Data Protection and Management Policy
(Association for Freedom in Education)
This policy sets out how we collect, process and hold your personal data if you visit our website or otherwise provide personal data to us. We are the Association for Freedom in Education of Bulgaria, Plovdiv, Trakia bl 151 vh E et 1 ap 3. Our Business reg. No. is 177226575. We are the data controller of your personal data collected and administered in relation to your use of our website (http://schoolfreedom.org) or to any other interaction with us.
Personal data we collect
We collect, process, store and use personal data when you buy a product from our online store, including your name, phone number, address and email address together with payment information. We may also collect personal data that you give to us about other people if you register them to attend an event or select to send them purchased goods. You agree that you have notified any other person whose personal data that you provide to us of this privacy notice and, where necessary, obtained their consent so that we can lawfully process their personal data in accordance with this policy.
We collect your public profile data only from your consent that you grant before initiating Social Login, from the social network (such as Facebook) used to login at our website. This data includes your first name, last name, email address, link to your social media profile, unique identifier, link to social profile avatar. This data is used to create your user profile at our website. You can revoke this consent at any time by sending us an email.
We collect the data related to the Facebook Comment you post, only from your consent that you grant before posting Facebook Comment at our website. This data includes your Facebook account name, unique Facebook account identifier, unique identifier associated to the posted Facebook comment, unique open graph object identifier of the webpage at which you posted the comment, unique identifier associated to the parent comment if you reply to an existing comment. This data is used to show recent Facebook Comments made all over our website and/or to show the old comments made at non-SSL webpages before we moved our website to SSL. You can revoke this consent at any time by sending us an email.
With regards to our performance as an NGO, we collect, process, store and use personal data of our members and volunteers, in order for them to be able to participate in our undertakings. However we do not collect, store and use any sensitive personal data, such as cultural, political or sexual preferences, or religious or ethnic identity.
All personal data that you provide to us must be true, complete and accurate. If you provide us with inaccurate or false data, and we suspect or identify fraud, we will record this.
You do not need to provide us with any personal data to view our website. However, we may still collect the information set under the Data we automatically collect section of this policy, and marketing communications in accordance with the Marketing Communications section of this policy.
When you contact us by email or post, we may keep a record of the correspondence and we may also record any telephone call we have with you.
Data we automatically collect
When you visit our online shop, we, or third parties on our behalf, automatically collect and store information about your device and your activities. This information could include (a) your computer or other device’s unique ID number; (b) technical information about your device such as type of device, web browser or operating system; (c) your preferences and settings such as time zone and language; and (d) statistical data about your browsing actions and patterns. We collect this information using cookies in accordance with the Cookie section of this policy and we use the information we collect on an anonymous basis to improve our online shop, our events and the services we provide, and for analytical and research purposes.
If you opt in to receive marketing or informational communications from us you consent to the processing of your data to send you such communications, which may include newsletters, blog posts, surveys and information about new events and products. We retain a record of your consent.
You can choose to no longer receive marketing communications by contacting us at email@example.com or clicking unsubscribe from a marketing email. If you do unsubscribe to marketing communications, it may take up to 5 business days for your new preferences to take effect. We shall therefore retain your personal data in our records for marketing purposes until you notify us that you no longer wish to receive marketing emails from us.
Lawful processing of your personal data
We will use your personal data in order to comply with our contractual obligation to supply to you the goods and/or services you may have requested or purchased, including to contact you with any information relating to the said goods and/or services, to deliver the goodr and/or services to you in accordance with any requests you make and that we agree to, and to deal with any questions, comments or complaints you have in relation to your purchase or request.
We may also use your personal data for our legitimate interests, including dealing with any customer services you require, enforcing the terms of any other agreement between us, for regulatory and legal purposes (for example anti-money laundering), for audit purposes and to contact you about changes to this policy.
Who do we share your data with?
We may share your personal data with any service providers, sub-contractors and agents that we may appoint to perform functions on our behalf and in accordance with our instructions, including payment providers, event ticketing providers, delivery services providers, email communication providers, IT service providers, accountants, auditors and lawyers.
Under certain circumstances we may have to disclose your personal data under applicable laws and/or regulations, for example, as part of anti-money laundering processes or protect a third party’s rights, property, or safety.
Where we hold and process your personal data
Some or all of your personal data may be stored or transferred outside of the European Union (the EU) for any reason, including for example, if our email server is located in a country outside the EU or if any of our service providers or their servers are based outside of the EU. We shall only transfer your personal data to organisations that have provided adequate safeguards in respect of your personal data.
A cookie is a small text file containing a unique identification number that is transferred (through your browser) from a website to the hard drive of your computer. The cookie identifies your browser but will not let a website know any personal data about you, such as your name and/or address. These files are then used by websites to identify when users revisit that website.
We also use Google Analytics to monitor how the online shop is used. Google Analytics collects information anonymously and generates reports detailing information such as the number of visits to the online shop, where visitors generally came from, how long they stayed on the online shop, and which pages they visited. Google Analytics places several persistent cookies on your computer’s hard drive. These do not collect any personal data. If you do not agree to this you can disable persistent cookies in your browser. This will prevent Google Analytics from logging your visits.
We shall process your personal data in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures. All information you provide to us is stored on our secure servers. Any payment transactions are encrypted using SSL technology.
Where we have given, or you have chosen a password, you are responsible for keeping this password confidential.
However, you acknowledge that no system can be completely secure. Therefore, although we take these steps to secure your personal data, we do not promise that your personal data will always remain completely secure.
You have the right to obtain from us a copy of the personal data that we hold for you, and to require us to correct errors in the personal data if it is inaccurate or incomplete. You also have the right at any time to require that we delete your personal data. To exercise these rights, or any other rights you may have under applicable laws, please contact us at firstname.lastname@example.org.
If you have any complaints in relation to this policy or otherwise in relation to our processing of your personal data, you should contact the supervisory authority in Bulgaria: the Commission for Personal Data Protection, see https://www.cpdp.bg/.
If you register with us, we shall retain your personal data until you close your account.
If you opted in to receive marketing or information communications from us, we shall retain your personal data until you opt out of receiving such communications.
If you have otherwise made a purchase or booked a ticket with us or contacted us with a question or comment, we shall retain your personal data for 6 months following such contact to respond to any further queries you might have.
If any provision of this policy is held by a court of competent jurisdiction to be invalid or unenforceable, then such provision shall be construed, as nearly as possible, to reflect the intentions of the parties and all other provisions shall remain in full force and effect.
This policy shall be governed by and construed in accordance with the law of Bulgaria, and you agree to submit to the exclusive jurisdiction of the Bulgarian Courts.
We may change the terms of this policy from time to time. You are responsible for regularly reviewing this policy so that you are aware of any changes to it. If you continue to use our online shop after the time we state the changes will take effect, you will have accepted the changes.
This Policy version last updated and published on 24.05.2018