Personal Data Protection Policy of GIPITIES Ltd.

  1. SUBJECT

This Privacy Policy, hereinafter referred to for brevity “Privacy Policy”, provides information on the manner in which “GIPITIES” Ltd, hereinafter referred to as for short “Supplier”, “Administrator”, “we” and/or “us”, the owner/operator of the website: https://gpts-shop.com/, hereinafter referred to as “Website”, processes (including, but not limited to, collecting and storing) personal data of data subjects, such as users of the Website and the Provider’s services, hereinafter referred to for brevity as “User(s)”, “You” and/or “you”, and on the rights of the latter in this respect.
The concept “personal data”as used in the Privacy Policy shall have the meaning given to it in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, hereinafter referred to for brevity. “General Data Protection Regulation” and/or “ORZD”namely: “any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”
Below you can find brief information about:

  • Supplier,
  • The competent supervisory authority,
  • The legal basis on which we process personal data,
  • The purposes for which we use personal data,
  • Principles of personal data processing,
  • What personal data we collect,
  • Storage period of personal data,
  • Access to and transmission of personal data, and
  • The rights and safeguards that the GDPR provides to data subjects.
  1. SUPPLIER INFORMATION
  • Name: “JIPITIES” Ltd, UIC 202273989
  •  Registered office and registered address. Registered office and registered office at Dolna Banya Str. “registered office and registered address: – 12A Marishka Street
  •  Tel: 0888 780 147, e-mail: gergana.noveva@gptsprintshop.com
  •  Entry in public registers: the Commercial Register at the Registry Agency of the Ministry of Justice of the Republic of Bulgaria.

III. INFORMATION ON THE COMPETENT SUPERVISORY AUTHORITY

  1. Name: Commission for Personal Data Protection of the Republic of Bulgaria
    2. Address. 1592 Sofia Blvd. “Proff. Tsvetan Lazarov” № 2
    3. Phone: 02 9153519
    4. E-mail: kzld@cpdp.bg
    5. Website: https://www.cpdp.bg/
  2. BASIS FOR COLLECTION, PROCESSING AND STORAGE OF PERSONAL DATA

We process (including but not limited to: collect and store) your personal data solely in connection with our business and in accordance with the requirements of applicable law, including the Personal Data Protection Act of the Republic of Bulgaria and the General Data Protection Regulation.
We process your personal data on at least one of the following grounds:

  • User’s consent to the processing of personal data;
  • The processing of personal data is necessary for the performance of contractual obligations of the Provider to the User;
  • The processing of personal data is necessary to take steps at the request of the User before entering into a contract;
  • The processing of personal data is necessary to comply with the Supplier’s legal obligations;
  • The processing of personal data is necessary for the purposes of the legitimate interests of the Provider to carry out its activities.
  1. PURPOSES FOR COLLECTING, PROCESSING AND STORING PERSONAL DATA

We collect, process and store Users’ personal data in connection with the provision of our services and communication in connection with the use of the Website, and for the following purposes:

  • Communication and identification in the performance of a service contract and a sales contract (including in the performance of a relevant contract);
  • Communication, identification, processing and fulfillment of inquiries, orders, requests, reservations, purchases of goods or services (including contract preparation, acceptance of orders, shipment of goods, resolution of issues related to cancellation of orders, reservations, return of purchased goods, refunds, etc.);
  • Compliance with tax and other legal obligations;
  • Accounting purposes in connection with the use of our services;
  • Protection of our legitimate interests in relation to the performance of our obligations to state and municipal authorities (for example: National Revenue Agency, Ministry of the Interior);
  • To protect our legitimate interests in relation to the storage of information for the purpose of defending against legal or tax claims and to improve the performance of the Website;
  • Information security protection of the website;
  • Statistical information about the use of the website;
  • Providing advertising content according to the interests of the User;
  • Leave comments on the content on the website;
  • Creating and managing an account on the Website and using the functionalities it provides;

If a data subject refuses to provide us with some or all of the personal data that is necessary for the relevant purpose set out above, we may be unable to provide the relevant service (for example, to perform a contract entered into with the relevant User) or to comply with relevant legal requirements (for example, to enable the data subject to exercise their rights under the GDPR).

  1. PRINCIPLES OF COLLECTION, PROCESSING AND STORAGE OF PERSONAL DATA

We comply with the following principles when collecting, processing and storing your personal data:

  • legality, fairness and transparency;
  • limitation of the purposes of processing;
  • limitation of the storage period in order to achieve the purposes for which the data are processed;
  • minimising the data processed;
  • data accuracy and timeliness;
  • integrity and confidentiality of data processing and ensuring an appropriate level of security of personal data.
  •  

VII. PERSONAL DATA

We collect the following categories of Users’ personal data for the following purposes and on the following grounds:

  • Your personal data (name and surname, telephone number and email address), as well as other data that you provide to us voluntarily, for the purpose of processing your enquiries, providing service offers and providing services on our part, at your request, including communication with you in this regard, and on the basis of taking steps at your request for the possible conclusion of a contract, performance of a contract to which you are a party or consent to processing provided by you;
  • Your personal data (name and surname, telephone number and email address) and information related to payment and payment methods chosen for the purpose of issuing and sending accounting/tax documents (invoices) in connection with services used by you, including communication with you in this regard, and on the basis of taking steps at your request for the possible conclusion of a contract, performance of a contract to which you are a party or performance of our legal obligation;
  • Your personal details (first and last name, telephone number and email address), information relating to delivery address (only in cases where you have indicated that you wish delivery to a specific address and not to a courier office or when collecting from a shop) and information relating to payment and payment methods chosen for the purposes of payment for orders placed, bookings made and/or goods or services purchased, including the issue and dispatch of accounting/tax documents (invoices) in relation to account registration, orders placed, bookings made, goods purchased
  • Your personal data (name and surname, telephone number and email address) and information related to the refund of amounts paid for orders, reservations, purchased goods or services, in the event of cancellation of orders, reservations, return of products, and on the basis of the performance of a contract to which you are a party and/or compliance with legal obligations;
  • Your personal data (first and last name and email address) and information related to leaving comments to the content on the website, if you wish;
  • Your IP address, browser settings and language preferences, pages visited, and actions taken for the purpose of sending push notifications if you have opted in to receive them;
  • Your IP address, the pages visited, for information security purposes;
  • Other data that may be necessary in certain cases or related to the provision of services to Users by us, including necessary for the performance of contractual obligations (e.g. date of birth, signature, SSN) or other data that Users choose to voluntarily share with us, and based on the performance of a contract to which you are a party, consent to processing provided by you or compliance with a legal obligation by us.
      •  

We use cookies on the Website, which are small files that are downloaded to your computer to improve your experience as a user of the Website. You can find more information in this regard on our dedicated cookie policy page here.
We do not process, respectively collect from Users, special categories of personal data (for example: data revealing racial or ethnic origin, political opinions, genetic or biometric data, as well as data on the sex life and sexual orientation of the data subject).
We do not make decisions based solely on automated data processing, including profiling.
We usually receive the personal data directly from the data subject. However, it is not excluded that we may receive personal data from other persons such as: other employees in the company where the data subject works, as well as from publicly available sources such as the Commercial Register and the Register of Non-Profit Legal Entities at the Registry Agency of the Ministry of Justice of the Republic of Bulgaria.

VIII. STORAGE PERIOD OF PERSONAL DATA

We keep Users’ personal data for no longer than is necessary to fulfil the relevant processing purpose or the statutory period, where applicable. For example:

  • personal data of our customers processed in connection with contracts concluded between us and the respective User will be stored for a period of no longer than ten years, starting from the 1st of January of the year following the year in which the contract was recorded for tax purposes;
  • personal data provided by you when completing the contact form will be stored until the request is fulfilled or the enquiry you have contacted us about is satisfied, and for a maximum of one year thereafter for statistics and marketing analysis;
  • personal data of our customers processed in connection with the issuance of tax documents (invoices) will be stored for a period of no longer than ten years from January 1st of the year following the year in which the document was recorded for tax purposes;
  • personal data of our partners/suppliers processed in connection with contracts concluded between us and the respective partner/supplier will be stored for a period of no longer than ten years from the 1st of January of the year following the year in which the contract was recorded for tax purposes;
  • the personal data of participants in recruitment and selection procedures will be kept for a period not exceeding six months from the time of the final conclusion of the recruitment/selection procedure in which the data subject concerned participates, respectively after the expiry of the appeal period of the procedure, unless the data subject concerned has consented to the storage of his/her personal data for a longer period, in which case the data subject shall have the right to withdraw his/her consent at any time and without giving reasons.
      •  

The retention period depends, among other things, on the duration of the legal relationship between us and the User concerned and on the purposes for which the personal data are processed. Where there is an indication(s) of potential legal claim(s) or liability, these time limits will be extended accordingly. Where the processing is based on the User’s consent (for example: in the case of personal data provided by third parties for direct marketing), we store this personal data as long as we have valid consent to process it.
After the expiry of the above time limits, we shall take the necessary care to delete and/or destroy your personal data without undue delay.

  1. ACCESS TO PERSONAL DATA AND TRANSFER OF PERSONAL DATA TO THIRD PARTIES

In general, the personal data of Users that we process is accessible to our employees, agents and partners who need it to comply with legal obligations and/or to fulfil contractual obligations (for example: providing a service under a contract with a User). In this regard, we may, at our discretion and subject to the requirements of the GDPR, transfer all or part of your personal data to third parties such as accountants, professional advisers including lawyers (for the purposes of financial, accounting and administrative services for our business), cloud platforms for data processing/storage (for the purposes of organizational services for our business, for example: storing and processing contracts with Cloud Platform Users for greater security), companies providing postal
Based on applicable law or at the request of public authorities, all or part of your personal data may also be accessible to public authorities.
We do not intend to transfer your personal data to countries outside the European Economic Community or to international organisations.

  1. RIGHTS OF DATA SUBJECTS

At any time while we are processing your personal data, and subject to the limitations set out in applicable law, you, the data subject, have the following rights:

  • Right of access – youhave the right to request information about whether we are processing your personal data and to access and obtain a copy of such personal data; in the event that you request more than one copy of such personal data, you may be liable to pay an appropriate fee for each additional copy;
  • Right to rectification/correction – youhave the right to request that your personal data be corrected if you believe it is inaccurate or incomplete. We will make such corrections/adjustments without undue delay;
  • Right to erasure/to be forgotten– in certain circumstances (for example: the personal data concerned is no longer necessary for the purposes for which it was collected; you have withdrawn your consent to the processing of certain of your personal data for which there is no other legal basis), you may request that your personal data that we process be deleted from our records/our database without undue delay. In certain cases We may refuse to erase such personal data (for example: the processing of personal data is necessary to comply with a specific legal obligation or to establish, exercise or defend legal claims);
  • Right to restriction of processing –where certain conditions apply (for example: the processing of certain of your personal data is unlawful, but you do not want this data to be erased), you have the right to request a restriction of the way in which your personal data is processed;
  • Right to portability– where your personal data is provided to us by you and is processed in an automated manner, you have the right to request that this personal data be transmitted to you in a structured, commonly used and machine-readable format, as well as to have it transferred to another personal data controller if this is technically feasible;
  • Right to object– you have the right, at any time, to object to the processing of your personal data for certain purposes, in which case we will stop using your personal data for that specific purpose unless we have overriding legitimate grounds for doing so (for example: you have the right, at any time, to object to the processing of your personal data for direct marketing purposes, in which case we will stop processing your personal data for those purposes without undue delay);
  • Right to object to automated processing, including profiling – youhave the right not to be subject to a decision that is based solely on automated processing of your personal data, including profiling, and you also have all the rights that accrue to you in the event that you are subject to the legal consequences of such processing;
  • Right to withdraw your consent to processing –if we process your personal data on the basis of consent, you have the right to withdraw your consent at any time. Withdrawal will not affect the lawfulness of processing based on consent prior to its withdrawal.
      •  

In the event that, at the request of a User, we delete his/her personal data from our database, we will keep only the information that may be necessary for the protection of our legitimate interests or for public authorities.
You have the right to request that we inform you of all recipients to whom the personal data for which rectification, erasure or restriction of processing has been requested has been disclosed. We may refuse to provide this information if it would be impossible or would require a disproportionate effort.
In the event that we are required to transfer personal data to another controller, to correct or erase personal data, to restrict the processing of personal data or to cease such processing, to provide information regarding the recipients to whom the personal data for which correction, erasure or restriction of processing has been requested has been provided, or to provide access to personal data, and in the event of concerns regarding the identity of the User making the relevant request, we may first request additional information in order to further
In the event that there is a third party in the processing of your personal data to whom all or part of your personal data has been transferred (as set out in Part IX above), all of the above requests will be forwarded to that third party.
The exercise of the above rights shall be free of charge for Users, except where the requests made are manifestly unfounded or excessive. In such a case, we may either impose a reasonable fee to comply with the request or refuse to act on the request.
Users may exercise the above rights by contacting us by email at: gergana.noveva@gptsprintshop.com

  1. COMPLAINT TO A SUPERVISORY AUTHORITY

In the event that you believe that your personal data is not being processed lawfully or that any of your rights relating to the protection of personal data have been violated, you have the right to lodge a complaint with the competent data protection supervisory authority referred to in Part III above of the Privacy Policy. You also have the right to seek redress in court.
In the event that the Website contains links to other websites, we recommend that you carefully read the privacy/privacy policies of those other websites because when you visit those websites, your personal data may be processed by those websites, which processing is not covered by the Privacy Policy.
We reserve the right to change the Privacy Policy as we see fit and as we see fit.