PRIVACY NOTICE by EKO MES EOOD
(notification of confidential treatment of personal data)
to customer, visitors to retail outlets and job candidates
We, EKO MES EOOD, UIC 112114123, 4413 Velichkovo village, Pazardzhik Municipality, Pamidovsko shose Str. (Our company), acting as data controller within the meaning of the General Data Protection Regulation (GDPR, (EU) 2016/679), in force as of 25 May 2018, have committed to ensuring compliance with the EU and Bulgarian legislation regarding the processing of personal data and the protection of the “rights and freedoms” of the persons whose personal data we collect and process, in view of which we provide you with a present information.
Under the General Data Protection Regulation, personal data is defined as: “any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person “.
This document applies to you, in your capacity as our customer, incl. a user of our website (a website), a visitor to our retail outlets and / or a candidate to work with us.
A. CONFIDENTIALITY of the CUSTOMERS ‘data by ECO MES EOOD
Personal data, source and purposes for which we collect and process it: By this website, we present you information about us and our activities. To provide you with additional information about our products, partners, and any information outside of our website, to respond to your requests and comments, to respond to your quality claim, in order to provide you with a reward from a game we’ve done and in general to be in communication with you, we need to collect your personal data so that we can identify you (if you wish) and respond to your needs if and as much as we can. To achieve these goals, we collect information about your names, e-mail, telephone, in the volume you provide us. For example, when contacting us through the contact form provided on the www.eco-mes.com site, you provide us with personal data according to the fields for filling in, the provision of e-mail is a prerequisite for to respond to your request and the provision of the remaining personal data is entirely at your discretion and desire. We guarantee that the information we collect and use is compatible for the stated purposes and is not intended to enter your personal area.
Grounds and processing period: Generally, we process your data on your consent, and we will store your data within one year of receipt, and then we will destroy them. In cases where you provide us with your data in connection with a purchase of our goods and / or make legal claims to us, we will process your data on the basis of a contractual relationship regarding the acquisition of the respective product, respectively on the ground of our legal obligation to respond to your request, respectively on the ground of our legitimate interest in the protection before the competent authorities, till the end of the relevant case, and thereafter the data shall be archived until the expiry of the limitation periods for seek liability by/against the data subject and / or by a public authority ( five years in general, unless otherwise required by law).
in our Cookies Terms of Service.
By agreeing to accept the terms and conditions for processing your personal information pursuant to this Privacy Notice, you authorize us to process your personal data only for the purposes stated by us above.
B. CONFIDENTIALITY of data of the VISITORS in the RETAIL OUTLETS of ECO MES EOOD, where VIDEO surveillance is performing
Personal data that we collect and process: In case you are a visitor to our retail outlet in the country, we process data for your image and behavior that provide information about the human face and features, view of your behavior, habits, committed offenses and other visible information.
Source: The above personal data is received by you personally.
We declare that the personal data we collect in video surveillance will only be used for legal purposes, such as property security, ensuring of security, safety and order at retail outlets, public health protection in food trade, and prevention of theft and other abuses .
Grounds that give us the right to process your data for image and behavior are: our legitimate interest in the implementation of the protection and the security of the retail outlets and on the ground of the public interest in ensuring public health in the food trade. In addition to this, we can also may perform lawful due assistance to competent public authorities within the frames of the powers granted to them.
Processing period: We store your video data for up to 3 days. Typically, this processing is limited to real-time monitoring of guarded area and the storage of relevant records.
C. CONFIDENTIALITY of DATA of the CANDIDATES for WORK in EKO MES EOOD
Personal data we collect and process: In case you apply to work with us, you need to provide us with your personal data, such as (personal data category, description): civil status (three names, age), education (professional knowledge and experience), data for length of working and experience, contact details (tel., e-mail), others (at your own discretion).
Source: The above personal data we receive from you, personally and directly or through internet-based job search platforms such as www.jobs.bg, www.zaplata.bg, whereof we have a contract signed. You usually provide us with your personal data through CV and / or recruitment applications.
We declare that the personal data we collect will only be used for legitimate purposes, such as: assessment whether you are eligible for a vacant position and whether you are the most suitable candidate for it. The provision of your personal data as specified in the job advertisements is a mandatory condition for participation in a selection procedure. If you do not provide us with any of the required categories of personal information, this may prevent us from analyzing your application in view of the requirements for that position, which may result in you assessment that you are not suitable for it. If you have provided us with more personal data than stated in the job advert, please note that we will not process these categories of personal data otherwise than their storage as part of the documents you submitted in the application. If you do not apply for a specific job offer, we will process your personal data you have provided to us only to the extent necessary for the purposes of the current selection procedure.
The grounds that entitle us to process your data: Your explicit consent expressed directly to us or intermediated through internet-based job search platforms. By agreeing to accept the terms and conditions for processing your personal information pursuant to this Privacy Notice, you authorize us to process your personal data only for the purposes stated by us above. If you apply for work via Internet-based platforms (such as www.jobs.bg, www.zaplata.bg, etc.), please note that the person who operates the platform (web site) is also a personal data processor, insofar as it gives us access to the appropriate job post publishing platform. If such a person carries out processing of your personal data out of our assignment (for its own purposes) out of our control that would mean that he acts as a sole personal data administrator. This would be the case, for example, if the platform allows creating user profiles that exist independently of our assignment and control. We recommend that you check for additional information on the relevant website or contact the person who operates it to find out more details and whether the person processes your personal data out of our assignment and control.
Processing period: after interviewing you or in case you do not show up on an agreed interview meeting, but no later than 3 months from receiving by us, we will destroy your personal data and your application documents.
GENERAL for all cases of processing your personal data (A, B, C) discussed above:
How we store and preserve your personal data we process:
We will process your personal data when undertaking necessary and sufficient technical and organizational measures for their protection. Among other things, we have adopted the necessary internal policies and have taken steps to protect your personal data at the design stage; data officers are well aware of the privacy requirements; the processing of your personal data is limited to the minimum necessary to achieve the relevant goals; we have implemented the necessary security measures, such as security, restricted access, security systems, etc .; we have put in place measures to ensure permanent confidentiality, integrity, availability and sustainability of processing systems and services, as well as measures in the event of a physical or technical incident for timely recovery of availability and access to personal data; an internal process for the regular testing, assessment and evaluation of the effectiveness of technical and organizational measures has been put in place in order to ensure the security of the processing; a procedure for storing and destroying data has been developed. We will process (collect, store and use) the information you provide in a manner consistent with the requirements of the General Data Protection Regulation (GDPR). We will strive to keep the information accurate and current.
We do not perform automated individual decision-making (without human intervention) in the processing of your personal data for any of the above purposes.
YOUR RIGHTS as a subject of personal data: At any time while we store or process your personal data, you, as a subject of such data, have the following rights:
• Make requests for confirmation that we process your personal data and, if so, to have access to the data as well as to receive processing information. For additional copies requested by you, a reasonable fee may be imposed for the necessary administrative costs;
• ask us for rectification your personal data when it is inaccurate and when it is not up to date, as well as filling in your personal data that is incomplete;
• require us to erase personal data (right to be forgotten) without undue delay, if and to the extent applicable to the grounds under Art. 17 of GDPR and / or the relevant national law, in cases inter alia as: personal data are no longer necessary for the purposes for which they have been collected; when you have withdrawn your consent; when you have objected to the processing; where the processing is unlawful; where personal data must be erased in order to comply with a legal obligation under EU law or the law of a Member State that applies to us as a data controller; where personal data has been gathered in connection with the provision of information society services.
• request from us the restriction of processing if and to the extent applicable to the grounds under Art. 18 of GDPR and / or the relevant national law, in cases inter alia as ascertaining the accuracy or reason for data processing; restricted data processing is usually simple to store;
• request and b being provided with personal data in a a structured, commonly used and machine-readable format, as well as request to be transferred to another administrator without obstruction on our part, if and to the extent applicable to the grounds under Art. 20 of GDPR and / or the relevant national law, in cases, inter alia, as where the processing has been based on consent f or a particular purpose or it is necessary for performance of a contract and it has been carried out in an automated manner;
• object to the processing of your personal data if and to the extent applicable to the grounds under Art. 21 of the GDPR and / or the relevant national law, including, but not limited to, processing in the performance of a public interest task or in the exercise of official authority; processing is necessary for the purposes of our or third party’s legitimate interests, including profiling of the stated grounds;
• you not to be subject to automated individual decision-making, incl. profiling that will significantly affect you without human intervention if and to the extent applicable to the grounds under Art. 22 GDPR and / or the relevant national law.
In most cases, your rights as data subjects are not absolute insofar as they are limited by the rights and freedoms of others. We may deny the exercise of a specific right, for statutory reasons, according to the law, such as, inter alia, most often the grounds for such a denial shall be: compliance with a legal obligation on our part or for the performance of a task of public interest; in the exercise of the public powers granted to us (if applicable); for the establishment, exercise or protection of legal claims. Our refusal must always be explicit, written, and justified by a specific statutory reason.
In cases where, pursuant to this Privacy Notice, we process your personal data on your consent, you may withdraw your consent at any time by express written notice addressed to us.
We provide conditions to ensure the exercise of your rights as data subjects, as in case you wish to address the processing of your personal data, exercise your right, withdraw your consent, or submit a complaint or petition, you may do so in writing via the contact form of this website or to the data controller contact details given or directly with our Data Protection Officer at firstname.lastname@example.org. We will respond to your comments, questions and requests within one month of receiving them. If necessary, this period may be extended by a further two months, taking into account the complexity and number of requests for which you will be informed within the original one month period.
Apart from the above rights, you have the absolute right to file complaints relating to the processing of your personal data, the processing of your request and your complaint, or the handling of complaints. You can bring your complaints directly to the Supervisory Authority – Personal Data Protection Commission, address: 2, Prof. Tzvetan Lazarov Str., 1592 Sofia, (www.cpdp.bg).
Sharing your personal information with other organizations or individuals: We will not sell your data to third parties, nor will we pass them on to obtain any benefit. We may provide your personal data to persons who assist us in achieving the above-described purposes – processors of personal data acting on a written contract in accordance with our explicit instructions and applying appropriate technical and organizational measures to protect your personal data. Personal data will not be shared with third parties nor shared outside the European Union or the European Economic Area. Recipients of your data may also be individuals and bodies with authority to whom we will provide them in accordance with specific and clear legal obligations. Under extraordinary circumstances, our company may provide personal information to a person acquiring our business and / or assets or respective parts thereto; to another person when required by law. When we intend to transfer your special personal data (if you have provided us) to a third party, we will do so only after we have received your consent, except that we will have to do otherwise.