Mandatory privacy information strong>
Information about the company processing your data:
Name: strong> Rushana Stancheva - strong> strong> strong> Address for correspondence: strong> Sofia, Mladost 3 bl 327 ent.8
Phone: strong> 0898838414
Website: strong> https://beautycosmetic.biz/
Information about the competent supervisory authority nni
Name: Commission for Personal Data Protection
Seat and address of management in the city. Sofia 1592, blvd. & bdquo; Prof. Tsvetan Lazarov & rdquo; № 2
Address for correspondence: Sofia 1592, Blvd. & prof. Tsvetan Lazarov & rdquo; 2
Telephone: 02 915 3 518
operates in accordance with the Personal Data Protection Act and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data . This information is intended to inform you of all aspects of the processing of your personal data by the Company and the rights you have in relation to such processing.
Reason for collecting, processing and storing your personal data
Art. 1. The administrator collects and processes your personal data in connection with the use of the e-shop https://beautycosmetic.biz/ and the conclusion of contracts with the company pursuant to Art. 6, para. 1, Regulation (EU) 2016/679 (GDPR), and in particular on the following grounds:
You have explicitly obtained your consent as a customer;
Perform the obligations of the Administrator under contract with you;
Comply with a legal obligation that applies to the Administrator;
For the legitimate interests of the Administrator or a third party;
Objectives and Principles in Collecting, Processing and Storing Your Personal Data
Art. 2. (1) We collect and process the personal data you provide to us in connection with the use of the e-shop and the conclusion of a contract with the Company, including for the following purposes:
creating a profile and providing full functionality in the use of online shop;
signing and executing a distance contract;
individualizing a party to the contract
protecting information security
Ensuring the performance of the contract to provide a corresponding (2) We comply with the following principles in the processing of your personal data: Legitimacy, Integrity and Transparency;
Limitation of processing goals;
Relevance to processing goals and minimizing data collected;
Accuracy and timeliness of data
Restriction of storage to achieve goals
confidentiality of processing and ensuring an adequate level of security of personal data.
(3) the processing and storage of personal data, the Administrator may process and store personal data in order to protect its following legitimate interests: fulfillment of its obligations to the National Revenue Agency, the Ministry of Interior and other state and municipal authorities. br /> What types of personal data collects, processes and stores our company
Art. 3. (1) The Company carries out the following transactions with the personal data you provide for the following purposes:
Registration of a consumer in the e-shop and execution of a distance-purchase contract & ndash; the purpose of this operation is to create an account for using the e-shop to purchase goods and provide contact details for delivery of purchased goods. The registration and creation of an account for using the online store is not a mandatory step in providing the service and it is accessible to a significant extent without the creation of an account.
Conclusion of the impact assessment: Based on the Impact Assessment, the operation "Registration of an e-shop user and the execution of a distance-purchase contract" is permitted to perform and provides sufficient safeguards to protect the rights and legitimate interests of the data subject in accordance with GDPR requirements.
Concluding and executing a trade deal with a client or partner & ndash; the purpose of this operation is to conclude and execute a contract with a trading partner or client and its administration. Given the limited scope of personal data collected and the fact that part of it is collected from publicly available sources, it is not necessary to carry out an impact assessment on the operation of the impact assessment.
Sending newsletter (newsletter) & ndash; the purpose of this operation is to administer the process of sending ballots to clients who have declared they wish to receive.
Given the limited scope of personal data collected, an impact assessment does not require an impact assessment the operation.
Exercising the right of withdrawal or making a claim & ndash; the purpose of this operation is to administer the process of exercising the right of withdrawal or claim by the client.
(2) The administrator processes the following categories of personal data and information for the following purposes and on the following grounds :
Your personalizing data (e-mail, name, etc.)
Purpose for which data is collected: 1) Making a contact with the user and sending information to him, 2) For the purpose of registering a user in the online store, and 3) to send to Reason for processing your personal information - By accepting the general terms and conditions and registering in the online store or placing an order without registration or upon entering into a written agreement between the Administrator and you are creating a contractual relationship, We process your personal data & ndash; Art. 6, para. 1, b. (b) GDPR. Your data for sending a newsletter is processed at your explicit consent - Art. 6, para. 1, b. (a) GDPR.
Delivery details (names, telephone, address, etc.) Purpose for which data is collected: Execution of obligations of the administrator under a contract for the purchase and sale of Purchased goods.
Reason for processing your personal data - By accepting the terms and conditions and registering in the online store or placing an order without registration or upon entering into a written agreement between the Administrator and you, a contractual relationship is created We process your personal data & ndash; Art. 6, para. 1, b. (b) GDPR.
Additional data provided by you & ndash; If you want to add your profile, you can fill in the name, surname, phone number.
Data collection purpose: You have explicitly given consent to process your personal data for one or more specific purposes - 6, para. 1, b. (a) of GDPR at the time of registration in the online store. The provision of this data is not mandatory for registration in the online store.
(3) The administrator does not collect or process personal data relating to the following:
revealing racial or ethnic origin;
reveal political, religious or philosophical beliefs, or membership of trade unions;
genetic and biometric data, health data, or data about sexual life or sexual orientation.
(4) Personal data has been collected by the Administrator from the persons to whom they refer.
(5) The company does not performs automated decision making with data.
Art. 4. (1) The Company carries out the following transactions with the legal persons or legal representatives of legal entities - trade partners, personal data for the following purposes:
Conclusion and execution of a commercial transaction: For the conclusion and execution of a commercial transaction with a commercial company, we process only the full names of the legal representative or the person authorized by the company. Conclusion of the Impact Assessment: Given the small volume of individuals whose data are being processed and given the limited amount of personal data collected, an impact assessment is not necessary for the current operation.
(2) Personal data are collected by the Administrator from the persons to whom they refer also from the Commercial Register to the Registry Agency.
(3) The Company does not carry out automated decision making with data. 5. The administrator can use the so-called & bdquo; cookies & ldquo; for the purpose of providing full functionality to the website, improving user experience, statistical purposes, facilitated access, etc. that you agree to using our website. You can at any time control and / or delete cookies & ldquo; using the settings of the browser you are using.
& bdquo; Cookies & ldquo; are not personal data and are not used to identify visitors and users of the e-shop.
Term of storage of your personal data
Art. 6. (1) The administrator keeps your personal data for a period no longer than the existence of your online store account. After deleting your account, the Administrator takes the necessary care to erase and destroy all your data without undue delay or to anonymize them (ie to bring them in a form that does not reveal your personality).
(2) The Administrator processes your personal data you provided when ordering without registration in the online store until the order is completed unless you have given your explicit consent when processing your order to process your data for the purposes of service improvement, (3) The administrator keeps your personal data provided in connection with online orders for a period of 5 years for the purpose of protecting the legal interests of the Administrator in case of legal or administrative disputes with users of the online store.
(4) The Administrator shall notify you in case the data retention period is required to be extended in order to comply with a statutory obligation or with respect to the legitimate interests of the Administrator (5) The administrator keeps the personal data that he or she needs to keep under the applicable law for the specified term, which may exceed the life of your e-shop account or until the order is completed.
Art. 7. The administrator keeps the personal data of the legal representatives of its trading partners for the duration of the contract, respecting the legitimate interests and legal obligations of the Administrator, which may exceed the term of the contract. processing data
Art. 8. (1) The administrator may, at its own discretion, transmit all or part of your personal data to processors for the fulfillment of the processing purposes you have agreed to, subject to the requirements of Regulation (EC) 2016/679 (GDPR) .
(2) Your administrator notifies you if you intend to transfer all or part of your personal data to third countries or international organizations.
Your rights to the collection, processing and storage of your personal data
Withdrawal of consent to process your personal data
Art. 9. (1) If you do not wish to have your personal data processed for marketing purposes and receive a newsletter, you may at any time withdraw your consent for processing by completing the withdrawal form in Appendix 1 or by request in free text, and send it to us by email.
(2) Once we receive your request, we will send you a letter with detailed instructions for your verification as a recipient to the email you have provided to receive newsletters and advertising messages bulletins and subject of personal data, for which (3) Withdrawal of consent does not affect the lawfulness of the processing of personal data that the Administrator has performed so far.
Right of access
Art. 10. (1) You have the right to request and obtain from the Administrator a confirmation that personal data relating to you are processed by sending a request in free text by email.
(2) You have the right to access the data, (3) Once we receive your request, we will send you to the email you used to register or place your personal information. in the e-shop, a letter with detailed instructions for your verification as a sub kt data to which access is requested.
(4) After completing the verification, according to par. 3, the Administrator shall provide you upon request with a copy of the processed personal data relating to you in electronic or other appropriate form.
(5) Providing access to the data is free of charge but the Administrator reserves the right to impose an administrative fee, in the event of repeatability or excessive demands.
Right to rectification or replenishment
Art. 11. (1) You can at any time correct or fill in the inaccurate or incomplete personal data associated with you through the & quot; Edit Account & quot; option.
(2) You can correct or fill in inaccurate or incomplete personal data relating directly to you through your website account or by requesting the Administrator by email using the form in Appendix 4 or a free text request.
Right to Delete (& bdquo; to be forgotten & ldquo; )
Right to delete (& bdquo; to be forgotten & ldquo;)
Art. 12. (1) You have the right to ask the Administrator to delete any or all personal data related to you and the Administrator has the obligation to delete them without undue delay when any of the following reasons exists:
personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
You withdraw your consent on which the processing of the data is based and no other legal basis for the processing;
You object to the processing of personal data related to you, incl for the purpose of direct marketing, and there are no legitimate grounds for processing that have an advantage; personal data has been tampered with;
personal data must be deleted to comply with a legal obligation under EU law or the law of a Member State that applies to the Administrator;
the personal data have been collected in connection with the provision of information society services. (2) The administrator is not obliged to delete the personal data if he / she keeps and processes them:
for the exercise of the right to freedom of expression and the right to information;
to comply with a legal obligation that requires treatment envisaged in EU law or the law of the Member State, which applies to the Administrator or for the performance of a task of public interest or in the exercise of the official authority conferred on it; for reasons of public interest in the field of public health;
for archive purposes public interest, scientific or historical research, or for statistical purposes;
for the establishment, exercise, or protection of legal claims.
(3) In order to exercise your right to be forgotten, an email request to delete your personal data that the Administrator processes by filling in the form in Appendix 2 or by free text request, and then the Administrator will send a letter to the email you used to register or place orders in the e-shop under (4) Once you have verified the identity of the person making the request and the person to whom the data relate in accordance with the instructions we send, we will delete all data we process for you in accordance with par. 3.
(5) If there is an order you are currently processing, the earliest point at which you can request to be & quot; forgotten & & quot; is upon the successful completion of the order. > Right of limitation
Art. 13. You have the right to require the Administrator to limit the processing of your related data by sending us a request in free text by email when:
you contest the accuracy of the personal data for a period that allows the Administrator to verify the accuracy
The processing is illegal, but you do not want the personal data to be deleted but only the use of the data is limited;
The administrator no longer needs the personal data for processing purposes, but you you require for establishment, exercise or the defense of your legal claims;
You have resisted the processing pending verification that the legal grounds of the Administrator have an advantage over your interests.
(2) Once we receive your request, we will send you the email that you used to sign up or place orders in the e-shop, a letter with detailed instructions for your verification as a shop user, and a subject of personal data that has been requested to restrict the processing.
(3) Once the verification has been performed agree o para. 2, the Company will cease processing your data but will not remove the posts you made in the online store, if any.
Art. 14. (1) If you have given consent for the processing of your personal data or processing is necessary for the contract with the Administrator, or if your data is processed in an automated way, you can:
can ask the administrator to provide you Your personal data in a readable format and transfer them to another Administrator;
You can ask the Administrator to transfer your personal data directly to an administrator you specify when it is technically feasible.
(2) You can exercise your right of portability us email the completed form in Annex № 3, or request a free text, then the administrator will send the email you used to register or carry out orders in the electronic shop, a letter with detailed instructions for your verification as a shop user and the subject of the personal data for which a request for portability is requested.
(3) After performing the verification under par. 2, the Company sends the data it processes to you in the XML format you specified.
The right to receive information
Art. 15. You may request the Administrator to inform you of all recipients to whom personal data for which the correction, deletion or limitation of the processing was requested has been disclosed. The administrator may refuse to provide this information if this would be impracticable or would require disproportionately large efforts.
Art. 16. You may object at any time to the processing of personal data by the Administrator, which relate to it, including if treated for the purposes of profiling and direct marketing.
Your Rights in breach of the security of your personal data < br /> Art. 17. (1) The Administrator finds co breach of security of your personal data, which may pose a high risk to your rights and freedoms, it lets you know without undue delay of the infringement and the measures taken or to be taken .
(2) The administrator is not required to notify you if:
has taken appropriate technical and organizational measures to protect to the data affected by the breach;
subsequently took measures , which ensure that the violation will not lead to a high risk your rights;
notification would require disproportionate efforts.
Persons who provide your personal data
Art. 18. (1) For the purposes of the processing of your personal data and provide the service in its full functionality and view your interests administrator can provide data on these persons processors:
process personal data Purposes processing of personal data
courier company Speedy shipment to arrive to the address you
courier company Rapido shipment to arrive to the address you
Courier employee at Beauty cosmetic company shipment to arrive to your specified address p>
Mandatory privacy information strong>