PRIVACY POLICY REGARDING THE PROCESSING OF PERSONAL DATA |
This Privacy Policy (the “Policy”) governs the terms, conditions, and principles under which „Newma Consulting“ EDPK, UIC 208209281, with its registered seat and address of management at: Lovech, 5500, 76 Targovska St., Entrance B, Apt. 11 (hereinafter referred to as the “Controller”), collects, processes, stores, and discloses personal data of data subjects when using the Platform.
This Policy has been prepared in accordance with the applicable Bulgarian and European legislation, including, but not limited to, Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”) and the Personal Data Protection Act.
This Policy is of an informative nature and aims to provide data subjects with clear and accessible information regarding the processing of personal data in connection with the use of the Platform. The use of the Platform does not, in itself, constitute consent to all personal data processing activities. Where consent is required for a specific processing activity, it shall be obtained separately through a clear and unambiguous affirmative action by the data subject.
The Controller declares that it respects the privacy of all data subjects, applies the principle of data minimisation, and implements all necessary technical and organisational measures to ensure the protection of personal data.
I. CATEGORIES OF PERSONAL DATA PROCESSED BY THE CONTROLLER.
The Controller processes the following main categories of personal data:
The processing of personal data is carried out solely for the purposes set out in this Policy and on the basis of applicable legal grounds, including consent, performance of a contract The aforementioned categories of personal data may relate to different categories of data subjects, including registered Users, visitors of the Platform, and individuals who have communicated with the Controller.
1. PERSONAL DATA OF USERS.
Categories of data subjects
Users are all natural persons who use the functionalities and services provided through the Platform.
Categories of personal data
In the course of using the services provided through the Platform, the Controller processes the following categories of personal data: names, date of birth (where applicable), email address, telephone number, as well as any other information voluntarily provided by the data subject, insofar as it is necessary for the provision of the services.
The Controller does not collect or store data relating to bank accounts or payment cards. Payments are processed through external payment service providers acting as independent controllers or data processors.
Identity verification
The Controller may request additional information for the purpose of verifying the identity of the User solely where there is a reasonable suspicion of misuse, fraud, or unauthorised use of the services. In such cases, the principle of data minimisation shall be observed, and copies or images of identity documents shall not be stored unless required by law.
Purposes and legal grounds for processing
Personal data shall be processed on the basis of at least one of the following legal grounds:
– Art. 6(1)(b) of Regulation (EU) 2016/679 – performance of a contract or steps prior to entering into a contract;
– Art. 6(1)(c) – for compliance with a legal obligation to which the Controller is subject;
– Art. 6(1)(a) – on the basis of the explicit consent of the data subject;
– Art. 6(1)(f) – on the basis of the legitimate interests of the Controller, provided that such interests are not overridden by the rights and freedoms of the data subject.
The main purposes of processing include: identification of users, conclusion and performance of contracts, processing of orders, provision of customer support, and compliance with statutory obligations.
Retention period
Personal data related to contractual relationships shall be retained for a period of up to 5 (five) years following the termination of the respective relationship, in accordance with applicable tax and accounting legislation, unless a longer retention period is required by law or is necessary for the establishment, exercise, or defence of legal claims.
Recipients of personal data
Personal data may be disclosed, where a legal basis exists, to the following categories of recipients: employees and collaborators of the Controller on a need-to-know basis; IT and hosting service providers; accounting and auditing firms; legal advisors; and competent public authorities and regulatory bodies.
Where third parties process personal data on behalf of the Controller, they shall act as processors within the meaning of Regulation (EU) 2016/679 and shall be bound by a contractual arrangement.
2. PERSONAL DATA OF VISITORS, USERS, AND DATA OBTAINED THROUGH CONTACT FORMS
Categories of personal data
When using the Platform, data relating to user behaviour may be processed, including activity history, interaction with content, and use of functionalities.
When a contact form is used, the following data are processed: name and email address, as well as the content of the message.
Purposes and legal grounds
The processing is carried out for the purposes of handling inquiries, maintaining communication, and ensuring the operation and security of the Platform..
The legal basis for processing is:
– Art. 6(1)(b) of Regulation (EU) 2016/679 – processing necessary for taking steps at the request of the data subject;
– Art. 6(1)(f) – legitimate interest in maintaining the security and functionality of the Platform.
Retention period
Data submitted via the contact form are retained for a period of up to 6 (six) months from receipt, unless a contractual relationship is subsequently established or another legal basis for longer retention exists.
3. MARKETING AND TECHNICAL DATA
Categories of personal data
Technical data include: IP address, access data, browser type and version, operating system, navigation data, duration of visits, and other data generated through the use of the website.
Marketing data include preferences regarding the receipt of commercial communications, participation in campaigns, games, and surveys.
Purposes and legal grounds
Technical data are processed for the purposes of ensuring the security, maintenance, and improvement of the Platform, on the basis of the Controller’s legitimate interest pursuant to Article 6(1)(f) of Regulation (EU) 2016/679.
Marketing data is processed:
– on the basis of consent – Article 6(1)(a);
– in the context of existing customer relationships – on the basis of legitimate interest, subject to the right to opt out at any time.
Retention period
Technical data are retained for a period of up to 12 (twelve) months. Marketing data are retained until consent is withdrawn, but in any event no longer than 3 (three) years from the last interaction with the data subject.
Special provisions
Marketing communications are sent electronically only where consent has been obtained or where an existing customer relationship exists, provided that an opt-out Prior to any disclosure of personal data to third parties for their own marketing purposes, explicit consent shall be required.
4. ADDITIONAL PROVISIONS
Rights of Data Subjects
Data subjects have the right of access, rectification, erasure, restriction of processing, data portability, as well as the right to object to processing.
Transfers outside the EU
Where a transfer of personal data outside the European Economic Area is necessary, appropriate safeguards shall be applied in accordance with Chapter V of Regulation (EU) 2016/679.
II. METHODS OF COLLECTION OF PERSONAL DATA
Personal data processed by the Controller are collected through several principal methods.
Firstly, personal data may be provided directly by the data subject through voluntary input within the Platform, including during registration, submission of inquiries, completion of purchases, or use of specific functionalities of the mobile application.
Secondly, certain categories of technical data are collected automatically through the use of the Platform by means of implemented technological tools, including cookies, SDK modules, and other similar technologies, which enable the collection of information regarding the user’s device, behaviour, and interaction with the Platform. Such data are processed for the purposes of ensuring the security, stability, and proper functioning of the services, as well as for analysis and improvement of their quality.
Thirdly, the Controller may receive personal data from third parties where this is necessary for the provision of services, including providers of technical, analytical, marketing, or payment services. In such cases, the respective third parties act either as independent controllers or as processors, depending on the specific relationship.
The data subject is responsible for the accuracy and up-to-dateness of the personal data provided. The provision of personal data relating to third parties is permitted only where a valid legal basis exists and in compliance with applicable law. The Controller shall not be liable for unlawfully provided data by users, insofar as it has no objective possibility to exercise prior control over such data.
When using the Platform, cookies and similar technologies may be deployed through which information regarding user activity, preferences, and service usage patterns is collected. The processing of data through such technologies is carried out in accordance with Regulation (EU) 2016/679 and applicable law, whereby:
– for strictly necessary technologies, the legal basis is Article 6(1)(b) or Article 6(1)(f);
– for all other technologies, processing is carried out on the basis of prior consent pursuant to Article 6(1)(a).
Detailed information regarding the technologies used, their purposes, retention periods, and management options is provided in the separate Cookies Policy, which forms an integral part of this Policy.
Where personal data are received from or transferred to third parties established outside the European Economic Area, the Controller ensures that processing is subject to appropriate safeguards pursuant to Chapter V of Regulation (EU) 2016/679. Such safeguards include the use of Standard Contractual Clauses approved by the European Commission or other recognised mechanisms ensuring an adequate level of protection of personal data.
Transfers of personal data to third countries are carried out only where necessary for the provision of specific services or functionalities and provided that effective means for safeguarding the rights and freedoms of data subjects are ensured.
III. SECURITY MEASURES.
The Controller implements appropriate technical and organisational measures for the protection of personal data, in accordance with the requirements of Article 32 of Regulation (EU) 2016/679, as well as the nature, scope, context and purposes of processing, and the risks to the rights and freedoms of data subjects.
The implemented measures are designed to ensure the confidentiality, integrity, availability, and resilience of the systems and services involved in the processing of personal data, as well as to prevent unauthorised access, loss, destruction, alteration, or unauthorised disclosure.
Access to personal data is granted solely to persons for whom such access is necessary for the performance of their duties, on a strict need-to-know basis. Such persons are duly authorised, receive appropriate training on personal data protection, and are bound by confidentiality obligations.
The Controller applies internal rules and procedures governing the processing of personal data, including policies on access control, incident management, data retention and destruction, as well as periodic review and updating of security measures.
As part of the technical security measures, and where applicable, the Controller implements: encryption and/or pseudonymisation of personal data; secure communication protocols; access control and management systems; logging and traceability of actions; protection against malicious software and unauthorised access; and data backup and recovery mechanisms.
The Controller conducts periodic assessments of the effectiveness of the implemented measures, including through testing, analysis, and audits, in order to ensure a continuously adequate level of security, in line with technological developments and evolving risks.
In the event of a personal data breach, the Controller shall take immediate action to determine the scope and cause of the incident, mitigate its consequences, and prevent further occurrences. Where required under applicable law, notification shall be made to the competent supervisory authority and to affected data subjects within the prescribed time limits.
It should be noted that, notwithstanding the implementation of state-of-the-art security measures, the transmission of information via the internet cannot be fully secured, and a residual risk of unauthorised access therefore exists. The Controller shall make all reasonable efforts to minimise such risk.
IV. PURPOSES OF DATA PROCESSING
The Controller collects and processes personal data solely for specified, explicit and lawful purposes, in accordance with the principles set out in Regulation (EU) 2016/679.
The main purposes of processing include the provision and maintenance of the services accessible through the Platform, management of user accounts, ensuring the functionality, security and stability of the systems, as well as the performance of contractual and pre-contractual obligations.
Personal data may also be used for communication with users, including for sending notifications related to the use of the Platform, as well as for providing information regarding services, functionalities, or changes in the Controller’s activities.
Where explicit consent has been obtained, personal data may be used for marketing purposes, including the sending of commercial communications, information about new services, promotions and campaigns, as well as for conducting surveys and studies aimed at improving service quality.
The legal basis for the processing of personal data is determined depending on the specific purpose and includes:
– Art. 6(1)(b) of Regulation (EU) 2016/679 – where processing is necessary for the performance of a contract or in order to take steps prior to entering into a contract;
– Art. 6(1)(c) – where processing is necessary for compliance with a legal obligation;
– Art. 6(1)(a) – where the data subject has given explicit consent;
– Art. 6(1)(f) – where processing is necessary for the purposes of the legitimate interests pursued by the Controller, including ensuring security, preventing abuse, and improving services, provided that such interests are not overridden by the rights and freedoms of the data subject.
Where processing is based on consent, such consent is given through a clear affirmative action for specific purposes and may be withdrawn at any time, without affecting the lawfulness of processing carried out prior to its withdrawal.
The Controller does not use personal data for purposes incompatible with those initially specified, except where required by applicable law, including where necessary for compliance with a legal obligation or for the protection of the vital interests of the data subject.
V. DISCLOSURE OF PERSONAL DATA
The Controller does not disclose or provide personal data to third parties, except where this is necessary and where an appropriate legal basis exists in accordance with Regulation (EU) 2016/679.
Personal data may be disclosed to third parties in the following cases:
Firstly, where this is necessary for the performance of a contract or for the provision of a service requested by the data subject. In such cases, the data may be disclosed to service providers, including technical, IT, hosting, payment service providers, or other external partners supporting the operation of the Platform.
Secondly, where third parties process personal data on behalf of the Controller, they act as processors within the meaning of Art. 28 of Regulation (EU) 2016/679. In such cases, processing is carried out on the basis of a concluded agreement ensuring that the processor acts solely on documented instructions from the Controller and in compliance with the applicable data protection requirements.
Thirdly, personal data may be disclosed to third parties acting as independent controllers, where this is necessary for the provision of certain services or functionalities. In such cases, the respective party processes the data in accordance with its own privacy policy.
Fourthly, personal data may be disclosed to competent public authorities, courts, or other institutions where this is necessary for compliance with a legal obligation, for the protection of the rights and legitimate interests of the Controller, or for the prevention, investigation, and detection of violations or abuses.
The Controller does not sell personal data to third parties and does not disclose such data for their own marketing purposes without the explicit consent of the data subject.
Where personal data is disclosed to third parties, the Controller takes the necessary measures to ensure that such parties process the data lawfully, in good faith, and in compliance with appropriate technical and organisational measures for protection.
Where recipients of personal data are established outside the European Economic Area, data transfers are carried out subject to appropriate safeguards in accordance with Chapter V of Regulation (EU) 2016/679, including the use of Standard Contractual Clauses or other recognised protection mechanisms.
VI. PERSONAL DATA RETENTION PERIODS.
Personal data shall be retained for a period necessary to achieve the purposes for which it has been collected, unless a longer retention period is required or permitted by applicable law. In determining retention periods, the Controller applies the principles of lawfulness, data minimisation, and storage limitation in accordance with Regulation (EU) 2016/679.
Retention periods are determined depending on the category of data and the purposes of processing, as follows:
Personal data processed in connection with the conclusion and performance of contractual relationships are retained for the duration of the contractual relationship and for a period of up to 5 (five) years following its termination, unless a longer period is required under applicable law.
Personal data contained in accounting and tax documents, including data relating to payments and transactions, shall be retained for a period of up to 10 (ten) years in accordance with the requirements of tax and accounting legislation.
Personal data processed for marketing purposes shall be retained until the withdrawal of consent by the data subject or until the exercise of the right to object to processing, unless another legal basis exists for their continued retention.
Technical data and data collected through cookies and similar technologies shall be retained for the periods specified in the Cookie Policy, unless a shorter period results from the technical parameters of the respective technology.
Personal data provided through contact forms or inquiries shall be retained for a period of up to 6 (six) months from their receipt, unless a subsequent contractual relationship arises or another legal basis for their retention exists.
Upon expiry of the applicable retention periods, personal data shall be securely deleted or anonymised in such a manner that the identity of the data subject can no longer be established.
Where personal data is retained for the purposes of the establishment, exercise, or defence of legal claims, such data may be retained for a longer period corresponding to the applicable limitation periods.
VII. RIGHTS OF DATA SUBJECTS.
Data subjects are entitled to rights guaranteed under Regulation (EU) 2016/679 and the Bulgarian Personal Data Protection Act, which ensure control over the processing of their personal data.
The data subject has the right of access under Article 15 of Regulation (EU) 2016/679, including the right to obtain confirmation as to whether personal data concerning them are being processed, and, where that is the case, access to such data and information regarding the purposes of processing, categories of data, recipients, and retention periods.
The data subject has the right to rectification under Article 16 of Regulation (EU) 2016/679, allowing them to request the correction of inaccurate personal data or the completion of incomplete data.
The data subject has the right to erasure (“right to be forgotten”) under Article 17 of Regulation (EU) 2016/679, where the legal conditions are met, including where the data is no longer necessary for the purposes for which it was collected, where consent has been withdrawn, or where the processing is unlawful. This right shall not apply where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.
The data subject has the right to restriction of processing under Article 18 where the legal grounds are met, including where the accuracy of the data is contested or where an objection to processing has been raised.
The data subject has the right to data portability under Article 20 of Regulation (EU) 2016/679, where processing is based on consent or a contract and is carried out by automated means.
The data subject has the right to object under Article 21 of Regulation (EU) 2016/679 to the processing of personal data based on legitimate interests, as well as to processing for direct marketing purposes, in which case processing shall cease without undue delay.
The data subject has the right to withdraw consent at any time pursuant to Article 7(3) of Regulation (EU) 2016/679, without affecting the lawfulness of processing carried out prior to such withdrawal.
The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, pursuant to Article 22 of Regulation (EU) 2016/679, subject to the statutory exceptions.
The data subject has the right to lodge a complaint with a supervisory authority pursuant to Article 77 of Regulation (EU) 2016/679, as well as to seek judicial protection.
Requests for the exercise of rights may be submitted to the Controller using the contact details provided in this Policy. The Controller shall review and respond to each request without undue delay and in any event within one (1) month of receipt. Where necessary, this period may be extended by up to two (2) additional months, taking into account the complexity and number of requests, and the data subject shall be informed accordingly.
Where requests are manifestly unfounded or excessive, in particular due to their repetitive nature, the Controller may refuse to act on the request or may charge a reasonable fee in accordance with Article 12(5) of Regulation (EU) 2016/679.
For security purposes, the Controller may request additional information necessary to confirm the identity of the person submitting the request.
VIII. LINKS TO THIRD-PARTY WEBSITES AND SERVICES.
The Platform may contain hyperlinks, integrations, plugins, or functionalities provided by third parties. The activation or use of such functionalities may result in the collection and processing of information, including personal data, by the respective third parties.
In such cases, the relevant third parties may act as independent controllers within the meaning of Regulation (EU) 2016/679, processing personal data in accordance with their own privacy policies and terms of use.
The Controller does not exercise control over the processing of personal data carried out by such third parties and assumes no responsibility for their policies, practices, or actions, except where such third parties act on behalf of and under the instructions of the Controller.
Where third parties process personal data on behalf of the Controller, such processing is carried out pursuant to contractual arrangements compliant with the requirements of Article 28 of Regulation (EU) 2016/679, and in such cases the Controller ensures the implementation of appropriate data protection measures.
The Controller does not knowingly track users’ activity outside the Platform, nor does it collect data regarding their behaviour on other websites or services, unless this is explicitly provided for through the use of integrated technologies and on the basis of an appropriate legal ground.
Upon leaving the Platform or using external services, data subjects are advised to review the respective privacy policies and terms of use, as the processing of personal data in such cases takes place outside the control of the Controller.
IX. CHANGES TO THE PRIVACY POLICY.
The Controller reserves the right to amend and supplement this Privacy Policy in the event of changes to applicable legislation, the services provided, the technologies used, or internal personal data processing practices. All amendments shall be made in accordance with the principles of lawfulness, fairness, and transparency under Regulation (EU) 2016/679.
The current version of the Policy is published on the Platform and shall enter into force as of the date of its publication, unless expressly stated otherwise.
Where changes result in a material modification of the purposes of processing, the categories of personal data processed, or the rights of data subjects, the Controller shall take appropriate measures to notify data subjects, including by electronic communication or by a prominent notice on the Platform.
Where applicable, and in cases where the changes require the provision of new consent by data subjects, processing shall continue only after such consent has been obtained.
Changes that do not materially affect the rights and legitimate interests of data subjects may enter into force immediately upon publication.
Data subjects are encouraged to periodically review this Policy in order to stay informed about how their personal data is processed.