What is the current policy?
With this policy, we want to inform you about the personal data we collect, who will process it and how, what we use it for, how long we will store it, and what protection measures we have taken to protect it.
Please read this policy carefully before providing your personal data.
Who processes your personal data?
We are Box From Bulgaria, with registration number 205867139, with headquarters and address of management: Republic of Bulgaria, region. Shumen, municipality Shumen, Shumen, 180 Vladaysko Vastanie Str., Hereinafter referred to as “Administrator”.
We are the Administrator of your personal data. As such, we are responsible for the processing and storage of your personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation) and Bulgarian law.
What personal data do we process?
When registering on the site and making orders:
When you decide to take advantage of our services, you must create your personal profile at (www.boxfrombulgaria.bg). To do this, you need to enter a set of personal data required for registration and subsequent delivery of the products you have selected. We process your personal data only if you have provided it to us. These can be:
• Name and surname;
• Phone number;
When using our contact form:
You can contact us at any time through our contact form, which you can open from the "Contacts" section of the website. For this purpose you will need to provide us with:
• Phone number.
For what purposes will we process your personal data?
We will process your personal data in order to make possible the conclusion and execution of a contract for the sale of goods offered through the Box From Bulgaria website, including the sending of the goods to you.
We also process your personal data if you use the contact form on our website to contact us.
Your email may only be used for direct marketing purposes if you have given your explicit consent to do so.
We may also use your personal data in the case of formal proceedings such as civil cases, administrative investigations, consumer claims and disputes, etc.
We may process your personal data for other purposes, when a certain applicable law obliges us to perform this processing or we have received your explicit consent in this regard.
On what legal basis do we process your personal data?
We collect and process your personal data according to the grounds provided in point 6 of the General Regulation on Personal Data Protection. We collect your personal data on the following grounds:
1. Execution of a contract
Based on the contract for the sale of goods we offer, we collect your personal data in order to fulfill our obligations under the contract, including delivery and delivery of the goods purchased by you.
2. Legitimate / legal / interest
We believe that both we and you have a legitimate interest in the protection of your personal data for the purposes of certain future marketing campaigns, as well as in the case of official proceedings.
Based on your unambiguous and explicit consent, we process your personal data related to the registration on the website, the use of the so-called Cookies, the use of our contact form, the use of direct marketing. You can withdraw your consent at any time.
4. Legal obligation
In certain cases, we may use your personal data in connection with legal obligations we have.
To whom can we provide your personal data?
In any case in which you have registered or placed an order, your personal data will be provided to third parties - hosting service providers, in order to use our website, and courier service providers, in order to deliver the desired goods to you. In case you do not want your personal data to be provided to third parties, you will not be able to take advantage of the services provided through Box From Bulgaria.
Your personal data may be provided to public authorities in connection with official proceedings.
How long will we store your personal data?
Your personal data will be stored for a period of 3 (three) years from the date of delivery of goods in connection with point 140 CPA, after which they will be deleted.
What rights do you have as a data subject?
You have the following rights, which we will assist at any time:
• Right to information
You have the right to receive information at the time of collection of your personal data about the data we collect, who will process it, for what purposes and on what grounds.
• Right of access
You have the right to request access to your personal data that we store at any time. You may also request the provision of a free copy of your personal data that is being processed.
• Right of adjustment
You have the right to request that your personal data be corrected in order for it to be up-to-date and accurate.
• Right to be deleted (right to be forgotten)
You have the right to request that your personal data be deleted after it is no longer needed for the purposes of processing or after the grounds for processing have ceased to exist.
• Right to limit processing
In certain cases, you have the right to request a restriction on the processing of your personal data.
• Right of portability
You may request to receive your personal data in a structured, widely used and machine-readable format (ie in digital form), as well as request the transfer of your data to another administrator specified by you, if possible. and feasible.
• Right to object
You may make a reasoned objection to the processing of your personal data when we use it on the basis of a legitimate interest. Thus, we may be obliged not to use them in the future.
• Right to withdraw consent
When the processing of your personal data is based on consent, you can withdraw it at any time. Thus, we are obliged not to process your personal data in the future.
• Right to appeal
You have the right to seek protection of your rights through the Commission for Personal Data Protection (CPDP). The CPDP is an independent state body that monitors the legality of personal data processing activities.
How can you exercise your rights?
You can exercise any of the listed rights by sending a written notification to the address: Shumen 9700, 180 Vladaysko Vastanie Str., Addressed to the Administrator.
The application is submitted by you personally or by a person authorised by you, unless a special law provides otherwise.
The application should contain name, address and PIN or personal number of a foreigner, or other similar identifier, description of the request, preferred form of communication and actions under Art. 15-22 of the General Regulation on Personal Data Protection, signature, date of submission of the application and address for correspondence. In case the application is submitted through a proxy, an explicit power of attorney should be attached.
If you have any questions about how to exercise your rights, please contact us at firstname.lastname@example.org.
How do we ensure the security of your data?
We understand how important it is for your personal data to be properly processed and protected. The team of the Administrator has introduced adequate technical and organisational measures for protection of your personal data. These measures, inter alia, ensure compliance with the principles underlying the processing of personal data by ensuring that your personal data is:
• Processed lawfully, in good faith and in a transparent manner in relation to you as a data subject ("lawfulness, good faith and transparency");
• Collected for specific, explicitly stated and legitimate purposes and not further processed in a way incompatible with these purposes ("limitation of objectives");
• Appropriate, related to and limited to what is necessary in relation to the purposes for which they are processed ("minimisation of data");
• Accurate and kept up to date. We have taken all reasonable steps to ensure the timely deletion or correction of inaccurate personal data, taking into account the purposes for which they are processed ("accuracy");
• Stored in a form that allows the identification of the data subject for a period not longer than necessary for the purposes for which the personal data are processed ("storage restriction");
• Processed in a way that provides an appropriate level of security for personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, applying appropriate technical or organisational measures ("integrity and confidentiality");
• The controller is responsible and able to demonstrate that it complies with the basic principles related to the processing of personal data ("reporting").
When can we change the current policy?
The Administrator reserves the right to change this policy at any time by updating, supplementing and amending it. You will be notified of changes to this policy by email. You can also find out about the changes through www.boxfrombulgaria.bg.
What if you are under 16?
We only process personal data of persons who have reached the age of 16. By agreeing to this Policy and providing us with your personal data, you declare that you are at least 16 years old.