“AAT 3” Ltd. respects the privacy of everyone who visits our website, sends us e-mail or is our customer, partner or team member. Therefore, we strictly adhere to the applicable legislation regarding the processing of personal data. This policy describes how and why “AAT 3” OOD uses your personal information, how we protect your privacy, as well as your rights and possible choices regarding this information. This policy constitutes the entire agreement between you and “AAT 3” OOD regarding the publicly accessible parts of our website. By using our website, you agree to be bound by this Privacy Policy.
This policy is effective as of May 25, 2018.
WHO WE ARE
In this Privacy Policy, “AAT OOD”, “we” or “us” means,
“AAT 3” Ltd., registered in the Commercial Register with EIC 131212593, with registered office and management address in Bulgaria, Sofia, Tsarigradsko Shose Blvd. No. 53, bl. 2, apartment 4, represented by Irina Serafimova – manager.
WHAT PERSONAL DATA WE COLLECT
The type and amount of information we collect and how we use it depends on why you provide it.
When you contact us by phone, mail, in person or online, we may collect information about you (referred to in this Privacy Policy as “personal information”). It may include your name, ID card / passport number, social security number, address, email address, telephone number, date of birth, job title, bank account details and other personal information that you may choose to provide to us.
Sensitive data
Under data protection legislation, certain types of personal information are more sensitive. These are the so-called “sensitive” or “special categories” personal data that includes information revealing racial or ethnic origin, religious or philosophical beliefs and political views, trade union membership, genetic or biometric data, health information or data about the sex life or sexual orientation of a given person. Sensitive information will only be collected as necessary, for example, we may need to collect your health information from you when we provide HR and Human Resources related services. In the event that we collect and process such information, we will provide you with clear notices stating what information is needed and why.
HOW WE COLLECT INFORMATION ABOUT YOU
We collect information in the following ways:
- When you provide it to us directly
- When you give permission to other organizations to share it with us or it is publicly available
- When we collect it when you use our website
“Cookies”
Like most websites, we use cookies to help us make our site – and the way you use it – better. “Cookies” are small text files that are downloaded and stored on your device when you visit a website. “Cookies” are widely used by website owners to provide you with a good internet experience and also to provide information that can help them improve the websites.
Our website uses cookies for the following purpose:
- To make our website work
- Collect anonymous data about how our users use our site to help us improve it
- To allow you to share the content on social networks
- To help us deliver relevant advertising to those who may be interested in it.
We do not use cookies to:
- To collect personally identifiable information
- To provide personal information to third parties.
Most internet browsers automatically accept cookies unless you change your browser settings. If you want to limit, block or delete cookies set by websites, you can usually do this through your browser settings. These settings are usually found in the “options” or “preferences” menu of your Internet browser. Please note that if you set your internet browser preferences to block all cookies, you may not be able to access all or parts of our website. Unless you have adjusted your internet browser settings to block cookies, our site will use cookies.
HOW WE USE YOUR INFORMATION
We will use your personal information for the following purpose:
- To provide you with the services or information you have requested;
- Upon initial registration of a company – to indicate owner(s) and manager(s) and to administer additional changes to this data;
- To administer your contractual relationship with us;
- To send you correspondence and communicate with you;
- To administer our website and troubleshoot, analyze data, research, generate statistics and research related to our technical systems;
- To prepare reports about our work and services;
- To fulfill our legal obligations, for example to fulfill a contract between us or obligations to regulatory authorities and/or law enforcement authorities;
- To carry out checks to prevent fraud or money laundering;
- To file, maintain or enforce legal claims;
We will not do anything with your information that is beyond the scope of your legitimate expectations.
LEGAL BASIS FOR PROCESSING
According to the legislation in the field of personal data protection, the use of personal information must have a “legal basis”. The legal grounds are specified in the General Regulation for the Protection of Personal Data (Regulation 2016/679) and the relevant national legislation for the protection of personal data.
Specific consent
Consent is when we ask you if we can use your information for a specific purpose and you agree to it.
Legal obligation
We have a legal basis to use your information where the processing is necessary to comply with a legal or regulatory obligation.
Contract performance
We have reason to use your personal information when we are in the process of entering into a contract with you or performing a contractual obligation.
Legitimate interests
We are entitled to use your personal information where it is reasonably necessary for us (or a third party) to do so in our (or a third party’s) “legitimate interest” (provided the purpose for which the information is used is fair and does not unreasonably affect your rights). We believe that our legitimate interests include all day-to-day activities that “AAT 3” Ltd. carries out with personal information. We are based on legitimate interests only when we consider that any potential impact on you (positive and negative), its degree of impact in terms of privacy and your rights under data protection laws do not outweigh our (third party) interest in us using your information in this way.
Where we use sensitive personal information, we require an additional legal basis under data protection legislation, so we will do so based on your express consent or any other means available to us by law for using this type of information (for example if you have made it clearly public, if we need to process it for employment, social security or social protection purposes, for your vital interests or, in some cases, if it is in the public interest to do so).
HOW WE KEEP YOUR INFORMATION SECURE
We implement technical and organizational measures to ensure that your personal information is protected. Our network is secure and routinely monitored. We take appropriate measures to ensure that our team members are aware that such information is only used in accordance with this Privacy Policy. We regularly review who has access to the information we hold to ensure that your information is only accessible to appropriately trained staff and contractors.
HOW LONG WE KEEP YOUR INFORMATION
“AAT 3” OOD applies specific criteria to determine how long to store your information, determined on the basis of legal and operational considerations, taking into account the guidelines of the Commission for the Protection of Personal Data. The principle is that we store it for a period not longer than necessary for the purposes for which it was collected.
SHARING OF YOUR INFORMATION WITH OTHER ORGANIZATIONS
We will use your information only for the purposes for which we collected it. Under no circumstances will we sell or share your personal information with any third party for their purposes and you will not receive marketing communications from any other organization as a result of sharing your data with us.
We will share your data only for the following purposes:
- Third party providers and subcontractors who may process personal data on our behalf: We may need to share your information with hosting and other service providers that help us provide our services. These suppliers will only act on our instructions, will be subject to prior verification and will undertake contractual obligations containing strict clauses regarding the protection of personal data. We strive to ensure that these third parties will only use personal data for lawful purposes in accordance with this Privacy Policy.
- When required by law: We will comply with such requests where disclosure is required by law. In addition, we will ensure the sharing of such information by signing, where possible, special agreements with the relevant organization or by conducting a case-by-case review that aims to establish that the request and disclosure of the information is lawful.
In accordance with national legislation and regulatory requirements, we share information related to employment contracts with the National Revenue Agency. Personal data contained in company registration documents are shared with the Commercial Register at the Registration Agency. To open corporate bank accounts, personal data is shared with a bank of the individual(s)’ choice.
When we use external companies to process personal data on our behalf, we carry out a thorough pre-screening of those companies and enter into a contract that contains our requirements regarding how they manage the personal data they collect or access.
In some cases, we may decide to use the services of a provider outside the European Economic Area (EEA), which means that your personal information is transferred, processed and stored outside the EEA. You should be aware that, in general, the legal protection of personal information in countries outside the EEA may not be equivalent to the level of protection provided in the EEA. However, we take steps to put in place appropriate safeguards to protect your personal information when it is processed by the provider, such as using standard contractual clauses approved by the European Commission. By providing us with your personal data, you consent to this transfer, storage or processing to a location outside the EEA.
YOUR RIGHTS
The legislation in the field of personal data protection gives you the right to request access to the personal information that “AAT 3” OOD has for you, as well as to request the correction of possible inaccuracies.
If we collect and process your personal information based on your consent, you have the right to withdraw your consent at any time. The withdrawal of your consent does not affect the lawfulness of the processing based on a given consent before its withdrawal, nor the processing of your personal information on another legal basis.
You have the right to request deletion of personal data relating to you, restriction of processing or to object to processing of your personal data.
If you wish to exercise any of your rights, please complete a special form (available on request) and send it along with copies of two different forms of ID that provide photo identification and confirm your address, such as passport, driver’s license, etc. In addition, please provide additional information about the nature of your relationship with us, as this will help us to locate your personal data. You can send the documents to us by mail to the address: Bulgaria, Sofia, 53 Tsarigradsko Shose Blvd., bl. 2, apartment 4, Irina Serafimova. We will respond to you within 30 days of receiving your written request and copies of identification documents.
COMPLAINTS
If you would like more information or have questions related to this Privacy Policy, as well as to make a formal complaint regarding our approach to the protection of personal data or would like to ask a question about privacy, you can contact us at: Bulgaria , Sofia, Tsarigradsko Shose Blvd. 53, bl. 2, apartment 4.
You also have the right to file a complaint regarding the processing of your personal data before the Commission for the Protection of Personal Data (www.cpdp.bg) – the Bulgarian supervisory authority for compliance with the legislation on personal data protection.
CHANGES TO THIS POLICY
We reserve the right, at our sole discretion, to change, amend, supplement or remove portions of this Privacy Policy at any time. Any such change that materially affects your rights to your personal data will be effective 30 days after notice of such change is posted on this website, during which time you may notify us that you do not accept that change. Continued use of this website after the 30-day period will be conclusively deemed acceptance of the changes to this Privacy Policy. You further agree that such notice posted on this website constitutes reasonable and sufficient notice. At all times, you are bound by the relevant current version of the Privacy Policy and applicable law.
(Last updated: May 25, 2018)
CONTACT US
If you have questions, comments or suggestions, you can inform us about them at the address: Bulgaria, Sofia, Tsarigradsko Shose Blvd. 53, bl. 2, apartment 4, Irina Serafimova.
Date: May 25, 2018
I affirm:
Irina Serafimova
Manager