{"id":20092,"date":"2025-04-25T09:37:21","date_gmt":"2025-04-25T06:37:21","guid":{"rendered":"https:\/\/digital4bulgaria.com\/?p=20092"},"modified":"2025-04-25T09:37:21","modified_gmt":"2025-04-25T06:37:21","slug":"privacy-and-data-security-policy-for-individuals","status":"publish","type":"post","link":"https:\/\/digital4bulgaria.com\/en\/blog\/privacy-and-data-security-policy-for-individuals\/","title":{"rendered":"Privacy and Data Security Policy for Individuals"},"content":{"rendered":"

This document contains the Personal Data Security Policy for individuals (\u201cPolicy\u201d) and is related to the General Terms and Conditions, but is not an integral part of them, as it does not regulate rights and obligations. Instead, its purpose is to explain to users what personal data we process, how we process it, for what purpose, and what security measures apply. Additionally, it provides information about the rights that you, our clients and users, have in relation to the processing of personal data by “IMG CONNECT” Ltd., UIC 207379619, VAT No. BG 207379619, with its headquarters and address at: Varna, 4 Bragalnitsa Street. In case of any changes to this Policy, the changes will be published here.<\/p>\n

Date of last update: January 10, 2024.<\/strong><\/p>\n

Your privacy is extremely important to us. This security policy outlines the personal data we collect from you through our interactions and how we use that data.<\/p>\n


\n

DATA CONTROLLER<\/strong><\/h2>\n

“IMG CONNECT” Ltd., UIC 207379619, VAT No. BG 207379619, with its headquarters and address at: Varna, 4 Bragalnitsa Street, contact phone +359 886 991 001; email: events@internetmediagroup.org<\/a> (hereinafter referred to as “We”, “online store”, “Site”, “Website”, “administrator”, IMG CONNECT) is the data controller for the information, including personal data, collected or provided when browsing the website www.digital4bulgaria.com<\/a> or making a purchase through it, as well as when browsing or purchasing a service through our Facebook page (hereinafter all collectively referred to as “Site”, “Internet Page”). The Policy also applies in cases where, as individuals (hereinafter “Data Subjects”), you voluntarily provide us with personal data via electronic means (such as email), by phone, or through other methods, including in person at our commercial facility or office. IMG CONNECT processes personal data from inquiries made by you, as well as for marketing and advertising purposes, profiling, participation in games, promotions, and raffles organized by us, and for any other purposes not prohibited by law. In processing personal data, IMG CONNECT adheres to all applicable laws related to data protection, including but not limited to Regulation (EU) 2016\/679 (“Regulation”) and the Personal Data Protection Act, because the security of our clients’ personal data is of paramount importance to us. Therefore, this Policy also applies in these cases.<\/p>\n


\n

DATA PROTECTION RESPONSIBLE PERSON<\/strong><\/h2>\n

The responsible person for data protection is Preslav Bobev.<\/p>\n

Correspondence address: Varna, 4 Bragalnitsa Street<\/p>\n

Email address: events@internetmediagroup.org<\/a><\/p>\n

Contact phone: +359 886 991 001<\/p>\n

APPLICABILITY OF THE POLICY<\/strong><\/h2>\n

This Policy applies to all our clients \u2013 individuals who use our services through orders placed on the Website or show interest in them by sending inquiries (hereinafter referred to as “data subjects” or “users”).<\/p>\n

Partners and third parties who work with or for IMG CONNECT, as well as those who have or may have access to personal data, will be expected to familiarize themselves with, understand, and comply with this policy. No third party can access personal data stored by IMG CONNECT without the company having first entered into a data confidentiality agreement, which imposes obligations on the third party that are no less burdensome than those assumed by IMG CONNECT, and which allows IMG CONNECT to conduct compliance checks on the obligations set out in the agreement.<\/p>\n

This policy applies to all employees\/workers (and stakeholders) of IMG CONNECT, as well as external suppliers of products and services with whom IMG CONNECT has contracts. Any violation of the General Data Protection Regulation (GDPR) will be considered a breach of labor discipline, or non-performance of contracts with partners, and if there is any suspicion of a criminal act, the matter will be referred for consideration to the relevant state authorities as soon as possible.<\/p>\n

For visitors to the Website who do not place orders or send inquiries, but only browse our internet page, the Cookie Policy published on the Website applies.<\/p>\n


\n

DEFINITIONS<\/strong><\/h2>\n

“Regulation”<\/strong> \u2013 The General Data Protection Regulation (GDPR) 2016\/679 from April 27, 2016. The aim of this European legislative act is to protect the “rights and freedoms” of individuals and ensure that personal data is not processed without their knowledge, and where possible, is processed with their consent.<\/p>\n

“Personal data”<\/strong> \u2013 Any information relating to an identified or identifiable individual (“data subject”); an identifiable individual is one who can be identified directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that individual.<\/p>\n

“Special categories of personal data”<\/strong> \u2013 Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or membership in trade unions, and the processing of genetic data, biometric data for the unique identification of an individual, data related to health or data regarding the sexual life or sexual orientation of an individual.<\/p>\n

“Processing”<\/strong> \u2013 Any operation or set of operations performed on personal data or sets of personal data, whether by automated means or otherwise, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making data available, alignment or combination, restriction, erasure, or destruction.<\/p>\n

“Data controller”<\/strong> \u2013 Any natural or legal person, public authority, agency, or other body that alone or jointly with others determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by EU law or the law of a member state, the data controller or the specific criteria for its designation may be provided for in EU or member state law.<\/p>\n

“Data subject”<\/strong> \u2013 Any living individual whose personal data is processed by the data controller.<\/p>\n

“Data subject’s consent”<\/strong> \u2013 Any freely given, specific, informed, and unambiguous indication of the data subject’s wishes, by which they, through a statement or clear affirmative action, consent to the processing of their personal data.<\/p>\n

“Child”<\/strong> \u2013 The General Regulation defines a child as any person under the age of 16. Processing of personal data of a child is lawful only if the child\u2019s parent or guardian has given consent. The data controller makes reasonable efforts to verify that the holder of parental responsibility for the child has given or is authorized to give consent.<\/p>\n

“Profiling”<\/strong> \u2013 Any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects related to a natural person, and specifically to analyze or predict aspects concerning the performance of the individual\u2019s professional duties, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.<\/p>\n

“Personal data breach”<\/strong> \u2013 A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.<\/p>\n

“Recipient”<\/strong> \u2013 A natural or legal person, public authority, agency, or another body to whom personal data is disclosed, whether a third party or not. Public authorities who may receive personal data in the course of a specific inquiry in accordance with EU law or the law of a member state are not considered “recipients”; processing of such data by those public authorities is subject to applicable data protection rules in accordance with the purposes of the processing.<\/p>\n

“Third party”<\/strong> \u2013 Any natural or legal person, public authority, agency, or body other than the data subject, the data controller, the data processor, and persons who, under the direct authority of the data controller or the data processor, are authorized to process personal data.<\/p>\n

PRINCIPLES<\/strong><\/h2>\n

When collecting and processing personal data, we are guided by the following principles: lawfulness, fairness, transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; accountability.<\/p>\n


\n

DATA SUBJECTS WHOSE DATA WE PROCESS<\/strong><\/h2>\n

In connection with its activities, “IMG CONNECT” Ltd. enters into and executes distance contracts, reviews job applications and offers, user rights exercise forms, as well as data subject requests, responds to inquiries, issues and receives invoices, processes statistical data, manages a user panel on the website, and conducts advertising activities through campaigns (promotions, games, etc.). In the course of these activities, IMG CONNECT processes information related to the following data subjects:<\/p>\n