PRIVACY POLICY AND PERSONAL DATA PROTECTION ON THE WEBSITE www.forestofherbs-bg.com

This document discloses the Privacy Policy and the protection of personal data collected by users of the website at (URL) www.forestofherbs-bg.com. The site www.forestofherbs-bg.com is owned by Forest of Herbs Ltd. This Privacy Policy is intended to inform you about how the owner of www.forestofherbs-bg.com treats your personal data as an Administrator, as well as how you can control your preferences and settings in relation to this treatment. Please read this Privacy Policy carefully before accessing the Website and its services. If you do not agree to any of the terms, you should not visit the website and do not use our services and products in any way.

WHAT ARE THESE PRIVACY RULES REGULATED AND ON WHAT LEGAL BASIS ARE THEY APPLIED?

As of May 25, 2018, the General Data Protection Regulation  (GDPR) is applied in Bulgaria. It has been adopted by the European Union and aims to harmonize the policies of the EU Member States regarding the collection and use of personal data. The new regulation comes with a number of requirements that www.forestofherbs-bg.com applies. Among them are:

• To inform you what data we use.

• Let you know why we use them.

• Ask for your consent to use them when we provide additional services based on them, such as targeted advertising, for example.

• Give you the opportunity to change your consent for various purposes through this site to have more freedom.

• The ability to delete them, as well as to be "forgotten".

• Indicate all third parties / other companies with whom we share your data. Keep in mind that the Internet is a global network, we often use standardized services to register logins and track behavior in an anonymous version, such as Google Analytics.

Personal data is any specific information concerning you through which your identity can be established. For example, such information is your real name, address, telephone number, your passwords for accessing our website, IP address. Data that cannot be directly or in combination with other data related to your true identity is not considered personal data.

This Privacy Policy applies to your personal information when you visit www.forestofherbs-bg.com or use our services, but does not apply when you use other sites or services that we do not own or control.

PERSONAL DATA ADMINISTRATOR

The collection, processing and storage of personal data by users of the website is performed by:

Company: Forest of Herbs Ltd.

UIC: 203906935

Headquarters and address of management: Sofia, Triaditsa district, 48 Solunska Str.

Manager: Vera Tornov

as an Administrator of personal data.

The Administrator collects and processes all personal data in accordance with the data protection laws applicable in the European Union.

 

SUPERVISOR

Commission for Personal Data Protection

Address: Sofia, Prof. Tsvetan Lazarov ”2

Contact details: 02/915 35 18; 02/915 35 19; www.cpdp.bg

GROUNDS FOR PERSONAL DATA COLLECTION

The Administrator collects and processes your personal data in connection with the use of the e-shop www.forestofherbs-bg.com and concluding contracts with the company on the grounds of art. 6, para. 1, Regulation (EU) 2016/679 (GDPR), and in particular on the following grounds:

• Explicit consent from you as a customer;

• Fulfillment of the obligations of the Administrator under a contract with you;

• Compliance with a legal obligation that applies to the Administrator;

• For the purposes of the legitimate interests of the Administrator or a third party;

PRINCIPLES FOR THE COLLECTION AND PROCESSING OF PERSONAL DATA

The Administrator follows the following principles when processing your personal data:

• legality, good faith and transparency;

• restriction of processing purposes;

• relevance to the purposes of processing and minimizing the data collected;

• accuracy and timeliness of the data;

• personal data is not used for profiling;

• personal data is not used for direct marketing;

• limitation of storage in order to achieve the objectives;

• integrity and confidentiality of the processing and ensuring an appropriate level of security of personal data.

 

WHAT DATA DO WE COLLECT FROM OUR USERS

This Privacy Policy is an integral part of our General Terms and Conditions for Use of the Website available here: terms of conditions. All definitions given in the General Terms and Conditions are applicable in this Policy as well.

Before accessing the Services on the Website, you must express your explicit consent to the processing of your personal data in accordance with this Privacy Policy. You can give your consent to the above actions when registering, when sending an order or when sending an inquiry through the contact form available through the website.

1. The Administrator shall not collect or store "sensitive" categories of personal data such as political beliefs, ethnic origin, sexual orientation, data on the health status of the subject, religious or philosophical beliefs, etc. If the Administrator receives "sensitive data", he undertakes to delete it immediately. Please do not send such data to the Administrator.

2. Personal data collected by the Administrator when data subjects contact the controller directly by telephone.

The telephone number for contacting the Administrator is indicated in the "Contacts" section. When the data subject contacts the Administrator by telephone, the Administrator collects and stores only the name and contact number of the person, and in certain cases may also collect and store e-mail of the person. This data is stored for the purposes of communication with the individual and providing more complete information about the services offered by "Forest of Herbs" Ltd.

3. Personal data collected by the person when he contact the Administrator through a contact form on the site.

When the person sends a message to the Administrator using the contact form, the Administrator collects and stores the name, telephone and e-mail address of the person, as well as the information provided in the message. The Administrator collects and stores the specified information for the purposes of communication with the individual.

4. Personal data collected automatically.

In our website we collect data for all visitors, namely:

• IP address;

• Browser ID;

• History of the pages you visit, in order to establish your preferences for certain types of content;

• History of your searches on our pages;

5. Personal data collected by users when placing an order:

• name and surname;

• email;

• address;

• telephone;

• debit / credit card number

• Paypal account number

• IBAN of the user - used only to return the relevant amounts in case of complaints and / or withdrawal from the contract.

6. Personal data collected by the data subject when the persons register on the site www.forestofherbs-bg.com. In the process of creating a user registration on the website, the creation of a unique password is required, as well as the provision of the following data:

• name and surname;

• email;

• address;

• telephone;

You can also register on the Website through your Facebook or Google account.

 

7. Personal data collected by users when leaving comments on the Blog of www.forestofherbs-bg.com

• name and surname / username;

• the information contained in the comment.

COOKIES

You can get more information about the way the Administrator uses cookies by reading the Cookie Policy at www.forestofherbs-bg.com at the following address: https://www.forestofherbs-bg.com/biscuits

PURPOSES FOR PROCESSING PERSONAL DATA

The Administrator collects and processes the personal data of individuals, which are provided directly by them or are collected automatically only for the following purposes:

- For the normal functioning of all services on the website;

- To send orders through the website;

- To make contact with the person by e-mail or phone;

- To provide services that are offered on the website www.forestofherbs-bg.com;

- For the conclusion and implementation of a contract;

- To improve the efficiency and functionality of the website.

- For accounting purposes;

- For statistical purposes;

- For protection of information security;

- To send a newsletter if you wish;

In the event of a change in goals, we will inform you and ask for your explicit consent to the processing of your personal data in accordance with the new goals.

When processing and storing personal data, the Administrator may process and store personal data in order to protect the following legitimate interests:

• Fulfillment of its obligations to the National Revenue Agency, the Ministry of Interior and other state and municipal bodies.

HOW LONG DO WE STORE THE INFORMATION

We will not store your data for longer than is necessary to achieve the purposes for which we process it. If the reason on which we store your personal data ceases to exist (for example, if we cease to have a legitimate interest in storing your personal data, if the statutory period for storing your personal data has expired or if you have withdrawn your consent to store your personal data), we will delete or destroy them in a safe way.

The storage of data continues as long as we have a reason for their storage.

We apply the following terms for storing the different types of personal data according to their purpose, namely:

1. Regarding the personal data of the persons who have made an inquiry, via the contact form on the website:

- up to 3 months from sending the request.

2. Regarding personal data of persons who have made an inquiry by telephone:

- up to 1 month from the inquiry by phone.

3. Regarding personal data collected during registration on the site:

Until you want your registration to be deleted or until www.forestofherbs-bg.com operates.

4. Personal data collected by users when placing an order: Data on name, email, address, telephone, debit / credit card number, Paypal account number IBAN of the user are processed pursuant to Art. 6, para. 1 (b) of the GDPR and for the purpose of enforcing the distance contract concluded between Forest of Herbs Ltd. and a consumer within the meaning of DIRECTIVE 2011/83 / EU OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 25 October 2011 on consumer rights , as well as for the purposes of concluding the same. The data are also processed in order to fulfill the obligations of Forest of Herbs Ltd. arising from the Bulgarian Accounting Act and are stored for a period of 10 years.

5. The Electronic Communications Act shall apply to traffic data and the data shall be stored within 6 months. These data shall be transmitted to the specialized bodies and institutions only in compliance with legal provisions and with due grounds.

6. Regarding personal data collected from Blog comments

- At the discretion of the Personal Data Administrator or until you wish the data subject to be deleted.

WHERE WE STORE YOUR PERSONAL DATA

Your personal data that we collect is stored on servers located in the territory of the Republic of Bulgaria.

We store your personal data for a period not longer than necessary to achieve the above-described goals, or until the termination of the services and / or the website.

SECURITY MEASURES

The administrator has taken a wide range of technical and organizational measures to protect your personal data against loss or other forms of illegal processing. All our employees are familiar with our security policy. The personal information of our visitors and authorized customers is only available to a limited number of qualified employees who have been given a password to access the information. We regularly check our security systems and processes. Sensitive information is protected by encryption protocols to protect the information sent over the Internet. Although we take reasonable commercial measures to maintain a secure site, electronic communications and databases are subject to errors, tampering and breaches, and we cannot guarantee that such events will not occur and we will not be liable to visitors for any such events. In case you want to receive detailed information about the technical and organizational measures, please do not hesitate to contact us.

PERSONAL DATA OF THIRD PARTIES

We only process and use data that you have provided to us voluntarily, and we rely on the fact that this data is owned and provided by you lawfully.

This means that each user is responsible for not providing Forest of Herbs Ltd. data to third parties in violation of their rights to personal data protection.

Therefore, each person bears unlimited personal liability if he provides us with data to a third party without his knowledge or without his consent in accordance with the requirements of applicable data protection law, regardless of the type of data or the reasons for which provide: names, phone, email address, and any other.

MINORS AND MINORS

If we receive information that we have collected personal data from / to a person under the age of 18, we will delete it immediately, unless we are legally obliged to store this data.

Please contact us if you believe we have incorrectly or unknowingly collected information from / under the age of 18.

TO WHOM WE SHARE AND DISCLOSE YOUR PERSONAL DATA

Sometimes we record some of the information on our servers or send it to third parties. This is necessary so that we can provide you with the best experience when using our services, and sometimes - in general, so that we can ensure the availability and accessibility of the service you use.

Your personal data will not be transferred to third parties unless:

• provide us with your explicit, informed and freely given consent;

• the third parties in question provide us with contractual support in order to provide our products or services;

• this is required by law or by virtue of an act of authority of a public body;

• there is a justified need to protect the rights, property or security of users of the website or other defensible public interest;

• this is required in connection with the sale of a business, our company or its assets, which are subject to confidentiality.

Our employees and partners are duly informed of the importance of their obligation of confidentiality and are responsible for fulfilling this obligation.

For any other purposes not explicitly mentioned in this policy, we will ask for your explicit consent, identifying our partners as well as the purposes for data transfer and sharing.

By virtue of a court decision or an act of authority of a public body, we may be obliged to reveal the identity of a User, especially in the case of investigation of violations of the rights of third parties or illegal acquisition of personal data. In the event that a user's personal data is disclosed to a public authority in connection with an investigation or proceeding against him, we are not obliged to notify the user in question.

LINKS, TOOLS AND CONTENT FROM OTHER COMPANIES

The website contains buttons, tools or content that connect with other companies, such as Facebook, Instagram, Viber, Google Analytics. The Administrator assumes no responsibility for damages and losses incurred as a result of the use of these sites. Individuals are solely responsible for their use of these sites and should read their Privacy Policies, as their privacy policies may differ from ours.

RIGHTS OF DATA SUBJECTS UNDER GDPR

• Right of access to your personal data: you have the right to receive confirmation from us whether personal data is processed for you and, if so, you have the right to access personal data and information.

• Right to correct personal data: if you find that the personal data we process about you is inaccurate, you have the right to have us correct this personal data.

• Right to delete personal data (right to be forgotten): in certain circumstances, such as if your personal data has been processed illegally or you have withdrawn your consent (if the processing of personal data is based on consent), you have the right to request and receive deletion of your personal data from us.

• Right to restrict processing: in certain circumstances, such as if you have doubts about the accuracy of your personal data or have objected to our legitimate purpose of processing your personal data, you have the right to request that we restrict the processing of your personal data until a solution is found.

• Right to object to the processing: in certain circumstances, such as if you doubt our legitimate interest in processing your personal data, you have the right to object to such processing for reasons related to your specific situation.

• Right to data portability: if your personal data is processed by automatic means with your consent or for the purpose of fulfilling our contractual relationship, you have the right to request that we provide you with your personal data in a machine-readable format for transfer to another data controller.

• Right to lodge a complaint with a control body: you have the right to lodge a complaint regarding the processing of your personal data by us with the relevant control body.

 

You can exercise all your rights regarding the protection of your personal data through the attachments to this information. Of course, these forms are optional and you can submit your requests in any form that contains a statement to that effect and identifies you as the data owner.

If the consent relates to a transfer, the controller shall describe the possible risks for the transfer of data to third countries in the absence of a decision on adequate protection and appropriate means of protection.

Appendix № 1

Withdrawal form of consent for processing purposes

 

Your Name*: .........................

Your email you used in the e-shop *: .........................

Feedback data (e-mail) *: .........................

 

To

Name: ...........Ltd.

UIC / BULSTAT: .........................

Headquarters and address of management:

Phone:

E-mail:

Website:

 

I hereby withdraw my consent to the processing of personal data provided by me for the purposes of receiving a newsletter, advertising messages or other marketing materials, as I am aware of the conditions for withdrawal of consent in accordance with the Mandatory Information on the Rights of Persons of the personal data of the e-shop.

In the event of a breach of your rights under the above or applicable data protection legislation, you have the right to lodge a complaint with the Data Protection Commission as follows:

 

Title: Commission for Personal Data Protection.

Headquarters and address of management: Sofia 1592, Blvd. "Prof. Tsvetan Lazarov ”№ 2

Address for correspondence: Sofia 1592, Blvd. "Prof. Tsvetan Lazarov ”№ 2

Phone: 02 915 3 518

Website: www.cpdp.bg.

Appendix № 2

Request to be "forgotten" - to delete personal data related to me

Your Name*: .........................

Your email with which you registered or used for orders in the e-shop *: .........................

Feedback data (e-mail) *: .........................

 

To

Name: ........... Ltd.

UIC / BULSTAT: .........................

Headquarters and address of management:

Phone:

E-mail:

Website:

 

I ask that all personal data that you collect, process and store provided by me or by third parties who are related to me, according to the specified identification, be deleted from your databases.

I declare that I am aware that some or all of my personal data may continue to be processed and stored by the controller for the purpose of fulfilling his legal obligations.

In the event of a breach of your rights under the above or applicable data protection legislation, you have the right to lodge a complaint with the Data Protection Commission as follows:

 

Title: Commission for Personal Data Protection.

Headquarters and address of management: Sofia 1592, Blvd. "Prof. Tsvetan Lazarov ”№ 2

Address for correspondence: Sofia 1592, Blvd. "Prof. Tsvetan Lazarov ”№ 2

Phone: 02 915 3 518

Website: www.cpdp.bg.

Appendix № 3

Request for portability of personal data

Your Name*: .........................

Your email with which you registered or used for orders in the e-shop *: .........................

Feedback data (e-mail) *: .........................

 

To

Name: ........... Ltd.

UIC / BULSTAT: .........................

Headquarters and address of management:

Phone:

E-mail:

Website:

 

I ask that all personal data related to me that is collected, processed and stored in your databases be sent in XML format to:

e-mail: .........................

Administrator - receiving the data: .........................

 

Name: .........................

Identification number (UIC, BULSTAT, registration number in the CPDP): .........................

Email: .........................

 

In the event of a breach of your rights under the above or applicable data protection legislation, you have the right to lodge a complaint with the Data Protection Commission as follows:

 

Title: Commission for Personal Data Protection.

Headquarters and address of management: Sofia 1592, Blvd. "Prof. Tsvetan Lazarov ”№ 2

Address for correspondence: Sofia 1592, Blvd. "Prof. Tsvetan Lazarov ”№ 2

Phone: 02 915 3 518

Website: www.cpdp.bg.

Appendix № 4

Request for correction of data

Your Name*: .........................

Your email with which you registered or used for orders in the e-shop *: .........................

Feedback data (e-mail) *: .........................

 

To

Name: ........... Ltd.

UIC / BULSTAT: .........................

Headquarters and address of management:

Phone:

E-mail:

Website:

 

Please correct the following personal data that you collect, process and store provided by me or by third parties who are related to me as follows:

Data to be corrected:

..................................................

Please correct as follows:

..................................................

In the event of a breach of your rights under the above or applicable data protection legislation, you have the right to lodge a complaint with the Data Protection Commission as follows:

 

Title: Commission for Personal Data Protection.

Headquarters and address of management: Sofia 1592, Blvd. "Prof. Tsvetan Lazarov ”№ 2

Address for correspondence: Sofia 1592, Blvd. "Prof. Tsvetan Lazarov ”№ 2

Phone: 02 915 3 518

Website: www.cpdp.bg.

 

 

This Policy is in force on 01.11.2020 and is in line with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of movement of such data and repealing Directive 95/46 / EC (General Data Protection Regulation).