Privacy policy

PERSONAL DATA PROTECTION POLICY

when using the website www.ipinthespotlight.bg

PREAMBLE

Attorney Teodora Stefanova Lalova, a member of the Sofia Bar Association, with attorney personal number 1100722010, registered on 20.12.2017 in the bar registry, is the founder of the law firm IP in the Spotlight, specializing in the field of intellectual property, hereinafter referred to as the “Controller” and/or “the Firm.”

The website www.ipinthespotlight.bg (“the Website”) is owned and administered by the Controller with due respect for the rights of data subjects in the electronic environment, as well as in strict compliance with the regulatory framework in the field of personal data protection.

The Firm is a controller of personal data within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“the General Data Protection Regulation” or GDPR) and the Personal Data Protection Act (PDPA), as it independently determines the purposes and means of processing personal data provided electronically by visitors to the Website.

PURPOSES AND SCOPE OF THE POLICY

Art. 1. (1) This Policy aims to inform visitors to the Website about the rules for processing their personal data collected through its use. (2) Every user should familiarise themselves with the contents of the Policy, and the Controller undertakes to immediately update its internal rules upon any amendment thereof.

Art. 2. The current version of the Policy contains information regarding:

  • the terminology used in the General Data Protection Regulation and the Personal Data Protection Act;
  • the principles related to the processing of personal data to which the Controller adheres;
  • the applicable legal bases for processing personal data pursuant to Article 6 of the General Data Protection Regulation;
  • the categories of personal data subject to processing;
  • the applicable retention periods for the processing of personal data by the Controller;
  • the categories of recipients to whom personal data are disclosed;
  • the rights of data subjects and the procedure for exercising them;
  • general obligations of the Controller;
  • obligations of the Controller in the event of a personal data security breach.

DEFINITIONS

Art. 3. For the purposes of this Policy, the terms listed below have the following definitions:

“personal data” means any information relating to an identified natural person or a natural person who can be identified (“data subject”); a natural person who can be identified is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, psychological, economic, cultural or social identity of that natural person;

“processing” means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

“user” means any natural person who accesses the Website;

“profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, and in particular to analyse or predict aspects concerning that natural person’s performance of professional duties, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;

“recipient” means a natural or legal person, public authority, agency or other body to whom personal data are disclosed, whether or not a third party;

“third party” means a natural or legal person, public authority, agency or body other than the data subject, the Controller, the processor and the persons who, under the direct authority of the Controller or the processor, are authorised to process personal data;

“personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;

“malicious attack” means any action that disrupts the normal functioning of the Website — including sending unsolicited messages (SPAM, JUNK MAIL), performing actions that may be classified as computer or other crimes within the meaning of the Penal Code, deliberate infection with viruses, disruption of the normal operation of other users of the Website, and similar acts;

“supervisory authority” means an independent public authority responsible for monitoring the application of the relevant provisions in order to protect the fundamental rights and freedoms of natural persons with regard to the processing of their personal data. For the territory of the Republic of Bulgaria, the supervisory authority within the meaning of Article 51 of the General Data Protection Regulation is the Commission for Personal Data Protection, with address: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd.

PRINCIPLES APPLIED IN THE PROCESSING OF PERSONAL DATA

Art. 4. In carrying out its activities as a controller of personal data, the team of the law firm IP in the Spotlight processes personal data in accordance with the following principles:

  • principle of lawfulness, fairness and transparency — personal data are processed by the Controller lawfully, fairly and in a transparent manner in relation to the data subject;
  • principle of purpose limitation — personal data are collected by the Controller for specified, explicit and legitimate purposes and are not processed in a manner incompatible with those purposes;
  • principle of data minimisation — personal data are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
  • principle of accuracy — personal data are accurate and kept up to date by the Controller, with all reasonable steps taken to ensure that inaccurate personal data are erased or rectified without delay, having regard to the purposes for which they are processed;
  • principle of storage limitation — personal data are stored by the Controller in a form that permits identification of the data subject for no longer than is necessary for the purposes for which the personal data are processed;
  • principle of integrity and confidentiality — personal data are processed by the Controller in a manner that ensures an appropriate level of security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, applying appropriate technical or organisational measures;
  • principle of accountability — the Controller is able to demonstrate compliance with the preceding principles.

LAWFULNESS OF THE PROCESSING OF PERSONAL DATA

Art. 5. (1) Adhering to the principle of lawfulness of processing and the principle of purpose limitation, the Firm processes personal data provided by data subjects when using the Website only if and to the extent that at least one of the following legal bases and one of the stated purposes are present:

  • processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract (for the purpose of identifying the contracting party);
  • processing is necessary for the purposes of the legitimate interests pursued by the Controller (providing information about the services offered by the Firm), except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data;
  • processing is carried out following the provision of explicit, informed, specific, unambiguous and freely given consent — for the purposes of direct marketing (when subscribing to our Newsletter).

(2) The Controller urges all parents and persons with parental responsibility to monitor children’s safety online and to raise them with a spirit of caution and responsibility regarding all their actions on the internet. The Firm assumes that the personal data it processes have been collected directly from the individuals to whom they relate.

Art. 6. In administering the Website, IP in the Spotlight does not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data processed solely for the purpose of identifying a natural person, data concerning health, or data concerning the sex life or sexual orientation of a natural person.

CATEGORIES OF PERSONAL DATA SUBJECT TO PROCESSING

Art. 7. (1) The Controller processes the following categories of personal data provided by data subjects when using the Website:

  • mandatory contact details — full name, email address, phone number;
  • optional data — voluntarily provided by the data subject when using the contact details listed on the website;
  • the IP address of the device from which the data subject accessed the Website.

(2) The Controller does not use the personal data received for the purpose of profiling data subjects within the meaning of Art. 3, item 4 of this Policy.

RETENTION PERIODS FOR THE PROCESSING AND STORAGE OF PERSONAL DATA

Art. 8. The Controller stores personal data in a form that permits the identification of natural persons for a period no longer than is necessary for the fulfilment of the purposes for which the personal data were collected, unless a different, expressly defined period is provided for by a legislative act or by the Controller’s internal personal data protection rules (5 years).

CATEGORIES OF RECIPIENTS OF PERSONAL DATA

Art. 9. (1) The personal data processed by the law firm IP in the Spotlight are disclosed to a limited number of employees — persons within the meaning of Article 29 of the GDPR, who act under the authority of the Controller, and to data processors with whom the Controller has concluded data processing agreements in accordance with the requirements of the GDPR (e.g. an accountant when processing invoices).

(2) The Controller takes all necessary measures to ensure that your data will be processed in compliance with all legal requirements and that the data processor has implemented the necessary technical and organisational measures for the protection of the data.

(3) Where documentation containing personal data is requested by state authorities in accordance with applicable legislation (e.g. the National Revenue Agency, the Consumer Protection Commission, courts, etc.), the Controller may be subject to a legal obligation to disclose personal data to the relevant state authority.

(4) Personal data are not disclosed to recipients in third countries and/or international organisations.

(5) The Website may contain links to other websites that do not apply the same personal data protection rules. When leaving the Controller’s website, please seek out and review the privacy policies of each website that collects personal data. The Firm bears no responsibility for the manner in which the administrators of those websites process data.

RIGHTS OF DATA SUBJECTS

Art. 10. In fulfilment of the requirements of Article 13 of the GDPR, the Controller provides the data subject with all of the information listed below (right to information):

  • the data identifying the Controller and the contact details for reaching them;
  • the purposes of the processing for which the personal data are intended, as well as the legal basis for the processing;
  • where processing is carried out on the basis of legitimate interests pursued by the Controller or by a third party, those interests must be stated;
  • the recipients or categories of recipients of the personal data, if any;
  • the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period;
  • the existence of the right to request from the Controller access to, rectification, erasure or restriction of processing of personal data relating to the data subject, or the right to object to the processing, as well as the right to data portability;
  • where processing is based on consent, the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
  • the right to lodge a complaint with a supervisory authority;
  • whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary for the conclusion of a contract, as well as whether the data subject is obliged to provide the personal data and the possible consequences of failing to provide such data;
  • the existence of automated decision-making, including profiling, and at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

Art. 11. The data subject has the right to obtain from the Controller confirmation as to whether personal data relating to them are being processed, and if so, to obtain access to the data and the following information (right of access):

  • the purposes of the processing;
  • the categories of personal data concerned;
  • the recipients or categories of recipients to whom the personal data have been or will be disclosed;
  • where possible, the envisaged period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period;
  • the existence of the right to request from the Controller rectification or erasure of personal data, or restriction of processing of personal data relating to the data subject, or to object to such processing;
  • the right to lodge a complaint with a supervisory authority;
  • the existence of automated decision-making, including profiling, and at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject;
  • the appropriate safeguards relating to the transfer of personal data to a third country or international organisation, where applicable.

Art. 12. The data subject has the right to request the Controller to rectify without undue delay inaccurate personal data relating to them (right to rectification).

Art. 13. The data subject has the right to request the Controller to erase personal data relating to them without undue delay where one of the following grounds applies (right to erasure or the “right to be forgotten”):

  • the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
  • the data subject withdraws their consent on which the processing is based, and there is no other legal basis for the processing;
  • the data subject objects to the processing and there are no overriding legitimate grounds for the processing;
  • the personal data have been unlawfully processed;
  • the personal data must be erased for compliance with a legal obligation under European Union or Bulgarian law;
  • the personal data have been collected in connection with the offer of information society services referred to in Article 8(1) of the General Data Protection Regulation.

Art. 14. (1) The data subject has the right to request the Controller to restrict processing where one of the following applies (right to restriction of processing):

  • the accuracy of the personal data is contested by the data subject, for a period enabling the Controller to verify the accuracy of the personal data;
  • the processing is unlawful, but the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
  • the Controller no longer needs the personal data for the purposes of the processing, but the data subject requires them for the establishment, exercise or defence of legal claims;
  • the data subject has objected to the processing pending verification of whether the legitimate grounds of the Controller override those of the data subject.

(2) Where processing has been restricted pursuant to the preceding paragraph, such data shall be processed, with the exception of storage, only with the consent of the data subject or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural person, or for reasons of important public interest of the European Union or a Member State.

Art. 15. The data subject has the right to receive the personal data concerning them, which they have provided to the Controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another controller without hindrance from the Controller (right to data portability), where:

  • the processing is based on consent or a contractual obligation; and
  • the processing is carried out by automated means.

Art. 16. (1) The data subject has the right, at any time and on grounds relating to their particular situation, to object to the processing of personal data concerning them which is based on the performance of a task carried out in the public interest or the legitimate interests of the Controller or of a third party, including profiling on the same grounds (right to object).

(2) In the cases referred to in paragraph 1, the Controller shall cease processing the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.

(3) Where personal data are processed for direct marketing purposes, the data subject has the right to object at any time to the processing of personal data concerning them for such marketing, which includes profiling to the extent that it is related to such direct marketing.

(4) In the cases referred to in paragraph 3, where the data subject objects to processing for direct marketing purposes, the processing of personal data for those purposes shall cease.

Art. 17. The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them (right not to be subject to automated individual decision-making, including profiling).

EXERCISE OF RIGHTS BY DATA SUBJECTS

Art. 18. The Controller assists the data subject by taking the necessary measures to provide information and carry out communication under the preceding section with the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language.

Art. 19. (1) Data subjects exercise their rights under the preceding section by sending an electronic communication (via the contact details provided on the Website) to the Controller.

(2) Where the data subject has submitted a request using the Website, i.e. by electronic means, the Controller shall provide the information by electronic means, unless the data subject has requested otherwise.

Art. 20. (1) The Controller shall provide the data subject with information on the actions taken in response to a request to exercise the rights under the preceding section without undue delay and in any event within 1 (one) month of receipt of the request.

(2) Where necessary, the period referred to in paragraph 1 may be extended by a further 2 (two) months, taking into account the complexity and number of requests. The Controller shall inform the data subject of any such extension within 1 (one) month of receipt of the request, stating the reasons for the delay as well.

Art. 21. If the Controller does not take action on the data subject’s request to exercise a right under the preceding section, the Controller shall notify the data subject without delay and no later than 1 (one) month from receipt of the request, of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority and seeking judicial remedy.

Art. 22. (1) The provision of information and the conduct of correspondence with the data subject under the preceding section shall be provided free of charge.

(2) Where the requests of a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the Controller may either:

  • impose a reasonable fee, taking into account the administrative costs of providing the information/communication/taking the requested action, or
  • refuse to act on the request.

GENERAL OBLIGATIONS OF THE FIRM

Art. 23. The Controller shall implement appropriate technical and organisational measures to ensure and be able to demonstrate that the processing is carried out in accordance with applicable legislation.

Art. 24. (1) The Controller shall use only processors that provide sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of applicable legislation.

(2) Processing by a processor shall always be governed by a contract or other applicable legal instrument, which sets out the subject matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the Controller.

OBLIGATIONS IN THE EVENT OF A PERSONAL DATA SECURITY BREACH

Art. 25. (1) In the event of a personal data breach, whether or not it has occurred as a result of a malicious attack, the Controller shall notify the supervisory authority of the breach no later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.

(2) Where notification to the supervisory authority has not been made within the 72-hour period, the notification must include the reasons for the delay.

Art. 26. The Controller shall document any personal data breach, including the facts relating to the breach, its consequences, and the measures taken to mitigate its adverse effects.

Art. 27. Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Controller shall communicate the breach to the data subject without undue delay, unless:

  • the Controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the breach;
  • the Controller has subsequently taken measures which ensure that the high risk to the rights and freedoms of data subjects is no longer likely to materialise;
  • communication would involve disproportionate effort — in which case the Controller shall make a public communication or take a similar measure, so that data subjects are informed in an equally effective manner.

The law firm IP in the Spotlight applies this Personal Data Protection Policy by monitoring changes in the applicable legislation in the field of personal data protection and promptly adapting all of its internal rules and procedures in accordance with legal requirements, in fulfilment of the principle of fairness under Article 5(1)(a) of the GDPR. For any questions regarding the processing of personal data, please use the contact form on the Website or the phone numbers/email addresses provided. If you have any doubts as to the lawfulness of the processing, you may contact the supervisory authority of the Republic of Bulgaria — the Commission for Personal Data Protection, with address: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd., www.cpdp.bg.

The content of the website www.ipinthespotlight.bg is protected by law and copying, use, reproduction, and other such actions with respect to texts, photographic images, and other copyright-protected works accessible on the site are not permitted without the consent of the authors.

error: Content is protected !!