Privacy notice on personal data processing held by AP Retail I EOOD
This Privacy Notice aims to provide information regarding the nature of your personal data processed by AP Retail I EOOD, in relation to the execution, service and performance of contracts for renting commercial areas, any other relations needed for the maintenance, marketing and management of Shopping Centre The Mall as well as the video surveilance held in the Shopping Center.
In case of any questions regarding this, please contact us via e-mail to: administration@themall.bg
or at: 115z , Tsarigradsko shose blvd., Mladost District, Sofia 1784, Bulgaria.
Should you wish to confirm whether AP Retail I EOOD processes your personal data, or to access any personal data AP Retail I EOOD might hold about you, please contact us us via e-mail: administration@themall.bg
INTRODUCTION
AP Retail I EOOD is the owner of Shopping Center The Mall (hereinafter “the Shopping Center” or “The Mall”).
The Mall is one of the largest shopping centers in Bulgaria and among the most popular ones in the capital Sofia. With its unique design, architecture and over 200 stores, situated on a total area of over 66,000 sq.m. the Mall offers its customers an unforgettable shopping experience and a variety of entertainment.
- I. CATEGORIES OF CONCERNED INDIVIDUALS (DATA SUBJECTS) AND PURPOSES OF DATA PROCESSING
For the performance of the activities, management and the development of the Shopping Center AP Retail I EOOD processes personal data of the following main categories of data subjects (Except for the internal employment and corporate relations):
- • INDIVIDUALS TAKING PART IN THE GAMES, PROMOTIONS AND OTHER MARKETING CAMPAIGNS ORGANISED BY AP RETAIL I EOOD
- • INDIVIDUALS SUBSCRIBED TO DIRECT MARKETING MESSAGES AND BULLETINS FROM THE MALL
- • VISITORS OF THE SHOPPING CENTRE – IN RELATION TO THE CARRYING OUT OF VIDEO SURVEILANCE ON THE TERRITORY OF THE MALL AND ITS PARKING LOT
- • LEGAL AND/OR AUTHORISED REPRESENTATIVES AND CONTACT PERSONS OF LESSEES OF COMMERCIAL AREAS IN THE MALL
- • LEGAL AND/OR AUTHORISED REPRESENTATIVES AND CONTACT PERSONS OF ALL CORPORATE ORGANISATIONS HAVING CONTRACTUAL RELATIONS WITH AP RETAIL I EOOD
- • BUSINESS CONTACTS
- II. HOW, WHY AND WITHIN WHAT TIME LIMITS DO WE PROCESS YOUR PERSONAL DATA
The below information is concerned to both data subjects who provided their personal data to AP Retail I EOOD by themselves as well as those whose personal data has been provided to AP Retail I by third parties (e.g. by their employers).
AP RETAIL I EOOD with Unified Identification Code: 20019535, having its seat and management address at: 115z Tsarigradsko shose blvd., Mladost district, 1784, Sofia, Republic of Bulgaria, represented by Veselin Ivanov Glavchev or any other registered manager, (hereinafter “APR”), in its capacity of Administrator, processes personal data as follows:
- • INDIVIDUALS PARTICIPATING IN GAMES, PROMOTIONS AND OTHER MARKETING CAMPAIGNS ORGANISED BY AP RETAIL I EOOD
APR processes the following categories of personal data of persons visiting Shopping Centre The Mall and/or The Mall’s Facebook and Instagram pages/profiles, participating in games, promotions and other marketing campaigns and initiatives organized by APR, and which are potential clients of The Mall’s lessees:
- (a) for physical identity: name and surname; gender; email; phone number;
- (b) data related to participation in games: data contained in photo/video recordings, comments and other social media publications (for more information regarding the data we process in relation to The Mall’s Facebook and Instagram page/profile, please see our Social Media Privacy Notice in our webpage https://bit.ly/3Lr2vaq);
- (c) data related to tax and accounting purposes: three names and personal identification code of winners in marketing campaigns.
Purpose, legal basis and time limit of processing
We may use the data above only for the following purposes:
- – administration of games and events, including contacting the winning/awarded participants, awarding prizes, discounts and/or other marketing materials, conducting mandatory accounting and taxation;
- – we may also (but not necessary) use the above personal data for direct marketing of any activities, initiatives and campaigns organized by The Mall and our partners, including but not limited to our lessees. This purpose for processing of your personal data also includes sending newsletters and various advertising messages for our activities.
APR processes these personal data on the legal basis of its legitimate interest to promote and advertise activities organized in the Shopping Center as well as on the ground of the APR’s contractual obligation to award prizes to the winning participants.
Information how to exercise your right to object can be found in Section III What Are Your Rights below.
The time limits for processing your personal data for these purposes are as follows:
- – for the purposes of administering the specific campaign/event your personal data will be processed for a maximum of 7 days after the expiration of the term for receiving the respective awards, discounts and/or other marketing materials (including in paper form);
- – for direct marketing purposes, the data are stored in marketing databases and the data storage term is 10 years after the end of the marketing campaign in which the data were collected;
- – data contained in documents, necessary for the execution of contracts – up to six years after termination of the respective contract or until closure of dispute related procedures;
- – data contained in accounting registers and financial statements or data contained in documents subject to tax audits and needed for accounting purposes – 11 years.
- • INDIVIDUALS SUBSCRIBED TO DIRECT MARKETING MESSAGES AND BULLETINS OF THE MALL
APR processes the following categories of personal data of visitors of the Shopping center and other persons, who have shown interest to marketing activities organized by APR and whose data has been included in our marketing database:
- (a) for physical identity: names, post address, email address, phone number, signature, gender.
Purpose, legal basis and time limit of processing
We use the above mentioned data only for the following purposes:
- – direct marketing of any activities, initiatives and campaigns organized by The Mall and our partners, including but not limited to our lessees. This purpose for processing of your personal data also includes sending newsletters and various advertising messages for our activities.
APR processes these personal data on the legal basis of its legitimate interest to popularize and advertise activities, taking place in the Shopping Center.
Information how to exercise your right to object to this processing can be found in Section III What Are Your Rights below.
The time limit for processing of your personal data for these purposes is 10 years from the end of the relevant marketing campaign, in the course of which the data was collected, or the receipt of your subscription request.
- • SHOPPING CENTER VISITORS – VIDEO SURVEILANCE
APR processes the following categories of personal data of visitors to the Shopping Center and the available parking lot:
- (a) for physical identity: video images;
- (b) other: registration numbers of vehicles.
Purpose, legal basis and time limit of processing
We use the above mentioned data only for the following purposes:
- – ensuring security on the territory of Shopping Center The Mall and its parking lot;
- – following the rules regarding the parking of vehicles on The Mall’s parking lot;
- – protection in the case of legal claims.
APR processes these personal data on the legal basis of its legitimate interest to ensure a higher level of protection and security on the territory of the Shopping Center, as well as in order to fulfill and control the performance of contractual obligations related to the use of the parking lot of the Shopping Center.
You have the right to object to the processing done on the basis of APR’s legitimate interest to ensure a higher level of protection and security on the territory of the Shopping Center. More information how to exercise your right to object can be found in Section III What Are Your Rights below.
The time limit for processing your personal data for these purposes is as follows:
- (a) data contained in general video recordings – up to 2 months;
- (b) video recordings, solely containing registration number of vehicles – up to 1 year;
- (c) data contained in video recordings of in case of accidents – up to 6 years or until the end of proceedings related to potential disputes.
- • LEGAL AND/OR AUTHORISED REPRESENTATIVES AND CONTACT PERSONS OF LESSEES OF COMMERCIAL AREAS IN THE MALL
- • LEGAL AND/OR AUTHORISED REPRESENTATIVES AND CONTACT PERSONS OF ALL CORPORATE ORGANISATIONS HAVING CONTRACTUAL RELATIONS WITH AP RETAIL I EOOD
(together referred to as the “Contractors” below)
APR processes the following categories of personal data of its Contractors:
- (a) the minimum amount of personal data necessary for the signing of relevant contracts – names and Personal Identification Number. Identity Card data are only used where the contract is signed with notary verification or by a representative authorized via notarized power of attorney.
- (b) personal data for business contact in the course of contract performance – this information is limited to the types of information which could be contained in business cards/electronic signature, including in e-mails: name and surname, position, name of employer, business address, business email address and business phone number.
We receive from our Contractors the above listed personal data (contact information) of employees or other individuals assigned by our Contractors as contact persons for the respective contract. Our Contractors providing us these data are also personal data controllers of these data and are responsible to provide the respective Data Subjects with all needed information with this respect. Furthermore, our Contractors are obliged to ensure the accuracy of these data and for keeping them up-to date all the time. This means that if any data provided to us is changed or no longer accurate, we need to be duly informed on this as soon as practically possible. Until receiving such notice, we assume that the provided contact related data are accurate and we may use it for the purposes below.
Purpose, legal basis and time limit of processing
The above mentioned data are only used for the following purposes:
- – performance of pre-contractual and contractual obligations, administration of contracts (including accounting and taxation), control over performance and debt collection, protection against legal claims.
The legal basis for this processing is the performance of pre-contractual and contractual obligations of APR and its legal obligation for accounting and taxation.
Personal data mentioned in this section is processed by APR in the following time limits:
- – data contained in accounting registers and financial statements: 11 years;
- – data contained in documents subject to tax audits and needed for accounting purposes: 11 years;
- – data contained in documents needed for the performance of contractual relations: up to 6 years after termination of the respective contract or until closure of dispute related procedures.
- – data processed in relation to the compliance with statutory obligations – within the applicable statutory terms.
- • BUSINESS CONTACTS
If you provided any employee of APR with your business contact information via your business card or in any other way or this information is publically available, please note that it is possible that APR has included this information of you in its business contacts list.
The above means that in case of business need, for the purpose of sending you holiday greetings or for the purpose of providing you with information about our services, events etc. APR may contact you but only in your official capacity in which we have your contact information.
APR provides all necessary protections to its database with business contacts as for all other personal data.
If you do not wish APR to contact you as described above, please inform us at any of our addresses listed in the next Section III and your contact information will be deleted from our business contacts database.
- III. WHAT ARE YOUR RIGHTS
If you are a person, whose personal data are processed by APR under any of the above circumstances, you have the following rights in this regard:
- (a) you have the right to object to the processing of your personal data for the purposes of direct marketing, if you are an addressee to direct marketing. If you make such an objection to our direct marketing messages we will no longer process your personal data for this purpose. However, in order to ensure that your objection is regarded, your data will be included in data base of objected against direct marketing data subjects;
- (b) you have the right to object to the processing of your personal data for the purposes of video surveillance of the Shopping center and The Mall’s parking lot. Please bear in mind that communication an objection does not automatically lead to the erasing of video footage containing your personal data. Our team will review the communicated objection in a one month period and will decide whether your rights and interests may override the legal basis for this processing.
- (c) all data subjects have the right:
- – to be informed about the types of personal data processed by APR;
- – to access to and copy of their processed personal data;
- – to correct or erase their personal data;
- – to limit processing;
- – portability.
You can exercise and of the above mentioned rights by submitting a written request, in either of the following ways:
- – by email to: administration@themall.bg
- – by letter, addressed to: AP Retail I EOOD, EIC 200019536, address: 115z , Tsarigradsko shose blvd., Mladost District, Sofia 1784, Bulgaria;
- – you may also object to direct marketing by other means, as specified in the relevant marketing message – for example, through following a link provided in an email.
You also have the right to complain regarding the processing of your personal data to the relevant authority, which for the Republic of Bulgaria is the Commission for Personal Data Protection with contact details: 2, Prof. Tsvetan Lazarov blvd., Sofia 1592; kzld@cpdp.bg; факс 029153525;
- IV. CONTENTS OF YOUR APPLICATION
Please note that your application for exercise of any of your rights should contain at least your names with other identification information about you, description of your request, preferred way of communication with you, address for correspondence, signature and date of the application.
If the application is signed by a representative, the respective power of attorney should be attached to the application.
APR may contact you for additional information, if it needs to ensure your identity or further clarify your request.
- V. WHOM WE CAN SHARE YOUR DATA WITH
APR may assign any of the above mentioned personal data processing activities related to direct marketing or games to marketing agencies and IT service providers, in the course ensuring the protection of data and its lawful processing. We may also provide your personal data to our partners, where necessary (for example to a couriers and co-organizers of games for the delivery of the prizes).
The data might also be provided to APR’s shareholder/s, third parties involved in the maintenance and management of Shopping center The Mall, such as our accountants, auditors, lawyers, marketing agencies, IT suppliers and other software and hardware service suppliers as well as to competent authorities if duly requested.
- VI. EXCESSIVE DATA PROVIDED BY/ABOUT YOU
If we receive any personal data in excesses of what is needed for us to comply with our purposes above, we will delete this information immediately but not later than a month after its receipt.
- VII. PROTECTION OF YOUR DATA
To help protect the privacy of your personal data, we maintain physical, personal, technical and administrative safeguards. We update and test our security technology on an ongoing basis. We restrict access to your personal data to those employees and personal data processors who need to know that information to provide benefits, goods or services to you. In addition, we train our employees about the importance of confidentiality and maintaining the privacy and security of your information. We commit to taking appropriate disciplinary measures to enforce our employees’ privacy responsibilities.
- VIII. USING THE WEBPAGE THEMALL.BG
As is true of most other websites, APR’s website collects certain information automatically and stores it in log files. The information may include internet protocol (IP) addresses, the region or general location where your computer or device is accessing the internet, browser type, operating system and other usage information about the use of our website, including a history of the subsections you view. We use this information to help us design our site to better suit our users’ needs. We may also use your IP address to help diagnose problems with our server and to administer our website, analyze trends, track visitor movements, and gather broad demographic information that assists us in identifying visitor preferences. APR website also uses cookies and web beacons. It does not track users when they cross to third party websites, does not provide targeted advertising to them, and therefore does not respond to Do Not Track (DNT) signals.
- IX. CHANGES AND UPDATES TO THIS PRIVACY NOTICE
As our organization, goods and services change from time to time, this Privacy Notice is expected to change as well. We reserve the right to amend the Privacy Notice at any time, for any reason, without notice to you, other than the posting of the amended Privacy Notice at this Site. We may e-mail periodic reminders of our notices and terms and conditions and will e-mail our partners and hotel guests of material changes thereto, but you should check our website frequently to see the current Privacy Notice that is in effect and any changes that may have been made to it.
The present document represents privacy notice within the meaning of Art. 13 and Art. 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).