OF Sport Depot SA
Effective from 19.12.2018
- Introduction
Sport Depot SA (“Sport Depot”) respects the privacy of its customers and ensures, to the greatest extent possible, the protection of their personal data. This Privacy and Personal Data Protection Policy (hereinafter referred to as the “Privacy Policy”) is prepared on the basis of current Bulgarian and European legislation on the protection of personal data.
This Privacy Policy governs the processing of personal data of natural persons or representatives of legal entities who are our customers or potential customers, as well as users of our website: www.sportdepot.bg (the “Site”), in connection with the services provided by Sport Depot, including those provided through and accessible on the Site, social media pages and promotional sites we control, our rewards programs, blogs, emails and text messages we send to you, through other interactive features (individually a “site” and collectively “sites”), and our online advertisements on third-party websites.
This Privacy Policy, together with the Website Terms of Use, the Cookie Policy, and any other documents referenced on the Site, sets out the rules that Sport Depot will follow when processing personal data that we collect from you or about you, or that you provide to us. This Privacy Policy does not affect, limit, or revoke your rights arising from the Personal Data Protection Act (“PDPA”) or other applicable legislation.
If you have any questions or comments regarding this Privacy Policy, please contact us at: [email protected]
Please read this Policy carefully before using the Site or providing your Personal Data, whether electronically on the Site or on paper, as by providing your Personal Data you agree to its terms. If you do not wish us to process your personal data as described in this Privacy Policy, please do not provide it to us. The provision of personal data by you is voluntary, for the purpose of using certain services we provide and the use of and/or access to the Site, as well as for online shopping on the Site. Please note that in some cases we may not be able to provide you with the service and/or sell you the product you have requested if you do not provide the necessary information. Also note that in certain cases your consent to the processing of personal data may not be required if Sport Depot has another legal basis, e.g., compliance with statutory obligations.
- Who processes and is responsible for your personal data?
Sport Depot SA (“Sport Depot”, “we”) is the company registered in the Commercial Register at the Registry Agency under UIC 175399518, which collects, processes, and stores your personal data under this Privacy Policy. Sport Depot is a personal data controller within the meaning of the Personal Data Protection Act (PDPA). You can contact us at any of the following coordinates:
Registered office address: Sofia, “Vasil Radoslavov” St. No. 6, Sport Depot building, floor 3
telephone: 0701 90009
e-mail: [email protected]
Data Protection Officer: Denitsa Milkova
III. Categories of personal data processed by Sport Depot.
- Sport Depot may process publicly available personal data and/or personal data provided by you. The main types of personal data processed are:
(i) Personal identification information (incl. name, email address, communication language, and others);
(ii) Contact details (incl. postal and email addresses, telephone and fax numbers of you or a contact person designated by you, and others);
(iii) Financial information (bank account and others);
(iv) Information about a representative (legal representative or attorney) of our client legal entity;
(v) Data from a Site profile (incl. name, username, postal and email addresses, phone number, date of birth, etc.);
(vi) Data for concluding contracts for sale, dealership, wholesale, deferred payment, etc. with natural or legal persons (such as names, personal number, etc.);
(vii) Billing and delivery information (e.g., credit/debit card number, expiration date, CVV code, billing and shipping address, and contact information);
(vii) Social media account information (e.g., username and passwords, profile photos and other images you provide, such as user-generated content);
- Sport Depot may process data and information prepared and generated by Sport Depot in the course of providing services, which we will treat as personal data and we ensure that our processing of this personal information complies with all applicable data protection and privacy laws. Similarly, if we combine other information with personal information, the resulting information will be treated as Personal for the entire period during which it remains combined.
(i) Data about the terminal electronic communications device used, the type of device, the operating system used, IP address, location;
(ii) Data about the goods and services you prefer;
(iii) Data from the communication between us and you, your habits, preferences, and satisfaction with our services (activity when using the services, complaints, requests, etc.);
(iv) Information regarding visits to the Site and the use of the Site, including operations and history of using the Site;
(v) Data obtained in the performance of obligations arising from regulatory acts (i.e., data arising from inquiries, regulators, investigative authorities, notary, tax authorities, court, bailiff);
(iii) Video recording when visiting stores or the head office;
(iv) Voice recording — calls made to Sport Depot’s contact center;
(v) Video recording or photography, made in accordance with the pre-announced terms of participation in games and/or other promotional campaigns organized by Sport Depot.
- To ensure the proper performance of services and obligations arising from customer contracts, Sport Depot has the right to process any information available in public registers (incl. public databases and data disclosed on the Internet) as well as information obtained from third parties in relation to the performance of legal provisions, regarding clients.
4 Sport Depot has the right and obligation to verify the accuracy of the personal data recorded in the database, for which purpose it requires you to verify the data and, if necessary, to correct or confirm the accuracy of your data.
- The different types of personal data may be processed independently or in combination with each other.
- Purposes and legal grounds for processing personal data
- Processing of personal data necessary for concluding or performing contracts with us or in connection with preparation for concluding contracts with us.
Sport Depot processes your data for the following purposes:
(i) Identifying the client upon conclusion of a new or amendment of an existing contract with us; clarifications about the services used; performance of a concluded contract.
(ii) Preparing proposals for concluding contracts, sending pre-contractual information and draft contracts; managing pre-sales activities;
(iii) Performance of obligations arising from contracts concluded with you or the company you represent, exercising rights and ensuring the performance of contracts by our clients;
(iv) Administration of and responses to customer complaints/queries/appeals/claims, incl. refunding amounts and goods, product exchanges;
(v) Identification and validation of the age required by law for online shopping;
(vi) Payment of obligations, installment of amounts due; management of receivables collection;
(vii) Warranty and service support;
(viii) Updating offers to dealers;
(ix) Management and administration of activities in online shopping; management of payments;
(x) Sending transactional emails when you make a purchase on our site, including order confirmation and abandoned cart emails;
(xi) Sending administrative information, such as information about the sites and changes to our rules, terms, and policies.
- In fulfillment of its legal obligations, Sport Depot processes your data for the following purposes:
(i) Issuance of invoices;
(ii) For tax and social security control by the respective competent authorities;
(iii) Fulfillment of obligations related to distance selling, off-premises sales, as provided in the Consumer Protection Act;
(iv) Provision of information to the Commission for Personal Data Protection in connection with obligations provided for in the legal framework for personal data protection — the Personal Data Protection Act, Regulation (EU) 2016/679 of 27 April 2016, etc.;
(v) Obligations provided for in the Accounting Act and the Tax and Social Insurance Procedure Code and other related regulations, in connection with maintaining proper and lawful accounting.
- Sport Depot processes relevant data provided with the client’s explicit consent for their processing for the following purposes:
(i) Creating and managing a personal profile on the Site; technical assistance for creating a profile and recovering a forgotten password to access our Site;
(ii) Direct marketing of products and services;
(iii) Participation in and management of surveys, giveaway games, promotional campaigns, including to inform you about the results;
- Please note that some promotions have additional rules that may contain further information on the use and disclosure of your information;
(iv) Participation in and management of the Sport Depot Club loyalty program, including via a virtual club card.
(v) Displaying personalized or targeted advertisements based on information we have received from your use of our sites and ads, information we have received from third parties, or a combination of these sources, including past purchases or interests;
- Processing is necessary for the purposes of the legitimate interests of Sport Depot.
(i) For the purpose of guarding and ensuring the protection of the property, interests, and security of Sport Depot, its visitors and employees, Sport Depot uses video surveillance equipment.
(ii) Assessing and determining user satisfaction, as well as the effectiveness of the advertising we offer to you and others, and meeting your expectations by presenting appropriate advertising;
(iii) Analysis of data on purchase history, customer preferences, and behavior;
(iv) Ensuring the quality of customer service (video recording, audio recording)
- Categories of third parties who receive access to and process your personal data
(i) With transport/courier companies, postal operators for the purpose of fulfilling our contractual obligations, sending correspondence and communications in connection with the contract between us, sending purchased goods;
(ii) With our trusted service providers to whom Sport Depot assigns the maintenance of equipment and software used to process your personal data;
(iii) With our trusted service providers for the assessment and improvement of our marketing and promotional efforts, content, products and services, for a better understanding of customer interests and preferences in order to provide you with relevant information, as well as for conducting joint marketing programs;
(iv) With our trusted service providers who assist us with business activities (e.g., processing credit card transactions, organizing promotions and contests, delivering your order, helping with site operations, providing customer service, and sending emails);
(v) With our trusted service providers to whom Sport Depot has assigned the performance of part of the activities or obligations related to a specific service we owe to you; data processors who, based on a contract with Sport Depot, process your personal data on behalf of Sport Depot;
(vi) With our trusted providers of consulting services in various areas — lawyers, accountants, marketing agencies, etc.;
(vii) In connection with promotions, for example third parties that sponsor a promotion, to provide the third party with lists of names and contact information or otherwise in accordance with the rules applicable to the promotion;
(viii) With banks and payment service providers processing payments made by and to you;
(ix) With debt collection service providers, notary, lawyer, bailiff or another third party if the client has breached an obligation arising from a contract with us;
(x) Authorities, institutions and persons to whom we are obliged to provide personal data under applicable law;
(xi) Security companies holding a license to carry out private security activities, processing video recordings from Sport Depot sites/offices and/or maintaining other registers in the process of ensuring the access control regime at these sites;
- For how long is your personal data stored?
The length of storage of your personal data depends on the purposes of processing for which it was collected:
- Personal data processed for the purpose of concluding/amending and performing contracts between Sport Depot and you or the company you represent — for the term of the contract and until the final settlement of all financial relations between the parties. Sport Depot may store some of your personal data for a longer period until the expiration of the relevant limitation period in order to protect against possible claims by customers in connection with the performance/termination of contracts with us, as well as for a longer period in the event of an already arisen legal dispute until its final resolution with a final court/arbitration decision;
- Personal data processed for the purpose of issuing accounting/financial documents for the exercise of tax and social security control, including but not limited to invoices, debit, credit notes, transfer-acceptance protocols, contracts for the provision of services/goods, is stored for at least 11 years after the expiration of the limitation period for the settlement of the public receivable, unless applicable law provides for a longer period.
- Personal data processed for participation in the Sport Depot Club loyalty program and management of the profile on the Site – until the explicit withdrawal of the given consent or the receipt of an objection to the processing of personal data for managing the profile or participation in the Sport Depot club.
- Personal data processed for direct marketing – until the explicit withdrawal of the given consent for direct marketing or the receipt of an objection to the processing of personal data for direct marketing.
- Data from video recordings from security cameras – up to 60 days from the creation of the recording.
- Data from telephone conversations is stored for up to 12 months from the date of the call.
VII. Your Rights in relation to the processing of your Personal Data
1. General rights
In relation to the processing of personal data, you have the following rights, which you can exercise at any time while we store or process your personal data, by sending a request to the address of Sport Depot indicated above, or electronically to the email: [email protected]
You have the right to request from Sport Depot:
- a copy of your personal data and access to it at any time;
- to correct without undue delay your inaccurate personal data, as well as data that is no longer up to date;
- your personal data in a form convenient for transfer to another personal data controller, or to request that we do so, without being hindered by us (right to data portability);
- your personal data to be erased without undue delay where any of the legal grounds for this exists;
- to restrict the processing of your personal data, in which case your data will be stored but not processed. Our refusal to restrict will be explicit only in writing, and we are obliged to justify it with the lawful reason;
You also have the right to:
- withdraw your consent to the processing of your personal data at any time with a separate request addressed to Sport Depot, where processing is based on consent given;
- object to the processing of your personal data;
- object to automated processing, including profiling;
- not be subject to a decision based solely on automated processing, including profiling;
- You have the right to lodge a complaint with the supervisory authority
You have the right to lodge a complaint directly with the supervisory authority, which is the Commission for Personal Data Protection, address: Sofia 1592, “Prof. Tsvetan Lazarov” Blvd. No. 2 (www.cpdp.bg).
If you wish to submit a complaint regarding the processing of your personal data by Sport Depot, you can do so at the contact details of the Controller provided or directly to the Data Protection Officer (at the contact details provided above).
- Automated processing and profiling
When you visit our Site, we use automated processing to tailor products and services to your needs in the best possible way.
- Objection to use for direct marketing
You have the right to object to the future processing of your personal data for the purposes of direct marketing and advertising, as well as to their disclosure to third parties and their use on their behalf for the purposes of direct marketing and advertising, by withdrawing your consent at any time. For this purpose, you can send an email with the respective request to stop using your data for the purposes of direct marketing to: [email protected]
- Can you refuse to provide personal data to Sport Depot and what are the consequences?
In order to conclude a contract with you and/or to provide you with the requested products and/or services and/or to deliver the ordered goods in accordance with our legal and then contractual obligations, Sport Depot needs certain data to identify the party to the contract, its representative, contact details, and payment data.
Failure to provide such data prevents us from being able to conclude a contract with you.
In order to make a purchase from our Site and for us to deliver the goods or services you have ordered, you must have a created profile on the Site. During the profile creation process, Sport Depot needs certain data to identify you, contact details, and payment data. Failure to provide such data prevents the possibility of purchasing and delivering goods or services by you.
VIII. How we protect your data
Sport Depot applies organizational, physical, information technology, and other necessary measures to ensure the security and protection of your personal data and the monitoring of personal data processing.
Among other things, such security measures include the following activities:
- Sport Depot has established requirements for the processing, registration, and storage of personal data through internal procedures, the compliance with which is constantly monitored;
- access by Sport Depot employees to personal data and authorization to process personal data in the Sport Depot database is limited depending on their duties;
- Sport Depot has established confidentiality obligations for its employees;
- access to Sport Depot’s office equipment and to each employee’s computers is restricted.
- we apply all necessary organizational and technical measures provided for in the Personal Data Protection Act, as well as best practices from international standards
- For maximum security in processing, transferring, and storing your data, we may use additional protection mechanisms such as encryption, pseudonymization, etc.
The security measures we apply are subject to continuous improvement and adaptation to the latest technologies. Please note that despite our efforts, no security measures are impenetrable. If you have reason to believe that your Personal Information is not secure, please contact us immediately.
- Links to other websites
Sometimes the Site may contain links/references (hyperlinks) to other websites. We do not operate the linked sites and do not endorse the content, services, and products of those sites. We advise you to use the linked sites carefully and with due attention to their content and terms of use. Sport Depot is not responsible for the privacy policy or the content of such sites and we advise you to review their privacy policies. Nevertheless, as soon as Sport Depot receives information regarding illegal activities or illegal information on such Internet pages, Sport Depot will take immediate measures to remove the electronic links to them.
- Social networks and online communities
On some sites we may give you the opportunity to access online communities for sharing information, such as messages, photos, and video clips. We may also give you the opportunity to post content from some sites to your profile on other social networks. Please note that any content you post or provide on this site will be subject to the privacy rules of the social network site. In addition, when you post or share content or communications from our sites with any third-party social network, you also allow us to share information with that third-party social network.
We cannot control the policies or terms of such third-party social networks. For example, sharing such information on Facebook may require the use of cookies and/or an application programming interface to facilitate communication between our sites and Facebook. Information shared via cookies and/or an application programming interface then becomes subject to Facebook’s data policy found at https://www.facebook.com/full_data_use_policy . As a result, we cannot be responsible for the use of your information or content by a third-party social network, which you use at your own risk.
- International data transfer
In connection with the use of service providers and suppliers, if Personal Information is transferred outside the European Economic Area (“EEA”), we will take measures to ensure that this information receives the same level of protection as if it had remained within the EEA, including by concluding data transfer agreements using the Standard Contractual Clauses approved by the European Commission, or by relying on certification schemes such as the EU-U.S. Privacy Shield. You have the right to obtain details of the mechanisms under which your data is transferred outside the EEA.
XII. Cookie Policy
You can review our “Cookie Policy” at https://www.b2b.sportdepot.bg/en/pages/cookie-consent-1103
XIII. Children’s personal data
We do not knowingly collect personal information from children under the age of 16. If we learn that we have collected personal information from a child under the age of 16, we will take steps to delete the information as soon as possible or to obtain the consent of the person holding parental responsibility for the child.
Changes to the Privacy Policy
We may periodically update our Privacy Policy. Upon changes to this policy, a notice will be posted on our website, as will the updated Privacy Policy. All amendments and supplements to the Privacy Policy will be applied only after the publication of its current content, accessible through our Site.