“Riviera” AD, UIC 103002712, having its seat and registered address at: 19, Karningradska Street, Sofia 1000, hereinafter referred to as the “Company” is a controller of personal data and is responsible for compliance with the provisions of the General Data Protection Regulation 2016/679.
The purpose of this Privacy Policy is to inform you of what personal data the Company proceses and for what purposes, to whom it provides them, what are your rights regarding the processing of your personal data and how you can exercise them.
Compliance with the provisions of the Regulation
The Company policy aims to ensure compliance with the provisions of the Regulation.
Personal data are collected and processed lawfully and fairly
The Company collects and processes personal data lawfully, fairly and in compliance with the principles and rights of the natural persons concerning their personal data processing.
Personal data are processed transparently
The Company ensures transparency in the communication for the collected and processed personal data, such information being in a short, transparent, comprehensible and easily accessible form and using clear and unambiguous formulations.
Personal data is collected and processed only for certain purposes
The Company processes personal data of natural persons only in the following cases:
Personal data unnecessary for the Company activity shall not be collected and processed
The Company does not collect or process personal data of natural persons who exceed their statutory obligations or business needs.
Collected personal data are processed for other purposes only having the consent of the persons
In all cases where it is necessary to collect and process personal data of natural persons for purposes other than the original, the Company shall notify the natural persons concerned, seek their consent and proceed to process their personal data for other purposes only after their explicit consent.
The minimum necessary personal data are collected for processing
The Company collects and processes only the minimum personal data required of natural persons who:
The processed personal data are accurate and up to date
The Company ensures that the processing of the personal data of natural persons is based on maximum accuracy and, if possible, they shall be always up to date.
Personal data are processed by the minimum number of people required
The Company ensures that the access to and the processing of personal data of natural persons is performed by the minimum number of persons (operators) who have the necessary competence for their processing and the necessary commitment to their secrecy.
Personal data are stored for the minimum required time
The Company keeps personal data for the minimum required time, which is:
Upon expiry of the minimum time required under items 1 to 4 of the preceding paragraph, personal data shall be destructed without undue delay.
In any case, the Company provides at least once a year to review the collected and processed personal data, and the ones that fall under any of the above hypotheses are erased without undue delay.
Personal data are processed with the necessary levels and measures of protection
The Company provides the necessary levels of physical, organizational and technological protection in view of:
The Company also provides all necessary measures for the timely recovery of collected and processed personal data in the case of their loss as a result of accidental, malicious or force majeure events.
Personal data are processed with controlled and traceable access
The Company provides the necessary and appropriate technical, organizational and technological measures for controlled and traceable access to the personal data of the natural persons.
Personal data are processed with the required accountability to comply with the Regulation
The Company provides for the necessary accountability and records to be able to demonstrate that the provisions of the Regulation have been complied with.
Respecting the rights of natural persons whose personal data are being processed
The Company ensures protection of the rights of the natural persons whose personal data are collected and processed, including:
Processed personal data in its capacity of Controller:
The Company as Controller performs the following operations and processes only the required personal data for the following purposes:
In connection with the fulfilment of the above objectives, the Company provides personal data to the following recipients:
If you have questions or ambiguitiesregarding the processing of your personal data or wish to exercise any of your rights, you can contact:
The competent supervisory body on the territory of the Republic of Bulgaria is the Commission for Personal Data Protection.
In case of doubt that your privacy rights have been violated, you can report to: