Privacy policy
|
PRIVACY POLICY |
This Privacy Policy (the “Policy”) governs the terms, procedures and principles under which PRIKSI22 EOOD, UIC 208900110, having its registered office and management address at 132 St. St. Cyril and Methodius Street, Vazrazhdane District, 1303 Sofia, Bulgaria, in its capacity as a personal data controller (the “Controller”), collects, processes, stores and discloses personal data in connection with the use of the online store https://mishuponastarr.myshopify.com (the “Online Store”), including when products are browsed, a customer account is created, orders are placed and performed, payments and delivery are made, goods are returned and customers are contacted.
This Policy has been prepared in accordance with applicable European and national data-protection legislation, including Regulation (EU) 2016/679 (the “General Data Protection Regulation” or “GDPR”), the Personal Data Protection Act and all other applicable legislation.
This Policy aims to provide all visitors, customers and other individuals whose personal data are processed by the Controller (the “Data Subjects”) with clear and transparent information regarding: the categories of personal data processed; the purposes and legal bases for processing; retention periods; the categories of recipients to whom personal data may be disclosed; and the rights of data subjects and the manner in which they may be exercised.
The Controller processes personal data in strict compliance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability established in Article 5 of Regulation (EU) 2016/679.
The Controller takes all appropriate technical and organisational measures to protect the personal data processed against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, and against any other form of unlawful processing.
For questions regarding the processing of personal data, the exercise of rights under Regulation (EU) 2016/679 or this Privacy Policy, data subjects may contact the Controller at: prixyprix22@gmail.com.
I. CATEGORIES OF PERSONAL DATA PROCESSED BY THE CONTROLLER
Depending on the services used and the manner of interaction with the Online Store, the Controller may process various categories of personal data. Processing is always carried out for a specific, expressly determined and lawful purpose, where an appropriate legal basis under Article 6(1) of Regulation (EU) 2016/679 exists.
1. PERSONAL DATA OF CUSTOMERS
1.1. Categories of Data Subjects
The Controller processes personal data of natural persons who browse products, create a customer account, place an order, make a purchase, request the return or replacement of goods, or otherwise use the services of the Online Store.
1.2. Categories of Personal Data Processed
Depending on the specific service, the following categories of personal data may be processed: first and last name; telephone number; email address; delivery and billing address; order data, including selected products, size, price, delivery method and order status; customer-account data; correspondence with the customer; payment data and confirmation of payment. The Controller does not store full bank-card details.
The Controller does not collect special categories of personal data within the meaning of Article 9 of Regulation (EU) 2016/679, except where required by law or necessary for the protection of lawful rights and interests.
1.3. Purposes of Processing
Personal data are processed for the following purposes: accepting, confirming and fulfilling orders; processing payments; arranging delivery; communicating with the customer about the order; handling requests for withdrawal, return, replacement or complaint; creating and maintaining a customer account; issuing accounting documents; performing statutory obligations; and protecting the Controller’s rights and legitimate interests in the event of disputes.
1.4. Legal Basis
Processing is based on: Article 6(1)(b) GDPR – taking steps at the request of the data subject before entering into a contract and performance of a contract; Article 6(1)(c) GDPR – compliance with a legal obligation; and Article 6(1)(f) GDPR – the Controller’s legitimate interest in protecting its rights and lawful interests.
1.5. Retention Period
Personal data related to orders, payments and issued accounting documents are retained for the periods provided for by applicable tax, accounting and civil legislation. Customer-account data are retained until the account is closed, unless a ground for longer retention exists. Data necessary for protection in a legal dispute are retained until its final conclusion and the expiry of applicable limitation periods.
2. PERSONAL DATA OF ONLINE STORE VISITORS AND PERSONS WHO SUBMIT ENQUIRIES
2.1. Categories of Personal Data
The Controller processes personal data of persons who visit the Online Store, submit an enquiry, subscribe to a newsletter or make contact through the available means of communication.
2.2. Categories of Personal Data Processed
Depending on the method of interaction, the following may be processed: name; telephone number; email address; content of the message sent; IP address; technical information about the device and browser used; data concerning products viewed, the shopping cart and user preferences; and data collected through cookies and other similar technologies.
2.3. Purposes of Processing
Personal data are processed for the following purposes: handling enquiries; providing requested information; maintaining communication; sending newsletters and commercial communications where consent has been given; ensuring the normal operation and security of the Online Store; and analysing and improving the operation of the Online Store.
2.4. Legal Basis
Processing is based on: Article 6(1)(b) GDPR – taking steps at the data subject’s request before entering into a contract; Article 6(1)(f) GDPR – the legitimate interest in ensuring the security and operation of the Online Store; and Article 6(1)(a) GDPR – consent to newsletter communications and the use of analytical cookies where such consent is required.
2.5. Retention Period
Data from enquiries are retained for the period necessary to handle them and for a reasonable period after the communication has ended. Data processed for sending newsletters are retained until consent is withdrawn or an objection to receiving commercial communications is made, unless the law provides otherwise.
3. TECHNICAL AND MARKETING DATA
3.1. Categories of Personal Data
When using the Online Store, the following may be processed automatically: IP address; information about the browser and operating system used; device identifiers; information about pages visited and products viewed; data concerning interaction with the shopping cart and checkout process; and data collected through cookies and other similar technologies.
3.2. Purposes of Processing
Personal data are processed for the following purposes: ensuring the technical operation and security of the Online Store; statistical analysis; improving the functionality of the Online Store; analysis of the use of its services; and personalisation of content, where applicable.
3.3. Legal Basis
Processing is based on: Article 6(1)(a) GDPR – the visitor’s consent to the use of analytical cookies; and Article 6(1)(f) GDPR – legitimate interest in the use of technically necessary cookies and in ensuring the security and proper operation of the Online Store.
3.4. Retention Period
Retention periods depend on the type of cookies used and are specified in detail in the Cookie Policy.
II. METHOD OF COLLECTING PERSONAL DATA
The Controller processes personal data provided directly by data subjects, collected automatically when the Online Store is used or received from third parties where this is necessary to fulfil an order, make delivery, process payment, return goods, take steps at the data subject’s request before entering into a contract or comply with a legal obligation. Personal data may be provided through the creation of a customer account, placing an order, subscribing to a newsletter, electronic correspondence and other means of contact. Some information is collected automatically through cookies and other similar technologies and through the information systems ensuring the operation and security of the Online Store.
Where necessary for the performance of a contract, compliance with a legal obligation or protection of the Controller’s legitimate interests, personal data may also be received from third parties, including payment-service providers, couriers, information-technology providers and public authorities. Irrespective of the source from which personal data are received, the Controller processes only the information necessary to achieve the particular processing purpose.
III. PERSONAL DATA PROTECTION MEASURES
The Controller applies appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unlawful access or any other form of unlawful processing. In determining security measures, account is taken of the nature, scope, context and purposes of processing, as well as the risks to the rights and freedoms of natural persons.
Access to personal data is granted only to persons for whom it is necessary in view of the performance of their official or contractual obligations and who are bound by a duty of confidentiality. The Controller uses secure information systems, access-control mechanisms, data backup and recovery procedures and other appropriate technical means intended to prevent unlawful access, alteration, loss or destruction of the personal data processed.
Technical and organisational measures are reviewed and updated periodically in view of technological developments, changes in applicable legislation and identified security risks to the personal data processed.
IV. RECIPIENTS OF PERSONAL DATA
The Controller does not disclose personal data to third parties except where necessary for the performance of a contract, provision of requested services, compliance with a legal obligation, or where disclosure is necessary for the protection of the Controller’s or third parties’ legitimate interests.
Depending on the particular purpose of processing, personal data may be disclosed to persons processing data on behalf of the Controller, including Shopify as the provider of the Online Store platform; providers of hosting, technical support, cloud services and cookie-consent management; payment-service providers; couriers and other logistics-service providers; accounting firms; external legal advisers; and other persons whose involvement is necessary to fulfil the order or provide a service to the customer.
Personal data may also be disclosed to competent public authorities, courts, enforcement authorities, pre-trial authorities, the Commission for Personal Data Protection, the National Revenue Agency, the State Agency for National Security, the Registry Agency and other public authorities where this is provided for by law or necessary for the Controller to comply with a legal obligation.
Where the Controller uses external service providers which process personal data on its behalf, processing is carried out on the basis of a written contract or other legal act under Article 28 of Regulation (EU) 2016/679, ensuring that the processor applies appropriate technical and organisational data-protection measures and processes the information only in accordance with the Controller’s documented instructions.
V. TRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES
The Controller processes personal data principally within the European Union and the European Economic Area. When Shopify and other international providers of information technology, payment or cloud services are used, personal data may be transferred to countries outside the European Union or the European Economic Area.
In such cases, the Controller ensures that transfers of personal data are carried out only where an appropriate legal basis exists and in compliance with Chapter V of Regulation (EU) 2016/679. Where the European Commission has not adopted an adequacy decision in respect of the relevant third country, the Controller takes the necessary measures to ensure an adequate level of protection through standard contractual clauses, binding corporate rules or another applicable mechanism provided for in the Regulation.
Where personal data are transferred to providers established in the United States of America, the Controller verifies whether the relevant provider participates in an effective adequacy mechanism recognised by the European Commission or applies another permissible transfer mechanism under Chapter V of Regulation (EU) 2016/679.
VI. PERSONAL DATA RETENTION PERIODS
Personal data are retained for a period not exceeding that necessary to achieve the purposes for which they were collected, unless a longer period is provided for by applicable law or is necessary for the establishment, exercise or defence of legal claims.
When determining the retention period, the Controller takes into account the nature of the personal data processed, the processing purposes, statutory retention obligations, applicable limitation periods and the need to protect its legitimate interests.
After the ground for processing has ceased to exist, personal data are erased, destroyed or anonymised securely, unless their further retention is required by legislation or is necessary in connection with pending administrative, judicial or other proceedings.
VII. PROCESSING OF PERSONAL DATA IN THE PERFORMANCE OF THE MEASURES AGAINST MONEY LAUNDERING ACT
For the performance of an order, the Controller processes customer identification and contact data, data concerning selected products, delivery data and payment-status data. Provision of the data marked as mandatory in the order-placement process is necessary for entering into and performing the distance sales contract.
Data necessary for fulfilling the order may be disclosed to the relevant payment-service provider and to the courier or other logistics-service provider. The Controller does not store full payment-card details; card data are processed by the relevant payment-service provider.
The legal basis for processing is Article 6(1)(b) of Regulation (EU) 2016/679 – performance of a contract to which the data subject is party or taking steps before entering into a contract at the data subject’s request; and Article 6(1)(c) of Regulation (EU) 2016/679 – compliance with a legal obligation where processing is necessary for issuing and retaining accounting documents.
VIII. RIGHTS OF DATA SUBJECTS
Every data subject whose personal data are processed by the Controller has the rights provided for in Regulation (EU) 2016/679 and applicable national legislation. Depending on the particular basis and purpose of processing, the data subject has the right to information regarding the processing of their personal data, the right of access to such data, the right to request rectification of inaccurate or incomplete personal data, and the right to request erasure of their personal data where the conditions for this are met.
The data subject has the right to request restriction of processing where they contest the accuracy of personal data, where processing is unlawful but they do not wish the data to be erased, where the Controller no longer needs the personal data for processing purposes but the data are required by the data subject for the establishment, exercise or defence of legal claims, and in the other cases provided for in Regulation (EU) 2016/679.
Where processing is based on consent or is necessary for the performance of a contract and is carried out by automated means, the data subject has the right to receive their personal data in a structured, commonly used and machine-readable format and to request their transfer to another controller, where technically feasible.
Where processing is based on the Controller’s legitimate interest or is carried out for the performance of a task in the public interest, the data subject has the right to object at any time to the processing of their personal data. Where personal data are processed for direct-marketing purposes, the objection takes effect immediately and the Controller ceases processing for those purposes.
Where processing is based on consent, the data subject has the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
The Controller considers every request to exercise rights without undue delay and within the time limits provided for in Regulation (EU) 2016/679. Where a request is manifestly unfounded or excessive, the Controller may refuse to act or charge a reasonable fee under the conditions of Article 12 of the Regulation.
Requests to exercise rights under this Policy may be sent to the Controller at: prixyprix22@gmail.com. The request shall contain sufficient information to identify the person submitting it and a description of the action requested. Where necessary, the Controller may request additional information to verify the applicant’s identity.
The Controller does not carry out automated decision-making, including profiling within the meaning of Article 22(1) and (4) of Regulation (EU) 2016/679, which produces legal effects concerning the data subject or similarly significantly affects them.
IX. LODGING A COMPLAINT
Every data subject who considers that the processing of their personal data infringes applicable data-protection legislation has the right to lodge a complaint with the Commission for Personal Data Protection or seek judicial protection.
The Commission for Personal Data Protection is the independent supervisory authority in the Republic of Bulgaria within the meaning of Regulation (EU) 2016/679.
Commission for Personal Data Protection
Address: 2 Prof. Tsvetan Lazarov Boulevard, 1592 Sofia, Bulgaria
Website: https://www.cpdp.bg
Email: kzld@cpdp.bg
Lodging a complaint with the Commission for Personal Data Protection does not limit the data subject’s right to seek judicial protection or use other remedies provided by law.
Before lodging a complaint with the supervisory authority, the data subject may contact the Controller to resolve the issue that has arisen.
X. EXTERNAL WEBSITES
The Online Store may contain links to websites, platforms and services maintained by third parties and outside the Controller’s control. This Policy does not apply to the processing of personal data carried out by such persons or to the content, functionality and privacy policies of the relevant websites.
The Controller is not responsible for the manner in which third parties collect, use, store or process personal data. Visitors should independently review the privacy policies and terms of use of the relevant websites before providing their personal data through them.
XI. AMENDMENTS TO THE PRIVACY POLICY
The Controller reserves the right to amend and supplement this Privacy Policy at any time in view of changes in applicable legislation, judicial and administrative practice, the services provided, the technologies used or the manner of processing personal data.
All amendments and supplements take effect on the date of their publication in the Online Store, unless expressly stated otherwise. In the event of material changes affecting the manner of processing personal data or data-subject rights, the Controller will take appropriate steps to notify the affected persons where required by applicable law.
Visitors and customers are advised to review this Policy periodically in order to remain informed about the current manner of processing personal data.