1. HOW DO WE PROCESS YOUR PERSONAL DATA?
Ciela Norma attaches great importance to your right to privacy and the protection of the privacy of your personal data. We want you to feel confident that when you communicate with Ciela Norma, your personal data is in good hands.
1.1. What categories of personal data do we collect?
In particular, the personal data we collect includes the following categories of personal data:
- ordinary personal data , such as name and surname, e-mail address, telephone, delivery address, position/employer, bank card, date of birth, education/professional development (e.g. if you are an expert in participating in public procurement), etc.;
- audiovisual materials – such as photographs and images/frames captured on CCTV or other video systems and voice recordings;
- system and application access data - when you access Ciela Norma's systems, the administrator may collect the information necessary to access Ciela Norma's systems and applications, such as system ID, LAN ID, email account, instant messaging account, other ID, system passwords, activity logs and electronic content produced through Ciela Norma systems,
In addition to you, as the subject of personal data, we may receive your personal data from the following sources:
o Your employers;
o subcontractors, suppliers and partners;
o public bodies;
o public websites, public registries and social media.
1.2. For what purposes and on what legal basis do we use your personal data?
- Providing our products and services, and managing Ciela Norma's business operations (including security);
- Facilitating communication with you;
- Financial and accounting activity;
- Ensuring business continuity, protecting the health and safety of employees and visitors, protecting IT infrastructure, office equipment and other property;
- IT and communications systems operations and management, IT security operations, facility access control, Ciela Norma asset management, business continuity and disaster recovery, compiling audit trails and other reporting tools, maintaining records, related to business activities and organization of Ciela Norma events/seminars;
- Reusing and combining information from the public sector, in accordance with the law;
- Apply analytics to business operations and data to describe, predict and improve business performance at Ciela Norma and/or provide a better user experience. Specifically, the areas of analysis include descriptive analytics, predictive analytics, analytics involving individuals (customers, business contacts), use of personal data, marketing-driven analytics.
Ciela Norma processes personal data for the above purposes on the following legal grounds:
- Your freely given consent;
- performance of a contract to which you are a party, incl. preliminary steps at your request (processing inquiries, bidding);
- compliance with a legal obligation of Ciela Norma;
- our legitimate interests.
When we declare that we rely on our legitimate interests for a given purpose, we consider that our legitimate interests do not override your interests, rights or freedoms because:
a) we provide full transparency regarding the processing activity;
b) we take a privacy approach;
c) we conduct regular privacy reviews and
d) we respect the rights you have in relation to processing activities.
We will not use your personal data for purposes that are incompatible with the purposes for which you have been informed, unless this is required or permitted by law, or is in your vital interest (eg in the case of a medical emergency).
1.3. Who will we provide your personal data to? Will we share your personal data with third countries?
We may transfer personal data to the following persons, in accordance with the stated purposes of processing:
o accountants, auditors, lawyers, insurers, bankers and other external professional advisors in all countries where Ciela Norma operates.
Ciela Norma Suppliers
o persons who provide products and services to Ciela Norma, such as providers and support of information systems, trade organizations and associations and other service providers.
o persons who regulate or have jurisdiction over Ciela Norma, such as regulatory authorities, law enforcement authorities, public authorities and judicial authorities .
o third parties - in connection with any proposed or actual reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or part of Ciela Norma's business, assets or stock (including in connection with bankruptcy proceedings or similar procedures).
o third parties - in connection with any proposed or actual client project.
These third parties may be located in other countries. Before doing so, we will take the necessary steps to ensure that your personal data will receive adequate protection as required by relevant data protection laws and Ciela Norma's internal policies.
Currently, the personal data we collect is primarily processed in the Republic of Bulgaria and within the European Economic Area (EEA) and is not provided to third parties outside the EEA.
Unless otherwise notified to you, any transfer of personal data from the European Economic Area (EEA) to third countries outside the EEA will be based on an adequacy decision or governed by standard contractual clauses. Any non-EEA transfer of your personal data will be made in accordance with appropriate international data transfer mechanisms and standards.
Regardless of whether Ciela Norma acts in its capacity as an administrator who entrusts a personal data processor, or in its capacity as a personal data processor for another administrator or a joint administrator, in any case the relevant conditions are objectified in a written contract (agreement) pursuant to Article 26 or Article 28 of the GDPR.
1.4. How do we treat "special personal data"?
The term "specific personal data" refers to data about a natural person's racial or ethnic origin, political views, religious, philosophical or other similar beliefs, trade union membership, biometric or genetic data, health status or sex life or orientation.
We generally do not collect sensitive data (special categories of data) through our sites or otherwise. In the limited cases where we may collect such data, we will do so as required by law and/or seek your consent, for example where we collect health/medical information such as disability status and dietary requirements/allergies within the events , which we organize or sponsor.
1.5. What data security measures do we implement?
We apply organizational, physical and technical security measures to all personal data we process. We have appropriate policies, procedures and guidelines in place to maintain data privacy, taking into account the risks associated with the categories of personal data and the processing we carry out.
We implement leading security measures to protect your personal data, which includes (but is not limited to) the fact that Ciela Norma holds a certificate according to ISO 27001, which confirms that we comply with the highest and strictest information security standards. This is a security standard recognized by the Bulgarian Institute for Standardization (BDS), which serves as an international certification that Ciela Norma adheres to the highest and strictest standards.
With respect to your use of our websites, please note that the free nature of the Internet means that information and personal data are distributed over networks that can be accessed and used by people other than those for whom the data is intended.
1.6. How long will your personal data be kept?
We will retain your personal data only for as long as is necessary to fulfill the purposes for which it was collected. We maintain specific policies and procedures for the management and storage of archives so that personal data is deleted after a reasonable period of time, according to the following retention criteria:
o We retain your data for as long as we have an ongoing relationship with you;
o We will retain your data for as long as necessary to provide you with services;
o We retain your data for as long as necessary to comply with our legal and contractual obligations.
1.7. What rights do you have regarding the processing of your personal data?
You have the right (in the circumstances and subject to the conditions and exceptions set out in applicable law) to:
o You request access to the personal data we process about you : this right gives you the opportunity to know whether we process personal data about you and, if we do, to receive information about them and a copy of that personal data.
o You request correction of your personal data : this right gives you the opportunity to correct your personal data if it is inaccurate or incomplete.
o Objections to the processing of your personal data : this right gives you the opportunity to request that Ciela Norma does not process your personal data.
o You request the deletion of your personal data : this right gives you the opportunity to request the deletion of your personal data, including when such personal data will no longer be necessary to achieve the purposes.
o You request restriction of the processing of your personal data : this right gives you the opportunity to request that Ciela Norma processes your personal data only in limited circumstances, including with your consent.
o Request portability of your personal data : this right gives you the opportunity to receive a copy (in a structured, commonly used and machine-readable format) of personal data that you have provided to Ciela Norma, or to request that Ciela Norma transmit such personal data to another administrator.
To the extent that the processing of your personal data is based on your consent, you have the right to withdraw such consent at any time by contacting Ciela Norma's Data Protection Officer in writing (and electronically). Please note that this will not affect Ciela Norma's right to process personal data received prior to the withdrawal of your consent, or its right to continue to process part of the data based on other legal grounds, regardless of the absence of your consent.
There are also cases in which you can get partial assistance from us within the limits of the law in exercising your rights (for example, when correcting personal data that we are obliged by virtue of a legal basis to maintain strictly in the form in which we received it from third parties, including obtained from public records as required by law) as current at the time we receive them, and accordingly we will only be able to direct you to those third parties to exercise your rights against them.
If, despite our commitments and efforts to protect your personal data, you believe that your rights have been violated, Ciela Norma will consider any inquiry or complaint in this regard. You have the right at any time to register a complaint directly with the relevant supervisory authority - the Commission for the Protection of Personal Data , or to file a claim against Ciela Norma before the relevant competent court.
2. HOW DO WE USE PERSONAL DATA WHEN YOU VISIT CIELA NORMA'S WEBSITES?
In addition to the information listed above, the following sections describe how we use personal data when you visit the Ciela Norma websites:
o What personal data do we collect?
o Do we include (links to) third-party websites and programs?
o How do we use the personal data we collect from our websites?
2.1. What personal data do we collect?
Ciela Norma collects personal data through its websites in two ways:
o directly (for example, when you provide personal data to create an account, sign up for a newsletter or register to comment on a website forum) and
o indirectly (for example through our website technology).
We may collect and process the following personal data:
o Personal data that you provide by filling in forms on our websites (general personal data such as first and last name, email address, telephone, delivery address, bank card). This includes registering to use the website, subscribing to services, newsletters and messages, registering for a conference or additional information, or online purchases. Sites that collect this type of personal data may provide additional information about why your personal data is needed and how it will be used. It is entirely up to you whether you want to provide them.
o If you contact us - by phone, fax, email, we may keep a record of the correspondence.
o We may ask you to complete surveys that we use for research purposes, although you do not have to answer them.
o Any posts, comments or other content you upload or post to a Ciela Norma website.
o Our website collects personal data about your computer, including (where available) your IP address, operating system and browser type, for system administration, traffic filtering, user domain searches and statistical reporting.
2.2. Do we include (links to) third-party websites and programs?
Our websites may include:
o links to and from the sites of our partner networks and advertisers;
o some third-party programs (gadgets and applications). In such case, please note that these third parties may process your personal data collected through such programs for their own purposes.
2.3. How do we use the personal data we collect from our websites?
We use personal data for the purposes described in the section For what purposes and on what legal basis we use your personal data above, for example:
o to fulfill your order;
o fulfill your requests for articles, newsletters or other content;
o for surveys and questionnaires;
o customize your access to our website;
o to contact you for marketing purposes.
3. COOKIES AND SIMILAR TECHNOLOGIES POLICY
3.1. What are cookies?
"Cookies" are text files containing a small amount of information that are downloaded to your computer or mobile device when you visit a website and allow a website to recognize your device.
Cookies perform many different tasks, such as allowing you to navigate between pages efficiently, remembering your preferences and improving your experience as a user. They can also help ensure that the ads you see online are more relevant to you and your interests.
We may use the data collected by our cookies to identify user behavior and display content and offers based on your profile and for the other purposes described below to the extent permitted by law.
Some of the cookies we use do not collect information that identifies visitors. For example:
o performance cookies;
o targeting cookies where you are not a registered user.
In other cases, we may associate cookie information (including information from cookies placed through our advertisements on third-party sites) with an identifiable individual. For example:
o If we send you a targeted email that includes web beacons , cookies or other similar technologies, we will know whether you open, read or delete the message.
3.4. Do we use third-party cookies?
Some cookies we use are from third-party companies, such as Adobe Analytics, Facebook, Google, Linked In Analytics, to provide us with web analytics and intelligence about our websites. These companies use programming code to collect information about your interaction with our websites, such as the pages you visit, the links you click, and how long you are on our sites. This code is only active while on the Ciela Norma website. For more information about how these companies collect and use information on our behalf, please see their privacy statements: Adobe, Facebook, LinkedIn , Google and others.
3.5. Does Ciela Norma use tracking technologies without cookies?
We may also use pixel tags (so-called web beacons, including so-called conversion pixels ) or other technologies for similar purposes as stated above, and we may include them on our sites, in marketing communications or in our newsletters, on linked websites, to determine whether messages have been opened, clicked on. Pixel tags ( web beacons) do not place information on your device, but they can work together with cookies to monitor website activity. The information below about cookies also applies to pixel tags and similar technologies. The so-called conversion pixelsare small codes located on a specific web page that are triggered when someone visits a page, causing their number to increase.
3.6. How do I proceed if I do not want cookies?
By using our website, you accept that we may place cookies on your device as explained below.
If you wish to remove existing cookies from your device, you can do so using your browser options. If you want to block future cookies being placed on your device, you can change your browser settings to do so. Please note that deleting and blocking cookies will affect your experience of the website as parts of it may no longer work. Unless you have adjusted your browser settings to block cookies, our system will issue cookies as soon as you visit our site or click on a link in a targeted email we send you, even if you have deleted our cookies.
3.7. What types of cookies are there and which ones do our websites use?
The "cookies" used on the Ciela Norma websites are categorized based on the categories found on the European Commission website ( http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm ) and others public sources.
However, it is important to note that not all cookies can be used on all websites. A list of cookies used by our websites by category is set out below. Within these four categories below, cookies are classified as session or persistent cookies.
"Session cookies" are temporary and are deleted from your device after you close the browser window.
"Persistent cookies" remain on your device for a longer period of time and are used by the website to recognize your device when you return. More information about "cookies" can be found at the Internet addresses: http://www.allaboutcookies.org/ and http://www.youronlinechoices.eu/ .
The "cookies" used by https://www.ciela.net/ fall into the following categories:
Strictly Functional/Mandatory Cookies:
· PHPSESSID - current user session of the PHP server scripting language.
· cookieconsent_dismissed - cookie indicating consent/disagreement with the Cookie Notice.
· resolution - cookie that stores the resolution of the user's monitor.
· nlet.ciela.net, PHPSESSID - current user session of the PHP scripting language server to the email newsletter system.
· _fbp, Facebook Pixel - saves advertising and analytical information for the Facebook social network.
· _ga, Google Analytics - saves analytical/statistical information for Google Analytics.
· _gid, Google ID - saves your unique Google user number, if you have one, against ciela.net.
Third party cookies:
· Google.com, NID - same as _gid, but relative to Google.
· YouTube.com, Cache Storage, Database storage, Local storage - YouTube session cookies for storing video information.
· YouTube.com, VISITOR_INFO1_LIVE - saves information about the speed of the user's Internet connection.
· YouTube.com, YSC - Saves user settings for the YouTube player. The cookie is only stored while the current browser window is open.
4. HOW DO WE USE PERSONAL DATA WHEN YOU VISIT OUR OFFICES AND/OR PHYSICAL POINTS OF SALE?
You can contact our data protection officer by phone (02/ 903 00 26) or by email firstname.lastname@example.org to obtain further details on how we process your personal data when you visit our offices and/or physical points of sale (including bookstores and others).
5. HOW DO WE USE PERSONAL DATA FOR MARKETING PURPOSES?
In addition to the information listed above, this section describes how we use personal data for marketing purposes:
o What are the sources of marketing data?
o Do we send targeted emails?
o Do we maintain customer relationship management databases?
o Do we combine and analyze personal data?
o Do we share personal data with third parties?
o What are your rights regarding marketing communications?
5.1. What are the sources of marketing data?
Most of the personal data we collect and use for marketing purposes relates to individual employees of our customers and other partners with whom we have an existing business relationship. We may also obtain contact information from public sources, including content posted on social media, to make initial contact with the appropriate person at a client or other company.
5.2. Do we send targeted emails?
Targeted electronic communications from Ciela Norma may include additional data privacy information as required by applicable laws.
5.3. Do we maintain customer relationship management databases?
Like most companies, Ciela Norma uses customer relationship management technology to manage and track our marketing efforts. Our customer relationship databases include personal data belonging to individuals of our customer and other companies with whom we already have a business relationship or wish to develop one. Personal data used for these purposes includes relevant business information such as: contact details, publicly available information (e.g. board memberships, published articles, press releases, social media posts, email (including web activity following links from our emails ), the website activity of registered users of our website and other business information. If you wish to be excluded from our databases, you can use a sample ofRequest from the subject of personal data or to contact our data protection officer by phone at 02/ 903 00 26 or by email at email@example.com.
5.4. Do we combine and analyze your personal data?
5.5. Do we share personal data with third parties?
In addition to the third parties listed in the section To whom will we provide your personal data? Will we share your personal data with third countries? , we may share your personal data with marketing agencies as required by law.
5.6. What are your rights regarding marketing communications?
You can exercise your right to opt out of receiving future marketing communications by checking certain boxes on the forms we use to collect your personal data or by using opt-out mechanisms from emails we send you. You can also exercise the right to discontinue our marketing communications or remove your personal data from our customer relationship management databases at any time by contacting our data protection officer by telephone at 02/ 903 00 26 or email firstname.lastname@example.org. In such cases, we will retain minimal personal data to note that you have opted out so that we do not contact you again in the future. In addition, from time to time, we may provide you with the opportunity to inform us of your preferences through our websites.
6.1. Which categories of personal data does Ciela Norma process?
Ciela Norma will collect personal data about you to achieve the purposes specified in this policy .
Ciela Norma processes the following categories of visitor personal data:
- ordinary personal data , such as name and surname, email address, telephone, position/employer, bank card, etc.;
- audiovisual materials – such as photographs and images/frames captured on CCTV or other video systems.
The purposes for which we use your personal data are related to:
- providing our products and services, and managing Ciela Norma's business operations (including security);
- facilitating communication with you;
- financial and accounting activity;
- ensuring business continuity, protecting the health and safety of employees and visitors, protecting IT infrastructure, office equipment and other property.
6.2. Why does Ciela Norma process your personal data?
Ciela Norma may collect, use, transfer, disclose and otherwise process your personal data in the context of facilitating communication with you (including in emergencies), operating and managing Ciela Norma's business operations and systems, and subject to legal requirements.
6.3. On what legal basis does Ciela Norma process your personal data?
Ciela Norma processes your personal data as permitted by applicable data protection laws and internal policies.
a) Ciela Norma is required to do so to comply with a legal obligation to which it is subject;
b) such information is necessary for the performance of a contract to which you are a party;
c) the processing is necessary for the purposes of the legitimate interests pursued by Ciela Norma or by a third party, or
d) when necessary to protect the vital interests of any person.
Ciela Norma has a legitimate interest in collecting and processing personal data, for example: (1) to ensure the security of Ciela Norma's networks and information, (2) to administer and generally conduct business, and (3) to prevent fraud.
Where any of the above purposes involves an automated decision, Ciela Norma will implement that automated decision only with your prior consent and after providing you with comprehensible information about the logic involved in the automated decision, as well as the significance and intended consequences of that automated decision for you.
6.4. Who has access to your personal data?
In addition, when necessary, Ciela Norma may share your personal data with third parties, such as service providers and public authorities. Before doing so, Ciela Norma takes steps to protect your personal data. All third-party service providers and professional consultants to whom your personal information is disclosed are expected and required to protect the confidentiality and security of your personal information and may only use your personal information in accordance with applicable privacy laws .
6.5. How does Ciela Norma protect your personal data?
Ciela Norma applies organizational, physical and technical security measures to all personal data it processes. Ciela Norma has rules, policies, procedures and guidelines that have been developed taking into account the risks associated with categories of personal data.
Ciela Norma implements leading security measures to protect your personal data, maintaining a certificate according to ISO 27001, which confirms that we comply with the highest and strictest information security standards ..
6.6. How long does Ciela Norma keep your personal data?
Ciela Norma keeps your personal data only for as long as is necessary to achieve the purposes of the processing. Ciela Norma maintains a special policy and procedures for the management and storage of archives so that personal data is deleted after a reasonable period according to the following retention criteria:
o Ciela Norma keeps your personal data as far as it has a relationship with you;
o Ciela Norma retains your personal data for as long as necessary to comply with applicable legal requirements;
o Ciela Norma retains your personal data when it is appropriate to provide legal protection of Ciela Norma (for example, in connection with statutes of limitations, litigation or investigations).