Art. 1. Scope and controller
(1) This policy describes the processing of personal data in connection with the B2B platform b2b.sportdepot.bg.
(2) The policy applies to individuals who represent or work for current and prospective business customers, as well as users of company B2B accounts.
(3) The controller is Sport Depot SA, UIC 175399518, registered address: Floor 3, SPORT DEPOT building, 6 Vasil Radoslavov St., Sofia 1715, Bulgaria. For questions about personal data, please email dpo@sportdepot.bg.
(4) Information about a legal entity is not personal data unless it identifies, or can be linked to, a specific individual.
Art. 2. Categories of personal data
(1) Depending on our relationship, we may process:
1. the name and position of a representative or contact person;
2. business email address, telephone number and correspondence address;
3. B2B account information and information about authority to represent;
4. information about enquiries, agreed prices, orders, invoicing and delivery;
5. information about bank or postal money transfers;
6. correspondence, complaints and after-sales service;
7. information needed to establish, collect or defend receivables and legal claims.
(2) When the platform is used, we may process:
1. IP address;
2. device, operating system and browser information;
3. technical logs;
4. session identifiers and security information;
5. information about pages used and actions taken on the platform;
6. analytics and marketing identifiers where the relevant technologies have been permitted.
(3) Where cookies and similar technologies are used, the specific technologies, providers, purposes and retention periods are described in the Cookie Policy and the dynamic declaration on the relevant page.
(4) When you communicate with the contact centre or visit a site, a call recording or video recording may be processed where such recording is carried out and you have been informed in advance.
Art. 3. Sources of personal data
(1) We obtain personal data:
1. directly from the user of the B2B account;
2. from the company or organisation represented by that user;
3. from a person who has requested delivery or contact;
4. from correspondence and order fulfilment;
5. from use of the platform and permitted technologies;
6. from service providers where this is necessary for the relevant operation and is lawful.
(2) Where necessary to verify a company or authority to represent, we may use public registers and official sources.
(3) You should not provide personal data that is not necessary for the specific B2B operation.
Art. 4. Purposes and legal bases
(1) We process personal data to:
1. review a partnership enquiry;
2. create and manage a company B2B account;
3. provide agreed prices and availability;
4. accept and fulfil orders;
5. invoice, receive payment and deliver;
6. handle enquiries, complaints and after-sales cases;
7. send confirmations and administrative messages relating to the account, orders and changes to applicable terms;
8. protect the account, platform and information systems;
9. prevent abuse and perform security checks;
10. analyse use, measure effectiveness and improve the platform;
11. measure advertising and display personalised content or advertising where the required consent has been given for the relevant technologies;
12. establish, collect and defend receivables and legal claims.
(2) For each processing activity, we rely on one or more of the following legal bases:
1. performance of a contract or steps taken before entering into a contract;
2. compliance with a legal obligation;
3. the legitimate interests of SPORT DEPOT and the business customer in managing their contractual relationship, security and the defence of legal claims;
4. consent, where required by law, including for optional analytics and marketing technologies.
(3) Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Art. 5. Required data
(1) Fields marked as required are necessary for the relevant enquiry, account or order.
(2) Without this information, it may not be possible to:
1. verify the business customer or authority to represent;
2. create or maintain a B2B account;
3. accept and fulfil an order;
4. issue an invoice;
5. make a delivery;
6. respond to a complaint or after-sales request.
(3) A person who provides information about another representative, employee or recipient must have a legal basis for doing so and must inform that person of this policy.
Art. 6. Recipients and processors
(1) Personal data is accessible only to employees and contractors who need it.
(2) Depending on the relevant operation, data may be disclosed to:
1. hosting, software and technical support providers;
2. courier and postal operators;
3. banks and payment service providers;
4. accounting, legal and audit advisers;
5. persons involved in collecting or defending receivables;
6. communications and customer service providers;
7. analytics, advertising and marketing technology providers where the relevant processing has been permitted;
8. physical or information security providers;
9. competent public and judicial authorities.
(3) Where a recipient processes data on behalf of SPORT DEPOT, the relationship is governed by a contract and the applicable data protection requirements. Only the data needed for the specific task is provided.
(4) Current information about technology providers used through cookies and similar means is available in the dynamic cookie declaration.
Art. 7. Transfers outside the EEA
(1) If a provider processes personal data outside the European Economic Area, the transfer is made only where there is an applicable legal basis and an appropriate mechanism under Chapter V of the General Data Protection Regulation.
(2) An appropriate mechanism may include an adequacy decision or approved standard contractual clauses.
(3) Information about the applicable mechanism and available safeguards may be requested at dpo@sportdepot.bg.
Art. 8. Retention periods
(1) We retain personal data only for as long as it is needed for the relevant purpose or as required by applicable law.
(2) The specific period is determined according to the category of data:
1. information about contracts, orders, payments and deliveries is retained for the duration of the relationship and afterwards in accordance with applicable limitation, accounting and tax requirements;
2. accounting and financial documents are retained for the period required by applicable law, which for certain documents may be up to 11 years;
3. B2B account data is retained while the account is active and, after it is closed, only to the extent needed for legal obligations, security or legal claims;
4. the retention periods for cookies and similar technologies are stated in the dynamic cookie declaration;
5. data processed for analytics or marketing purposes on the basis of consent is retained until consent is withdrawn or the applicable period expires, whichever occurs first;
6. telephone call recordings, where calls are recorded, are retained for up to 12 months;
7. video surveillance recordings, where surveillance is used, are retained for up to 60 days, unless a particular recording is needed for an investigation or legal claim;
8. in the event of a dispute, investigation or proceedings, relevant data may be retained until the matter has been finally resolved.
(3) When the applicable period expires, the data is deleted or anonymised unless the law requires otherwise.
Art. 9. Rights of individuals
(1) Subject to applicable law, you have the right to:
1. information and access to your personal data;
2. correction of inaccurate or outdated data;
3. erasure or restriction of processing;
4. data portability, where applicable;
5. object to processing based on legitimate interests;
6. object to processing for direct marketing and related profiling;
7. withdraw consent;
8. not be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, except where permitted by law;
9. lodge a complaint with the Commission for Personal Data Protection.
(2) You may send a request to dpo@sportdepot.bg or to the controller’s address.
(3) To protect the data, we may request information needed to verify identity and authority to represent.
(4) These rights are not absolute and may be limited by legal obligations or the rights of other persons.
Art. 10. Security
(1) SPORT DEPOT applies appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure.
(2) Access to data is limited according to job responsibilities and the need for processing.
(3) Users must protect their company account credentials and notify SPORT DEPOT if they suspect unauthorised access.
(4) No system can guarantee absolute security. If you suspect a security breach, contact us without undue delay.
Art. 11. External links and third-party services
(1) The platform may contain links to, or embedded content from, external websites and providers.
(2) Processing by an external provider is also governed by that provider’s privacy policy. We recommend that you review it before using the relevant service.
(3) Current providers of technologies activated through cookies and similar means are listed in the dynamic cookie declaration.
Art. 12. Contact and changes
(1) For questions or to exercise your rights, please email dpo@sportdepot.bg or use the controller’s address in Art. 1.
(2) The supervisory authority is the Commission for Personal Data Protection, www.cpdp.bg.
(3) Updates to this policy are published on this page and apply from the date stated upon publication.
Last updated: 29 September 2026.