Privacy Policy
Information regarding the rights of individuals in relation to personal data protection
Information about the company processing your data:
Company name: Nova Valna RG Ltd.
UIC/BULSTAT: BG131056044
Registered office and address: 45 Rayko Daskalov St., Radomir
Correspondence address: 45 Rayko Daskalov St., Radomir
Phone: 0893593293
Email: info@rali.wine
Website: www.rali.wine
Information about the competent supervisory authority for personal data protection:
Name: Commission for Personal Data Protection
Registered office and address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592
Correspondence address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592
Phone: 02 915 3 518
Nova Valna RG Ltd. (hereinafter referred to as the “Controller” or the “Company”) carries out its activities in accordance with the Personal Data Protection Act and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) regarding the protection of natural persons with regard to the processing of personal data and the free movement of such data. This information aims to inform you about all aspects of the processing of your personal data by the Company and about your rights in relation to this processing.
Legal grounds for collecting, processing, and storing your personal data
Art. 1. The Controller collects and processes your personal data in connection with your use of the online store www.rali.wine and the conclusion of contracts with the Company, pursuant to Art. 6(1) of Regulation (EU) 2016/679 (GDPR), and in particular on the following grounds:
- Explicit consent provided by you as a customer;
- Performance of the Controller’s obligations under a contract with you;
- Compliance with a legal obligation applicable to the Controller;
- For the purposes of the legitimate interests of the Controller or a third party;
Purposes and principles for collecting, processing, and storing your personal data
Art. 2.
(1) We collect and process personal data that you provide to us in connection with your use of the online store and the conclusion of a contract with the Company, including for the following purposes:
- Creating a user profile and providing full functionality of the online store;
- Concluding and performing distance contracts;
- Identifying a party to the contract;
- Accounting purposes;
- Statistical purposes;
- Ensuring information security;
- Ensuring the performance of the contract for the respective service;
- Sending newsletters, if you have explicitly agreed to receive them;
(2) We follow the following principles when processing your personal data:
- Lawfulness, fairness, and transparency;
- Purpose limitation;
- Data minimization and relevance to the purposes of processing;
- Accuracy and up-to-date data;
- Storage limitation in line with the purposes;
- Integrity and confidentiality, ensuring an appropriate level of data security;
(3) When processing and storing personal data, the Controller may also process and store personal data in order to protect its legitimate interests, including:
- Fulfillment of obligations to the National Revenue Agency, the Ministry of Interior, and other state and municipal authorities.
What types of personal data we collect, process, and store
Art. 3.
(1) The Company performs the following operations with the personal data you provide for the following purposes:
User registration in the online store and performance of a distance sales contract – the purpose of this operation is to create a user profile for using the online store to purchase goods and to provide contact details for the delivery of purchased products. Registration and account creation are not mandatory for using the service, and the online store is largely accessible even without creating a profile.
Conclusion from the impact assessment: Based on the conducted impact assessment, the operation “User registration in the online store and performance of a distance sales contract” is permissible and provides sufficient guarantees for the protection of the rights and legitimate interests of data subjects in accordance with GDPR requirements.
Conclusion and performance of a commercial transaction with a client or partner – the purpose of this operation is to conclude and perform a contract with a commercial partner or client and to administer it. Given the limited scope of the personal data collected and the fact that part of it is obtained from publicly available sources, conducting an impact assessment is not required.
Sending a newsletter – the purpose of this operation is to manage the process of sending newsletters to customers who have opted in to receive them. Given the limited scope of personal data collected, conducting an impact assessment is not required.
Exercising the right of withdrawal or submitting a complaint – the purpose of this operation is to manage the process of handling withdrawal requests or customer complaints. Given the limited scope of personal data collected, conducting an impact assessment is not required.
(2) The Controller processes the following categories of personal data and information for the following purposes and on the following legal grounds:
Your identification data (email, name, etc.)
Purpose of data collection:
- To establish contact with the user and send information;
- For user registration in the online store;
- For sending newsletters.
Legal basis for processing:
By accepting the General Terms and Conditions and registering in the online store, placing an order without registration, or entering into a written contract, a contractual relationship is established between you and the Controller. On this basis, we process your personal data under Art. 6(1)(b) GDPR. Your data for receiving newsletters is processed based on your explicit consent under Art. 6(1)(a) GDPR.
Delivery data (names, phone number, address, etc.)
Purpose of data collection:
To fulfill the Controller’s obligations under a contract for the purchase and delivery of goods.
Legal basis for processing:
By accepting the General Terms and Conditions and registering in the online store, placing an order without registration, or entering into a written contract, a contractual relationship is established, and your personal data is processed under Art. 6(1)(b) GDPR.
Additional data provided by you
If you choose to complete your profile, you may provide additional information such as first name, last name, and phone number.
Purpose of data collection:
To supplement the information in your user account.
Legal basis for processing:
You have given explicit consent for processing your personal data for one or more specific purposes under Art. 6(1)(a) GDPR at the time of registration. Providing this data is not mandatory for registration in the online store.
(3) The Controller does not collect or process personal data that relates to:
- racial or ethnic origin;
- political, religious, or philosophical beliefs, or membership in trade unions;
- genetic and biometric data, health data, or data concerning a person’s sex life or sexual orientation.
(4) Personal data is collected by the Controller from the individuals to whom it relates.
(5) The Company does not carry out automated decision-making based on personal data.
Art. 4.
(1) The Company performs the following operations with personal data provided by you, in your capacity as legal representatives or authorized persons of legal entities – commercial partners, for the following purposes:
Conclusion and performance of a commercial transaction:
For the conclusion and execution of a commercial transaction with a company, we process only the full name of the legal representative or the person authorized by the company.
Conclusion from the impact assessment:
Given the limited number of individuals whose data is processed and the limited scope of personal data collected, conducting an impact assessment is not required for this operation.
(2) Personal data is collected by the Controller from the individuals to whom it relates, as well as from the Commercial Register maintained by the Registry Agency.
(3) The Company does not carry out automated decision-making based on personal data.
Art. 5. The Controller may use cookies in order to provide full website functionality, improve user experience, perform statistical analysis, facilitate access, and for other purposes, to which you agree by using our website. You can manage and/or delete cookies at any time through your browser settings. Cookies do not constitute personal data and are not used to identify visitors or users of the online store.
Retention period of your personal data
Art. 6.
(1) The Controller stores your personal data for no longer than the duration of your account in the online store. After your account is deleted, the Controller takes the necessary steps to delete or anonymize your data without undue delay.
(2) The Controller processes personal data provided when placing an order without registration until the order is completed, unless you have given explicit consent for your data to be processed for purposes such as service improvement, personalized content, individual offers, promotions, and statistical analysis.
(3) The Controller stores personal data related to online orders for a period of 5 years for the purpose of protecting its legal interests in the event of legal or administrative disputes with users of the online store.
(4) The Controller will notify you if it is necessary to extend the data retention period in order to comply with a legal obligation or to protect legitimate interests.
(5) The Controller stores personal data that must be retained under applicable law for the required statutory period, which may exceed the duration of your account or the completion of your order.
Art. 7. The Controller stores personal data of legal representatives of its commercial partners for the duration of the contract, as well as for the protection of its legitimate interests and compliance with legal obligations, and this period may exceed the term of the contract.
Transfer of your personal data for processing
Art. 8.
(1) The Controller may, at its discretion, transfer part or all of your personal data to personal data processors for the purpose of fulfilling the processing objectives you have agreed to, in compliance with Regulation (EU) 2016/679 (GDPR).
(2) The Controller will inform you in case of intention to transfer part or all of your personal data to third countries or international organizations.
Your rights regarding the collection, processing, and storage of your personal data
Withdrawal of consent for processing your personal data
Art. 9.
(1) If you do not wish your personal data to be processed for marketing purposes and receiving newsletters, you may withdraw your consent at any time by completing the withdrawal form (Appendix No. 1) or by sending a request in free text via email.
(2) After receiving your request, we will send you an email to the address you have provided for receiving newsletters and marketing communications, containing detailed instructions for verifying your identity as a data subject requesting withdrawal of consent.
(3) Withdrawal of consent does not affect the lawfulness of the processing carried out by the Controller prior to the withdrawal.
Right of access
Art. 10.
(1) You have the right to request and obtain confirmation from the Controller as to whether personal data relating to you is being processed by submitting a request in free text via email.
(2) You have the right to access your personal data, as well as information related to its collection, processing, and storage.
(3) After receiving your request, we will send you an email to the address you used for registration or placing orders in the online store, containing detailed instructions for verifying your identity as the data subject requesting access.
(4) After completing the verification under paragraph 3, the Controller shall provide you, upon request, with a copy of your personal data in electronic or another appropriate format.
(5) Access to your data is provided free of charge; however, the Controller reserves the right to charge an administrative fee in cases of repetitive or excessive requests.
Right to rectification or completion
Art. 11.
(1) You may at any time correct or complete inaccurate or incomplete personal data related to you via the “Edit Profile” option.
(2) You may also correct or complete your personal data directly through your profile on the website or by submitting a request to the Controller via email, using the form in Appendix No. 4 or a free-text request.
Right to erasure (“right to be forgotten”)
Art. 12.
(1) You have the right to request that the Controller delete part or all of your personal data, and the Controller is obliged to delete it without undue delay when one of the following grounds applies:
- the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
- you withdraw your consent on which the processing is based and there is no other legal ground for processing;
- you object to the processing of your personal data, including for direct marketing purposes, and there are no overriding legitimate grounds for processing;
- the personal data has been processed unlawfully;
- the personal data must be erased to comply with a legal obligation under EU law or the law of a Member State applicable to the Controller;
- the personal data has been collected in relation to the offering of information society services.
(2) The Controller is not obliged to delete personal data if it is processed and stored for the following purposes:
- exercising the right of freedom of expression and information;
- compliance with a legal obligation under EU law or the law of a Member State applicable to the Controller, or for the performance of a task carried out in the public interest or in the exercise of official authority;
- reasons of public interest in the area of public health;
- archiving purposes in the public interest, scientific or historical research, or statistical purposes;
- the establishment, exercise, or defense of legal claims.
(3) To exercise your right to be forgotten, you need to send a request for deletion of your personal data via email, by completing the form in Appendix No. 2 or by submitting a free-text request. The Controller will then send an email to the address you used for registration or placing orders, containing detailed instructions for verifying your identity as a user and data subject requesting deletion.
(4) After verifying your identity in accordance with the instructions provided, we will delete all personal data we process about you in accordance with paragraph 3.
(5) If you have an active order in process, the earliest moment you can request to be “forgotten” is after the successful completion of the order.
Right to restriction of processing
Art. 13.
(1) You have the right to request that the Controller restrict the processing of your personal data by sending a request in free text via email when:
- you contest the accuracy of the personal data, for a period allowing the Controller to verify its accuracy;
- the processing is unlawful, but you do not want the personal data to be erased, only its use to be restricted;
- the Controller no longer needs the personal data for processing purposes, but you require it for the establishment, exercise, or defense of legal claims;
- you have objected to processing pending verification of whether the Controller’s legitimate grounds override your interests.
(2) After receiving your request, we will send an email to the address you used for registration or placing orders, containing detailed instructions for verifying your identity as a user and data subject requesting restriction of processing.
(3) After completing the verification, the Company will suspend the processing of your data but will not remove any content you may have published in the online store, if applicable.
Right to data portability
Art. 14.
(1) If you have given consent for the processing of your personal data, or if processing is necessary for the performance of a contract with the Controller, or if your data is processed by automated means, you may:
- request that the Controller provide your personal data in a structured, readable format and transfer it to another Controller;
- request that the Controller directly transfer your personal data to another controller designated by you, where technically feasible.
(2) You may exercise your right to data portability by sending a completed form (Appendix No. 3) or a free-text request via email. The Controller will then send an email to the address you used for registration or placing orders, containing detailed instructions for verifying your identity.
(3) After verification, the Company will send the personal data it processes about you to the email address you have specified, in XML format.
Right to obtain information
Art. 15. You may request that the Controller inform you about all recipients to whom the personal data, for which rectification, erasure, or restriction of processing has been requested, has been disclosed. The Controller may refuse to provide this information if it would be impossible or would require disproportionate effort.
Right to object
Art. 16. You may object at any time to the processing of your personal data by the Controller, including where such data is processed for profiling or direct marketing purposes.
Your rights in case of a personal data breach
Art. 17.
(1) If the Controller establishes a personal data breach that is likely to result in a high risk to your rights and freedoms, it shall notify you without undue delay of the breach, as well as of the measures taken or to be taken.
(2) The Controller is not required to notify you if:
- it has implemented appropriate technical and organizational protection measures regarding the data affected by the breach;
- it has subsequently taken measures ensuring that the breach is unlikely to result in a high risk to your rights;
- notification would involve disproportionate effort.
Recipients of your personal data
Art. 18.
(1) For the purposes of processing your personal data and providing the service in its full functionality, and taking into account your interests, the Controller may provide your data to the following data processors:
Data Processor: Nova Valna RG Ltd.
Purpose of processing: Processing and delivery of registered orders in the online store
(2) Data processors comply with all legal and security requirements when processing and storing your personal data.
Art. 19. The Controller does not transfer your personal data to third countries.
Art. 20. In case your rights under the above or applicable personal data protection legislation are violated, you have the right to file a complaint with the Commission for Personal Data Protection, as follows:
Name: Commission for Personal Data Protection
Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592
Correspondence address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592
Phone: 02 915 3 518
Art. 21. You may exercise all your rights regarding the protection of your personal data using the forms attached to this information. These forms are not mandatory, and you may submit your requests in any form that contains a clear statement and allows you to be identified as the data subject.
Art. 22. Where consent relates to data transfer, the Controller shall describe the possible risks associated with transferring data to third countries in the absence of an adequacy decision and appropriate safeguards.
Appendix No. 1
Consent Withdrawal Form
Your name*: …………………….
Your email used in the online store*: …………………….
Contact details (email)*: …………………….
To
Company name: Nova Valna RG Ltd.
UIC/BULSTAT: BG131056044
Registered office and address: 45 Rayko Daskalov St., Radomir
Correspondence address: 45 Rayko Daskalov St., Radomir
Phone: 0893593293
Email: info@rali.wine
Website: www.rali.wine
I hereby withdraw my consent for the processing of my personal data for the purposes of receiving newsletters, promotional messages, or other marketing materials, and I confirm that I am aware of the conditions for withdrawal in accordance with the mandatory information on personal data protection rights provided by the online store.
In case of violation of your rights under the above or applicable personal data protection legislation, you have the right to file a complaint with the Commission for Personal Data Protection, as follows:
Name: Commission for Personal Data Protection
Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592
Correspondence address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592
Phone: 02 915 3 518
Appendix No. 2
Request to be “forgotten” – request for deletion of personal data
Your name*: …………………….
Your email used for registration or orders in the online store*: …………………….
Contact details (email)*: …………………….
To
Company name: Nova Valna RG Ltd.
UIC/BULSTAT: BG131056044
Registered office and address: 45 Rayko Daskalov St., Radomir
Correspondence address: 45 Rayko Daskalov St., Radomir
Phone: 0893593293
Email: info@rali.wine
Website: www.rali.wine
Please delete all personal data related to me that you collect, process, and store, provided by me or by third parties related to me, based on the identification provided.
I declare that I am aware that some or all of my personal data may continue to be processed and stored by the Controller for the purposes of fulfilling legal obligations.
In case of violation of your rights, you have the right to file a complaint with the Commission for Personal Data Protection (details as above).
Appendix No. 3
Request for data portability
Your name*: …………………….
Your email used for registration or orders in the online store*: …………………….
Contact details (email)*: …………………….
To
Company name: Nova Valna RG Ltd.
UIC/BULSTAT: BG131056044
Registered office and address: 45 Rayko Daskalov St., Radomir
Correspondence address: 45 Rayko Daskalov St., Radomir
Phone: 0893593293
Email: info@rali.wine
Website: www.rali.wine
Please provide all personal data related to me that you collect, process, and store in your databases in XML format to the following:
Email: …………………….
Receiving Controller: Nova Valna RG Ltd.
Company name: Nova Valna RG Ltd.
Identification number: BG131056044
Email: info@rali.wine
In case of violation of your rights, you have the right to file a complaint with the Commission for Personal Data Protection (details as above).
Appendix No. 4
Request for data correction
Your name*: …………………….
Your email used for registration or orders in the online store*: …………………….
Contact details (email)*: …………………….
To
Company name: Nova Valna RG Ltd.
UIC/BULSTAT: BG131056044
Registered office and address: 45 Rayko Daskalov St., Radomir
Correspondence address: 45 Rayko Daskalov St., Radomir
Phone: 0893593293
Email: info@rali.wine
Website: www.rali.wine
Please correct the following personal data that you collect, process, and store, provided by me or by third parties related to me, as follows:
Data to be corrected:
…………………………………………..
Correction to be made:
…………………………………………..
In case of a violation of your rights under the above or applicable personal data protection legislation, you have the right to file a complaint with the Commission for Personal Data Protection, as follows:
Name: Commission for Personal Data Protection
Registered office and address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592
Correspondence address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592
Phone: 02 915 3 518
