ZIZITO BG EOOD (the Company) processes your personal data in compliance with the requirements of the General Regulation on the Protection of Personal Data (Regulation (EU) 2016/679) and the Law on Personal Data Protection.
According to Art. 4 of Regulation (EU) 2016/679, 'personal data' means any information relating to an identified natural person or natural person, which can be identified, directly or indirectly, in particular by an identifier such as a name, identification number, location data, an online identifier, or by one or more attributes specific to that individual's physical, physiological, genetic, mental, intellectual, economic, cultural, or social identity.
In compliance with our obligations under Regulation (EU) 2016/679 of the European Parliament and the Council (the “Data Protection Regulation”), the Company ensures that the processing of personal data, such as name, address, telephone and email address, will always be in compliance with the Regulation and the applicable Bulgarian legislation in the field of personal data protection.
1. Collection and use of personal data
The Company collects personal data intended for:
- The preparation and conclusion of a contract, including its implementation, and
- Marketing activity - where personal data is provided after giving explicit, free, and informed consent to their use.
The personal information you provide is only processed for the purposes of the activities of the site . The goals of our business are: the selling of distance goods, management of user profiles on the website and statistical goals related to internal analysis and improvement of the Company's activity.
The Company does not collect personal information beyond what is necessary for the performance of its business or that is provided by you with your explicit and free consent.
2. The personal data we process and the purpose:
2.1. For the purpose of contracting, delivery of goods and customer information services
For the purposes of entering into a contract for the sale of goods, we collect the following personal information:
- Three names;
- Email address;
- Telephone and delivery address;
- Bank account number;
- Sound recording data from a supported center.
Personal information is collected through the order form on our site - through a profile or as a guest. The processing of personal data is necessary for the conclusion of a contract to which the data subject is a party or for taking steps at the request of the data subject prior to the conclusion of a contract (Article 6 (1) (b) of the Regulation).
2.2. For the purposes of marketing activities
We collect the following personal information for the newsletter and other marketing activities:
- Two names;
- Email address;
- Other information provided by you regarding specific marketing purposes of which you have been informed.
2.3. Technical information
Each time you visit the website at www.zizito.com and/or its various sections, we receive information in the form of an information protocol with the following content:
- Your IP address and the page from which you are redirected to our site;
- Information about your stay on our website and the sections you have visited;
- Information about your browser and operating system;
- Other types of technical information relative to the technical requirements of the information system;
2.4. Other data
Due to legal requirements and the different types of goods offered on the site, it may be necessary to collect other types of personal information. In such cases, the Company will explicitly inform you of the personal data that are required, the reason for the collection and the purposes for which it is processed.
3. Personal data that are not processed
The Company does not collect or process personal data that:
- Disclose the racial or ethnic origin of consumers or other data relating to their health or mental health;
- Disclose political, religious, or philosophical beliefs or membership of trade union organizations;
- Disclose genetic or biometric or sexual orientation data to users.
4. Grounds and purposes for the processing of personal data by the Company
The company does not make use of automated decision making, the data provided will not be used for advertising or marketing purposes, nor will it be made available to third parties, except in specific cases, namely:
- When required by law;
- If duly requested by a competent state or judicial authority;
- When we have received your explicit consent to do so.
4.1. Grounds for processing of personal data
The grounds for the processing of personal data are the following:
- Pre-contractual and contractual relations with clients with regard to the conclusion of a contract for the purchase of distance goods;
- Your explicit and freely stated consent to the processing of certain types of personal data;
- Legal requirements related to the activity of the Company.
4.2. Purposes of the processing of personal data
- Performing all actions related to the conclusion of a contract between the Company and the consumer;
- Execution of an order made from the e-shop;
- Accounting regulatory requirements;
- Managing your profile or using the blog section of the site
- Notifying you of new promotions and current offers;
- The exercising of your rights to claim and warranty;
- Answering questions and queries.
5. Period of storage of the submitted data
The Company stores your data in compliance with the time limits provided by law. The main criterion by which we will determine the extent of processing is the extent of time the information is needed.
In cases where no contract is concluded, your personal data will be deleted in a timely manner. Personal data provided for the conclusion of a contract will be retained for the duration of its conclusion. In cases where we process personal data on the basis of your consent, the personal data will be stored until you withdraw your consent and exercise your right that any personal data you have provided will be deleted/removed.
6. Technical security regarding the protection of personal data
The Company has implemented all the technical and organizational measures necessary for the processing and protection of personal data in compliance with Regulation (EU) 2016/679 and the applicable Bulgarian legislation.
The measures taken relate to the specific risks associated with the processing and storage of the personal data provided. It is organizationally and technically safeguarded to protect your data from loss, alteration, theft or unauthorized access by unauthorized third parties.
If you do not wish to receive cookies, please configure your Internet browser to delete all cookies from the hard disk on your computer, to block cookies, or to warn you before storing cookies.
8. Sharing and disclosure of personal data with third parties
In some cases, the Company may disclose certain personal information to our partners or subcontractors who work with us by providing products and services related to the Company's business or assisting the Company in its marketing activities.
The Company may disclose your personal information to third parties, including such third parties located outside the European Union, subject to the requirements of the Regulation, for instance:
- When organizing games, competitions, or promotions in accordance with the rules of the specific games;
- Couriers and/or other third parties organizing the delivery of the products;
- Third parties with whom the Company has a contractual relationship with regard to the delivery and extent of content or advertisements, including servers for the delivery of advertised content, inventory exchanges (Ad Exchanges), publishing tools (SSP), advertising tools (DSP) );
- Third parties with whom the Company has a contractual agreement for the use of virtual servers (VPS);
- Third parties providing services to improve the advertising targeting of the Company's products and services;
- Providers of server and cloud services related to ordering and servicing of the hub;
- Third parties providing services to the Company, such as accountants, auditors, attorneys, notaries, advertising and PR agencies or companies engaged in the systematic administration of data.
The Company will share personal data with third parties only after explicitly providing the technical and legal mechanisms under which the processing of the shared personal data will proceed in compliance with the requirements of Regulation (EU) 679/2016 and the Bulgarian legislation.
The Company undertakes to take all necessary steps to ensure the legitimate processing of personal data in compliance with the confidentiality requirements set out in this Policy.
9. Your rights as a data subject
According to the Regulation, every data subject has the following rights:
9.1. Right of access
You have the right to know for free what personal data we process and whether we process it.
9.2. Right of correction
In the event of a discrepancy between your data and the data we process, you have the right to ask us to correct, without undue delay, any data stored by us that is inaccurate.
9.3. Right to restrict processing
In certain circumstances, you may request restriction or blocking of the processing of certain data. Such cases are: the need to verify the accuracy of your personal data, the reason for the processing or the illegality of its processing.
9.4. Right to delete
In the event that the processing grounds are not complied with, you have the right to request the deletion of all data processed by us.
9.5. Data portability right
If you wish to use your personal data provided electronically for the same service but from another provider, you have the right to request the transfer to another provider in a machine-readable format. This right only applies to the information you have provided to us with your consent.
9.6. Right to object
If you do not agree with the way we process your personal data, you have the right to file an objection. This right shall apply only to data processing which is necessary for the performance of a public interest task or in the exercise of official powers conferred on the controller, and to data processing which is necessary for the purposes of the legitimate interests of the controller or to a third party, except where the interests of the data subject prevail over such interests.
9.7. Right to withdraw consent
When providing data based on your consent, you have the right at any time to request the withdrawal of consent to the processing of the specific type of personal data.
9.8. Right to complain
If you are dissatisfied with the manner in which the application submitted by you was managed with regard to any of the above rights or you believe that we are not processing your personal data lawfully, you have the right to file a complaint regarding the personal data, with the supervisory authority responsible for the implementation of Regulation (EU) 2016/679 and the Personal Data Protection Act.
If you wish to exercise any of the above rights, you can send a corresponding application regarding this matter with your exact request to the following email address: email@example.com