Effective date: 25 June 2024

1. INTRODUCTION AND SCOPE

This Privacy Policy (the "Policy") is intended to inform you about how Inferno Parfyums EOOD ("Controller", "we", "us"), with company registration number (EIK) 208160838 and registered office at 12 Yantra St., 7020 Vazrazhdane district, Ruse, processes your personal data as a visitor or customer of our website www.inferno.bg (the "Website").

We understand the importance of your privacy and are committed to protecting your data in a transparent and lawful manner in full compliance with Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR) and applicable Bulgarian law.

2. IDENTIFICATION OF THE DATA CONTROLLER

  • Name: Inferno Perfumes Ltd.
  • UIC/BULSTAT: 208160838
  • Registered office and management address: Ruse, 12 Yantra St., 7020 Vazrazhdane district
  • Address for correspondence: Ruse, 12 Yantra St., 7020 Vazrazhdane district
  • Contact email: [email protected]
  • Contact phone: 0875 40 40 50

3. CATEGORIES OF PERSONAL DATA WE PROCESS

Depending on how you interact with our Website, we may collect and process the following categories of personal data:

  • Identification details: First, middle and last name.
  • Contact details: Email address, phone number, shipping address.
  • Order and payment details: Purchase history, details of payment method chosen (we do not store full bank card details; these are handled securely by our payment service provider partners), order number, billing address.
  • User profile details: Username, encrypted password, wish list ("Wishlist"), fragrance preferences (where such functionality is available).
  • Technical and digital data: IP address, cookie data (according to our Cookie Policy), device and browser type, login details.
  • Communication data: Any information you provide when corresponding with us by email, contact form or telephone.

4. PURPOSES AND LEGAL GROUNDS FOR PROCESSING

We only process your personal data for specific, explicit and legitimate purposes, and for each purpose we apply the relevant legal basis under the GDPR.

Purpose of processingCategories of dataLegal basis (under GDPR)
1. Conclusion and execution of a purchase and sale agreement (order processing, delivery, payment)Identification, contact, ordersArt. 6(1)(b) - performance of a contract to which you are a party.
2. Create and manage a user profileIdentification, contact, profileArt. 6(1)(b) - to take steps at your request before entering into a contract.
3. Accounting and tax reportingIdentification, for orders, addressArt. 6(1)(c) - compliance with a legal obligation (e.g. Accounting Act, VAT Act).
4. Communication and customer service (answering queries, solving cases)Identification, contact, from communicationArt. 6(1)(f) - our legitimate interest to provide quality service.
5. Direct marketing and sending commercial messages (information about new perfumes, promotions, personalized offers)Identification, contact, ordersArt. 6(1)(a) - Your express, freely given consent.
6. Website improvement and user behaviour analysisTechnical and digital dataArt. 6(1)(a) (for analytical cookies) and point (f) (legitimate interest for optimization).
7. Prevent fraud and protect legal interestsAll relevant categoriesArt. 6(1)(f) - our legitimate interest in protecting our business and assets.

5. DATA RETENTION PERIOD

We retain your personal data only for the period necessary to achieve the purposes for which it was collected or as required by law:

  • Data related to orders: For a period of 10 years, starting from 1 January of the year following the year of the order, in accordance with the Accounting Act.
  • User profile data: Until you request its deletion, or after a period of inactivity of 3 years.
  • Data for marketing purposes (subject to consent): Until your consent is withdrawn.
  • Communication data: For the period up to 1 year after completion of the correspondence.

6. SHARING AND DISCLOSURE OF PERSONAL DATA

We do not sell or provide your personal data to third parties for their marketing purposes. We may only share your data with trusted partners (data processors) who assist us in our activities, subject to strict confidentiality and security requirements:

  • Courier companies: For carrying out deliveries (e.g. Econt, Speedy).
  • Payment service providers: For secure payment processing.
  • IT providers and hosting companies: For the maintenance and security of the Website.
  • Marketing and advertising agencies: Subject to your express consent for advertising purposes.
  • Accounting and legal consultants.
  • State and municipal authorities: Upon a legal basis and in due course.

7. DATA TRANSFERS OUTSIDE THE EU/EEA

Some of our partners (e.g. Google, Meta) may be located outside the European Union. In such cases, we ensure that the transfer of data is subject to standard contractual clauses approved by the European Commission or other appropriate safeguards under Chapter V of the GDPR that provide an adequate level of protection.

8. YOUR RIGHTS AS A DATA SUBJECT

Under the GDPR, you have the following rights in relation to your personal data:

  • Right of access: To receive a copy of the data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure („right to be forgotten“): Request erasure of your data in certain circumstances.
  • Right to restriction of processing: Request a temporary suspension of processing.
  • Right to data portability: To receive your data in a structured, machine-readable format and transfer it to another controller.
  • Right to object: To object to processing based on a legitimate interest.
  • Right to withdraw consent: At any time, without prejudice to the lawfulness of the processing up to the time of withdrawal.

If you wish to exercise any of these rights, please contact us at the contacts listed in section 2.

You also have the right to lodge a complaint with the supervisory authority – the Commission for Personal Data Protection (CPDP), address: 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, or online at www.cpdp.bg.

9. DATA SECURITY

We implement appropriate technical and organisational measures to protect your personal data from accidental loss, unauthorised access, alteration or disclosure. These include the use of an SSL certificate for connection encryption, access control, pseudonymisation and regular security audits.

10. UPDATES TO THIS POLICY

This Declaration may be updated from time to time. Any changes will be posted on this page and the date of the last revision will be reflected.