Privacy and cookie policy

I. GENERAL PROVISIONS

Art. 1
(1) “TEODOR” Ltd. (hereinafter referred to as the “Company”) is registered in the Commercial Register with the Bulgarian Registry Agency under UIC 114515613, with its seat and registered office: Republic of Bulgaria, Sofia, Vitosha District, 31 Bulgarska Legia St., fl. 4, apt. 18.
(2) The Company is a data controller and processes personal data in connection with its activities, independently determining the purposes and means of processing.
(3) Data Protection Officer: Veneslav Hristov, email: [email protected].

Art. 2
This Privacy and Cookie Policy ("the Policy") provides information about the personal data processed by the Company and outlines the conditions and procedures for exercising the rights of individuals whose personal data are processed.

Art. 3
For the purposes of this Policy:

  1. "Personal data" means any information relating to an identified or identifiable natural person (“data subject”).

  2. "Processing" means any operation or set of operations performed on personal data, whether automated or not (e.g., collection, recording, organization, storage, consultation, use, disclosure, erasure).

  3. "Restriction of processing" means marking stored personal data to limit future processing.

  4. "Pseudonymization" means processing personal data in a way that they can no longer be attributed to a specific data subject without additional information.

  5. "Personal data register" means any structured set of personal data accessible according to specific criteria.

  6. "Controller" means a natural or legal person who determines the purposes and means of processing personal data.

  7. "Processor" means a natural or legal person who processes personal data on behalf of the controller.

  8. "Recipient" means any entity to whom personal data is disclosed, whether a third party or not.

  9. "Third party" means anyone other than the data subject, controller, processor, or persons authorized to process data under the direct authority of the controller or processor.

  10. "Consent of the data subject" means any freely given, specific, informed, and unambiguous indication of the data subject's wishes.

  11. "Personal data breach" means a security breach leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure or access.

  12. "Supervisory authority" means an independent public authority established by a member state under Article 51 of the GDPR.

Art. 4
The principles relating to the processing of personal data are:

  1. Lawfulness, fairness, and transparency – data must be collected lawfully and fairly.

  2. Purpose limitation and data minimization – data must only be used for specified purposes and kept no longer than necessary.

  3. Accuracy – data must be accurate and kept up to date.

  4. Integrity and confidentiality – data must be processed securely to prevent unauthorized or unlawful access, loss, or damage.

Art. 5
The personal data of customers (natural persons) of the Company’s online store www.teodor.bg are processed in the “Contractors” register, specifically in the sub-register “Consumers under the CPA”.

Loading...