This Privacy Policy ("Policy") has been adopted and duly approved by the company "CLOLYTIC", having its registered office and principal place of business in Sofia, Oborishte District, 86 “Exarch Yosif” Str., UIC 206931993 (hereinafter referred to as the "Company").
This Privacy Policy is intended for informational purposes and aims to provide information on the rules for processing, storing, and protecting personal data collected by "CLOLYTIC" while delivering its services to clients and partners, as well as to inform you of your rights regarding the processing of your personal data.
Please note that this Policy will be regularly updated in accordance with changes in applicable regulations to reflect any modifications in the manner in which we process your personal data. Certain specific activities may be subject to separate and/or individual privacy declarations.
We understand the importance of maintaining the confidentiality of your personal data. Every time you access and use our website (www.clolytic.com), we ensure the security of all users’ data and guarantee that your personal data is protected.
The purpose of this Privacy Policy is to help you understand how we collect, use, and protect the information that reaches us and that you provide, as well as to assist you in making informed decisions when using our services and products.
All services and products of "CLOLYTIC" are available on its website: www.clolytic.com, where our clients can purchase digital informational products.
"CLOLYTIC" is duly registered as a commercial company in accordance with the applicable legislation of the Republic of Bulgaria. The Company is duly entered in the Commercial Register at the Bulgarian Registry Agency.
"CLOLYTIC" is a partner of the platform Amazon Wev Services and part of the Amazon AWS Partner Network (APN) for e-commerce partnerships. The Company provides its clients in the Republic of Bulgaria with some of Amazon's proprietary products and web services (Amazon Web Services), the most popular of which include VPS hosting management, cloud applications, hosting services, domain registration and transfer, all supporting the business activities of each of the Company’s clients.
As an official partner, the Company operates in compliance with applicable regulations, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation), as well as the current Bulgarian Personal Data Protection Act (published in the State Gazette, issue No. 1 of 04.01.2002, effective as of 01.01.2002, last amended and supplemented in issue No. 17 of 26.02.2019; Constitutional Court Decision No. 8 of 15.11.2019 – State Gazette No. 93 of 26.11.2019) – PDPA.
The provision of products and web services offered by "CLOLYTIC" is carried out in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation) – Regulation (EU) 2016/679.
The current Bulgarian Personal Data Protection Act (published in the State Gazette, issue No. 1 of 04.01.2002, effective as of 01.01.2002, last amended and supplemented in issue No. 17 of 26.02.2019; Constitutional Court Decision No. 8 of 15.11.2019 – State Gazette No. 93 of 26.11.2019) – PDPA, is also applicable.
Key Terms
- "Personal Data" is defined according to Article 4, point 1 of Regulation (EU) 2016/679.
- "Controller" (excluding the controller under Chapter Eight of the PDPA) is defined according to Article 4, point 7 of Regulation (EU) 2016/679.
- "Data Processor" is defined according to Article 4, point 8 of Regulation (EU) 2016/679.
- "Processing" is defined according to Article 4, point 2 of Regulation (EU) 2016/679.
- "Restriction of Processing" is defined according to Article 4, point 3 of Regulation (EU) 2016/679.
- "Profiling" is defined according to Article 4, point 4 of Regulation (EU) 2016/679.
- "Pseudonymization" is defined according to Article 4, point 5 of Regulation (EU) 2016/679.
- "Recipient" is defined according to Article 4, point 9 of Regulation (EU) 2016/679. A state or local authority, as well as any entity whose main activity involves the expenditure of public funds, may receive personal data in the context of specific investigations in accordance with the law but are not considered recipients under Chapter Eight of the PDPA. Processing of personal data by these authorities or entities complies with applicable data protection rules according to the purpose of processing.
- "Personal Data Register" is defined according to Article 4, point 6 of Regulation (EU) 2016/679.
- "Personal Data Breach" is defined according to Article 4, point 12 of Regulation (EU) 2016/679.
- "Genetic Data" is defined according to Article 4, point 13 of Regulation (EU) 2016/679.
- "Biometric Data" is defined according to Article 4, point 14 of Regulation (EU) 2016/679.
- "Erasure" under the PDPA refers to the irreversible deletion of information from the respective medium.
- "Destruction" under the PDPA refers to the irreversible physical destruction of the medium containing the information.
- "Consent of the Data Subject" is defined according to Article 4, point 11 of Regulation (EU) 2016/679.
- "Amazon Web Services" refers to a suite of remote computing web services that form the world's most extensive and widely used cloud platform, offering over 200 services globally.
- "Amazon AWS Partner Network" (APN) is a global community of Amazon partners that provides programs, expertise, and resources to create, offer, and sell services to end users. This diverse network includes around 100,000 Amazon partners from over 150 countries. Amazon Europe Core Sarl, Amazon EU Sarl, and/or other Amazon-related companies provide a variety of functionalities on their websites, as well as other products and services, which you can find on Amazon’s website.
Principles Related to the Processing of Personal Data
- The personal data provided to "CLOLYTIC" is processed in accordance with the principles governing data processing as outlined in Regulation (EU) 2016/679.
- Data is processed lawfully, fairly, and transparently in relation to the data subject. The lawfulness of processing personal data is based on the data subject’s explicit consent for the processing of their personal data for one or more specific purposes specified by "CLOLYTIC" as the controller.
- Data is collected for specific, explicitly stated, and legitimate purposes and is not further processed in a way that is incompatible with those purposes. The principle of "data minimization" applies, in accordance with Article 5, point 1(c) of Regulation (EU) 2016/679, meaning that the personal data collected is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.
- The principle of "accuracy" applies, as per Article 5, point 1(d) of Regulation (EU) 2016/679, meaning that personal data is accurate and, where necessary, kept up to date. All reasonable steps are taken to ensure that inaccurate personal data is erased or rectified without delay, considering the purposes for which it is processed.
- The principle of "storage limitation" applies, whereby personal data is stored in a form that allows for the identification of the data subject for no longer than necessary for the purposes for which the data is processed, with appropriate technical and organizational measures applied, as outlined in Regulation (EU) 2016/679.
What Personal Data You Provide Us
"CLOLYTIC" processes the following personal data that you provide: names (including first and/or last name), email address, and contact phone number.
This personal data is provided for the purpose of identifying the individual who has contacted "CLOLYTIC" in the following cases:
- By completing the electronic form for registration on "CLOLYTIC"'s website at https://clolytic.com/;
- When searching for and purchasing Amazon products and services from the range we offer;
- When you request an accounting document (invoice) for the products and services you have purchased, you must also provide the details of the legal entity, identifier, VAT number, registered address, and headquarters.
The provided personal data does not fall under the special categories of personal data, as defined in Article 9, point 1, and Article 10 of Regulation (EU) 2016/679, nor does it include genetic, biometric, or health-related data of the data subject as outlined in Article 4, points 13, 14, and 15 of the Regulation.
You may choose not to provide some of your personal data, which may limit our ability to offer you certain Amazon services.
Automatic Information We Collect and Analyze
This includes internet protocol (IP) address, which connects your computer to other devices; usernames, passwords, email addresses; the location of your computer; and information on documents and data downloaded from our site. We also collect and process data from other sources, including: Information on your purchasing behavior related to our products and services – such as data on credit and other bank cards you have chosen to use for payment of our products and/or services, as well as any additional services to be specified.
Data You Have Access To
You have access to the following data you have provided us:
- Status of your most recent order;
- Your complete order history;
- Personal identifying information: (name, phone number, email, username, password);
- Payment method settings, including provided bank card information, and any discount/voucher codes used;
- Order confirmation details we send to the email address you have provided.
Rules for Processing Personal Data
Processing of personal data is based on the data subject’s consent. The data subject has the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Personal data processing is minimized, and only data necessary to provide "CLOLYTIC"'s services are processed. The processing is conducted in a way that prevents unauthorized individuals from accessing personal data without intervention by "CLOLYTIC".
Cases of Processing Without Consent of the Data Subject
If applicable, "CLOLYTIC" will be a joint data controller with Amazon under Article 26 of the Regulation. If so, both parties are required to jointly and transparently determine the purposes and means of processing the data and designate a contact person.
Processing of Children’s Data
Processing of personal data for children is lawful if the child is at least 16 years old. If the child is under 16, processing is lawful only if consent is given or authorized by the person with parental responsibility. "CLOLYTIC" makes reasonable efforts to verify that such consent is given or authorized by the person with parental responsibility, taking into account available technology.
"CLOLYTIC" does not process special categories of personal data as defined in Article 9(1) of Regulation (EU) 2016/679, nor does it process personal data related to criminal convictions and offenses under Article 10 of Regulation (EU) 2016/679.
Information Provided When Collecting Personal Data
Upon collecting personal data, "CLOLYTIC" provides the data subject with:
- Administrator identification data and contact information;
- Contact details for the data protection officer, if applicable;
- The purposes and legal basis for processing the personal data;
- The period for which the data will be processed;
- The right to request access to, rectification, erasure, or restriction of processing of personal data or to object to processing, as well as the right to data portability;
- The right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
- The right to lodge a complaint with a supervisory authority;
- Whether providing personal data is a legal or contractual requirement, or a requirement necessary for contract conclusion, and the possible consequences of not providing data;
- The existence of automated decision-making, including profiling, as per Regulation (EU) 2016/679, as well as the significance and anticipated consequences of such processing for the data subject.
As a Data Subject, You Have the Following Rights
- Right of Access: To obtain confirmation from the data controller as to whether your personal data is processed and, if so, to access the data and receive information as outlined in Article 15(1) of Regulation (EU) 2016/679.
- Right to Rectification: To request correction of inaccurate personal data without undue delay and completion of incomplete personal data, including by adding a declaration.
- Right to Be Forgotten: To request erasure of personal data without undue delay, as specified in Article 17(1) of Regulation (EU) 2016/679.
- Right to Restrict Processing: Under conditions specified in Article 18(1) of Regulation (EU) 2016/679.
- Right to Data Portability: To receive your personal data in a structured, commonly used, and machine-readable format and to transfer that data to another controller without hindrance, under conditions specified in Article 20(1) of Regulation (EU) 2016/679.
- Right to Object to Processing of Personal Data, as per Article 21 of Regulation (EU) 2016/679, including profiling. For direct marketing purposes, you may object to the processing of your personal data, including profiling related to direct marketing.
- Right Not to Be Subject to a Decision Based Solely on Automated Processing, Including Profiling, that produces legal effects or similarly affects you significantly.
These rights can be exercised by submitting a written request to the data controller. Requests can also be submitted electronically, under applicable regulations, or via the user interface of the information system that processes the data, once identification is completed through system-specific identification means.
If you believe your rights under Regulation (EU) 2016/679 and the Bulgarian Personal Data Protection Act have been violated, you have the right to contact the Commission for Personal Data Protection within six months of learning of the violation, but no later than two years from the date of the violation. The contact details of the Commission for Personal Data Protection are: Republic of Bulgaria, Sofia 1592, Prof. Tsvetan Lazarov Blvd. № 2, GPS Coordinates: N 42.668839, E 23.377495 Email: kzld@cpdp.bg Website: www.cpdp.bg
Certification under Article 42 of the Regulation
Regarding certification, it is not specified whether "CLOLYTIC" has obtained certification for personal data protection under Article 42 of Regulation (EU) 2016/679.
Personal Data Processing Register
As a data controller, "CLOLYTIC" maintains a personal data processing register (in written and electronic form), which includes at least the following information as per Article 30, paragraph 5 of the Regulation:
- The name and contact details of the data controller, their representative, the data protection officer, if applicable, and where relevant, the data processor and joint controllers;
- The purposes of processing;
- A description of the categories of data subjects and the categories of personal data;
- The categories of recipients to whom the personal data have been or will be disclosed, including recipients in member states, third countries, or international organizations, where applicable;
- Where applicable, information about data transfers to a third country or international organization, including identification of the third country or organization and documentation of appropriate safeguards;
- Where possible, the intended retention periods for different data categories;
- Where feasible, a general description of the technical and organizational security measures outlined in Article 33.
Upon request from the supervisory authority, "CLOLYTIC" provides access to the register.
Security Measures for Data Processing
To ensure data processing security, "CLOLYTIC" implements appropriate technical and organizational security measures, where relevant, such as:
- Encryption of personal data;
- Ability to maintain continuous confidentiality, integrity, availability, and resilience of processing systems and services;
- Capability to promptly restore availability and access to personal data in case of physical or technical incidents;
- Regular testing, assessment, and evaluation of the effectiveness of the technical and organizational measures to ensure processing security.
"CLOLYTIC" has taken necessary steps to ensure that any individual acting under its supervision, who has access to personal data, processes the data only according to the instructions of the controller, except where required to do so by EU or Member State law.
Personal Data Security Breach
In the event of a personal data security breach, the data controller notifies the supervisory authority without undue delay and, if feasible, within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. The notification includes reasons for the delay if not submitted within 72 hours.
The controller documents each personal data security breach, including facts related to the breach, its consequences, and the actions taken to address it.
If there is a high risk to the rights and freedoms of individuals, the controller promptly informs the data subject about the breach. However, this notification to the data subject is not required if any of the following conditions are met: a)The controller has implemented appropriate technical and organizational safeguards, such as encryption, for the affected personal data; b) The controller has taken subsequent measures to ensure that the high risk to the rights and freedoms of data subjects is no longer likely to materialize; c) It would involve disproportionate effort.
Purpose of Data Processing
Personal data is processed solely to provide "CLOLYTIC"'s clients and partners with access to the company’s services and products, as an official European partner of Amazon’s e-commerce platform and a member of the Amazon AWS Partner Network (APN).
Data Retention
"CLOLYTIC" stores personal data for five (5) years or for a period necessary to fulfill the relevant purposes, unless applicable law requires a longer period.
Privacy Policy Changes
"CLOLYTIC" reserves the right to amend and supplement this Privacy Policy at any time, in order to update the information presented here. This is intended to provide the most accurate, comprehensive, and reliable information to our clients and partners about our services and the protection of their personal data.
