In compliance with regulatory requirements, “VEGA LOG” Ltd. is obligated to inform you about what to expect when we process your personal information.
- Who is the Data Controller of the processed personal data?
“VEGA LOG” Ltd. is a specialized customs agency providing customs and foreign trade representation. Our primary task is to assist our partners in their international activities and to relieve them from the bureaucratic barriers of customs formalities.
According to the General Data Protection Regulation (GDPR, Regulation 2016/679), “VEGA LOG” Ltd. is the Data Controller because:
- Personal Data
Any information related to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. - Processing
Any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction. - Data Controller
A natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union law or Member State law, the Data Controller or the specific criteria for its nomination may be provided for by Union or Member State law.
- What Personal Data Do We Process?
In carrying out our legally defined functions, it is necessary for us to collect, use, store, and transfer various types of personal data about you, which we have categorized as follows:
- Identity Data: This may include names, unique citizen numbers, nationality, gender, education, criminal records, and other data required to fulfill legal obligations in employment/service relationships.
- Contact Data: Address, email address, and phone numbers.
- Employment Data: Information about your activities, or those related to them, organization (including international); information about your role in projects you have worked on; correspondence between you and colleagues in the organization or between you and individuals interacting with the organization.
- Health Data: Information about the physical and mental health of employees and job applicants.
- Financial Data: Bank account details, employment remuneration, tax and insurance information, data on paid compensation and grounds for payment, reports on payments to and from you, garnishment notices, insurance, and other data necessary for fulfilling our legitimate purposes.
- Technical Data: Internet Protocol (IP) address, your login data on the internet and our Facebook pages, browser type and version, time zone setting and location, language used, types and versions of operating system.
- Data from our Video Surveillance and Access Control Systems: Installed in administrative buildings.
- How Do We Process Your Personal Data?
We process your personal data:
- Lawfully, fairly, and transparently;
- For specific, explicitly stated, and legitimate purposes;
- In a manner that is appropriate, relevant, and limited to what is necessary in relation to the purposes for which they are processed;
- Accurately, taking all reasonable measures to ensure timely erasure or correction of inaccurate personal data, considering the purposes for which they are processed;
- In a form that allows identification of the data subject for no longer than necessary for the purposes for which they are processed;
- In a manner that ensures an adequate level of security.
- To Whom Do We Disclose Your Personal Data?
4.1 We disclose your personal data to:
- Competent authorities who, by virtue of a legislative act, have the right to request this type of information;
- Contractors who process data on our behalf and with whom we have a written agreement under Article 28, Paragraph 3 of the General Regulation. We require all third parties to adhere to the security rules for your personal data, to process them in accordance with the law, and only for the agreed terms and purposes.
- How Do We Ensure the Security of Your Data?
We have implemented appropriate organizational and technical measures to protect your data to prevent accidental loss, unauthorized use, or access to your personal data in an unregulated manner, alteration, or disclosure. In addition, we limit access to your personal data to employees, strictly adhering to the “Need to Know” principle. They process your personal data only when there is a legitimate basis and are bound by confidentiality.
- How Long Do We Retain Your Data?
6.1 We process your personal data only for as long as is necessary to fulfill the purposes for which we have collected them, including for the purposes of satisfying any legal, accounting, or reporting requirements.
6.2 In determining the appropriate retention period for your personal data, we consider:
- The existence of a specific regulatory retention period, or
- The nature and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the data, and whether those purposes can be achieved through other means, in accordance with applicable regulatory requirements.
- What Are Your Rights?
In accordance with the provisions of the General Data Protection Regulation (GDPR) and the Data Protection Act, you have:
- The right to be informed.
- The right to access the processed data.
- The right to rectification.
- The right to erasure.
- The right to restrict processing.
- The right to data portability.
- The right to object.
- Rights related to automated decision-making and profiling.
The exercise of these rights is carried out through the undertaking of necessary actions within specified timeframes, as follows:
| Rights | Necessary Actions |
| The Right to Be Informed: | At the time of data collection or within a reasonable period after obtaining your personal data, but no later than one month, we inform you about: The purposes of processing and the legal basis for processing; The relevant categories of personal data; The recipients or categories of recipients of personal data; The retention period; The source of the data and, if applicable, whether the data comes from a publicly accessible source; The existence of automated decision-making, including profiling; Your right to lodge a complaint with the supervisory authority, the Data Protection Commission. |
| The Right to Access Processed Data: | We provide you with: Information on whether data concerning you is being processed by “VEGA LOG” Ltd.; Information on the purposes of this processing, the categories of data, and the recipients or categories of recipients to whom they are disclosed; Information on the logic of any automated processing of personal data relating to you, in cases of automated decisions. |
| The Right to Rectification: | We erase, correct, or block your personal data whose processing does not comply with legal requirements; We notify third parties to whom personal data has been disclosed of any erasure, correction, or blocking, except when this is impossible or involves disproportionate effort. |
| The Right to Object: | You may object at any time to the processing of your personal data if there is a legal basis for doing so; when the objection is justified, your personal data can no longer be processed and will be erased. |
| The Right to Restrict Processing: | You may request a restriction on the processing of your personal data if: The accuracy of the data is contested, for the period during which we must verify its accuracy; or The processing is unlawful, but instead of erasing it, you request restricted processing; or The data is no longer needed (for the specific purpose), but you need it for the establishment, exercise, or defense of legal claims; or You have objected to the processing, pending verification of whether the controller’s grounds are legitimate. |
| The Right to Data Portability: | You may request that we provide your personal data entrusted to us in an organized, orderly, structured, commonly accepted electronic format if: We process the data according to a contract and there is a declaration of consent, and The processing is carried out automatically. |
| The Right to Erasure: | If we process your data without a legal basis, it is subject to erasure (deletion), unless there is a regulatory requirement for its retention. |
| The Right to Lodge a Complaint: | If there is an indication of a violation of applicable regulations and the individual has not contacted us to resolve the issue, there is a legal option to file a complaint with the Data Protection Commission or a regulatory body within the EU. |
- How to Exercise Your Rights
7.1 If you wish to exercise any of the rights mentioned above, please contact us at the following address:
- City: Vidin, TIR Parking MagDak, Northern Industrial Zone
- Phone: +359 887 614 182
- Email: cspvidin@gmail.com
- And also our Data Protection Officer at:
- Phone: +359 887 614 182
- Email: cspvidin@gmail.com
7.2 Requests to exercise rights must be submitted personally or by an expressly authorized person through a notarially certified power of attorney. A request can also be sent electronically, in accordance with the procedures for the preparation and submission of electronic documents provided for in current legislation.
7.3 The request should contain:
a) Name, address, and other identification data of the relevant individual;
b) Description of the request;
c) Preferred form of communication and actions under Articles 15-22 of Regulation (EU) 2016/679;
d) Signature, date of submission, and correspondence address;
e) When submitting a request by an authorized person, the corresponding power of attorney should be attached.
7.4 You are not required to pay a fee to access your personal data (or to exercise any of the other rights). If your request is clearly unfounded, repetitive, or excessive, we may refuse to comply with your request under these circumstances.
7.5 We may need to request specific information from you to help us confirm your identity and ensure your right to access personal data. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
7.6 We try to respond to all legitimate requests within one month. It may take us longer if your request is particularly complex or you have made multiple requests. In objectively necessary cases—due to data collection or serious operational difficulties—this period may be extended, but not more than 60 days. In this case, you will be duly notified.
7.7 You have the right to lodge a complaint with the supervisory authority at any time—Data Protection Commission of the Republic of Bulgaria. However, we would like to have the opportunity to address your concerns before you approach the Data Protection Commission, so please contact us first.
- Changes to This Transparency Policy
This Transparency Policy was adopted on October 1, 2023. If necessary, we will update this document, and all older versions can be obtained by contacting us.