top of page

PRIVACY POLICY
MANDATORY INFORMATION ON THE DATA PROTECTION RIGHTS OF INDIVIDUALS (PRIVACY NOTICE)
 

INTRODUCTION

  •         This Privacy Notice explains what we do with your personal data from the moment you register on www.23stor3.com or become our customer and after the termination of our relationship.  

  • It describes how we collect, use and process your personal data and how, in doing so, we comply with our legal obligations to you. Your personal data is important to us and we are committed to safeguarding it and protecting your rights.  

  •       For the purposes of applicable data protection legislation (including but not limited to the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the company responsible for your personal data is 23stor3

  •      This Personal Data Policy is a unilateral act on our part and we reserve the right to change it, for which you will be notified in a timely manner.

  •       If you are dissatisfied with any aspect of our Privacy Policy, you have the right to exercise your legal rights, which we have described below in the applicable places.

PRIVACY POLICY STATEMENT

  • This Mandatory Information on the Rights of Individuals on the Protection of Personal Data is prepared and approved by 23stor3 and is an integral part of the terms and conditions for entering into and exercising a legal relationship with 23stor3.

  • 23stor3 is committed to ensuring compliance with EU and Member State legislation regarding the processing of personal data and the protection of the "rights and freedoms" of individuals whose personal data "23stor3 collects and processes under the General Data Protection Regulation (Regulation (EU) 2016/679).

  • Regulation (EU) 2016/679 and this privacy notice apply to all processing functions of individuals' personal data, including those carried out on personal data of employees/workers, customers, consumers, contractors, suppliers and partners, and any other personal data that the organisation processes from a variety of sources.

  • This privacy notice applies to all individuals - employees/employees/job applicants, customers, consumers, contractors, suppliers, subcontractors, partners of 23stor3 and/or their representatives, as well as other interested parties (e.g. individuals who have submitted a complaint, grievance, request, alert, inquiry; individuals using the www.23stor3.com website, etc.).

The basis for collecting, processing, and storing your personal data

Basis for collecting, processing and storing your personal data

Art. 1. (1) The controller collects and processes your personal data in connection with the use of the website and the online shop https://www.23stor3.com , conclusion of contracts with the company on the basis of Art. 6 para. 1, Regulation (EU) 2016/679 (GDPR), and in particular on the following grounds:

  • Your explicit consent as a customer;

  • Performance of the Controller's obligations under a contract with you;

  • Compliance with a legal obligation applicable to the Controller;

  • For the purposes of the legitimate interests of the Controller or a third party.

  • (2) 23stor3 collects and processes the personal data that you provide to us for the purposes of performing its obligations under the contract, including for the following purposes - accounting and commercial purposes, securing the performance of the contract, protecting information security

Purposes and principles for the collection, processing and storage of your personal data


Art. 2. (1) We collect and process the personal data that you provide to us in connection with your use of the website and the online shop https://www.23stor3.com and entering into a contract with the company, including for the following purposes: 

  • creating an account and providing full functionality when using the online shop;

  • placing orders and purchasing goods;

  • individualisation of the contracting party;

  • accounting purposes;

  • statistical purposes;

  • information security protection;

  • securing the performance of the contract for the provision of the relevant service;

  • participation in games, raffles, promotions, advertising campaigns;

  • sending newsletters at your request.

(2) We comply with the following principles when processing your personal data: 

  • awfulness, fairness and transparency;l

  • imitation of the purposes of processing;

  • relevance to the purposes of the processing and minimisation of the data collected;

  • accuracy and timeliness of data;

  • limitation of storage to achieve the purposes;

  • integrity and confidentiality of processing and ensuring an appropriate level of security of personal data.

 

(3) In processing and storing personal data, the Controller may process and store personal data for the purpose of protecting its following legitimate interests:

Performance of its obligations to the National Revenue Agency, the Ministry of the Interior and other state and municipal authorities.

What types of personal data our company collects, processes and stores

5.What types of personal data our company collects, processes and stores
Art. 3. The Company shall carry out the following operations with the personal data provided by you for the following purposes:

        Conclusion and execution of a commercial transaction or contract with a customert-the purpose of this operation is the conclusion and execution of a contract with a commercial partner or customer and its administration. In individual cases, the purpose of the operation may also be to protect the legitimate interests of the company in the execution of the transaction. Given the limited scope of the personal data collected and the fact that some of it is collected from publicly available sources, an impact assessment is not necessary for this operation

          Registration of a user in the e-shop and execution of a purchase contract - the purpose of this operation is to create an account to use the e-shop to purchase goods and receive newsletters if requested. Provision of contact details for making delivery of purchased goods. Given the limited scope of the personal data collected and the fact that some of it is collected from publicly available sources, an impact assessment is not necessary for this operation.
        Sending a newsletter - the purpose of this operation is to administer the process of sending newsletters to customers who have indicated that they wish to receive them. Given the limited scope of the personal data collected and the fact that some of it is collected from publicly available sources, an impact assessment is not necessary for this operation.
        Exercise of the right of cancellation or reclamation - the purpose of this operation is to administer the process of sending purchased goods to customers. Given the limited scope of the personal data collected and the fact that some of it is collected from publicly available sources, an impact assessment is not necessary for this operation.
        Registration of participant in events/promotions and sending of information or prizes - the purpose of this operation is to administer the process of registering participants in events and games and sending prizes from games held. Given the limited scope of the personal data collected and the fact that some of it is collected from publicly available sources, an impact assessment is not necessary for this operation.
        Request for notification/delivery of an out-of-stock product - the purpose of this operation is to contact the individual in order to request delivery of a product that is currently out of stock. Given the limited scope of the personal data collected and the fact that some of it is collected from publicly available sources, an impact assessment is not necessary for this operation
Art. 4. (1) The controller shall process the following categories of personal data and information for the following purposes and on the following grounds:

Registration and newsletter data (names, e-mail)
Purpose for which the data is collected:

  1. To contact the user and send information to the user, 

  2. for the purpose of registering a user in the online shop, and 

  3. to send information and advertising newsletters.

 

     ​The basis for processing your personal data - By accepting the terms and conditions and registering in the online store or placing an order without registration, or by concluding a written contract, a contractual relationship is established between the Controller and you, on which basis we process your personal data - Art. 6, para. 1 (b) GDPR. Your data for sending newsletters is processed on the basis of your explicit consent - Art. 6 para. 1 (a) GDPR.

     Data for receiving the newsletter (names, e-mail)
The purpose for which the data is collected:

  • To send a newsletter.

 

      The basis for processing your personal data - Your data for sending the newsletter is processed on the basis of your explicit consent - Art. 6 para. 1 (a) GDPR.

     Grounds for processing your personal data - By accepting the terms and conditions and registering in the e-shop or placing an order without registration, or by concluding a written contract, a contractual relationship is established between the Administrator and you, on which basis we process your personal data - Art. 1 (b) GDPR.
Data from your social media accounts (publicly available information from your Facebook or Google accounts)
     The purpose for which the data is collected:
To contact the user and send information to the user, 
for the purpose of registering for a game, sweepstakes, campaign, etc. 
      The basis for processing your personal data - Your data for registration in our events, games, campaigns, etc. is processed on the basis of your explicit consent - Art. 1 (a) GDPR
(2) The controller does not collect or process personal data relating to the following: 

  • reveal racial or ethnic origin;

  • disclose political, religious, or philosophical beliefs, or trade union membership;

  • genetic and biometric data, data concerning health, or data concerning sex life or sexual orientation.

(3) Personal data are collected by the Controller from the individuals to whom they relate.
(4) The Company does not carry out automated decision-making with data.
(5) The Company does not collect or process data about persons under the age of 16 except with the express consent of their parents or legal representatives.


Storage period of your personal data


        Art. 5. (1) The controller shall store your personal data for a period no longer than the existence of your account in the online store or until you withdraw consent to processing. After deletion of your account or successful termination, the Controller shall take the necessary care to delete and destroy all your data without undue delay or to anonymize them (i.e. to put them in a form that does not reveal your identity).

      (2) The Controller shall keep your personal data provided in connection with online orders for a period of 10 years for the purpose of protecting the legal interests of the Controller in the event of legal or administrative disputes with users of the online shop, and the accounting documents shall be kept for the relevant statutory period.
     (3) The Controller shall notify you in the event that the storage period needs to be extended in order to comply with a statutory obligation or in view of the legitimate interests of the Controller or otherwise.

    Art. 6. The Data Controller shall store the personal data of the legal representatives of its business partners for the duration of the performance of the contract, in order to comply with the legitimate interests and legal obligations of the Data Controller, which period may exceed the duration of the concluded contract.

Your rights in the collection, processing and storage of your personal data

Withdrawal of consent to the processing of your personal data
Art. 8. (1) If you do not wish all or part of your personal data to continue to be processed by the Company for any or all of the processing purposes, you may withdraw your consent to processing at any time by completing the form in your profile or by making a free text request.

   (2) The controller may ask you to verify your identity and identity with the data subject by asking you to enter your email address and password to access the site on site at the Company's office to an employee.
   (3) By withdrawing your consent to the processing of personal data that is required to create and maintain an online store account, your account will become inactive. You wi
ll of course be able to browse the online shop and the products offered and place orders as a guest or make a new registration.
   (4) If there is an order placed by you that is in the process of being processed, the earliest point at which you can withdraw your consent to processing is upon successful completion of the order.

 

Right of access
    Art. 9. (1) You have the right to request and obtain confirmation from the Controller as to whether personal data relating to you is being processed, and if you are a registered user, you may at any time view in your profile the personal data that you have provided and is being processed about you.
     (2) You have the right to access the data relating to you and the information relating to the collection, processing and storage of your personal data.
    (3) The controller shall provide you, upon request, with a copy of the personal data processed relating to you in electronic or other appropriate form.
    (4) Providing access to the data is free of charge, but the Controller reserves the right to charge an administrative fee in the event of repetitive or excessive requests.
 
Right to rectification or completion
Art. 10. You may rectify or complete inaccurate or incomplete personal data relating to you directly through your website profile or by making a request to the Controller.

 
Right to erasure ("to be forgotten")

        Art. 11. (1) You have the right to ask the Controller to erase some or all of the personal data relating to you, and the Controller has the obligation to erase them without undue delay where one of the following grounds applies:

the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
you withdraw your consent on which the processing is based and there is no other legal basis for the processing;
You object to the processing of personal data relating to you, including for direct marketing purposes, and there are no legitimate grounds for the processing which override;
the personal data have been unlawfully processed;
the personal data must be erased in order to comply with a legal obligation under EU or Member State law to which the Controller is subject;
the personal data have been collected in connection with the provision of information society services.
     (2) The Controller is not obliged to erase personal data if it stores and processes them:

for the exercise of the right to freedom of expression and the right to information;
for compliance with a legal obligation requiring processing provided for in EU or Member State law applicable to the Controller or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
for reasons of public interest in the field of public health;
for archiving purposes in the public interest, scientific or historical research or statistical purposes;
for the establishment, exercise or defence of legal claims.
     (3) In the event of the exercise of your right to be forgotten, the Company will delete all your data except for the following information:

Information that is necessary to verify that your right to be forgotten has been exercised;
technical information for the operation of the online shop, which information cannot be linked in any way to your person;
the e-mail address with which you registered in the online shop.
    (4) In order to exercise your right to be forgotten, it is necessary to submit a request via your account in the online shop or by sending an email request to the Administrator.
    (5) The Administrator may ask you to verify your identity and identity with the person to whom the data relates.

    (6) If there is an order placed by you that is in the process of being processed, the earliest point at which you can request to be "forgotten" is upon successful completion of the order.

    (7) By deleting your personal data, your account will become inactive. Of course, you will be able to browse the online shop and the products offered and place orders as a guest or make a new registration.

    (8) The controller does not delete data that it has a legal obligation to store, including for the defence of legal claims made against it or to prove its rights.

 
Right to restriction
    Art. 12. You have the right to require the Controller to restrict the processing of data relating to you where:

you contest the accuracy of the personal data, for a period that allows the Controller to verify the accuracy of the personal data;
the processing is unlawful, but you do not wish the personal data to be erased, but only for its use to be restricted;
The Controller no longer needs the personal data for the purposes of the processing, but you require it for the establishment, exercise or defence of legal claims;
You have objected to the processing pending verification that the Controller's legitimate grounds override your interests.
 
Right to portability

    Art. 13. (1) You may, at any time, download or obtain in machine-readable format the data stored and processed about you in connection with the use of the services of the Controller, directly through your account via the data export option or by email request.
   (2) You may request the Controller to transfer your personal data directly to a controller designated by you, where this is technically feasible. 

 
Right to receive information

Art. 14. You may request the Controller to inform you of any recipients to whom the personal data for which rectification, erasure or restriction of processing has been requested have been disclosed. The controller may refuse to provide this information if it would be impossible or would require a disproportionate effort.

Right to object
Art. 15. You may object at any time to the processing of personal data concerning you by the Data Controller, including if processed for profiling or direct marketing purposes.

 
Your rights in the event of a personal data breach
Art. 16. (1) If the Controller becomes aware of a breach of the security of your personal data which may pose a high risk to your rights and freedoms, he shall notify you without undue delay of the breach and of the measures which have been taken or are to be taken.

    (2) The controller is not obliged to notify you if:

it has taken appropriate technical and organisational protection measures in respect of the data affected by the security breach;
has subsequently taken measures to ensure that the breach will not result in a high risk to your rights;
notification would require a disproportionate effort.

 

PROVIDING YOUR PERSONAL DATA TO THIRD PARTIES

DISCLOSURE OF YOUR PERSONAL DATA TO THIRD PARTIES
   Art.17. (1) The controller may, at its own discretion, transfer some or all of your personal data to processors for the purposes of processing, subject to the requirements of Regulation (EU) 2016/679.

    (2) The controller shall not authorise the use, sale, disclosure or sharing of personal data about you with other persons or with unrelated companies, except where this is necessary in order to provide you with the services you have requested and where you have provided your permission.

 

     Art.18. (1) This privacy policy applies only to the website and e-shop operated and owned by SPORT VISION EAD. It does not apply to links to other websites and to data collected by third parties who operate other websites and use cookies on them.

     (2) For the purposes of processing your personal data and providing the services, 23stor3 may provide the data to trusted partners who work on behalf of 23stor3 on a contractual basis and under confidential agreements. These companies may use such information to enable 23stor3 to deliver advertising to its customers. These companies may not independently share this information.

If you do not want 23stor3 to send information to any of its trusted partners, you may withdraw your consent by sending an email message stating "I do not want my data to be shared with third parties" to

 

      Art. 19. In the event of a violation of your rights under the above or applicable data protection legislation, you have the right to lodge a complaint with the Data Protection Commission as follows:

Name-Data Protection Commission

Registered office and address-Address. Headquarters and registered office, 1592 Sofia Blvd. "Prof. Tsvetan Lazarov № 2

Address for correspondence-gr. Sofia 1592, bul. "Prof. 2 Tsvetan Lazarov

Telephone-02 915 3 518

Website-www.cpdp.bg

 

Art. 20. You can exercise all your rights regarding the protection of your personal data by using the forms attached to this information. Of course, these forms are optional and you may make your requests in any form that contains a statement to that effect and identifies you as the data holder.

Art. 21. If the consent relates to a transfer, the Data Controller shall describe the possible risks for the transfer of the data to third countries in the absence of an adequate protection solution and appropriate remedies.
 

23STOR3 ЕООД
BULGARIA
VELIKO TARNOVO, BULEVARD BULGARIA 33 FLOOR 0 
ЕИК: 207538943

 

bottom of page