Privacy Policy
Mandatory Information Regarding Personal Data Protection Rights
Information about the company processing your data:
Name: ATEK 1, Ltd
Unified Identification Code (UIC)/Bulgarian Unique Identifier for Legal Entities (BULSTAT): 200543140
Registered Office and Management Address: 6 Angista Street, Sofia
Correspondence Address: 6 Angista Street, Sofia
Phone: 0882 881 999
Email: a.krastev@atek.bg
Website: www.atek.bg
Information about the competent supervisory authority for personal data protection
Name: Commission for Personal Data Protection
Registered Office and Management Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592
Correspondence Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592
Phone: 02 915 3 518
Website: www.cpdp.bg
ATEK 1 Ltd (referred to below for brevity as the "Administrator" or the "Company") carries out its activities in accordance with the Personal Data Protection Act and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals concerning the processing of personal data and on the free movement of such data. This information aims to inform you about all aspects of the processing of your personal data by the Company and the rights you have in connection with this processing.
Legal Basis for the Collection, Processing, and Storage of Your Personal Data
Art. 1. The Administrator collects and processes your personal data in connection with the use of the online store www.atek.bg and the conclusion of contracts with the company on the basis of Art. 6, para. 1 of Regulation (EU) 2016/679 (GDPR), specifically based on the following grounds:
- Explicit consent obtained from you as a customer;
- Performance of the Administrator's obligations under a contract with you;
- Compliance with a legal obligation applicable to the Administrator;
- For the purposes of the legitimate interests of the Administrator or a third party;
Purposes and Principles for the Collection, Processing, and Storage of Your Personal Data
Art. 2. (1) We collect and process the personal data you provide to us in connection with the use of the online store and the conclusion of a contract with the company, including for the following purposes:
- Creating a profile and providing full functionality when using the online store;
- Conclusion and execution of a distance contract;
- Individualization of the contracting party;
- Accounting purposes;
- Statistical purposes;
- Information security;
- Ensuring the performance of the contract for the provision of the respective service.
- Sending a newsletter upon your express request;
(2) We adhere to the following principles in processing your personal data:
- Legality, good faith, and transparency;
- Limitation of the purposes of processing;
- Compatibility with the purposes of processing and reduction of the data collected to a minimum;
- Accuracy and timeliness of data;
- Limitation of storage in order to achieve the objectives;
- Integrity and confidentiality of processing and ensuring an appropriate level of security for personal data.
- Fulfilling its obligations to the National Revenue Agency, the Ministry of Internal Affairs, and other state and municipal authorities.
- User Registration in the Online Store and Execution of a Distance Purchase-Sale Agreement – The purpose of this operation is to create a profile for using the online store for purchasing goods and providing contact information for delivering purchased goods. Registration and profile creation for using the online store are not mandatory steps for providing the service and are largely available without creating a profile.
Impact Assessment Conclusion: Based on the impact assessment conducted, the operation "User Registration in the Online Store and Execution of a Distance Purchase-Sale Agreement" is permissible and provides sufficient guarantees for the protection of the rights and legitimate interests of data subjects in accordance with GDPR requirements. - Conclusion and Execution of a Commercial Transaction with a Customer or Partner – The purpose of this operation is to conclude and execute a contract with a commercial partner or customer and administer it. Given the limited scope of personal data collected and the fact that some of it is obtained from publicly accessible sources, conducting an impact assessment is not necessary for this operation.
- Sending a Newsletter – The purpose of this operation is to administer the process of sending newsletters to customers who have expressed their desire to receive them. Due to the limited scope of personal data collected, conducting an impact assessment is not necessary for this operation.
- Exercising the Right to Withdraw Consent or Filing a Complaint – The purpose of this operation is to administer the process of exercising the right to withdraw consent or file a complaint by a customer. Given the limited scope of personal data collected, conducting an impact assessment is not necessary for this operation.
- Your Identifying Information (email, name, etc.)
- Purpose of Data Collection: 1) Establishing contact with the user and sending information to them, 2) for user registration in the online store, as well as 3) for sending newsletters.
- Legal Basis for Processing Your Personal Data: By accepting the terms and conditions and registering in the online store or placing an order without registration or by concluding a written contract, a contractual relationship is established between the Administrator and you, on the basis of which we process your personal data – Article 6(1)(b) of the GDPR. Your data for sending newsletters is processed with your explicit consent – Article 6(1)(a) of the GDPR.
- Delivery Data (names, phone number, address, etc.)
- Purpose of Data Collection: Execution of the Administrator's obligations under a purchase-sale contract and delivery of purchased goods.
- Legal Basis for Processing Your Personal Data: By accepting the terms and conditions and registering in the online store or placing an order without registration or by concluding a written contract, a contractual relationship is established between the Administrator and you, on the basis of which we process your personal data – Article 6(1)(b) of the GDPR.
- Additional Data Provided by You – If you wish to supplement your profile, you can enter additional information such as your name, last name, and phone number.
- Purpose of Data Collection: Enhancing the user's profile information in their user account.
- Legal Basis for Data Processing: You have provided explicit consent for processing your personal data for one or more specific purposes when registering in the online store. Providing this data is not mandatory for registering in the online store.
- Revealing racial or ethnic origin;
- Revealing political, religious, or philosophical beliefs or membership in trade unions;
- Genetic and biometric data, data concerning health, or data concerning a person's sex life or sexual orientation.
- Conclusion and execution of a commercial transaction: For the conclusion and execution of a commercial transaction with a commercial company, we process only the three names of the legal representative or the person authorized by the company. Impact Assessment Conclusion: Given the small number of individuals whose data is processed and the limited volume of personal data collected, an impact assessment is not required for this operation.
- The personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
- You withdraw your consent, and there is no other legal ground for the processing;
- You object to the processing of your personal data, including for direct marketing purposes, and there are no overriding legitimate grounds for the processing;
- The personal data has been unlawfully processed;
- The personal data must be erased for compliance with a legal obligation under EU law or the law of a Member State that applies to the Administrator, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Administrator;
- The personal data has been collected in relation to the offer of information society services.
- For exercising the right of freedom of expression and information;
- For compliance with a legal obligation that requires processing under EU law or the law of a Member State that applies to the Administrator, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Administrator;
- For reasons of public interest in the area of public health;
- For archival purposes in the public interest, for scientific or historical research purposes, or for statistical purposes;
- For the establishment, exercise, or defense of legal claims.
- You dispute the accuracy of the personal data, for a period allowing the Administrator to verify the accuracy of the personal data;
- Processing is unlawful, but you do not wish your personal data to be erased, only to be restricted in use;
- The Administrator no longer needs the personal data for the purposes of processing, but you require them for the establishment, exercise, or defense of legal claims;
- You have objected to processing while awaiting verification as to whether the legitimate grounds of the Administrator override your interests.
- Request the Administrator to provide your personal data in a readable format and transfer them to another Administrator;
- Request the Administrator to directly transfer your personal data to an Administrator of your choice, if technically feasible.
- The Administrator has implemented appropriate technical and organizational measures to protect the data affected by the security breach;
- The Administrator has subsequently taken measures to ensure that the breach is unlikely to result in a high risk to your rights;
- Notifying you would require disproportionate effort.
(3) In processing and storing personal data, the Administrator may process and store personal data for the purpose of protecting the following legitimate interests:
Types of Personal Data Collected, Processed, and Stored by Our Company
Art. 3. (1) The company carries out the following operations with the personal data provided by you for the following purposes:
(2) The Administrator processes the following categories of personal data and information for the following purposes and on the following legal bases:
(3) The Administrator does not collect or process personal data related to the following:
(4) Personal data is collected by the Administrator from the individuals to whom it pertains.
(5) The company does not make automated decisions with data.
Art. 4. (1) The company performs the following operations with the personal data provided by you, acting as legal representatives or authorized agents of legal entities-commercial partners, for the following purposes:
(2) Personal data is collected by the Administrator from the individuals to whom it pertains and from the Commercial Register maintained by the Registry Agency.
(3) The company does not perform automated decision-making with data.
Article 5. The Administrator may use so-called "cookies" for the purpose of providing full functionality of the website, improving the user experience, statistical purposes, facilitating access, and more. By using our website, you agree to this. You can control and/or delete "cookies" at any time through your browser settings. "Cookies" do not constitute personal data and are not used to identify visitors and users of the online store.
Retention Period of Your Personal Data
Article 6. (1) The Administrator stores your personal data for a period not exceeding the existence of your profile in the online store. After deleting your profile, the Administrator takes the necessary steps to delete and destroy all your data without undue delay or to anonymize it (i.e., to transform it into a form that does not reveal your identity).
(2) The Administrator processes your personal data that you have provided when placing an order without registration in the online store until the order is completed, unless you have given your explicit consent during the order process for your data to be processed for the purposes of improving the service, providing recommended content for you, individual terms, promotions, and for statistical purposes.
(3) The Administrator retains your personal data provided in connection with online orders for a period of 5 years for the purpose of protecting the Administrator's legal interests in case of legal or administrative disputes with users of the online store.
(4) The Administrator informs you in case the data retention period needs to be extended for the purpose of complying with a legal obligation or to serve the legitimate interests of the Administrator or otherwise.
(5) The Administrator stores personal data as required by applicable law for the respective period, which may exceed the duration of your profile in the online store or until the completion of the order.
Article 7. The Administrator retains the personal data of the legal representatives of its commercial partners for the duration of the contract, for compliance with the legitimate interests and legal obligations of the Administrator, and this period may exceed the term of the concluded contract.
Transfer of Your Personal Data for Processing
Article 8. (1) The Administrator may, at its own discretion, transfer part or all of your personal data to data processors to fulfill the processing purposes with which you have consented, in compliance with the requirements of Regulation (EU) 2016/679 (GDPR).
(2) The Administrator will notify you in the event of the intention to transfer part or all of your personal data to third countries or international organizations.
Your Rights in the Collection, Processing, and Storage of Your Personal Data
Withdrawal of Consent for Processing Your Personal Data
Article 9. (1) If you do not want your provided personal data to be processed for marketing purposes and receiving newsletters, you can withdraw your consent at any time by completing the withdrawal of consent form in Appendix No. 1 or by sending a request in free text via email.
(2) Upon receiving your request, we will send you an email to the address you provided for receiving newsletters and promotional messages with detailed instructions for verifying your status as a recipient of newsletters and as a subject of personal data for which consent withdrawal has been requested.
(3) The withdrawal of consent does not affect the lawfulness of the data processing that the Administrator has carried out up to that point.
Right of Access
Article 10. (1) You have the right to request and obtain from the Administrator confirmation as to whether personal data related to you is being processed by sending a request in free text via email.
(2) You have the right to access the data related to you, as well as information regarding the collection, processing, and storage of your personal data.
(3) After receiving your request, we will send you an email to the address you used for registration or placing orders on the website with detailed instructions for verifying your status as a data subject to whom access has been requested.
(4) Following the verification process according to paragraph 3, the Administrator provides you, upon request, with a copy of the processed personal data related to you, in electronic or other suitable form.
(5) Access to the data is provided free of charge, but the Administrator reserves the right to impose an administrative fee in case of repetition or excessiveness of requests.
Right to Rectification or Completion
Article 11. (1) You may, at any time, correct or complete inaccurate or incomplete personal data related to you through the "Profile Editing" option.
(2) You can correct or complete inaccurate or incomplete personal data related to you directly through your profile on the website or by sending a request to the Administrator via email using the form in Appendix No. 4 or through a free-text request.
Right to Erasure ("Right to be Forgotten")
Article 12. (1) You have the right to request from the Administrator the erasure of part or all of the personal data related to you, and the Administrator is obliged to erase them without undue delay when one of the following grounds applies:
(2) The Administrator is not required to erase personal data if it processes them:
(3) In order to exercise your right to be forgotten, you must send a request for the deletion of your personal data processed by the Administrator by filling out the form in Appendix No. 2 or by sending a request in free text via email. The Administrator will then send an email to the address you used for registration or placing orders on the online store with detailed instructions for verifying your status as a user of the store and a data subject for whom a request for deletion has been made.
(4) After verifying the identity of the person who submitted the request and the individual to whom the data pertains, following your instructions, we will delete all data we process for you in accordance with paragraph 3.
(5) If you have made an order that is being processed, the earliest point at which you can request to be "forgotten" is upon successful completion of the order.
Right to Restriction
Article 13. You have the right to request the Administrator to restrict the processing of your data by sending us a free-text request via email when:
(2) After receiving your request, we will send you an email to the address you used for registration or placing orders on the online store with detailed instructions for verifying your status as a user of the store and a data subject for whom a request for restriction has been made.
(3) After verification in accordance with paragraph 2, the Company will cease processing your data but will not remove any online store publications you have made, if any.
Right to Data Portability
Article 14. (1) If you have provided consent for the processing of your personal data or if the processing is necessary for the performance of a contract with the Administrator, or if your data is being processed automatically, you can:
(2) You can exercise the right to data portability by sending us an email with the form according to Appendix No. 3 or a free-text request, after which the Administrator will send you an email to the address you used for registration or placing orders on the online store with detailed instructions for verifying your status as a user of the store and a data subject for whom a request for data portability has been made.
(3) After verification according to paragraph 2, the Company will send the data it processes for you in XML format to the email you specified.
Right to Information
Article 15. You may request the Administrator to inform you about all recipients to whom the personal data for which correction, deletion, or processing restriction has been requested have been disclosed. The Administrator may refuse to provide this information if it would be impossible or would require disproportionate effort.
Right to Object
Article 16. You have the right to object at any time to the processing of personal data concerning you, including profiling or direct marketing.
Your Rights in the Event of a Personal Data Breach
Article 17. (1) If the Administrator detects a breach of the security of your personal data that may result in a high risk to your rights and freedoms, the Administrator will inform you of the breach without undue delay, as well as of the measures taken or planned.
(2) The Administrator is not required to notify you if:
Recipients of Your Personal Data
Article 18. (1) For the purposes of processing your personal data and providing the service in its full functionality and in view of your interests, the Administrator may provide data to the following data processors:
Personal Data Processor | Purpose of Personal Data Processing |
---|---|
... | ... |
... | ... |
(2) The data processors comply with all requirements for lawfulness and security in the processing and storage of your personal data.
Article 19. The Administrator does not transfer your data to third countries.
Article 20. In case of a breach of your rights under the above or applicable legislation for the protection of personal data, you have the right to lodge a complaint with the Commission for Personal Data Protection as follows:
Name: Commission for Personal Data Protection.
Registered Office and Management Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Correspondence Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Phone: 02 915 3 518
Website: www.cpdp.bg
Article 21. You can exercise all your rights regarding the protection of your personal data using the forms provided with this information. Of course, these forms are not mandatory, and you can submit your requests in any form that includes a statement identifying you as the data subject.
Article 22. If consent relates to a transfer, the Administrator describes the possible risks of transferring data to third countries in the absence of a decision on adequate protection and appropriate safeguards.
Appendix No. 1
Withdrawal Form for Processing Consent Purposes
Your Name*: .........................
Your Email used in the online store*: .........................
Contact Information (email)*: .........................
To
Name: .........................
Company ID/BULSTAT: .........................
Registered Office and Management Address: .........................
Correspondence Address: .........................
Phone: .........................
Email: .........................
Website: .........................
I hereby withdraw my consent for the processing of my personal data provided by me for the purpose of receiving newsletters, promotional messages, or other marketing materials. I am aware of the conditions for withdrawing consent in accordance with the Mandatory Information on the Rights of Data Subjects provided by the online store.
In case of a breach of your rights as mentioned above or applicable data protection legislation, you have the right to file a complaint with the Commission for Personal Data Protection, as follows:
Name: Commission for Personal Data Protection.
Registered Office and Management Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Correspondence Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Phone: 02 915 3 518
Website: www.cpdp.bg
Appendix No. 2
Request to Be Forgotten - Data Deletion Request
Your Name*: .........................
Your email, which you used for registration or for making orders in the online store*: .........................
Contact Information (email)*: .........................
To
Name: [Insert the name of the entity or organization]
EIK/BULSTAT: [Insert the EIK/BULSTAT number]
Registered Office and Management Address: [Insert the registered office and management address]
Correspondence Address: [Insert the correspondence address]
Phone: [Insert the phone number]
Email: [Insert the email address]
Website: [Insert the website URL]
Please delete all personal data collected, processed, and stored by you, provided by me or by third parties associated with me, according to the provided identification.
I declare that I am aware that part or all of my personal data may continue to be processed and stored by the administrator for the purpose of fulfilling its legal obligations.
In case of a violation of your rights as mentioned above or applicable data protection legislation, you have the right to file a complaint with the Commission for Personal Data Protection as follows:
Name: Commission for Personal Data Protection.
Registered Office and Management Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Correspondence Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Phone: 02 915 3 518
Website: www.cpdp.bg
Appendix No. 3
Data Portability Request
Your Name*: [Insert your name]
Your email, which you used for registration or for making orders in the online store*: [Insert your email]
Contact Information (email)*: [Insert contact email]
To
Name: [Insert the name of the entity or organization]
EIK/BULSTAT: [Insert the EIK/BULSTAT number]
Registered Office and Management Address: [Insert the registered office and management address]
Correspondence Address: [Insert the correspondence address]
Phone: [Insert the phone number]
Email: [Insert the email address]
Website: [Insert the website URL]
Please send all personal data related to me, which is collected, processed, and stored in your databases, in XML format to the following email:
Email: [Insert email]
Administrator – the one receiving the data: [Insert the name of the recipient]
Name: [Insert the name]
Identification number (EIK, BULSTAT, reg. number in KZLD): [Insert identification number]
Email: [Insert email]
In case of a violation of your rights as mentioned above or applicable data protection legislation, you have the right to file a complaint with the Commission for Personal Data Protection as follows:
Name: Commission for Personal Data Protection.
Registered Office and Management Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Correspondence Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Phone: 02 915 3 518
Website: www.cpdp.bg
Appendix No. 4
Data Correction Request
Your Name*: [Insert your name]
Your email, which you used for registration or for making orders in the online store*: [Insert your email]
Contact Information (email)*: [Insert contact email]
To
Name: [Insert the name of the entity or organization]
EIK/BULSTAT: [Insert the EIK/BULSTAT number]
Registered Office and Management Address: [Insert the registered office and management address]
Correspondence Address: [Insert the correspondence address]
Phone: [Insert the phone number]
Email: [Insert the email address]
Website: [Insert the website URL]
Please correct the following personal data, which is collected, processed, and stored, provided by me or by third parties associated with me, as follows:
Data to be corrected:
[Insert the data to be corrected]
Please correct it as follows:
[Insert the correction details]
In case of a violation of your rights as mentioned above or applicable data protection legislation, you have the right to file a complaint with the Commission for Personal Data Protection as follows:
Name: Commission for Personal Data Protection.
Registered Office and Management Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Correspondence Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Phone: 02 915 3 518
Website: www.cpdp.bg