PRIVACY POLICY FOR THE PERSONAL DATA OF INDIVIDUALS
This document contains the Privacy Policy for Individuals (“Policy”) and is related to the General Terms and Conditions, but is not an integral part of them, as it does not regulate rights and obligations, but rather aims to explain to users what personal data we process, how we process it, for what purpose, and what security measures are in place. It also provides information about the rights that you, our customers and users, have regarding the processing of personal data by “Travel Books” Ltd. (TRAVEL BOOKS). If the Policy is amended, the changes will be published here.
Date updated: July 25, 2020
Your privacy is extremely important to us. This privacy policy explains what personal data we collect from you through our relationship with you and how we use that data.
DATA CONTROLLER
“Travel Books” Ltd., UIC 203279952, with its registered office and Registered office: Sofia, 12 Georgi Bakalov St., mailing address: Sofia, 12 Georgi Bakalov St., Contact Phone: +359 877 571558, Email: info@travelbooks.bg (hereinafter referred to as “We,” “Online Store,” “Site, ” “Website,” “Administrator”) isthe data controller—including for personal data—with respect to the information collected or provided when browsing the website www.travelbooks.bg or when making a purchase through it, as well as when viewing or purchasing goods or services through our Facebook page (collectively referred to as “Site” or “Website” for brevity).
This policy also applies in cases where you, as individuals (hereinafter referred to as “Data Subjects”), voluntarily provide us with personal data electronically (via email), by phone, or through other means, including in person at our retail location or office. “Travel Books” Ltd. also processes personal data from inquiries you submit to us, as well as for marketing and advertising purposes, profiling, participation in games, promotions, and sweepstakes organized by us, and for any other purposes not prohibited by law.
When processing personal data, “Travel Books” Ltd. complies with all data protection regulations applicable to its activities, including, but not limited to, Regulation (EU) 2016/679 (“Regulation”) and the Personal Data Protection Act, because the security of our customers’ personal data is of paramount importance to us. Therefore, this Policy applies in this case as well.
DATA PROTECTION OFFICER
Mailing Address: Sofia, 23A Lyulyakova Gradina St.
Email: info@travelbooks.bg
Phone: +359 877 571558
SCOPE OF THE POLICY
This Policy applies to all of our customers—individuals who use our services by placing an order on the Website or who express interest in them by submitting inquiries (hereinafter referred to as “data subjects,” “users”).
Partners and third parties who work with or for “Travel Books” Ltd., as well as anyone who has or may have access to personal data, is expected to read, understand, and comply with this policy. No third party may have access to personal data stored by “Travel Books” Ltd. unless the company has first entered into a data confidentiality agreement that imposes obligations on the third party that are no less stringent than those “Travel Books” Ltd. has undertaken, which entitles it to “Travel Books” Ltd. shall conduct inspections to verify compliance with the obligations imposed by the agreement.
This policy applies to all employees/workers (and stakeholders) of “Travel Books” Ltd., as well as to external suppliers of products and services with whom “Travel Books” Ltd. has entered into contracts. Any violation of the General Regulations will be considered a breach of workplace discipline or a breach of contracts with partners; and if there is suspicion of a criminal offense, the matter will be referred to the relevant state authorities for review as soon as possible.
For visitors to the Site who do not place orders or submit inquiries, but merely browse our website, the Cookie Policy adopted and published on the Site applies.
DEFINITIONS
“Regulation”– General Data Protection Regulation 2016/679 of April 27, 2016, referred to as the GDPR. The purpose of this European legislative act is to protect the “rights and freedoms” of natural persons and to ensure that personal data is not processed without their knowledge and, where possible, that it is processed with their consent.
“Personal data”—any information relating to an identified natural person or a natural person who can be identified (“data subject”); a natural person who can be identified is a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, psychological, economic, cultural, or social identity of that natural person.
“Specialcategories of personal data”—personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the unique identification of a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation.
“Processing”– any operation or set of operations performed on personal data or a set of personal data, whether by automated means or otherwise, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or any other means by which the data becomes accessible, alignment or combination, restriction, erasure, or destruction;
“Controller”means any natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union law or the law of a Member State, the controller or the specific criteria for its designation may be laid down in Union law or the law of a Member State;
“Data subject”– any living natural person who is the subject of the personal data stored by the Controller.
“Consentof the data subject”—any freely given, specific, informed, and unambiguous indication of the data subject’s will, by a statement or a clear affirmative action, which signifies his or her consent to the processing of personal data relating to him or her;
“Child”– The General Regulation defines a child as any person under the age of 16. The processing of a child’s personal data is lawful only if a parent or guardian has given consent. In such cases, the controller shall make reasonable efforts to verify that the person with parental responsibility for the child has given or is authorized to give consent.
“Profiling”– any form of automated processing of personal data that involves the use of personal data to evaluate certain personal aspects relating to a natural person, and, in particular, to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movement;
“Personal data breach”—a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to personal data that is transmitted, stored, or otherwise processed;
“Recipient”means a natural or legal person, public authority, agency, or other body to which personal data are disclosed, whether or not it is a third party. However, public authorities that may receive personal data in the context of a specific investigation in accordance with Union law or the law of a Member State are not considered “recipients”; the processing of such data by those public authorities complies with the applicable data protection rules in accordance with the purposes of the processing;
“Thirdparty”—any natural or legal person, public authority, agency, or other body other than the data subject, the controller, the processor, and persons who, under the direct authority of the controller or the processor, are authorized to process personal data;
PRINCIPLES
When collecting and processing personal data, we are guided by the following principles: lawfulness, good faith, transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability.
DATA SUBJECTS WHOSE DATA WE PROCESS
In connection with its business activities, “Travel Books” Ltd. enters into and fulfills distance sales contracts, reviews job applications and proposals, processes forms for the exercise of consumer rights by buyers, as well as requests from data subjects, responds to inquiries, issues and receives invoices, processes statistical data, manages the user dashboard on the website, and conducts advertising activities through promotional campaigns (promotions, contests, etc.). In the course of these activities, “Travel Books” Ltd. processes information regarding the following data subjects:
(a) individuals who use the website without registering and without providing any data (in this case, we process data, but not personal data) and individuals who use the website without registering and who have voluntarily provided a limited amount of personal data (e.g., a phone number and/or email address);
(b) individuals who use the website and are registered as users— in these cases, we process the user’s data that they entered during registration—email address, shipping address, names, billing information, order details, and other data entered by the user.
(c) individuals who have submitted inquiries (including by phone), requests, initiatives, reports, complaints, or other correspondence to us, including via the website, by phone, by email, or by other means;
(d) individuals whose information is contained in inquiries (including by phone), requests, initiatives, reports, complaints, or other correspondence sent to us;
(e) individuals with whom we enter into contracts (civil contracts, including commercial or employment contracts, primarily distance contracts) electronically ( via our website or social media, as well as through email) or in person at our office or retail location;
(e) individuals whose data we have received from third parties ( for example, in connection with an order intended as a gift).
PERSONAL DATA WE PROCESS
Depending on the reason for processing personal data, the type of such data may vary. The features provided on the Site are not intended for the storage or processing of special categories of data within the meaning of Articles 9 and 10 of the Regulation. (Note: Read Articles 9 and 10 of the Regulation here.) We request only the personal data necessary for us to provide the activity, service, or product requested from us. When individuals use the website, we may also process other data that does not contain personal data but relates to the data subject, such as their IP address, data regarding their activity on the website, and other similar information.
Information Provided When Placing an Order
In order to fulfill the distance contract (order) concluded between you and “Travel Books” Ltd. , we require certain information from you. You decide for yourself whether and how to use the options for entering into a distance sales contract provided through the Website or the Facebook page. In the forms used to enter personal data, we clearly indicate whether providing the data is mandatory or voluntary. The data that must be provided are those without which it is impossible to conclude the relevant contract. These include: name, email address, shipping address, contact phone number, your payment information ( e.g., credit card), and billing information—including your personal identification number (EGN)—if you request an invoice in the name of an individual. If you provide data to third parties who will receive the order (for example, for orders intended as gifts or other types of donations), you are responsible for providing that data to those third parties.
Information Provided When Registering on the Site
If you have chosen to store information about yourself on the Site by registering an account, we store the data listed above, as well as the order history for each account registered on the Site. The required data corresponds to that requested when placing an order. In addition, we process your IP address and activity data (time and date of registration, acceptance of the Security Policy and Terms and Conditions, account logins, etc.);
Information Provided When Entering into Other Contracts
In cases where “Travel Books” Ltd. enters into contracts with individuals other than distance sales, we require the person’s full name, personal identification number, address, and email address.
Data provided by, through, and to other websites and applications, referred to as third parties
In certain cases, you have the option to share information with social networks or to use theirwebsites to create your own profile or link your profile on our website to the respective social network. In this case, the social network may automatically provide us with access to certain personal information it has collected about you (e.g., the content you’ve viewed, the content you’ve requested, and information about the ads you’ve been shown or clicked on, etc.). By linking your social media profile to your account on our website, you authorize us to access your personal data processed by the respective social network, as well as to collect, use, and store this information in accordance with this Privacy Policy. This linking of a social media profile to registration on our website occurs when you click on a link provided to create an account on our website via social media, thereby voluntarily establishing a connection with the relevant social media site. If you have chosen to register on our website through a social media platform, we may process your data, such as your name, phone number, email address, gender, marital status, age, photo, education, place of birth, place of residence, and other data that you have provided to these platforms and that are visible to us if you log in to our website using them.
If you provide your personal data to “Travel Books” Ltd. would like to inform you that when using Viber, Skype, Facebook, or any other platform or social network, these platforms, websites, andsocial networks have their own privacy policies, and that we accept no responsibility or liability for these policies, as their processing practices cannot be controlled by “Travel Books” Ltd. In this regard, we recommend that you review these policies before submitting your personal data to us through these websites or apps.
Information provided when posting a comment, review, or post
If you leave a post or comment on this website, your IP address will be stored along with your name, if you have entered that information. This is for the security of the website operator. If your text violates the law, the operator would like to be able to trace your identity. In addition, “Travel Books” Ltd. is required to retain this data (referred to as “traffic data”) for specific periods and for specific purposes, as outlined below. Since sending comments, inquiries, and other messages to the website, Facebook page/group, or their administrators constitutes the submission of an electronic statement under the Law on Electronic Documents and Electronic Certification Services (“ZEDEUU”), the administrator is required to maintain logs of the submission of such statements for a period of 1 year. The log contains the date of the statement, as well as the sender’s name and email address.
Employee data and data collected during the processing of job applications
We process data when entering into employment contracts and when evaluating and processing job applications. When concluding employment contracts, we require full name, personal identification number, address, age, gender, educational background, work experience, and bank details; subsequently, we also process health-related data. When processing resumes, we process names, address, email address, age, gender, education, work experience, a photo, and information voluntarily provided by the candidate during an interview or in the resume.
Data provided in connection with correspondence, complaints, and reports
In order to resolve complaints, reports, disputes, inquiries, requests, or other issues raised in communications with “Travel Books” Ltd. submitted via electronic forms on the Website or through phone calls to “Travel Books” Ltd., whether sent by regular mail or email, “Travel Books” Ltd. stores and processes this information, as well as the results of such processing.This may include names, email addresses, phone numbers, and addresses.
Furthermore, given that sending comments, inquiries, and other messages to the website, the Facebook page, or their administrators constitutes the submission of an electronic statement under the Law on Electronic Documents and Electronic Certification Services (“ZEDEUU”), we are required to maintain a log of the fact that the statement was sent (excluding its content) for a period of 1 (one) year. The log contains the date of the statement, the sender’s name and email address, and the sender’s identification.
If you provide us with personal information about someone else, you must do so only with that person’s authorization. You must inform them how we collect, use, disclose, and store personal information in accordance with this Privacy Policy for Individuals.
Technical data collected during use of the Site
In addition, we collect information from your computer, phone, tablet, or other device that you use. This information may include the following:
- the identifier of the device you are using, the type of that device, and a unique identifier for that device; “log data,” including information that your browser automatically sends to us when you visit a website; this log data includes your IP address, the URLs and activity of the websites you visit, search queries, browser type and settings, the date and time of your request, how you used the site, cookie data, and device data; if you would like more details about the information we collect, please contact us via the contact form.
- location information transmitted by the device, if you have configured the device to share location data—please note that mobile devices allow you to control or disable the use of location services by any app on your mobile device in the device’s settings menu;
- computer and connection information, such as statistics on page views, IP address, website browsing history, language settings, date, and time;
- Bookmarks to make your searches easier—the quick links for repeating previous searches allow you to repeat your searches instead of having to enter them each time. This feature can be used with or without registration. When you use the Site, a cookie with a randomly generated number is stored in your browser, allowing the Site to display quick links to repeat previous searches. The Site stores and displays the last 10 searches associated with this browser; when you log in to your account, you can save them and use them there. If you use the Service with registration (currently an inactive feature), the last 10 searches are stored in your account;
- logos related to security, technical support, development, etc.:
- To ensure the reliable operation of the services and to identify technical issues;
- To ensure the security of our services and detect malicious activity;
- To develop and improve the services on the website;
- To measure website traffic and usage;
- Logos in cases where required by law (such as logos on electronic declarations of intent);
- User Profile (Account) Login Log – this log makes it possible to detect and automatically block unauthorized attempts to access accounts; it is retained for a period of up to one year and contains the date and time of the login, the status, whether the login was via the mobile version, an app, or a desktop browser, and the IP address;
- server logs, logs from security devices (Web Application Firewalls), and other devices falling into this category. These logs are necessary for identifying technical issues, detecting malicious activity, and other purposes listed above; they are retained for a period of up to one year. The logs may contain the following information: date and time, IP address, URL, browser, and device information. In addition, some of these devices may use cookie-based security technology;
- Cookies – The use of cookies is necessary for the Website to function. In this regard, we have adopted a Cookie Policy; please review the Policy for more details regarding the types of cookies we use, their retention and usage periods, and more.
We may choose to reduce the volume of data we store and process, in accordance with the purposes of the processing.
We do not require, and will not collect or process, personal data that reveals: racial or ethnic origin; political, religious, or philosophical beliefs; trade union membership; genetic and biometric data; data concerning health, as well as data concerning sex life or sexual orientation. If a data subject voluntarily provides such categories of data on their own initiative and of their own free will, “Travel Books” Ltd. bears no responsibility for the provision of such data, but is solely obligated to provide the same protection measures for such data as those provided for the requested personal data. We do not transfer data to third countries. Furthermore, we do not make automated decisions regarding personal data and do not process data from individuals under the age of 16. If you are under the age of 16, you should not provide us with any personal data about yourself.
FOR WHAT PURPOSES DO WE PROCESS YOUR DATA?
The main purpose for which WE process your personal data is, broadly speaking, related to the provision of services through the Website and social media, namely, entering into a distance sales contract and delivering the goods and services you have ordered, as well as recording revenue. We also use your personal information to provide and improve our Services, to offer you a personalized experience on our website, to contact you regarding your profile and our Services, to provide you with customer service, to provide you with personalized advertising and marketing tailored to your interests, to conduct sweepstakes and contests organized by us, and, in certain cases, to detect and investigate fraudulent or illegal activities.
“Travel Books” Ltd. collects , uses, and processes the information described above for the purposes set forth in this Policy, which may relate to:
- To enter into a distance sales contract for goods/services between you and “Travel Books” Ltd. via the Website or social media—we require your identification, contact information, and payment details in order to enter into a contract with you and, accordingly, to ship your order to you;
- entering into a consumer credit agreement when you have requested to purchase goods or services from the Site on credit;
- processing payments and preventing fraudulent transactions (we may share your data with a third party to perform these functions);
- the conclusion of employment contracts and the processing and evaluation of submitted resumes;
- to protect and enforce the legitimate interests of other usersof the Services, third parties, and the Website—the legitimate interest serves purposes related to the legitimate interests of “Travel Books” Ltd. and/or third parties. These purposes include:
- identifying and resolving technical or functionality issues, and developing and improving the Site’s intended purpose;
- to communicate with you, including electronically, regarding important matters related to the services we provide and the performance of the contracts we have entered into;
- to tailor our marketing efforts, update our services, and provide you with promotional offers based on your preferences.
- receiving and processing reports, complaints, requests, and other correspondence;
- to exercise and protect the rights and legitimate interests of the Site, including through legal proceedings, and to assist in the exercise and protection of the rights and legitimate interests of other users of the Site and/or affected third parties;
- administering the website and the app and keeping them secure and safe;
- analyzing and improving the use of our website, app, and retail stores (including using information about how you navigate our website, app, and/or stores);
- measuring and analyzing our advertising and sending you offers and recommendations based on the information you share with us;
- communicating with you regarding your account and resolving issues with your account. When we contact you by phone, we may use automated or pre-recorded calls and text messages to ensure efficiency;
- to inform you about products and services for which you have requested that we send you information via email, mail, mobile phone, and/or other digital channels (depending on your stated preferences), including social media platforms—only when we have received your explicit consent to do so;
- your registration on the website (in this case, we will also use your personal information to help you maintain and update your profile, such as by changing your address or updating your marketing preferences);
- administration of all contests, raffles, and games of chance organized by “Travel Books” Ltd.;
- to provide you with location-based services (such as advertising, search results, and other personalized content);
- the fulfillment of Travel Books Ltd.’ s legal obligations, which includes:
- compliance with statutory obligations to retain or provide information in connection with our tax obligations to the state (for example, under the Accounting Act and other tax laws—the Value-Added Tax Act, the Personal Income Tax Act, the Corporate Income Tax Act, the Tax and Social Security Procedure Code, and others);
- compliance with legal obligations under the Labor Code, the Law on the Commercial Register and the Register of Nonprofit Legal Entities, and other regulatory acts;
- compliance with an order received by us from competent government or judicial authorities (for example, pursuant to the Law on the Ministry of Internal Affairs, the Penal Procedure Code, or the Electronic Communications Act);
- compliance with the obligations set forth in the General Data Protection Regulation regarding notifying you of various circumstances related to your rights, the Services provided, or the protection of your data, and other similar matters;
- fulfillment of obligations set forth in the Consumer Protection Act, such as ensuring the right of withdrawal and the right to a statutory warranty;
- the legal defense of “Travel Books” Ltd. ;
Your data may be processed based on your explicit consent; in this case, the processing is specific and limited to the extent and scope set forth in the relevant consent. We typically request such consent from you when we wish to process your personal data without there being a legal obligation or legitimate interest on the part of “Travel Books” Ltd. Most often, we request such consent when we wish to provide you with information about new promotions, products, and more.
RETENTION PERIOD FOR YOUR PERSONAL DATA
When storing data, WE apply the general principle of storing data in the minimum amount and for a period no longer than is necessary to provide the Services and fulfill the contracts, ensuring their security and reliability, and complying with legal requirements. We will retain your personal information for a period necessary to fulfill the purposes set forth in this “Privacy Policy,” unless we are required by law or on the basis of our legitimate interest to retain it for a longer period. Depending on the type of data and the purposes for which it was collected, a retention period for storage, upon the expiration of which the information is permanently deleted.
|
Data Type |
Retention Period
Legal Basis for Processing |
Explanations |
|
Registration data (first name, last name, email address, phone number, address) and ; information regarding registration and acceptance of the Terms and Conditions (date, time, IP address) |
Retention period
For the entire duration of the account on the Site and up to 5 (five) years after termination of registration Legal basis Performance of contractual obligations; compliance with legal obligations; protection of legitimate interests; |
Your data identifies you as a registered user of the Site. For the purpose of resolving any disputes that have arisen or become known after the termination of the agreement for use of the Site and in connection with the ZEDEUU (see below), this data is retained for a period of up to 5 (five) years after the account is terminated.
Important! Pursuant to the ZEDEUU (see below), certain data (activity, IP address) must be retained by the administrator for a period of up to 1 (one) year following the termination of the account. The extension of the retention period is necessary to protect the controller’s legitimate interests. |
|
Personal data from orders and from invoices issued or received by the administrator, payment documents (payment orders, statements), reports, and other accounting, reporting, and payment documents.
Personal data from employees’ personnel files.
|
Retention period
For the period during which the rights and obligations of the parties to the legal relationship under which the accounting, reporting, or payment document was issued remain in effect, up to 5 years from the termination of the legal relationship; Certain data is also retained for a longer period than that specified above, as required by law, since it constitutes accounting information—transaction data, invoicing data—between 5 and 50 years Legal basis Compliance with legal obligations and protection of the controller’s legitimate interests. |
Your data identifies you as a party to the distance sales contract and is stored to ensure your rights and to fulfill our legal obligations as taxpayers. Storage is also necessary to safeguard the rights of buyers (individuals) when a specific time period is stipulated for such rights (e.g., a 2-year warranty). Legal obligations also require that the retention period be determined in the manner described.
Pursuant to Article 38 of the Tax and Social Security Procedural Code (TSSPC), accounting and commercial information, as well as all other information and documents relevant to taxation and mandatory social security contributions, shall be retained by the liable person in accordance with the procedures established in the National Archives Act, for the following periods: payroll records—50 years; accounting records and financial statements—10 years; documents for tax and social security audits—5 years after the expiration of the statute of limitations for the public obligation to which they relate; all other media—5 years. Pursuant to Article 38, paragraph 2 of the Tax and Social Security Procedure Code, after the expiration of their retention period, the information carriers referred to in paragraph 1 (paper or electronic), which are not subject to transfer to the National Archives, may be destroyed. |
|
Personal data from correspondence, complaints, reports, requests, and initiatives |
Retention period
Data from correspondence, complaints, reports, requests, and initiatives are retained for up to 5 (five) years pursuant to the Obligations and Contracts Act (statute of limitations for filing claims); Legal Basis Protection of the controller’s legitimate interests |
In order to resolve complaints, reports, disputes, inquiries, requests, or other issues raised in communications sent to us via electronic forms on the Website, by regular mail, or by email, we store and process this information, as well as the results of such processing. In view of the statute of limitations under Bulgarian law for the resolution of disputes, this information is retained for a period of up to 5 (five) years. |
|
A log confirming the submission of a comment, inquiry, order, or other expression of intent ( containing the sender, recipient, and the date and time of the submission) |
Retention period
For a period of 1 (one) to 5 years. Legal basis Compliance with legal obligations and protection of the controller’s legitimate interests |
Since the submission of a comment, review, inquiry, or other statement constitutes the submission of an electronic statement by you to us under the Electronic Document and Electronic Signature Act (EDESA), the company is required to maintain a log of the fact that the statement was sent for a period of 1 (one) year.
The controller’s legitimate interest allows us, in certain cases, to extend the retention period for this data to 5 years from the date the statement was made. |
| Quick searches
do not contain personal data |
Retention period
Until you delete them; until your registration is terminated; or up to 6 (six) months if you use this feature without registering Legal basis Consent of the data subject and protection of the controller’s legitimate interests |
This option allows you to repeat your searches instead of entering them each time. The feature can be used with or without registration. Quick links to repeat the last 10 searches are stored.You can change this setting in the browser you are using. |
| Settings and System Logs
do not contain personal data, may contain information such as: date and time, IP address, URL, browser version and device information |
Storage period
Until you delete them or until your registration is terminated. If they are stored in a cookie, between 6 (six) and 12 (twelve) months from the last use Reason Consent of the data subject. Compliance with legal obligations and protection of the controller’s legitimate interests |
This category includes settings such as language selection and other similar options.
You have control over the settings and can change them through your browser. Server logs, logs from security devices (Web Application Firewalls), and other devices that fall into this category. These logs are necessary for identifying technical issues and/or detecting malicious activity. |
| Information stored in a mobile app | For the duration of its use (until it is uninstalled) | Information necessary for the technical provision of the Services (such as settings, etc.) |
|
Cookies |
Retention period
Between 6 and 12 months—depending on the type of cookie and your browser settings Legal basis Consent of the data subject and protection of the legitimate interests of OSA |
For a description of the cookies used, see the “Cookie Policy” |
| Exceptions to the Rules on Retention Periods
Please note that we will not delete or anonymize your personal data if it is necessary for pending judicial, administrative, arbitration, enforcement proceedings, or proceedings related to the review of your complaint filed with us. Deletion will take place once the need for the data no longer exists, which may occur after the expiration of the time limits specified above. You may always ask us to delete certain information or close your account, and we will respond to that request by retaining certain information, even after the account is closed, when required by applicable law or legitimate interests. If we are legally required to do so, or if it is reasonably necessary to comply with regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our terms, we may retain some of your personal information for a limited period of time, even after you have deleted your account. In order to ensure the reliability of our services and prevent data loss due to technical issues, the Site implements a data backup policy. The maximum retention period (before data is deleted) for all backups is 30 days. |
DO WE SHARE YOUR PERSONAL DATA WITH THIRD PARTIES?
“Travel Books” Ltd., or the Site, does not disclose your personal data to third parties unless there is a legal basis for doing so —a legal or contractual obligation, a legitimate or vital interest, or your consent. We strive to minimize the personal data we disclose, ensuring that it is always directly related to and necessary for achieving the specified purpose. We do not sell, rent, or otherwise disclose your personal information to third parties for their marketing and advertising purposes without your consent. We ensure that access to your data by third-party private entities is carried out in accordance with legal provisions regarding data protection and confidentiality, based on contracts entered into with them.
We may disclose your personal data when we are subject to a legal obligation to do so. In certain cases, Travel Books Ltd. is required to disclose your data to public authorities such as the police, the prosecutor’s office, or the courts in connection with the prevention or investigation of crimes. This also includes sharing information with other companies and organizations for the purpose of fraud prevention and credit risk mitigation. You should be aware that if we are requested by the police or another regulatory or government authority investigating alleged illegal activities to provide your personal information or other information we have received about you, we have the right to do so after verifying the validity of the government authorities’ request. When we receive revenue from sales, we may be required bythe tax authorities to provide sales data containing information from your orders, including personal information. In this regard, we provide your data to the accounting firms with which we work. The Website and “Travel Books” Ltd. have a legal obligation to protect the security of the networks and the data processed by the company. In this regard, we implement a number of measures, the execution of which may require the processing of your data by IT companies responsible for security at our company.
We may have a contractual obligation to provide your data if we have entered into a distancesales contract with you , under which we are required to deliver the goods or services you have ordered via courier. The same applies if you have chosen to purchase and pay for a product or service on our Site using payment, credit, or banking services, for which you either share your data directly with the service providers or authorize us to do so on your behalf. If you have chosen to insure a product or service during the purchase process on the Site, your data is shared with the insurance companies as part of the order. If we havea subcontractor installa purchased product, we may provide your data to that subcontractor so they can perform the service or warranty work.
Our legitimate interest justifies, in certain cases, the disclosure of personal data to third parties. This would be the case in proceedings initiated before the Personal Data Protection Commission, the Consumer Protection Commission, and other government authorities. A legitimate interest also exists for “Travel Books” Ltd. when we engage other companies and individuals to perform certain tasks on our behalf that complement our services, within the framework of data processing agreements. We would like to keep you informed about the best offers for the products and services in which you are interested. In this regard, we may provide certain of your data —only with your explicit consent—to marketing and telemarketing service providers and other companies with whom we may develop joint programs to market our goods and services.
Our website may also contain links to and from third-party websites. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we accept no responsibility or liability for those policies. Please review these policies before submitting any information to these websites. Our website uses YouTube LLC, represented by Google Inc., to embed videos. Typically, when you visit a page with an embedded video, your IP address will be sent to YouTube and cookies will be installed on your device. However, our YouTube videos are embedded in enhanced privacy mode (in this case, YouTube is still connected to Google’s DoubleClick service, but personal data is not used in accordance with Google’s privacy policy). As a result, YouTube does not store any information about visitors unless you watch the video itself. If you click on the video, your IP address will be sent to YouTube, and YouTube will know that you have watched the video. If you are logged into YouTube via your user account, this information will also be linked to your user account (you can prevent this by logging out of YouTube before clicking on the video to watch it). We have no information regarding the possible collection and use of your data by YouTube. For more information, see YouTube’s Privacy Policy at www.google.com/intl/bg/policies/privacy/.
TO WHICH COUNTRIES DO WE TRANSFER YOUR PERSONAL DATA?
We currently store and process your personal data in Bulgaria.
However, it is possible that some of your personal data may be transferred to entities located within or outside the European Union, including countries for which the European Commission has not recognized an adequate level of personal data protection.
We will always take steps to ensure that any international transfer of personal data is carefully managed in order to protect your rights and interests. Data transfers to service providers and other third parties will always be protected by contractual obligations and, where appropriate, by other safeguards, such as standard contractual clauses issued by the European Commission or certification schemes, such as the Privacy Shield for the protection of personal data transferred from the EU to the United States.
You can contact us at any time using the contact information listed at the end of this Policy to find out to which countries we transfer your data and what safeguards we have in place regarding these data transfers.
YOUR RIGHTS REGARDING YOUR PERSONAL DATA
Under the General Data Protection Regulation, you have the following rights:
Right to Information
The purpose of this Policy is to provide you with detailed information regarding the processing of your personal data. If there is a risk of a breach of the security of your personal data, the controller is required to notify you of the nature of the breach and the measures taken to address it, as well as whether the supervisory authority has been notified of the breach. Furthermore, the data subject may request information regarding all recipients to whom the personal data—for which rectification, erasure, or restriction of processing has been requested—has been disclosed.
Right of Access
You have the right to obtain confirmation as to whether your personal data is being processed, to access it, and to receive information regarding how it is processed and your rights in this regard. As a data subject, you have the right to request confirmation as to whether your personal data is being processed and, if so, to access your data and the following information: the purpose of the processing, the types of personal data being processed, the recipients of the data, and the duration of the processing. Requests for access must be submitted in writing or electronically and addressed to the data controller. In such cases, we will provide a copy of the personal data being processed in electronic or another appropriate format.
Right to Rectification
You have the right to correct and supplement your personal data if it is incomplete or inaccurate. For registered users, this option is also available in the user dashboard on the Site. Unregistered users can obtain this information by submitting a request to the administrator. As a data subject, you have the right to request the correction or supplementation of your personal data that is inaccurate, out of date, or incomplete. To do so, you must submit a separate request. The administrator will respond to your request in writing to the email address you provided.
Right to erasure (“right to be forgotten”) and account closure
As a data subject, you have the right to “be forgotten,” i.e., to request that your personal data be erased without undue delay, meaning the controller to delete your personal data from all systems and records where it is stored, including notifying all third parties/data processors to whom the data has been provided.
If you wish, you may close your account on the website at any time. This option is also available in the user dashboard on the website. Once the account is closed, all or part of your data will be deleted. In accordance with our obligations, responsibilities, and legal requirements (e.g., the Electronic Communications Act or the Personal Data Protection Act), we may retain certain data for a specific period (see the section above).
In order to ensure the reliability of our services and prevent data loss due to technical issues, the Site implements a data backup policy. The maximum retention period (before data is deleted) for all backups is 30 days.
A request for erasure may be submitted on the grounds provided for in the Regulation, including if any of the following grounds apply:
– the personal data is no longer necessary for the purposes for which it was collected;
– when you have withdrawn your consent;
– when you have objected to the processing of personal data and there are no legitimate grounds for the processing that take precedence;
– when the processing is unlawful;
– when personal data must be erased to comply with a legal obligation under Union law or the law of a Member State to which the controller is subject;
– when personal data has been collected in connection with the provision of information society services.
Please note that we may refuse to delete some or all of your personal data in cases where there is a legitimate reason and/or a legal obligation for its processing. You will be informed of this in a timely manner. The controller may refuse to erase personal data on the grounds specified in the Regulation—when the processing of the specific data is for the purpose of:
– to exercise the right to freedom of expression and the right to information;
– to comply with a legal obligation that requires processing, as provided for in EU law or the law of a Member State to which the Controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
– for reasons of public interest in the field of public health;
– for the purposes of archiving in the public interest, for scientific or historical research, or for statistical purposes;
– to establish, exercise, or defend legal claims;
Right to Restriction of Processing
The General Data Protection Regulation provides for the possibility to restrict the processing of your personal data if there are grounds for doing so as set forth in the Regulation. Restriction is permitted in the following cases:
– when you believe that your personal data is inaccurate; in this case, the restriction applies for the period necessary for the controller to verify the accuracy;
– when the processing of your personal data is unlawful, but you do not wish to have it erased; instead, you wish only to restrict its use;
– when the controller no longer needs your personal data for the purposes of processing, but you, as the data subject, require it for the establishment, exercise, or defense of legal claims;
– when you have objected to the processing pending a review of whether the controller’s legitimate grounds override your interests.
Right to Notify Third Parties
Where applicable, you have the right to request that the controller of your personal data notify third parties to whom your data has been disclosed regarding the correction, erasure, or restriction of the processing of your personal data.
Right to Data Portability
You have the right to receive the personal data concerning you that you have provided in a structured, commonly used, and machine-readable format, and you have the right to transmit that data to another controller without hindrance from us, provided that the processing is based on consent or a contractual obligation, or the processing is carried out by automated means.
Important: You are solely responsible for the storage of data exported from the Site, as well as for any consequences resulting from its disclosure to other data controllers.
The right not to be subject to a decision based solely on automated processing
You have the right not to be subject to such automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you, unless there are grounds for such processing as provided for in the applicable data protection legislation and appropriate safeguards are in place to protect your rights, freedoms, and legitimate interests.
Right to Withdraw Consent
You have the right, at any time, to withdraw the consent you have given regarding the processing of personal data based on your prior consent. Such withdrawal does not affect the lawfulness of the processing based on the consent given prior to its withdrawal. For services such as email newsletter subscriptions, which are based on your preference (consent), you have the option to cancel your subscription at any time (withdrawal of consent). In the event of a withdrawal of consent, we reserve the right to request verification of the applicant’s identity to confirm that they are the data subject.
Right to Object
You have the right to object to the processing of your data based on a legitimate interest. If we receive such an objection, we will review your request and, if it is justified, we will comply with it. If we believe there are compelling legitimate grounds for the processing or that it is necessary for the establishment, exercise, or defense of legal claims, we will inform you accordingly.
Right to File a Complaint with a Supervisory Authority
You have the right to file a complaint against our company (the data controller) with the supervisory authority if you believe that the processing of your personal data violates applicable data protection laws. The supervisory authority in the Republic of Bulgaria is the Commission for Personal Data Protection, located at: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, e-mail kzld@cpdp.bg, website: www.cpdp.bg, phone: 02 915 3 518.
HOW YOU CAN EXERCISE YOUR RIGHTS. DEADLINES FOR RULINGS
You may exercise the rights listed above free of charge at any time by email or by submitting a request to the addresses listed in the contact form on the Website or at the end of this Privacy Policy, and you may address your requests to either the administrator or directly to the Data Protection Officer. Requests must be made in a manner that allows the applicant’s identity to be verified. For certain rights, technical means may be available to exercise them, such as an “Unsubscribe” button. In all cases, the controller must respond to the request or issue a decision regarding the exercised right at the address provided in the request, including an email address, within one month of receiving it.
If you exercise these rights in a manifestly unfounded or excessive manner, particularly due to their repetitive nature, we reserve the right to charge a reasonable fee, taking into account the administrative costs of providing the information or communication or taking the requested actions, or to refuse to act on the request. We will inform you of our fees, if applicable, before responding to your request.
ACCURACY OF THE INFORMATION
We are not responsible for the accuracy of the data you provide; we do not conduct any checks in this regard, nor do we guarantee the true identity of the individuals who provided the data. In all cases of doubt on your part, or in the event of established fraud and/or abuse, please notify us immediately. You agree that when providing any information on the Site, you will not violate the rights of others with respect to the protection of their personal data or any other rights they may have.
GENERAL INFORMATION ABOUT THE POLICY
This Privacy Policy may be amended or supplemented due to changes in applicable Bulgarian or European legislation, at the initiative of “Travel Books” Ltd. or a competent authority.
“Travel Books” Ltd. will notify users of any changes or additions to this Privacy Policy by publishing the updated Privacy Policy on our website.
Users are advised to periodically check the most recent version of this Privacy Policy on the “Travel Books” Ltd. website .
HOW WE PROTECT YOUR RIGHTS, SECURITY MEASURES
In order to ensure the best possible protection of the company’s data and that of our customers, users, business partners, and visitors to the Website, WE implement all necessary organizational and technical measures provided for in the General Data Protection Regulation and the Personal Data Protection Act, as well as best practices based on international standards. We apply the appropriate and necessary level of protection and, to this end, have developed effective physical, electronic, and administrative procedures to safeguard the data we collect from accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to personal data that has been transmitted, stored, or otherwise processed.
We store your data on secure servers using the latest encryption algorithms and ensure that backups are maintained.
The company has adopted the necessary rules and procedures related to the lawful processing of your personal data, including a Data Breach Response Plan, has established structures to prevent misuse and security breaches, and has appointed a Data Protection Officer who supports the processes for lawful processing, protecting and ensuring the security of your data.
Access to your personal data is granted only to those employees, service providers, or affiliated parties who need the information for business purposes or who require it to perform their job duties. All employees/workers are required to undergo training and accept the relevant contractual clauses/declarations/rules regarding compliance with organizational and technical access measures before being granted access to any type of information.
A fundamental principle of our organization is that all employees and workers are responsible for ensuring the security of the data for which they are accountable and which we process, and that the data is stored securely and is not disclosed under any circumstances to third parties, unless we have granted such rights to that third party by entering into a contract or confidentiality agreement. In this regard, all personal data is accessible only to those who need it, and access may be granted only in accordance with established access control rules. All personal data is handled with the utmost security and is stored:
- in a private room with controlled access; and/or
- in a locked cabinet accessible only to authorized personnel; and/or
- a computerized system protected by a password in accordance with the internal requirements set forth in the organizational and technical measures for controlling access to; and/or
- computer storage media that are protected in accordance with organizational and technical measures for controlling access to information;
Personal data is deleted or destroyed only in accordance with internal procedures for data retention and destruction.
To ensure maximum security when processing, transferring, and storing your data, we may use additional security measures such as encryption, pseudonymization, and backup technology.
We use a payment service to process payments. All payment information is encrypted using SSL technology.
When you post on forums, chat rooms, or social media services, the personal information you share is visible to other users and may be read, collected, or used by them. In these cases, you are responsible for the personal information you choose to provide.
Despite the measures we take to protect your personal data, we are aware that, in general, transmitting information over the Internet or other public networks is not completely secure, and there is a risk that the data may be viewed and used by unauthorized third parties. We cannot be held responsible for these vulnerabilities in systems that are beyond our control. In the event of a data breach involving personal data, we guarantee that we will comply with all applicable notification requirements in such cases.
COOKIE POLICY
As an integral part of this Privacy Policy for Individuals, “Travel Books” Ltd. has also adopted a Cookie Policy, which is published and available both on the Website and on our Facebook page.
CONTACT US, DATA PROTECTION OFFICER
You may submit questions and requests regarding the exercise of your personal data protection rights to “Travel Books” Ltd. via the contact form available on the Website or via any of the following contact methods:
“Travel Books” Ltd., UIC 203279952, with its registered office and address of management: Sofia, 12 Georgi Bakalov St.
DATA PROTECTION OFFICER
Mailing Address: Sofia, 23A Lyulyakova Gradina St.
Email: info@travelbooks.bg
Phone: +359 877 571558





