DATA PROTECTION AND
PRIVACY POLICY
INTRODUCTION
This Privacy and Personal Data Protection Policy (“Policy”) governs the manner in which GALAXY INVESTMENT GROUP LTD collects, processes and stores your personal data in accordance with the requirements of the “General Data Protection Regulation” – Regulation (EU) 2016/679, the Personal Data Protection Act of the Republic of Bulgaria and other Bulgarian or international regulations.
The confidentiality of our users’ information is a top priority for us.
GALAXY INVESTMENT GROUP LTD, as a Personal Data Controller and in accordance with legislation and good practice, applies the required technical and organisational measures to protect the personal data of individuals. GALAXY INVESTMENT GROUP LTD complies with all the requirements of the new regulation by collecting only individuals’ data as it is necessary, respectively: for the conduct of the company’s business; for the provision of our services; for the use of our websites and for marketing purposes.
This Policy describes how and what categories of personal data we gather from and about you, why we require it, to whom it may be transferred or disclosed, and how it is protected.
Definitions:
- "personal data" means any information relating to an identified natural person or an identifiable natural person ("data subject");
- “identifiable natural person”, means a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, psychological, economic, cultural or social identity of that natural person;
- "processing” means any operation or set of operations which is performed upon personal data or a set of personal data, whether or not by automatic means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- „Regulation“ means the „General Data Protection Regulation” – Regulation (EU) 2016/679.
Please read this Policy carefully. By providing your personal data to GALAXY INVESTMENT GROUP LTD, whether electronically or on paper, you accept and agree to the practices described in this Privacy and Data Protection Policy.
If you have any questions about this Policy, please contact our Data Protection Officer; and if you do not agree with any of the terms contained in the Privacy Policy, we do not recommend that you use the products and services provided by GALAXY INVESTMENT GROUP LTD for which you must provide your personal data.
PRINCIPLES AND GROUNDS FOR COLLECTING, PROCESSING AND STORING PERSONAL DATA
To ensure that personal data is processed in accordance with legal requirements, personal data is collected and used lawfully, processing operations are secure, and GALAXY INVESTMENT GROUP LTD has taken the necessary precautions to ensure that personal data is not unlawfully disclosed. In compliance with the fundamental principles maintained by GALAXY INVESTMENT GROUP LTD, your personal data is:
- processed lawfully, fairly and in a transparent manner in relation to the data subject ("lawfulness, fairness and transparency");
- collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes ("purpose limitation");
- appropriate, relevant and limited to what is necessary in relation to the purposes for which it is processed ("data minimisation");
- accurate and kept up to date; GALAXY INVESTMENT GROUP LTD has taken all reasonable steps to ensure that personal data which is inaccurate is erased or rectified in a timely manner, taking into account the purposes for which it is processed ("accuracy");
- kept in a form which permits identification of the data subject no longer than necessary for the purposes for which the personal data is processed; ("storage limitation");
- processed in a manner that ensures an adequate level of security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, by implementing appropriate technical or organisational measures ("integrity and confidentiality");
- GALAXY INVESTMENT GROUP LTD is responsible for and is able to demonstrate compliance with the fundamental principles relating to the processing of personal data ("accountability").
GROUNDS FOR COLLECTING PERSONAL DATA:
- GALAXY INVESTMENT GROUP LTD collects and processes your personal data in connection with the use of the company's website and subsequent provision of information, on the basis of Article 6(1) of Regulation (EU) 2016/679 and, in particular, on the basis of explicit consent obtained from you as a client/potential client. You are under no obligation to, and we do not require you to, register or provide personal data in order to view our website or to access the majority of its content. Personal information is provided using our website's inquiry form. By entering your personal data in the inquiry form, you must consent to the provision of the data, which immediately implies consent for us to process it to answer your request;
- GALAXY INVESTMENT GROUP LTD collects and processes your personal data in case you give your consent to receive communications from us related to our projects, events, campaigns, offers, proposals related to our activities and news about the company;
- GALAXY INVESTMENT GROUP LTD also collects and processes your personal data in connection with the conclusion (including negotiations not leading to a contract) and/or performance of a contract - contracts for the use of our services; purchase and sale contracts; contracts by which we commission the performance of certain work, or the performance of services and/or orders, etc.).
- GALAXY INVESTMENT GROUP LTD collects and processes personal data in connection with compliance with legal obligations that apply to the controller - in order to fulfil our obligations to the NRA (National Revenue Agency), NSSI (National Social Insurance Institute) and other state and municipal authorities;
- GALAXY INVESTMENT GROUP LTD also administers personal data for the purposes of the legitimate interests of the controller or of a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject, which require the protection of personal data;
- GALAXY INVESTMENT GROUP LTD collects and processes personal data in connection with the recruitment of staff for various vacancies advertised by the company. Vacancies can be advertised in the "Careers" section of our website, with the possibility to apply for a position using a special contact form or by sending us a message and the necessary documents to a specified email;
as well as in other, legally established postulates.
PURPOSES OF PROCESSING PERSONAL DATA
In accordance with the requirements of Section I – Transparency and Conditions of Regulation (EU) 2016/679, GALAXY INVESTMENT GROUP LTD provides transparent information, communication and conditions for the exercise of the rights of data subjects under Article 12 of the Regulation.
GALAXY INVESTMENT GROUP LTD collects, processes and stores personal data for the following purposes:
- DELETE - repeating
- Provision of services;
- Execution of sales;
- For marketing activities - related to our projects, events, campaigns, offers, proposals related to our activities and news about our company and (if explicitly requested to receive such information), etc.
- For communication with you - regarding contractual and non-contractual relationships;
- For legal purposes - to resolve legal disputes and protect the rights and legitimate interests of the company;
- For the performance of employment and insurance relations, including for recruitment purposes;
TYPES OF DATA COLLECTED, PROCESSED AND STORED BY GALAXY INVESTMENT GROUP LTD.
For the purposes set out in section 4 of this policy, GALAXY INVESTMENT GROUP LTD collects, processes and stores the following categories of data:
Personal identification data: first name, middle name, last name;
- Contact data: address, telephone, email, position, etc.;
- IP address data (when logging into the site);
- Data required for employment relations (according to company procedures), etc.;
- Data depending on the specificity of the services used, respectively the type of legal relationship in which you are involved;
GALAXY INVESTMENT GROUP LTD does not collect: personal data related to racial or ethnic origin; revealing political, religious or philosophical beliefs; genetic and biometric data;
STORAGE PERIOD OF PERSONAL DATA:
- GALAXY INVESTMENT GROUP LTD will retain your personal data for the period necessary to fulfil the purposes described in this Policy, unless a longer retention period is necessary or permitted by applicable law. The storage shall be carried out in compliance with the statutory time limits for a certain category of documents (payrolls, financial statements, accounting records, etc.), as well as the statutory limitation periods in the Tax and Social Security Procedural Code (TSSC), the Accounting Act, the Social Security Code (SSC), the Obligations and Contracts Act. After the expiry of the retention period, GALAXY INVESTMENT GROUP LTD shall take the necessary care to delete and destroy all data without undue delay in accordance with the adopted internal company procedure for the destruction of personal data;
- GALAXY INVESTMENT GROUP LTD shall notify you in the event that the data retention period needs to be extended in order to fulfil the purposes, perform the contract, for the legitimate interests of GALAXY INVESTMENT GROUP LTD or otherwise.
ERASURE
GALAXY INVESTMENT GROUP LTD will erase your personal data as soon as possible and in such a way that it can be reproduced or retrieved. GALAXY INVESTMENT GROUP LTD has adopted a corporate procedure for the erasure of personal data.
SOURCES OF PERSONAL DATA
The personal data collected by GALAXY INVESTMENT GROUP LTD is collected from the individuals to whom it relates; through the contact forms on the company’s websites; from third parties – our contractors and/or intermediaries, subject to the requirements of the Regulation.
RIGHTS OF PERSONS WHOSE DATA IS PROCESSED BY GALAXY INVESTMENT GROUP LTD
Right of access:
You have the right to request and obtain from GALAXY INVESTMENT GROUP LTD confirmation as to whether personal data relating to you is being processed; To obtain access to the data relating to you and information relating to the collection, processing and storage of your personal data; GALAXY INVESTMENT GROUP LTD shall provide you, upon request, with a copy of the personal data processed relating to you in electronic or other appropriate form; Providing access to the data is free of charge, but GALAXY INVESTMENT GROUP LTD reserves the right to charge an administrative fee in the event of repetitive or excessive requests;
Right to rectification:
You may rectify or complete inaccurate or incomplete personal data related to you directly by making a request to GALAXY INVESTMENT GROUP LTD;
Right to erasure (right to be forgotten):
You have the right to request GALAXY INVESTMENT GROUP LTD to erase the personal data related to you, and GALAXY INVESTMENT GROUP LTD is obliged to erase it without undue delay when the grounds provided for by law are present and if there is no other ground for lawful processing or lawful ground for refusal of the controller to erase the data; GALAXY INVESTMENT GROUP LTD shall not delete data for which it has a legal obligation to retain, including for defence, in respect of legal claims made against it or to prove its rights.
Right to restriction:
You have the right to require GALAXY INVESTMENT GROUP LTD to restrict the processing of personal data relating to you where: you contest the accuracy of the personal data, for a period that allows GALAXY INVESTMENT GROUP LTD to verify the accuracy of the personal data; the processing is unlawful, and you do not want your personal data to be erased but only for its use to be restricted; GALAXY INVESTMENT GROUP LTD no longer needs the personal data for the purposes of processing, but you require it for the establishment or defence of your legal claims; You have objected to the processing pending verification whether GALAXY INVESTMENT GROUP LTD’s legitimate grounds override your interests;
Right to portability:
You may, at any time, retrieve the data stored and processed about you in connection with your relationship with GALAXY INVESTMENT GROUP LTD by making a written request to the controller. Where it is technically feasible, you may request a direct transfer of the personal data to a controller designated by you;
Right to obtain information:
You have the right to request to be notified of any action relating to rectification, erasure or restriction of processing;
Right to object:
You may object at any time to the processing by GALAXY INVESTMENT GROUP LTD of personal data concerning you where the processing is for the performance of a task carried out in the public interest or on the basis of official authority; for the purposes of the legitimate interests of the controller; for scientific or historical research purposes, or for statistical purposes, including profiling or processing for direct marketing purposes;
You have the right to refuse to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or significantly affects you. GALAXY INVESTMENT GROUP LTD does not carry out automated data decision-making.
Right of appeal:
You have the right to lodge a complaint with the Data Protection Commission for breaches of Regulation (EU) No 2016/679 as of 27 April 2016, and the right to an effective resolution against the DPA, controller or processor of your personal data;
Right to compensation:
You have the right to compensation for material or non-material damage suffered as a result of a breach of Regulation (EU) 2016/679.
In order to exercise the above-mentioned rights, you must make a request to GALAXY INVESTMENT GROUP LTD and verify your identity and the identity of the person to whom the data relates.
You may exercise your rights as follows:
At the office of GALAXY INVESTMENT GROUP LTD located at: 4003 Plovdiv, 5 Dunav Blvd.
By phone, mobile +359 32 92 4747
Via Internet by e-mail address: office@galaxy-bg.com; privacy@galaxy-bg.com
Website: www.galaxy-bg.com
WITHDRAWAL OF CONSENT TO THE PROCESSING OF YOUR PERSONAL DATA
In case you have given your consent to the processing of your personal data for one or more specific purposes, and you do not want all or part of the data to continue to be processed by GALAXY INVESTMENT GROUP LTD for a specific or all processing purposes, you may withdraw your consent at any time by making a free text request to GALAXY INVESTMENT GROUP LTD
TRANSFER OF PERSONAL DATA TO THIRD COUNTRIES OR INTERNATIONAL ORGANISATIONS
Transfers of personal data that are processed or intended to be processed after the transfer to a third country or to an international organisation outside the EU shall only be carried out by GALAXY INVESTMENT GROUP LTD under the terms of the General Data Protection Regulation – Regulation (EU) 2016/679, subject to the conditions set out in Chapter V of the Regulation. GALAXY INVESTMENT GROUP LTD shall apply all provisions of the Regulation so as not to compromise the necessary level of protection of natural persons afforded by the Regulation.
In the event that GALAXY INVESTMENT GROUP LTD transfers personal data to a third country or to an international organisation outside the EU, such transfer shall be carried out in accordance with the Company’s Non-EU Data Transfer Procedure and the data subjects shall be notified in advance and their Consent for the transfer of personal data shall be required.
PERSONS TO WHOM YOUR PERSONAL DATA IS PROVIDED
The persons, employees of GALAXY INVESTMENT GROUP LTD, who have access to your personal data are strictly defined in the Company’s Internal Regulations and Procedures for the processing of personal data, and the level of access to the various personal data registers is defined.
It is possible that GALAXY INVESTMENT GROUP LTD transmits your personal data to third parties who are involved in the processing or are processors of personal data, to administrative structures and bodies of executive power, etc., or to persons related to GALAXY INVESTMENT GROUP LTD (for the purposes of financial statements). In all cases, the transmission of personal data by GALAXY INVESTMENT GROUP LTD is carried out for the fulfilment of the processing purposes and in strict compliance with the requirements of Regulation (EU) 2016/679.
BREACHES AND NOTIFICATION OF BREACHES
- "Personal data breach" means a breach of security that results in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data that is transmitted, stored or otherwise processed by GALAXY INVESTMENT GROUP LTD.
- In the event of a personal data breach which is likely to result in a risk to the rights and freedoms of natural persons, GALAXY INVESTMENT GROUP LTD shall notify the Personal Data Protection Commission of the breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it.
- If GALAXY INVESTMENT GROUP LTD becomes aware of a breach of security of your personal data which may pose a high risk to your rights and freedoms, we shall notify you without undue delay of the breach and of the measures taken or to be taken.
GALAXY INVESTMENT GROUP LTD MAY NOT NOTIFY YOU IF:
- it has taken appropriate technical and organisational measures to protect the data affected by the security breach;
- it has subsequently taken measures to ensure that the breach will not result in a high risk to your rights;
- Notification would require disproportionate effort.
CHANGES TO THE PRIVACY POLICY
GALAXY INVESTMENT GROUP LTD has the right to update, amend and supplement the Privacy Policy at any time in the future if the circumstances require it.
CONTACTS AND LINKS
- Information about GALAXY INVESTMENT GROUP LTD as a Data Controller.
In connection with the processing of your personal data, you can contact us using the following contacts:
Name: GALAXY INVESTMENT GROUP LTD
UIC: 115509755
Headquarters and registered office: 1592 Sofia, 2 Prof. Tsvetan Lazarov Blvd.
Address for correspondence: Bulgaria, Plovdiv district, 4003 Plovdiv, 5 Dunav Blvd.
Phone: +359 32 92 4747
E-mail: office@galaxy-bg.com
Website: www.galaxy-bg.com
Contact details of the Data Protection Officer:
Address: country Bulgaria, Plovdiv district, 4003 Plovdiv, 5 Dunav Blvd.
Phone: +359 32 92 4747
E-mail: privacy@galaxy-bg.com
- Information on the competent supervisory authority:
Name: Commission for Personal Data Protection
Headquarters and registered office:1592 Sofia, 2 Prof. Tsvetan Lazarov Blvd.
Headquarters and registered office: 1592 Sofia, 2 Prof. Tsvetan Lazarov Blvd.
Phone: +359 2 915 3518
E-mail: kzld@government.bg; kzld@cpdp.bg
Website: www.cpdp.bg
If you believe that we are violating your rights related to the processing of your personal data, and in accordance with the requirements of the “General Data Protection Regulation” – Regulation (EU) 2016/679, you have the right to lodge a complaint with the Data Protection Officer, lodge a complaint with a supervisory authority and seek judicial redress as follows:
- Right to lodge a complaint with a supervisory authority
If you wish to lodge a complaint about the processing of your personal data carried out by us, or about the way in which we have handled your complaint, you have the right to lodge a complaint with the Data Protection Commission and the Data Protection Officer (if available).
You can make a complaint in one of the following ways:
- In person, on paper, at the office of the CPDP at 1592 Sofia, 2 Prof. Tsvetan Lazarov Blvd.
- By letter addressed to: 1592 Sofia, 2 Prof. Tsvetan Lazarov Blvd., Personal Data Protection Commission.
- By fax to: 029153525.
- By electronic mail to the email address of the CPDP (kzld@cpdp.bg). In this case, your complaint must be in the form of an electronic document signed with an electronic signature (not scanned).
- Via the CPDP website at https://cpdp.bg/?p=pages&aid=6 in the manner described on the relevant page. In this case, your complaint must be in the form of an electronic document signed with an electronic signature.
In either case, the complaint should contain:
- details of the complainant - name, address, contact telephone number, e-mail address (if available)
- the nature of the complaint
- other information and documents you consider relevant to the complaint
- date and signature (electronic for electronic documents, handwritten for paper documents)
The CPDP provides a complaint form to the Commission (to assist and guide citizens) in relation to the misuse of personal data in the voters’ lists supporting the registration of political entities. The form can be downloaded from the following page: https://cpdp.bg/userfiles/file/Documents_2017/Forma_jalba_politicheski subekti.doc