Security and proper use of personal data is of utmost importance to us. Our personal data policy does not regulate rights and obligations but serves to explain the users what data we use in order to provide our goods and services, why and how do we process it and when is it necessary to disclose it to third parties. The policy also serves to inform about the rights that users have concerning the processing of personal data done by EL SMART Ltd.
To make this document clear and user friendly, we use illustrative examples throughout. These examples are not a part of the Personal Data Policy and are not exhaustive.
Basic principles in personal data processing
We process personal data in a lawful, well-meaning and transparent manner. The personal data is processed for concrete, explicitly stated and legitimate purposes and is NOT processed for any other reasons. The processed data is appropriate, associated with and limited to what is necessary according to our purposes (“reducing data to the minimum”);
The processed data can be kept up to date by taking all necessary means to guarantee timely deletion or correction of inaccurate personal data considering our purposes (“accuracy”);
The processed data is kept in a state that allows identifying the subject for a period no longer than the necessary (“limited storage”);
The processed data is kept in a state that guarantees a necessary level of security, including protection from unauthorized or illegal processing and from accidental loss, destruction or damage by taking suitable technical and organizational measures (“integrity and confidentiality”).
Personal data administrator
The personal data Administrator is EL SMART Ltd., BULSTAT Unified Identification Code (UIC) BG204353117, with headquarters and registered office addressSofia, Mladost District, Ring Road, Kare Business Center, 257 . If you have questions concerning privacy or security and want to contact our employees, you can do it via this e-mail address: firstname.lastname@example.org
This personal data policy can be altered according to the national and the European legislation. All changes take effect the moment they’re published on this page. We advise you to check our website regularly so that you can see the latest changes. The changes can not be made if they imply weaker security of personal data without your agreement.
What types of data do we process
We collect personal data so that we can improve our goods and services. Here are the types of information that we need:
Information you provide: we receive and keep all information you provide that has to do with EL SMART’s services. For example: information concerning searches you conducted, your client profile, e-mail, phone number, address, inquiries, applications for access to personal information, etc.
We may also use device identifiers, cookies, and other technologies on devices, applications, and web pages to collect information about browsing, use, or other technical information for fraud prevention purposes.
Information from other sources: We may receive information about you from other sources, such as: delivery information of goods purchased through the site, information on the number of page views.
On what basis do we collect and process your personal data
Objectives for personal data processing
We process your personal data in order to provide and improve the goods and services on the site. These objectives include:
Purchase and delivery of products and services. We use your personal data to accept and handle orders, deliver products and services, make payments and communicate with you about orders, products, services and promotional offers.
Provide, troubleshoot and improve the services of EL SMART Ltd. We use your personal data to provide functionality, analyze performance, correct errors and improve website usability and efficiency.
Recommendations and personalization. We use your personal information to recommend features, products and services that may be of interest to you, identify your preferences and customize your experience on the site.
Fulfillment of statutory obligations. In some cases, we have a legal obligation to collect and process your personal information. For example, we process personal data in order to fulfill the obligations arising from accounting and tax law. Also, when a consumer purchases a product from EL SMART Ltd. under consumer protection law, EL SMART Ltd. is obliged to provide a guarantee for the product if, at the time of its delivery, it is defective, which manifests itself within two years after making it available to the user. In order to fulfill this obligation, EL SMART Ltd. should process the basic data of the consumer (by which the right to claim is established), as well as the data for the respective contract (by which it is established whether the commodity is under warranty).
Communicating with you. We use your personal information to communicate with you regarding the goods and services we provide through various channels (e.g., by phone, email, chat). Fraud and Credit Risk Prevention. We process personal information to prevent and detect fraud and abuse and to protect the security of our customers.
Objectives for which we seek your consent. We may also request your consent to process your personal data for the specific purpose that we communicate to you. When you agree to process your personal data for a specific purpose, you may withdraw your consent at any time and we will stop processing your data for that purpose. However, if the processing is necessary for other lawful purpose, we can continue to process the data.
Categories of individuals to whom we disclose the user’s personal data
Examples of personal data processors are:
- Courier service providers;
- Service providers for the deployment and / or maintenance of information systems that sometimes need to access personal data processed in the systems concerning providing the services;
- Law firms, accounting firms or other consultancy providers;
- Hosting Service Providers
EL SMART Ltd. may share personal information of its clients with banks and payment institutions. For the purpose of servicing the consumers’ payments, whether by bank transfer or through a payment institution, it is necessary to exchange data between EL SMART Ltd. and the respective bank or payment institution. Third parties that have to do with the transformation (e.g. merger or acquisition) or the transfer of an enterprise. In the case of conversion of EL SMART Ltd., as well as in the case of transfer of assets in accordance with the applicable legislation, it is possible that the personal data of the users, administered by EL SMART Ltd., may be provided to a third party successor. Authorities. The legislation of the Republic of Bulgaria requires EL SMART Ltd. to store certain personal data for the users for a fixed period. In the presence of statutory prerequisites, such personal data processed by EL SMART Ltd. should be made available to the competent authorities.
What methods do we use to protect your personal data?
We work diligently to protect the security of your information when transferring it, using a Secure Sockets Layer (SSL) certificate that encrypts the information you enter. In addition, we maintain physical, electronic, and procedural safeguards regarding the collection, storage and disclosure of your personal information. Our security procedures mean that we may sometimes ask for proof of identity before disclosing your personal information. Devices that store your personal data offer security features to help protect them against unauthorized access and data loss. It’s important to protect yourself against unauthorized access to your password and to your computers and devices. Be sure to sign out when you’re done using a shared computer.
How long do we store your personal data
General information on the rights of individuals
EL SMART Ltd. takes action at the request of an individual to exercise a right under this section only if able to identify the person concerned. Only individuals who can be identified by EL SMART Ltd. have the opportunity to exercise their rights under this section. If the purposes for which EL SMART Ltd. processes personal data do not require or no longer require the identification of an individual, EL SMART Ltd. has no obligation to maintain, obtain or process additional information in order to identify the person for the sole purpose of taking action at the request of that person. EL SMART Ltd. notifies individuals of the actions taken within one month of receiving a request under this section, in some cases this period may be extended by another two months. EL SMART Ltd. shall provide individuals with information on actions taken in connection with their claims for the exercise of rights under this section without undue delay and in any event within one month of receipt of the request. If necessary, this period may be extended by another two months, taking into account the complexity and number of requests. EL SMART Ltd. shall inform the person concerned of any such extension within one month of receipt of the request, indicating the reasons for the delay. In case of refusal to fulfill the request, EL SMART Ltd. informs the respective individuals about their rights. If EL SMART Ltd. does not take action at the request of an individual, EL SMART Ltd. shall notify them (without delay and within one month after receiving the request) for the reasons for not taking action, as well as for the possibility of filing Appeal to the Commission for Personal Data Protection and Legal Prosecution. In certain cases EL SMART Ltd. may request additional information to verify the identity of individuals. In the event that EL SMART Ltd. has reasonable concerns about the identity of the individual who requests this section, EL SMART Ltd. may request the provision of additional information necessary to confirm the identity of the individual.The actions taken by EL SMART Ltd. for and in connection with claims for the exercise of rights under this section are completely free of charge to the persons, unless their claims are manifestly unfounded or excessive. When the case is such (for example, because of its repetitive nature), EL SMART Ltd. has the right, at its sole discretion: (a) to refuse to comply with the request; or (b) request payment of a reasonable fee, determined on the basis of the administrative costs necessary to provide the requested information or to take the requested action.
Users have the right to access personal data concerning them
Consumers have the right to receive information from EL SMART Ltd. whether personal data related to them is being processed. If so, users have the right to access the relevant data.Correcting inaccurate or out of date personal dataIf the personal data processed by EL SMART Ltd. is inaccurate or out of date, users have the right to request that EL SMART Ltd. corrects them.
Deletiton of personal information (“Right to be forgotten”)
Users have the right to request from EL SMART Ltd. to delete their personal data in the following cases:
- personal data is no longer needed for the purposes for which it was collected or processed;
- the consumer has withdrawn his consent on which the processing of personal data is based and there is no other legal basis for the processing of the personal data;
- the consumer has objected to the processing of personal data which is based on the legitimate interest of EL SMART Ltd., unless there are other legitimate grounds for processing that take precedence over the interests, rights and freedoms of the user, or the processing of data is necessary for the establishment, exercise or defense of legal claims;
- the consumer has objected to the processing of personal data for the purposes of direct marketing and there are no other legitimate grounds for processing that data;
- personal data relating to the respective user wasprocessed illegally;
- personal data must be deleted by EL SMART Ltd. in order to comply with a legal obligation arising from the law of the Republic of Bulgaria or the law of the European Union.
Restrict the processing of my personal data
As of May 25, 2018, users have the right to request from EL SMART Ltd. to restrict the processing of related personal data in the following cases:
- the accuracy of personal data is challenged by the user for a period that allows EL SMART Ltd. to verify the accuracy of the personal data;
- the processing is unlawful, but the user does not want the personal data to be erased, but calls for restricting its use instead;
- EL SMART Ltd. no longer needs personal data for the purposes of processing, but the user requires it for the establishment, exercise or defense of legal claims;
- the consumer has objected to the processing of personal data based on the legitimate interest of EL SMART Ltd., pending verification that the legitimate grounds of EL SMART Ltd. have priority over the interests of EL SMART Ltd.
Portability of my personal data
As of May 25, 2018, users have the right to receive from EL SMART Ltd. the personal data provided by them in a structured, widely used and machine-readable format, as well as to transfer this data to another administrator without hindrance from EL SMART Ltd. insofar as:
- EL SMART Ltd. processes this data for the purpose of concluding or executing a contract with the consumer, or on the basis of the consent of the latter; and
- the processing of the relevant data is done in an automated manner.
Users have the right to request EL SMART Ltd. to transfer their personal data directly to another administrator, when technically feasible.
Objection to the processing of personal data
Consumers have the right, at any time and on grounds relating to their particular situation, to object to the processing of personal data concerning them when EL SMART Ltd. processes their data to protect their legitimate interests. In certain cases, this right is unconditional and EL SMART Ltd. will always suspend the processing of data in case of objection from the users. These are the cases in which EL SMART Ltd. processes personal data for direct marketing purposes.
In all other cases, depending on the nature of the objection and the circumstances put forward by the relevant consumer, EL SMART Ltd. will carry out an internal review of the objection and rule on it in accordance with this section, by: (a) informing the consumer that it will suspend the processing of his / her personal data; or (b) reasonably refuses to suspend the processing of his / her personal data, if there are legal grounds for doing so.
You can exercise your right of access to your personal data, correct, delete, restrict their processing and portability here.
Right to complain to a supervisory authority
Consumers have the right to file complaints or alerts to the Commission for Personal Data Protection (CPDP) in the event that they believe EL SMART Ltd. violates personal data protection legislation. Complaint instructions are published on the CPDP website https://www.cpdp.bg
After 25.05.2018, consumers may also file complaints with other supervisory authorities within the territory of the European Union as provided for in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (on the protection of individuals with regard to the processing of personal data and the free movement of such data and repealing Directive 95/46 / EC (General Data Protection Regulation), or hereinafter referred to as “GDPR”.