Privacy Policy

NBG Company Ltd.

This policy is effective as of 28 February 2024

Last updated: 28 February 2024

 

This Privacy Policy for NBG Company Ltd. (“we,” “us,” or “our“) describes how and why we might collect, store, use, and/or share (“process“) your information when you use our services, such as when you use our website https://nbg.eu to view, register and/or purchase goods.

We respect your privacy and comply with any applicable law and regulation regarding any personal information we may collect about you, including across our website, and other sites we own and operate.

Personal information is any information about you which can be used to identify you. This includes information about you as a person (such as name, address, and date of birth), your devices, payment details, and even information about how you use a website or online service.

Information and contact details of the controller

NBG Company Ltd. is a controller, with regards to the definition of the General Data Protection Regulation (GDPR). NBG Company Ltd. is a company, registered in the Republic of Bulgaria, with UIC: 206946657, having its seat and management address in Varna, Primorski district, 68 Vasil Levski blvd.

You can contract us via email at: [email protected] or [email protected].

Collection of personal information

We will most likely collect your personal information directly from you or indirectly through our contractors, service providers and/or third parties who lawfully provide us with your personal information.

We undertake, where necessary, to obtain your consent and/or to allow you to refuse the use of your personal information for certain purposes.

In each specific case, you will be informed about the purposes for which your personal data is collected by means of the various online data collection forms.

Types of information we collect

Information we collect falls into one of two categories: “voluntarily provided” information and “automatically collected” information.

“Voluntarily provided” information refers to any information you knowingly and actively provide us when using or participating in any of our services and promotions.

“Automatically collected” information refers to any information automatically sent by your devices in the course of accessing our products and services.

Log data

When you visit our website, our servers may automatically log the standard data provided by your web browser. It may include your device’s Internet Protocol (IP) address, your browser type and version, the pages you visit, the time and date of your visit, the time spent on each page, and other details about your visit.

Additionally, if you encounter certain errors while using the site, we may automatically collect data about the error and the circumstances surrounding its occurrence. This data may include technical details about your device, what you were trying to do when the error happened, and other technical information relating to the problem. You may or may not receive notice of such errors, even in the moment they occur, that they have occurred, or what the nature of the error is.

Please be aware that while this information may not be personally identifying by itself, it may be possible to combine it with other data to personally identify individual persons.

Personal Information

We may ask for personal information – for example, when you make a purchase or when you contact us – which may include one or more of the following:

  • Name
  • Email
  • Phone/mobile number
  • Home/mailing address

Collection and use of information

We may collect personal information from you when you do any of the following on our website:

  • Register for an account
  • Purchase any products and/or services
  • Purchase a subscription
  • Use a mobile device or web browser to access our content
  • Contact us via email, social media, or on any similar technologies
  • When you mention us on social media

We may collect, hold, use, and disclose information for the following purposes, and personal information will not be further processed in a manner that is incompatible with these purposes:

  • to provide you with our platform’s core features and services
  • to enable you to customize or personalize your experience of our website
  • to process any payments
  • to deliver products and/or services to you
  • to contact and communicate with you
  • for advertising and marketing, including to send you promotional information about our products and services and information about third parties that we consider may be of interest to you
  • to enable you to access and use our website, associated applications, and associated social media platforms

We may combine voluntarily provided and automatically collected personal information with general information or research data we receive from other trusted sources. For example, if you provide us with your location, we may combine this with general information about currency and language to provide you with an enhanced experience of our site and service.

User-Generated Content

We consider “user-generated content” to be reviews, ratings, image, and/or video materials voluntarily supplied to us by our users for the purpose of publication on our website or re-publishing on our social media channels. All user-generated content is associated with the account or email address used to submit the materials.

Please be aware that any content you submit for the purpose of publication will be public after posting (and subsequent review or vetting process). Once published, it may be accessible to third parties not covered under this privacy policy.

Legal bases for processing

We will only collect and use your personal information when we have a legal right to do so. In which case, we will collect and use your personal information lawfully, fairly, and in a transparent manner. If you are under 16 years of age, we will seek your parent or legal guardian’s consent to process your personal information for the specific purpose.

Our lawful bases depend on the services you use and how you use them. This means we only collect and use your information on the following grounds:

  • Consent from you

We process your person information when you give us consent to collect and use your personal information for a specific purpose. You may withdraw your consent at any time using the facilities we provide; however this will not affect any use of your information that has already taken place. For example you may provide a physical address for the purpose of receiving orders. While you may change or delete this address at any time, this will not affect orders that have already been sent. If you have any further enquiries about how to withdraw your consent, please feel free to enquire using the contact details provided above.

  • Performance of a contract or transaction

We process your person information when you have entered into a contract or transaction with us, or in order to take preparatory steps prior to our entering into a contract or transaction with you. For example, if you purchase a product, service, or subscription from us, we may need to use your personal and payment information in order to process and deliver your order.

  • Our legitimate interests

Where we assess it is necessary for our legitimate interests, such as for us to provide, operate, improve and communicate our services. We consider our legitimate interests to include research and development, understanding our audience, marketing and promoting our services, measures taken to operate our services efficiently, marketing analysis, and measures taken to protect our legal rights and interests.

  • Compliance with law

In some cases, we may have a legal obligation to use or keep your personal information. Such cases may include (but are not limited to) court orders, criminal investigations, government requests, and regulatory obligations. If you have any further enquiries about how we retain personal information in order to comply with the law, please feel free to enquire using the details above.

Disclosure of personal information to third parties

We may disclose personal information to:

  • a parent, subsidiary or affiliate of our company
  • third-party service providers for the purpose of enabling them to provide their services, including (without limitation) IT service providers, data storage, hosting and server providers, ad networks, analytics, error loggers, maintenance or problem-solving providers, providers, professional advisors, and payment systems operators
  • our employees, contractors, and/or related entities
  • our existing or potential agents or business partners
  • credit reporting agencies, courts, tribunals, and regulatory authorities, in the event you fail to pay for goods or services we have provided to you
  • courts, tribunals, regulatory authorities, and law enforcement officers, as required by law, in connection with any actual or prospective legal proceedings, or in order to establish, exercise, or defend our legal rights
  • third parties, including agents or sub-contractors who assist us in providing information, products, services, or direct marketing to you
  • third parties to collect and process data
  • an entity that buys, or to which we transfer all or substantially all of our assets and business

Third parties we currently use include:

  • Google Analytics

International transfers outside of the European Economic Area (EEA)

We will ensure that any transfer of personal information from countries in the European Economic Area (EEA) to countries outside the EEA will be protected by appropriate safeguards, for example by using standard data protection clauses approved by the European Commission, or the use of binding corporate rules or other legally accepted means.

Personal information retention period

We keep your personal information only for as long as we need to. This time period may depend on what we are using your information for, in accordance with this privacy policy. For example, if you have provided us with personal information as part of creating an account with us, we may retain this information for the duration your account exists on our system. If your personal information is no longer required for this purpose, we will delete it or make it anonymous by removing all details that identify you.

However, if necessary, we may retain your personal information for our compliance with a legal, accounting, or reporting obligation or for archiving purposes in the public interest, scientific, or historical research purposes or statistical purposes.

Sensitive data

As a general rule, we do not process sensitive data. “Sensitive data” is any information revealing an individual’s racial or ethnic origin, political views, religious or philosophical beliefs, trade union membership, health data or data related to the individual’s sex life or sexual orientation. This term also includes personal data relating to convictions and offences.

In the event that it is absolutely necessary to collect such information in order to achieve the purpose for which the processing is carried out, we will do so in accordance with the requirements of personal data protection legislation, including after obtaining your express prior consent and under the conditions described in this policy.

Children’s privacy

We do not intend to collect personal information of children under 16 years of age, without the appropriate permission from a parent or legal guardian, in accordance with legal requirements.

Security of your personal information

When we collect and process personal information, and while we retain this information, we will protect it within commercially acceptable means to prevent loss and theft, as well as unauthorized access, disclosure, copying, use or modification.

Although we will do our best to protect the personal information you provide to us, we advise that no method of electronic transmission or storage is 100% secure and no one can guarantee absolute data security.

You are responsible for selecting any password and its overall security strength, ensuring the security of your own information within the bounds of our services. For example, ensuring any passwords associated with accessing your personal information and accounts are secure and confidential.

Your rights and controlling your personal information

  • Right of access

You have the right to receive confirmation from us as to whether or not personal information relating to you is being processed, including requesting information on the purposes, grounds and terms of processing, categories of relevant personal information etc. You also have the right to access your personal information. When you submit a request to us via email to one of the email addresses provided above and after we verify your identity (in view of the possibility granted to us in Art. 12 (6) of the GDPR) – we will disclose and provide you with the personal information we process for you.

  • Right to rectification

You have the right to ask us to correct inaccurate personal information or to supplement incomplete personal information that we process for you.

  • Right to erasure

You have the right to ask us to delete any personal information about you that we have collected and processed. Please note that this right of yours is not absolute and may not apply in any of the following cases:

  1. We are legally required to keep the personal information for a certain period of time or we have to comply with another legal obligation;
  2. We protect the right to freedom of speech and information – we guarantee the right of another data subject to exercise his right to freedom of speech, or we assist in the exercise of another right that takes precedence over your right, or we assist in the exercise of another right provided for by law;
  • We process the personal information for the purposes of archiving in the public interest, for scientific or historical research or for statistical purposes, to the extent that the right to erasure is likely to make it impossible or seriously hinder the achievement of the purposes of this processing;
  1. We process your personal information to establish, exercise or defend legal claims.

You may request the deletion of your personal information if any of the following circumstances apply:

  1. Your personal information is no longer necessary in relation to the purposes for which we collected or otherwise processed it;
  2. You have withdrawn the consent on which the processing is based and we have no other legal basis for the processing;
  • You object to the processing of your personal information under the conditions of automated individual decision-making and Profiling or you object to processing for the purposes of direct marketing;
  1. Personal information has been processed unlawfully;
  2. Personal information must be deleted to comply with a legal obligation under EU or Member State law that we are required to comply with;

In case you want to exercise your right to erasure, go through the necessary identification by sending a request for this to one of the email addresses provided above. If there are legal grounds for exercising your right, we will irrevocably delete all of your personal information that we process, thus you will no longer be a person who we identify or can identify. Thus, we will stop processing your personal information.

  • Right to restriction of processing

You have the right to ask us to restrict the processing of your personal information in any of the following cases:

  1. You have disputed the accuracy of your personal information; you may request that we limit the processing of your personal information for a period that allows us to verify its accuracy;
  2. The processing is unlawful, but you do not want your personal information to be deleted, but instead want us to restrict its use;
  • We no longer need your personal information for the purposes of processing, but you require it to establish, exercise or defend legal claims;
  1. You have objected to the processing of your personal information on the basis of a legitimate interest and pending verification of whether our legitimate grounds prevail over your interests as a data subject, you want us to restrict the processing.

 

  • Right to portability of personal information

You have the right to receive your personal information that you have provided to us in a structured, commonly used and machine-readable format, and you have the right to transmit this data to another controller without hindrance from us, insofar as the processing is carried out by automated means and is based on your consent or contract you have with us.

  • Right to object

You have the right, at any time and on grounds related to your specific situation, to object to the processing of personal information concerning you, when the processing is carried out on the basis of a legitimate interest (Art. 6 (1) (f) GDPR).

When you exercise your right to object, we will stop processing your personal information, unless we demonstrate that there are compelling legal grounds for the processing that take precedence over your interests, rights and freedoms or are aimed at establishing, exercising or defending legal claims.

If you are not sure on what grounds and for what purposes we process your personal information, you can contact us for information.

  • Withdrawal of consent

You have the right to withdraw your consent at any time for any operation of processing your personal information for which you have given us this consent.

Withdrawal of your consent will not affect the lawfulness of processing based on consent prior to such withdrawal.

  • Submitting a complaint to a competent authority

You have the right to file a complaint with the national supervisory authority if you believe that we have violated the GDPR or another applicable law when processing your personal information.

Any of the aforementioned rights may be exercised by submitting a request via email. We will respond to your request no later than 30 days after receiving it. The exercise of any of the above rights does not allow NBG Company Ltd. to discriminate against the relevant data subject.

Use of Cookies

We use “cookies” to collect information about you and your activity across our site. A cookie is a small piece of data that our website stores on your computer, and accesses each time you visit, so we can understand how you use our site. This helps us serve you content based on preferences you have specified.

Please refer to our Cookie Policy for more information.

Business transfers

If we or our assets are acquired, or we go out of business or enter bankruptcy, we would include data, including your personal information, among the assets transferred to any parties who acquire us. You acknowledge that such transfers may occur, and that any parties who acquire us may, to the extent permitted by applicable law, continue to use your personal information according to this policy, which they will be required to assume as it is the basis for any ownership or use rights we have over such information.

Limits of our Privacy Policy

Our website may link to external sites that are not operated by us. Please be aware that we have no control over the content and policies of those sites, and cannot accept responsibility or liability for their respective privacy practices.

Changes to our Privacy Policy

At our discretion, we may change our Privacy Policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. If we decide to change this Privacy Policy, we will post the changes here at the same link by which you are accessing the current Privacy Policy.

If required by applicable law, we will contact you (based on your selected preferences for communications from us) and all our registered users with the new details and links to the updated or changed policy.

If required by law, we will get your permission or give you the opportunity to opt in to or opt out of, as applicable, any new uses of your personal information.