Mandatory Information about Personal Data Protection Rights
Information about the Company processing your data:
Information about the competent supervisory authority for personal data protection:
Shagre Ltd (hereinafter referred to as "Administrator" or "the Company") conducts its activities in accordance with the Personal Data Protection Act and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals concerning the processing of personal data and on the free movement of such data. This information is intended to inform you about all aspects of the processing of your personal data by the Company and the rights you have in connection with this processing.
Basis for collecting, processing, and storing your personal data
Article 1. The Administrator collects and processes your personal data in connection with the use of the online store www.shagre.com and the conclusion of contracts with the company based on Article 6, paragraph 1 of Regulation (EU) 2016/679 (GDPR), specifically based on the following grounds:
Purposes and principles of collecting, processing, and storing your personal data
Article 2. (1) We collect and process the personal data that you provide to us in connection with the use of the online store and the conclusion of a contract with the company, including for the following purposes:
(2) We adhere to the following principles in processing your personal data:
(3) In the processing and storage of personal data, the Administrator may process and store personal data for the purpose of protecting its legitimate interests:
Article 3. (1) The Company performs the following operations with the personal data provided by you for the following purposes:
User registration in the online store and execution of a distance sales contract: The purpose of this operation is to create a profile for using the online store to purchase goods and provide contact information for the delivery of purchased goods. Registration and the creation of a profile for using the online store are not mandatory steps for providing the service and are widely accessible without creating a profile.
Conclusion from the impact assessment: Based on the impact assessment performed, the operation of "User registration in the online store and execution of a distance sales contract" is permissible and provides sufficient guarantees for the protection of the rights and legitimate interests of data subjects in accordance with the requirements of GDPR.
Conclusion and execution of a commercial transaction with a customer or partner: The purpose of this operation is to conclude and execute a contract with a business partner or customer and administer it. Given the limited scope of the collected personal data and the fact that part of it is collected from publicly available sources, conducting an impact assessment is not necessary for the performance of the impact assessment of the operation.
Sending a newsletter (newsletter): The purpose of this operation is to administer the process of sending newsletters to customers who have expressed a desire to receive them. Given the limited scope of the collected personal data, conducting an impact assessment is not necessary for the performance of the impact assessment of the operation.
Exercise the right to refuse or file a complaint: The purpose of this operation is to administer the process of exercising the right to refuse or complain by the customer. Given the limited scope of the collected personal data, conducting an impact assessment is not necessary for the performance of the impact assessment of the operation.
(2) The Administrator processes the following categories of personal data and information for the following purposes and on the following grounds:
Your identifying data (email, name, etc.)
Delivery information (names, phone, address, etc.)
Additional data provided by you – If you want to supplement your profile, you can fill in additional data such as name, surname, phone number.
(3) The Administrator does not collect and process personal data related to the following:
(4) Personal data are collected by the Administrator from the individuals to whom they relate.
(5) The company does not perform automated decision-making with data.
Article 4. (1) The Company performs the following operations with the personal data provided by You, as legal representatives or representatives of legal entities - business partners, for the following purposes:
(2) Personal data are collected by the Administrator from the individuals to whom they relate and from the Trade Register of the Commercial Register Agency.
(3) The Company does not perform automated decision-making with data.
Article 5. The Administrator may use so-called "cookies" for the purpose of providing full functionality of the website, improving user experience, statistical purposes, facilitating access, etc., which You agree to by using our website. You can control and/or delete "cookies" at any time through the settings of your browser. "Cookies" do not constitute personal data and are not used to identify visitors and users of the online store.
Article 6. (1) The Administrator stores Your personal data for a period not longer than the existence of Your profile in the online store. After deleting your profile, the Administrator takes the necessary measures to delete and destroy all Your data without undue delay or to anonymize them (i.e., to present them in a form that does not reveal your identity).
(2) The Administrator processes Your personal data provided when placing an order without registration in the online store until the completion of the order unless you have given your explicit consent when placing the order for your data to be processed for the purpose of improving the service, providing recommended content for You, individual conditions, promotions, and for statistical purposes.
(3) The Administrator stores Your personal data provided in connection with online orders for a period of 5 years for the purposes of protecting the legal interests of the Administrator in judicial or administrative disputes with users of the online store.
(4) The Administrator informs You in case the data storage period needs to be extended for the purpose of fulfilling a regulatory obligation or for the legitimate interests of the Administrator or otherwise.
(5) The Administrator stores the personal data that it is required to keep under the applicable legislation for the respective prescribed period, which may exceed the duration of Your profile in the online store or until the completion of the order.
Article 7. The Administrator stores the personal data of the legal representatives of its business partners for the period of performance of the contract, to comply with the legitimate interests and legal obligations of the Administrator, and this period may exceed the duration of the concluded contract.
Article 8. (1) The Administrator may, at its discretion, transfer part or all of Your personal data to data processors for the purpose of processing, to which You have agreed, while complying with the requirements of Regulation (EU) 2016/679 (GDPR).
(2) The Administrator informs You in case of intention to transfer part or all of Your personal data to third countries or international organizations.
Your Rights in the Collection, Processing, and Storage of Your Personal Data
Withdrawal of Consent for the Processing of Your Personal Data
Article 9. (1) If you do not want the personal data provided by You to be processed for marketing purposes and receiving newsletters, You can withdraw Your consent for processing at any time by completing the withdrawal form in Annex No. 1 or by sending a free-text request to us by email.
(2) Once we receive Your request, we will send you an email to the address you provided for receiving newsletters and promotional messages, with detailed instructions for verifying You as the recipient of newsletters and the data subject for which withdrawal of consent has been requested.
(3) The withdrawal of consent does not affect the lawfulness of the processing of personal data that the Administrator has carried out until that moment.
Right of Access
Article 10. (1) You have the right to request and receive confirmation from the Administrator whether personal data related to You is being processed by sending a free-text request via email.
(2) You have the right to access the data related to you, as well as information about the collection, processing, and storage of Your personal data.
(3) After receiving Your request, we will send you an email to the address you used for registration or placing orders in the online store, with detailed instructions for verifying You as the data subject for which access is requested.
(4) Upon verification, in accordance with paragraph 3, the Administrator provides you, upon request, with a copy of the processed personal data related to You, in electronic or another suitable form.
(5) Access to the data is free of charge, but the Administrator reserves the right to impose an administrative fee in case of repetitiveness or excessiveness of requests.
Right to Rectification or Completion
Article 11. (1) You can at any time correct or complete inaccurate or incomplete personal data related to You through the "Profile Edit" option.
(2) You can correct or complete inaccurate or incomplete personal data related to You directly through Your profile on the website or by sending a request to the Administrator by email, using the form in Annex No. 4 or through a free-text request.
Right to Erasure ("Right to be Forgotten")
Article 12. (1) You have the right to request from the Administrator the erasure of part or all of the personal data related to You, and the Administrator is obliged to delete them without undue delay when one of the grounds listed below exists:
(2) The Administrator is not obliged to delete personal data if he/she keeps and processes them:
(3) To exercise Your right to be forgotten, You need to send an email request for the deletion of Your personal data processed by the Administrator by completing the form in Annex No. 2 or through a free-text request. The Administrator will then send an email to the address you used for registration or placing orders in the online store, with detailed instructions for verifying You as a user of the store and a data subject for which a request for deletion has been made.
(4) After verifying the identity of the person who sent the request and the person to whom the data relates in accordance with Your instructions, we will delete all data we process for You, in accordance with paragraph 3.
(5) If You have made an order that is in the process of being processed, the earliest moment You can request to be "forgotten" is upon successful completion of the order.
Right to Restriction
Article 13. You have the right to request from the Administrator the restriction of processing Your data by sending us a free-text request via email when:
(2) After receiving Your request, we will send You an email to the address you used for registration or placing orders in the online store, with detailed instructions for verifying You as a user of the store and a data subject for which a request for restriction of processing has been made.
(3) After verification according to paragraph 2, the Company will cease processing Your data, but it will not remove the publications You have made in the online store, if any.
Right to Data Portability
Article 14. (1) If You have given consent for the processing of Your personal data or the processing is necessary for the performance of a contract with the Administrator, or if Your data is processed automatically, You have the right to:
(2) You can exercise the right to data portability by sending us an email with the completed form according to Annex No. 3 or a free-text request. After that, the Administrator will send an email to the address you used for registration or placing orders in the online store, with detailed instructions for verifying You as a user of the store and a data subject for which a request for data portability has been made.
(3) After verification according to paragraph 2, the Company will send the data it processes for You to the email address provided by You in XML format.
Right to Receive Information
Article 15. You have the right to request from the Administrator information about all recipients to whom the personal data for which correction, deletion, or restriction of processing has been requested has been disclosed. The Administrator may refuse to provide this information if it would be impossible or would require disproportionate effort.
Right to Object
Article 16. You have the right to object at any time to the processing of personal data by the Administrator, which concerns you, including if they are processed for profiling or direct marketing.
Your Rights in the Event of a Personal Data Breach
Article 17. (1) If the Administrator identifies a breach of the security of Your personal data, which may pose a high risk to Your rights and freedoms, he informs You without undue delay about the breach and the measures that have been taken or are about to be taken.
(2) The Administrator is not obliged to notify You if:
Persons to Whom Your Personal Data Are Provided
Article 18. (1) For the purposes of processing Your personal data and providing the service in its full functionality and in view of Your interests, the Administrator may provide the data to the following persons who are data processors:
Processor of Personal Data Purpose of Processing
............................................... .....................................................................
............................................... .....................................................................
............................................... .....................................................................
(2) The processors of personal data comply with all requirements for legality and security in the processing and storage of Your personal data.
Article 19. The Administrator does not transfer Your data to third countries.
Article 20. In case of violation of Your rights under the above or applicable personal data protection legislation, you have the right to file a complaint with the Commission for Personal Data Protection, as follows:
Name: Commission for Personal Data Protection.
Headquarters and management address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2.
Correspondence address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2.
Phone: 02 915 3 518.
Website: www.cpdp.bg.
Article 21. You can exercise all your rights regarding the protection of Your personal data through the forms attached to this information. Of course, these forms are not mandatory, and you can submit your requests in any form that contains a statement to that effect and identifies you as the data subject.
Article 22. If the consent relates to a transfer, the Administrator describes the possible risks of transferring data to third countries in the absence of a decision on adequate protection and appropriate safeguards.
Attachment № 1
Form for Withdrawing Consent for Processing Purposes
Your Name:* .........................
Your Email Used in the Online Store:* .........................
Feedback Data (e-mail)*: .........................
To
Name: .........................
EIK/BULSTAT: .........................
Headquarters and Management Address: .........................
Correspondence Address: .........................
Phone: .........................
E-mail: .........................
Website: .........................
I hereby withdraw my consent for the processing of my personal data provided by me for the purposes of receiving a newsletter, promotional messages, or other marketing materials. I am aware of the conditions for withdrawing consent in accordance with the Mandatory Information on the Rights of Data Subjects of the online store.
In case of a violation of your rights under the above or applicable data protection legislation, you have the right to file a complaint with the Commission for Personal Data Protection, as follows:
Commission for Personal Data Protection
Headquarters and Management Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Correspondence Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Phone: 02 915 3 518
Website: www.cpdp.bg
Attachment № 2
Request for "Right to be Forgotten" - Deletion of Personal Data Associated with Me
Your Name:* .........................
Your Email, used for registration or orders in the online store:* .........................
Feedback Data (e-mail)*: .........................
To
Name: .........................
EIK/BULSTAT: .........................
Headquarters and Management Address: .........................
Correspondence Address: .........................
Phone: .........................
E-mail: .........................
Website: .........................
I request all personal data collected, processed, and stored, provided by me or by third parties related to me, according to the specified identification, to be deleted from your databases.
I declare that I am aware that some or all of my personal data may continue to be processed and stored by the administrator for the purpose of fulfilling its legal obligations.
In case of a violation of your rights under the above or applicable data protection legislation, you have the right to file a complaint with the Commission for Personal Data Protection, as follows:
Commission for Personal Data Protection
Headquarters and Management Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Correspondence Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Phone: 02 915 3 518
Website: www.cpdp.bg
Attachment № 3
Request for Data Portability
Your Name:* .........................
Your Email, used for registration or orders in the online store:* .........................
Feedback Data (e-mail)*: .........................
To
Name: .........................
EIK/BULSTAT: .........................
Headquarters and Management Address: .........................
Correspondence Address: .........................
Phone: .........................
E-mail: .........................
Website: .........................
Please send all personal data related to me, which is collected, processed, and stored in your databases, in XML format to:
E-mail: .........................
Administrator - Data Recipient: .........................
Name: .........................
Identification Number (EIK, BULSTAT, reg. number in KZLD): .........................
E-mail: .........................
In case of a violation of your rights under the above or applicable data protection legislation, you have the right to file a complaint with the Commission for Personal Data Protection, as follows:
Commission for Personal Data Protection
Headquarters and Management Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Correspondence Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Phone: 02 915 3 518
Website: www.cpdp.bg
Attachment № 4
Request for Data Correction
Your Name:* .........................
Your Email, used for registration or orders in the online store:* .........................
Feedback Data (e-mail)*: .........................
To
Name: .........................
EIK/BULSTAT: .........................
Headquarters and Management Address: .........................
Correspondence Address: .........................
Phone: .........................
E-mail: .........................
Website: .........................
Please correct the following personal data that you collect, process, and store, provided by me or by third parties related to me:
Data subject to correction:
..................................................
Please correct them as follows:
..................................................
In case of a violation of your rights under the above or applicable data protection legislation, you have the right to file a complaint with the Commission for Personal Data Protection, as follows:
Commission for Personal Data Protection
Headquarters and Management Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Correspondence Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
Phone: 02 915 3 518
Website: www.cpdp.bg
All images on the website www.shagre.com are subject to copyright and may not be used/copy/edited and/or provided to third parties without the explicit written consent of their author.