Privacy Policy
This PRIVACY POLICY is an integral part of the GENERAL TERMS OF USE of www.aquaparksofia.bg (hereinafter referred to as the Site), administered by “AQUAPARK SOFIA” EOOD (hereinafter referred to as the Administrator). The manner in which the Administrator collects and processes personal data of data subjects who visit the Site is set out below. The manner in which data subjects can contact the Administrator if they need to do so is also described.
1. PROCESSING OF PERSONAL DATA
For the best presentation of the Site, its information system needs certain information about visitors.
Sometimes (including in cases where this is necessary to provide a certain service) it may be necessary to share the following categories of personal data: 1) names; 2) valid email address; 3) telephone; 4) physical address for correspondence or 5) additional data that visitors determine themselves. When exercising the rights of the subjects of personal data, the processing of the specified categories will be necessary.
For some of the functions of the site, the following data is also collected: 1) IP address; 2) browser type; 3) language settings; 4) type of device on which the Site is accessible; 5) time of use; 6) type of operating system through which it is accessed.
Personal data about visitors to the Site may be collected personally by the subjects and/or automatically through the Site, through the use of cookies and other similar solutions.
The Administrator processes data on the following grounds and under the expressly specified conditions:
IP address; Type of browser; Language settings; Type of device; Time of use; Type of operating system
Method of collection: When using the site by the data subjects and through cookies
Purpose: To provide the full functionality of the Site
Basis according to Regulation (EU) 2016/679 of the EP: Art. 6, para. 1 b)
Term: 2 years
Two names; email address
Method of collection: Personally by the data subjects and/or through the “Contacts” section and attached contact form
Purpose: Official, legal and/or systematic warnings, legal purposes, inquiries, comments and feedback
Basis according to Regulation (EU) 2016/679 of the EP: Art. 6, para. 1 a) and c)
Term: 2 years
Two names; email address; contact telephone number; data for accounting purposes and payments; information about tickets and discounts.
Method of collection: When an order is placed by the user
Purpose: For the performance of contractual obligations
Basis according to Regulation (EU) 2016/679 of the EP: Art. 6, para. 1 b)
Term: up to 60 months
Analytical data
Method of collection: When using the site
Purpose: Improving the services provided by the Site and statistics
Basis according to Regulation (EU) 2016/679 of the EP: Art. 6, para. 1 f)
Term: up to 26 months
Marketing data, including unique visitor and device identifier, HTTP GET/POST data, IP addresses, user behavior
Method of collection: When using the Site
Purpose: User profiling and advertising targeting, content serving and measurement, retargeting and remarketing
Basis according to Regulation (EU) 2016/679 of the EP: Art. 6, para. 1 a)
Term: up to 26 months
2. PROTECTION OF PERSONAL DATA
In accordance with European legislation, the Administrator maintains appropriate, necessary and proportionate technical and organizational measures to protect user data, including to prevent unauthorized access to them and/or their improper use.
The Administrator uses business systems, procedures and information technologies that adequately protect personal data and ensure their safety. The data collected from users of the Site are systematized in registers that are subject to cryptographic protection. The data registers themselves are located on the hard memory of computer systems with limited technical and physical access, only by qualified and trained personnel.
3. SHARING OF PERSONAL DATA
The Administrator may share personal data of the users of the Site with industry-recognized solutions, such as Google Analytics, Facebook, automated chat programs.
For the purposes of making payments, personal data of users are processed by third parties – in these cases, the third party – a provider of payment services for electronic payments, is an independent administrator of personal data, and the Site is only a platform through which end users could use this service (online payment) in accordance with the personal data protection policy adopted by the third party. The Administrator does not have the opportunity to influence the way in which the third party processes personal data, since the service provided is performed in an information environment and system, fully controlled by the latter.
In certain situations, it may be necessary to share data with a special authority (administrative, judicial and/or executive authority) on the basis of Art. 6, para. 1, b. “c” and b. “f” of the General Data Protection Regulation (GDPR), when this is required for the resolution of legal disputes, is provided for by a legal provision or is strictly necessary for the prevention, detection or prosecution of criminal activity or fraud.
In addition to the above, personal data of users may be shared with:
Accounting and control
Purpose: To fulfill obligations under accounting law or approved international accounting standards.
Grounds under Regulation (EU) 2016/679 of the EP: Art. 6, para. 1, c)
Special body of the judicial, administrative and/or executive power
Purpose:
1. Where necessary and under an obligation to disclose a trade secret;
2. In connection with the resolution of legal disputes before a competent court and/or arbitration;
3. Sharing information with law enforcement authorities and financial institutions, to whom this is required by law or is strictly necessary for the prevention, detection or prosecution of criminal activity or fraud.
Grounds under Regulation (EU) 2016/679 of the European Parliament: Art. 6, paragraph 1, c)
Business partners
Purpose: To provide remarketing and retargeting services
Grounds under Regulation (EU) 2016/679 of the European Parliament: Art. 6, paragraph 1, a)
Payment service providers
Purpose: To provide remarketing and retargeting services
Grounds under Regulation (EU) 2016/679 of the European Parliament: Art. 6, paragraph 1, b)
4. USE OF COOKIES
The Administrator uses cookies and other similar tools on the Site to improve its performance and to personalize user content. This policy explains how this is done.
What are cookies?
“Cookies” are small text files that are created, accessed, read, modified or deleted on the hard drive of end users in one of the following ways:
1) by an Internet server through the Website, in the context of HTTP/HTTPS GET/POST requests.
2) by program code added to the Website (e.g. JavaScript).
The term “cookies” refers to all files and technologies that collect information in this way.
What are they used for?
The information recorded in them can be used in various ways: for traffic analysis, advertising purposes, system reports on the Site’s activity and its usage, as well as for analyzing and improving its functionalities. Reading cookies allows the Site to be designed in an optimal way for users and facilitates its effective use.
What types of cookies do we use and for what?
According to their purpose, cookies can be:
Necessary – these cookies enable the normal operation of the Site by ensuring the operation of basic functions such as navigating through the different pages. Without them, the Site cannot operate fully and be useful to users.
Functional – they help the Site remember the user session, the contents of the user cart and the preferences of the individual user in order to provide them with the necessary services. They are anonymous and do not transfer user data when visiting other websites.
Statistical – these cookies help the Site understand how users interact with it by collecting and analyzing statistical data about its use. The collected data is anonymous and is used solely to optimize the functions of the Site and eliminate possible errors.
Marketing – they are used to collect information about user activity and preferences, thus providing relevant marketing content according to user interests.
Depending on the duration of their action, cookies can be session – temporary cookies that are deactivated when the browser is closed, or permanent – they are saved on the end device until they are deleted by the User or his browser. All permanent cookies have a certain expiration date, which is systemically set.
Depending on their “administrator”, cookies are first-party – they are installed and managed by the Site, or third-party cookies – these are cookies that are installed and used by external providers, such as Facebook, Google, Youtube and others.
Third-party cookies
Cookies can be created, accessed, read and manipulated both by the Site and by third parties whose codes the Site has added and used for various purposes. The Site may also use functional social network plugins (so-called Social Plugins), which provide the opportunity to obtain more detailed data on the activities if the users explicitly choose to follow the Site page on the social network in question (for example, Facebook or Instagram). The Site may also use such plugins that provide the opportunity to share information about it on social networks. In connection with these functional plugins, another group of tracking cookies may be introduced when using the Site, which are placed by a third party, in case a user has visited their web page before visiting our Site, most often in order to show the User more relevant advertisements.
The Site may use functions of the Google Analytics web analytics service. The information generated by Google Analytics cookies regarding the use of the Site may be sent to Google servers in the USA and stored there. The Site uses Google Analytics only with activated IP anonymization. In view of this, the User’s IP address is pre-shortened by Google within the member states of the European Union or in other countries that are party to the Agreement on the European Economic Area. Google may use this information to evaluate the use of the Site by users, to compile reports on Site activities and to provide other services related to Internet usage and activity. Google will not correlate the IP address transmitted by a user’s browser within the framework of Google Analytics with other data. The User may prevent the data generated by cookies relating to his use of the Site (including IP address) from being tracked and processed by Google by installing a browser plug-in available HERE.
To learn more about cookies, you can visit www.allaboutcookies.org. You can manage them from your browser using the relevant settings:
5. RIGHTS OF DATA SUBJECTS
Visitors to the Site are data subjects within the meaning of the General Data Protection Regulation (GDPR).
Right to information
When providing their personal data or before they are collected by the administrator for processing, the User has the right to be informed about the following basic circumstances: 1. Who is the administrator; 2. What are the purposes of the processing; 3. What is the legal basis and/or legitimate interests; 4. Who can receive the data; 5. What is the period for their storage; 6. What are the rights of users; 7. Is automated decision-making performed, including profiling.
Right to access
The User has the right to access their personal data that the Site processes. This includes the data from the “Right to Information”, as well as the source of personal data, and the categories of data that are processed. When personal data are not collected directly from the User, the latter should also receive information about the method of collection, the type of processing, the applicable legal basis.
Right to rectification
The User has the right to request the administrator to correct without undue delay inaccurate personal data related to the user – the subject of personal data.
Right to erasure
The user has the right to request from the controller the erasure of personal data concerning him or her without undue delay.
Right to be forgotten
Where the controller has made the personal data public and is obliged to erase them, the controller shall take reasonable steps to inform other controllers processing the personal data that the data subject has requested erasure by such controllers of all links, copies or replications of those personal data.
Right to restriction of processing
The user has the right to request from the controller the restriction of processing where at least one of the following applies:
1. The accuracy of the data is contested by the user.
2. The processing is unlawful but the user does not wish to have them erased.
3. The Administrator no longer needs the personal data for the purposes of the processing, but the User requires them for the exercise or defense of his/her legal claims.
4. The User has objected to the processing of the data and the verification by the Administrator is expected to be completed.
During the period of limitation of processing, the data may continue to be stored by the Administrator.
Right to data portability
The User has the right to receive from the Administrator the personal data concerning him/her and which the User has provided to the Administrator, if:
1. The processing is carried out in an automated manner.
2. The processing is based on consent or in fulfillment of a contractual obligation.
This right also includes the Administrator’s obligation to transfer the personal data specified by the User to another administrator.
Right to object to processing of personal data
The User has the right to object to the processing of his/her personal information, which is provided to the Administrator in connection with the performance of a task of public interest, is necessary for the purposes of the legitimate interests of the Administrator, profiling or direct marketing is carried out.
When exercising this right, the User’s personal data may be deleted from the Administrator’s devices.
Right to lodge a complaint
The User has the right to lodge a complaint with a supervisory authority (Personal Data Protection Commission) if he/she considers that the processing of personal data relating to him/her violates the provisions of the General Data Protection Regulation.
The data subject may exercise this right in the Member State of his/her habitual residence, place of work or place of the alleged infringement.
Users can learn more about their rights and how to exercise them on the information website of the European Data Protection Supervisor or the supervisory authority for the Republic of Bulgaria – Personal Data Protection Commission.
The user can always and at any time exercise his rights. For this purpose, he needs to send a letter or email to the contacts listed below:
Data Administrator:
“AQUAPARK SOFIA” EOOD / UIC 205751266
Address of management: Bulgaria, Sofia, 1510, 22 “Kapitan Georgi Mamarchev” Str.
Contact phone: (+359) 88 7700999
Email: office@aquaparksofia.bg
Supervisory authority in relation to the protection of personal data:
COMMISSION FOR PERSONAL DATA PROTECTION
Address: Bulgaria, Sofia, 1592, 2 “Prof. Tsvetan Lazarov” Blvd.
Email: kzld@cpdp.bg
Date of approval and publication: xx.06.2024
Date of last modification and publication: n/a