when using the website www.ipinthespotlight.bg
Attorney Teodora Stefanova Lalova, a member of the Sofia Bar Association, with attorney personal number 1100722010, registered on 20.12.2017 in the bar registry, is the founder of the law firm IP in the Spotlight, specializing in the field of intellectual property, hereinafter referred to as the “Controller” and/or “the Firm.”
The website www.ipinthespotlight.bg (“the Website”) is owned and administered by the Controller with due respect for the rights of data subjects in the electronic environment, as well as in strict compliance with the regulatory framework in the field of personal data protection.
The Firm is a controller of personal data within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“the General Data Protection Regulation” or GDPR) and the Personal Data Protection Act (PDPA), as it independently determines the purposes and means of processing personal data provided electronically by visitors to the Website.
Art. 1. (1) This Policy aims to inform visitors to the Website about the rules for processing their personal data collected through its use. (2) Every user should familiarise themselves with the contents of the Policy, and the Controller undertakes to immediately update its internal rules upon any amendment thereof.
Art. 2. The current version of the Policy contains information regarding:
Art. 3. For the purposes of this Policy, the terms listed below have the following definitions:
“personal data” means any information relating to an identified natural person or a natural person who can be identified (“data subject”); a natural person who can be identified is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, psychological, economic, cultural or social identity of that natural person;
“processing” means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
“user” means any natural person who accesses the Website;
“profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, and in particular to analyse or predict aspects concerning that natural person’s performance of professional duties, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
“recipient” means a natural or legal person, public authority, agency or other body to whom personal data are disclosed, whether or not a third party;
“third party” means a natural or legal person, public authority, agency or body other than the data subject, the Controller, the processor and the persons who, under the direct authority of the Controller or the processor, are authorised to process personal data;
“personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
“malicious attack” means any action that disrupts the normal functioning of the Website — including sending unsolicited messages (SPAM, JUNK MAIL), performing actions that may be classified as computer or other crimes within the meaning of the Penal Code, deliberate infection with viruses, disruption of the normal operation of other users of the Website, and similar acts;
“supervisory authority” means an independent public authority responsible for monitoring the application of the relevant provisions in order to protect the fundamental rights and freedoms of natural persons with regard to the processing of their personal data. For the territory of the Republic of Bulgaria, the supervisory authority within the meaning of Article 51 of the General Data Protection Regulation is the Commission for Personal Data Protection, with address: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd.
Art. 4. In carrying out its activities as a controller of personal data, the team of the law firm IP in the Spotlight processes personal data in accordance with the following principles:
Art. 5. (1) Adhering to the principle of lawfulness of processing and the principle of purpose limitation, the Firm processes personal data provided by data subjects when using the Website only if and to the extent that at least one of the following legal bases and one of the stated purposes are present:
(2) The Controller urges all parents and persons with parental responsibility to monitor children’s safety online and to raise them with a spirit of caution and responsibility regarding all their actions on the internet. The Firm assumes that the personal data it processes have been collected directly from the individuals to whom they relate.
Art. 6. In administering the Website, IP in the Spotlight does not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data processed solely for the purpose of identifying a natural person, data concerning health, or data concerning the sex life or sexual orientation of a natural person.
Art. 7. (1) The Controller processes the following categories of personal data provided by data subjects when using the Website:
(2) The Controller does not use the personal data received for the purpose of profiling data subjects within the meaning of Art. 3, item 4 of this Policy.
Art. 8. The Controller stores personal data in a form that permits the identification of natural persons for a period no longer than is necessary for the fulfilment of the purposes for which the personal data were collected, unless a different, expressly defined period is provided for by a legislative act or by the Controller’s internal personal data protection rules (5 years).
Art. 9. (1) The personal data processed by the law firm IP in the Spotlight are disclosed to a limited number of employees — persons within the meaning of Article 29 of the GDPR, who act under the authority of the Controller, and to data processors with whom the Controller has concluded data processing agreements in accordance with the requirements of the GDPR (e.g. an accountant when processing invoices).
(2) The Controller takes all necessary measures to ensure that your data will be processed in compliance with all legal requirements and that the data processor has implemented the necessary technical and organisational measures for the protection of the data.
(3) Where documentation containing personal data is requested by state authorities in accordance with applicable legislation (e.g. the National Revenue Agency, the Consumer Protection Commission, courts, etc.), the Controller may be subject to a legal obligation to disclose personal data to the relevant state authority.
(4) Personal data are not disclosed to recipients in third countries and/or international organisations.
(5) The Website may contain links to other websites that do not apply the same personal data protection rules. When leaving the Controller’s website, please seek out and review the privacy policies of each website that collects personal data. The Firm bears no responsibility for the manner in which the administrators of those websites process data.
Art. 10. In fulfilment of the requirements of Article 13 of the GDPR, the Controller provides the data subject with all of the information listed below (right to information):
Art. 11. The data subject has the right to obtain from the Controller confirmation as to whether personal data relating to them are being processed, and if so, to obtain access to the data and the following information (right of access):
Art. 12. The data subject has the right to request the Controller to rectify without undue delay inaccurate personal data relating to them (right to rectification).
Art. 13. The data subject has the right to request the Controller to erase personal data relating to them without undue delay where one of the following grounds applies (right to erasure or the “right to be forgotten”):
Art. 14. (1) The data subject has the right to request the Controller to restrict processing where one of the following applies (right to restriction of processing):
(2) Where processing has been restricted pursuant to the preceding paragraph, such data shall be processed, with the exception of storage, only with the consent of the data subject or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural person, or for reasons of important public interest of the European Union or a Member State.
Art. 15. The data subject has the right to receive the personal data concerning them, which they have provided to the Controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another controller without hindrance from the Controller (right to data portability), where:
Art. 16. (1) The data subject has the right, at any time and on grounds relating to their particular situation, to object to the processing of personal data concerning them which is based on the performance of a task carried out in the public interest or the legitimate interests of the Controller or of a third party, including profiling on the same grounds (right to object).
(2) In the cases referred to in paragraph 1, the Controller shall cease processing the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.
(3) Where personal data are processed for direct marketing purposes, the data subject has the right to object at any time to the processing of personal data concerning them for such marketing, which includes profiling to the extent that it is related to such direct marketing.
(4) In the cases referred to in paragraph 3, where the data subject objects to processing for direct marketing purposes, the processing of personal data for those purposes shall cease.
Art. 17. The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them (right not to be subject to automated individual decision-making, including profiling).
Art. 18. The Controller assists the data subject by taking the necessary measures to provide information and carry out communication under the preceding section with the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language.
Art. 19. (1) Data subjects exercise their rights under the preceding section by sending an electronic communication (via the contact details provided on the Website) to the Controller.
(2) Where the data subject has submitted a request using the Website, i.e. by electronic means, the Controller shall provide the information by electronic means, unless the data subject has requested otherwise.
Art. 20. (1) The Controller shall provide the data subject with information on the actions taken in response to a request to exercise the rights under the preceding section without undue delay and in any event within 1 (one) month of receipt of the request.
(2) Where necessary, the period referred to in paragraph 1 may be extended by a further 2 (two) months, taking into account the complexity and number of requests. The Controller shall inform the data subject of any such extension within 1 (one) month of receipt of the request, stating the reasons for the delay as well.
Art. 21. If the Controller does not take action on the data subject’s request to exercise a right under the preceding section, the Controller shall notify the data subject without delay and no later than 1 (one) month from receipt of the request, of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority and seeking judicial remedy.
Art. 22. (1) The provision of information and the conduct of correspondence with the data subject under the preceding section shall be provided free of charge.
(2) Where the requests of a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the Controller may either:
Art. 23. The Controller shall implement appropriate technical and organisational measures to ensure and be able to demonstrate that the processing is carried out in accordance with applicable legislation.
Art. 24. (1) The Controller shall use only processors that provide sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of applicable legislation.
(2) Processing by a processor shall always be governed by a contract or other applicable legal instrument, which sets out the subject matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the Controller.
Art. 25. (1) In the event of a personal data breach, whether or not it has occurred as a result of a malicious attack, the Controller shall notify the supervisory authority of the breach no later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
(2) Where notification to the supervisory authority has not been made within the 72-hour period, the notification must include the reasons for the delay.
Art. 26. The Controller shall document any personal data breach, including the facts relating to the breach, its consequences, and the measures taken to mitigate its adverse effects.
Art. 27. Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Controller shall communicate the breach to the data subject without undue delay, unless:
The law firm IP in the Spotlight applies this Personal Data Protection Policy by monitoring changes in the applicable legislation in the field of personal data protection and promptly adapting all of its internal rules and procedures in accordance with legal requirements, in fulfilment of the principle of fairness under Article 5(1)(a) of the GDPR. For any questions regarding the processing of personal data, please use the contact form on the Website or the phone numbers/email addresses provided. If you have any doubts as to the lawfulness of the processing, you may contact the supervisory authority of the Republic of Bulgaria — the Commission for Personal Data Protection, with address: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd., www.cpdp.bg.
The content of the website www.ipinthespotlight.bg is protected by law and copying, use, reproduction, and other such actions with respect to texts, photographic images, and other copyright-protected works accessible on the site are not permitted without the consent of the authors.
За да осигурим най-добрите преживявания, ние използваме технологии като „бисквитки“, за да съхраняваме и/или осъществяваме достъп до информация за устройството. Съгласието с тези технологии ще ни позволи да обработваме данни, като например поведение при сърфиране или уникални идентификатори на този сайт. Несъгласието или оттеглянето на съгласие може да повлияе неблагоприятно на определени функции.