Privacy Policy
At NIVARIA OOD ("we," "our," or "the Company"), we are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and purchase our natural and organic body care products.
1. LEGAL BASIS FOR PROCESSING
We process your personal data based on the following legal grounds provided by the General Data Protection Regulation (GDPR):
-
Consent: When you explicitly agree to receive our newsletter or marketing materials.
-
Contractual Necessity: To process and deliver your orders.
-
Legal Obligation: To comply with Bulgarian accounting and tax laws (e.g., invoicing).
-
Legitimate Interest: To improve our services and ensure the security of our website.
-
2. DATA WE COLLECT
We may collect and process the following types of personal data:
-
Contact Details: Name, email address, phone number, and shipping/billing address.
-
Transaction Data: Details about products purchased and payments made (processed via secure payment gateways).
-
Technical Data: IP address, browser type, and usage data collected through cookies.
-
3. HOW WE USE YOUR DATA
Your information is used to:
-
Manage your orders, payments, and deliveries.
-
Provide customer support and respond to inquiries.
-
Send promotional emails (only if you have opted in).
-
Comply with legal requirements in the Republic of Bulgaria.
-
4. DATA RETENTION
We store your data only as long as necessary for the purposes for which it was collected:
-
Accounting records: 10 years (as required by Bulgarian law).
-
Newsletter data: Until you withdraw your consent.
-
Customer account data: Until you request deletion, or after [X] years of inactivity.
-
5. YOUR RIGHTS
Under GDPR and Bulgarian law, you have the right to:
-
Access: Request a copy of your personal data.
-
Rectification: Correct inaccurate or incomplete data.
-
Erasure ("Right to be Forgotten"): Request deletion of your data when no longer needed.
-
Restriction: Limit how we process your data.
-
Portability: Receive your data in a structured, machine-readable format.
-
Objection: Object to processing based on legitimate interests or direct marketing.
-
Withdraw Consent: At any time, without affecting the lawfulness of processing prior to withdrawal.
-
To exercise these rights, contact us at [Inserire Email].
6. THIRD-PARTY DISCLOSURES
We do not sell your data. We only share it with trusted partners necessary for our operations:
-
Courier Services: For delivery of your products.
-
Payment Providers: To process secure transactions.
-
IT & Hosting Services: To maintain our website infrastructure.
-
Public Authorities: Only when required by Bulgarian or EU law.
-
7. DATA SECURITY
We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, or alteration, in compliance with Art. 32 of the GDPR.
8. SUPERVISORY AUTHORITY
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Bulgarian supervisory authority:
Commission for Personal Data Protection (CPDP)
Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
Website: www.cpdp.bg
Email: kzld@cpdp.bg