Information about the controller of personal data:

“IN – EXPORT SERVICE” EOOD, is a company registered in the Commercial Register of the Registration Agency with EIK 206157786, with headquarters and management address: BULGARIA, Varna region, Varna municipality, Varna city, 9000, Vladislav Varnenchik district , PERPERIKON STREET No. 4

Grounds and purposes for which we use your personal data

We process your personal data on the following grounds:

  • A contract concluded between us and you in order to fulfill our obligations under it;
  • Explicit consent from you – the purpose is specified for each specific case;
  • If required by law; In the following paragraphs you will find detailed information about the processing of your personal data depending on the basis on which we process it.

FOR PERFORMANCE OF A CONTRACT OR IN THE CONTEXT OF PRE-CONTRACTUAL RELATIONS

We process your personal data in order to fulfill the contractual and pre-contractual obligations and to enjoy the rights under the contracts concluded with you.

Purposes of processing:

  • establishing your identity;
  • management and execution of your request and execution of a concluded contract;
  • preparation of a proposal for concluding a contract;
  • preparing and sending a bill/invoice for the services you use with us;
  • to provide you with the comprehensive service you need, as well as to collect the amounts due for the services used;
  • retaining correspondence in connection with placed orders, processing requests, reporting problems, etc.
  • notification of everything related to the services you use with us;
  • customer history analysis;
  • detect and/or prevent illegal actions or actions contrary to our terms of the relevant services;

Data we process on this basis:

On the basis of the contract concluded between us and you, we process information about the type and content of the contractual relationship, as well as any other information related to the contractual relationship, including:

  • personal contact details – contact address, email, phone number;
  • identification data – the three names;
  • data on the orders placed;
  • correspondence in connection with the overall service – e-mail, letters, information about your requests for fixing problems, complaints, requests, complaints, feedback that we receive from you;
  • Information by credit or debit card reference code, bank account number or other banking and payment information in relation to payments made;

Other information such as:

  • Customer number, code or other identifier created for identification;
  • IP address when visiting our website;
  • Demographic data
  • Social network profile data
  • Information from your actions on the site

The processing of the specified personal data is mandatory for us in order to be able to conclude the contract with you and fulfill it. Without you providing us with the above data, we would not be able to fulfill our obligations under the contract.

We provide personal data to third parties:

We provide your personal data to third parties, and our main goal is to offer you quality, fast and comprehensive service. We do not provide your personal data to third parties before making sure that all technical and organizational measures are taken to protect this data and we strive to implement strict controls to fulfill this purpose. In this case, we remain responsible for the confidentiality and security of your data.

We provide personal data to the following categories of recipients (data controllers):

  • postal operators and courier companies;
  • persons who, by assignment, maintain equipment, software and hardware used for processing personal data and necessary for the company’s activities
  • persons performing consulting services in various fields.

When we delete data collected on this basis:

We delete the data collected on this basis 5 years after termination of the contractual relationship, regardless of whether due to expiration of the contract, cancellation or any other reason. The term is determined by the 5-year statute of limitations for possible claims from the contract.

TO FULFILL REGULATORY OBLIGATIONS

It is possible that the law stipulates an obligation for us to process your personal data. In these cases, we are required to carry out the processing, such as:

  • Obligations under the Anti-Money Laundering Measures Act;
  • Fulfillment of obligations in connection with distance sales, off-premise sales provided for in the Consumer Protection Act;
  • Providing information to the Consumer Protection Commission or third parties provided for in the Consumer Protection Act;
  • Providing information to the Commission for the Protection of Personal Data in connection with obligations provided for in the normative framework for the protection of personal data;
  • Obligations provided for in the Law on Accounting and the Tax-Insurance Procedure Code and other related legal acts, in connection with the keeping of legal accounting;
  • Providing information to the court and third parties, within the proceedings before a court, in accordance with the requirements of the legal acts applicable to the proceedings;
  • Age verification when shopping online.

When we delete personal data collected on this basis

We delete the data collected pursuant to an obligation provided by law after the obligation to collect and store is fulfilled or ceases. For example:

  • according to the Accounting Act for the storage and processing of accounting data (11 years),
  • obligations to provide information to the court, competent state authorities, etc. grounds provided for in the current legislation (5 years).

Provision of data to 3rd parties

When we are required by law, we may provide your personal data to the competent state authority, natural or legal person.

AFTER YOUR CONSENT

We process your personal data on this basis only after your express, unequivocal and voluntary consent. We will not foresee any adverse consequences for you if you refuse to process personal data.

Consent is a separate basis for processing your personal data and the purpose of the processing is stated therein, and is not covered by the purposes listed in this policy. If you give us the relevant consent and until its withdrawal or termination of any contractual relationship with you, we prepare suitable product/service offers for you by carrying out detailed analyzes of your basic personal data;

Detailed analysis is a method of performing analysis that allows the processing of large volumes of data by means of statistical models and algorithms and others that include the use of personal data, as well as processes of pseudonymization and anonymization of the same, in order to extract information about trends and various statistical indicators.

Data we process on this basis:

On this basis, we only process the data for which you have given us your express consent. Specific data is determined on a case-by-case basis. Usually this data is email, phone, address and name.

Provision of data to third parties

On this basis, we may provide your data to marketing agencies, Facebook, Google, Mailchimp or the like.

Withdrawal of consent:

Consents may be withdrawn at any time. Withdrawal of consent does not affect the fulfillment of contractual obligations. If you withdraw your consent to the processing of personal data for any or all of the ways described above, we will not use your personal data and information for the purposes specified above. Withdrawal of consent does not affect the lawfulness of processing based on consent given prior to its withdrawal.

To withdraw the given consent, you only need to use our site or simply our contact details.

When we delete data collected on this basis

We delete data collected on this basis upon your request or 12 months after initial collection.

PROCESSING OF ANONYMIZED DATA

We process your data for static purposes, that is, for analyzes in which the results are only generalizable and therefore the data is anonymous. Identification of a specific person from this information is impossible.

Your data can also be anonymized. Anonymization is an alternative to data deletion. Upon anonymization, all personally identifiable elements/elements enabling your identification are irreversibly deleted. For anonymized data, there is no legal obligation to delete it, as it does not constitute personal data.

Why and how we use automated algorithms

For the processing of your personal data, we use partially automated algorithms and methods in order to constantly improve our products and services to adapt our products and services to your needs in the best possible way. This process is called profiling.

How we protect your personal data

To ensure adequate data protection of the company and its customers, we implement all necessary organizational and technical measures provided for in the Personal Data Protection Act.

The company has established policies to prevent abuse and security breaches.

For the purpose of maximum security in the processing, transfer and storage of your data, we may use additional protection mechanisms such as encryption, pseudonymization, etc.

Personal data we have received from 3rd parties

  • Marketing agencies, Facebook, Google, Mailchimp or similar.
  • Rights of Users

Each User of the site enjoys all the rights to protect personal data according to Bulgarian legislation and the law of the European Union.

The user can exercise his rights through the contact form by sending a message to our email.

Each User has the right to:

  • Information (in connection with the processing of his personal data by the administrator);
  • Access to your own personal data;
  • Correction (if data is inaccurate);
  • Deletion of personal data (“right to be forgotten”);
  • Restriction of processing by the administrator or processor of personal data;
  • Portability of personal data between individual administrators;
  • Objection to the processing of his personal data;
  • The data subject also has the right not to be subject to a decision based solely on automated processing, including profiling, which gives rise to legal consequences for the data subject or similarly significantly affects him;
  • Right to judicial or administrative protection in the event that the data subject’s rights have been violated.

The user can request deletion if one of the following conditions is present:

  • The personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
  • The user withdraws his consent on which the data processing is based and there is no other legal basis for the processing;
  • The data user objects to the processing and there are no overriding legal grounds for the processing;
  • Personal data has been processed unlawfully;
  • The personal data must be deleted in order to comply with a legal obligation under Union law or the law of a Member State that applies to the controller;
  • Personal data has been collected in connection with the provision of information society services to children and consent has been given by the holder of parental responsibility for the child.

The user has the right to limit the processing of his personal data by the administrator when:

  • Dispute the accuracy of personal data. In this case, the restriction of processing is for a period that allows the administrator to verify the accuracy of the personal data;
  • The processing is unlawful, but the User does not want the personal data to be deleted, but instead requests the restriction of its use;
  • The Administrator no longer needs the personal data for the purposes of processing, but the User requires them for the establishment, exercise or defense of legal claims;
  • Objects to the processing pending verification of whether the legitimate grounds of the administrator prevail over the interests of the User.

Right of portability:

The data subject has the right to receive the personal data concerning him and which he has provided to an administrator in a structured, widely used and machine-readable format and has the right to transfer such data to another administrator without hindrance from the administrator to whom the personal data data is provided when the processing is based on consent or a contractual obligation and the processing is carried out in an automated manner. When exercising the right to data portability, the data subject has the right to obtain a direct transfer of the personal data from one administrator to another, when this is technically feasible.

Right to object:

Users have the right to object to the administrator against the processing of their personal data. The administrator of personal data is obliged to terminate the processing, unless it proves that there are compelling legal grounds for the processing that take precedence over the interests, rights and freedoms of the data subject, or for the establishment, exercise or defense of legal claims. In case of objection to the processing of personal data for the purposes of direct marketing, the processing should be stopped immediately.

Complaint to the supervisory authority

Every User has the right to file a complaint against illegal processing of his personal data to the Commission for the Protection of Personal Data or to the competent court.

Maintaining a register

We maintain a register of the processing activities for which we are responsible. This register contains all the information below:

  • Administrator’s name and contact details
  • The purposes of processing;
  • Description of the categories of data subjects and of the categories of personal data;
  • The categories of recipients to whom the personal data is or will be disclosed,
  • Including recipients in third countries or international organizations;
  • Where possible, the envisaged periods for erasure of the various categories of data;
  • Where possible, a general description of the technical and organizational security measures