top of page
fst

PRIVACY POLICY

On the website and online store " FST 2020 EOOD " (www.fst.bg) personal data of visitors and registered users are processed for the purposes of the sale and delivery of the products offered by fst.bg for the ancillary activities related to them, as and for the purposes of online advertising related to the products offered.

This information is intended to inform you about all aspects of the processing of your personal data by the Administrator and the rights you have in relation to this processing.

 

INFORMATION REGARDING THE “ADMINISTRATOR” OF PERSONAL DATA - THE COMPANY THAT PROCESSES YOUR DATA:

 

Name: " FST 2020 " LTD
UIC: 206095352
Headquarters and management address: Pazardzhik, 11 Ivaylo Street, contact phone: + 359 894767479;
Correspondence address: Pazardzhik, 11 Ivaylo St., phone number: + 359 894767479; Email: fstbar@gmail.com;
Website: https://www. fst.bg/

 

INFORMATION REGARDING THE COMPETENT SUPERVISORY AUTHORITY FOR THE PROTECTION OF PERSONAL DATA:

Name: "Commission for personal data protection"
Headquarters and management address: Sofia 1592, "Prof. Tsvetan Lazarov" No. 2
Address for correspondence: Sofia 1592, "Prof. Tsvetan Lazarov" No. 2
Phone: 02 915 3 518
Email: kzld@government.bg, kzld@cpdp.bg
Website: https://www.cpdp.bg/

 

TYPES OF PERSONAL DATA WE PROCESS AND BASIS FOR PROCESSING THEM

I. WE CONTRACTUALLY PROCESS THE FOLLOWING CATEGORIES OF DATA:

  1. Data for your profile in "fst.bg " online store , which is created for you after entering into an informal contract with the Administrator, accepting the General Terms and Conditions for using the " fst.bg " website and online store :

    • Personal name and surname

    • Email

    • Contact details: Phone

    • Company ( if any)

    • Address (city, address, district, postal code, country)

    • Password

  2. Data for an online order through the " fst.bg " online store, made by you, concluding an informal contract at a distance with the Administrator in application of the General Terms and Conditions:

    • First and last name of the person for delivery;

    • Delivery address - country, city, region, postal code, address;

    • Delivery phone number;

    • Invoice data - names, phone, city, country, postal code, address;

    • Way of delivery;

    • Order number;

    • Payment amount;

    • Payment status;

    • Delivery status;

II. WE PROCESS THE FOLLOWING DATA BASED ON YOUR CONSENT EXPRESSED THROUGH A PURPOSEFUL ACTION – INDEPENDENT ENTERING OPTIONAL DATA AND/OR FREELY CHOOSING SPECIFIC OPTIONS:

  1. Data for your account in the " fst.bg " online store:

    • Personal name and surname;

    • Email;

    • Contact phone number

    • Company (if any)

    • Address (city, address, district, postal code, country)

    • Password;

  2. Contact data and sent message or comment, provided when filling out a contact form of the " fst.bg " online store, when sending an email to us, conventional mail, calling by phone, sending an SMS, posting a comment on the site, using of online chat, as well as other forms of communication and/or expression:

    • Personal name, surname or pseudonym (fictitious name);

    • E-mail address;

    • Phone number;

    • Address;

    • Content of the comment / message;

Different forms of contact require different data from those listed above.

  1. Data for online ordering through the fst.bg online store :

    • Delivery address - country, city, postal code, address;

    • Delivery phone number;

    • Invoice data - names, phone, city, country, postal code, address;

    • Way of delivery;

    • Method of payment;

    • Order number;

    • Payment amount;

    • Payment status and history;

    • Delivery status and history;

    • Order history;

You may withdraw any of the consents provided above through your account settings or according to the form and manner prescribed in this Policy. Upon withdrawal of consent, the processing of the relevant type of personal data for the specified purposes is suspended. Withdrawal of consent does not affect the lawfulness of processing based on consent given prior to its withdrawal.

III. WE PROCESS THE FOLLOWING DATA ON A LEGAL BASIS ACCORDING TO LOCAL AND FEDERAL LAW:

  1. Information about your account in " fst.bg ":

    • Personal name and / or surname

    • Email

    • Contact phone number

    • Company (if any)

    • Address (city, address, district, postal code, country)

    • Password

  2. Data for online ordering through the " fst.bg " online store:

    • Delivery address - country, city, postal code, address;

    • Delivery phone number;

    • Invoice data - names, phone, city, country, postal code, address;

    • Way of delivery;

    • Method of payment;

    • Order number;

    • Payment amount;

    • Payment status and history;

    • Delivery status and history;

    • Order history;

IV. WE PROCESS THE FOLLOWING DATA ON THE BASIS OF LEGITIMATE INTEREST:

  1. Data about your account in the online store " fst.bg ":

    • Personal name and surname;

    • Email;

    • Contact phone number

    • Company

    • Address (town, address, district, postal code, country)

    • Password;

  2. Data for online ordering through the " fst.bg " e-store:

    • Delivery address - country, city, postal code, address;

    • Delivery phone number;

    • Invoice data - names, phone, city, country, postal code, address;

    • Way of delivery;

    • Method of payment;

    • Order number;

    • Payment amount;

    • Payment status and history;

    • Delivery status and history;

    • Order history;

PURPOSES OF PERSONAL DATA PROCESSING

  1. Your profile data in the " fst.bg " e-store is processed for the purposes of:

    • Fulfillment of the Administrator's accountability obligation by recording legally significant authentication data in electronic protocols - technical logs;

    • Delivery of ordered products;

    • Providing support in case of technical malfunctions, informing customers in relation to their orders or in relation to complaints, tracking deliveries, payments and others;

    • Verification by sending an email to ensure the security of access to your account data and when changing your password;

    • Authentication when logging into your account;

    • Sending messages via email and/or push notifications for direct marketing and advertising purposes with your express consent;

    • Compliance with the provisions of laws, court decisions, legal orders and decisions of authorities and supervisory bodies. This includes using your personal data to collect and verify accounting data and comply with accounting reporting rules;

  2. The data for an online order through the " fst.bg " e-shop are processed for the purposes of:

    • Delivery of ordered products;

    • Providing support in case of technical malfunctions, informing customers about their orders or complaints, tracking deliveries, payments and others;

    • Preventing and investigating abuses in online ordering and related deliveries, as well as losses and fraud;

    • Compliance with the provisions of laws, court decisions, legal orders and decisions of authorities and supervisory bodies. This includes using your personal data to collect and verify accounting data and comply with accounting reporting rules;

    • Analysis of statistical data obtained after anonymization of your data;

  3. Contact data and sent inquiry, message or published comment are processed for the purposes of:

    • Your identification as the sender/author of a message or posted comment;

    • Communicating with you;

THIRD PARTIES WITH ACCESS TO PERSONAL DATA IN CONNECTION WITH THEIR ACTIVITIES AND SERVICES PROVIDED JOINTLY WITH FST.BG

  1. We use the following hosting providers, cloud services and servers:

    • "Wix.com LTD, with VAT ID : EU442008451 - provide hosting for reserved connectivity.

  2. We use the services of the following Suppliers and Courier companies

    • Courier company Speedy for delivery of products ordered by you to an office or address. You can familiarize yourself with Speedy's privacy policy at the following address: https://www.speedy.bg/bg/gdpr

 

  1. State bodies and institutions in connection with inspections carried out by them in accordance with legal requirements and restrictions;

    With respect to private entities, we require and monitor said third parties to implement all technical and organizational measures to protect this data.

DATA STORAGE PERIOD:

The duration of storage of personal data is determined by the relevant retention period (e.g. commercial and tax periods). After the expiration of this period, the relevant data will be deleted, provided that they are no longer necessary for the performance or discovery of the contract and / or there are no longer any legitimate interests on our part for further storage.

  1. Data provided on a contractual basis:

    • Account data - until the expiry of 5 years from the date of the last online order or, in the absence of an order - until the deletion of the account through the functionalities of the online store or until the expiry of 5 years from the date of your last login, whichever is sooner . The profile data is also linked to the data defining the online orders, which determines the application of the deadlines set in relation to them. In the absence of an order based on the informal contract, you as a user have a legal expectation to use the profile. If you wish to delete your account before the deadline, we provide you with the functionality to do so at any time.

    • Data for online orders - until the expiration of 5 years from the date of the specific order. The term is determined based on the statute of limitations for repayment of receivables.

  2. Data related to collection and verification of accounting data and compliance with accounting reporting - accounting registers and financial statements, including documents for tax control, audit and subsequent financial inspections are stored for 10 years, starting from January 1 of the reporting period following the reporting period, for which relate; all other carriers of accounting information - three years, starting from January 1 of the accounting period following the accounting period to which they refer;

  3. Data provided on the basis of consent - until its withdrawal, in the way it was provided, including through the functionalities of the online store or by deletion, and in relation to the online store - and until the expiration of 5 years from the date of your last login or last order, whichever is earlier;

    Regarding your data, related to comments you have published on the site (expressed opinions or comments on articles or products), which therefore constitute an exercise of your constitutional right to free expression in the format and content of your choice, no deadline is set, after the expiration of which their processing is suspended, and instead you are given the opportunity to remove the published content by exercising your rights as a data subject in accordance with the form and manner prescribed in this Policy. When the content of a particular comment contains offensive words or phrases, defamatory, slanderous and/or damage to the good name of the Administrator or third parties, the Administrator has the right, based on his or third parties' legitimate interests, to remove the content of the comment from his sites.

    After the expiration of the specified period, the data is deleted and cannot be recovered and used any more. The data is not deleted, but continues to be processed only for the purposes of protecting our legal rights and legitimate interests or in fulfillment of our legal obligations, in the event that there are pending judicial, administrative and pre-trial proceedings at the date of expiry of the specified period or during an ongoing investigation regarding abuses, complaints and potential violations that have been received or brought to our attention - until their completion.

YOUR RIGHTS REGARDING YOUR PERSONAL DATA

  1. Right of access:

    1. You have the right to request and receive confirmation from the Administrator as to whether personal data related to you is being processed, and you can at any time see in your profile, if you are a registered user, the data we are processing for you.

    2. You have the right to access the data relating to you, as well as the information relating to the collection, processing and storage of your personal data.
      You can contact us and based on a written request and verification of your identity, the data will be provided to you;

    3. Providing access to the data is free of charge, but the Administrator reserves the right to impose an administrative fee in case of repetitive or excessive requests.

  2. Right to rectification of inaccurate personal data

  • You have the right to request correction of your personal data if it is incorrect, including completion of incomplete personal data. You can do this through your profile or by contacting us with a written request, after proper authentication of your identity;

  1. Right to erasure ("Right to be forgotten") in the following cases:

  • You have the right to request the deletion of part or all of your personal data, and the Administrator has the obligation to delete them without undue delay, when any of the following grounds are present:

    • the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;

    • You withdraw your consent on which the data processing is based and there is no other legal basis for the processing;

    • You object to the processing of your personal data, including for direct marketing purposes, and there are no overriding legal grounds for the processing;

    • the personal data were processed unlawfully;

    • the personal data must be deleted in order to comply with a legal obligation under EU law or the law of a Member State that applies to the Administrator;

    • personal data were collected in connection with the provision of information society services.

  • The administrator is not obliged to delete the personal data if it stores and processes them:

    • to exercise the right to freedom of expression and the right to information;

    • to comply with a legal obligation that requires processing provided for in EU or Member State law applicable to the Administrator or for the performance of a task in the public interest or in the exercise of official powers conferred on him;

    • for reasons of public interest in the field of public health;

    • for the purposes of archiving in the public interest, for scientific or historical research or for statistical purposes;

    • for the establishment, exercise or defense of legal claims.

  • In the event of exercising your right to be forgotten, the Company will delete all your data, except for the following information:

    • information that is necessary to verify that your right to be forgotten has been met - email, IP address;

    • technical information about the functioning of the online store, which information cannot be linked in any way to your person;

  • To exercise your right to be forgotten, you need to take the following steps:

    • submit a request by email , which requires identifying yourself as the account holder;

  • If there is an order placed by you that is being processed, the earliest you can request to be "forgotten" is upon successful completion of the order.

  • By deleting your personal data, your account will become inactive. Of course, you will be able to browse the online store and the products offered and place orders as a guest or make a new registration.

  • The administrator does not delete the data that he has a legal obligation to store, including for defense in connection with legal claims made against him or to prove his rights.

  1. Right to limit processing when:
    - the veracity of the data is disputed, for the period in which their veracity must be verified; or - the processing of the data is without a legal basis, but instead of deleting them, you want their limited processing; or - if necessary, the data for the establishment, exercise or defense of your legal claims; or - an objection has been filed to the processing of the data, pending verification of whether the administrator's grounds are legal

  • In case of exercising your right to restriction, the Company will stop processing your data, but will not remove the posts you have made on the site.

In the event of correction, erasure or restriction of processing, we will notify each recipient to whom the personal data has been disclosed, unless this is impossible or requires a disproportionate effort.

  1. Right to portability of machine-readable data pursuant to which:

  • we provide the data directly to you; or

  • upon your request and technical possibility, the data is provided to another administrator of your choice;

You can at any time download or receive in machine-readable format the data that is stored and processed for you in connection with the use of the Administrator's services by expressing your desire in writing to the specified email address.

Right to receive information

You can ask the Administrator to inform you about all recipients to whom the personal data for which correction, deletion or restriction of processing has been requested has been disclosed. The administrator may refuse to provide this information if it would be impossible or would require a disproportionate effort.

  1. Right to object:

  • You may object at any time to the Administrator's processing of personal data relating to you, including if it is processed for the purposes of profiling or direct marketing.

  • The administrator will not continue to process your personal data unless it is proven that there are compelling legal grounds for doing so that take precedence over your interests and rights or due to legal disputes and other procedural and non-procedural actions it is necessary.

  • You have the right to object to receiving marketing communications, including profiling and analysis for direct marketing purposes. You can opt out of receiving marketing communications by sending a written message to the email address of the company FST 2020 EOOD.

  1. Right of appeal to a supervisory authority

In the event of a breach of your rights under applicable data protection legislation, you have the right to lodge a complaint with the Commission for Personal Data Protection as follows:

Name: "Commission for personal data protection"
Headquarters and management address: Sofia 1592, "Prof. Tsvetan Lazarov" No. 2
Address for correspondence: Sofia 1592, "Prof. Tsvetan Lazarov" No. 2
Phone: 02 915 3 518
Website: www.cpdp.bg

  1. Your rights in the event of a breach of the security of your personal data

  • If the Administrator detects a violation of the security of your personal data, which may create a high risk for your rights and freedoms, he notifies you without undue delay about the violation, as well as about the measures that have been taken or are about to be taken.

  • The administrator is not obliged to notify you if:

    • has taken appropriate technical and organizational measures to protect the data affected by the security breach;

    • has subsequently taken measures to ensure that the breach will not result in a high risk to your rights;

    • notification would require a disproportionate effort;

You can exercise all your rights regarding the protection of your personal data through the functionalities in your profile. You can make your requests in any form that contains a statement to that effect and identifies you as the data owner.

METHODS USED FOR AUTOMATED INDIVIDUAL DECISION MAKING, INCLUDING PROFILING

We do not use automated algorithms and/or profiling.

USE OF "COOKIES"

FST.BG website and online store uses the so-called "cookies" (cookies) to provide the most relevant information for you and ensure your best experience. They help you get a personalized experience while on our site and using our services. At the same time, they help us provide you with content that is relevant to you.

Regarding the data contained in the "cookies" of the FST.BG online store and third parties, you can find information from our Policy on the use of "cookies".

 

SECURITY MEASURES TAKEN BY THE ADMINISTRATOR AND FST.BG ONLINE STORE REGARDING THE SECURITY OF PERSONAL DATA

Measures taken by the Administrator
In order to protect the personal data of users and customers of the fst.bg website and online store , we use an encryption protocol - Secure Sockets Layer (SSL security certificate). When you access the fst.bg website through its HTTPS (Hypertext Transfer Protocol Secure) web browser application, an encrypted connection is provided between the web server (site) and the browser you are using.
 

bottom of page