Privacy policy

Privacy policy

(effective from 23.05.2018)

The e-shop “THE FAMILY COFFEE ROASTERS” (https://thefamilycoffee.com/wpbelly) processes personal data of visitors and registered users for the purposes of advertising, sale and delivery of coffee and ancillary activities and services related to them. Administrator of personal data (“Administrator”) processed by the e-shop “THE FAMILY COFFEE ROASTERS“.

The Data Protection Officer of the Administrator will answer all your questions regarding the processing and protection of personal data, as well as make easier and more understandable the process of using your rights as a subject of personal data. The address for direct contact with him / her is e-mail: roastery@thefamilycoffee.com

The types of personal data we process I. We process the following categories of data on a contractual basis: 1. Data about your account in the e-shop “THE FAMILY COFFEE ROASTERS“, which is created for you after entering into an informal contract with the Administrator, accepting the General Terms of Use of the website and e-shop “THE FAMILY COFFEE ROASTERS” – http: //thefamilycoffee.com/wpbelly, (“General Terms”):

● Personal and family name;
● Email address;
● Address and telephone

2. On-site order details made by you when purchasing goods from the physical store “THE FAMILY COFFEE ROASTERS“:

● Invoice data – names, PIN, telephone, city, country, postal code, address;
● Personal and surname of the delivery person;
● Delivery address – country, city, postal code, address; ● Telephone for delivery;
● Method of delivery;
● Method of payment;
● Payment status;
● Delivery status;

3. Data for an online order through the e-shop “THE FAMILY COFFEE ROASTERS“, made by you, concluding an informal contract at a distance with the Administrator in application of the General Terms:

● Personal and surname of the delivery person;
● Delivery address – country, city, postal code, address; ● Delivery phone;
● Invoice data – names, PIN, telephone, city, country, postal code, address;
● Method of delivery;
● Method of payment;
● Order number;
● Payment amount;
● Payment status;
● Delivery status;

II. We process the following data on the basis of your consent, expressed through deliberate action – self-entry of optional data and / or free choice of specific options:

1. Information about your account in the e-shop “THE FAMILY COFFEE ROASTERS“:

● Company name of the legal entity and / or name of another personified or impersonal entity / organization;

2. Contact details and sent message or published comment provided when filling in the contact form of the e-shop “THE FAMILY COFFEE ROASTERS” or when sending to us by e-mail, conventional mail, telegram, fax, phone call, sending an SMS , posting a comment and other forms of communication and / or expression:

● Personal and family name;
● Email address;
● Phone number;
● Fax number;
● Address;
● Internet site;
● Content of the comment / message;

3. Data for online order through the e-shop “THE FAMILY COFFEE ROASTERS“:

● Order history;

You may revoke any of the consents provided above through your account settings or in the form and manner prescribed in this Policy. Upon withdrawal of the consent, the processing of the respective type of personal data for the specified purposes shall be suspended. Withdrawal of consent shall be without prejudice to the lawfulness of the processing based on a consent prior to its withdrawal.

III. We process on a legal basis, according to local and federal legislation, the following data:

1. Information about your account in the e-shop “THE FAMILY COFFEE ROASTERS“:

● Personal and family name;
● Email address;
● Company name of the legal entity and / or name of another personified or impersonal entity / organization;

2. Data for online order through the e-shop “THE FAMILY COFFEE ROASTERS“:

● Delivery address – country, city, postal code, address;
● Delivery phone;
● Invoice data – names, phone, city, country, postal code, address;
● Method of delivery;
● Method of payment;
● Order number;
● Payment amount;
● Status and history of payments;
● Status and history of deliveries;
● Order history;

3. On-site order details:

● Invoice data – names, PIN, telephone, city, country, postal code, address;
● Personal and surname of the delivery person;
● Delivery address – country, city, postal code, address;
● Telephone for delivery;
● Method of delivery;
● Method of payment;
● Payment status;
● Delivery status;

4. Data for loyal customers:

● Personal and family name;
● Email address;
● Contact telephone;

IV. We process the following data on the basis of legitimate interest:

1. Information about your account in the e-shop “THE FAMILY COFFEE ROASTERS“:

● Personal and family name;
● Email address;
● Company name of the legal entity and / or name of another personified or impersonal entity / organization;

2. Details of the on-site order:

● Invoice data – names, phone, city, country, postal code, address;
● personal and surname of the delivery person;
● Delivery address – country, city, postal code, address;
● Telephone for delivery;
● Method of delivery;
● Method of payment;
● Payment status;
● Delivery status;

3. Data for online order through the e-shop “THE FAMILY COFFEE ROASTERS“:

● Delivery address – country, city, postal code, address;
● Delivery phone;
● Invoice data – names, phone, city, country, postal code, address;
● Method of delivery;
● Method of payment;
● Order number;
● Payment amount;
● Status and history of payments;
● Status and history of deliveries;
● Order history;

4. Data for loyal customers:

● Personal and family name;
● Email address;
● Contact telephone;

Purposes of personal data processing

1. Your account data in the e-shop “THE FAMILY COFFEE ROASTERS” is processed for the purposes of:

● Fulfillment of the obligation for reporting of the Administrator by recording legally significant certifying data in electronic protocols – technical logs;
● Delivery of ordered products;
● Providing support in case of technical malfunctions, complaints, tracking of deliveries, payments and others;
● Verification by sending an email to ensure the security of access to data about your account and when changing the password;
● Authentication when logging in to your account;
● Sending messages via email and / or push notifications for the purposes of direct marketing and advertising with your explicit consent;
● Compliance with the provisions of the laws, court decisions, legal orders and decisions of the authorities and supervisory authorities. This includes using your personal data to collect and verify accounting data and comply with accounting policies;

2. On-the-spot order data shall be processed for the purposes of:

● Delivery of ordered goods and products;
● Informing customers in connection with complaints, tracking deliveries, payments and others;
● Compliance with the provisions of the laws, court decisions, legal orders and decisions of the authorities and supervisory authorities. This includes using your personal data to collect and verify accounting data and comply with accounting policies;
● Prevention of losses, as well as for detection and prevention of abuses in the submission, registration and delivery of orders;

3. The data for online ordering through the e-shop “THE FAMILY COFFEE ROASTERS” are processed for the purposes of:

● Delivery of ordered food and products;
● Providing support in case of technical malfunctions, informing customers from operators in connection with complaints, tracking deliveries, payments and others;
● Prevention and investigation of abuses in online orders and related deliveries, as well as in losses and fraud;
● Compliance with the provisions of the laws, court decisions, legal orders and decisions of the authorities and supervisory authorities. This includes using your personal data to collect and verify accounting data and comply with accounting policies;
● Analyzing statistical data obtained after anonymization of your data;

4. Contact details and sent message or published comment shall be processed for the purposes of:

● Identification of you as the sender / author of a message or a published comment;
● Communicating with you;

5. Loyal customer data shall be processed for the purposes of:

● Fulfillment of contractual obligations for application of a price discount for orders;
● Certification and identification of the quality “loyal customer” and the rights arising from it;

Third parties with access to personal data, in connection with their activities and services provided in conjunction with “THE FAMILY COFFEE ROASTERS

1. We use the following cloud service providers, hosting, reverse proxy, CDN, servers / clusters and colocation:

● ETN HOST Ltd., with UIC: 203180452 – provide hosting and cloud services for the needs of “THE FAMILY COFFEE ROASTERS“. You can read their privacy policy at the following address: https://etnhost.bg

2. Consultants and suppliers in various fields for the purposes of protecting our legitimate interests in maintaining and improving the quality of the services we provide to meet legal requirements, protection of legal rights and interests in court, pre-trial and administrative proceedings. Those of them that we use regularly are the following:

● Courier delivery companies: Econt, Speedy, Rapido, Aramex, Transpress, DHL and TNT;

3. State bodies and institutions in connection with inspections performed by them in accordance with the legal requirements and restrictions;

With regard to private entities, we require and monitor the said third parties to apply all technical and organizational measures to protect this data.

The data are processed for the following terms:

1. Data provided on a contractual basis:

● Account data – until the expiration of 5 years from the date of the last online order or in the absence of an order – until the deletion of the account through the functionalities of the e-shop or until the expiration of 5 years from the date of your last login, -Soon. The profile data are related to and determining the data for online orders, which determines the application of the term set in connection with them. In the absence of an order based on the informal contract, you as a user have a legal expectation to use the account and therefore we have provided you with a functional opportunity to delete your account at any time before the deadline of five years.
● Data for online orders – until the expiration of 5 years from the date of the specific order. The term is determined on the basis of the limitation period for repayment of receivables.
● Data for loyal customers – until the termination of the contract.

2. Data in connection with the collection and verification of accounting data and compliance with accounting – accounting records and financial statements, including documents for tax control, audit and subsequent financial inspections are stored for 10 years from 1 January of the reporting period following the reporting period to which they relate; all other carriers of accounting information – three years, starting from January 1 of the reporting period following the reporting period to which they refer;

3. Data provided on the basis of consent – until its withdrawal, as provided, including through the functionality of the e-shop or blog or by deletion, and in the case of the e-shop – and until the expiration of 5 years from the date on your last entry, whichever is sooner; Your data on the online store are related to the comments published by you under articles and videos, and therefore represent the exercise of your constitutional right to free expression in a format and content of your choice. Therefore, no deadline is set after which their processing is terminated, but instead you are given the opportunity to remove the published content by exercising your rights as a data subject in the form and manner prescribed in this Policy. When the content of a specific comment contains insulting words or phrases, defamatory, defamatory and / or damaging the good name of the Administrator, the Administrator has the right based on its own or third parties legitimate interests to remove the content of the comment from its sites.

After the expiration of the specified period, the data is deleted and can no longer be recovered and used. The data are not deleted, but continue to be processed only for the purposes of protecting our legitimate rights and legitimate interests or in fulfillment of our legal obligations, in the event that there is pending court, administrative and pre-trial proceedings at the date of expiry of the said period, or in the case of an ongoing investigation into abuses, complaints received or brought to our attention and potential violations – until their completion.

Your rights in relation to your personal data

1. Right of access, including the right to copy data in processing:

● You have the right to request information about your personal data that we store at any time. You can contact us and based on a written request and verification of your identity, the data will be provided to you;

2. Right to correct inaccurate personal data

● You have the right to request the correction of your personal data if it is incorrect, including the addition of incomplete personal data. You can do this by contacting us with a written request, after proper verification of your identity;

3. Right of deletion (“Right to be forgotten”) in the following cases:

● Elimination of the need for processing;
● Withdrawal of consent when processing is based on consent;
● Illegal data processing;
● Legal obligation to delete;

The right to be forgotten is not an absolute right and may not be respected in cases provided by law or due to lack of proper authentication of your identity.

4. Right to limit processing where:

● the accuracy of the data is disputed, for the period in which their accuracy must be checked; or
● the processing of the data has no legal basis, but instead of deleting it, you want its limited processing; or
● if necessary, the data for the establishment, exercise or protection of your legal claims; or
● an objection has been filed for the processing of the data, pending verification of whether the grounds of the controller are lawful

In the event of a correction, deletion or restriction of processing, we will notify any recipient to whom the personal data have been disclosed, unless this is impossible or requires a disproportionate effort.

5. The right to portability of machine-readable data, according to which:

● we provide the data directly to you; or
● at your request and technical possibility, the data is provided to another administrator of your choice;

6. Right to object to processing on the basis of a legitimate interest:

● You have the right to object to the processing of your personal data based on the legitimate interest of the Administrator or a third party. The controller will not continue to process your personal data unless it is proven that there are compelling legal grounds for doing so that take precedence over your interests and rights or due to litigation and other procedural and extra-procedural actions as required.

7. Right to object to direct marketing:

● You have the right to object to receiving marketing messages, including profiling and analysis for direct marketing purposes.

8. Right to complain to a supervisory authority in the Member State of my usual place of residence, place of work or place of the alleged infringement if I consider that the processing of my personal data infringes the provisions of Regulation (EU) 2016/679. On the territory of the Republic of Bulgaria, where the seat of the Administrator is located and the physical stores “THE FAMILY COFFEE ROASTERS” are located, the supervisory body is the Commission for Personal Data Protection.

The above rights are exercised by a written request in a form specified by the Administrator, which you can obtain at the seat of the Administrator or electronically upon request to the Data Protection Officer and fill in an electronic form received in response with the necessary documents.

You will receive an answer to your inquiry within one month of receiving your written request.

Methods used for automated individual decision making, including profiling

We do not use automated algorithms and / or profiling.