Cookies policy
cookie policy and similar technologies
1. Object and scope
1.1.
This Cookies Policy explains how LEAN BULGARIA OOD. uses cookies and other similar technologies in relation to Lean Champions Platform, Lean Champions Store and the website leanchampionscommunity.com.
1.2.
The policy shall apply to:
1) visiting the public pages of the Platform;
2) creating and using a user profile;
3) entering an individual or corporate profile;
4) use of the basket;
5) making an order;
6) choice of payment method;
7) choice of delivery method;
8) use of paid digital content;
9) use of digital service or subscription;
10) use of the training environment;
11) use of 5S, audit, reporting and other modules;
12) view embedded video, map, external form or other content;
13) granting or refusing consent for optional technologies;
14) using another functionality that stores information in the final device or receives access to already stored information.
1.3.
This policy applies not only to traditional cookies, but also to other technologies by which information can be stored or read by a computer, telephone, tablet or other terminal device.
1.4.
This policy shall apply together with:
1) The Privacy Policy;
(2) The Terms and Conditions;
3) Delivery and payment policy;
4) the information in the panel
5) the additional information displayed prior to activation of a specific external service;
6) the applicable legislation.
1.5.
The consent for optional cookies is separate from:
1) acceptance of the Terms and Conditions;
2) the execution of an order;
3) the agreement for marketing electronic communications;
4) consent to the immediate provision of digital content;
5) the request for early start of a digital service;
6) other contractual or legal statements.
1.6.
Continue browsing the site, scrolling the page, closing the banner, inactivity or use of the main features do not constitute consent for optional cookies.
1.7.
The refusal of optional cookies does not restrict the mandatory rights of the visitor and does not interfere with the use of the main content and the strictly necessary functions of the Platform.
2. Supplier data
2.1.
A provider of Lean Champions Platform and a personal data controller processed for the own purposes described in this policy shall be:
LEAN BULGARIA OOD
Unified Identification Code (UIC): 203317933
VAT identification number: BG203317933
Registered office and management address: Sofia, 55 Kiril Popov Street, entrance A, floor 1, apartment 4, Republic of Bulgaria
Manager: Todor Neychev
Email: office@lean.bg
Telephone: +359 896 060 911
Website: leanchampionscommunity.com
hereinafter referred to as "the merchant', "the supplier', "the controller', "the controller', "the us' or "ours'.
3. What cookies are
3.1.
Cookies are small files or parts of information that a website can store in the browser or the final device of the visitor.
3.2.
On a next visit, the browser can return the relevant information to the website or to the supplier who placed the technology.
3.3.
Cookies can allow the Platform to:
1) maintain an active user session;
2) recognizes that the user has entered his account;
3) remembers the contents of the basket;
4) protects forms and payments;
5) remembers selected settings;
6) record the choice for cookies;
7) identifies technical problems;
8) measures the use of pages;
9) provides external content;
10) measures the effectiveness of an advertising campaign;
11) perform another pre-explained function.
3.4.
A cookie may contain a unique identifier but does not normally contain a direct name, address or full payment card number.
3.5.
Information collected through cookies may constitute personal data where it allows the direct or indirect identification or differentiation of a natural person.
3.6.
The requirements for storing or reading information from the final device may also apply where the relevant information does not in itself represent personal data.
4. Similar technologies
4.1.
In addition to cookies, the Platform may use similar technologies, including:
1) local storage in the browser;
2) session storage;
3) pixels;
4) tags;
5) scripts;
6) development software kits;
7) device identifiers;
8) technologies for measuring openings and interactions;
9) protective tokens;
10) fraud prevention technologies;
11) other technical means by which information is stored or accessed in the final device.
4.2.
The rules of this policy apply to these technologies according to their purpose, action and legal basis.
4.3.
When a new technology is introduced, its purpose, supplier, term and category shall be added to the register of technologies used prior to its activation for visitors.
5. First and third party cookies
5.1.
Cookie on the first side is a cookie that is placed or managed by the domain of Lean Champions Platform.
5.2.
A third party cookie is a cookie that is placed or managed by an external supplier through an integrated service, external resource, embedded content or redirection.
5.3.
External suppliers may include:
1) payment operators;
2) courier and logistics providers;
3) video content platforms;
4) card services;
5) video conference services;
6) training platforms;
7) analytical services;
8) advertising platforms;
9) cybersecurity providers;
10) other technical suppliers.
5.4.
The existence of a particular category in this policy does not mean that any possible external service is actually active.
5.5.
Current suppliers and technologies are listed in the register accessible through "Cookie Settings."
6. Session and persistent cookies
6.1.
Session cookies usually only work until the browser is open and deleted at the end of the session, unless their technical characteristics provide otherwise.
6.2.
Permanent cookies remain in the device for a pre-defined period or until their removal by the user.
6.3.
Each permanent cookie shall be determined according to:
1) its purpose;
(2) the need;
3) the risk to the personal sphere;
4) security requirements;
5) the time limit set by the supplier concerned;
6) the applicable legislation.
6.4.
The specific duration of each active technology shall be indicated in the cookie register.
7. Rules on storage and access to information
7.1.
Keeping information or gaining access to information in the final device shall be carried out:
1) after providing clear and comprehensive information;
2) after providing a real choice;
3) after valid prior consent where the technology is not strictly necessary;
4) without consent only where the legal exception for strictly necessary technology is applicable.
7.2.
A technology is strictly necessary where its use is objectively necessary:
1) only for transmission of a message via an electronic communications network;
2) for the provision of a service to the information society explicitly requested by the consumer.
7.3.
The convenience of the Supplier, the general desire for statistics, advertising or improvement of consumer experience in themselves do not make the technology strictly necessary.
7.4.
In the case of optional technology, the consent shall be:
1) freely given;
2) in particular;
3) informed;
4) unambiguously;
5) given by clear affirmative action;
6) demonstrable;
7) Withdrawn at any time.
7.5.
The consent shall not be derived from:
1) silence;
2) inaction;
3) pre-checked field;
4) continuation of the examination;
5) scroll;
6) closing the window;
7) pressing a button for another primary purpose;
8) general acceptance of the Terms and Conditions.
8. Technology categories
8.1.
For their purpose, technology can be divided into:
1) strictly necessary;
2) functional and preference;
3) analytical and performance;
4) marketing and advertising;
5) external content and social functions;
6) other clearly described categories.
8.2.
Categories outside strictly required are excluded by default until the visitor makes a valid choice.
8.3.
Where a technology has more than one objective, it shall be classified according to all actual objectives and consent shall be determined according to the objective requiring higher protection.
8.4.
Technology is not marked as strictly necessary only to avoid the requirement of consent.
9. Strictly necessary cookies
9.1.
The strictly necessary technologies provide basic features explicitly requested by the visitor.
9.2.
They may be used for:
1) creating and maintaining a protected session;
2) login to a user profile;
3) authentication of identity;
4) protection against counterfeiting of applications;
5) protection of forms;
6) prevent unauthorised access;
7) management of the basket;
8) remember the selected products within the ordering process;
9) memorizing the selected delivery method during the order;
10) maintaining the technical connection;
11) load distribution;
12) remembering the choice for cookies;
13) prevention of fraud;
14) provision of payment explicitly initiated by the Client;
15) another function without which the explicitly requested service cannot be technically provided.
9.3.
Highly necessary technologies shall not be used for:
1) profiling for advertising;
2) tracking between unrelated websites;
3) measuring advertising campaigns;
4) creation of marketing audiences;
5) general analyst, which is not necessary to provide the explicitly requested service.
9.4.
No agreement is required for the strictly necessary technologies, but information is provided for them.
9.5.
The consumer may block some of these technologies through his browser, but this may lead to the inability to:
1) login to a profile;
2) keeping a basket;
3) making an order;
4) protection of a form;
5) using another basic functionality.
10. Security and authentication cookies
10.1.
Security technologies may be used for:
1) recognition of a valid session;
2) identification of unsuccessful entry attempts;
3) limiting automated attacks;
4) prevention of fraud;
5) protection of administrative functions;
6) protection of payments;
7) detection of abnormal behaviour;
8) maintaining the integrity of requests;
9) another necessary protective function.
10.2.
Where protective technology is objectively necessary for the secure provision of the explicitly requested service, it may be classified as strictly necessary.
10.3.
Protection technology shall not be used for unrelated marketing or profiling without separate relevant justification and consent.
11. Basket and ordering process
11.1.
The platform may use strictly necessary technologies for:
1) adding product to the basket;
2) keeping the selected quantity;
3) calculating the final price;
4) connecting individual steps of the order;
5) maintaining the chosen method of payment;
6) maintaining the chosen delivery method;
7) protection against double dispatch;
8) prevent loss of order when passing between pages.
11.2.
Technology necessary only to preserve the basket for an extended marketing period after leaving the site is not automatically considered strictly necessary.
11.3.
Use of an abandoned marketing basket shall only be carried out in the case of the relevant legal basis and relevant information.
12. Payments and myPOS
12.1.
When the Client selects a card payment and starts the payment process, it can be redirected to the protected environment of myPOS.
12.2.
myPOS may use its own strictly necessary technologies for:
1) secure processing of payment;
2) authentication of the transaction;
3) prevention of fraud;
4) maintaining the payment session;
5) fulfilling regulatory requirements.
12.3.
These technologies can be activated when the Client explicitly selects a card payment and starts the payment process.
12.4.
myPOS may act as an independent controller for its own processing and provide separate information on its technologies and personal data.
12.5.
Lean Champions Platform does not use the information from the payment environment for marketing tracking without a separate applicable basis.
12.6.
A payment component which includes optional analytical or advertising technologies should not activate these technologies without the necessary consent.
13. Delivery and courier functions
13.1.
Where the Client uses an integrated function to select an office, address or service of Econt or another courier, the technologies required to perform the action explicitly requested may be used.
13.2.
Such technologies may be used for:
1) loading a list of offices;
2) choice of settlement;
3) calculation of delivery;
4) keeping the selected office within the order;
5) technical interaction with the courier service.
13.3.
Where integration includes optional analytical or marketing technologies of the courier, they shall only be activated if applicable.
13.4.
The courier can process personal data and technology as an independent controller for providing its service.
14. Functional cookies and preferences
14.1.
Functional technologies allow the Platform to remember choices and settings that are not necessarily necessary for the basic service.
14.2.
They can be used for:
1) preferred language;
2) selected view;
3) text size or interface;
4) last-used section;
5) Video preferences;
6) Board settings;
7) re-visit facilities;
8) other customized settings.
14.3.
Functional technologies shall be activated after consent, unless the specific technology is strictly necessary for a function explicitly requested by the user.
14.4.
In case of failure of functional technologies, the Platform remains accessible, but some settings may not be remembered between individual visits.
15. Analytical cookies and efficiency technologies
15.1.
Analytical technologies may be used to obtain statistical information on:
1) number of visits;
2) pages used;
3) charging time;
4) technical errors;
5) the sequence of consideration;
6) the type of device used;
7) the overall interface efficiency;
8) interaction with certain functions;
9) the source of the visit;
10) other indicators for the use of the Platform.
15.2.
Information may be used for:
1) improving navigation;
2) detection of technical difficulties;
3) Evaluation of the use of functionalities;
4) development planning;
5) the creation of statistical reports.
15.3.
Analytical technologies that are not strictly necessary to provide the explicitly requested service shall be activated only after prior consent.
15.4.
The fact that analytical information is used in a summary or pseudonymised form does not automatically remove the consent requirement for the original storage or reading of information from the device.
15.5.
Where technically possible, the analytical settings shall be configured to:
1) collect a minimum amount of data;
2) limit the shelf life;
3) limit sharing;
4) exclude advertising functions;
5) abbreviate or nickname IDs;
6) do not create profiles for unrelated purposes.
15.6.
In the event of failure of analytic technologies, the main functions of the Platform continue to work.
16. Marketing and advertising technologies
16.1.
Marketing technologies can be used for:
1) measuring advertising campaign;
2) establish whether a visitor has reached the Platform through advertising;
3) limiting the frequency of display of advertising;
4) the creation of audiences;
5) Customization of advertising content;
6) re-achieve visitors via an external platform;
7) connecting interactions between different websites or applications;
8) other advertising purposes.
16.2.
Marketing technologies are not strictly necessary for the use of the Platform.
16.3.
They shall only be activated after prior, specific and informed consent.
16.4.
The refusal of marketing technology does not necessarily mean that the visitor will not see advertising, but that advertising should not be personalised through the refused technologies.
16.5.
The agreement on marketing cookies does not constitute automatic consent to receive marketing electronic communications.
16.6.
The consent for an electronic newsletter does not constitute automatic agreement for marketing cookies.
17. External video, maps and other embedded content
17.1.
The platform may contain embedded elements from external suppliers, including:
1) video items;
2) cards;
3) presentations;
4) audio materials;
5) forms;
6) training resources;
7) social publications;
8) other external components.
17.2.
The external supplier may place their cookies or obtain technical information including IP address, device, browser and interaction with the content.
17.3.
Where the external component is not strictly necessary, it shall not be loaded prior to the necessary agreement.
17.4.
Instead of automatic charging, it can be shown:
1) static replacement;
2) communication of confidentiality;
3) button
4) possibility to activate the relevant category.
17.5.
When the visitor explicitly chooses to load specific external content, he receives information about the supplier and possible technologies.
17.6.
Where reasonably possible, an alternative means of accessing basic information without activation of external marketing technologies shall be provided.
18. Social networks and sharing buttons
18.1.
A simple connection to a social network must not activate tracking technology itself before the visitor pushes the link.
18.2.
Built-in button, publication or component of a social network may transmit information to the relevant platform.
18.3.
Where such a component uses optional technologies, it shall be loaded only after consent or explicit action in the case of appropriate information provided.
18.4.
After visiting the social network, its operator processes data according to its own terms and policies.
19. Cookie banner
19.1.
Upon first visit or where a renewal of the selection is required, a cookie management window shall be displayed.
19.2.
The first layer of the window shall provide clear information on:
1) the use of cookies and similar technologies;
(2) the main objectives;
3) the existence of optional categories;
4) the right to refuse optional technologies;
5) the right to change or withdraw the choice at any time;
6) Reference to current policy.
19.3.
The first layer shall be provided with clearly visible possibilities:
1) I accept all.
2) "I refuse those who are in debt;
3) "Cookie settings."
19.4.
The possibility of withdrawal is not concealed in long text, outside the window or through a visually invisible connection.
19.5.
Buttons and texts do not form in a misleading way that unwarrantedly directs the visitor to acceptance.
19.6.
Not used:
1) pre-checked categories;
2) misleading colors;
3) vague double negatives;
4) incorrectly marked closing button;
5) a claim that cookies are mandatory when they are not;
6) repeated acceptance pressure after a valid withdrawal;
7) another manipulative structure.
19.7.
The main content of the Platform is not made available solely because of the withdrawal of optional technologies.
19.8.
A specific external function may remain unavailable where technically it cannot be provided without a chosen technology, but this is clearly explained and, where reasonably possible, an alternative is provided.
20. “Cookie settings” panel
20.1.
The panel allows the visitor to:
1) see the different categories;
2) received information about the purposes;
3) include or exclude any optional category;
4) accepts all;
5) declines all optional;
6) maintain a customized choice;
7) withdrew previous consent;
8) opened the current technology register.
20.2.
Highly necessary technologies can be labeled as always active.
20.3.
For each optional category the switch is switched off by default.
20.4.
The categories do not come together in a way that forces the visitor to accept unrelated goals simultaneously.
20.5.
Where individual suppliers process data for materially different purposes, the information shall be provided with sufficient detail.
21. Giving consent
21.1.
The visitor gives consent by:
1) pressing
2) activation of selected categories and pressing of
3) another clear affirmative action, which is specifically related to the chosen technology.
21.2.
Before consent, optional technologies remain blocked.
21.3.
The consent shall only concern:
1) the selected categories;
(2) the objectives described;
3) those suppliers;
4) the current version of the settings.
21.4.
The agreement shall not be used as a materially different new objective without new information and, where necessary, a new choice.
21.5.
Where a new supplier or a new target is added that is not covered by the previous choice, the relevant technology shall not be activated on the basis of the old consent.
22. Refusal of optional cookies
22.1.
The visitor can refuse all optional technologies through the button.
22.2.
Upon withdrawal:
1) the strictly necessary technologies remain active;
2) analytical technologies are not activated;
3) marketing technologies are not activated;
4) optional functional technologies are not activated;
5) optional external content may remain blocked.
22.3.
withdrawal does not lead to:
1) additional price;
2) withdrawal of service;
3) loss of legal law;
4) automatic termination of the profile;
5) Inability to examine the main public information.
22.4.
When the visitor does not make a choice, optional technologies remain excluded.
23. Withdrawal and modification of consent
23.1.
The consent may be withdrawn at any time.
23.2.
Withdrawal should be as easy as giving consent.
23.3.
Constantly available connection "Cookie settings" is provided at the bottom of the pages or at another easily accessible location.
23.4.
In this connection, the visitor may:
1) to see your current choice;
2) to exclude individual categories;
3) to refuse all optional technologies;
4) to make a new choice.
23.5.
Withdrawal shall take effect on the future use of the technologies concerned.
23.6.
The withdrawal shall be without prejudice to the lawfulness of the processing carried out before it.
23.7.
Where technically possible, after withdrawal, the Platform removes its optional cookies.
23.8.
Some previously stored third party technologies may need to be deleted by:
1) browser settings;
(2) the instrument of the supplier concerned;
3) another provided technical opportunity.
23.9.
The change of settings shall not require any more necessary action than the initial adoption.
24. Duration of the choice and renewed requests
24.1.
The choice concerning cookies shall be remembered for the period specified in the consent technology register.
24.2.
The choice shall not be treated as unlimited.
24.3.
A new selection may be requested at:
1) expiry of the reasonable period of the previous choice;
2) a substantial change of objectives;
3) adding a new category;
4) adding a new supplier with a substantially different activity;
5) change of legal requirements;
6) losing or erasing the selection information;
7) reasonable doubt as to the validity of the old agreement.
24.4.
The window does not appear unduly often after a valid withdrawal only in order to move the visitor to change his mind.
24.5.
If the visitor deletes the cookie that stores the choice, the platform may not recognize the previous setting and show the window again.
25. Recording and demonstrating the choice
25.1.
To prove and manage the choice we can store:
1) random consent identifier;
2) date and time;
3) selected categories;
4) refused categories;
5) version of the window;
6) version of the Cookies Policy;
7) language;
8) domain;
9) technical source of choice;
10) Limited technical information necessary to demonstrate the choice.
25.2.
No more information shall be collected than reasonably necessary to demonstrate and apply the choice.
25.3.
The consent record may also be stored after its withdrawal where necessary for:
1) proof of legality;
(2) enforcement of the objection;
3) prevent re-activating;
4) protection of legal claims.
25.4.
The detailed time limits shall be determined in accordance with the Privacy Policy.
26. Browser management
26.1.
Most browsers allow:
1) review of stored cookies;
2) delete individual or all cookies;
3) blocking cookies on the first side;
4) blocking third party cookies;
5) delete when closing;
6) limiting local storage;
7) Manage permissions on websites.
26.2.
The control mode depends on the browser and device used.
26.3.
Blocking all cookies can lead to:
1) inability to enter;
2) losing the basket;
3) Inability to send a protected form;
4) inability to maintain the choice for cookies;
5) incorrect operation of other basic functions.
26.4.
Delete through the browser does not replace the withdrawal of consent when the visitor wishes the Platform to remember its withdrawal.
26.5.
It is recommended that the selection is first changed by using the Cookie Settings (Cookie Settings) and then deleted by browser if necessary.
27. Register of used cookies and technologies
27.1.
The current register is provided via the panel "Cookie settings" or by a separate easily accessible section of this page.
27.2.
For each active technology, the register shall contain, where applicable:
1) name;
2) supplier;
3) domain;
4) category;
5) objective;
6) a description of the information processed;
7) whether it is on a first or third party;
8) whether it is session or permanent;
9) period of validity;
10) activation moment;
11) a legal basis;
12) third party access information;
13) information on transmission outside the European Economic Area;
14) Link to the information of the external supplier.
27.3.
The register shall be updated on:
1) adding technology;
2) removing technology;
3) change of supplier;
4) change of target;
5) change of time;
6) change of category;
7) change of international transmission.
27.4.
Technology not specified in the register should not intentionally be used as optional technology.
27.5.
A temporary technical device used solely to address an immediate security problem shall be documented and removed or added to the register if its use continues.
27.6.
Enumeration of possible categories in current policy does not mean that all categories are active.
27.7.
Indeed, the technologies listed in the current register are active.
28. Changes in cookies and suppliers
28.1.
Before introducing a new optional technology, verification of:
1) the objective;
(2) the need;
3) the category;
4) the supplier;
5) the time limit;
6) the data processed;
7) recipients;
8) international programmes;
9) the need for consent;
10) Technical blocking before choice.
28.2.
A new optional technology shall not be activated on the basis of old consent where the new target or supplier has not been covered by the information provided.
28.3.
Where the change is non-essential and does not extend the purpose or recipients, the register may be updated without re-applying to the extent that the previous choice remains valid.
29. Third party technology
29.1.
The external supplier may receive information where:
1) its component is charged;
2) the visitor pressed external connection;
3) The visitor activates built-in content;
4) start payment;
5) select an integrated courier function;
6) uses an external training or video conference service.
29.2.
The external supplier may combine information with information from other services where it has a relevant legal basis.
29.3.
Providers acting as independent administrators shall be responsible for their own processing.
29.4.
When a supplier processes data on behalf of LEAN BULGARIA OOD, relations are settled by contract and appropriate instructions.
29.5.
The choice of external suppliers shall be made taking into account:
1) security;
(2) confidentiality;
3) the term of technology;
4) the possibility of pre-blocking;
5) the possibility of withdrawal;
6) international programmes;
7) other applicable requirements.
30. International data transmission
30.1.
Some external providers may process information outside the European Economic Area.
30.2.
Where the information constitutes personal data, the transfer shall be carried out in the event of an applicable mechanism, including:
1) an adequate level of protection decision;
(2) standard contractual clauses;
3) binding corporate rules;
4) applicable legal exception;
5) another permissible mechanism.
30.3.
International transmission information shall be specified in the Register or in the Privacy Policy.
30.4.
The consent for a cookie does not automatically replace the requirements for the lawful international transfer of personal data.
31. Retention periods
31.1.
Each technology shall be used for a period corresponding to its purpose.
31.2.
Time limits shall be limited to what is reasonably necessary.
31.3.
Session technology shall, as a rule, be terminated after the end of the session.
31.4.
Permanent technologies shall be deleted or expired after the period specified in the register.
31.5.
The proof of choice can be kept longer than the cookie itself when it is necessary to prove compliance with the law.
31.6.
Data extracted through technology may have a different storage period specified in the Privacy Policy or the information of the supplier concerned.
32. Security
32.1.
We apply appropriate technical and organisational measures to protect information processed through cookies and similar technologies.
32.2.
The measures may include:
1) secure connection;
2) restriction of access;
3) appropriate attributes of cookies;
4) protection against intersite attacks;
5) limitation of the time limit;
6) division of categories;
7) management of suppliers;
8) recording administrative changes;
9) periodic scanning;
10) other risk measures.
32.3.
Where technically applicable, the strictly necessary certification technologies shall be configured to limit customer script access and unprotected transmission.
32.4.
No technology can guarantee absolute security, but this does not exempt the Supplier from the obligation to apply appropriate measures.
33. Rights concerning personal data
33.1.
Where the information processed through cookies constitutes personal data, the person may be entitled to:
1) information;
2) access;
3) correction;
4) delete;
5) limitation;
6) portability, where applicable;
7) an objection;
8) withdrawal of consent;
9) a complaint to a supervisory authority;
10) Judicial protection.
33.2.
The specific right depends on the type of data, legal basis and circumstances.
33.3.
Where we do not have information allowing reasonable identification of the person, it may be necessary to provide additional information.
33.4.
No new identification is required only to be associated anonymous or unidentified information with a specific person.
33.5.
Detailed information on rights is contained in the Privacy Policy.
34. Exercise of the rights
34.1.
Requests for personal data may be sent to:
LEAN BULGARIA OOD
Email: office@lean.bg
Address: Sofia, 55 Kiril Popov Str., A, floor 1, ap. 4, Republic of Bulgaria
34.2.
The theme of the electronic message may specify:
Cookies and personal data
34.3.
In order to change or withdraw the choice, it is not necessary to send a written request where this can be done by
34.4.
The GDPR requests shall be dealt with in accordance with the time limits and procedure set out in the Privacy Policy.
35. Complaint to a supervisory authority
35.1.
Where a person considers that the processing of personal data violates applicable legislation, he may lodge a complaint with the Commission for the protection of personal data.
35.2.
Contact details of the Personal Data Protection Commission:
Address: 1592 Sofia, Blvd. "Prof. Tsvetan Lazarov" No 2, Republic of Bulgaria
E-mail: kzld@cpdp.bg
Website: cpdp.bg
35.3.
Where the issue concerns storage or access to information in the final device, the powers of another competent authority under legislation may also be applicable.
35.4.
The submission of a complaint shall not be subject to a mandatory prior request to the Supplier.
35.5.
The person shall also have the right to judicial protection.
36. Policy changes
36.1.
This policy may be updated in:
1) change of legislation;
2) changing the technologies used;
3) adding or removing a supplier;
4) introducing a new module;
5) change of objectives;
6) change of time limits;
7) change of international programmes;
8) change of the consent mechanism;
9) another objective reason.
36.2.
The current version shall contain:
1) version number;
2) date of entry into force;
3) date of latest update.
36.3.
In the event of a substantial change affecting the validity or scope of the previous choice, the visitor shall receive new information and be able to make a new choice.
36.4.
The publication of a new policy does not in itself constitute an agreement on new optional technologies.
36.5.
Previous versions may be archived to demonstrate the information provided.
37. Contacts
37.1.
In the case of questions about cookies and similar technologies you can contact:
LEAN BULGARIA OOD
Unified Identification Code (UIC): 203317933
VAT identification number: BG203317933
Address: Sofia, 55 Kiril Popov Str., A, floor 1, ap. 4, Republic of Bulgaria
Email: office@lean.bg
Telephone: +359 896 060 911
Website: leanchampionscommunity.com
37.2.
In case of technical problem with the selection panel, specify:
1) the browser used;
2) the device used;
3) the approximate date and time;
4) description of the problem;
5) screenshot, where applicable.
37.3.
Do not send:
1) password;
2) full bank card number;
3) security code;
4) code for two-factor identification;
5) other unnecessary certification data.
38. Entry into force
38.1.
The current Cookies Policy shall enter into force from the date specified in the field in force of the Cookies Policy.
38.2.
The specific choice shall be subject to the version of the information shown to the visitor when giving or refusing consent.
38.3.
Where a separate provision is contrary to a binding rule of law, the legal standard shall apply without prejudice to the rest of the policy.
38.4.
The withdrawal of optional technologies shall be respected regardless of the content of the current policy.
38.5.
The current register of cookies and similar technologies actually used is an integral part of the information provided to visitors.
1. Object and scope
1.1.
This Cookies Policy explains how LEAN BULGARIA OOD. uses cookies and other similar technologies in relation to Lean Champions Platform, Lean Champions Store and the website leanchampionscommunity.com.
1.2.
The policy shall apply to:
1) visiting the public pages of the Platform;
2) creating and using a user profile;
3) entering an individual or corporate profile;
4) use of the basket;
5) making an order;
6) choice of payment method;
7) choice of delivery method;
8) use of paid digital content;
9) use of digital service or subscription;
10) use of the training environment;
11) use of 5S, audit, reporting and other modules;
12) view embedded video, map, external form or other content;
13) granting or refusing consent for optional technologies;
14) using another functionality that stores information in the final device or receives access to already stored information.
1.3.
This policy applies not only to traditional cookies, but also to other technologies by which information can be stored or read by a computer, telephone, tablet or other terminal device.
1.4.
This policy shall apply together with:
1) The Privacy Policy;
(2) The Terms and Conditions;
3) Delivery and payment policy;
4) the information in the panel
5) the additional information displayed prior to activation of a specific external service;
6) the applicable legislation.
1.5.
The consent for optional cookies is separate from:
1) acceptance of the Terms and Conditions;
2) the execution of an order;
3) the agreement for marketing electronic communications;
4) consent to the immediate provision of digital content;
5) the request for early start of a digital service;
6) other contractual or legal statements.
1.6.
Continue browsing the site, scrolling the page, closing the banner, inactivity or use of the main features do not constitute consent for optional cookies.
1.7.
The refusal of optional cookies does not restrict the mandatory rights of the visitor and does not interfere with the use of the main content and the strictly necessary functions of the Platform.
2. Supplier data
2.1.
A provider of Lean Champions Platform and a personal data controller processed for the own purposes described in this policy shall be:
LEAN BULGARIA OOD
Unified Identification Code (UIC): 203317933
VAT identification number: BG203317933
Registered office and management address: Sofia, 55 Kiril Popov Street, entrance A, floor 1, apartment 4, Republic of Bulgaria
Manager: Todor Neychev
Email: office@lean.bg
Telephone: +359 896 060 911
Website: leanchampionscommunity.com
hereinafter referred to as "the merchant', "the supplier', "the controller', "the controller', "the us' or "ours'.
3. What cookies are
3.1.
Cookies are small files or parts of information that a website can store in the browser or the final device of the visitor.
3.2.
On a next visit, the browser can return the relevant information to the website or to the supplier who placed the technology.
3.3.
Cookies can allow the Platform to:
1) maintain an active user session;
2) recognizes that the user has entered his account;
3) remembers the contents of the basket;
4) protects forms and payments;
5) remembers selected settings;
6) record the choice for cookies;
7) identifies technical problems;
8) measures the use of pages;
9) provides external content;
10) measures the effectiveness of an advertising campaign;
11) perform another pre-explained function.
3.4.
A cookie may contain a unique identifier but does not normally contain a direct name, address or full payment card number.
3.5.
Information collected through cookies may constitute personal data where it allows the direct or indirect identification or differentiation of a natural person.
3.6.
The requirements for storing or reading information from the final device may also apply where the relevant information does not in itself represent personal data.
4. Similar technologies
4.1.
In addition to cookies, the Platform may use similar technologies, including:
1) local storage in the browser;
2) session storage;
3) pixels;
4) tags;
5) scripts;
6) development software kits;
7) device identifiers;
8) technologies for measuring openings and interactions;
9) protective tokens;
10) fraud prevention technologies;
11) other technical means by which information is stored or accessed in the final device.
4.2.
The rules of this policy apply to these technologies according to their purpose, action and legal basis.
4.3.
When a new technology is introduced, its purpose, supplier, term and category shall be added to the register of technologies used prior to its activation for visitors.
5. First and third party cookies
5.1.
Cookie on the first side is a cookie that is placed or managed by the domain of Lean Champions Platform.
5.2.
A third party cookie is a cookie that is placed or managed by an external supplier through an integrated service, external resource, embedded content or redirection.
5.3.
External suppliers may include:
1) payment operators;
2) courier and logistics providers;
3) video content platforms;
4) card services;
5) video conference services;
6) training platforms;
7) analytical services;
8) advertising platforms;
9) cybersecurity providers;
10) other technical suppliers.
5.4.
The existence of a particular category in this policy does not mean that any possible external service is actually active.
5.5.
Current suppliers and technologies are listed in the register accessible through "Cookie Settings."
6. Session and persistent cookies
6.1.
Session cookies usually only work until the browser is open and deleted at the end of the session, unless their technical characteristics provide otherwise.
6.2.
Permanent cookies remain in the device for a pre-defined period or until their removal by the user.
6.3.
Each permanent cookie shall be determined according to:
1) its purpose;
(2) the need;
3) the risk to the personal sphere;
4) security requirements;
5) the time limit set by the supplier concerned;
6) the applicable legislation.
6.4.
The specific duration of each active technology shall be indicated in the cookie register.
7. Rules on storage and access to information
7.1.
Keeping information or gaining access to information in the final device shall be carried out:
1) after providing clear and comprehensive information;
2) after providing a real choice;
3) after valid prior consent where the technology is not strictly necessary;
4) without consent only where the legal exception for strictly necessary technology is applicable.
7.2.
A technology is strictly necessary where its use is objectively necessary:
1) only for transmission of a message via an electronic communications network;
2) for the provision of a service to the information society explicitly requested by the consumer.
7.3.
The convenience of the Supplier, the general desire for statistics, advertising or improvement of consumer experience in themselves do not make the technology strictly necessary.
7.4.
In the case of optional technology, the consent shall be:
1) freely given;
2) in particular;
3) informed;
4) unambiguously;
5) given by clear affirmative action;
6) demonstrable;
7) Withdrawn at any time.
7.5.
The consent shall not be derived from:
1) silence;
2) inaction;
3) pre-checked field;
4) continuation of the examination;
5) scroll;
6) closing the window;
7) pressing a button for another primary purpose;
8) general acceptance of the Terms and Conditions.
8. Technology categories
8.1.
For their purpose, technology can be divided into:
1) strictly necessary;
2) functional and preference;
3) analytical and performance;
4) marketing and advertising;
5) external content and social functions;
6) other clearly described categories.
8.2.
Categories outside strictly required are excluded by default until the visitor makes a valid choice.
8.3.
Where a technology has more than one objective, it shall be classified according to all actual objectives and consent shall be determined according to the objective requiring higher protection.
8.4.
Technology is not marked as strictly necessary only to avoid the requirement of consent.
9. Strictly necessary cookies
9.1.
The strictly necessary technologies provide basic features explicitly requested by the visitor.
9.2.
They may be used for:
1) creating and maintaining a protected session;
2) login to a user profile;
3) authentication of identity;
4) protection against counterfeiting of applications;
5) protection of forms;
6) prevent unauthorised access;
7) management of the basket;
8) remember the selected products within the ordering process;
9) memorizing the selected delivery method during the order;
10) maintaining the technical connection;
11) load distribution;
12) remembering the choice for cookies;
13) prevention of fraud;
14) provision of payment explicitly initiated by the Client;
15) another function without which the explicitly requested service cannot be technically provided.
9.3.
Highly necessary technologies shall not be used for:
1) profiling for advertising;
2) tracking between unrelated websites;
3) measuring advertising campaigns;
4) creation of marketing audiences;
5) general analyst, which is not necessary to provide the explicitly requested service.
9.4.
No agreement is required for the strictly necessary technologies, but information is provided for them.
9.5.
The consumer may block some of these technologies through his browser, but this may lead to the inability to:
1) login to a profile;
2) keeping a basket;
3) making an order;
4) protection of a form;
5) using another basic functionality.
10. Security and authentication cookies
10.1.
Security technologies may be used for:
1) recognition of a valid session;
2) identification of unsuccessful entry attempts;
3) limiting automated attacks;
4) prevention of fraud;
5) protection of administrative functions;
6) protection of payments;
7) detection of abnormal behaviour;
8) maintaining the integrity of requests;
9) another necessary protective function.
10.2.
Where protective technology is objectively necessary for the secure provision of the explicitly requested service, it may be classified as strictly necessary.
10.3.
Protection technology shall not be used for unrelated marketing or profiling without separate relevant justification and consent.
11. Basket and ordering process
11.1.
The platform may use strictly necessary technologies for:
1) adding product to the basket;
2) keeping the selected quantity;
3) calculating the final price;
4) connecting individual steps of the order;
5) maintaining the chosen method of payment;
6) maintaining the chosen delivery method;
7) protection against double dispatch;
8) prevent loss of order when passing between pages.
11.2.
Technology necessary only to preserve the basket for an extended marketing period after leaving the site is not automatically considered strictly necessary.
11.3.
Use of an abandoned marketing basket shall only be carried out in the case of the relevant legal basis and relevant information.
12. Payments and myPOS
12.1.
When the Client selects a card payment and starts the payment process, it can be redirected to the protected environment of myPOS.
12.2.
myPOS may use its own strictly necessary technologies for:
1) secure processing of payment;
2) authentication of the transaction;
3) prevention of fraud;
4) maintaining the payment session;
5) fulfilling regulatory requirements.
12.3.
These technologies can be activated when the Client explicitly selects a card payment and starts the payment process.
12.4.
myPOS may act as an independent controller for its own processing and provide separate information on its technologies and personal data.
12.5.
Lean Champions Platform does not use the information from the payment environment for marketing tracking without a separate applicable basis.
12.6.
A payment component which includes optional analytical or advertising technologies should not activate these technologies without the necessary consent.
13. Delivery and courier functions
13.1.
Where the Client uses an integrated function to select an office, address or service of Econt or another courier, the technologies required to perform the action explicitly requested may be used.
13.2.
Such technologies may be used for:
1) loading a list of offices;
2) choice of settlement;
3) calculation of delivery;
4) keeping the selected office within the order;
5) technical interaction with the courier service.
13.3.
Where integration includes optional analytical or marketing technologies of the courier, they shall only be activated if applicable.
13.4.
The courier can process personal data and technology as an independent controller for providing its service.
14. Functional cookies and preferences
14.1.
Functional technologies allow the Platform to remember choices and settings that are not necessarily necessary for the basic service.
14.2.
They can be used for:
1) preferred language;
2) selected view;
3) text size or interface;
4) last-used section;
5) Video preferences;
6) Board settings;
7) re-visit facilities;
8) other customized settings.
14.3.
Functional technologies shall be activated after consent, unless the specific technology is strictly necessary for a function explicitly requested by the user.
14.4.
In case of failure of functional technologies, the Platform remains accessible, but some settings may not be remembered between individual visits.
15. Analytical cookies and efficiency technologies
15.1.
Analytical technologies may be used to obtain statistical information on:
1) number of visits;
2) pages used;
3) charging time;
4) technical errors;
5) the sequence of consideration;
6) the type of device used;
7) the overall interface efficiency;
8) interaction with certain functions;
9) the source of the visit;
10) other indicators for the use of the Platform.
15.2.
Information may be used for:
1) improving navigation;
2) detection of technical difficulties;
3) Evaluation of the use of functionalities;
4) development planning;
5) the creation of statistical reports.
15.3.
Analytical technologies that are not strictly necessary to provide the explicitly requested service shall be activated only after prior consent.
15.4.
The fact that analytical information is used in a summary or pseudonymised form does not automatically remove the consent requirement for the original storage or reading of information from the device.
15.5.
Where technically possible, the analytical settings shall be configured to:
1) collect a minimum amount of data;
2) limit the shelf life;
3) limit sharing;
4) exclude advertising functions;
5) abbreviate or nickname IDs;
6) do not create profiles for unrelated purposes.
15.6.
In the event of failure of analytic technologies, the main functions of the Platform continue to work.
16. Marketing and advertising technologies
16.1.
Marketing technologies can be used for:
1) measuring advertising campaign;
2) establish whether a visitor has reached the Platform through advertising;
3) limiting the frequency of display of advertising;
4) the creation of audiences;
5) Customization of advertising content;
6) re-achieve visitors via an external platform;
7) connecting interactions between different websites or applications;
8) other advertising purposes.
16.2.
Marketing technologies are not strictly necessary for the use of the Platform.
16.3.
They shall only be activated after prior, specific and informed consent.
16.4.
The refusal of marketing technology does not necessarily mean that the visitor will not see advertising, but that advertising should not be personalised through the refused technologies.
16.5.
The agreement on marketing cookies does not constitute automatic consent to receive marketing electronic communications.
16.6.
The consent for an electronic newsletter does not constitute automatic agreement for marketing cookies.
17. External video, maps and other embedded content
17.1.
The platform may contain embedded elements from external suppliers, including:
1) video items;
2) cards;
3) presentations;
4) audio materials;
5) forms;
6) training resources;
7) social publications;
8) other external components.
17.2.
The external supplier may place their cookies or obtain technical information including IP address, device, browser and interaction with the content.
17.3.
Where the external component is not strictly necessary, it shall not be loaded prior to the necessary agreement.
17.4.
Instead of automatic charging, it can be shown:
1) static replacement;
2) communication of confidentiality;
3) button
4) possibility to activate the relevant category.
17.5.
When the visitor explicitly chooses to load specific external content, he receives information about the supplier and possible technologies.
17.6.
Where reasonably possible, an alternative means of accessing basic information without activation of external marketing technologies shall be provided.
18. Social networks and sharing buttons
18.1.
A simple connection to a social network must not activate tracking technology itself before the visitor pushes the link.
18.2.
Built-in button, publication or component of a social network may transmit information to the relevant platform.
18.3.
Where such a component uses optional technologies, it shall be loaded only after consent or explicit action in the case of appropriate information provided.
18.4.
After visiting the social network, its operator processes data according to its own terms and policies.
19. Cookie banner
19.1.
Upon first visit or where a renewal of the selection is required, a cookie management window shall be displayed.
19.2.
The first layer of the window shall provide clear information on:
1) the use of cookies and similar technologies;
(2) the main objectives;
3) the existence of optional categories;
4) the right to refuse optional technologies;
5) the right to change or withdraw the choice at any time;
6) Reference to current policy.
19.3.
The first layer shall be provided with clearly visible possibilities:
1) I accept all.
2) "I refuse those who are in debt;
3) "Cookie settings."
19.4.
The possibility of withdrawal is not concealed in long text, outside the window or through a visually invisible connection.
19.5.
Buttons and texts do not form in a misleading way that unwarrantedly directs the visitor to acceptance.
19.6.
Not used:
1) pre-checked categories;
2) misleading colors;
3) vague double negatives;
4) incorrectly marked closing button;
5) a claim that cookies are mandatory when they are not;
6) repeated acceptance pressure after a valid withdrawal;
7) another manipulative structure.
19.7.
The main content of the Platform is not made available solely because of the withdrawal of optional technologies.
19.8.
A specific external function may remain unavailable where technically it cannot be provided without a chosen technology, but this is clearly explained and, where reasonably possible, an alternative is provided.
20. “Cookie settings” panel
20.1.
The panel allows the visitor to:
1) see the different categories;
2) received information about the purposes;
3) include or exclude any optional category;
4) accepts all;
5) declines all optional;
6) maintain a customized choice;
7) withdrew previous consent;
8) opened the current technology register.
20.2.
Highly necessary technologies can be labeled as always active.
20.3.
For each optional category the switch is switched off by default.
20.4.
The categories do not come together in a way that forces the visitor to accept unrelated goals simultaneously.
20.5.
Where individual suppliers process data for materially different purposes, the information shall be provided with sufficient detail.
21. Giving consent
21.1.
The visitor gives consent by:
1) pressing
2) activation of selected categories and pressing of
3) another clear affirmative action, which is specifically related to the chosen technology.
21.2.
Before consent, optional technologies remain blocked.
21.3.
The consent shall only concern:
1) the selected categories;
(2) the objectives described;
3) those suppliers;
4) the current version of the settings.
21.4.
The agreement shall not be used as a materially different new objective without new information and, where necessary, a new choice.
21.5.
Where a new supplier or a new target is added that is not covered by the previous choice, the relevant technology shall not be activated on the basis of the old consent.
22. Refusal of optional cookies
22.1.
The visitor can refuse all optional technologies through the button.
22.2.
Upon withdrawal:
1) the strictly necessary technologies remain active;
2) analytical technologies are not activated;
3) marketing technologies are not activated;
4) optional functional technologies are not activated;
5) optional external content may remain blocked.
22.3.
withdrawal does not lead to:
1) additional price;
2) withdrawal of service;
3) loss of legal law;
4) automatic termination of the profile;
5) Inability to examine the main public information.
22.4.
When the visitor does not make a choice, optional technologies remain excluded.
23. Withdrawal and modification of consent
23.1.
The consent may be withdrawn at any time.
23.2.
Withdrawal should be as easy as giving consent.
23.3.
Constantly available connection "Cookie settings" is provided at the bottom of the pages or at another easily accessible location.
23.4.
In this connection, the visitor may:
1) to see your current choice;
2) to exclude individual categories;
3) to refuse all optional technologies;
4) to make a new choice.
23.5.
Withdrawal shall take effect on the future use of the technologies concerned.
23.6.
The withdrawal shall be without prejudice to the lawfulness of the processing carried out before it.
23.7.
Where technically possible, after withdrawal, the Platform removes its optional cookies.
23.8.
Some previously stored third party technologies may need to be deleted by:
1) browser settings;
(2) the instrument of the supplier concerned;
3) another provided technical opportunity.
23.9.
The change of settings shall not require any more necessary action than the initial adoption.
24. Duration of the choice and renewed requests
24.1.
The choice concerning cookies shall be remembered for the period specified in the consent technology register.
24.2.
The choice shall not be treated as unlimited.
24.3.
A new selection may be requested at:
1) expiry of the reasonable period of the previous choice;
2) a substantial change of objectives;
3) adding a new category;
4) adding a new supplier with a substantially different activity;
5) change of legal requirements;
6) losing or erasing the selection information;
7) reasonable doubt as to the validity of the old agreement.
24.4.
The window does not appear unduly often after a valid withdrawal only in order to move the visitor to change his mind.
24.5.
If the visitor deletes the cookie that stores the choice, the platform may not recognize the previous setting and show the window again.
25. Recording and demonstrating the choice
25.1.
To prove and manage the choice we can store:
1) random consent identifier;
2) date and time;
3) selected categories;
4) refused categories;
5) version of the window;
6) version of the Cookies Policy;
7) language;
8) domain;
9) technical source of choice;
10) Limited technical information necessary to demonstrate the choice.
25.2.
No more information shall be collected than reasonably necessary to demonstrate and apply the choice.
25.3.
The consent record may also be stored after its withdrawal where necessary for:
1) proof of legality;
(2) enforcement of the objection;
3) prevent re-activating;
4) protection of legal claims.
25.4.
The detailed time limits shall be determined in accordance with the Privacy Policy.
26. Browser management
26.1.
Most browsers allow:
1) review of stored cookies;
2) delete individual or all cookies;
3) blocking cookies on the first side;
4) blocking third party cookies;
5) delete when closing;
6) limiting local storage;
7) Manage permissions on websites.
26.2.
The control mode depends on the browser and device used.
26.3.
Blocking all cookies can lead to:
1) inability to enter;
2) losing the basket;
3) Inability to send a protected form;
4) inability to maintain the choice for cookies;
5) incorrect operation of other basic functions.
26.4.
Delete through the browser does not replace the withdrawal of consent when the visitor wishes the Platform to remember its withdrawal.
26.5.
It is recommended that the selection is first changed by using the Cookie Settings (Cookie Settings) and then deleted by browser if necessary.
27. Register of used cookies and technologies
27.1.
The current register is provided via the panel "Cookie settings" or by a separate easily accessible section of this page.
27.2.
For each active technology, the register shall contain, where applicable:
1) name;
2) supplier;
3) domain;
4) category;
5) objective;
6) a description of the information processed;
7) whether it is on a first or third party;
8) whether it is session or permanent;
9) period of validity;
10) activation moment;
11) a legal basis;
12) third party access information;
13) information on transmission outside the European Economic Area;
14) Link to the information of the external supplier.
27.3.
The register shall be updated on:
1) adding technology;
2) removing technology;
3) change of supplier;
4) change of target;
5) change of time;
6) change of category;
7) change of international transmission.
27.4.
Technology not specified in the register should not intentionally be used as optional technology.
27.5.
A temporary technical device used solely to address an immediate security problem shall be documented and removed or added to the register if its use continues.
27.6.
Enumeration of possible categories in current policy does not mean that all categories are active.
27.7.
Indeed, the technologies listed in the current register are active.
28. Changes in cookies and suppliers
28.1.
Before introducing a new optional technology, verification of:
1) the objective;
(2) the need;
3) the category;
4) the supplier;
5) the time limit;
6) the data processed;
7) recipients;
8) international programmes;
9) the need for consent;
10) Technical blocking before choice.
28.2.
A new optional technology shall not be activated on the basis of old consent where the new target or supplier has not been covered by the information provided.
28.3.
Where the change is non-essential and does not extend the purpose or recipients, the register may be updated without re-applying to the extent that the previous choice remains valid.
29. Third party technology
29.1.
The external supplier may receive information where:
1) its component is charged;
2) the visitor pressed external connection;
3) The visitor activates built-in content;
4) start payment;
5) select an integrated courier function;
6) uses an external training or video conference service.
29.2.
The external supplier may combine information with information from other services where it has a relevant legal basis.
29.3.
Providers acting as independent administrators shall be responsible for their own processing.
29.4.
When a supplier processes data on behalf of LEAN BULGARIA OOD, relations are settled by contract and appropriate instructions.
29.5.
The choice of external suppliers shall be made taking into account:
1) security;
(2) confidentiality;
3) the term of technology;
4) the possibility of pre-blocking;
5) the possibility of withdrawal;
6) international programmes;
7) other applicable requirements.
30. International data transmission
30.1.
Some external providers may process information outside the European Economic Area.
30.2.
Where the information constitutes personal data, the transfer shall be carried out in the event of an applicable mechanism, including:
1) an adequate level of protection decision;
(2) standard contractual clauses;
3) binding corporate rules;
4) applicable legal exception;
5) another permissible mechanism.
30.3.
International transmission information shall be specified in the Register or in the Privacy Policy.
30.4.
The consent for a cookie does not automatically replace the requirements for the lawful international transfer of personal data.
31. Retention periods
31.1.
Each technology shall be used for a period corresponding to its purpose.
31.2.
Time limits shall be limited to what is reasonably necessary.
31.3.
Session technology shall, as a rule, be terminated after the end of the session.
31.4.
Permanent technologies shall be deleted or expired after the period specified in the register.
31.5.
The proof of choice can be kept longer than the cookie itself when it is necessary to prove compliance with the law.
31.6.
Data extracted through technology may have a different storage period specified in the Privacy Policy or the information of the supplier concerned.
32. Security
32.1.
We apply appropriate technical and organisational measures to protect information processed through cookies and similar technologies.
32.2.
The measures may include:
1) secure connection;
2) restriction of access;
3) appropriate attributes of cookies;
4) protection against intersite attacks;
5) limitation of the time limit;
6) division of categories;
7) management of suppliers;
8) recording administrative changes;
9) periodic scanning;
10) other risk measures.
32.3.
Where technically applicable, the strictly necessary certification technologies shall be configured to limit customer script access and unprotected transmission.
32.4.
No technology can guarantee absolute security, but this does not exempt the Supplier from the obligation to apply appropriate measures.
33. Rights concerning personal data
33.1.
Where the information processed through cookies constitutes personal data, the person may be entitled to:
1) information;
2) access;
3) correction;
4) delete;
5) limitation;
6) portability, where applicable;
7) an objection;
8) withdrawal of consent;
9) a complaint to a supervisory authority;
10) Judicial protection.
33.2.
The specific right depends on the type of data, legal basis and circumstances.
33.3.
Where we do not have information allowing reasonable identification of the person, it may be necessary to provide additional information.
33.4.
No new identification is required only to be associated anonymous or unidentified information with a specific person.
33.5.
Detailed information on rights is contained in the Privacy Policy.
34. Exercise of the rights
34.1.
Requests for personal data may be sent to:
LEAN BULGARIA OOD
Email: office@lean.bg
Address: Sofia, 55 Kiril Popov Str., A, floor 1, ap. 4, Republic of Bulgaria
34.2.
The theme of the electronic message may specify:
Cookies and personal data
34.3.
In order to change or withdraw the choice, it is not necessary to send a written request where this can be done by
34.4.
The GDPR requests shall be dealt with in accordance with the time limits and procedure set out in the Privacy Policy.
35. Complaint to a supervisory authority
35.1.
Where a person considers that the processing of personal data violates applicable legislation, he may lodge a complaint with the Commission for the protection of personal data.
35.2.
Contact details of the Personal Data Protection Commission:
Address: 1592 Sofia, Blvd. "Prof. Tsvetan Lazarov" No 2, Republic of Bulgaria
E-mail: kzld@cpdp.bg
Website: cpdp.bg
35.3.
Where the issue concerns storage or access to information in the final device, the powers of another competent authority under legislation may also be applicable.
35.4.
The submission of a complaint shall not be subject to a mandatory prior request to the Supplier.
35.5.
The person shall also have the right to judicial protection.
36. Policy changes
36.1.
This policy may be updated in:
1) change of legislation;
2) changing the technologies used;
3) adding or removing a supplier;
4) introducing a new module;
5) change of objectives;
6) change of time limits;
7) change of international programmes;
8) change of the consent mechanism;
9) another objective reason.
36.2.
The current version shall contain:
1) version number;
2) date of entry into force;
3) date of latest update.
36.3.
In the event of a substantial change affecting the validity or scope of the previous choice, the visitor shall receive new information and be able to make a new choice.
36.4.
The publication of a new policy does not in itself constitute an agreement on new optional technologies.
36.5.
Previous versions may be archived to demonstrate the information provided.
37. Contacts
37.1.
In the case of questions about cookies and similar technologies you can contact:
LEAN BULGARIA OOD
Unified Identification Code (UIC): 203317933
VAT identification number: BG203317933
Address: Sofia, 55 Kiril Popov Str., A, floor 1, ap. 4, Republic of Bulgaria
Email: office@lean.bg
Telephone: +359 896 060 911
Website: leanchampionscommunity.com
37.2.
In case of technical problem with the selection panel, specify:
1) the browser used;
2) the device used;
3) the approximate date and time;
4) description of the problem;
5) screenshot, where applicable.
37.3.
Do not send:
1) password;
2) full bank card number;
3) security code;
4) code for two-factor identification;
5) other unnecessary certification data.
38. Entry into force
38.1.
The current Cookies Policy shall enter into force from the date specified in the field in force of the Cookies Policy.
38.2.
The specific choice shall be subject to the version of the information shown to the visitor when giving or refusing consent.
38.3.
Where a separate provision is contrary to a binding rule of law, the legal standard shall apply without prejudice to the rest of the policy.
38.4.
The withdrawal of optional technologies shall be respected regardless of the content of the current policy.
38.5.
The current register of cookies and similar technologies actually used is an integral part of the information provided to visitors.