Prism Ltd. is a personal data controller within the meaning of Art. 4, para. 7 of REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR).
As a personal data controller, Prism Ltd. has the obligation to inform you about the processing of personal data that it carries out, as well as about the possibilities to exercise your rights in case of unlawful processing of personal data.
AS CLIENTS OF "PRIZMA" LTD, YOUR PERSONAL DATA IS COLLECTED AND PROCESSED FOR THE FOLLOWING PURPOSES:
- For accounting and tax purposes, based on the Accounting Act, the Tax and Social Security Procedural Code, etc.
- For marketing purposes, when participating in games and raffles, based on the consent of the data subjects.
- For the purposes of registered online applications and accounts.
- Consent for the processing of personal data is required only in the absence of another legal ground for processing data - for example, a contract, a specific provision of the law, the legitimate interest of the controller, etc.
CATEGORIES OF PERSONAL DATA THAT "PRIZMA" LTD. PROCESSES ABOUT YOU ARE AS FOLLOWS:
- For accounting and tax purposes: names, EGN (Personal Identification Number), address.
- For marketing purposes when participating in games and raffles: names, date of birth, address, contact phone number, email address.
- For the purposes of registered online applications and accounts: name, address, phone number, email address.
DATA STORAGE PERIODS ARE DETERMINED AS FOLLOWS:
- For accounting and tax purposes - in accordance with the applicable legislation.
- For marketing purposes when participating in games and raffles - until the end of the marketing campaign.
- For the purposes of registered online applications and accounts - up to 5 years after the termination of the accounts.
ONLINE PRIVACY STATEMENT
PERSONAL DATA
According to the EU General Data Protection Regulation (GDPR), personal data is defined as:
"any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person."
HOW WE USE YOUR INFORMATION
This privacy notice informs you about how we, "PRIZMA" Ltd., will collect and use your personal data for invoicing, customer complaints, cookies, Facebook pixel, pixel tags, complaints, subscriptions, and others.
WHY DOES PRIZMA LTD NEED TO COLLECT AND STORE PERSONAL DATA?
In order to provide you with a document of ownership for the purchased goods, correct service and newsletters, we need to collect personal data for the purposes of the Accounting Act, the VAT Act, and for the purposes of correspondence and detailed provision of the service. In any case, we are committed to and guarantee that the information we collect and use is appropriate for this purpose and does not constitute a violation of your personal space.
When making contact for marketing purposes, PRIZMA LTD will contact you for additional consent.
HOW DOES PRIZMA LTD USE THE PERSONAL DATA IT COLLECTS ABOUT ME?
PRIZMA LTD will process (collect, store and use) the information you provide in a way that is compatible with the EU General Data Protection Regulation (GDPR). We will endeavor to keep your information accurate and up-to-date, and not to store it for longer than necessary. PRIZMA LTD is required to keep information by law, such as information required for income tax purposes and for auditing purposes. The period for which certain types of personal data must be kept may also be regulated by specific business sector requirements and contractual practices. Personal data may be stored in addition to these periods depending on individual business needs.
CAN I FIND OUT WHAT PERSONAL DATA THE COMPANY STORES ABOUT ME?
At your request, "PRIZMA" Ltd. can inform you about what information we store about you and how we process it. If "PRIZMA" Ltd. stores personal data about you, you can request the following information:
- The data that identifies the controller and the contact details of the person or organization that has determined how and why your data is processed;
- The contact details of the data protection officer, where applicable;
- The purpose of the processing and the legal basis for the processing;
- If the processing is based on the legitimate interests pursued by "PRIZMA" Ltd. or a third party - information about these interests;
- The categories of personal data that are collected, stored and processed;
- The recipients or categories of recipients to whom the data has been or will be disclosed;
- If we intend to transfer personal data to a third country or international organization - information on how we ensure that this is done securely. The EU has approved the transfer of personal data to some countries as they meet a minimum standard of data protection. In some cases, we will ensure that specific safeguards are in place for the security of your information.
- For how long the personal data will be stored;
- Information about your rights to correct, delete, restrict or object to such processing;
- Information about your right to withdraw your consent at any time;
- How to file a complaint with the supervisory authority;
- Whether the provision of personal data is a mandatory or contractual requirement, or a requirement necessary for the conclusion of a contract, and whether you are obliged to provide the personal data and the possible consequences if such data is not provided;
- The source of the personal data, if it has not been collected directly from you;
- Any details and information about automated decision-making, such as profiling, and any relevant information about the logic of this process, as well as the significance and expected consequences of such processing.
"PRIZMA" Ltd. does not provide data about its clients to third parties, except when required by explicit provisions of law, for example for the purposes of preventing, investigating, detecting or prosecuting crimes or enforcing imposed sanctions, including protection from and prevention of threats to public security.
PRIZMA LTD. DOES NOT PROVIDE DATA ABOUT ITS CLIENTS TO A THIRD COUNTRY OR INTERNATIONAL ORGANIZATION.
As clients of PRIZMA LTD., and in your capacity as data subjects, you have the right to request from the administrator access to, correction or deletion of your personal data or to restrict the processing of personal data concerning you, or the right to object to processing, as well as to exercise the right to data portability.
In cases where your personal data is processed on the basis of your informed consent, you have the right to withdraw it at any time, bearing in mind that the withdrawal of consent takes effect for the future.
The provision of a certain amount of personal data is mandatory in cases where it is necessary for the fulfillment of legal requirements or is related to the performance of a contract.
PRIZMA LTD. does not apply automated decision-making, including profiling, with respect to the personal data of its clients.
AS DATA SUBJECTS, YOU HAVE THE RIGHT TO FILE A COMPLAINT WITH THE SUPERVISORY AUTHORITY:
Commission for Personal Data Protection
Sofia 1592, Prof. Tsvetan Lazarov Blvd. 2
Email: kzld@cpdp.bg
Web page: www.cpdp.bg