GDPR
Information about the company that processes your data:
Picture name: MARKAN PROJECT Ltd.
UIC/BULSTAT: 131221670
Headquarters and registered office address: Sofia, Druzhba, bl.604, ground floor
Phone: +359 889 997 199
Email: office@markan-project.bg
Website: www.markan-project.bg
Information on the competent data protection supervisory authority
Name: Commission for Personal Data Protection
UIC/BULSTAT: 204062841
Registered office and registered address: gr. 1592 Sofia Blvd. "Proff. Tsvetan Lazarov" № 2
Address for correspondence: gr. 1592 Sofia Blvd. "Proff. Tsvetan Lazarov" № 2
Phone: 02 915 3 518
Website: www.cpdp.bg
MARKAN PROJECT Ltd (hereinafter referred to as "Controller" or "Company") carries out its activities in accordance with the Personal Data Protection Act and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. This information is intended to inform you about all aspects of the processing of your personal data by the Company and the rights you have in relation to this processing.
Basis for collecting, processing and storing your personal data
Art. 1. The controller collects and processes your personal data in connection with the use of the website https://markan-project.bg and the conclusion of contracts with the company on the basis of Art. 1, Regulation (EU) 2016/679 (GDPR), in particular on the following grounds:
- Explicit consent obtained from you as a customer;
- Performance of the Administrator's obligations under a contract with you;
- Compliance with a legal obligation applicable to the Administrator;
- For the purposes of the legitimate interests of the Controller or a third party.
Purposes and principles of collecting, processing and storing your personal data
Art. 2. (1) We collect and process the personal data you provide to us in connection with your use of the https://markan-project.bg website and entering into a contract with the company, including for the following purposes:
- creating a profile and providing full functionality when using the online store;
- placing orders and purchasing goods;
- individualization of a party to the contract;
- accounting purposes;
- statistical purposes;
- information security protection;
- securing the performance of the contract for the provision of the relevant service;
- participation in games, raffles, advertising campaigns;
- sending a newsletter if you wish.
(2) We comply with the following principles when processing your personal data:
- legality, fairness and transparency;
- limitation of the purposes of processing;
- relevance to the purposes of the processing and minimisation of the data collected;
- data accuracy and timeliness;
- limitation of storage to achieve the objectives;
- integrity and confidentiality of processing and ensuring an appropriate level of security of personal data.
(3) In processing and storing personal data, the Controller may process and store personal data in order to protect its following legitimate interests:
- fulfilling its obligations to the National Revenue Agency, the Ministry of the Interior and other state and municipal authorities.
What types of personal data our company collects, processes and stores
Art. 3. The Company shall carry out the following operations with the personal data provided by you for the following purposes:
- Conclusion and execution of a commercial transaction or contract with a customer - the purpose of this operation is the conclusion and execution of a contract with a commercial partner or customer and its administration. In individual cases, the purpose of the transaction may also be to protect the company's legitimate interests in the transaction. Given the limited scope of the personal data collected and the fact that some of it is collected from publicly available sources, an impact assessment is not necessary for this operation.
- Registration of a user in the e-shop and execution of a purchase contract - the purpose of this operation is to create a profile for using the e-shop to purchase goods and receive newsletters if desired. Providing contact details for making delivery of purchased goods. Given the limited scope of the personal data collected and the fact that some of it is collected from publicly available sources, an impact assessment is not necessary for this operation.
- Newsletter Sending - the purpose of this operation is to administer the process of sending newsletters to customers who have indicated that they wish to receive them. Given the limited scope of the personal data collected and the fact that some of it is collected from publicly available sources, an impact assessment is not necessary for this operation.
- Exercising the right of refusal or making a claim - the purpose of this operation is to administer the process of sending purchased goods to customers. Given the limited scope of the personal data collected and the fact that some of it is collected from publicly available sources, an impact assessment is not necessary for this operation.
- Event participant registration and sending information or prizes - the purpose of this operation is to administer the process of registering participants in events and games, and sending prizes from games held. Given the limited scope of the personal data collected and the fact that some of it is collected from publicly available sources, an impact assessment is not necessary for this operation.
- Request for delivery of a product that is not in stock - the purpose of this operation is to contact the individual in order to request delivery of a product that is currently out of stock. Given the limited scope of the personal data collected and the fact that some of it is collected from publicly available sources, an impact assessment is not necessary for this operation.
Art. 4. (1) The controller processes the following categories of personal data and information for the following purposes and on the following grounds:
- Registration and newsletter details (names, e-mail)
- Purpose for which the data is collected:
- Making contact with the user and sending information to him,
- for the purpose of user registration in the online store, and
- to send a newsletter.
- Basis for processing your personal data - By accepting the terms and conditions and registering in the e-shop or placing an order without registration, or by concluding a written contract, a contractual relationship is established between the Administrator and you, on the basis of which we process your personal data - Art. 1, б. (b) GDPR. Your data for sending the newsletter is processed on the basis of your explicit consent - Art. 6, para. 1, б. (a) GDPR.
- Purpose for which the data is collected:
- Details for receiving the newsletter (names, e-mail)
- Purpose for which the data is collected:
- To send a newsletter.
- Grounds for processing your personal data - Your data for sending the newsletter is processed on the basis of your explicit consent - Art. 1, б. (a) GDPR.
- Purpose for which the data is collected:
- Delivery details (name, phone, e-mail, address)
- Purpose for which the data is collected: performance of the controller's obligations under a distance purchase contract and delivery of purchased goods, including the exercise of the right of return and exchange or withdrawal from purchased goods.
- Basis for processing your personal data - By accepting the terms and conditions and registering in the e-shop or placing an order without registration, or by concluding a written contract, a contractual relationship is established between the Administrator and you, on the basis of which we process your personal data - Art. 1, б. (b) GDPR.
- Data from your social media accounts (publicly available information from your Google+, Facebook, Instagram accounts)
- Purpose for which the data is collected:
- Making contact with the user and sending information to him,
- for the purpose of registration for a game, raffle, campaign, etc.
- Grounds for processing your personal data - Your data for registration in our events, games, campaigns, etc. are processed on the basis of your explicit consent - Art. 1, б. (a) GDPR
- Purpose for which the data is collected:
(2) The controller shall not collect or process personal data relating to the following:
- reveal racial or ethnic origin;
- reveal political, religious or philosophical beliefs, or trade union membership;
- genetic and biometric data, health data or data on sex life or sexual orientation.
(3) Personal data are collected by the Controller from the persons to whom they relate.
(4) The Company shall not carry out automated decision-making with data.
(5) The Company does not collect and process data about persons under the age of 16 except with the express consent of their parents or legal representatives.
Storage period of your personal data
Art. 5. (1) The controller shall store your personal data for a period no longer than the existence of your account in the online store or until you withdraw consent to processing. Upon deletion of your account or successful termination, the Administrator shall take reasonable care to delete and destroy all of your data without undue delay or to anonymize it (i.e., to put it in a form that does not reveal your identity).
(2) The Controller shall store your personal data provided in connection with online orders for a period of 5 years for the purpose of protecting the legal interests of the Controller in the event of legal or administrative disputes with users of the online store, and the accounting documents shall be kept for the relevant statutory period.
(3) The Controller shall notify you in the event that the data retention period needs to be extended in order to comply with a legal obligation or in view of the legitimate interests of the Controller or otherwise.
Art. 6. The Controller shall store the personal data of the legal representatives of its business partners for the duration of the performance of the contract, in order to comply with the legitimate interests and legal obligations of the Controller, which may exceed the duration of the concluded contract.
Transfer of your personal data for processing
Art. 7. (1) The controller may, at its discretion, transfer some or all of your personal data to processors for the purposes of processing to which you have consented, subject to the requirements of Regulation (EU) 2016/679 (GDPR).
(2) The controller shall notify you in the event of an intention to transfer some or all of your personal data to third countries or international organisations.
Your rights in the collection, processing and storage of your personal data
Withdrawal of consent to the processing of your personal data
Art. 8. (1) If you do not wish all or part of your personal data to continue to be processed by the Company for any or all of the processing purposes, you may withdraw your consent to processing at any time by completing the form in your profile or by making a free text request.
(2) The Controller may ask you to verify your identity and identity with the data subject by asking you to enter your email address and password to access the website on site at the Company's office in front of an employee.
(3) By withdrawing consent to the processing of personal data that is required for the creation and maintenance of an online store account, your account will become inactive. Of course, you will be able to browse the online shop and the products offered and place orders as a guest or make a new registration.
(4) If there is an order placed by you that is in the process of being processed, the earliest point at which you can withdraw your consent to processing is upon successful completion of the order.
Right of access
Art. 9. (1) You have the right to request and obtain confirmation from the Controller as to whether personal data relating to you is being processed and, if you are a registered user, you may at any time view in your profile the personal data that you have provided and is being processed about you.
(2) You have the right to access the data relating to you and the information concerning the collection, processing and storage of your personal data.
(3) The controller shall provide you, upon request, with a copy of the personal data processed relating to you in electronic or other appropriate form.
(4) Providing access to the data is free of charge, but the Controller reserves the right to impose an administrative fee in case of repetition or excessive requests.
Right of correction or completion
Art. 10. You may correct or complete inaccurate or incomplete personal data relating to you directly through your website profile or by making a request to the Controller.
Right to erasure ("being forgotten")
Art. 11. (1) You have the right to ask the Controller to erase some or all of the personal data relating to you and the Controller has the obligation to erase them without undue delay where one of the following grounds applies:
- the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
- You withdraw your consent on which the processing is based and there is no other legal basis for the processing;
- You object to the processing of personal data relating to you, including for direct marketing purposes, and there are no legitimate grounds for the processing that override;
- personal data have been unlawfully processed;
- the personal data must be erased in order to comply with a legal obligation under EU or Member State law to which the Controller is subject;
- personal data have been collected in connection with the provision of information society services.
(2) The controller is not obliged to erase the personal data if it stores and processes them:
- to exercise the right to freedom of expression and the right to information;
- to comply with a legal obligation requiring processing provided for by EU or Member State law to which the Controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
- for public health reasons;
- for archiving purposes in the public interest, for scientific or historical research or for statistical purposes;
- for the establishment, exercise or defence of legal claims.
(3) In the event that you exercise your right to be forgotten, the Company will delete all of your data except for the following information:
- information that is necessary to certify that your right to be forgotten has been exercised;
- technical information about the operation of the online shop, which information cannot be linked to your person in any way;
- e-mail address with which you registered in the online store.
(4) In order to exercise your right to be forgotten, you need to submit a request via your account in the online store or by sending an email request to the Administrator.
(5) The controller may ask you to verify your identity and identity with the person to whom the data relate.
(6) If there is an order placed by you that is in the process of being processed, the earliest point at which you can request to be "forgotten" is upon successful completion of the order.
(7) By deleting your personal data, your account will become inactive. Of course, you will be able to browse the online shop and the products offered and place orders as a guest or make a new registration.
(8) The controller shall not delete the data which it has a legal obligation to store, including for the purpose of defending legal claims made against it or proving its rights.
Right to restriction
Art. 12. You have the right to request the Controller to restrict the processing of data relating to you where:
- contest the accuracy of the personal data, for a period that allows the Controller to verify the accuracy of the personal data;
- the processing is unlawful, but you do not wish the personal data to be erased, but only for its use to be restricted;
- The controller no longer needs the personal data for processing purposes, but you require it for the establishment, exercise or defence of legal claims;
- You have objected to processing pending verification that the legitimate grounds of the Controller override your interests.
Right to portability
Art. 13. (1) You can at any time download or receive in machine-readable format the data that is stored and processed for you in connection with the use of the services of the Controller, directly through your account via the data export option or by email request.
(2) You may request the Controller to transfer your personal data directly to a controller designated by you, where this is technically feasible.
Right to receive information
Art. 14. You may request the Controller to inform you of any recipients to whom the personal data for which rectification, erasure or restriction of processing has been requested have been disclosed. The controller may refuse to provide this information if it would be impossible or would require a disproportionate effort.
Right to object
Art. 15. You may object at any time to the processing of personal data concerning you by the Controller, including if processed for profiling or direct marketing purposes.
Your rights in the event of a data breach
Art. 16. (1) If the Controller identifies a breach of the security of your personal data that may pose a high risk to your rights and freedoms, it shall notify you without undue delay of the breach and of the measures that have been taken or are to be taken.
(2) The controller is not obliged to notify you if:
- has taken appropriate technical and organisational measures to protect the data affected by the security breach;
- has subsequently taken measures to ensure that the infringement will not result in a high risk to your rights;
- notification would require a disproportionate effort.
Persons to whom your personal data is provided
Art. 17. For the purposes of processing your personal data and providing the service in its full functionality and in view of your interests, the Controller may provide the data to the following persons who are data processors - see the list of data processors. These processors comply with all legality and security requirements when processing and storing your personal data.
Art. 18. The controller does not transfer your data to third countries.
Art. 19. In the event of a violation of your rights under the foregoing or applicable data protection law, you have the right to file a complaint with the Personal Data Protection Commission as follows:
Name: Commission for Personal Data Protection
UIC/BULSTAT: 204062841
Registered office and registered address: gr. 1592 Sofia Blvd. "Proff. Tsvetan Lazarov" № 2
Address for correspondence: gr. 1592 Sofia Blvd. "Proff. Tsvetan Lazarov" № 2
Phone: 02 915 3 518
Website: www.cpdp.bg
Art. 20. You can exercise all your rights regarding the protection of your personal data using the forms attached to this information. Of course, these forms are optional and you can make your requests in any form that contains a statement to that effect and identifies you as the data holder.
Art. 21. If the consent relates to a transfer, the Controller shall describe the possible risks of the transfer of the data to third countries in the absence of an adequate protection solution and appropriate means of protection.