CONFIDENTIALITY AND PERSONAL DATA PROTECTION POLICY
Of Memento Enterprise
Effective from 25.05.2018
II. Who processes and takes responsibility for your personal data?
Мanagement address: Sofia city, Dimitar Dimov Str No 11, 4rd floor
Phone number: +359884641416
III. Categories of personal data processed by Memento Enterprise Ltd.
1. Memento Enterprise Ltd. may process publicly available personal data and / or personal data provided by you. The main types of personal data processed are:
(i) Personal identification information (including name, email address, language of communication, etc.);
(ii) Contact details (including postal and e-mail addresses, telephone and fax numbers to you or a contact person you specify, etc.);
(iii) Financial information (bank account and other);
(iv) Information about a representative (legal representative or proxy of one) of our client legal entity;
(v) Data from the profile on the site (including name, postal and e-mail addresses, phone number, date of birth, etc.);
(vi) Data on the conclusion of sales, dealership, wholesale, delayed payment, etc. with individuals or legal entities (such as names, PIN, etc.).
2. Memento Enterprise Ltd. may process data prepared and generated by Memento Enterprise Ltd. in the process of providing the services:
(i) data about the terminal electronic communication device used, the type of device, operating system used, IP address, location;
(ii) data about your preferred goods and services
(iii) Data of communication between us and you, your habits, preferences, your satisfaction with our services (service activity, complaints, requests, etc.);
(iv) Information on site visits and use of the Site, including operations and usage history of the Site;
(v) The data obtained in the execution of the obligations ensuing from the normative acts (i.e. data resulting from inquiries, regulations, investigative authorities, notary, tax offices, court, judge's contractor).
3. In order to ensure the proper performance of the services and the obligations arising from client contracts, Memento Enterprise Ltd. has the right to process any information that is available in public registers (including public database and data disclosed on the Internet) as well as information obtained from third parties regarding the implementation of legal provisions regarding customers.
4. Memento Enterprise Ltd. has the right and the duty to verify the correctness of the personal data stored in the database and for this purpose requires you to verify the data and, if necessary, correct or validate your data.
5. Different types of personal data can be processed on their own or in combination.
IV. Objectives and legal bases for the processing of personal data
1. Processing of personal data that is necessary for the conclusion or performance of contracts with us or in conjunction with the preparation for concluding contracts with us.
Memento Enterprise Ltd. processes your data for the following purposes:
(i) Customer identification upon: signing a new or changing an existing contract with us; clarifications of the services used; execution of contract.
(ii) Preparation of proposals for contracts, sending pre-contractual information and draft contract; management of pre-sales activities;
(iii) Data obtained from you in performance of obligations arising from contracts with you or a company represented by you, use of rights and ensuring the execution of contracts by our clients;
(iv) Administration and responding to customer complaints / inquiries; return of goods and refunds; product replacement;
(v) Technical assistance for creating an account(s) and recovering a forgotten password to access our Site for electronic service of electronic invoices.
(vi) Identification and validation of legal age for online shopping;
(vii) Payment of obligations, rescheduling of amounts; management of receivables collection;
(viii) Warranty and service;
(ix) Updating of offers to dealers; sharing important information about changes to our policy and other administrative information;
(x) Managing and administration of online shopping activities; payment management.
2. In fulfillment of its legal obligations, Memento Enterprise Ltd. processes your data for the following purposes:
(i) Invoices issuing;
(ii) To perform tax - insurance control by the respective competent authorities;
(iii) Execution of obligations in relation to distance selling, off-premises sales provided in the Consumer Protection Act;
(iv) Providing information to the Commission of personal data protection in relation to obligations provided by the regulatory of personal data protection - Personal Data Protection Act, Regulation (EC) 2016/679 of 27 April 2016, etc.;
(v) Obligations provided by Accountancy Act and the Tax-Insurance Procedure Code and other related normative acts in relation to proper and legal accounting.
3. Memento Enterprise Ltd. processes the relevant data provided with the expressly written consent of the client for their processing for the following purposes:
(i) Creating and managing a personal profile on the Site; technical assistance to create an account(s) and restore a forgotten password to access our Site;
(ii) Direct marketing of products and services;
(iii) Participation and management of surveys, gift games, promotional campaigns;
(iv) Participation and management of Memento Club.
4. Processing is necessary for the legitimate interests of Memento Enterprise Ltd.
(i) Evaluate and establish customer satisfaction as well as the effectiveness of the advertising we offer you and others and meet your expectations by presenting adequate advertising;
(ii) Analysis of Purchase History, Customer Preference, and Customer Behavior;
V. Third-party categories that access and process your personal information
(i) Transportation / courier companies, postal operators in order to fulfill our contractual obligations, sending correspondence and communications, in connection with the contract between us, sending of purchased goods;
(ii) People who, under the responsibility of Memento Enterprise Ltd. , maintain the equipment and software used to process your personal data;
(iii) Debt collection service providers, notary, lawyer, bailiff or other third party if the client has breached the obligation arising from a contract with us;
(iv) Banks, servicing payments made by and to you;
(v) Individuals to whom Memento Enterprise Ltd. has provided the implementation of part of the service or service-specific obligations we owe to you; people processing personal data who, on the basis of a contract with Memento Enterprise Ltd., process your personal data on behalf of Memento Enterprise Ltd.;
(vi) People doing consulting services in different spheres - lawyers, accountants, marketing agencies etc.;
(vii) People, institutions and persons to whom we are required to provide personal data under current legislation.
VI. For what period is your personal data stored?
The period of time that your personal data is stored depends on the processing purposes for which it was collected:
1. Personal data processed for the purpose of concluding / amending and executing contracts between Memento Enterprise Ltd. and you or a represented by you company - for the term of the agreement and for the final settlement of all financial relations between the parties. Memento Enterprise Ltd. may store some of your personal data for a longer period of time until the expiration of the applicable limitation period in order to protect any customer claims regarding performance / termination of contracts with us as well as for a longer term in the case of a legal dispute that has already arisen until its final settlement with a court / arbitration ruling which has took effect;
2. Personal data processed for the purpose of issuing accounting / financial documents for tax - insurance purposes, but not only - invoices, debit cards, credit notices, delivery protocols, service / goods contracts are kept for at least 11 years after expiry of the limitation period for repayment of the public collection, unless the applicable legislation does not provide a longer period.
3. Personal data processed for the purpose of participating in the Memento Club and account managing on the site – until the explicit withdrawal of the consent or receipt of an objection to the processing of personal profile data or participation in the Memento Club.
4. Personal data processed for the purposes of direct marketing – to the explicit withdrawal of the consent given for direct marketing or the receipt of an objection to the processing of personal data for direct marketing.
VII. Your Rights in relation to the processing of your Personal Information
In conjunction with the processing of personal data, you have the following rights that you may exercise at any time while we store or process your personal data by sending an application to the address of Memento Enterprise Ltd. mentioned above or by email: email@example.com
You have the right to request from Memento Enterprise Ltd.:
• a copy of your personal data and access to them at any time;
• to correct without undue delay your inaccurate personal data as well as data that is not up to date;
• personal data in a form convenient to transfer to another data administrator, or request us to do so without being impeded by us (the right of portability);
• to delete your personal data without undue delay in the presence of any of the legal grounds for doing so;
• restrict the processing of your personal data, in which case your data will only be stored but not processed. Our refusal to restrict will be explicit only in writing, and we are obliged to motivate it with legitimate reason;
You may also:
• to withdraw your consent to the processing of your personal data at any time with a separate request addressed to Memento Enterprise Ltd. upon consent-based processing;
• to object to the processing of your personal data;
• to object to automated processing, including profiling;
• not to be the subject of a decision based solely on automated processing including profiling;
2. You have the right to appeal to the supervisory authority
You have the right to submit a complaint directly to the supervisory authority and the competent authority that is the Personal Data Protection Commission, address: Bulgaria, Sofia 1592, "Prof. Tzvetan Lazarov "№ 2 (www.cpdp.bg). (or your national supervisory authority)
In case you wish to file a complaint about the processing of your personal data from Memento Enterprise Ltd. , you can do so by contacting the Administrator or directly with the Data Protection Officer (the above mentioned contact details).
3. Automated processing and profiling
When you visit our Site, we use automated processing to adapt products and services to your needs in the best possible way.
4. Opposition against the Use for Direct Marketing
You have the right to object to the future processing of your personal data for the purposes of direct marketing and advertising as well as to disclosure to third parties and their use on their behalf for the purposes of direct marketing and advertising by withdrawing your consent anytime. To do so, you may send an e-mail with the request to discontinue use of your data for direct marketing purposes at: firstname.lastname@example.org
5. Can you refuse to provide personal data to Memento Enterprise Ltd. and what are the consequences of that?
In order to conclude a contract with you and / or to provide you with the requested products and / or services and / or to deliver the ordered goods in accordance with our legal and consequent contractual obligations, Memento Enterprise Ltd. needs certain data identifying the side under the contract, its proxy, contact details, payment details of the obligations.
Not providing such data prevents us from signing a contract with you.
In order to make a purchase from our Site and to provide you with the goods or services you ordered, you must have a profile created on the Site. During the account creation process, Memento Enterprise Ltd. needs certain details to identify you, contact details, payment details. Failure to provide such data prevents the purchase and delivery of goods or services by you.
VIII. How we protect your data
Memento Enterprise Ltd. applies the organizational, physical, IT and other necessary measures to ensure the security and protection of your personal data and the monitoring of the processing of personal data.
Among other things, such security measures include the following activities:
- Memento Enterprise Ltd. has established the requirements for processing, registering and storing personal data with inside procedures, the observance of which is constantly monitored;
- the access of the employees of Memento Enterprise Ltd. to personal data and the permission to process personal data in the Memento Enterprise Ltd. database is limited, depending on their obligations;
- Memento Enterprise Ltd. has established confidentiality obligations for its employees;
- access to the office equipment of Memento Enterprise Ltd. and the computers of each employee is limited.
- we apply all the necessary organizational and technical measures provided by the Personal Data Protection Act, as well as the best practices of international standards
- For maximum security when processing, transferring, and storing your data, we may use additional protection mechanisms such as encryption, etc.
The security measures we apply are subject to constant improvement and adaptation to the most advanced technologies.
IX. Links to other sites
X. „Cookie” use policy
Personal data for children
We do not consciously collect personal information from children under the age of 16. If we learn that we have collected personal information on a child under the age of 16, we will take steps to delete the information as soon as possible or obtain the consent of the person bearing parental responsibility for the child.