are kept for 50 years; accounting registers for 10 years; tax control documents for 5 years after the statute of limitations expires. |
|
Personal Data from correspondence, complaints, reports, requests, and initiatives. |
Up to 5 (five) years based on the Law on Obligations and Contracts (statute of limitations for claims). Protection of the controller's legitimate interests. |
To resolve complaints, disputes, or inquiries received via electronic forms, email, or mail. Based on Bulgarian legislation for dispute resolution, this information is stored for up to 5 years. |
|
Logs certifying the sending of a comment, inquiry, order, or other statement (sender, recipient, date, and time). |
Between 1 (one) and 5 years. Compliance with legal obligations and protection of the controller's legitimate interests. |
Sending a comment or inquiry constitutes an electronic statement under EDETSA. The company is required to maintain a log of the fact of sending for 1 year. This may be extended to 5 years for legitimate interests. |
|
Quick Searches (do not contain personal data). |
Until deleted by you; until account termination; or up to 6 months if used without registration. Consent of the subject and protection of the controller's legitimate interests. |
This option allows you to repeat searches without re-typing. It stores the last 10 searches via a browser cookie. You can manage this through your browser settings. |
|
Settings and System Logs (do not contain personal data; may include date, time, IP, URL, browser/device version). |
Until deleted by you or account termination. If stored in a cookie: between 6 and 12 months from last use. Consent; Compliance with legal obligations; Protection of legitimate interests. |
Includes settings like language choice. Server logs and WAF logs are used to identify technical problems or malicious activity. You control these settings via your browser. |
|
Information stored in a mobile application. |
For the period of its use (until uninstalled). Necessity for the technical provision of Services. |
Information required for the technical functioning of the application (settings, etc.). |
|
Cookies |
Between 6 and 12 months, depending on the type of cookie and browser settings. Consent of the subject and protection of legitimate interests. |
For a detailed description of the cookies used, please refer to the "Cookie Policy." |
|
Exceptions to the Retention Period Rules Please note that we will not delete or anonymize your personal data if they are necessary for a pending judicial, administrative, arbitration, or enforcement proceeding, or for the processing of a complaint submitted by you to us. Deletion will be carried out once the need for the data no longer exists, which may occur after the expiration of the retention periods specified above. You may always request that we delete certain information or close your account. We will respond to such requests while retaining certain information, even after the account is closed, where applicable legislation or legitimate interests require it. If we are legally obligated or if it is reasonably necessary to comply with regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our terms and conditions, we may also retain a portion of your personal information for a limited period, even after you have deleted your profile.
To ensure the reliability of the services and protect against data loss due to technical reasons, the Site implements a data redundancy (backup) policy. The maximum period for updating (deleting data) from all backup copies is 30 days. |
||
DO WE SHARE YOUR PERSONAL DATA WITH THIRD PARTIES
Bulgarian Rose Plc, and respectively the Site, does not provide your personal data to third parties unless there is a legal basis for doing so—a legal or contractual obligation, a legitimate or vital interest, or your explicit consent. We strive to minimize the personal data we disclose, ensuring it is always directly relevant and necessary to achieve the specific purpose. We do not sell, rent, or otherwise disclose your personal information to third parties for their marketing and advertising purposes without your consent. We guarantee that access to your data by third-party private entities is carried out in accordance with legal provisions regarding data protection and information confidentiality, based on contracts concluded with them.
We may disclose your personal data when we are subject to a legal obligation. In certain cases, Bulgarian Rose Plc is required to disclose your data to public authorities such as the police, the prosecutor's office, or the courts, in connection with the prevention or detection of crime. This also includes exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction. You should be aware that if we are requested by the police or any other regulatory or state authority investigating suspected illegal activities to provide your personal information or any other information we have obtained about you, we are entitled to do so after verifying the validity of the state authorities' request. When we receive revenue from sales, we may be obligated by the revenue authorities (NAP) to provide sales data containing details of your orders, including personal data. In this regard, we provide your data to the accounting firms with which we work. It is a legal obligation of the Site and Bulgarian Rose Plc to ensure the security of the networks and the data processed by the company. In connection with this, we implement a series of measures, the execution of which may require the processing of your data by IT companies responsible for the security within our company.
We may have a contractual obligation to provide your data under a distance sale agreement concluded with you, by virtue of which we are obligated to deliver the goods or services you requested via a courier. The same applies if you have chosen to purchase or pay for a product or service from our Site using payment, credit, or banking services, where you personally share your data with the providers or authorize us to do so. If you have opted to insure a product/service at the time of purchase through the Site, your data is shared with insurance companies via the order. If we install a purchased product through a subcontractor, we may provide your data to them so they can perform the service or warranty fulfillment.
Our legitimate interest justifies the provision of personal data to third parties in certain cases. Such a situation would arise during proceedings initiated before the Commission for Personal Data Protection, the Commission for Consumer Protection, or other state authorities. A legitimate interest also exists for Bulgarian Rose Plc when we engage other companies or individuals to perform specific tasks on our behalf that supplement our services, within the framework of data processing agreements. We want you to always be informed about the best offers for the products/services you are interested in. In this regard, we may provide certain data of yours - only with your explicit consent - to marketing/telemarketing service providers and other companies with which we may develop joint programs for marketing our goods and services.
Our website may also contain links to and from the websites of third parties. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before submitting any information to these websites. Our site uses YouTube LLC, represented by Google Inc., to integrate videos. Typically, when you visit a page with an embedded video, your IP address will be sent to YouTube and cookies will be installed on your device. However, our YouTube videos are integrated in "enhanced privacy mode" (in this case, YouTube still contacts the DoubleClick service by Google, but personal data is not used in accordance with Google's privacy policy). As a result, YouTube does not store any information about visitors unless you watch the video itself. If you click on the video, your IP address will be sent to YouTube, and YouTube will know that you have viewed the video. If you are logged into YouTube through your user profile, this information will also be linked to your profile (you can prevent this by logging out of YouTube before clicking to watch the video). We have no information regarding the possible collection and use of your data by YouTube. For more information, please see YouTube's Privacy Policy at: www.google.com/intl/en/policies/privacy/.
TO WHICH COUNTRIES DO WE TRANSFER YOUR PERSONAL DATA
Currently, we store and process your personal data in Bulgaria.
Nevertheless, it is possible that some of your personal data may be transferred to entities located within the European Union or outside of it, including countries for which the European Commission has not recognized an adequate level of personal data protection.
We will always take steps to ensure that any international transfer of personal data is carefully managed to protect your rights and interests. Data transfers to service providers and other third parties will always be protected by contractual obligations and, where appropriate, by other safeguards such as standard contractual clauses issued by the European Commission or certification schemes.
You may contact us at any time using the contact details provided at the end of this Policy to find out which countries we transfer your data to and what protective measures we apply in connection with these data transfers.
YOUR RIGHTS REGARDING YOUR PERSONAL DATA
Under the General Data Protection Regulation (GDPR), you have the following rights:
Right to be Informed
This Policy aims to inform you in detail about the processing of your personal data. When there is a risk of a breach of the security of your personal data, the controller is obliged to notify you of the nature of the breach and what measures have been taken to remedy it, as well as whether the supervisory authority has been notified of the breach. Also, the data subject may request information regarding all recipients to whom the personal data, for which rectification, erasure, or restriction of processing has been requested, have been disclosed.
Right of Access
You have the right to obtain confirmation as to whether your personal data are being processed, access to them, and information regarding the method of their processing and your rights in connection with this. As a data subject, you have the right to request confirmation as to whether your personal data are being processed and, if so, to receive access to your data and the following information: the purpose of the processing, the categories of personal data concerned, the recipients of the data, and the period of processing. Requests for access must be made in writing/electronic form and addressed to the controller. In such cases, we provide a copy of the processed personal data in an electronic or other appropriate form.
Right to Rectification
You have the right to correct and supplement your personal data in the event that they are incomplete or inaccurate. For registered users, this option is also available in the user panel on the Site. Unregistered users can obtain this information by submitting a request to the controller. As a data subject, you have the right to request the rectification or completion of your personal data that are inaccurate/outdated or incomplete. For this purpose, you must submit a separate request. Your request will be answered by the controller in writing at the email address provided by you.
Right to Erasure (Right to be Forgotten) and Account Closure
As a data subject, you have the right to "be forgotten," i.e., to request that your personal data be erased without undue delay. This means the controller must delete your personal data from all systems and records where they are stored, including notifying all third parties/data processors to whom the data has been provided.
If you wish, you have the option to close your account on the site at any time. This option is available within the user panel on the Site. After the account is closed, all or part of the data is deleted. In connection with our obligations, responsibilities, and legal requirements (e.g., the Electronic Communications Act or EDETSA), we may retain certain data for a specific period (see the section above).
To ensure the reliability of the services and protect against data loss due to technical reasons, the Site implements a data redundancy (backup) policy. The maximum period for updating (deleting data) from all backup copies is 30 days.
A request for erasure may be submitted on the grounds provided for in the Regulation, including the presence of any of the following:
- the personal data are no longer necessary for the purposes for which they were collected;
- when you have withdrawn your consent;
- when you have objected to the processing of personal data and there are no overriding legitimate grounds for the processing;
- when the processing in ulawful;
- when the personal data must be erased for compliance with a legal obligation under Union or Member State law to which the controller is subject;
- when the personal data were collected in relation to the offer of information society services.
Please note that we may refuse to delete some or all personal data in cases where there is a substantial ground and/or a legal obligation for their processing. You will be promptly informed of such a decision. The controller may refuse to erase personal data on the grounds specified in the Regulation — when the processing of specific data is for the purpose of:
- exercising the right of freedom of expression and the right to information;
- compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- reasons of public interest in the area of public helth;
- archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes;
- the establishment, exercise, or defense of legal claims.
Right to Restriction of Processing
The General Data Protection Regulation (GDPR) provides the possibility to restrict the processing of your personal data if there are grounds for this as provided therein. Restriction is permitted in the following cases:
- when you believe that your personal data are not accurate; in this case, the restriction is for a period necessary for the controller to verify the accuracy;
- when the processing of your personal dat is unlawful, but you do not want them to be erased, requesting instead only the restriction of their use;
- when the controller no longer needs the personal data for the purposes of the processing, but you, as the data subject, require them for the establishment, exercise, or defense of legal claims;
- when you have objected to the processing pending the verification of whether the legitimate grounds of the controller override your interests.
Right to Notification of Third Parties
Where applicable, you have the right to request the Controller of your personal data to notify third parties to whom your data has been disclosed regarding any rectification, erasure, or restriction of the processing of your personal data.
Right to Data Portability
You have the right to receive the personal data concerning you, which you have provided, in a structured, commonly used, and machine-readable format, and you have the right to transmit those data to another controller without hindrance from us, provided that the processing is based on consent or a contractual obligation and the processing is carried out by automated means.
Important: The responsibility for the storage of data exported from the Site, as well as for all consequences of providing it to other controllers, lies entirely with you.
Right Not to be Subject to a Decision Based Solely on Automated Processing
You have the right not to be subject to such automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless there are grounds provided for in the applicable data protection legislation and appropriate safeguards are in place to protect your rights, freedoms, and legitimate interests.
Right to Withdraw Consent
You have the right, at any time, to withdraw the consent you have given in connection with the processing of personal data based on your prior agreement. Such a withdrawal does not affect the lawfulness of processing based on consent before its withdrawal. For services such as email subscriptions, where enrollment is based on your request (consent), an option to unsubscribe at any time (withdrawal of consent) is provided. In the event of a withdrawal of consent, we reserve the right to verify the identity of the requester to ensure it matches the person to whom the data relates.
Right to Object
You have the right to object to the processing of data based on legitimate interest. In the event of such an objection, we will review your request and, if it is well-founded, comply with it. If we believe that there are compelling legal grounds for the processing or that it is necessary for the establishment, exercise, or defense of legal claims, we will inform you accordingly.
Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint against our company (as data controller) with the supervisory authority if you believe that the processing of personal data relating to you violates applicable data protection legislation. The supervisory authority in the Republic of Bulgaria is the Commission for Personal Data Protection, with the following contact details: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592; email: kzld@cpdp.bg; website: www.cpdp.bg; phone: 02 915 3 518
HOW TO EXERCISE YOUR RIGHTS. RESPONSE DEADLINES
You may exercise the aforementioned rights free of charge at any time via email or by submitting a request to the addresses specified in the contact form on the Site or at the end of this Privacy Policy. You may address your requests both to the controller and directly to the Data Protection Officer. Requests must be made in a manner that allows for the identification of the applicant's identity. Regarding certain rights, technical options for exercising them may be available, such as an "Unsubscribe" button. In all cases, the controller shall respond to the request or rule on the exercised right at the address provided in the request, including electronic addresses, within one month of its receipt.
In the event that you exercise these rights in a manner that is clearly unfounded or excessive, particularly due to their repetitive nature, we reserve the right to either charge a reasonable fee, taking into account the administrative costs of providing the information or communication or taking the requested action, or refuse to act on the request. We will inform you of our fees, if applicable, before ruling on your request.
ACCURACY OF INFORMATION
We are not responsible for the accuracy of the data you provide; we do not perform checks in this regard and do not guarantee the actual identity of the individuals who have provided the data. In all cases of doubt on your part, or in the event of identified fraud and/or abuse, please notify us immediately. You undertake, when providing any information on the Site, not to violate the rights of other persons in connection with the protection of their personal data or any other of their rights.
GENERAL INFORMATION ABOUT THE POLICY
This Personal Data Policy may be amended or supplemented due to changes in applicable Bulgarian or European legislation, at the initiative of Bulgarian Rose Plc, or at the request of a competent authority.
Bulgarian Rose Plc will inform users of any amendments or supplements to this Personal Data Policy by publishing the updated Policy on our website.
It is recommended that users periodically check the most current version of this Personal Data Policy on the Bulgarian Rose Plc website.
HOW WE PROTECT YOUR RIGHTS
SECURITY MEASURES
In order to ensure the best possible protection for the data of the company and our customers/users/contractors/visitors to the Site, WE apply all necessary organizational and technical measures provided for in the General Data Protection Regulation and the Personal Data Protection Act, as well as best practices from international standards. We apply the appropriate and necessary level of protection and, for this purpose, we have developed efficient physical, electronic, and administrative procedures to safeguard the data we collect from accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to personal data transmitted, stored, or otherwise processed.
We store your data on secure servers using the latest encryption algorithms and ensure the storage of backup copies.
The company has adopted the necessary rules and procedures related to the lawful processing of your personal data, including a Data Breach Response Plan, has established structures to prevent abuse and security breaches, and has appointed a Data Protection Officer who supports the processes of lawful processing, protection, and security of your data.
Access to your personal data is permitted only to those employees, service providers, or related persons on a "need-to-know" basis for business purposes or who require it to perform their professional duties. All employees/workers are required to be trained and to accept relevant contractual clauses/declarations/rules for compliance with organizational and technical access measures before being granted access to information of any kind.
It is a fundamental principle in our structure that all employees are responsible for ensuring the security of the data for which they are accountable and which we process. Data is stored securely and is not disclosed under any circumstances to third parties unless we have granted such rights to that third party through a confidentiality agreement/clause. In this regard, all personal data is accessible only to those who need it, and access is granted only in accordance with established access control rules.
All personal data is treated with the highest level of security and is stored in:
- a separate room with controlled access; and/or
- a locked cabinet accessible only by authorized persons; and/or
- a computerized system protected by a password in accordance with internal requirements specified in the organizational and technical measures for access control; and/or
- computer media that are protected in accordance with organizational and technical measures for controlling access to information.
Personal data is deleted or destroyed only in accordance with internal procedures for data retention and destruction. For maximum security during the processing, transfer, and storage of your data, we may use additional protection mechanisms such as encryption, pseudonymization, and backup technology.
We use a payment service to process payments. All payment information is encrypted using SSL technology.
When you post in forums, chat rooms, or social media services, the personal information you share is visible to other users and can be read, collected, or used by them. In these cases, you are responsible for the personal information you choose to provide.
Despite the measures we implement to protect your personal data, we are aware that, in general, the transmission of information over the internet or other public networks is not completely secure, and there is a risk that data may be viewed and used by unauthorized third parties. We cannot accept responsibility for these vulnerabilities in systems that are not under our control. In the event of a data breach involving personal data, we guarantee that we will comply with all applicable notification standards for such cases.
COOKIE POLICY
As an integral part of this Privacy Policy for individuals, Bulgarian Rose Plc has also adopted a Cookie Policy, which is published and accessible both on the Site and on our Facebook page.
CONTACT US
DATA PROTECTION OFFICER
Questions and requests related to the exercise of your personal data protection rights may be addressed to Bulgarian Rose Plc via the contact form available on the Site or through any of the following contact methods:
Bulgarian Rose Plc, UIC 115009344, VAT No. BG 115009344, with registered office and address for management and correspondence: Karlovo, Industrial Zone, Bulgarian Rose Plc Building; Contact phone: +359 33 59 53 28; E-mail: contact@bulgarianrose.bg
DATA PROTECTION OFFICER
The Data Protection Officer is E. Dabenska Correspondence address: 4300 Karlovo, Industrial Zone 1, email address: contact@bulgarianrose.bg; contact phone: +359 33 59 53 28