Privacy Policy
Privacy policy and protection of personal data
1. Object and scope
1.1.
This Privacy Policy governs the way that LEAN BULGARIA OOD collects, receives, uses, stores, organizes, changes, provides, restricts, deletes and otherwise processes personal data in relation to Lean Champions Platform, Lean Champions Store and related products, services and functionalities.
1.2.
The policy shall apply to:
1) visiting and using the website leanchampionscommunity.com;
2) creating and using a user profile;
3) use of an individual, team or corporate profile;
4) execution and execution of orders;
5) purchase and delivery of physical goods;
6) purchase and supply of digital content;
7) activation and use of digital services;
8) purchase and use of subscription access;
9) participation in remote, online or presence training;
10) participation in webinars, seminars, events and consultations;
11) use of 5S, audit, reporting, training and other Platform modules;
12) submitting an inquiry, application for withdrawal, request for return, claim, complaint or other request;
13) making payment through myPOS, bank transfer, cash on delivery or other active method;
14) communication with the merchant;
15) receiving contractual, informational or marketing messages;
16) use of cookies and similar technologies;
17) ensuring the security and proper functioning of the Platform.
1.3.
The policy shall apply to the personal data of:
1) visitors to the website;
2) registered users;
3) clients and recipients of orders;
4) participants in training;
5) representatives, employees and contact persons of corporate clients;
6) administrators of company profiles;
7) persons included in uploaded material, photos, audits, reports or other records;
8) persons associated with the merchant;
9) persons exercising rights under the legislation on the protection of personal data;
10) other natural persons whose data are lawfully processed through the Platform.
1.4.
Data concerning legal persons shall not constitute personal data unless the information identifies or may be related to a specific natural person, such as a manager, employee, representative or contact person.
1.5.
This policy provides information pursuant to Regulation (EU) 2016/679, hereinafter referred to as "GDPR', the Personal Data Protection Act and other applicable legislation.
1.6.
Acquaintance with this Privacy Policy does not constitute an agreement on all the processing activities described.
1.7.
Where the processing requires consent, it shall be requested separately, for a specific purpose, by clear affirmative action and without pre-aligned field.
1.8.
The policy shall apply together with:
1) the Terms and Conditions;
2) Cookies Policy;
3) Delivery and payment policy;
4) The policy on the right of withdrawal;
5) Return policy;
6) The complaint policy;
7) the conditions of the particular product or service;
8) the additional notifications shown in individual functionalities;
9) personal data processing contracts with corporate clients where applicable.
2. Data controller
2.1.
Personal data controller processed for the own purposes of Lean Champions Platform and Lean Champions Store is:
LEAN BULGARIA OOD
Unified Identification Code (UIC): 203317933
VAT identification number: BG203317933
Registered office and management address: Sofia, 55 Kiril Popov Street, entrance A, floor 1, apartment 4, Republic of Bulgaria
Manager: Todor Neychev
Email: office@lean.bg
Telephone: +359 896 060 911
Website: leanchampionscommunity.com
hereinafter referred to as "the merchant', "the controller', "the controller', "the person', "the us' or "ours'.
2.2.
On issues concerning the protection of personal data in the topic of electronic communication, it may be stated:
Personal data.
2.3.
The merchant shall determine the purposes and means of processing personal data when acting as an controller.
2.4.
When processing data on behalf of a corporate client and only on its documented order, the merchant may act as a processor.
3. Basic concepts
3.1.
“Personal data” means any information relating to an identified or identifiable natural person.
3.2.
The data subject is the natural person to whom the personal data relate.
3.3.
“Processing” means any operation or set of operations on personal data, including collection, recording, organisation, structuring, storage, alteration, retrieval, consultation, use, disclosure, restriction, erasure or destruction.
3.4.
“Controller” means the person who determines the purposes and means of processing.
3.5.
The processor is the person who processes personal data on behalf of the controller.
3.6.
“Recipient” means a person, organisation or authority to which personal data are disclosed.
3.7.
“Consent” means a freely given, specific, informed and unambiguous indication of the data subject’s wishes.
3.8.
“Pseudonymisation” means processing that prevents data from being attributed to a specific person without additional information kept separately.
3.9.
"Anonymised data' is data that cannot be reasonably related to a specific natural person.
3.10.
A personal data breach is an infringement which leads to accidental or unlawful destruction, loss, modification, unauthorised disclosure or access to personal data.
3.11.
"Corporate client" is an organisation that buys or manages access to the Platform for its employees, representatives, counterparties or other authorised users.
3.12.
The information, documents, photos, recordings, audits, reports, tasks, comments and other data entered or uploaded by a client or its users is client content.
4. Roles in Processing
4.1.
The merchant shall act as an independent controller with regard to data processed for:
1) website management;
2) registration and management of user profiles;
3) conclusion and execution of contracts;
4) processing of orders;
5) payments and accounting;
6) supply of physical goods;
7) provision of digital content and digital services;
8) conducting trainings;
9) customer service;
10) consideration of refusals, returns and claims;
11) security protection;
12) prevention of fraud;
13) the fulfilment of legal obligations;
14) protection of legal claims;
15) own marketing communication.
4.2.
The corporate client shall normally act as an controller in relation to the personal data that he or his users enter into the Platform for their own organisational purposes, including data concerning:
1) employees;
(2) operators;
3) Heads;
4) auditors;
5) participants in 5S checks;
6) persons responsible for corrective actions;
7) participants in training;
8) internal users;
9) other persons designated by the corporate client.
4.3.
When processing customer content under a documented order of the corporate client, the merchant may act as a processor.
4.4.
The relationship between the corporate client and the merchant may be further settled by contract or application for processing of personal data.
4.5.
The corporate client shall be responsible for:
1) has a valid legal basis for the data entered;
(2) provide the necessary information to the persons concerned;
3) enter only data necessary for its legal purposes;
4) lays down appropriate access rights;
5) update and correct inaccurate data;
6) not use the Platform for unlawful surveillance;
7) does not upload unnecessary special categories of data;
8) gives legal instructions to the Merchant.
4.6.
Where a data subject requests data for which the corporate client is an controller, the merchant may:
1) forward the request to the corporate client;
(2) inform the person who is the relevant controller;
3) to assist the corporate client within the framework of their contractual and legal obligations.
4.7.
The merchant shall not determine independently the objectives for which the corporate client uses the internal data uploaded by him, except as regards its own security, maintenance, billing and enforcement objectives.
5. Processing principles
5.1.
Personal data shall be processed in accordance with the following principles:
1) the legality;
2) good faith;
3) transparency;
4) limitation of the objectives;
5) minimise data;
6) accuracy;
7) a storage restriction;
8) integrity;
9) confidentiality;
10) reporting.
5.2.
The merchant shall endeavour to process only personal data that are appropriate, connected and limited to what is necessary for the particular purpose.
5.3.
The merchant shall take reasonable action to correct or delete inaccurate data when notified of inaccurateness.
5.4.
Personal data shall not be used for a new incompatible purpose without further legal basis and necessary information to the data subject.
6. Categories of data subjects
6.1.
We can process personal data on:
1) visitors to the Platform;
2) customers;
3) recipients of consignments;
4) payloads;
5) bank account holders;
6) registered users;
7) Profile administrators;
8) representatives of legal entities;
9) employees and associates of corporate clients;
10) participants in trainings and events;
11) trainers and lecturers;
12) persons making inquiries;
13) persons applying for withdrawal;
14) persons making claims;
15) persons included in consumer content;
16) visitors, whether or not they refused to consent to cookies;
17) persons subscribed for marketing communication;
18) persons for whom we are obliged to process data under law.
7. Identification data
7.1.
Depending on the service used, we can process:
1) name;
2) last name;
3) username;
4) internal profile identifier;
5) client number;
6) participant number;
7) certificate number;
8) Signature when required for paper document;
9) a position;
10) organisation;
11) Department;
12) professional role;
13) a business identifier when introduced by a corporate client;
14) other identification information necessary for the specific service.
7.2.
As a rule, we do not require a single civil number, an ID number or a copy of an identity document for a simple registration or order.
7.3.
An identity document may only be requested where it is lawful, necessary and proportionate, for example, to verify identity on a specific request or to prevent fraud.
7.4.
Where sufficient, the unnecessary data in the document must be deleted.
8. Contact details
8.1.
We can process:
1) e-mail address;
2) telephone number;
3) delivery address;
4) billing address;
5) address for correspondence;
6) Selected courier office;
7) Place of residence;
8) postal code;
9) State;
10) working contact details;
11) Preferred communication channel.
9. User profile data
9.1.
When creating and using a profile we can process:
1) username;
2) e-mail address;
3) cryptographically protected presentation of the password;
4) role and level of access;
5) organisation;
6) language settings;
7) Profile settings;
8) date of registration;
9) date of confirmation of the e-mail address;
10) date of last entry;
11) Profile status;
12) activated products and modules;
13) start and end of access;
14) number of authorised users;
15) History of changes in the profile;
16) information about invitations to other users;
17) used functions;
18) administrative actions;
19) information on blocking, refund or termination of access.
9.2.
Passwords are not stored in visible and readable text when the system is technically configured according to the security measures applied.
9.3.
The merchant never requires the user to send his password by email.
10. Order details
10.1.
When performing an order we can process:
1) order number;
2) date and time;
3) selected products and services;
4) quantities;
5) single and general prices;
6) applied discounts;
7) currency;
8) taxes;
9) delivery costs;
10) chosen method of payment;
11) Selected delivery method;
12) the status of the order;
13) history of changes;
14) contractual consents granted;
15) version of the accepted Terms and Conditions;
16) version of policies;
17) date and time of the explicit consents given;
18) activation information;
19) cancellation information;
20) refund information;
21) contractual correspondence;
22) other data necessary to implement and prove the contract.
11. Delivery data
11.1.
For delivery of physical goods we can process:
1) name of the recipient;
2) telephone;
(3) e-mail address;
4) address;
5) Selected office of Econt;
6) Additional delivery instructions;
7) bill of lading number;
8) value of the consignment;
9) amount of the imposed payment;
10) content of the consignment in the required volume;
11) Delivery status;
12) date of dispatch;
13) date of receipt;
14) information on the consignment not received or returned;
15) fault protocols;
16) communication with the courier;
17) other information required for the courier service.
11.2.
The data shall be provided to the courier only in the volume required for delivery, collection of required payment, tracking and problem-solving.
12. Data on card payments through myPOS
12.1.
When payment by bank card via myPOS, the merchant may receive and store limited information such as:
1) transaction identifier;
2) order number;
3) size and currency;
4) date and time;
5) status of payment;
6) status of refund;
7) partially masked payment instrument data where provided;
8) type of card scheme;
9) code or description of the result;
10) information necessary to prevent fraud;
11) correspondence on payment;
12) details of dispute, refund or verification.
12.2.
The merchant does not receive or store:
1) the full number of the bank card;
(2) the security code;
3) the personal identification number;
4) password for banking application;
5) Full certification card data.
12.3.
Full payment data shall be entered into the protected environment of myPOS or any other designated authorised payment service provider.
12.4.
myPOS may process personal data as an independent controller for the provision of the payment service, fraud prevention, regulatory obligations and other own legal purposes.
12.5.
The processing by myPOS is also governed by its own confidentiality information.
13. Bank transfer data
13.1.
When the bank payment is activated, we can process:
1) name of the orderer;
2) name of the account holder;
3) IBAN;
4) BIC;
5) Bank;
6) amount and currency of the translation;
7) date of order and receipt;
8) reason for payment;
9) order number;
10) status of payment;
11) data on partial, overpaid or late payment;
12) refund information;
13) correspondence on translation.
13.2.
Bank data shall be used for:
1) identification of the payment;
2) connection to the order;
3) accounting;
4) refund of an amount;
5) preventing errors and fraud;
6) fulfillment of legal obligations.
13.3.
Banks and payment service providers shall process the data and as independent administrators in accordance with their own legal obligations.
14. Invoicing and accounting data
14.1.
When issuing accounting documents, we can process:
1) name and surname;
2) name of organisation;
3) EIC or other registration number;
4) VAT identification number;
5) address;
6) name of the representing person;
7) contact person;
8) e-mail address;
9) order details;
10) payment details;
11) content and value of the invoice;
12) Other legally required props.
14.2.
Information relating only to a legal person is not personal but the data of representing, contact persons and individuals shall be protected under this policy.
15. Digital content and platform access data
15.1.
When providing digital content or digital service we can process:
1) purchased product;
2) activated plan;
3) activated modules;
4) date and time of activation;
5) Initial and deadline;
6) number of authorised users;
7) downloads;
8) access to materials;
9) progress;
10) successfully completed modules;
11) technical events;
12) actions in the profile;
13) history of licenses;
14) used device and browser;
15) maintenance information;
16) termination or renewal data.
15.2.
Those data shall be processed for the provision of agreed access, licence control, security, technical support and proof of performance.
16. Data from 5S, audit and organisational modules
16.1.
When using company functionalities can be processed:
1) name of organisation;
2) object name;
3) production area;
4) Department;
5) place of work;
6) name or auditor identifier;
7) name or identifier of a responsible person;
8) audit result;
9) findings;
10) corrective actions;
11) time limits;
12) comments;
13) photos;
14) attachments;
15) history of changes;
16) Statuses;
17) date and time;
18) Signature or electronic confirmation;
19) other information introduced by the corporate client.
16.2.
The corporate client shall determine what data to be entered and shall be responsible for making them necessary and legal.
16.3.
The platform should not be used for hidden surveillance, disproportionate monitoring or automatic evaluation of employees without appropriate legal basis and transparency.
16.4.
Where an audit or a report can be drawn up without indicating the full name of an employee, the corporate client should use less identifiable information.
17. Photos, images and media files
17.1.
Users can upload photos and other files for:
1) 5S audits;
2) proof of a condition before and after action;
3) documenting discrepancies;
4) instructions;
5) training;
6) claims;
7) technical support;
8) other authorised targets.
17.2.
Photos may contain personal data when showing:
1) person;
2) work card;
3) a name plate;
4) Signature;
5) registration number;
6) document;
7) computer screen;
8) working schedule;
9) other identifying information.
17.3.
The consumer and the corporate client shall:
1) do not film persons when this is not necessary;
(2) avoid uploading of personal documents;
3) to hide unrelated personal data;
4) use a blur or cut, where appropriate;
5) inform the persons concerned;
6) have a valid legal basis;
7) limit access to photos.
17.4.
Audit photos shall not be used for public marketing without a separate applicable legal basis.
18. Data on trainings and events
18.1.
When recording and participating in training we can process:
1) name;
2) e-mail address;
3) telephone;
4) organisation;
5) position;
6) selected training;
7) date and format;
8) Payment status;
9) presence;
10) participation;
11) progress;
12) completed jobs;
13) test results;
14) feedback received;
15) communication with the trainer;
16) technical details for inclusion;
17) preferred language;
18) necessary information for a certificate;
19) data for cancellation or transfer of participation;
20) other data needed to provide training.
18.2.
Where training is conducted through an external platform for video conferences or e-learning, the necessary data may be provided to the supplier concerned.
18.3.
Where training is recorded, participants shall be informed in advance of:
1) the fact of the recording;
2) the objective;
3) scope;
4) the storage period;
5) persons who will have access;
6) how to exercise rights.
18.4.
The recording is not used for advertising purposes only because the person was involved in the training.
18.5.
The use of an image, voice, name or statement for public advertising content shall be carried out in the event of a separate appropriate legal basis.
19. Certificate details
19.1.
To issue and verify a certificate, we can process:
1) name and surname;
2) name of the training;
3) date of conduct;
4) result;
5) date of issue;
6) unique number;
7) organisation;
8) level or type of certificate;
9) information on validity;
10) information on withdrawal or correction;
11) other data required for verification.
19.2.
Public verification of a certificate where it is offered should only show the necessary information.
19.3.
Full results, personal contacts and other unnecessary information shall not be published in public inspection.
20. Communication and service data
20.1.
In contact with us we can process:
1) name;
2) e-mail address;
3) telephone;
4) organisation;
5) content of the message;
6) attachments;
7) history of correspondence;
8) date and time;
9) channel used;
10) order number;
11) technical information;
12) the actions of the application;
13) Internal notes necessary for the service.
20.2.
A telephone call shall not be recorded unless the person has been informed in advance and there is a valid legal basis.
21. Data relating to withdrawals, returns, product complaints and other complaints
21.1.
We can process:
1) name and contacts;
2) order number;
3) product or service concerned;
4) the basis of the application;
5) date of receipt or activation;
6) date of application;
7) unique number;
8) bill of lading;
9) photos;
10) evidence;
11) correspondence;
12) the result of the verification;
13) a preferred solution;
14) banking data where necessary for refund;
15) size and mode of refund;
16) status and history of processing;
17) other data needed to solve the case.
21.2.
Data shall be used to fulfil legal and contractual obligations, protect the rights of the parties, prevent fraud and accounting.
22. Technical data and logs
22.1.
When using the Platform, they can be automatically processed:
1) IP address;
2) date and time;
3) page visited;
4) requested Internet address;
5) type and browser version;
6) operating system;
7) type of device;
8) language settings;
9) session identifier;
10) Reference page;
11) codes for technical result;
12) error information;
13) input and output actions;
14) unsuccessful entry attempts;
15) changes of rights;
16) administrative actions;
17) withdrawals;
18) procurement actions;
19) consents given;
20) security information;
21) other technical events necessary to operate and protect the system.
22.2.
Technical logs shall be used for:
1) provision of the service;
2) identification of errors;
3) protection against unauthorised access;
4) prevention of fraud;
5) incident verification;
6) Prove action;
7) improving reliability;
8) fulfillment of legal obligations.
22.3.
The technical logs are not used for a hidden assessment of the performance of the employees of the merchant.
23. Consent and preference data
23.1.
We can store evidence of:
1) acceptance of the Terms and Conditions;
2) the version of the adopted document;
3) consent to immediate digital content;
4) request for early start of a digital service;
5) marketing consent;
6) choice of cookies;
7) withdrawal of consent;
8) objection to marketing;
9) date and time;
10) technical identifier;
11) source and form;
12) the text shown in agreement.
23.2.
The maintenance of evidence of withdrawal of consent may continue where necessary in order to demonstrate compliance with the law and not to resume unwanted communication.
24. Special categories of personal data
24.1.
The platform is not intended for the systematic processing of specific categories of personal data, including data on:
1) health status;
2) racial or ethnic origin;
3) religious or philosophical beliefs;
4) political views;
5) membership of a trade union organisation;
6) genetic data;
7) biometric data for unique identification;
8) sexual life or sexual orientation.
24.2.
Users shall not upload such data unless:
1) this is objectively necessary;
2) there is an applicable legal basis;
3) the additional requirements of the law are fulfilled;
4) the corporate client has authorised the processing;
5) appropriate protective measures have been applied.
24.3.
A person's photo does not automatically represent a biometric data. It can become a biometric data when processed by special technical means for unique identification.
24.4.
The merchant shall not use facial recognition to identify users unless a separate lawful functionality is introduced and persons shall be informed in advance.
25. Data on convictions and violations
25.1.
The platform is not intended for systematic processing of data on convictions and infringements.
25.2.
Such data must not be entered unless the processing is expressly authorised by law and the necessary guarantees are applied.
26. Personal data sources
26.1.
We're getting personal data:
1) directly from the data subject;
(2) by the person performing the order;
3) by the consignee of the consignment;
4) by a corporate client;
5) by an controller of a company profile;
6) by an authorised person;
7) by myPOS;
8) by banks and payment providers;
9) by Econt or any other courier;
10) of a training platform or video conferences;
11) by e-mail;
12) of technical systems and devices;
13) of cookies and similar technologies;
14) from a public source where it is lawful and necessary;
15) by a competent authority;
16) by another person entitled to provide the data.
26.2.
When a corporate controller creates a user profile, the data can be obtained from the organisation and not directly from the person.
26.3.
In such a case, the necessary processing information shall be provided on the first contact, on the first entry, within a reasonable period or through the corporate controller, except where a legal exception is applicable.
27. Purposes of processing
27.1.
Personal data may be processed for:
1) providing and maintaining the website;
2) registration and management of profiles;
3) authentication and access management;
4) the conclusion and execution of contracts;
5) processing of orders;
6) acceptance and confirmation of payments;
7) supply of physical goods;
8) activation of digital content;
9) provision of digital services;
10) subscription management;
11) conducting trainings;
12) issue and verification of certificates;
13) provision of technical support;
14) communication with customers;
15) processing of refusals and returns;
16) review of claims and complaints;
17) refund of amounts;
18) invoicing and accounting;
19) the fulfilment of tax obligations;
20) prevention of fraud;
21) protection of profiles and systems;
22) management of consents;
23) sending contractual messages;
24) sending marketing messages on grounds;
25) analysis and improvement of the Platform;
26) developing new functionalities;
27) creation of anonymised statistics;
28) the exercise and protection of legal claims;
29) implementation of requests by competent authorities;
30) fulfilling other legal obligations.
28. Legal bases
28.1. Contract and pre-contract actions
We process data where necessary for:
1) registration at the request of the consumer;
2) preparing a tender;
3) making an order;
4) payment;
5) delivery;
6) activation of access;
7) provision of digital content;
8) participation in training;
9) technical support;
10) processing of a contractual request;
11) fulfilling other contractual obligations.
28.2. Legal obligation
We process data where necessary for:
1) accounting;
(2) taxation;
3) issue and storage of invoices;
4) processing of consumer claims;
5) exercising the right of withdrawal;
6) protection of personal data;
7) response to competent authorities;
8) fulfilling other legal obligations.
28.3. Legal Interest
We can process data on legitimate interests such as:
1) protection of information systems;
2) prevention of fraud;
3) proof of contractual actions;
4) protection of legal claims;
5) improvement of services;
6) Business management;
7) internal reporting;
8) protection of property and rights;
9) Limited communication with business contacts;
10) preventing abuse;
11) anonymisation of information;
12) maintain a minimum list of persons objecting to marketing.
28.4.
Before processing on the basis of legitimate interest, the need, the expectations of persons and the possible impact on their rights shall be assessed.
28.5. Agree
We can rely on consent for:
1) marketing newsletter;
2) optional cookies;
3) publication of a review;
4) use of image or voice for marketing;
5) participation in a voluntary survey;
6) another specific objective for which consent is an appropriate legal basis.
28.6.
The consent may be withdrawn at any time.
28.7.
The withdrawal shall be without prejudice to the lawfulness of the processing carried out before it.
28.8.
The explicit consent to the immediate provision of digital content is a contractual consumer statement and should not be automatically mixed with a marketing consent or other processing of personal data.
29. Mandatory and voluntary provision of data
29.1.
Some data are necessary for the conclusion or execution of a contract.
29.2.
Without the necessary data, it may not be possible:
1) creating a profile;
2) processing of an order;
3) making or identifying payment;
4) delivery;
5) issue of an invoice;
6) activation of access;
7) participation in training;
8) issue of a certificate;
9) examination of a claim;
10) reimbursement.
29.3.
The data indicated as optional shall be provided voluntarily.
29.4.
Refusal of marketing consent does not prevent the making of a purchase.
29.5.
Refusal from optional analytic or marketing cookies should not interfere with the use of the main functionalities.
30. Contractual and service messages
30.1.
We can send without separate marketing consent messages necessary for:
1) confirmation of registration;
2) confirmation of order;
3) payment;
4) delivery;
5) activation of access;
6) security;
7) change password;
8) leakage of agreed access;
9) training;
10) invoice;
11) withdrawal;
12) Return;
13) a claim;
14) technical support;
15) change of contract service;
16) fulfillment of a legal obligation.
30.2.
Such communications shall not constitute marketing where their content is limited to the necessary contractual or service information.
31. Marketing messages
31.1.
Marketing messages may be sent:
1) upon valid consent;
(2) where another applicable legal basis so permits;
3) in case of easy and free opt-out.
31.2.
The marketing message may contain:
1) news;
2) information about books;
3) information on training;
4) information on the platform;
5) promotional proposals;
6) invitations to events;
7) useful professional content.
31.3.
The recipient may be written off by:
1) link in the message;
2) profile settings;
3) e-mail to office@lean.bg;
4) another provided mechanism.
31.4.
The objection to direct marketing shall be respected without undue delay.
31.5.
After writing off, we can store minimal information on an exclusion list to ensure that the person will not be added again without a new reason.
32. Cookies and similar technologies
32.1.
The platform may use:
1) cookies;
2) local storage;
3) session identifiers;
4) pixels;
5) Similar technologies.
32.2.
The strictly necessary technologies may be used without consent where they are necessary for:
1) security;
2) input into a profile;
3) basket;
4) maintain the selected session;
5) protection against abuse;
6) maintaining the choice of confidentiality;
7) provision of an explicitly requested service.
32.3.
Analytical, functional or marketing technologies for which the law requires consent are activated only after a valid choice.
32.4.
Detailed information on specific technologies, suppliers, objectives and deadlines shall be provided in the Cookies Policy and in the consent management mechanism.
33. Anonymous and aggregated data
33.1.
We can create aggregated or anonymised statistics for:
1) number of visits;
2) used functionalities;
3) purchases;
4) trainings;
5) technical performance;
6) improving the service;
7) Internal analysis.
33.2.
Where the data are actually and irreversibly anonymised, they do not represent personal data.
33.3.
Anonymised data may be stored for a longer period when it does not allow identification of a natural person.
34. Recipients of personal data
34.1.
Personal data may be provided to:
1) myPOS;
2) banks and payment providers;
3) Econt and other couriers;
4) hosting providers;
5) cloud infrastructure providers;
6) e-mail providers;
7) providers of information systems;
8) Developers and technical support;
9) backup and cybersecurity providers;
10) remote learning platforms;
11) Videoconference platforms;
12) suppliers of certificates;
13) accounting officers;
14) auditors;
15) lawyers and legal consultants;
16) Insurance;
17) partners involved in the implementation of training or service;
18) state and municipal authorities;
19) Courts;
20) control bodies and supervisory authorities;
21) law enforcement authorities;
22) successor to conversion or transfer of activity;
23) other persons, where the entity is informed or required by the law.
34.2.
Access shall be granted only in the required volume and in accordance with the role of the recipient.
34.3.
Where a supplier processes data on behalf of the merchant, the relationship shall be settled by contract and appropriate instructions.
34.4.
The processor shall not use the data for incompatible own purposes.
34.5.
Where the recipient acts as an independent controller, he shall be responsible for his own processing.
35. Corporate administrators
35.1.
A corporate administrator may have access to:
1) the names of the users in their organisation;
2) their business e-mail addresses;
3) roles;
4) access status;
5) the results of training;
6) company audits and reports;
7) customer content;
8) other information authorised by the corporate plan.
35.2.
The corporate administrator does not have access to:
1) complete card data;
2) personal passwords;
3) data from unrelated organisations;
4) other information beyond the rights granted to it.
35.3.
The organisation shall be responsible for granting admin rights only to appropriately authorised persons.
36. Transmission outside the European Economic Area
36.1.
We strive for personal data to be processed in the European Economic Area whenever reasonably possible.
36.2.
Some suppliers can process data in a country outside the European Economic Area.
36.3.
Such transmission shall only be carried out in the presence of an applicable mechanism, including:
1) a decision of the European Commission on an adequate level of protection;
(2) standard contractual clauses;
3) binding corporate rules;
4) approved code or certification mechanism with commitments;
5) explicit legal exception;
6) another permissible mechanism.
36.4.
Where standard contractual clauses are used, an assessment of the conditions in the recipient country may be carried out and additional measures may be applied where necessary.
36.5.
The data subject may request information on the applicable mechanism and how to obtain a copy of the relevant guarantees, insofar as this does not violate third party rights or security requirements.
37. Retention periods
37.1.
Personal data shall only be stored for the period necessary for that purpose, unless a longer period:
1) is required by law;
2) is necessary for the protection of legal claims;
3) is legally agreed;
4) is necessary for the conclusion of a dispute, verification or investigation.
37.2. Consumer Profiles
Active profile data shall be stored during the registration period and contractual access.
37.3.
After closing the profile, the data in active systems shall be deleted or limited within a reasonable technical time, except for the part necessary for:
1) contractual relationship;
2) accounting;
3) security;
4) proof of action;
5) Legal claims.
37.4.
Basic contractual and identity data may be stored until the applicable limitation periods, normally up to five years after termination of the relationship, unless another time limit applies.
37.5. Client content of corporate client
The customer content shall be kept for the duration of the contract and under the agreed rules.
37.6.
In the absence of a special arrangement after termination, a reasonable export period may be provided and the content shall be deleted or anonymised by the active systems, except where the law requires retention.
37.7. Orders and contracts
The details of contracts and contracts shall be kept for the period of execution and for the applicable limitation period.
37.8.
Where data are part of accounting information, they may be kept for the legally established accounting period.
37.9. Accounting documents
Accounting registers, financial statements and tax control documents, audit and follow-up financial inspections shall be kept for the applicable legal period, which shall normally be 10 years as provided for in the Accounting Act.
37.10. Unpaid and cancelled orders
Data on unpaid or cancelled orders may be stored for up to six months, except where necessary for the prevention of fraud, legal dispute or legal obligation.
37.11. Abandoned basket
Unfinished basket information may be stored for up to 30 days unless the user has kept the basket through his account or provided a separate basis for longer use.
37.12. Enquiry
Questions that do not lead to a contract may be stored for up to two years after the last substantial communication.
37.13. Refuse, returns and claims
Data on refusals, returns, claims and A complaint may be kept for up to five years after the close of the case.
37.14.
Documents representing accounting information shall be kept for the relevant longer legal period.
37.15. Trainings
Data on participation, presence, progress and results may be kept for up to five years after completion of the training, unless the specific programme or law requires another period.
37.16. Certificates
The basic information required to verify a certificate issued may be kept for up to 10 years or for the period of validity of the certificate, where necessary for authentication.
37.17. Marketing
Marketing data shall be stored until consent, objection, termination of the grounds or determination of continued inactivity is withdrawn.
37.18.
A minimum recording of refusal of marketing may be kept for the period necessary to comply with the objection.
37.19. Evidence of consent
The consent records may be kept for up to five years after the withdrawal or termination of the relevant activity, where necessary to prove the legality.
37.20. Technical Logs
The usual technical and protective logs may be stored for up to 12 months.
37.21.
Logs relating to an incident, fraud, dispute or infringement may be stored until the final closure and expiry of the applicable claim period.
37.22. Cookies
The term of each cookie shall be specified in the Cookies Policy or in the agreement management mechanism.
37.23. Archival copies
Data deleted from active systems may remain temporarily in protected backups until the technical cycle of the archives expires.
37.24.
Archiving copies shall not be used for the usual active processing and shall be recovered only if necessary to restore the system, security or legal obligation.
37.25. Legal claims
Where there is a dispute, verification or production, the relevant data may be stored until the end and expiry of the subsequent protection period.
38. Erasure, restriction and anonymisation
38.1.
After expiry of the applicable period, personal data shall be:
1) delete;
2) destroy;
3) irreversibly anonymise;
4) limit where temporary retention is required by law or dispute.
38.2.
Where the data must be preserved by law, they shall not be used for an incompatible new purpose.
38.3.
Delete from all backups may occur gradually during their normal rotation.
38.4.
Upon recovery of a archive, procedures may be applied to delete data previously legally deleted.
39. Technical and organisational measures
39.1.
The merchant shall apply appropriate measures taking into account the risk, nature, scope, context and purposes of the processing.
39.2.
The measures may include:
1) access control;
2) individual user profiles;
3) roles and permissions;
4) cryptographic password protection;
5) protected transmission of information;
6) registration of administrative actions;
7) Back-up;
8) protection against unauthorised access;
9) updating systems;
10) vulnerable management;
11) limiting unsuccessful entry attempts;
12) protection of the payment process;
13) separation of media;
14) incident procedures;
15) contractual confidentiality obligations;
16) training of persons with access;
17) a periodic review of rights;
18) Minimization of data;
19) pseudonymisation, where appropriate;
20) physical protection of infrastructure;
21) Other measures according to technology development.
39.3.
Access shall only be granted to persons for whom this is necessary for their official or contractual obligations.
39.4.
The provision of specific details of the protection may be restricted where disclosure would create a security risk.
39.5.
No system can guarantee absolute protection against all possible risks.
39.6.
This circumstance does not exempt the merchant from the obligation to apply appropriate measures and to respond to an accident.
40. Consumer security obligations
40.1.
Consumer follows:
1) use a strong and unique password;
2) not to share your password;
3) not to provide its profile to unauthorized persons;
4) exit the profile of a shared device;
5) to keep your device and browser up-to-date;
6) do not open suspicious connections;
7) notify in case of suspicion of compromise;
8) check the website address;
9) not to send payment codes and passwords;
10) respect the rights of access in the corporate profile.
40.2.
If unauthorized access is suspected, the user should immediately change his password and contact the Merchant.
41. Security breaches
41.1.
Where an infringement has been detected, the merchant shall assess:
1) the nature of the data;
(2) the number of persons concerned;
3) the possible consequences;
4) the likelihood of injury;
5) the safeguard measures taken.
41.2.
Where the law so requires, the supervisory authority shall be informed without undue delay and, where possible, within 72 hours of knowledge.
41.3.
Where the infringement may lead to a high risk to the rights and freedoms of persons concerned, the persons concerned shall be notified without undue delay, unless a legal exception is applicable.
41.4.
The notification may contain:
1) the nature of the infringement;
(2) the possible consequences;
3) the measures taken;
4) recommendations to the person;
5) contact for further information.
42. Automated decision-making and profiling
42.1.
Unless the person is explicitly informed in a separate notification, the merchant shall not take decisions based solely on automated processing which give rise to legal effects or affect the person in a similar material way.
42.2.
Automatic rules may be used for:
1) protection against spam;
2) detection of unusual entry attempts;
3) verification of technical validity;
4) calculation of price and delivery;
5) activation after successful payment;
6) display content according to the purchased plan;
7) other routine operations without significant legal impact.
42.3.
If an automated material impact solution is introduced, information will be provided on:
1) logic;
2) the meaning;
3) the possible consequences;
4) the right to human intervention;
5) the right to express an opinion;
6) the right to challenge the decision.
43. Right to information
43.1.
The subject shall have the right to obtain clear and understandable information about the processing.
43.2.
The information shall be provided by:
1) the current policy;
2) Cookies Policy;
3) notifications upon registration;
4) information on ordering;
5) contracts;
6) Special notifications;
7) response to an individual request.
44. Access rights
44.1.
The subject may request confirmation of whether his personal data are being processed.
44.2.
When processing data, it may request:
1) a copy of the data;
2) the objectives;
3) categories of data;
4) recipients;
5) the term or criteria;
6) the source;
7) information on rights;
8) information on international programmes;
9) information on automated solutions where applicable.
44.3.
The right to a copy shall not adversely affect the rights and freedoms of others.
45. Right to rectification
45.1.
The subject may request the correction of inaccurate personal data.
45.2.
Taking into account the objective, it may request the addition of incomplete data.
45.3.
Some data can be corrected directly through the profile.
46. Right to erasure
46.1.
The subject may request the deletion when:
1) the data are no longer necessary;
2) the consent has been withdrawn and there is no other reason;
3) a reasonable objection has been made;
4) the data were processed illegally;
5) the deletion is required by law;
6) Another GDPR basis is applicable.
46.2.
The right to delete is not absolute.
46.3.
Data may be retained where necessary for:
1) fulfilling a legal obligation;
(2) exercising the right to freedom of expression and information;
3) public interest;
4) archive, scientific or statistical objectives under applicable conditions;
5) establishment, exercise or defence of legal claims;
6) another legal basis.
46.4.
Delete a profile does not automatically result in the deletion of invoices, contractual records or other data to be retained.
47. Right to restriction of processing
47.1.
The subject may request restriction where:
1) contests accuracy;
(2) processing is unlawful but does not wish to delete;
3) the data are no longer necessary for the merchant, but necessary for a legal claim;
4) an objection has been lodged and an inspection is carried out.
47.2.
In the case of restriction, the data shall normally be stored but shall not be used for other activities without applicable grounds.
48. Right to data portability
48.1.
Where processing is automated and is based on an agreement or contract, the entity may be entitled to obtain the data it provides in a structured, widely used and machine-readable format.
48.2.
Where technically possible, the person may request that the data be transmitted directly to another controller.
48.3.
The right of portability shall not apply to all data and shall not affect the rights of third parties.
49. Right to object
49.1.
The subject may object to legal-interest-based processing for reasons related to his particular situation.
49.2.
In the event of an objection, the processing shall be terminated unless the merchant proves compelling legal grounds which have priority or the data are necessary for legal claims.
49.3.
The objection against direct marketing is respected without the need for the person to state a special reason.
50. Right to withdraw consent
50.1.
Where the processing is based on consent, it may be withdrawn at any time.
50.2.
Withdrawal should be as easy as giving consent.
50.3.
The withdrawal shall be without prejudice to the legality of the processing carried out before it.
50.4.
The withdrawal of marketing consent does not terminate contractual communications.
51. Rights relating to automated decisions
51.1.
Where applicable, the entity shall have the right not to be subject to a decision based solely on automated processing which produces legal effects or affects it in a similar material way.
51.2.
Where an exception applies, the person may be entitled to:
1) human intervention;
2) expression of a view;
3) contesting the decision.
52. Exercise of the rights
52.1.
A request may be submitted to:
LEAN BULGARIA OOD
Email: office@lean.bg
Address: Sofia, 55 Kiril Popov Str., A, floor 1, ap. 4, Republic of Bulgaria
52.2.
In the topic of the e-mail message it is advisable to specify:
? Request for personal data ?
52.3.
The request shall contain:
1) name;
2) way of contact;
(3) a description of the action requested;
4) information allowing identification of the profile or relationship;
5) The preferred way to get the answer.
52.4.
The person does not have to identify a specific member of the GDPR.
52.5.
Where the merchant acts as a processor, the request may be forwarded to the relevant corporate controller.
53. Identity check
53.1.
Where there is reasonable doubt as to identity, additional information may be requested.
53.2.
The verification shall be:
1) necessary;
2) proportionate;
3) taking into account the risk;
4) limited to minimum information.
53.3.
No copy of default personal document is required.
53.4.
Where possible, less invasive agents shall be used, such as:
1) confirmation from the registered e-mail address;
2) login to the profile;
3) order number;
4) limited verification of known data;
5) another safe method.
54. Response deadline
54.1.
The merchant shall respond without undue delay and, as a rule, within one month of receipt of the request.
54.2.
In the case of complexity or a large number of requests, the period may be extended by another two months.
54.3.
The person shall be informed of the extension and the reasons within one month of receipt of the request.
54.4.
Where no action is taken, the person shall be informed of the reasons and of the possibility to lodge a complaint or to seek judicial remedy.
55. Fees
55.1.
The exercise of rights as a rule is free of charge.
55.2.
In the event of a manifestly unfounded or excessive request, in particular due to recurrence, the merchant may:
1) to charge a reasonable fee corresponding to the administrative costs;
2) refuse to take action.
55.3.
The merchant shall be responsible for proving the obvious unjustifiedness or excessiveness.
56. Right to lodge a complaint with a supervisory authority
56.1.
The subject shall have the right to lodge a complaint with the Commission for the protection of personal data where he considers that the processing violates applicable legislation.
56.2.
Contact details of the Personal Data Protection Commission:
Address: 1592 Sofia, Blvd. "Prof. Tsvetan Lazarov" No 2, Republic of Bulgaria
E-mail: kzld@cpdp.bg
Website: cpdp.bg
56.3.
The right of appeal shall not be subject to a mandatory prior request to the Merchant.
56.4.
The subject shall also have the right to effective judicial protection.
57. Children’s data
57.1.
The platform is intended mainly for adults, professionals, organisations and persons who can make a valid contract.
57.2.
We do not knowingly collect personal data from children for marketing purposes without proper legal basis.
57.3.
Where processing of data of a person under 14 years is based on consent when offering a direct service to the information society, consent must be given or authorised by a parent or guardian under the applicable Bulgarian legislation.
57.4.
Where training or other service is intended for minors, separate appropriate information shall be provided and appropriate measures shall be taken.
57.5.
If it is found that child data are collected without due cause, they shall be deleted or processed lawfully without undue delay.
58. External links and services
58.1.
The platform may contain links to external websites and services.
58.2.
The merchant shall not determine how an independent external controller processes the data after visiting its page.
58.3.
The consumer should be familiar with the privacy policy of the relevant external service.
58.4.
Where the external service is embedded in the Platform, the necessary information and consent shall be provided under the applicable legislation.
59. Social networks
59.1.
When a person interacts with a Lean Champions profile on a social network, the social network operator can also process data as an independent controller.
59.2.
We can get information that the person:
1) has made public;
2) sent by personal message;
3) has submitted by comment;
4) has shared through a function of the social network.
59.3.
Data shall not be automatically transferred to a marketing list without applicable legal basis.
60. Policy changes
60.1.
The policy may be updated on:
1) change of legislation;
2) change of services;
3) introducing a new method of payment;
4) adding a new module;
5) change of suppliers;
6) changing storage times;
7) change of international programmes;
8) development of security measures;
9) another objective reason.
60.2.
The current version shall be published with a number, date of entry into force and date of latest update.
60.3.
Where the change is substantial, the persons concerned may be informed by:
1) e-mail;
2) message in the profile;
3) notice on the website;
4) another suitable channel.
60.4.
Where consent is needed for a new purpose, the change of policy does not in itself replace the agreement.
60.5.
Previous versions may be archived to demonstrate the information provided.
61. Contacts
61.1.
In the case of questions, requests or complaints concerning personal data, you may contact:
LEAN BULGARIA OOD
Unified Identification Code (UIC): 203317933
VAT identification number: BG203317933
Address: Sofia, 55 Kiril Popov Str., A, floor 1, ap. 4, Republic of Bulgaria
Email: office@lean.bg
Telephone: +359 896 060 911
Website: leanchampionscommunity.com
61.2.
For faster processing, specify:
1) your name;
2) the e-mail address used;
3) the organisation, where applicable;
4) order number or profile when known;
5) a clear description of the request;
6) A preferred way of contact.
61.3.
Do not send by email:
1) full bank card number;
2) security code;
3) password;
4) code for two-factor identification;
5) other unnecessary certification data.
62. Entry into force
62.1.
This Privacy Policy shall enter into force as from the date specified in the field in force by the.
62.2.
The version shall apply to the processing from the date of its entry into force.
62.3.
Where a specific processing is governed by a separate contract, a specific notification or a contract for the processing of personal data, the relevant documents shall be applied together with this policy.
62.4.
Where a provision of this policy is contrary to a binding rule of law, the rule of law shall apply without prejudice to the rest of the policy.
1. Object and scope
1.1.
This Privacy Policy governs the way that LEAN BULGARIA OOD collects, receives, uses, stores, organizes, changes, provides, restricts, deletes and otherwise processes personal data in relation to Lean Champions Platform, Lean Champions Store and related products, services and functionalities.
1.2.
The policy shall apply to:
1) visiting and using the website leanchampionscommunity.com;
2) creating and using a user profile;
3) use of an individual, team or corporate profile;
4) execution and execution of orders;
5) purchase and delivery of physical goods;
6) purchase and supply of digital content;
7) activation and use of digital services;
8) purchase and use of subscription access;
9) participation in remote, online or presence training;
10) participation in webinars, seminars, events and consultations;
11) use of 5S, audit, reporting, training and other Platform modules;
12) submitting an inquiry, application for withdrawal, request for return, claim, complaint or other request;
13) making payment through myPOS, bank transfer, cash on delivery or other active method;
14) communication with the merchant;
15) receiving contractual, informational or marketing messages;
16) use of cookies and similar technologies;
17) ensuring the security and proper functioning of the Platform.
1.3.
The policy shall apply to the personal data of:
1) visitors to the website;
2) registered users;
3) clients and recipients of orders;
4) participants in training;
5) representatives, employees and contact persons of corporate clients;
6) administrators of company profiles;
7) persons included in uploaded material, photos, audits, reports or other records;
8) persons associated with the merchant;
9) persons exercising rights under the legislation on the protection of personal data;
10) other natural persons whose data are lawfully processed through the Platform.
1.4.
Data concerning legal persons shall not constitute personal data unless the information identifies or may be related to a specific natural person, such as a manager, employee, representative or contact person.
1.5.
This policy provides information pursuant to Regulation (EU) 2016/679, hereinafter referred to as "GDPR', the Personal Data Protection Act and other applicable legislation.
1.6.
Acquaintance with this Privacy Policy does not constitute an agreement on all the processing activities described.
1.7.
Where the processing requires consent, it shall be requested separately, for a specific purpose, by clear affirmative action and without pre-aligned field.
1.8.
The policy shall apply together with:
1) the Terms and Conditions;
2) Cookies Policy;
3) Delivery and payment policy;
4) The policy on the right of withdrawal;
5) Return policy;
6) The complaint policy;
7) the conditions of the particular product or service;
8) the additional notifications shown in individual functionalities;
9) personal data processing contracts with corporate clients where applicable.
2. Data controller
2.1.
Personal data controller processed for the own purposes of Lean Champions Platform and Lean Champions Store is:
LEAN BULGARIA OOD
Unified Identification Code (UIC): 203317933
VAT identification number: BG203317933
Registered office and management address: Sofia, 55 Kiril Popov Street, entrance A, floor 1, apartment 4, Republic of Bulgaria
Manager: Todor Neychev
Email: office@lean.bg
Telephone: +359 896 060 911
Website: leanchampionscommunity.com
hereinafter referred to as "the merchant', "the controller', "the controller', "the person', "the us' or "ours'.
2.2.
On issues concerning the protection of personal data in the topic of electronic communication, it may be stated:
Personal data.
2.3.
The merchant shall determine the purposes and means of processing personal data when acting as an controller.
2.4.
When processing data on behalf of a corporate client and only on its documented order, the merchant may act as a processor.
3. Basic concepts
3.1.
“Personal data” means any information relating to an identified or identifiable natural person.
3.2.
The data subject is the natural person to whom the personal data relate.
3.3.
“Processing” means any operation or set of operations on personal data, including collection, recording, organisation, structuring, storage, alteration, retrieval, consultation, use, disclosure, restriction, erasure or destruction.
3.4.
“Controller” means the person who determines the purposes and means of processing.
3.5.
The processor is the person who processes personal data on behalf of the controller.
3.6.
“Recipient” means a person, organisation or authority to which personal data are disclosed.
3.7.
“Consent” means a freely given, specific, informed and unambiguous indication of the data subject’s wishes.
3.8.
“Pseudonymisation” means processing that prevents data from being attributed to a specific person without additional information kept separately.
3.9.
"Anonymised data' is data that cannot be reasonably related to a specific natural person.
3.10.
A personal data breach is an infringement which leads to accidental or unlawful destruction, loss, modification, unauthorised disclosure or access to personal data.
3.11.
"Corporate client" is an organisation that buys or manages access to the Platform for its employees, representatives, counterparties or other authorised users.
3.12.
The information, documents, photos, recordings, audits, reports, tasks, comments and other data entered or uploaded by a client or its users is client content.
4. Roles in Processing
4.1.
The merchant shall act as an independent controller with regard to data processed for:
1) website management;
2) registration and management of user profiles;
3) conclusion and execution of contracts;
4) processing of orders;
5) payments and accounting;
6) supply of physical goods;
7) provision of digital content and digital services;
8) conducting trainings;
9) customer service;
10) consideration of refusals, returns and claims;
11) security protection;
12) prevention of fraud;
13) the fulfilment of legal obligations;
14) protection of legal claims;
15) own marketing communication.
4.2.
The corporate client shall normally act as an controller in relation to the personal data that he or his users enter into the Platform for their own organisational purposes, including data concerning:
1) employees;
(2) operators;
3) Heads;
4) auditors;
5) participants in 5S checks;
6) persons responsible for corrective actions;
7) participants in training;
8) internal users;
9) other persons designated by the corporate client.
4.3.
When processing customer content under a documented order of the corporate client, the merchant may act as a processor.
4.4.
The relationship between the corporate client and the merchant may be further settled by contract or application for processing of personal data.
4.5.
The corporate client shall be responsible for:
1) has a valid legal basis for the data entered;
(2) provide the necessary information to the persons concerned;
3) enter only data necessary for its legal purposes;
4) lays down appropriate access rights;
5) update and correct inaccurate data;
6) not use the Platform for unlawful surveillance;
7) does not upload unnecessary special categories of data;
8) gives legal instructions to the Merchant.
4.6.
Where a data subject requests data for which the corporate client is an controller, the merchant may:
1) forward the request to the corporate client;
(2) inform the person who is the relevant controller;
3) to assist the corporate client within the framework of their contractual and legal obligations.
4.7.
The merchant shall not determine independently the objectives for which the corporate client uses the internal data uploaded by him, except as regards its own security, maintenance, billing and enforcement objectives.
5. Processing principles
5.1.
Personal data shall be processed in accordance with the following principles:
1) the legality;
2) good faith;
3) transparency;
4) limitation of the objectives;
5) minimise data;
6) accuracy;
7) a storage restriction;
8) integrity;
9) confidentiality;
10) reporting.
5.2.
The merchant shall endeavour to process only personal data that are appropriate, connected and limited to what is necessary for the particular purpose.
5.3.
The merchant shall take reasonable action to correct or delete inaccurate data when notified of inaccurateness.
5.4.
Personal data shall not be used for a new incompatible purpose without further legal basis and necessary information to the data subject.
6. Categories of data subjects
6.1.
We can process personal data on:
1) visitors to the Platform;
2) customers;
3) recipients of consignments;
4) payloads;
5) bank account holders;
6) registered users;
7) Profile administrators;
8) representatives of legal entities;
9) employees and associates of corporate clients;
10) participants in trainings and events;
11) trainers and lecturers;
12) persons making inquiries;
13) persons applying for withdrawal;
14) persons making claims;
15) persons included in consumer content;
16) visitors, whether or not they refused to consent to cookies;
17) persons subscribed for marketing communication;
18) persons for whom we are obliged to process data under law.
7. Identification data
7.1.
Depending on the service used, we can process:
1) name;
2) last name;
3) username;
4) internal profile identifier;
5) client number;
6) participant number;
7) certificate number;
8) Signature when required for paper document;
9) a position;
10) organisation;
11) Department;
12) professional role;
13) a business identifier when introduced by a corporate client;
14) other identification information necessary for the specific service.
7.2.
As a rule, we do not require a single civil number, an ID number or a copy of an identity document for a simple registration or order.
7.3.
An identity document may only be requested where it is lawful, necessary and proportionate, for example, to verify identity on a specific request or to prevent fraud.
7.4.
Where sufficient, the unnecessary data in the document must be deleted.
8. Contact details
8.1.
We can process:
1) e-mail address;
2) telephone number;
3) delivery address;
4) billing address;
5) address for correspondence;
6) Selected courier office;
7) Place of residence;
8) postal code;
9) State;
10) working contact details;
11) Preferred communication channel.
9. User profile data
9.1.
When creating and using a profile we can process:
1) username;
2) e-mail address;
3) cryptographically protected presentation of the password;
4) role and level of access;
5) organisation;
6) language settings;
7) Profile settings;
8) date of registration;
9) date of confirmation of the e-mail address;
10) date of last entry;
11) Profile status;
12) activated products and modules;
13) start and end of access;
14) number of authorised users;
15) History of changes in the profile;
16) information about invitations to other users;
17) used functions;
18) administrative actions;
19) information on blocking, refund or termination of access.
9.2.
Passwords are not stored in visible and readable text when the system is technically configured according to the security measures applied.
9.3.
The merchant never requires the user to send his password by email.
10. Order details
10.1.
When performing an order we can process:
1) order number;
2) date and time;
3) selected products and services;
4) quantities;
5) single and general prices;
6) applied discounts;
7) currency;
8) taxes;
9) delivery costs;
10) chosen method of payment;
11) Selected delivery method;
12) the status of the order;
13) history of changes;
14) contractual consents granted;
15) version of the accepted Terms and Conditions;
16) version of policies;
17) date and time of the explicit consents given;
18) activation information;
19) cancellation information;
20) refund information;
21) contractual correspondence;
22) other data necessary to implement and prove the contract.
11. Delivery data
11.1.
For delivery of physical goods we can process:
1) name of the recipient;
2) telephone;
(3) e-mail address;
4) address;
5) Selected office of Econt;
6) Additional delivery instructions;
7) bill of lading number;
8) value of the consignment;
9) amount of the imposed payment;
10) content of the consignment in the required volume;
11) Delivery status;
12) date of dispatch;
13) date of receipt;
14) information on the consignment not received or returned;
15) fault protocols;
16) communication with the courier;
17) other information required for the courier service.
11.2.
The data shall be provided to the courier only in the volume required for delivery, collection of required payment, tracking and problem-solving.
12. Data on card payments through myPOS
12.1.
When payment by bank card via myPOS, the merchant may receive and store limited information such as:
1) transaction identifier;
2) order number;
3) size and currency;
4) date and time;
5) status of payment;
6) status of refund;
7) partially masked payment instrument data where provided;
8) type of card scheme;
9) code or description of the result;
10) information necessary to prevent fraud;
11) correspondence on payment;
12) details of dispute, refund or verification.
12.2.
The merchant does not receive or store:
1) the full number of the bank card;
(2) the security code;
3) the personal identification number;
4) password for banking application;
5) Full certification card data.
12.3.
Full payment data shall be entered into the protected environment of myPOS or any other designated authorised payment service provider.
12.4.
myPOS may process personal data as an independent controller for the provision of the payment service, fraud prevention, regulatory obligations and other own legal purposes.
12.5.
The processing by myPOS is also governed by its own confidentiality information.
13. Bank transfer data
13.1.
When the bank payment is activated, we can process:
1) name of the orderer;
2) name of the account holder;
3) IBAN;
4) BIC;
5) Bank;
6) amount and currency of the translation;
7) date of order and receipt;
8) reason for payment;
9) order number;
10) status of payment;
11) data on partial, overpaid or late payment;
12) refund information;
13) correspondence on translation.
13.2.
Bank data shall be used for:
1) identification of the payment;
2) connection to the order;
3) accounting;
4) refund of an amount;
5) preventing errors and fraud;
6) fulfillment of legal obligations.
13.3.
Banks and payment service providers shall process the data and as independent administrators in accordance with their own legal obligations.
14. Invoicing and accounting data
14.1.
When issuing accounting documents, we can process:
1) name and surname;
2) name of organisation;
3) EIC or other registration number;
4) VAT identification number;
5) address;
6) name of the representing person;
7) contact person;
8) e-mail address;
9) order details;
10) payment details;
11) content and value of the invoice;
12) Other legally required props.
14.2.
Information relating only to a legal person is not personal but the data of representing, contact persons and individuals shall be protected under this policy.
15. Digital content and platform access data
15.1.
When providing digital content or digital service we can process:
1) purchased product;
2) activated plan;
3) activated modules;
4) date and time of activation;
5) Initial and deadline;
6) number of authorised users;
7) downloads;
8) access to materials;
9) progress;
10) successfully completed modules;
11) technical events;
12) actions in the profile;
13) history of licenses;
14) used device and browser;
15) maintenance information;
16) termination or renewal data.
15.2.
Those data shall be processed for the provision of agreed access, licence control, security, technical support and proof of performance.
16. Data from 5S, audit and organisational modules
16.1.
When using company functionalities can be processed:
1) name of organisation;
2) object name;
3) production area;
4) Department;
5) place of work;
6) name or auditor identifier;
7) name or identifier of a responsible person;
8) audit result;
9) findings;
10) corrective actions;
11) time limits;
12) comments;
13) photos;
14) attachments;
15) history of changes;
16) Statuses;
17) date and time;
18) Signature or electronic confirmation;
19) other information introduced by the corporate client.
16.2.
The corporate client shall determine what data to be entered and shall be responsible for making them necessary and legal.
16.3.
The platform should not be used for hidden surveillance, disproportionate monitoring or automatic evaluation of employees without appropriate legal basis and transparency.
16.4.
Where an audit or a report can be drawn up without indicating the full name of an employee, the corporate client should use less identifiable information.
17. Photos, images and media files
17.1.
Users can upload photos and other files for:
1) 5S audits;
2) proof of a condition before and after action;
3) documenting discrepancies;
4) instructions;
5) training;
6) claims;
7) technical support;
8) other authorised targets.
17.2.
Photos may contain personal data when showing:
1) person;
2) work card;
3) a name plate;
4) Signature;
5) registration number;
6) document;
7) computer screen;
8) working schedule;
9) other identifying information.
17.3.
The consumer and the corporate client shall:
1) do not film persons when this is not necessary;
(2) avoid uploading of personal documents;
3) to hide unrelated personal data;
4) use a blur or cut, where appropriate;
5) inform the persons concerned;
6) have a valid legal basis;
7) limit access to photos.
17.4.
Audit photos shall not be used for public marketing without a separate applicable legal basis.
18. Data on trainings and events
18.1.
When recording and participating in training we can process:
1) name;
2) e-mail address;
3) telephone;
4) organisation;
5) position;
6) selected training;
7) date and format;
8) Payment status;
9) presence;
10) participation;
11) progress;
12) completed jobs;
13) test results;
14) feedback received;
15) communication with the trainer;
16) technical details for inclusion;
17) preferred language;
18) necessary information for a certificate;
19) data for cancellation or transfer of participation;
20) other data needed to provide training.
18.2.
Where training is conducted through an external platform for video conferences or e-learning, the necessary data may be provided to the supplier concerned.
18.3.
Where training is recorded, participants shall be informed in advance of:
1) the fact of the recording;
2) the objective;
3) scope;
4) the storage period;
5) persons who will have access;
6) how to exercise rights.
18.4.
The recording is not used for advertising purposes only because the person was involved in the training.
18.5.
The use of an image, voice, name or statement for public advertising content shall be carried out in the event of a separate appropriate legal basis.
19. Certificate details
19.1.
To issue and verify a certificate, we can process:
1) name and surname;
2) name of the training;
3) date of conduct;
4) result;
5) date of issue;
6) unique number;
7) organisation;
8) level or type of certificate;
9) information on validity;
10) information on withdrawal or correction;
11) other data required for verification.
19.2.
Public verification of a certificate where it is offered should only show the necessary information.
19.3.
Full results, personal contacts and other unnecessary information shall not be published in public inspection.
20. Communication and service data
20.1.
In contact with us we can process:
1) name;
2) e-mail address;
3) telephone;
4) organisation;
5) content of the message;
6) attachments;
7) history of correspondence;
8) date and time;
9) channel used;
10) order number;
11) technical information;
12) the actions of the application;
13) Internal notes necessary for the service.
20.2.
A telephone call shall not be recorded unless the person has been informed in advance and there is a valid legal basis.
21. Data relating to withdrawals, returns, product complaints and other complaints
21.1.
We can process:
1) name and contacts;
2) order number;
3) product or service concerned;
4) the basis of the application;
5) date of receipt or activation;
6) date of application;
7) unique number;
8) bill of lading;
9) photos;
10) evidence;
11) correspondence;
12) the result of the verification;
13) a preferred solution;
14) banking data where necessary for refund;
15) size and mode of refund;
16) status and history of processing;
17) other data needed to solve the case.
21.2.
Data shall be used to fulfil legal and contractual obligations, protect the rights of the parties, prevent fraud and accounting.
22. Technical data and logs
22.1.
When using the Platform, they can be automatically processed:
1) IP address;
2) date and time;
3) page visited;
4) requested Internet address;
5) type and browser version;
6) operating system;
7) type of device;
8) language settings;
9) session identifier;
10) Reference page;
11) codes for technical result;
12) error information;
13) input and output actions;
14) unsuccessful entry attempts;
15) changes of rights;
16) administrative actions;
17) withdrawals;
18) procurement actions;
19) consents given;
20) security information;
21) other technical events necessary to operate and protect the system.
22.2.
Technical logs shall be used for:
1) provision of the service;
2) identification of errors;
3) protection against unauthorised access;
4) prevention of fraud;
5) incident verification;
6) Prove action;
7) improving reliability;
8) fulfillment of legal obligations.
22.3.
The technical logs are not used for a hidden assessment of the performance of the employees of the merchant.
23. Consent and preference data
23.1.
We can store evidence of:
1) acceptance of the Terms and Conditions;
2) the version of the adopted document;
3) consent to immediate digital content;
4) request for early start of a digital service;
5) marketing consent;
6) choice of cookies;
7) withdrawal of consent;
8) objection to marketing;
9) date and time;
10) technical identifier;
11) source and form;
12) the text shown in agreement.
23.2.
The maintenance of evidence of withdrawal of consent may continue where necessary in order to demonstrate compliance with the law and not to resume unwanted communication.
24. Special categories of personal data
24.1.
The platform is not intended for the systematic processing of specific categories of personal data, including data on:
1) health status;
2) racial or ethnic origin;
3) religious or philosophical beliefs;
4) political views;
5) membership of a trade union organisation;
6) genetic data;
7) biometric data for unique identification;
8) sexual life or sexual orientation.
24.2.
Users shall not upload such data unless:
1) this is objectively necessary;
2) there is an applicable legal basis;
3) the additional requirements of the law are fulfilled;
4) the corporate client has authorised the processing;
5) appropriate protective measures have been applied.
24.3.
A person's photo does not automatically represent a biometric data. It can become a biometric data when processed by special technical means for unique identification.
24.4.
The merchant shall not use facial recognition to identify users unless a separate lawful functionality is introduced and persons shall be informed in advance.
25. Data on convictions and violations
25.1.
The platform is not intended for systematic processing of data on convictions and infringements.
25.2.
Such data must not be entered unless the processing is expressly authorised by law and the necessary guarantees are applied.
26. Personal data sources
26.1.
We're getting personal data:
1) directly from the data subject;
(2) by the person performing the order;
3) by the consignee of the consignment;
4) by a corporate client;
5) by an controller of a company profile;
6) by an authorised person;
7) by myPOS;
8) by banks and payment providers;
9) by Econt or any other courier;
10) of a training platform or video conferences;
11) by e-mail;
12) of technical systems and devices;
13) of cookies and similar technologies;
14) from a public source where it is lawful and necessary;
15) by a competent authority;
16) by another person entitled to provide the data.
26.2.
When a corporate controller creates a user profile, the data can be obtained from the organisation and not directly from the person.
26.3.
In such a case, the necessary processing information shall be provided on the first contact, on the first entry, within a reasonable period or through the corporate controller, except where a legal exception is applicable.
27. Purposes of processing
27.1.
Personal data may be processed for:
1) providing and maintaining the website;
2) registration and management of profiles;
3) authentication and access management;
4) the conclusion and execution of contracts;
5) processing of orders;
6) acceptance and confirmation of payments;
7) supply of physical goods;
8) activation of digital content;
9) provision of digital services;
10) subscription management;
11) conducting trainings;
12) issue and verification of certificates;
13) provision of technical support;
14) communication with customers;
15) processing of refusals and returns;
16) review of claims and complaints;
17) refund of amounts;
18) invoicing and accounting;
19) the fulfilment of tax obligations;
20) prevention of fraud;
21) protection of profiles and systems;
22) management of consents;
23) sending contractual messages;
24) sending marketing messages on grounds;
25) analysis and improvement of the Platform;
26) developing new functionalities;
27) creation of anonymised statistics;
28) the exercise and protection of legal claims;
29) implementation of requests by competent authorities;
30) fulfilling other legal obligations.
28. Legal bases
28.1. Contract and pre-contract actions
We process data where necessary for:
1) registration at the request of the consumer;
2) preparing a tender;
3) making an order;
4) payment;
5) delivery;
6) activation of access;
7) provision of digital content;
8) participation in training;
9) technical support;
10) processing of a contractual request;
11) fulfilling other contractual obligations.
28.2. Legal obligation
We process data where necessary for:
1) accounting;
(2) taxation;
3) issue and storage of invoices;
4) processing of consumer claims;
5) exercising the right of withdrawal;
6) protection of personal data;
7) response to competent authorities;
8) fulfilling other legal obligations.
28.3. Legal Interest
We can process data on legitimate interests such as:
1) protection of information systems;
2) prevention of fraud;
3) proof of contractual actions;
4) protection of legal claims;
5) improvement of services;
6) Business management;
7) internal reporting;
8) protection of property and rights;
9) Limited communication with business contacts;
10) preventing abuse;
11) anonymisation of information;
12) maintain a minimum list of persons objecting to marketing.
28.4.
Before processing on the basis of legitimate interest, the need, the expectations of persons and the possible impact on their rights shall be assessed.
28.5. Agree
We can rely on consent for:
1) marketing newsletter;
2) optional cookies;
3) publication of a review;
4) use of image or voice for marketing;
5) participation in a voluntary survey;
6) another specific objective for which consent is an appropriate legal basis.
28.6.
The consent may be withdrawn at any time.
28.7.
The withdrawal shall be without prejudice to the lawfulness of the processing carried out before it.
28.8.
The explicit consent to the immediate provision of digital content is a contractual consumer statement and should not be automatically mixed with a marketing consent or other processing of personal data.
29. Mandatory and voluntary provision of data
29.1.
Some data are necessary for the conclusion or execution of a contract.
29.2.
Without the necessary data, it may not be possible:
1) creating a profile;
2) processing of an order;
3) making or identifying payment;
4) delivery;
5) issue of an invoice;
6) activation of access;
7) participation in training;
8) issue of a certificate;
9) examination of a claim;
10) reimbursement.
29.3.
The data indicated as optional shall be provided voluntarily.
29.4.
Refusal of marketing consent does not prevent the making of a purchase.
29.5.
Refusal from optional analytic or marketing cookies should not interfere with the use of the main functionalities.
30. Contractual and service messages
30.1.
We can send without separate marketing consent messages necessary for:
1) confirmation of registration;
2) confirmation of order;
3) payment;
4) delivery;
5) activation of access;
6) security;
7) change password;
8) leakage of agreed access;
9) training;
10) invoice;
11) withdrawal;
12) Return;
13) a claim;
14) technical support;
15) change of contract service;
16) fulfillment of a legal obligation.
30.2.
Such communications shall not constitute marketing where their content is limited to the necessary contractual or service information.
31. Marketing messages
31.1.
Marketing messages may be sent:
1) upon valid consent;
(2) where another applicable legal basis so permits;
3) in case of easy and free opt-out.
31.2.
The marketing message may contain:
1) news;
2) information about books;
3) information on training;
4) information on the platform;
5) promotional proposals;
6) invitations to events;
7) useful professional content.
31.3.
The recipient may be written off by:
1) link in the message;
2) profile settings;
3) e-mail to office@lean.bg;
4) another provided mechanism.
31.4.
The objection to direct marketing shall be respected without undue delay.
31.5.
After writing off, we can store minimal information on an exclusion list to ensure that the person will not be added again without a new reason.
32. Cookies and similar technologies
32.1.
The platform may use:
1) cookies;
2) local storage;
3) session identifiers;
4) pixels;
5) Similar technologies.
32.2.
The strictly necessary technologies may be used without consent where they are necessary for:
1) security;
2) input into a profile;
3) basket;
4) maintain the selected session;
5) protection against abuse;
6) maintaining the choice of confidentiality;
7) provision of an explicitly requested service.
32.3.
Analytical, functional or marketing technologies for which the law requires consent are activated only after a valid choice.
32.4.
Detailed information on specific technologies, suppliers, objectives and deadlines shall be provided in the Cookies Policy and in the consent management mechanism.
33. Anonymous and aggregated data
33.1.
We can create aggregated or anonymised statistics for:
1) number of visits;
2) used functionalities;
3) purchases;
4) trainings;
5) technical performance;
6) improving the service;
7) Internal analysis.
33.2.
Where the data are actually and irreversibly anonymised, they do not represent personal data.
33.3.
Anonymised data may be stored for a longer period when it does not allow identification of a natural person.
34. Recipients of personal data
34.1.
Personal data may be provided to:
1) myPOS;
2) banks and payment providers;
3) Econt and other couriers;
4) hosting providers;
5) cloud infrastructure providers;
6) e-mail providers;
7) providers of information systems;
8) Developers and technical support;
9) backup and cybersecurity providers;
10) remote learning platforms;
11) Videoconference platforms;
12) suppliers of certificates;
13) accounting officers;
14) auditors;
15) lawyers and legal consultants;
16) Insurance;
17) partners involved in the implementation of training or service;
18) state and municipal authorities;
19) Courts;
20) control bodies and supervisory authorities;
21) law enforcement authorities;
22) successor to conversion or transfer of activity;
23) other persons, where the entity is informed or required by the law.
34.2.
Access shall be granted only in the required volume and in accordance with the role of the recipient.
34.3.
Where a supplier processes data on behalf of the merchant, the relationship shall be settled by contract and appropriate instructions.
34.4.
The processor shall not use the data for incompatible own purposes.
34.5.
Where the recipient acts as an independent controller, he shall be responsible for his own processing.
35. Corporate administrators
35.1.
A corporate administrator may have access to:
1) the names of the users in their organisation;
2) their business e-mail addresses;
3) roles;
4) access status;
5) the results of training;
6) company audits and reports;
7) customer content;
8) other information authorised by the corporate plan.
35.2.
The corporate administrator does not have access to:
1) complete card data;
2) personal passwords;
3) data from unrelated organisations;
4) other information beyond the rights granted to it.
35.3.
The organisation shall be responsible for granting admin rights only to appropriately authorised persons.
36. Transmission outside the European Economic Area
36.1.
We strive for personal data to be processed in the European Economic Area whenever reasonably possible.
36.2.
Some suppliers can process data in a country outside the European Economic Area.
36.3.
Such transmission shall only be carried out in the presence of an applicable mechanism, including:
1) a decision of the European Commission on an adequate level of protection;
(2) standard contractual clauses;
3) binding corporate rules;
4) approved code or certification mechanism with commitments;
5) explicit legal exception;
6) another permissible mechanism.
36.4.
Where standard contractual clauses are used, an assessment of the conditions in the recipient country may be carried out and additional measures may be applied where necessary.
36.5.
The data subject may request information on the applicable mechanism and how to obtain a copy of the relevant guarantees, insofar as this does not violate third party rights or security requirements.
37. Retention periods
37.1.
Personal data shall only be stored for the period necessary for that purpose, unless a longer period:
1) is required by law;
2) is necessary for the protection of legal claims;
3) is legally agreed;
4) is necessary for the conclusion of a dispute, verification or investigation.
37.2. Consumer Profiles
Active profile data shall be stored during the registration period and contractual access.
37.3.
After closing the profile, the data in active systems shall be deleted or limited within a reasonable technical time, except for the part necessary for:
1) contractual relationship;
2) accounting;
3) security;
4) proof of action;
5) Legal claims.
37.4.
Basic contractual and identity data may be stored until the applicable limitation periods, normally up to five years after termination of the relationship, unless another time limit applies.
37.5. Client content of corporate client
The customer content shall be kept for the duration of the contract and under the agreed rules.
37.6.
In the absence of a special arrangement after termination, a reasonable export period may be provided and the content shall be deleted or anonymised by the active systems, except where the law requires retention.
37.7. Orders and contracts
The details of contracts and contracts shall be kept for the period of execution and for the applicable limitation period.
37.8.
Where data are part of accounting information, they may be kept for the legally established accounting period.
37.9. Accounting documents
Accounting registers, financial statements and tax control documents, audit and follow-up financial inspections shall be kept for the applicable legal period, which shall normally be 10 years as provided for in the Accounting Act.
37.10. Unpaid and cancelled orders
Data on unpaid or cancelled orders may be stored for up to six months, except where necessary for the prevention of fraud, legal dispute or legal obligation.
37.11. Abandoned basket
Unfinished basket information may be stored for up to 30 days unless the user has kept the basket through his account or provided a separate basis for longer use.
37.12. Enquiry
Questions that do not lead to a contract may be stored for up to two years after the last substantial communication.
37.13. Refuse, returns and claims
Data on refusals, returns, claims and A complaint may be kept for up to five years after the close of the case.
37.14.
Documents representing accounting information shall be kept for the relevant longer legal period.
37.15. Trainings
Data on participation, presence, progress and results may be kept for up to five years after completion of the training, unless the specific programme or law requires another period.
37.16. Certificates
The basic information required to verify a certificate issued may be kept for up to 10 years or for the period of validity of the certificate, where necessary for authentication.
37.17. Marketing
Marketing data shall be stored until consent, objection, termination of the grounds or determination of continued inactivity is withdrawn.
37.18.
A minimum recording of refusal of marketing may be kept for the period necessary to comply with the objection.
37.19. Evidence of consent
The consent records may be kept for up to five years after the withdrawal or termination of the relevant activity, where necessary to prove the legality.
37.20. Technical Logs
The usual technical and protective logs may be stored for up to 12 months.
37.21.
Logs relating to an incident, fraud, dispute or infringement may be stored until the final closure and expiry of the applicable claim period.
37.22. Cookies
The term of each cookie shall be specified in the Cookies Policy or in the agreement management mechanism.
37.23. Archival copies
Data deleted from active systems may remain temporarily in protected backups until the technical cycle of the archives expires.
37.24.
Archiving copies shall not be used for the usual active processing and shall be recovered only if necessary to restore the system, security or legal obligation.
37.25. Legal claims
Where there is a dispute, verification or production, the relevant data may be stored until the end and expiry of the subsequent protection period.
38. Erasure, restriction and anonymisation
38.1.
After expiry of the applicable period, personal data shall be:
1) delete;
2) destroy;
3) irreversibly anonymise;
4) limit where temporary retention is required by law or dispute.
38.2.
Where the data must be preserved by law, they shall not be used for an incompatible new purpose.
38.3.
Delete from all backups may occur gradually during their normal rotation.
38.4.
Upon recovery of a archive, procedures may be applied to delete data previously legally deleted.
39. Technical and organisational measures
39.1.
The merchant shall apply appropriate measures taking into account the risk, nature, scope, context and purposes of the processing.
39.2.
The measures may include:
1) access control;
2) individual user profiles;
3) roles and permissions;
4) cryptographic password protection;
5) protected transmission of information;
6) registration of administrative actions;
7) Back-up;
8) protection against unauthorised access;
9) updating systems;
10) vulnerable management;
11) limiting unsuccessful entry attempts;
12) protection of the payment process;
13) separation of media;
14) incident procedures;
15) contractual confidentiality obligations;
16) training of persons with access;
17) a periodic review of rights;
18) Minimization of data;
19) pseudonymisation, where appropriate;
20) physical protection of infrastructure;
21) Other measures according to technology development.
39.3.
Access shall only be granted to persons for whom this is necessary for their official or contractual obligations.
39.4.
The provision of specific details of the protection may be restricted where disclosure would create a security risk.
39.5.
No system can guarantee absolute protection against all possible risks.
39.6.
This circumstance does not exempt the merchant from the obligation to apply appropriate measures and to respond to an accident.
40. Consumer security obligations
40.1.
Consumer follows:
1) use a strong and unique password;
2) not to share your password;
3) not to provide its profile to unauthorized persons;
4) exit the profile of a shared device;
5) to keep your device and browser up-to-date;
6) do not open suspicious connections;
7) notify in case of suspicion of compromise;
8) check the website address;
9) not to send payment codes and passwords;
10) respect the rights of access in the corporate profile.
40.2.
If unauthorized access is suspected, the user should immediately change his password and contact the Merchant.
41. Security breaches
41.1.
Where an infringement has been detected, the merchant shall assess:
1) the nature of the data;
(2) the number of persons concerned;
3) the possible consequences;
4) the likelihood of injury;
5) the safeguard measures taken.
41.2.
Where the law so requires, the supervisory authority shall be informed without undue delay and, where possible, within 72 hours of knowledge.
41.3.
Where the infringement may lead to a high risk to the rights and freedoms of persons concerned, the persons concerned shall be notified without undue delay, unless a legal exception is applicable.
41.4.
The notification may contain:
1) the nature of the infringement;
(2) the possible consequences;
3) the measures taken;
4) recommendations to the person;
5) contact for further information.
42. Automated decision-making and profiling
42.1.
Unless the person is explicitly informed in a separate notification, the merchant shall not take decisions based solely on automated processing which give rise to legal effects or affect the person in a similar material way.
42.2.
Automatic rules may be used for:
1) protection against spam;
2) detection of unusual entry attempts;
3) verification of technical validity;
4) calculation of price and delivery;
5) activation after successful payment;
6) display content according to the purchased plan;
7) other routine operations without significant legal impact.
42.3.
If an automated material impact solution is introduced, information will be provided on:
1) logic;
2) the meaning;
3) the possible consequences;
4) the right to human intervention;
5) the right to express an opinion;
6) the right to challenge the decision.
43. Right to information
43.1.
The subject shall have the right to obtain clear and understandable information about the processing.
43.2.
The information shall be provided by:
1) the current policy;
2) Cookies Policy;
3) notifications upon registration;
4) information on ordering;
5) contracts;
6) Special notifications;
7) response to an individual request.
44. Access rights
44.1.
The subject may request confirmation of whether his personal data are being processed.
44.2.
When processing data, it may request:
1) a copy of the data;
2) the objectives;
3) categories of data;
4) recipients;
5) the term or criteria;
6) the source;
7) information on rights;
8) information on international programmes;
9) information on automated solutions where applicable.
44.3.
The right to a copy shall not adversely affect the rights and freedoms of others.
45. Right to rectification
45.1.
The subject may request the correction of inaccurate personal data.
45.2.
Taking into account the objective, it may request the addition of incomplete data.
45.3.
Some data can be corrected directly through the profile.
46. Right to erasure
46.1.
The subject may request the deletion when:
1) the data are no longer necessary;
2) the consent has been withdrawn and there is no other reason;
3) a reasonable objection has been made;
4) the data were processed illegally;
5) the deletion is required by law;
6) Another GDPR basis is applicable.
46.2.
The right to delete is not absolute.
46.3.
Data may be retained where necessary for:
1) fulfilling a legal obligation;
(2) exercising the right to freedom of expression and information;
3) public interest;
4) archive, scientific or statistical objectives under applicable conditions;
5) establishment, exercise or defence of legal claims;
6) another legal basis.
46.4.
Delete a profile does not automatically result in the deletion of invoices, contractual records or other data to be retained.
47. Right to restriction of processing
47.1.
The subject may request restriction where:
1) contests accuracy;
(2) processing is unlawful but does not wish to delete;
3) the data are no longer necessary for the merchant, but necessary for a legal claim;
4) an objection has been lodged and an inspection is carried out.
47.2.
In the case of restriction, the data shall normally be stored but shall not be used for other activities without applicable grounds.
48. Right to data portability
48.1.
Where processing is automated and is based on an agreement or contract, the entity may be entitled to obtain the data it provides in a structured, widely used and machine-readable format.
48.2.
Where technically possible, the person may request that the data be transmitted directly to another controller.
48.3.
The right of portability shall not apply to all data and shall not affect the rights of third parties.
49. Right to object
49.1.
The subject may object to legal-interest-based processing for reasons related to his particular situation.
49.2.
In the event of an objection, the processing shall be terminated unless the merchant proves compelling legal grounds which have priority or the data are necessary for legal claims.
49.3.
The objection against direct marketing is respected without the need for the person to state a special reason.
50. Right to withdraw consent
50.1.
Where the processing is based on consent, it may be withdrawn at any time.
50.2.
Withdrawal should be as easy as giving consent.
50.3.
The withdrawal shall be without prejudice to the legality of the processing carried out before it.
50.4.
The withdrawal of marketing consent does not terminate contractual communications.
51. Rights relating to automated decisions
51.1.
Where applicable, the entity shall have the right not to be subject to a decision based solely on automated processing which produces legal effects or affects it in a similar material way.
51.2.
Where an exception applies, the person may be entitled to:
1) human intervention;
2) expression of a view;
3) contesting the decision.
52. Exercise of the rights
52.1.
A request may be submitted to:
LEAN BULGARIA OOD
Email: office@lean.bg
Address: Sofia, 55 Kiril Popov Str., A, floor 1, ap. 4, Republic of Bulgaria
52.2.
In the topic of the e-mail message it is advisable to specify:
? Request for personal data ?
52.3.
The request shall contain:
1) name;
2) way of contact;
(3) a description of the action requested;
4) information allowing identification of the profile or relationship;
5) The preferred way to get the answer.
52.4.
The person does not have to identify a specific member of the GDPR.
52.5.
Where the merchant acts as a processor, the request may be forwarded to the relevant corporate controller.
53. Identity check
53.1.
Where there is reasonable doubt as to identity, additional information may be requested.
53.2.
The verification shall be:
1) necessary;
2) proportionate;
3) taking into account the risk;
4) limited to minimum information.
53.3.
No copy of default personal document is required.
53.4.
Where possible, less invasive agents shall be used, such as:
1) confirmation from the registered e-mail address;
2) login to the profile;
3) order number;
4) limited verification of known data;
5) another safe method.
54. Response deadline
54.1.
The merchant shall respond without undue delay and, as a rule, within one month of receipt of the request.
54.2.
In the case of complexity or a large number of requests, the period may be extended by another two months.
54.3.
The person shall be informed of the extension and the reasons within one month of receipt of the request.
54.4.
Where no action is taken, the person shall be informed of the reasons and of the possibility to lodge a complaint or to seek judicial remedy.
55. Fees
55.1.
The exercise of rights as a rule is free of charge.
55.2.
In the event of a manifestly unfounded or excessive request, in particular due to recurrence, the merchant may:
1) to charge a reasonable fee corresponding to the administrative costs;
2) refuse to take action.
55.3.
The merchant shall be responsible for proving the obvious unjustifiedness or excessiveness.
56. Right to lodge a complaint with a supervisory authority
56.1.
The subject shall have the right to lodge a complaint with the Commission for the protection of personal data where he considers that the processing violates applicable legislation.
56.2.
Contact details of the Personal Data Protection Commission:
Address: 1592 Sofia, Blvd. "Prof. Tsvetan Lazarov" No 2, Republic of Bulgaria
E-mail: kzld@cpdp.bg
Website: cpdp.bg
56.3.
The right of appeal shall not be subject to a mandatory prior request to the Merchant.
56.4.
The subject shall also have the right to effective judicial protection.
57. Children’s data
57.1.
The platform is intended mainly for adults, professionals, organisations and persons who can make a valid contract.
57.2.
We do not knowingly collect personal data from children for marketing purposes without proper legal basis.
57.3.
Where processing of data of a person under 14 years is based on consent when offering a direct service to the information society, consent must be given or authorised by a parent or guardian under the applicable Bulgarian legislation.
57.4.
Where training or other service is intended for minors, separate appropriate information shall be provided and appropriate measures shall be taken.
57.5.
If it is found that child data are collected without due cause, they shall be deleted or processed lawfully without undue delay.
58. External links and services
58.1.
The platform may contain links to external websites and services.
58.2.
The merchant shall not determine how an independent external controller processes the data after visiting its page.
58.3.
The consumer should be familiar with the privacy policy of the relevant external service.
58.4.
Where the external service is embedded in the Platform, the necessary information and consent shall be provided under the applicable legislation.
59. Social networks
59.1.
When a person interacts with a Lean Champions profile on a social network, the social network operator can also process data as an independent controller.
59.2.
We can get information that the person:
1) has made public;
2) sent by personal message;
3) has submitted by comment;
4) has shared through a function of the social network.
59.3.
Data shall not be automatically transferred to a marketing list without applicable legal basis.
60. Policy changes
60.1.
The policy may be updated on:
1) change of legislation;
2) change of services;
3) introducing a new method of payment;
4) adding a new module;
5) change of suppliers;
6) changing storage times;
7) change of international programmes;
8) development of security measures;
9) another objective reason.
60.2.
The current version shall be published with a number, date of entry into force and date of latest update.
60.3.
Where the change is substantial, the persons concerned may be informed by:
1) e-mail;
2) message in the profile;
3) notice on the website;
4) another suitable channel.
60.4.
Where consent is needed for a new purpose, the change of policy does not in itself replace the agreement.
60.5.
Previous versions may be archived to demonstrate the information provided.
61. Contacts
61.1.
In the case of questions, requests or complaints concerning personal data, you may contact:
LEAN BULGARIA OOD
Unified Identification Code (UIC): 203317933
VAT identification number: BG203317933
Address: Sofia, 55 Kiril Popov Str., A, floor 1, ap. 4, Republic of Bulgaria
Email: office@lean.bg
Telephone: +359 896 060 911
Website: leanchampionscommunity.com
61.2.
For faster processing, specify:
1) your name;
2) the e-mail address used;
3) the organisation, where applicable;
4) order number or profile when known;
5) a clear description of the request;
6) A preferred way of contact.
61.3.
Do not send by email:
1) full bank card number;
2) security code;
3) password;
4) code for two-factor identification;
5) other unnecessary certification data.
62. Entry into force
62.1.
This Privacy Policy shall enter into force as from the date specified in the field in force by the.
62.2.
The version shall apply to the processing from the date of its entry into force.
62.3.
Where a specific processing is governed by a separate contract, a specific notification or a contract for the processing of personal data, the relevant documents shall be applied together with this policy.
62.4.
Where a provision of this policy is contrary to a binding rule of law, the rule of law shall apply without prejudice to the rest of the policy.