Personal Data Protection Policy – FICOSOTA

The present Personal Data Protection Policy has been drawn up in performance of the obligations of Ficosota OOD, UIC: 837055835/ hereinafter referred to as Ficosota and/or We /pursuant to Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) of the European Parliament and of the Council of 27 April 2016 and the Personal Data Protection Act.

The policy is informational in nature and is aimed at explaining what personal data Ficosota collects, with what purpose, on what legal grounds, how we process and store such data, as well as when it is necessary to disclose personal data to third parties. By means of this policy, information is also provided in relation to the rights the subjects have with respect to the processing of their personal data and the technical and organizational measures applied for protection in relation to that.

Information about us

The administrator of the personal data collected and processed is: Ficosota OOD, UIC: 837055835.

Legal residence and registered officeShumen 9700, 48 Madara Blvd.
Correspondence details
Emailprivacy@ficosota.com
Webpagewww.ficosota.com

Information about our personal data protection official:

Ficosota applies higher care in relation to the storage and processing of personal data and to that end, we have appointed an Official responsible for the data protection whose function is to be the contact person concerning all issues pertaining to the processing of your personal data, including upon exercising of the rights provided for by the legislation.

NameYordan Cholakov
Correspondence detailsSofia, 102 Bulgaria Blvd.
Emaildpo@ficosota.com

Personal data subjects

Ficosota collects and processes your personal data in exercising in business activity as well as during performance of the various types of statutory obligations. To that effect, such personal data may include but not be limited to data:

  • of natural persons processed in relation to entering into and performance of agreements, including legal representatives of other business companies – partners and customers;
  • of persons taking part in promotional campaigns and games, including in Facebook and Instagram or through partners – marketing agencies;
  • of persons for the purposes of direct marketing;
  • of persons taking part in surveys conducted by Ficosota;
  • of visitors of our sites, etc.

Personal data collected and processed; legal grounds and purpose of processing

We may possibly collect personal data about you when you take part in our games, surveys, promotion and marketing campaigns, as well as when you use our website. In most cases, we process your personal data based on your express and specific consent. Upon other processing, we require your personal data with the purpose of entering into an agreement, to observe a legal obligation or to protect our legitimate interest. Without that data, we could not possibly let you participate in most campaigns, including send you a reward or render our relevant services to you due to the impossibility to identify you. In all cases, we only process the minimum information necessary to fulfill the specific purpose.

We may collect and process the following information about you:

Categories of personal dataPurpose of processingLegal grounds (applied alternatively according to the specific category and purpose of processing)
• Names
• PIN /Personal ID No./
• Permanent address
• Contact details (telephone number and e-mail address)
• Letters and email messages we receive from you
– notifications related to our products and services.
 
The data may also be used for:
Processing is necessary to observe a legal obligation applicable to us.
 
– performance of obligations provided for in the Accounting Act and the Tax and Social Security Procedure Code and other related statutory instruments, in relation to keeping correct and legitimate accounting as well as in relation to the compliance with other statutory obligations;
– performance of obligations to provide information to all government commissions and regulatory bodies;
– providing information to the court and public order authorities.
Starting and conducting court proceedings.The processing is necessary for the purposes of keeping our legitimate interests as data administrator.
• Names
• telephone number
• e-mail address
• address for delivery of prizes won
• photographs;
• in some cases, a social profile as well
For the purposes of:
– participation in campaigns and games;
– publishing part of the data in the capacity of winner;
– sending the prize won;
– participation in surveys;
– direct marketing of our products and services;
Processing takes place on the grounds of your freely expressed, specific, informed and unambiguous consent.
• Names
• telephone number
• e-mail address, in some cases, a social profile as well
Responding to your enquiries through the contact form.
 
Responding to your requests for information and/or complaints.
Processing is necessary for keeping our legitimate interests as data administrator.

Sharing your information:

Ficosota does not provide personal data to third parties prior to ensuring that all technical, organizational and legal measures have been taken (by signing agreements) to protect such data. We perform strict control of the accomplishment of this goal. To that end, we may use third parties to assist certain contractual activities. Some of these third parties (service providers) could be: law firms and accounting firms, auditors, couriers, carriers, contractors or suppliers with government authorities as well as with other natural persons or legal entities – for example, providers of software and/or hardware solutions and/or infrastructure, external consultants in relation to establishing of rights pursuant to a legal obligation or with a view of their legitimate interest as the case may be.

Providing personal data is obligatory in certain cases in order to observe legal requirements to us and to that effect, we provide information to: public and municipal authorities, ministries, the National Revenue Agency, the National Social Security Institute, the Commission for Protection of Competition, the Commission for Consumer Protection and other regulatory bodies and commissions.

Automated algorithms

We do not use any automated decision making devices.

Security

The security of the data you have entrusted us with is very important for us. That is why we protect your data by applying all appropriate technical and organizational means we have in order not to allow unauthorized access, unauthorized or malicious use, loss or premature deletion of information.

Ficosota undertakes measures to protect your personal data against accidental loss or unauthorized access, use, change or disclosure. There are policies and procedures in place intended to protect the information from loss, abuse or illegal disclosure. In addition, we undertake further information security measures, including access control, strict physical protection and reliable practices for collection, storage and processing of information. Part of the measures applied are:

  • Protection of the collected personal data against unjustified use and traces of its processing;
  • Maintenance of secure computer systems by which personal data is processed. Adequate control mechanisms for data separation and management are applied to our systems;
  • Adoption of strict policies and procedures applicable to our staff for minimization of the risks of personal data processing;
  • The employees of Ficosota are familiar with the applicable rules and are trained to process personal data by applying utmost care and complying with the approved good practices;
  • Upon exercising its activity, Ficosota works only with reputable organizations and avoids working with companies, which we believe may jeopardize the persons’ personal data security;
  • Good practices have been adopted in the introduction and administration of the security systems and monitoring of the technological developments in terms of possible risks for the information security in our company;
  • Observing the security of computer systems and the personal data contained in them, including the opportunities for access to certain types of personal data by company employees;
  • Providing access only to such personal data, which is necessary to perform the work of the relevant employee.

On the other hand, we apply technical measures such as encryption, pseudonymisation and anonymization of the collected personal data where possible.

When do we delete your personal data?

Ficosota destroys the collected and processed personal data according to a specific procedure within the statutorily provided periods (for example, in the Accounting Act) and if there are no such periods, within the periods stipulated by us in the Policy on storage limitation and after final settlement of all our relations and the expiry of the limitation periods. Personal data is not stored longer than necessary for the specific purposes.

In case of personal data anonymization, the periods mentioned do not apply because we cannot identify you.

Transfer between countries

In the process of its ordinary activity, Ficosota does not transfer personal data outside the borders of the EU. In specific situations, we may hand over your data outside the European Union but only if an adequate level of protection or appropriate guarantees and legal grounds thereof have been provided.

Your rights with respect to the personal data

You have the right to information, access and receipt of a copy of your personal data processed by Ficosota. If you believe that information about you that Ficosota has is inaccurate or incomplete, you can request the editing of your personal data.

In addition, you have the right to:

  • objection against the processing of your personal data;
  • request destruction/deletion of your personal data when the legal grounds for its processing are dropped off;
  • request limitations on the processing of your personal data; and/or
  • withdraw your consent when Ficosota is processing your personal data on the grounds of consent (without such withdrawal affecting the legitimacy of processing performed prior to said withdrawal);
  • a complaint to the supervisory body – Commission for Personal Data Protection (Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd. or www.cpdp.bg).

Ficosota will perform requests, withdrawals or objections pursuant to the requirements of the applicable rules for personal data protection but those rules are not absolute: they are not always applicable and exceptions are possible. In response to a request forwarded it is necessary to confirm your personal identity and/or to provide further information to help us better understand your request.

When you have exercised a repeated right to access to information or copy of the data in machine-readable format, Ficosota may impose a reasonable fee based on the administrative costs necessary for providing those.

How can you exercise your rights?

Each of the rights provided by the law can be exercised by filing a request for exercising the relevant right. A request to exercise the rights of the personal data subjects may be filed in the following manners:

  • Electronically to the following e-mail address: dpo@ficosota.com.
  • Personally to the following address: town of Shumen 9700, 48 Madara Blvd

The request to exercise rights to personal data should contain the following information:

  • Identification of the person – names and personal ID No. /PIN/;
  • Contact and feedback details – address, telephone number, e-mail address;
  • Request – description of the request.

Ficosota provides information regarding the activities undertaken in relation to a request to exercise you rights within a period of one month.

Where necessary, the above period may be extended with two more months taking into account the complexity and number of requests by a specific person. Ficosota informs the person of each such extension within a period of one month from receipt of the request by also specifying the reasons for the delay. The information provided to the subject and each communication and actions of exercising the rights of the data subject are provided free of charge (except in the event of misuse of the rights granted).

We may request providing additional information necessary to confirm your personal identity when there are doubts in relation to the identity of a natural person filing a request. Upon exercising your rights through a proxy, a notarized power of attorney should also be provided to us.

Ficosota is not obliged to respond to a request if it is not in the condition to identify the data subject.

Where the request is filed through electronic devices the information is possibly provided with electronic devices unless you have expressly requested otherwise.

Use of cookies

Ficosota collects or processes personal data through cookies and you can find more information about that in the Policy on the use of cookies on our internet page.

Updating the personal data protection policy

The present policy may be subject to amendment by Ficosota, and it has last been updated on 17.09.2019. Any future amendments or additions to the present policy will be duly marked.