Personal Data Protection Policy
AT "MI AMANTE" LTD.
- Introduction
1.1. General provisions
This personal data protection policy (hereinafter referred to as the "Policy") regulates the personal data processing activities of "Mi Amante" Ltd., UIC 204519279, with registered office and management address: Sofia 1408, Lozenets district, "Sv. Osiy Kordobski" St., Residential group "Yuzhen park", bl. 113, ap. office 2, (hereinafter referred to as the "Company"), with the aim of guaranteeing compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, hereinafter referred to as the "Regulation"), as well as with all other applicable normative acts on the protection of personal data. This Policy applies to matters concerning the protection of personal data for which there is no other regulation under other acts of the Company.
1.2. The Policy aims to regulate and covers in particular the following matters:
the personal data processing activities, the categories of data subjects to which the Policy applies, the principles and responsibilities in connection with the processing;
the obligations of the persons acting under the direction of the Company in the processing of personal data and their responsibility in case of non-fulfilment;
rights of the data subjects and a procedure for exercising them;
a procedure for processing personal data on the basis of the consent of the data subjects;
rules for responding in case of a breach of the security of personal data;
the technical and organisational measures applied for the protection of personal data.
1.3. Information about the Company
The company "Mi Amante" Ltd.
Registration data entered in the commercial register and register of non-profit legal entities at the Registry Agency, with UIC 204519279
Registered office and management address Sofia 1408, Lozenets district, "Sv. Osiy Kordobski" St., Residential group Yuzhen park, bl. 113, ap. office 2,
Contact address: Sofia 1330, 116 "Nikola Mushanov" Blvd., floor 2, office 8
Subject of activity Production and trade of cosmetics, perfumery and other chemical products related to them, foreign and domestic trade in food and industrial goods, commercial representation and intermediation and any other type of economic activity that is not prohibited by law
Contact email office@miamantehair.com
- Terms and abbreviations used
All terms and abbreviations that are not expressly defined in the Policy have the meaning defined in the Regulation.
- Personal data processing activities
3.1. Principles of personal data processing
The processing of personal data by the Company is subject to the principles of lawfulness, fairness and transparency and of data minimisation. The personal data processed are limited to what is necessary in connection with the purposes for which they are processed. Personal data are collected for specific, explicitly stated and legitimate purposes and are not further processed in a manner incompatible with those purposes. Personal data are accurate and, where necessary, kept up to date. Personal data are stored in a form that permits the identification of the data subject for a period no longer than necessary for the purposes for which the personal data are processed. Personal data are processed in a manner that guarantees an appropriate level of security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, disclosure, destruction or damage, by applying appropriate technical or organisational measures, in compliance with the principles of ongoing confidentiality, integrity, availability and resilience of the processing systems and services.
3.2. Categories of data subjects. Categories of personal data and purposes of the processing.
3.2.1. The Company has the right to process personal data concerning its customers, employees and other data subjects, as follows:
customers (natural persons) of the Company in its main activity of offering and trading in cosmetic products, in respect of which personal data such as IP address, e-mail address, telephone number, MAC address, address (postal and for delivery), information for invoicing and acceptance of bank payments, etc. may be processed. The purposes of the processing for this category of subjects include: (i). acceptance, processing and fulfilment of requests for ordering the products and/or services offered by the Company, including the use of the Company's website; (II). keeping a tax and accounting register; (III). fulfilment of legislative requirements; (IV). purposes related to the legitimate interests of the Company; (v). purposes for which the data subject has given consent to the processing of their data;
potential, current and/or former employees of the Company, and natural persons who are or have been in contractual relationships with the Company under civil contracts; candidates for work or for the conclusion of a civil contract as external contractors - natural persons who are not in employment or contractual relationships with the Company, but wish to enter into such, in respect of which personal data such as three names, personal identification number / personal number of a foreigner / official number, date of birth; address, data on previous employment or professional experience, education and qualification, disciplinary liability incurred; information on bank accounts (IBAN, in case of payment by bank transfer), contact data: tel. number; e-mail address; other data required under the applicable legislation for the conclusion and performance of an employment or civil contract; data directly related to the activity of performing the contracts concluded with these persons (e.g.: data from logs or activity of the persons in the systems maintained by the Company, with a view to performing the functions assigned to the persons (e.g. systems for entering orders), IP address, etc. The purposes of the processing in respect of this category of subjects include: (i). investigating the possibility of, concluding and performing an employment or civil contract with the data subjects; (ii). keeping a tax and accounting register; (iii). fulfilment of legislative requirements; (iv). purposes related to the legitimate interests of the Company; (v). purposes for which the data subject has given consent to the processing of their data.
co-contractors and partners - natural persons, under contracts for advertising and promoting the products offered by the Company, for whom the Company may collect personal data also in the form of photographic images. The purposes of the processing in respect of this category of subjects include: (i). performance of contracts for advertising or promotion; (ii). purposes related to the legitimate interests of the Company; (iii). purposes for which the data subject has given consent to the processing of their data;
other natural persons and natural persons-representatives or contact persons of legal entities who have contact with the Company (including, but not limited to suppliers, business contacts, subcontractors, business partners and the like) for the purposes of performing and/or managing the activity of the Company;
other natural persons, representatives by law or power of attorney, of natural persons - customers of the Company.
3.2.2. The Company retains personal data for the longer of the periods necessary either for compliance with the applicable laws and subordinate normative acts, or another period in accordance with the requirements applicable to the commercial activity of the Company or to its activity as an employer or assignor under civil contracts. The processing of personal data is based on the principle of data minimisation, depending on and for the purposes of providing the services used by the respective customer.
- Categories of data recipients
The Company may disclose personal data to the following persons:
service providers - consultants, lawyers, accountants, IT specialists, etc., in connection with the conclusion of contracts from the main activity of the Company, fulfilment of legal requirements, technical support, etc.;
subcontractors - when providing services on behalf of the Company (distributors, etc.), in connection with the conclusion and performance of contracts for trade in the products offered by the Company;
persons providing services for the provision and maintenance of equipment, software and hardware used for processing (including storage) of personal data, for accounting of payments, etc.;
banks, for servicing payments by the data subjects;
public and/or judicial authorities, in and to the extent permitted and/or required under the law.
- Obligations of the Company
The Company has the following obligations:
determines the policies and procedures for the protection of the processed personal data in accordance with the applicable legislation;
introduces appropriate technical and organisational measures with a view to the effective application of the principles for data protection, as well as to guarantee that, by default, only personal data that are necessary for the respective purpose of the processing are processed;
ensures the exercise of the rights of the subjects for the protection of personal data;
updates the maintained databases and exercises control over compliance with the protection requirements, establishes circumstances related to a breach of the protection, and takes measures for their remedy;
maintains the personal data in a form that permits identification of the respective subjects for a period no longer than necessary for the purposes for which this data is processed;
informs the employees as appropriate on the matters of the protection of personal data;
provides assistance in the exercise of the control functions of the Commission for Personal Data Protection (hereinafter referred to as the "CPDP");
determines the rights of the employees for access to personal data in the information systems in accordance with the purposes of the processing;
uses processors of personal data who provide sufficient guarantees through the application of appropriate technical and organisational protection measures;
complies with certain rules in case of a breach of the security of personal data;
documents breaches of the security of personal data in accordance with the applicable legislation;
carries out a risk assessment, in accordance with the requirements of the Regulation, respectively an impact assessment, if under the Regulation the conditions for this are present.
- Obligations of the employees of the Company. Responsibility. Confidentiality
6.1. The employees of the Company begin to process personal data after familiarisation with:
the regulatory framework in the field of the protection of personal data;
the Policy and the other internal acts of the Company related to the protection of personal data;
the dangers to the personal data processed by the Company.
The employees of the Company are obliged:
to comply with the requirements of the Regulation, the rest of the applicable legislation in the field of the protection of personal data, the Policy and the other internal acts of the Company related to the protection of personal data;
to process personal data only when there is a condition for lawful processing, namely: a legal ground for processing; or a ground for processing that arises from the contractual relations with the person or is necessary for the possible conclusion of contractual relations with the person; or a ground for processing that arises from the explicit consent of the person; or a ground for processing that arises from the legitimate interest of the Company or of a third party in accordance with the requirements of the Regulation;
to use the personal data in accordance with the purposes for which they are collected and not to process them additionally in a manner incompatible with those purposes;
not to use the personal data to which they have access in their capacity as employees of the Company, for any personal purposes whatsoever;
to comply with the rule of avoiding the possibility of unregulated access to personal data and of leaving accessible personal data unattended at the respective workplace. In premises to which external persons have access, the respective employees are obliged to take measures so that external persons do not have any unlawful access whatsoever to documents containing personal data, including to be able to view, copy or photograph them with a technical means;
when the performance of the respective activity permits, to limit the personal data used to the maximum extent;
to ensure and guarantee compliance with the rights of the subjects in connection with the processing of personal data;
not to allow, assist or create conditions for breaches of the security in the processing of personal data;
not to share or provide among themselves or to third parties information of essential importance for the security of the data (their user names, passwords for access to the systems, etc.);
not to copy files with corporate information containing personal data onto a portable medium in an unencrypted (or password-unprotected) form;
not to send by email to email addresses outside the Company information containing substantial volumes of personal data, or any special categories of personal data, or other personal data, unlawful access to which may constitute a high risk for the rights and interests of the data subjects to which they relate, in password-unprotected files or in an unencrypted or otherwise non-pseudonymised form.
not to publish personal data of customers or employees of the Company on public sites, etc., without the presence of an adequate legal ground for this;
6.2. Responsibility of the employees
6.2.1. All actions that lead or may lead to the unregulated deletion, destruction or modification of personal data received at the Company in electronic form or on paper, as well as the unregulated sharing/disclosure of personal data, on the part of employees of the Company is prohibited and may lead to the realisation of the responsibility of the respective employee (disciplinary, administrative-penal and/or criminal, and/or civil).
6.3. The Company:
ensures the signing of a declaration of confidentiality and non-distribution of personal data by all employees who process personal data for it.
informs the employees who process personal data of their obligations related to this processing.
- Maintaining a Register of personal data processing activities as a controller
In accordance with the requirements of Art. 30, para. 1 of the Regulation, the Company keeps a Register of processing activities in the capacity of a controller, which contains the name and contact details of the Company. The Register includes a detailed description of all personal data processing activities in accordance with Art. 30, para. 1 of the Regulation, including with the following characteristics: name of the activity (business process, function) of processing; the purposes of the processing; the categories of natural persons whose personal data are processed; the categories of personal data that are processed in the respective activity; third parties that receive or otherwise participate in the processing of personal data in the respective activity; where applicable, the transfer of personal data to a third country, outside the EU; the envisaged periods for storage and deletion of the various categories of personal data, where possible; a general description of the technical and organisational security measures, where possible.
- Maintaining a Register of personal data processing activities as a processor
In the event that, in view of the activities of the Company, the need arises for it to maintain a Register of personal data processing activities as a processor within the meaning of Art. 30, para. 2 of the Regulation, the Company will create and maintain such a Register in the form, volume and content required under the applicable legislation.
- Data protection officer
The Company will appoint a data protection officer (hereinafter referred to as the "DPO") in the event that the appointment of such becomes or proves necessary in accordance with the applicable legislative requirements for the protection of personal data.
- Rights of the data subjects
The Company ensures the exercise of the following rights of the data subjects:
the right to information, upon the collection of personal data from the data subject;
the right of access to the data of the data subject and more specifically: (i). confirmation of whether personal data of the data subject is being processed by the Company; (ii). the provision of access to the data through a copy of the data that is being processed, as well as information regarding the purposes of the processing; the categories of personal data; the recipients or categories of recipients to whom the personal data have been or will be disclosed; the storage periods of the personal data; the existence of a right to rectification or erasure of personal data or restriction of the processing of personal data, or to objection to the processing; the right to lodge a complaint with the CPDP; the sources of the personal data; the existence of automated decision-making, including profiling.
the right of rectification - to require the rectification or completion of their personal data, if it is inaccurate or incomplete;
the right to erasure of the personal data, when the grounds provided for in the Regulation are present;
the right to restriction of the processing;
the right to data portability;
the right to object;
the right of the data subject not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or otherwise significantly affects them;
giving, changing or withdrawing consent to the processing of personal data, when the ground for the processing is the consent of the data subject.
The data subjects can exercise their rights by submitting a written application to the Company, in one of the following ways:
by email to the company's email address indicated above, through a qualified electronic signature, in accordance with the Electronic Document and Electronic Trust Services Act (hereinafter referred to as the "QES");
by post to the contact address of the Company, with the sending of a notarised application for the purpose of ensuring identification of the applicant, and in cases where the application is submitted by a legal representative of the applicant, or through a representative of the applicant authorised by a notarised power of attorney, the application should also contain the notarised signature of the person who signed.
Applications are reviewed without undue delay. Within a period of one month from the submission of the application, the Company notifies the data subject of the actions taken on the application, respectively of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority and seeking judicial protection. If actions are taken in connection with the application, the period for notifying the data subject of these actions may be extended to a total of three months, taking into account the complexity and number of applications. In this case the Company notifies the data subject of the extension of the period within the initial one-month period.
The information (which may vary depending on which right of the data subject is exercised) is provided on paper personally to the data subject or to their legal representative or representative authorised by an explicit notarised power of attorney. If the application is submitted by email, the information is provided also by email to the e-mail address from which the submitted application originates, in password-protected files.
- Consent of the data subject as a ground for processing
11.1. Ground
In cases where the ground for the processing of personal data is consent within the meaning of the Regulation, the consent should be given personally through a written declaration, in electronic form or another manner determined by the Company, which guarantees that the consent is freely given, specific, informed, and unambiguous.
11.2. Data subjects
The Company may collect consents for all categories of data subjects for which the processing of personal data is carried out, including customers, employees and persons with whom the Company has concluded civil contracts for the provision of services or orders, etc.
11.3. Withdrawal
The Company provides the data subjects with the possibility to easily change or withdraw their consent, without this giving rise to adverse legal consequences for them, when there is objectively a possibility for this. Changes or withdrawal of consent are carried out by the data subjects in accordance with the procedure for collecting consents. In the event of partial or full withdrawal of consent, when the processing of personal data is carried out on this ground, the Company may find itself unable to provide the service requested by the customer or to carry out the activity for which the respective provision of personal data was required. The withdrawal of consent does not affect the lawfulness of the processing based on the consent given up to the moment of its withdrawal.
11.4. Collection of consents
Consents are collected in one of the following ways:
in person, at the contact office - for customers of the Company;
by official email - for current employees;
through a licensed postal operator with notarial certification of the declaration of consent; or
a declaration of consent signed with a QES, sent by email.
11.5. Giving and withdrawing consents online
In the presence of cases in which obtaining consent for the processing of personal data by the Company is required in view of services provided by the Company that are requested online, this consent is obtained (respectively, withdrawn) also online.
11.6. Storage
Consents to the processing of personal data are registered and stored by the Company, in the form and volume correspondingly possible for such storage.
- Processing of personal data by the Company through a processor of personal data
For the carrying out of its activity, the Company may use third parties (subcontractors, distributors, providers of courier services, etc.), constituting processors of personal data within the meaning of Art. 4, item 8 of the Regulation. Such processors may be:
commercial companies;
natural persons hired under civil contracts.
When assigning the processing of personal data to a processor, the Company complies with the following requirements:
processors are chosen who provide sufficient guarantees for the application of appropriate technical and organisational measures for the protection of personal data;
the conditions for the protection of personal data are settled in writing between the Company and the processor.
The contracts/agreements that the Company concludes with the processors of personal data determine and settle: the subject and term of effect, the purposes and nature of the processing; the categories of data subjects whose personal data are processed; the type of personal data that the processor will process on behalf of the Company; the rights and obligations of the Company and the processor; the requirements for the technical and organisational protection measures that the processor should apply (no deviation from what is provided for in this Policy is allowed in respect of the processor); an obligation for the processor to provide assistance in accordance with Art. 31-36 of the Regulation; an obligation for the processor to notify the Company without undue delay after becoming aware of the presence of a breach of the security; requirements for the processor and other mandatory conditions, in accordance with Art. 28, item 3 of the Regulation.
- Rules for responding in case of a breach of the security of personal data
13.1. Discovery of a breach of the security by an employee
In the case of a breach of the security, discovered by an employee of the Company, the employee reports this immediately to the management of the Company, or to the DPO, if such has been appointed, in written form (and where possible - also orally), providing also the information that they have on this - on the nature of the breach, on the presumed time of occurrence / commission of the breach, etc.
13.2. Investigation of the breach of the security and measures
Without undue delay, the Company should investigate the facts, carry out an analysis and assessment of the severity of the breach, with a view to the risk to the rights and freedoms of the subjects, the number of affected data subjects, etc., and propose appropriate measures for remedy, and where this is impossible - for minimising the identified risks and the possible adverse consequences.
13.3. Notification of the CPDP
In the case of a breach of the security, the Company informs the CPDP of this within a period of up to 72 hours from the establishment, unless in the particular case there is no likelihood whatsoever that the breach of the security will give rise to a risk for the rights and freedoms of natural persons.
13.4. Notification of the data subjects
When the breach of the security may lead to a high risk for the rights and freedoms of natural persons, the Company communicates the breach of the security of personal data to the affected data subjects without undue delay. The communication describes the nature of the breach of the security and indicates at least: the name and contact details of the Company; a description of the possible consequences of the breach; a description of the measures taken or proposed by the Company to deal with the breach.
The Company has the right not to communicate the breach to the affected data subjects, if:
(I). it has taken appropriate technical and organisational protection measures in advance and these measures have been applied, (e.g. encryption); and/or
(II). it has subsequently taken measures that guarantee that there is no longer a likelihood of the high risk for the rights and freedoms of the data subjects materialising; and/or
(III). such communication would entail disproportionate efforts. In this case, the Company makes a public communication on its website and/or through disclosure in an appropriate manner through the mass media of the breach.
13.5. Storage
Signals of breaches of the security of personal data are registered and stored by the Company.
- Technical and organisational measures for the protection of personal data
14.1. Technical and organisational measures of the Company as a controller
In the activity of the Company, the necessary technical and organisational measures for the protection of personal data from accidental or unlawful destruction, or from accidental loss, from unauthorised access, modification or distribution, as well as from other unlawful forms of processing, are provided for. The types of protection are physical, personnel, documentary, protection of automated information systems and/or networks, cryptographic protection. The technical and organisational measures that the Company applies are listed in detail in Appendix 1 to this Policy, as the same may be the subject of periodic updates.
14.2. Technical and organisational measures of the Company as a processor
In the event that the Company processes personal data as a processor for other controllers, the specific technical and organisational measures applied by the Company in its capacity as a processor are determined in individual agreements with the respective controller. If such determination is absent, the Company will adhere to the technical and organisational measures that it applies as a controller.
- Transfer of personal data outside the European Economic Area (EEA)
The Company may carry out international transfer of data originating from the European Economic Area (EEA), when the European Commission has recognised a country outside the EEA as ensuring an adequate level of data protection. For transfers to countries outside the EEA whose level of protection is not recognised by the European Commission, the Company will rely either on a specific derogation applicable to the particular situation, in accordance with the Regulation, or will apply one of the safeguards provided for by the applicable legislation. In the remaining cases, the transfer of personal data outside the EEA is carried out on the basis of the explicit consent of the data subject to the proposed transfer of data, obtained in compliance with the requirements of the Regulation for this.