PERSONAL DATA PROTECTION POLICY
of STEADY BRAND OOD
For us, Steady Brand OOD, (the Company), the protection of your personal data is of primary importance. Therefore, we would like to inform you on what grounds, for what purposes, within what periods and by what means your personal data are processed when you visit our website: https://bestefficient.com, and when you have partnership relations with the Company. We strictly adhere to the applicable data protection regulations in each operation of personal data processing. The General Data Protection Regulation 2016/679 (“GDPR”) on the protection of natural persons with regard to the processing of personal data shall apply to the territory of the EU, including Bulgaria, with effect from 25 May 2018). It provides you with enhanced data protection rights, to which our more detailed obligations also correspond; more information on this issue may be found below in this Personal Data Protection Policy (the Policy).
- I. Introduction
In this Personal Data Protection Policy, Steady Brand, “we”, “us” or “our” shall mean Steady Brand EOOD, and “you”, “your” and “user” shall mean visitors to our website – https://bestefficient.com.
This Personal Data Protection Policy shall explain and govern:
- how and when we collect your personal data, and what information we collect;
- how and why we use your personal data; and
- your rights to control your personal data.
Please carefully read this Personal Data Protection Policy. By accessing and using our website and services, you confirm that you have had an opportunity to read this Policy, that you understand it and that you agree to be bound by it. If you fail to do so, you must immediately cease using our website and any services provided by us.
We may amend this Policy from time to time in order to comply with applicable laws and regulations or meet changing business requirements. You are encouraged to periodically review this page for the latest information on our privacy practices and amendments to our Personal Data Protection Policy. Every time we make an amendment to the Policy, we will notify you of possible effects of the amendment without delay and in summary on our website https://bestefficient.com and at the Company’s office located in the City of Bankya, 29 Alexander Stamboliiski Str.
- I General Information.
- 1. Some terms for better understanding of this Policy:
– “Personal Data” – means any information relating to a natural person, which separately or in combination with other information, may result in their identification or may identify them.
– Data Subject” – means any alive natural person who is identified or identifiable by means of processed personal data.
– “Personal Data Processing ” – means any action that we carry out or may carry out with your personal data, including but not limited to their collection, analysis or destruction.
– “Data Controller – with regard to personal data it controls, this is Steady Brand. We define the purpose of your personal data processing, on any of the legal grounds to this effect; in principle, we also define the methods for such processing – for example, the technical infrastructure and applications used for the processing. We assume the responsibilities with regard to the security and protection of your personal data.
– “Data Processor” – this is a third party that processes your personal data upon our assignment, whereas Steady Brand has strictly defined the purpose and methods of processing, and has verified whether the entity meets the requirements of GDPR. For example, such data processor may be an agency, which is responsible for a marketing campaign of Steady Brand in social media and issues reports for its success.
– “Personal Data Breach” means any breach of security, which results in accidental or unauthorized destruction, loss, change, unauthorized disclosure of or access to personal data that are transferred, stored or processed otherwise. .
– “Digital Assets” – the website https://bestefficient.com, all landing pages supported by the Company, web, native and mobile applications accessible to customers.
- Who we are?
Steady Brand EOOD, UIC 205468229 is a company duly registered under the laws of Republic of Bulgaria, whose objects of activity include trade activity on the territory of Republic of Bulgaria and abroad, import and export of goods and services, trade mediation and representation, consulting services, as well as any other activity not prohibited by law.
- How can you contact us?
Steady Brand EOOD has its seat and registered office situated in the City of Bankya, 29 Alexander Stamboliiski Str. You can contact us by visiting us at the Company’s address specified above and on our website: https://bestefficient.com.
- Who is the person within the organization responsible for the protection of my personal data and how can I contact him/her?
Data Protection Officer (“DPO”) is the General Manager of the company, e-mail [email protected].
- Type, purpose and grounds of processing of personal data collected by Steady Brand OOD:
Personal Data |
Purpose |
Grounds |
Name and surname, e-mail |
· Making contact with the customer in view of answering questions given by the client through the contact form on the website of the Company https://bestefficient.com; |
Performance of an agreement remotely |
|
· Offering products and services of Steady Brand OOD · Sending advertising messages |
Consent |
Your personal data will be processed by Steday Brand OOD only in accordance with the applicable data protection regulations. When you communicate with us through any of the communication channels, you acknowledge that the data you have provided are accurate, correct and up-to-date.
We should inform you that any consent to processing your personal data may be withdrawn at any time by submitting a request in writing to the Company’s registered office situated in the City of Bankya, 29 Alexander Stamboliiski Str. and/or and by sending an e-mail to [email protected].
- For how long will my personal data be stored?
Personal data shall be stored for the time periods required to achieve the purposes for which they have been collected. After achieving the purposes for which personal data have been collected, we will destroy them immediately.
Steady Brand OOD shall take all necessary technical and organizational measures for the destruction of data that are no longer necessary, except in cases where there are legitimate grounds for Steady Brand OOD to process them for a longer period of time; when you make a request for restricting processing in accordance with your rights detailed below; or with a view to or compatible with the original purpose for processing of which you will be informed in a timely manner.
Steady Brand OOD shall store collected personal data within the following periods:
- a) where data are processed on the basis of consent – until the explicit withdrawal of the consent;
- b) where data are processed for the protection of implementation of the Company’s rights and interests, which reasonably override the interests of natural persons – until the right is extinguished and/or interest no longer exists.
After the expiration of the pointed above time periods, if there are no other grounds for the processing of the data, they will be erased. For the purpose of obtaining and analyzing information related to the products and services used by you, and improving customer service, the Company may erase only part of the data. In such cases, it shall continue to store such part of the data that does not allow natural persons to be subsequently identified.
- Will my personal data be accessible to third parties?
The following categories of persons, that may be processors on the grounds of contracts entered into with the Company, may also have access to your personal data, namely persons supporting the information systems of the Company located in the Republic of Bulgaria;
The Company is obliged to provide personal data on its customers to competent authorities and institutions pursuant to applicable law and when such data are lawfully requested.
Steady Brand OOD does not transfer personal data to a third country or international organization outside the European Union.
- How we protect your personal data?
To ensure adequate protection of the data of the Company and our customers, we apply all necessary organisational and technical measures provided for in the Personal Data Protection Act and the General Data Protection Regulation.
The Company has established structures designated to prevent any misuse and security breaches, and has also appointed a Data Protection Officer supporting the processes related to protecting and ensuring the security of your data.
- When visiting this website, Steady Brand OOD shall process your personal data using cookies. Please become familiar with our Cookie Policy here.
- II. Your rights
As a data subject, whose data are processed by Steady Brand OOD, you shall have rights described in details below.
You should take into consideration that the provision of personal data is voluntary – it is necessary for the conclusion of a contract with the Company or to receive an answer from the Company in relation to asked by you questions. In the event that data are not provided, the Company will not be able to provide a product or service.
Steady Brand OOD shall meet your requests without delay, within 30 calendar days after submitting them. By our decision, we provide or refuse access and/or information requested by the applicant, but we always justify our response. For the purpose of the website of the Company, there is a link to this Policy published on a clearly visible and accessible position.
Applications concerning the exercise of your rights shall be submitted:
- in person or by a proxy who has been expressly authorized by you through a notarized power of attorney at the Company’s registered office situated in the City of Bankya, 29 Alexander Stamboliiski Str. The notarized power of attorney through which a request for erasure is submitted should contain the following power: “To represent me before Steady Brand OOD, UIC 205468229 having the right to submit on my behalf a request for exercise of personal data protection rights”;
- executed as an electronic document signed by your electronic signature to [email protected];
- by post or by courier to the Company’s address: City of Bankya, 29 Alexander Stamboliiski Str.;
The exercise of rights shall be free and cover all structured and unstructured data, and all databases supported by the Company.
Exceptions to the time period intended for satisfying the rights and the free of charge basis are allowed in cases of requests made by the same customer of data with a frequency greater than 3 times a year and requiring mobilization of a significant administrative resource on part of the Company. In this case, we may charge a reasonable fee with a view to the administrative costs incurred.
Where the data subject submits a request by electronic means, the information shall be provided, where possible, by electronic means, unless the data subject has not requested otherwise.
Where the Company has reasonable concerns in relation to the identity of the natural person who submits a request for the exercise of their rights under this section, the directly responsible person shall immediately consult with the Data Protection Officer in view to the identification of the customer.
You should also consider that the withdrawal of consents provided does not affect the lawfulness of the processing of your personal data before such withdrawal. Despite the withdrawn consent, your personal data may be processed by the Company, if there are grounds for processing the data other than those referred to in Section 5.
You shall have the following rights:
- Right to be informed
As a data subject, you shall have a right to obtain information on important features of the processing of your personal data, including, but not limited to its purpose, period and grounds, on the recipients and the categories of recipients of the personal data, etc.
In addition to the above information, you should consider that you are not a subject of automated decision making, including profiling.
In accordance with the applicable personal data protection laws, you have the rights specified below, and we are obliged to respond to each of your requests within 1 month of receipt of the request and for no extra charge. In case of any difficulties for the timely fulfillment of such requests, the period may be extended by another 2 months, of which you will be notified within 1 month of receipt of the request.
- Right of access
You may request information on what personal data concerning you we process, and whether we process such. You may request access to such data.
We will provide you with a statement of personal data that are being processed. For additional statements we may adopt a reasonable fee on the basis of administrative costs. When you submit a request through electronic means, we will provide the information, where possible, in a widely used electronic form unless you have requested otherwise.
- c. Right to rectification
If we process incomplete or incorrect personal data concerning you, you have the right to have such data rectified or completed at any time.
- d. Right to erasure
You may request to have your personal data erased in the following cases:
- the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
- you withdraw your consent on which the processing is based and there is no other legitimate grounds for the processing;
- you consider that the personal data have been unlawfully processed.
Note that there may be other reasons that can thwart the immediate erasure of your data, such as statutory obligations for storage, pending proceedings, the establishment, exercise or defense of legal claims, etc.
- e. Right to restriction of processing
You have the right to obtain restriction of processing, if:
- you contest the accuracy of the personal data for a period enabling us to verify the accuracy of the personal data;
- the processing is unlawful, but you do not want the personal data to be erased and request the restriction of their use instead;
- we no longer need the personal data for the purposes of the processing, but you require them for the establishment, exercise or defense of legal claims
- you have objected to processing pending the verification whether the legitimate grounds of Steady Brand OOD for processing of the data override your grounds.
If you request restriction of processing, we will inform you prior to revoking the restriction of processing.
- f. Right to data portability
You may request from us to provide you with the personal data concerning you that we process in a structured, commonly used and machine-readable format and which can be transmitted to another financial institution for example. This shall apply, provided that
- the processing of the particular data is based on your consent or is in relation to conclusion and performance of a contract for service; and
- the processing is carried out by automated means.
- g. Right to object
You have the right, at any time and on grounds relating to your particular situation, to object to processing of your personal data, which is based on legitimate interest – grounds are indicated in the table above, including profiling based on such grounds.
When you have given your consent to the processing of data for the purposes of direct marketing, you have the right at any time to object to the processing of personal data without having to specify any grounds.
- h. Right to lodge a complaint
Please contact us if you think that we have violated any applicable law on the protection of personal data in the processing of your data and as a result we have affected your rights. Surely, you also have the right to lodge a complaint with the Personal Data Protection Commission, which is a supervisory authority in respect of personal data protection, to the following address: City of Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd., tel. 02/91-53-518, e-mail: [email protected].