Kiril Miroslavov Hristov, applies the following Privacy Policy in his commercial relations with employees under labor contracts and with his contractors:
Kiril Miroslavov Hristov is the "data controller" within the meaning of Article 4, paragraph 7 of the General Data Protection Regulation and as such collects, processes, and stores certain information about individuals.
I. Legal Basis
This Privacy Policy is issued based on the Personal Data Protection Act and its subordinate regulations and the General Data Protection Regulation (EU) 2016/679.
1. The Data Controller takes necessary measures to ensure that the processed personal data is not subject to unlawful disclosure. The Data Controller is aware of and follows the principles stipulated in the General Regulation, namely:
1.1. Personal data is processed lawfully, fairly, and transparently. Each employee, contractor, or their representative gives their voluntary consent for the processing of the personal data provided by them in the process of negotiating and executing a contract between them and the Data Controller.
1.2. Personal data is collected for specific, explicitly stated, and legitimate purposes and is not processed further in a manner incompatible with those purposes.
1.3. Personal data is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
1.4. Each employee/representative of a contractor and client is required to ensure the accuracy of the personal data they provide and, if necessary, to keep it up-to-date.
1.5. Personal data is stored in a form that allows the identification of the data subjects for no longer than necessary for the purposes for which the personal data is processed.
1.6. Personal data is processed in a manner that ensures an appropriate level of security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.
1.7. Right to erasure ("right to be forgotten") of personal data processed unlawfully or with no legal basis. Each employee/client/contractor has the opportunity at any time to submit a request for correction and/or deletion of their personal data after the termination of the contractual relationship. The Data Controller is obliged to review and fulfill the request without undue delay and in all cases within one month of receiving the request.
1.8. Right to data portability - the data subject has the right to receive the personal data concerning them and which they have provided to the Data Controller in a structured, commonly used, and machine-readable format.
II. Objectives of the Policy
2. This Policy aims to:
2.1. Ensure compliance with applicable data protection legislation and follow established best practices;
2.2. Establish mechanisms for maintaining and protecting records;
2.3. Define the obligations of data processing officers and/or individuals who have access to personal data and work under the supervision of data processors, and their responsibility in case of failure to meet these obligations;
2.4. Protect the rights of staff, clients, and partners;
2.5. Be transparent about how personal data is stored and protected;
2.6. Establish necessary technical and organizational measures to protect personal data from unlawful processing (accidental or unlawful destruction, accidental loss, unauthorized access, alteration, or dissemination, as well as other illegal forms of processing);
2.7. Be protected in case of risks of breaches;
III. Scope
This Policy applies to the processing of personal data of employees, managers, clients, suppliers, contractors, business contacts, and other individuals with whom the Data Controller has a connection or wishes to establish a business connection.
IV. Collection of Personal Data
Personal data means any information relating to an identified or identifiable natural person, directly or indirectly, through an identification number or through one or more specific characteristics. It includes data of any nature that alone or in combination with other data can lead to the unequivocal identification of a specific natural person.
4.1 Purposes of Data Collection
The Data Controller collects personal data in connection with the following purposes:
4.1.1. To perform activities related to the conclusion, existence, amendment, and termination of contractual relationships, including:
4.1.1.1. Preparation of any documents;
4.1.1.2. To establish contact with the contact person by phone, email, or any other lawful manner;
4.1.1.3. To maintain accounting records in connection with the execution of contracts to which the Data Controller is a party;
4.1.1.4. To process payments related to the contracts with the Data Controller;
4.2. Data Collection
Personal data for each individual is provided voluntarily by the individuals themselves and is collected by the Data Controller in compliance with a legal obligation, in connection with the conclusion of a contract and/or the fulfillment of obligations under a concluded contract according to the provisions of the Labor Code, the Code of Social Security, the Commercial Act, the Accounting Act, the Obligations and Contracts Act, the Value Added Tax Act, and others, and the conditions specified in the particular contract through:
Paper - written documents (including powers of attorney, contracts, garnishment notices, bank information, etc.), via email - provided in connection with the performance of commercial contracts
V. Processing of Personal Data
Processing of personal data means any operation or set of operations performed on personal data, whether by automated or non-automated means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure to third parties for transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction.
5.1 The data provided by employees and individuals representing contractors include: full name, permanent and/or current address, email address and phone number, and financial data.
VI. Breaches. Notification of Breaches
A data breach occurs when personal data for which Kiril Miroslavov Hristov is responsible is affected by a security incident that leads to a breach of the confidentiality, availability, or integrity of the personal data. In this sense, a data breach occurs when there is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of data, which is transmitted, stored, or otherwise processed.
6.1 In case of a personal data breach that is likely to pose a risk to the rights and freedoms of individuals, the Data Controller (through the relevant employee), without undue delay and where possible - not later than 72 hours after becoming aware of it, notifies the Personal Data Protection Commission of the breach.
6.2 The Data Controller documents each personal data breach, including the facts related to the breach, the consequences of the breach, and the actions taken to address it.
VII. Destruction
Accounting and commercial information, as well as all other data and documents relevant for tax purposes and mandatory social security contributions, are retained by the Data Controller for the following periods:
7.1.1. Payroll records - 50 years;
7.1.2. Accounting registers and financial reports - 10 years;
7.1.3. Documents for tax and social security control - 5 years after the expiration of the limitation period for the public obligation with which they are related;
7.1.4. All other records - 5 years.
7.2. After the expiration of the storage period, the information carriers (paper or technical) that are not subject to transfer to the National Archive Fund may be destroyed.
7.3. After the expiration of the storage period, data is destroyed as quickly as possible by shredding paper carriers and by erasing and deleting the relevant files from the Data Controller's computers for technical carriers.
IX. Additional Provisions
For the purposes of this Policy:
§ 1. "Data Controller" is Kiril Miroslavov Hristov, and actions on behalf of the controller are carried out by Kiril Miroslavov Hristov or an explicitly authorized person.
§ 2. "Data Processor" for employees and workers employed under labor or other contracts for performing specific work is the designated data protection officer.
§ 3. Integral parts of this Policy are the records maintained by Kiril Miroslavov Hristov as a controller - "Personal Data of Employees" and "Personal Data of Contractors."
§ 4. The Privacy Policy was adopted by Kiril Miroslavov Hristov on 14.05.2018 and is available to every employee/contractor in paper or electronic format.