29 March 2022
As administrator of personal data, Gatsby Metals Ltd. has an obligation in case of written request to inform where and for what purposes personal information is stored and processed.
For contact with Gatsby Metals EOOD:
I Types of information related to personal data received on the website
• Information provided by filling in forms on the site or any other information sent through the website or by email
• Records of correspondence via website, email, postal address, telephone or other methods
• Answers to questionnaires or surveys
• Data on site visits, including but not limited to traffic data, IP address, weblog and other communication data.
II Information that may contain personal data is processed for the following purposes
• Exercise of rights within the meaning of Regulation (EU) 2016/679 before Gatsby Metals EOOD in its capacity as controller of personal data
We can keep the information we collect and monitor in our network only as long as we need to meet the above objectives.
Gatsby Metals EOOD's rules on personal data protection guarantee the interests and fundamental rights of the data subject, which take precedence over the interest of the controller when personal data are processed in circumstances where data subjects do not reasonably expect further processing.
The processing of personal data, strictly necessary for the purposes of crime prevention, is in the legitimate interest of Gatsby Metals EOOD, as a data controller. The processing of personal data for the purposes of direct marketing is considered to be carried out of legitimate interest.
III Legal basis for the processing of personal data
To the extent that we obtain the consent of the data subject for the processing of personal data, the provision of Art. 6, paragraph 1, b. "A" of the EU General Data Protection Regulation (GDPR) applies as a legal basis for the processing of personal data.
In the processing of personal data, which is necessary for the performance of a contract to which the data subject is a party, Art. 6, paragraph 1, b. "B" of the GDPR applies as a legal basis. This also applies to the processing required for pre-contractual relations.
When the processing of personal data is required to fulfill a legal obligation that applies to our company, Art. 6, paragraph 1, b. "C" GDPR serves as a legal basis.
In case the vital interests of the data subjects or another natural person require the processing of personal data, the provision of Art. 6, paragraph 1, b. "D" The GDPR serves as a legal basis.
If the processing is related to a legitimate interest of our company and if the civil rights and fundamental freedoms of the data subject do not exceed the stated interest, Art. 6 (1) (b) "A" GDPR applies as a legal basis for processing.
IV Sharing personal data
Stored personal data may be provided to our branch or to trusted business partners who provide services on our behalf, for example for technical support to evaluate the usefulness of the website, for marketing purposes, to computer security incident response teams, for delivery of goods or provision other types services.
Personal data is shared with such parties only to the extent necessary to perform the services requested by the client and to protect his and Gatsby Metals EOOD's rights, property or security, or if we are required to do so by legal obligation or if this disclosure is required for the investigation of crimes.
V Human resources
For the purposes of human resources management, we process personal data of job applicants, current and former employees of Gatsby Metals Ltd.
In the course of human resources management activities, data for identification of individuals, data on education and qualification, health data, contact data, as well as other data required by virtue of special laws governing employment and service relations are processed. , tax and social security relations, business accounting, health and safety working conditions, and social issues.
The collected data are used only for the above purposes and are provided to third parties only in cases where this is required by law. In such cases, data may be provided to, for example, the NRA, the Court of Auditors, the DG Labor Inspectorate and other public bodies, in view of their powers and competences. The information is not stored outside the EU and the European Economic Area.
Gatsby Metals Ltd. provides the appropriate technical and organizational measures for personal data protection. In connection with the performance of employment or official legal relations, only the personal data required by law are processed, which are stored within the time limits set by the labor and social security legislation. The personnel selection procedures shall comply with the requirements of the special laws governing this activity. Gatsby Metals Ltd. sets a period of three months for storing personal data of participants in personnel acquisition procedures.
Where the selection procedure requires the presentation of originals or notarized copies of documents certifying the candidate's physical and mental fitness, the required qualifications and experience for the position held, the data subject who has not been approved for appointment may request within 30 day from the final completion of the selection procedure to receive back the submitted documents. Gatsby Metals Ltd. returns the documents in the way they were submitted.
The activities for ensuring health and safety working conditions are regulated by a contract with an occupational medicine service pursuant to Ordinance № 3 of 25 January 2008 on the conditions and procedure for carrying out the activities of occupational medicine services.
In the performance of its activities, personal data of individuals are processed for the fulfilment of contracts concluded by Gatsby Metals EOOD within the meaning of the CPA, CA, etc.
To the extent that in connection with the performance of these contracts personal data of individual individuals are processed, information about them shall be processed in a minimum volume, sufficient only for the exact performance of the obligations under the respective contract. Access to this information is granted to third parties only when specified in a special law.
Personal data is processed for:
• providing services to users, including the creation and management of user profiles, the resolution of technical problems and the activation of functions
• customize offers and experiences, including ads
• monitoring general and individual user activity, such as keyword searches, publications and transaction activity, as well as website traffic management
• connect with our customers, including for service issues, customer care or authorized marketing communications through all available communication channels
• performing analyzes to improve our services
• to apply our Terms and Conditions, including the fight against fraud and abuse.
VII Exercise of rights within the meaning of Regulation (EU) 2016/679 before Gatsby Metals EOOD in its capacity as personal data controller
Every client has the right to exercise his rights under Art. 15-22 of Regulation (EU) 2016/679 before Gatsby Metals EOOD, for the personal data that Gatsby Metals EOOD processes for him.
When submitting requests for the exercise of rights within the meaning of Regulation (EU) 2016/679 to Gatsby Metals EOOD, identification will be requested - by providing an identity document or by other methods and means of identification.
The personal data processed in connection with the processing of individual requests will be used only for the purposes of exercising these rights. In this regard, personal data may be provided to third parties only if required by law.
Each client will be assisted if he decides to exercise his rights over his personal data, including: withdrawal of his consent; access to his personal data; updating his personal data; deletion of his personal data; limiting the processing of personal data in certain circumstances; the possibility to object to the processing of data; possibility to challenge a decision taken entirely through automated processing.
Gatsby Metals Ltd. strictly observes the "right to be forgotten" in the online environment. To this end, Gatsby Metals Ltd. takes reasonable measures, taking into account its available technologies and available resources, including technical measures to inform administrators / co-administrators who process personal data at the request of the data subject.
VIII Newsletter subscribers
Gatsby Metals EOOD publishes an Information Bulletin containing news about the work of the company, as well as useful information about the activities of Gatsby Metals EOOD.
In order to receive the newsletter, immediately after its issuance, registration is required via e-mail. Regardless of whether in this case the e-mail address represents personal data or not, Gatsby Metals EOOD will use the provided e-mail addresses only for the purposes of delivering the Newsletter.
Individuals have the right to unsubscribe from receiving the newsletter by e-mail at any time. The option is available in the profile of each registered user on the website of Gatsby Metals EOOD, as well as with each sent newsletter.
IX Collection of personal data in order to provide services requested by the user
Each order is related to the provision of personal information that is necessary to perform the requested service. This information is recorded in a database located on a secure server located in a server room in the office of Gatsby Metals Ltd. Gatsby Metals Ltd. uses the information provided only to perform the required service. Gatsby Metals Ltd. does not provide this information to third parties.
A cookie is a small amount of data that a website stores on a visitor's computer or mobile device. On the gatsbymetals.com website, cookies are used in connection with its operation, as well as to collect statistics for Google Analytics analysis. The cookies are used to differentiate between users and sessions, to define new sessions, to submit requests, to store the source of traffic and the way in which the site is reached.
The website of Gatsby Metals Ltd. uses the following cookies:
• PHPSESSID - contains only a reference to a session stored on the web server. No information is stored in the user's browser and this cookie can only be used in the current session.
• Cookies used to collect statistics for analysis, for which we use Google Analytics. You can find out more about the cookies generated by Google Analytics here.
• Cookies used to collect statistics for Facebook Pixel analysis. You can find out more about the cookies generated by Facebook Pixel here.
By setting up their browser accordingly, each customer can always turn off the cookies of Gatsby Metals Ltd. or third-party cookies. In this case, it is possible to lose some of the functionality the services on the website.
XI Log Files
Like most websites, the website of Gatsby Metals Ltd. collects data in log files. This information includes IP, browser (such as Mozzilla, IE, Chrome and others), operating system (Linux, Windows, iOS), date and time of visit to the website, pages visited. We reserve the right to use the IP addresses of users to reveal their identity in cases where this is necessary in compliance with the law. This information is kept on our web server, located in a server room in the office of Gatsby Metals Ltd.
XII Links to other websites
XIII Processing of personal data of minors
Persons under the age of 16 must not pass on any personal data of their parents or legal guardians without their consent. According to Art. 8 of the GDPR, children aged 16 and under may declare such consent only with the consent of their parents or legal guardians. The personal data of minors are not collected and processed deliberately.
XIV Violation of personal data security
Violation of personal data security may, if not adequately and timely addressed, lead to physical, material or non-material damage to individuals, such as loss of control over personal data or restriction of their rights, discrimination, identity theft or fraud with false identity, financial loss, unauthorized removal of pseudonymization, damage to reputation, breach of confidentiality of personal data protected by professional secrecy, or any other significant economic or social adverse consequences for the individuals concerned.
Therefore, as soon as it establishes a breach of personal data security, Gatsby Metals Ltd. assumes the obligation and responsibility, without undue delay to notify the Commission for Personal Data Protection of the breach of personal data security, no later than 72 hours after establishment, unless Gatsby Metals EOOD is able to prove in accordance with the principle of accountability that there is no likelihood that the breach of personal data security will lead to a risk to the rights and freedoms of individuals.
When such notification cannot be submitted within 72 hours, Gatsby Metals EOOD shall state the reasons for the delay and submit the information in stages to the Commission for Personal Data Protection, without unnecessary additional delay.
XV Changes in the data protection policy
XVI Questions, requests and complaints
If a client has questions about the processing of personal data in Gatsby Metals Ltd. or suggestions regarding our measures and rules on personal data protection, he can send a message to the following address with the subject "Personal data protection": firstname.lastname@example.org
If you suspect that the processing of personal data violates the provisions on personal data protection, you can contact the competent state administrative body. In Bulgaria, this is the Commission for Personal Data Protection. To contact the Commission for Personal Data Protection:
Sofia 1592, Blvd. "Prof. Tsvetan Lazarov "№ 2
Each client has the right to appeal against actions and acts of Gatsby Metals EOOD, as a controller of personal data, and in court if it deems that it has violated rights under Regulation 2016/679 and the Personal Data Protection Act. As of 15 February 2016, the European Commission provides a platform for out-of-court mediation, the purpose of which is to enable consumers to resolve out-of-court disputes over online orders. The out-of-court dispute resolution platform is available at the following address: https://ec.europa.eu/consumers/odr/