Information about the data controller:
Varna Beauty Studio Ltd is a company registered in the Commercial Register of the Registry Agency with UIC: 203539072, e-mail: firstname.lastname@example.org, phone number: 0896662444.
The grounds and purposes for which we use your personal data
We process your personal data on the following grounds:
- The Website Terms and Conditions of Use;
- Explicit consent from you – the purpose is stated on a case-by-case basis;
- Where required by law;
In the following paragraphs you will find detailed information about the processing of your personal data depending on the basis on which we process it.
For contract performance
We process your personal data for the purposes of using the Website in accordance with the terms and conditions
Purposes of processing (where applicable):
- to establish your identity;
- to provide the functionalities of our website
On this basis, we only process personal data in connection with the user profile you have created.
We delete the data collected on this basis 2 years after the termination of the contractual relationship, whether due to expiry of the contract, termination or any other reason.
After your consent
We process your personal data on this basis only after your explicit, unambiguous and voluntary consent. We do not foresee any adverse consequences for you if you refuse the processing of personal data.
Consent is a separate basis for processing your personal data and the purpose of the processing is set out therein, and is not covered by the purposes listed in this policy. If you give us the relevant consent and until you withdraw it or terminate any contractual relationship with us, we make product/service suggestions that are appropriate for you by carrying out detailed analyses of your basic personal data;
Data we process on this basis:
We may process personal data on this basis for direct marketing purposes, including website usage data and social media profile data.
Provision of data to third parties
On this basis we may provide your data to marketing agencies, Facebook, Google or similar.
Withdrawal of consent
The provided consent may be withdrawn at any time. Withdrawal of consent has no impact on the performance of contractual obligations. If you withdraw your consent to the processing of personal data for any or all of the ways described above, we will not use your personal data and information for the purposes set out above. Withdrawal of consent does not affect the lawfulness of processing based on consent given prior to withdrawal.
To withdraw consent you need only use our website or simply our contact details.
When we delete data collected on this basis
We delete data collected on this basis at your request or 12 months after it was originally collected.
How we protect your personal data
To ensure adequate protection of the company’s and its customers’ data, we apply all necessary organizational and technical measures provided for in the Personal Data Protection Act.
The company has established rules that prevent misuse and security breaches, and support the processes of protecting and securing your data.
In order to maximize the security of the processing, transmission and storage of your data, we may use additional protection mechanisms such as encryption, pseudonymization, etc.
Rights of Users
Each User of the Site enjoys all the rights for the protection of personal data under Bulgarian and European Union law.
The User may exercise his rights by sending a message to our email.
Each User has the right to:
- Information (regarding the processing of his personal data by the controller);
- Access to their own personal data;
- Rectification (if the data is inaccurate);
- Erasure of personal data
- Restriction of processing by the controller or processor;
- Portability of personal data between controllers;
- Objection to the processing of his or her personal data;
- The data subject also has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal consequences, concerning him/her or significantly affects him/her in a similar way;
- The right to a judicial or administrative remedy where the data subject’s rights have been violated.
The user may request deletion if one of the following conditions applies:
- The personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
- The user withdraws the consent on which the processing is based and there is no other legal basis for the processing;
- The data user objects to the processing and there are no legitimate grounds for the processing which override;
- The personal data has been unlawfully processed;
- The personal data must be erased in order to comply with a legal obligation under Union or Member State law to which the controller is subject;
- The personal data have been collected in connection with the provision of information society services to children and consent has been given by the person having parental responsibility for the child.
The user has the right to restrict the processing of his/her personal data by the controller when:
- Challenge the accuracy of the personal data. In this case, the restriction of processing shall be for a period that allows the controller to verify the accuracy of the personal data;
- The processing is unlawful, but the User does not wish the personal data to be erased, but requests instead the restriction of its use;
- The controller no longer needs the personal data for the purposes of the processing, but the User requires it for the establishment, exercise or defence of legal claims;
- Objects to processing pending verification that the controller’s legitimate grounds override the interests of the User.
Right to portability
The data subject shall have the right to obtain the personal data concerning him or her which he or she has provided to a controller in a structured, commonly used and machine-readable format and shall have the right to transfer those data to another controller without hindrance from the controller to whom the personal data have been provided, where the processing is based on consent or a contractual obligation and the processing is carried out by automated means. When exercising his or her right to data portability, the data subject shall also have the right to obtain a direct transfer of the personal data from one controller to another where this is technically feasible.
Right to object
Users have the right to object to the controller to the processing of their personal data. The data controller shall be obliged to terminate the processing unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims. If you object to the processing of personal data for direct marketing purposes, the processing shall cease immediately.
Complaint to the supervisory authority
Every User has the right to lodge a complaint against unlawful processing of his/her personal data with the Personal Data Protection Commission or the competent court.