Support 24x7 0700 17 978
Privacy Policy
WE TAKE CARE OF THE PROTECTION OF YOUR PERSONAL DATA.
WHO ARE WE?
Identification of the personal data controller: STEMO LTD (hereinafter STEMO) is a company registered in the Commercial Register and the Register of Non-Profit Legal Entities at the Registry Agency, with UIC 817080126, with registered office and legal address in Gabrovo, 48 Nikolaevska Str., represented by Aleksander Dimitrov, CEO and Mladen Markoski, Managing Director and they are also administrators (controllers) of personal data in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals in connection with the processing of personal data (General Regulation on Data Protection) and the Personal Data Protection Act (PDPA).
HOW TO CONTACT US?
Address: 48 Nikolaevska Str., Gabrovo, tel. 066 801951, e-mail: dataprivacy@stemo.bg
STEMO LTD. RESPECTS THE CONFIDENTIALITY OF YOUR PERSONAL DATA.
The protection of your personal information throughout the processing of personal data, as well as the security of all personal data, is an important issue for us. We process personal data confidentially and in accordance with legal provisions at national and European level. Data protection and information security are included in our corporate Policies.
WHAT IS THE PRIVACY POLICY?
This Privacy Policy aims to provide you in clear and accessible language with information about the actions taken with the personal data processed by STEMO in connection with its business relations, including:
- What personal data we collect about you;
- What is the purpose of its processing;
- For how long we store personal data;
- With whom we share your personal data;
- Describes details regarding the processing of personal data of individuals related to our business partners (employees and representatives of our business partners and other individuals related to them);
- What are your rights regarding your personal data.
With this Privacy Policy STEMO Ltd. declares that it applies all technical and organizational measures, prescribed by law or other regulations at national and European level for the protection of personal data of individuals.
YOUR RESPONSIBILITIES:
- Read this Policy and review it regularly.
- If you are in a contractual relationship with us or if you are a natural person related to our business partner / employee and / or a representative of our business partner or another natural person related to our business partner, you could (if you have the right and opportunity to do so) check the terms contained in contracts and other documents. They may contain additional details about how we collect and process your data. For this purpose (if you wish) you could turn to the relevant business partner with whom you are connected (respectively to your colleague, whose functions include these issues).
- Pay attention to the additional information and conditions that we introduce to you at different stages of our interaction.
- If you provide us with information about third parties, you should have a legal basis for doing so. Also, before providing us with data to a third party, you should inform him or her that you will provide their data to us, as well as inform them about the way we will process the data and about this Policy.
- Please let us know, if there is a change, error or incompleteness in your data that we process.
- By providing us with data, you declare that you are over 18 (eighteen) years of age.
WHAT IS PERSONAL DATA?
"Personal data" means any information related to an identified or identifiable natural person ("data subject").
WHAT PERSONAL DATA DOES STEMO COLLECT FOR YOU?
In order to provide effective access to its products / services, STEMO collects certain information about you:
- Name, telephone, e-mail, other contact details, location, organization - when filling in any of the forms (for contact, for registration) on the STEMO website www.stemo.bg (STEMO website);
- PIN for bank payment or purchase on installment is in PC shop
- Technical data, automatically sent to us when you use the STEMO website - IP address, information about the device from which you visit the STEMO website;
- Cookies to identify your browser or device.
Regarding the data of individuals related to our business partners, please see the special section "PROCESSING OF PERSONAL DATA OF INDIVIDUALS RELATED TO OUR BUSINESS PARTNERS (EMPLOYEES, REPRESENTATIVES) AND OTHERS".
DO YOU HAVE TO PROVIDE US WITH PERSONAL DATA?
In any case, if you do not provide us with the personal data we have requested, we may not be able to achieve one or more of the processing purposes described in this Policy. In some cases, the provision of personal data could be a legal and / or contractual requirement (in these cases, if the data is not provided, the relevant consequences provided for in the law or in the contract could occur). The provision of certain personal data may be a requirement necessary for the conclusion of a contract (in these cases, if this data is not provided, it is not possible to conclude the relevant contract). If you have any doubts about the exact data, which you are obliged to provide us with, please ask us such a question and we will answer you.
ON WHAT BASIS DOES STEMO PROCESS YOUR PERSONAL DATA?
The processing of personal data includes the collection, storage, destruction, transmission, correction, updating, deletion, destruction and all other actions performed with your personal data.
If you are a natural person, with whom we have concluded a contract or there is your request in connection with the future conclusion of a contract, STEMO processes your data in order to fulfill its contractual obligations under contracts concluded with you or to take steps before concluding a contract.
In some cases, STEMO processes personal data after obtaining clear, free and unambiguous consent from you for the purposes of processing. Consent to the processing of your personal data could be provided, for example, by marking the appropriate box (ticking) for consent on the STEMO website, through a written declaration of consent when visiting our office or otherwise. The consent you provide can always be revoked as described below in the section "WHAT ARE YOUR RIGHTS REGARDING YOUR PERSONAL DATA? “.
STEMO could also process personal data in compliance with legal obligations, as well as if necessary in order to protect the life and health of the data subject. STEMO may also process personal data if it or a third party has a legitimate interest in doing so (unless the interests or fundamental rights and freedoms of the individual that require the protection of personal data take precedence over that interest).
FOR WHAT PURPOSE DO WE PROCESS YOUR PERSONAL DATA?
Your personal data enable us to fulfill our obligations (contractual or legal), as well as to fulfill other purposes, including, but not limited to:
- Exercise the rights and / or fulfill the obligations under concluded contracts (this could be a contract between STEMO and you or a contract between STEMO and its business partner with which you are connected) and / or to take steps in connection with the conclusion of such contracts;
- Make possible access and order of products / services through STEMO Internet sites;
- Respond to your inquiries, opinions, recommendations and / or other communications;
- Send / provide you with certain information in connection with our relationship with you or our business partner;
- With a view to establishing, exercising or defending legal claims;
- Comply with legal obligations that apply to us.
HOW DO WE COLLECT YOUR PERSONAL DATA?
STEMO collects personal data most often in the following ways:
- by filling in registration forms on the STEMO website;
- by providing your data to other persons - for example when our business partners provide us with contact data and other necessary data about individuals related to them (employees, representatives and others);
- by filling in forms and declarations. The forms are provided and filled in free form or in a form provided to you on paper or electronic media by STEMO;
- by visiting and using online ordering platforms and Internet sites of STEMO;
- when updating data at your request and filling in an update form on paper or in an electronic environment;
- by processing information about your visits to the STEMO website;
- by processing IP address information, cookies to identify your browser or device.
HOW LONG DO WE STORE AND PROCESS YOUR DATA BEFORE WE DESTROY IT?
Depending on the reason for processing personal data, the period of storage is different. When deciding what is the best retention period for data, we must provide the technical object, nature and sensitivity, potential risk of harm from unauthorized use or disclosure, comprehensive processing, and results can be obtained by other means as well as submit legal requirements.
If we process your personal data with your consent, we will continue to process the data for the period for which the consent was given or until you withdraw the consent (unless we then apply another reason for processing). However, we may terminate the processing on the basis of consent even earlier if we consider that we no longer need the data for the relevant purposes or for other reasons (for example, in order not to infringe the applicable legislation).
We store your personal data for a period of 6 years from the termination of our contractual basis, if we process personal data for the performance of contractual obligations to you. After the expiration of this period and in case there is no other reason to continue storing your personal data, the information about you is going to be destroyed. This means that the records are going to be permanently deleted from our system, as well as the paper media containing your personal data are destroyed.
If we process your personal data based on legitimate interests, STEMO will process your data as long as there is a relevant legitimate interest. If we process your data based on a legitimate interest and you object to the processing of your data, STEMO should stop processing it, unless:
- Demonstrate that there are compelling legitimate grounds for processing that take precedence over your interests, rights and freedoms, or
- The processing is necessary for the establishment, exercise or defense of legal claims.
If we process your personal data in order to comply with our legal obligation, we will continue to process it for the period necessary to comply with the legal obligation (unless we then apply another legal basis).
TO WHOM CAN WE TRANSFER YOUR PERSONAL DATA? INTERNATIONAL TRANSMISSION OF DATA. STEMO may disclose your personal information to the following persons:
- Companies providing courier services;
- The company that provides hosting services related to the STEMO website;
- Public bodies, including those performing supervisory functions;
- Banks and financial institutions in the country and abroad when conducting money transactions;
- Insurance and reinsurance companies on loans and credit lines granted by STEMO;
- Lawyers, auditors, notaries, courts, prosecutors, police, investigation;
- Third parties - debt collection companies;
- STEMO contractors for fulfillment of obligations, such as IT companies, logistics, telecommunications, collection, printing services, marketing and others;
- To our suppliers - when we provide them with your contact details in order for the respective provider to communicate with you regarding trainings, events and / or marketing information.
Each transfer is made in strict compliance with the confidentiality and security of your personal data. In all the above cases, the persons to whom we provide your personal data have declared that they provide an adequate level of protection of your personal data.
Your personal data is usually processed within the European Union or the European Economic Area and is not transferred to other countries ("third countries"), nor is it transferred to international organizations. If data transmission to a "third country" is required, we guarantee that the necessary level of data protection in the third country concerned or at the recipient in that third country is ensured prior to such transfer. This could be based on a decision of the European Commission on the adequate level of data protection in a particular third country as a whole. Alternatively, the transmission of data may be based on so-called "Standard Contract Clauses" agreed with the recipient or on other appropriate / applicable guarantees. We will be happy to provide you with additional information upon request (including how you can read the relevant texts / documents guaranteeing the protection of your data).
PROFILING - USING COOKIES.
The STEMO website uses cookies. To read the Cookie Policy, click here.
PROCESSING OF PERSONAL DATA OF INDIVIDUALS RELATED TO OUR BUSINESS PARTNERS (EMPLOYEES, REPRESENTATIVES AND OTHERS).
If you are a natural person related to our business partner (his employee, representative or other person), you should know and understand how STEMO processes your personal data in connection with the relationship between STEMO and the respective business partner (customer, supplier, etc.). We often collect your data from you. In some cases, we may receive your data from your colleagues or from other persons related to the respective business partner. We may also receive your data from publicly available information in a commercial register and / or from the website of our business partner for whom you work or with whom you are otherwise connected. Most often we have the following information about you: names, email, phone, other contact information, your communication with us (eg by email).
STEMO processes your data on the following grounds:
- Reasons for "legitimate interests" (Article 6 (1) (e) of the General Data Protection Regulation). These could be legitimate interests of STEMO and / or legitimate interests of the respective business partner, as follows:
- To exercise the rights and / or fulfill the obligations under concluded contracts between STEMO and the respective business partner;
- To take steps in connection with the conclusion of a contract between STEMO and the respective business partner;
- To make it possible to order products / services through the STEMO website;
- So STEMO could provide access to its website. In this regard, STEMO could display content that is relevant and personalized (to our business partner you are affiliated with) and limited by the set criteria;
- So STEMO could respond to your inquiries, opinions, recommendations and / or other communications;
- Transmission of contact data to STEMO suppliers - in order for the respective provider to communicate with you regarding trainings, events and / or marketing information;
- With a view to establishing, exercising or defending legal claims;
- So STEMO could send you information regarding the relationship between STEMO and its business partner with whom you are affiliated;
- The "legitimate interest" basis does not apply to the sending of information for which we have envisaged using the "consent" basis. Please see below for which cases we have foreseen that we will apply grounds for "consent".
- Grounds for "consent" (Article 6 (1) (a) of the General Data Protection Regulation). We use this ground in all cases where we have informed you that consent is the basis for the processing of your personal data.
In all cases where we have provided grounds for "consent", you have the right to decide freely whether to give your consent or not. In addition, if you have given your consent, you will have the right to withdraw it at any time, and this will not affect the lawfulness of processing based on consent before it is withdrawn. You can withdraw your consent in the ways set out below in the section "WHAT ARE YOUR RIGHTS REGARDING YOUR PERSONAL DATA?“ .
- Grounds for "compliance with a legal obligation applicable to STEMO" (Article 6 (1) (c) of the General Data Protection Regulation). This applies, for example, to data contained in accounting documents, data stored for tax purposes, etc.
If you are an individual related to our business partner - CLIENT, read carefully the following additional information applicable to you: In addition to the information that STEMO provides through the STEMO website, it also carries out commercial communication with the CLIENT through individuals related to the CLIENT (its employees, representatives and others). If you are such a person, STEMO may use your contact details at its disposal and will be guided by the contractual relationship with the respective CLIENT (with whom you are connected), by its interests, as well as by the interests of STEMO. Thus, you will usually receive and actively participate in the following communication:
- Communication for which we use "legitimate interest" grounds:
- Communication on activation, change and other issues related to your user profile (if you have one) on the STEMO website.
- Communication on activation, change and other issues related to the CLIENT's user profile (if he has such a profile) on the STEMO website - in the cases where you manage this profile.
- Communication related to orders made by the CLIENT, complaints, questions / requests and other questions related to specific sales / transactions carried out by STEMO to the CLIENT.
- Communication related to your position and role with the CLIENT, for example with payments and accounting - if you are part of the financial and accounting team of the CLIENT.
- Any other communication, with the exception of the communication for which we use the "consent" basis.
If you do not wish to receive a communication for which we use a "legitimate interest" legal basis, you could request this from STEMO (exercise your right to object) by contacting us as set out below in the section "WHAT ARE YOUR RIGHTS REGARDING YOUR PERSONAL DATA?”. Before doing so, we recommend you to discuss this issue with the CLIENT (with whom you are connected), because he may require you to receive appropriate communication, in view of his contract / relationship with STEMO. If, despite everything, you make such an objection to us to receive communication, then we have the following rights:
- To satisfy your request or
- Not to satisfy your request, because we consider that our legitimate interests or the legitimate interests of the CLIENT with whom you are connected have priority over your request. To make this assessment, we may decide to contact the CLIENT to discuss your request for non-participation in such communication.
- Communication for which we use "consent" grounds:
We will communicate with you only if we have obtained your consent. You can give your consent for each type of communication by checking (ticking) the appropriate consent field when registering / activating your user profile (user profile managed by you) on the STEMO website or later in the user profile itself. Please make sure that no one else has access to the consent settings regarding communication with you and that only you manage them. Please also note, that you may not change the communication settings between others and us (for example, in a profile that is not yours).The information you provide to us in connection with your consent (such as contact email) should be yours and not those of others. We would like to inform you that we would consider that you have personally made the settings / consents for communication with you. Therefore, please do not disclose your password to access the profile of others and notify us immediately if you suspect or learn that another person has given or withdrawn consent to the processing of your data instead of you. In case of your consent for a certain type of communication, we will use your contact details from your user profile, as well as your contact details obtained in other ways. Your consent may be revoked as set out in the section "WHAT ARE YOUR RIGHTS REGARDING YOUR PERSONAL DATA?" of this Policy. In some cases, we may carry out automated processing of your personal data - automatic communication with you in connection with overdue obligations of our business partner with whom you are connected. Automatic communication for which we use the "consent" basis (it is indicated above in which cases we use this basis); automatic communication in connection with orders placed; automatic communication in connection with the activation, existence and / or administration of a user profile on the STEMO website.
WHAT ARE YOUR RIGHTS REGARDING YOUR PERSONAL DATA? In compliance with the Bulgarian and European legislation on personal data protection, including the General Regulation on data protection, you can exercise the following rights:
- the right of access to the personal data that STEMO processes for you;
- the right to request from STEMO correction / addition in case you find inaccuracies, incompleteness (taking into account the purposes of processing) or the need to update your personal data;
- the right to request a restriction on the processing of personal data in the cases specified by law;
- the right to request the deletion of your personal data from STEMO, in case there are conditions for this;
- the right to object to the processing of your personal data in the cases specified in the legislation;
- the right to withdraw your consent to the processing of your data at any time. Withdrawal of consent shall not affect the lawfulness of processing on the basis of consent before it is withdrawn;
- the right to request the portability of your personal data in a structured, widely used and machine-readable format and / or to transfer your personal data to another controller (in the cases specified in the legislation);
For more information on the above rights, please see the next section "WHAT DOES EACH OF THE ABOVE RIGHTS MEAN?". You can exercise any of the above rights by contacting us by email: dataprivacy@stemo.bg or address: Gabrovo, 48 Nikolaevska Str.
In some cases, the following additional options for exercising your rights are applicable:
- If the unsubscribe option (or similar) is available in a message sent to you, you could opt out of this type of communication (by following the unsubscribe option or similar). In this case, it will be considered that you withdraw your consent for communication (if we use the ground "consent") or that you have objected to a certain type of communication (if we use the ground "legitimate interest");
- persons with a user profile on the STEMO website have the following additional opportunities to exercise some of their rights:
- they can view personal data filled in their user profile, as well as possibly change their access password using the functionalities in their user profile,
- if they have given their consent by ticking / marking the appropriate consent field (upon registration / activation of their user profile or through the user profile itself), the persons have the right to withdraw their consent at any time by removing the respective tick / marking in their user profile on the STEMO website.
When requesting the exercise of any of your rights, we will grant the request if we deem it necessary to do so in the light of applicable law. If there are changes, errors, inaccuracies and / or incompleteness in your personal data, please notify us, as well as correct and / or supplement your data in your user profile (if any) on the STEMO website. Please notify us immediately if you suspect or learn that unauthorized access to your profile has taken place.
WHAT DOES EACH OF THE ABOVE RIGHTS MEAN?
- Right of access to personal data: this right gives you the opportunity to receive confirmation whether your personal data is processed and, if so, to access the data and certain information related to them. In addition, you have the right to receive a copy of your personal data, which is going to be processed.
- Right to delete, correct / supplement, restrict processing: the right to request STEMO to delete correct / supplement or restrict the processing of your personal data.
- Right to object: you have the right, at any time and on grounds related to your specific situation, to object to the processing of personal data on the grounds of "legitimate interest".
- Right of portability: when the processing of personal data takes place in an automated way, you have the right to receive the personal data relating to you that you have provided to STEMO in a structured, widely used and machine-readable and interoperable format. Where technically feasible, you have the right to transfer personal data directly to another controller. This right should apply when you have provided your personal data on the basis of your own consent or the processing is necessary due to an obligation under a contract to which you are a party. In cases, based on another legal basis, the law should not apply. Due to its very nature, this right should not be exercised in respect of data controllers in the performance of their public duties. Therefore, this right should not be applied when the processing of personal data is necessary to comply with a legal obligation to which the controller is subject, or to perform a task of public interest, or in the exercise of official authority conferred on the controller. Your right to transmit or receive personal data concerning you does not create an obligation for STEMO, as an administrator, to adopt or maintain technically compatible processing systems. Where more than one data subject is affected in a given set of personal data, the right to receive personal data should not affect the rights and freedoms of other data subjects in accordance with the General Data Protection Regulation.
- Right to lodge a complaint with a supervisory authority: if you believe that the processing of your data violates the General Data Protection Regulation and / or other applicable data protection legislation, you have the right to refer it to the supervisory authority. In Bulgaria, this body is the Commission for Personal Data Protection (CPDP), address: Sofia 1592, Blvd. "Prof. Tsvetan Lazarov” № 2; e-mail: kzld@cpdp.bg; Website: www.cpdp.bg. You have the right to refer the matter to the supervisory authority by the expiry of certain time limits. In case of violation of your rights under the legislation on personal data protection, you also have the right to appeal against actions and acts of STEMO in court. The court cannot be seized if there is pending proceedings before the CPDP for the same violation or a decision of the CPDP on the same violation has been appealed and no court decision has entered into force.
CHANGES TO THE PRIVACY POLICY.
STEMO reserves the right to change this Privacy Policy at any time. In case of changes in the Privacy Policy, an updated version, containing the changes made will be published on the STEMO website, If required by applicable law or deemed necessary, we will notify you in an appropriate manner (for example, by email) of changes to this Privacy Policy. In addition, we may notify you of changes to this Privacy Policy by posting notices on the STEMO offices and / or on the STEMO website.
In view of the changes, you will be able to stop using some or all of the services (if this is possible and permissible in the specific case from the point of view of the law, concluded contracts, etc.) and / or to exercise your rights (part of which are explicitly mentioned above) .
The current update of the Privacy Policy enters into force on 01.06.2023. From this date, the Privacy Policy applies to all existing and future relationships and any existing and future processing of personal data carried out by STEMO.