PERSONAL DATA PROTECTION POLICY
SUN CITY Ltd. has the capacity of controller of personal data according to Regulation (EU) 2016/679 (hereinafter referred to as “Regulation“).
Administrator identification: SUN CITY LTD
Headquarters and address of management: Sandanski, 12 Mladost Street
UIC 101078768, VAT number: BG 101078768
SUN CITY Ltd. treats as personal data any
information that identifies a specific individual or that relates to an individual through which he or she can be identified. The processing of personal data is an action or set of actions that can be performed on personal data by automatic or other means.
1. How do we collect information about you?
We collect personal data with the express consent of the person to whom it relates. When you register on our site or use any of the forms, you provide us with certain information voluntarily, which we process and store. This information may include: first name, last name, email address, phone number, date of birth, pins, comments and any other information you provide to us. You may choose to share location information or photos with us. We may prefer to reduce the amount of data we store and process according to the purposes of the processing.
In the event that you decide to purchase a product or order a particular service through suncitysandanski.com, we may collect payment information, contact information (address and telephone number) and details of the product or service you have ordered.
When we link your account to your Facebook or Google account or to other third-party services, we also receive information from those accounts (such as friends or contacts). The information we receive from these services depends on the settings and privacy statements, so each person should check what they are.
We also receive technical information when you use our site. Each time you use the site, mobile application or other Internet service, the system creates and saves certain information automatically. Here are some of the categories of information we collect:
a / Data in the log files. When you use the site, our servers record information (log data or log data), including information that your browser automatically sends when you visit a website or your mobile application automatically sends when you use it. This log data includes the address of the Internet Protocol, the address and activity of the websites you visit, searches, type and settings of the browser, date and time of your request, how you used the site, cookie data and device data.
c / Device information. In addition to log data, we collect information about the device through which you use our website, including device type, operating system, settings, unique device identifiers, and crash data to help us understand when something breaks. Whether we collect some or all of the information often depends on the type of device you are using and its settings. For example, there are different types of information depending on whether you’re using a Mac or PC or iPhone or Android phone. To learn more about what information makes your device available to us, please also check the device manufacturer’s or software provider’s policies.
2. What do we do with the information we collect. Purposes and term of processing:
SUN CITY Ltd. processes and stores the personal data mentioned above only for the purpose of processing the requests of its users, making deliveries, as well as for the following purposes:
a / Pursuant to Art. 6, item 1, letter “b” of the Regulation – for implementation of pre-contractual relations;
b / Pursuant to Art. 6, item 1, letter “b” of the Regulation – for fulfillment of already incurred contractual obligations.
c / Pursuant to Art. 6, para. 1, letter “a” and Art. 7 of the Regulation – for non-personalized advertising;
d / On the grounds of art. 6, para. 1, letter “a” and Art. 7 of the Regulation – for personalized advertising;
e / On the grounds of art. 22, para. 2, letter “c”, Art. 6, para. 1, letter “a” and Art. 7 of the Regulation – for personalized assessment of information;
f / Pursuant to Art. 6, para. 1, letter “e” – for marketing purposes.
g / Pursuant to Art. 6, para. 1, letter “e” of the Regulation – for retargeting in connection with the purposes of marketing, remarketing or optimization;
The data is stored and processed as long as the user’s account is valid and 1 year after its deactivation or deletion, as well as, as long as it is needed to provide our services. In case the person makes the respective request, the information shall be destroyed immediately.
In order to make a delivery, when requested by the user, SUN CITY Ltd. has the right to provide the above personal data or part of them to courier companies or national postal operators, incl. ECONT, SPEEDY, EUROPE. In this regard, the user may receive SMS or calls from these persons.
3. Rights you may exercise in relation to your personal data:
All rights are exercised, and the relevant requests and notifications in connection with the rights of data subjects are deposited through the CONTACT FORM ON PERSONS RELATED TO PERSONAL DATA, to e-mail: [email protected] Or by mail to the management address given above. Requests shall be made in a way that allows the identity of the applicant to be identified. For some rights, technical possibilities for exercising them may be applicable, such as an Unsubscribe button. In any case, the administrator should respond to the request or rule on the declared right to the address or e-mail provided in the contact form, within one month of receiving it.
According to the General Data Protection Regulation, the data subject is entitled to:
· Awareness (in connection with the processing of his personal data by the administrator); When there is a risk of a breach of the security of your personal data, the controller is obliged to inform you about the nature of the breach and what measures have been taken to eliminate it, as well as whether the supervisory authority has been notified of the breach.
· Access to your own personal data and the right to withdraw consent to processing. As a data subject, you have the right to request onfirmation of whether your personal data is being processed and, if so, to have access to your data and the following information: for what purpose data are processed, what personal data, data recipients, processing time. Requests for access must be made in writing / electronically and addressed to the administrator. You also have the right to withdraw your consent to the processing of your personal data at any time.
· Correction (if the data is inaccurate). As a data subject, you have the right to request correction of your personal data that is inaccurate / out of date. You must submit a separate request for this purpose. Your request will be answered by the administrator in the following way – in writing, at the provided e-mail address.
· Deletion of personal data (right to be “forgotten”). As a data subject, you have the right to be “forgotten”, ie. to request that your personal data be deleted without undue delay, ie. the administrator to delete your personal data from all systems and records where they are stored, including notifying all third parties / processors of personal data to whom he has provided the data. A request for deletion may be submitted
on the grounds provided for in the Regulation, incl. in the presence of any of the following grounds: personal data are no longer necessary for the purposes for which they were collected; when you have withdrawn your consent; when you have objected to the processing, when the processing is illegal; where personal data must be deleted in order to comply with a legal obligation under Union law or the law of a Member State applicable to the controller; where personal data have been collected in connection with the provision of information society services. The controller may refuse to delete personal data on the grounds specified in the Regulation – when the processing of specific data is for the
purpose of: exercising the right to freedom of expression and information; performing a legal obligation or task of public interest or exercising public authority; for public health purposes; archiving for purposes of public interest, historical research or statistical purposes; or establishing,
exercising or defending legal claims.
· Restriction of processing by the controller or processor of personal data. As a data subject, you have the right to ask the controller of your personal data to restrict the processing of personal data. The restriction is allowed in the following cases: – when you believe that your personal data is not accurate, in which case the restriction is for a period necessary for the administrator to verify the accuracy; – when the processing of your personal data is illegal, but you do not want them to be deleted, but you only want their use to be restricted; – when the controller no
longer needs your personal data for the purposes of processing, but you, as the data subject, require them for the establishment, exercise or protection of legal claims; – when you have objected to the processing pending verification that the legal grounds of the administrator take precedence over your interests. For this purpose, in the presence of any of the above conditions, you should submit a request.
· Portability of personal data, incl. between individual administrators. The data subject has the right to portability – to receive personal data concerning him and which he has provided to the controller, in a structured, widely used and machine-readable format and has the right to transfer this data to another controller without interruption by the controller, to whom the personal data are provided when the processing
is based on consent or a contractual obligation and the processing is carried out in an automated manner. When exercising its right to data portability, the data subject shall also have the right to receive a direct transfer of personal data from one controller to another, where this is technically feasible.
· Objection to the processing of his personal data. As a data subject, you have the right to object to the processing of your personal data at any time, incl. when for direct marketing purposes. The administrator should be motivated whether he accepts the objection, resp. why he continues to process personal data if he rejects the objection.
· The data subject is also entitled not to be the subject of a decision based solely on automated processing, including profiling, which has legal consequences for the data subject or similarly affects him to a significant degree. The data subject has the right to challenge the automated
decision at any time.
· Right to judicial or administrative protection in case the data subject’s rights have been violated. As a subject of personal data you have the right to complain against the processing of your personal data or non-compliance with your rights in connection with the protection of personal data before the competent supervisory authority – Commission for Personal Data Protection, address: Sofia 1592, Blvd. . Tsvetan
Lazarov ”№ 2 (cpdp.bg). Also, a person who has suffered material or non-material damage as a result of a breach of this Regulation shall be
entitled to receive compensation from the controller or processor for the damage caused.
We have taken many technical, legal and organizational measures to protect the personal data of each person. In order to avoid unauthorized access, we perform encryption procedures in some areas. We also use SSL protocols to prevent the possibility of data misuse by third parties. We do not share data with third parties, except in cases where we should make a delivery of our service.
It is possible to use the services of third parties who are processors of personal data for the above purposes of processing. These persons process personal data on our behalf and are obliged to comply with current regulations for personal data protection. These individuals are carefully selected by us and have access only to the data they need to provide the services with which they are engaged and within the framework of our consent. In the event that these persons are outside the EU and do not meet the necessary requirements of the GDPR, based on its status as a legal act, we will guarantee the protection of personal data through contractual or other legal instruments. Also, it is possible that personal data may be provided to state or municipal authorities that exercise different types of control within the law.
By confirming the application for registration of an account, confirming an order for a service or product, the user gives his explicit consent to the processing and transfer of personal data for one or more of the following purposes:
a / Inclusion of the user’s assessment and his opinion in marketing research by electronic methods – by e-mail or messenger.
b / Receiving electronic messages for products, services, etc. advertising messages on all owned devices.
c / Receive personalized advertising that is tailored to the user’s preferences. Personalization is based on an assessment of user behavior data;
d / Receiving personalized commercial offers in accordance with the consumer’s behavior and relevant to his preferences by e-mail, mail or messenger. For this purpose, the data on the consumer’s consumption based on his purchasing behavior, his participation in advertising campaigns, as well as the use of the site may be subject to analysis and forecast of the consumer’s interests.
e / Receiving non-personalized advertising. Users will also receive information about current products, services, initiatives and more advertising messages.
In the process of personal data processing SUN CITY Ltd. observes the principles of European and national legislation related to the protection of personal data. By applying a package of organizational, technical and legal measures, we strive to ensure a high level of security of personal data, protection against unauthorized processing, destruction or damage.