Privacy Policy

GENERAL POLICY FOR THE PROTECTION OF PERSONAL DATA OF DUNONIA AD, EIK 207021255

This policy aims to inform you about the manner, scope, purposes, grounds, terms of data storage and your rights in relation to the processing of your personal data.

WHO ARE WE?

With this Policy, we inform you that Dunonia AD (hereinafter referred to as the “Company”) is an Administrator of personal data within the meaning of Regulation (EU) 2016/679 and in this capacity collects, records, stores, destroys or otherwise processes personal data.

We provide you with the following information regarding the Administrator of your personal data:

Name: Dunonia AD

EIK: 207021255

Address: Sofia, 14B Filip Kutev St

Website: vidinplaza.com

Email: info@vidinplaza.com

WHAT CATEGORIES OF PERSONS DOES THE COMPANY COLLECT AND PROCESS PERSONAL DATA:

The company collects and processes your personal data if you are:

– employees of the Company, appointed under an employment or civil contract;

– natural persons, candidates for employment with us;

– natural persons – counterparties of the Company (suppliers, customers, subcontractors, tenants), as well as representatives or proxies of the representing counterparties – legal entities;

– natural persons – visitors to the “Vidin Plaza” Retail Park;

– natural persons, users of our site vidinplaza.com

WHY DO WE NEED TO COLLECT YOUR PERSONAL DATA?

3.1. If you are an employee of the Company, the Company collects and processes your personal data for the following purposes:

– conclusion and/or termination of an employment/civil contract;

– payment of remunerations, bonuses;

– evaluation of work performance and results, disciplinary sanctions and proceedings;

– participation in corporate programs for human resources management, conducting trainings;

– fulfillment of the legal obligations of the Company, established in the labor, insurance and tax legislation (in CT, KSO, ZDDFL, etc.), incl. for summarizing and securing the data for the needs of state institutions (e.g. NOI, NRA, etc.);

– accounting for remuneration, tax liabilities and mandatory social security contributions, administration of employee fringe benefits (eg short-term and long-term compensation and bonus programs);

– provision of social benefits and additional health insurance services to employees and their family members;

– making contact and sending correspondence; internal company communication;

– maintenance, monitoring and security of internal networks and IT systems, providing access;

– data from remote access devices – gaining access to them for the purpose of protection and security, crime prevention, based on legitimate interest;

– participation in social, cultural or other corporate events.

3.2. If you are a job candidate, the Company collects and processes your personal data in order to assess whether you meet the requirements for filling the position and selecting the Company’s personnel.

3.3. If you are natural persons – counterparties of the Company (suppliers, customers, subcontractors, tenants, etc.), as well as representatives or proxies of the representing counterparties – legal entities, the Company collects and processes your personal data in order to fulfill the contracts and protect the legitimate interests of the Company, as well as for the fulfillment of the Company’s legal obligations arising from tax and accounting legislation, as well as other legal acts applicable to the Company’s activities.

3.4. If you are individuals – visitors to the Vidin Plaza retail park, such as a commercial, office, warehouse and production park with shops, parking spaces and internal alleys, located in Vrazhebna district, Bogrovski pesotsi locality, Kremikovtsi district, Sofia municipality, built by the Company on land owned by it, the Company collects and processes your personal data for the following purposes:

– to protect our legitimate interest in connection with the execution of the contracts concluded with the tenants in the “Vidin Plaza” retail park;

– for planning, reporting and tracking the attendance of the “Vidin Plaza” Retail Park in connection with the implementation of the Company’s main activity;

– to protect the life and health of individuals whose data are collected or of another individual;

– in order to manage the Company’s business strategy – to improve and optimize the Company’s business strategy, as well as to plan appropriate actions and activities of the Company;

– to protect legitimate economic interests – to exercise the right to defend the Company when its rights and legitimate interests are violated, to conduct audits, etc.

3.5. If you are natural persons, users of our site, the Company collects and processes your personal data for statistical purposes regarding the use of our site, in which case your data is anonymized.

3.6. If you do not fall into any of the above categories of natural persons, the Company collects and processes your personal data only if you have given us your consent for this. In this case, you have the right to withdraw your consent at any time.

For persons under the age of 14, consent to the collection and processing of their personal data should be provided by the parent exercising parental rights or the guardian of the data subject.

WHAT PERSONAL DATA OF YOURS DO WE COLLECT AND PROCESS?

The company collects and processes your following personal data:

4.1. To employees of the Company:

– identification and contact data – names, gender, nationality, social security number, address, telephones, email, place of residence, data from an identity document, a copy of the SUMPS (only if the persons are provided with a company car);

– family identity – marital status, family ties, names and social security number of children up to 18 years old;

– data on education and competences – diploma of completed education, certificates, qualifications;

– data on professional experience and previous employers;

– photo;

– financial data – bank accounts, information on bank loans, participation and/or ownership of shares or securities in companies;

– data on competition and participation in other organizations (non-compete data)

– data on access to the Company’s systems, buildings and premises;

– work activity – position, place of work, department, official contact details – phone, email, fax, working hours (full-time and half-time), data on completed training, work and insurance experience, remuneration, bonuses, days of temporary incapacity for work, income and social security experience paid by a previous employer for the relevant calendar year, number of days and dates of annual leave;

– work performance – evaluations, disciplinary sanctions, etc.

– membership in professional organizations, insurances;

– medical data – state of health according to a medical examination document upon initial employment, etc. medical documents submitted by the person during the period of validity of the concluded employment contract in fulfillment of the Company’s legal obligations;

– criminal record data – criminal record certificate, only for the positions for which this is necessary according to Bulgarian and European legislation.

4.2. To natural persons – candidates for employment with us:

– identification and contact data – name, surname and surname, telephone, email, photo;

– data on education, skills and competences (language proficiency certificates and others;

– data on previous experience and employers;

– recommendations – with the consent provided by the applicant;

4.3. To natural persons – counterparties of the Company (suppliers, customers, subcontractors), as well as representatives or proxies of the representing counterparties – legal entities:

– identification and contact data – name, surname and surname; Social security number, permanent address and/or address for correspondence; Email;

– In the event that contracts are concluded by a proxy and a notarized power of attorney is presented, the following data are collected for the authorizer and the authorized person: name, surname, surname, social security number (date of birth), ID card number, date of issue.

4.4. To natural persons – visitors to Vidin Plaza Retail Park: photographic images, video and voice recordings stored with the records created by means of surveillance in the Vidin Plaza Retail Park parking lot.

4.5. To natural persons, users of our site vidinplaza.com: electronic identification data from your computer (such as “cookies” or “IP addresses”).

Please note that we collect and process your personal data only to the extent necessary to fulfill the purposes for which they were collected. Unless specifically indicated, please do not disclose sensitive personal information to us, such as data about your health, race or ethnic origin, your religion, trade union membership, sexual orientation, etc.

HOW LONG DO WE STORE YOUR PERSONAL DATA?

Your personal data is stored by us only for the period for which it is necessary to fulfill the purposes for which it was collected or processed, and for a period not longer than permitted under the applicable legislation.

5.1. The personal data of employees providing information about the employee’s work and insurance experience or certifying such (including the documents under Article 13 of the Ordinance on the work record and work experience) are stored for a period of 50 years (payrolls , employment contracts (appointment orders), reassignment orders, orders for unpaid leave over 30 working days, orders for termination of employment). All other documents related to the employment relationship are kept until the expiration of the terms for filing claims under the so-called labor disputes under Art. 358, paragraph 1 of the Criminal Code or for a period of three years, starting from the date of termination of the employment relationship.

5.2. Personal data of job applicants are stored for the duration of the process under recruitment and within 30 days of its termination, unless the applicant has consented to their data being stored for applying for future or other open positions. After the completion of the recruitment process, the job application of a person with whom an employment/civil contract has been concluded will not be stored.

5.3. The personal data of natural persons – counterparties of the Company (suppliers, customers, subcontractors, tenants, etc.), as well as of representatives or proxies of the representing counterparties – legal entities are stored for a period of 5 years, starting from the expiration of the contract or termination of the same.

5.4. The personal data of natural persons – visitors to the Vidin Plaza Retail Park are stored for a period of 1 (one) month, starting from the day of the recording.

5.5. The personal data of natural persons, users of our site vidinplaza.com, are stored only until the purposes for which they were collected or processed are fulfilled.

After the expiration of the storage periods, we take all necessary steps without undue delay to destroy the collected personal data in an appropriate manner.

WHO ELSE CAN BE THE RECIPIENT OF YOUR PERSONAL DATA?

The company may share your personal data with third parties under the following conditions:

– when assigning the processing to carry out specific processing activities by documented order of the Company to accountants, subcontractors and others;

– when it is necessary for the Company to share such personal data with its service providers, for example our technical service providers such as maintenance and hosting service providers;

– upon receipt by the Company of a request from a judicial authority or other legally authorized authority for the provision of such personal data in accordance with current legislation.

WHAT ARE YOUR RIGHTS REGARDING YOUR PERSONAL DATA?

You have the right to request from the Company:

– Access to your personal data, i.e. you have the right to know what personal data about you is being processed by us. The Company provides you, upon request, a free copy of the processed personal data relating to you. When you submit a request by electronic means, the Administrator provides the information in a widely used electronic form;

– Correction – the right to request correction of your data held by us if it is inaccurate or incomplete;

– Deletion (“right to be forgotten”). You have the possibility to request deletion of your personal data in the following cases:

a/ if the personal data are no longer necessary for the purposes for which they were collected;

b/ if the data subject exercises his right to object and there are no overriding legal grounds for the processing;

c/ if the processing was illegal;

d/ if there is a legal obligation of the administrator to delete the data.

However, the right to erasure does not apply in cases where the data is processed:

– to exercise the right to freedom of expression and the right to information;

– to comply with a legal obligation that requires processing provided for in Union law or Member State law that applies to the controller or for the performance of a task in the public interest or in the exercise of official powers that have been conferred on the controller;

– for reasons of public interest in the field of public health;

– for archiving purposes in the public interest, for scientific or historical research or for statistical purposes pursuant to Article 89(1) of Regulation (EU) 2016/679, insofar as the right to erasure is likely to make it impossible or seriously hinder the achievement of the objectives of this processing;

– for the establishment, exercise or defense of legal claims.

– Limiting the processing of your personal data. If it is necessary to check the accuracy of the data, the basis for the processing or the legality of their processing, you can request the Administrator to limit (stop) the processing of your data.

– Object to processing. Regarding data that is processed on the basis of “legitimate interest”, you have the right to object to the processing at any time and on grounds related to your specific situation. In the event of such an objection, the Administrator is obliged to terminate the processing of your personal data, unless it proves that there are compelling legitimate grounds for the processing that take precedence over your interests, rights and freedoms or in the event that the data is processed for the establishment , the exercise or defense of legal claims.

– Data portability (ie to request your personal data in a structured, widely used and machine-readable format).

– Where the processing is based on your consent, you have the right to withdraw your consent at any time.

You also have the right to file a complaint with the competent supervisory authority if you believe that your data has been processed at unlawfully by the Administrator:

Commission for the Protection of Personal Data

Headquarters and management address: Sofia 1592, “Prof. Tsvetan Lazarov” #2;

Address for correspondence: Sofia 1592, “Prof. Tsvetan Lazarov” #2;

Phone: 02 / 915 3 518;

Website: www.cpdp.bg

Email: kzld@cpdp.bg

To exercise your rights, you may contact us as set out in section 10 below “Contact About Personal Data.”