Privacy Policy

PRIVACY POLICY

Thank you for visiting our website.

This Privacy Policy informs you about the processing of your personal data when visiting our website and using its services. Here you can find who we are, which of your personal data we use and what they are used for, the purpose and lawfulness of their use, the period of time for which we use your data, and the measures we implement to protect them. You can also learn about your rights and how to exercise them.

Personal data refers to any information relating to an identified or identifiable natural person, such as name, location data, online identifiers, etc.

Processing personal data covers any operation performed on personal data with automated or non-automated means, including but not limited to collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction, as regulated by Article 4 (2) GDPR.

  1. Who we are

The controller of the processing of personal data which determines the purposes and means of the processing within the meaning of Article 4 (7) GDPR is ILMATEX EAD, 17 Europe Boulevard 2800, Sandanski, Bulgaria e-mail: info@ilmatex.com. UNDERS is part of the ILMATEX EAD Group registered in Bulgaria (Thereof referred to as “UNDERS”, “we”, “us” or “our”).

  1. Categories of Personal data that we are processing

When you use our website for simple browsing, we collect data that your browser transmits to our servers (saved on "server log files"). Therefore, we may process your browsing, connection and location data such as your IP address, the browser you use, your location and time of access to our website, the previous website that has led you to visit our website and your preferences during navigation. In this regard, you may also consult our Cookie Policy. (link)

We may also process the personal data categories mentioned below in the following circumstances:

  • When you contact us or register to our services, we may process your identification data, such as your name, contact information (e-mail and/or phone number), usernames and passwords.
  • When you place an order or make a purchase, we may also process your financial data, such as billing or delivery address and the payment card details.
  • When you use our web services, we may also process your product, marketing and communication preferences and other commercial information.

We process the personal data that you have given us directly (e.g., you name and e-mail when you create an account or register for our newsletter or when you order and purchase products) or indirectly through your browsing activities and interactions with third parties provided that you have expressly given your prior consent for that purpose.

  1. Purpose and legal basis for processing your personal data
  • While browsing, we process your data to make our website available to you and improve its quality. At the same time, we may use your data to ensure safe and efficient navigation as well as for anonymized statistic purposes. In that case, your browsing data is being processed in accordance with Art. 6 (1) point f GDPR, on the legal basis of our legitimate interest.
  • When you use our services, we may process your identification and/or financial data for the following purposes
    • Order handling and/or contractual performance

If you wish to place an order and proceed with a purchase of a product that we offer by using our platform, we will process your identification and financial data for the purpose of fulfilling our contractual obligations. We may use your data to verify you as a counterparty when you open a customer account or place an order as a guest, to notify you of the development and execution of your order, to manage payment and invoicing when you buy our products and to handle possible return or reservation of goods requests. The legal basis for the processing in that case is Art. 6 (1) point b GDPR. We may also proceed with the processing of your data in relation to the contractual performance to ensure the necessary technical support to respond to your purchase request, to evaluate the quality of our services and products by asking you to participate in surveys, as well as to prevent fraudulent transactions and potential interception of your financial details. This processing is based on our legitimate interest, in accordance with Art. 6 (1) point f GDPR. Furthermore, if you wish to save your payment card details on our platform for future purchases you can do so by enabling the relevant functionalities of our website. In that case we rely on your consent according to Art. 6 (1) point a GDPR, which may be withdrawn at any time.

  • Opening an account or filling-in registration forms

If you decide to register on our website to receive our newsletter and promotional communication, we may process your identification data to meet your request. The legal basis for the above processing is Art. 6 (1) point a GDPR. You may unsubscribe from our services and withdraw your consent at any time. See also Marketing and advertising purposes below.

  • Communication requested from you

We process your data strictly for the purpose of answering your requests and responding to any queries you may have raised. That processing is based on our legitimate interest according to Art. 6 (1) point f GDPR. The same applies when we need to handle potential legal claims. If you address our customer service support regarding a purchase, we may use your data for any related communication to fulfil our contractual obligation according to Art. 6 (1) point b GDPR.

 

  • With your consent in accordance with Art. 6 (1) point a GDPR we may process your data (e-mail and IP address) to analyze your browsing activity and to establish your customer profile based on previous purchases and browsing history. This will enable us to address you with product suggestions and offers that meet your preferences and may interest you. To do so we shall use automated technology.

Promotional communication may be sent by e-mail, SMS or other means of electronic communication that you authorize (e.g. push notifications if this option is activated on your device). You provide your consent for promotional communication when you fill-in the registration form for our newsletter services. You also consent to your profiling by accepting the behavioral Cookies. See our Cookie policy here.

You can unsubscribe from our newsletter at any time by clicking here https://unders.us14.list-manage.com/unsubscribe?u=53f7e9d6bb9a35b597dde7ed8&id=2de1f769ce or by clicking on the unsubscribe button at the end of our newsletters. You can also manage cookies here https://unders.us14.list-manage.com/unsubscribe?u=53f7e9d6bb9a35b597dde7ed8&id=2de1f769ce please replace the https address with a link that users can click on to be redirected (it will also have a more appealing look) or by using the cookie banner at the footer of our website. If you have created an account on our platform, you can always manage your subscription preferences to indicate the form of communication that you prefer by clicking on “account details” (link). 

You can opt-out from receiving personalized advertising by blocking these cookies via your browser software See how on our Cookie policy here or by installing the plug-in available at the following link:

https://support.google.com/ads/answer/7395996

Furthermore, if you have a Facebook or Instagram account and you have accepted all cookies on our website (including behavioral cookies) your data may be shared with Facebook Ireland Limited, which has been renamed to Meta Platforms Ireland Limited, for advertising purposes, when you are using your Facebook or Instagram App or platform. You can access Facebook’s ‘Meta’ new privacy policy here https://www.facebook.com/about/privacy/update

You can find more about advertisement preferences on Facebook ‘Meta’ here https://www.facebook.com/adpreferences/ad_settings/?entry_product=account_settings_menu

In general, we usually process your data

  • to fulfill an obligation for contractual performance
  • to comply with a legal or regulatory obligation
  • to pursue our legitimate interest

Legitimate interests may include marketing and advertising purposes, promotional communication, profiling and satisfying navigation preferences, improving of our products and services, handling legal claims e.tc. 

We only use the necessary data for the purpose for which they are being processed, as described above, unless we have a legal right or obligation to do otherwise e.g. retain information to support legal claims or disclose it to public or judicial authorities. We limit the cases where we rely on your consent as a legal basis according to Art. 6 (1) point a GDPR only for direct marketing or communication purposes. You may withdraw your consent at any time (link here to the rights mentioned below).

  1. Third parties and international data transfers

Within our establishment, your data are processed only by authorized and trained employees who are bound by confidentiality agreements. Moreover, in order to pursue the above purposes, we may have to transfer your data to other organizations to assist us with the necessary processing in the following cases:

  • We work with technology service providers for web software, web services, technical support and web storage to ensure safe and efficient navigation on our website so that you enjoy our web services to the fullest. These providers may have access to your data to the extent that this is necessary for the performance of their obligations to us.
  • When you want to make a purchase, we transmit your financial data to payment service providers (e.g. Paypal) or banks and other financial institutions. For that matter we may also disclose your financial data to public or judicial authorities in the field of anti-fraud detection, as well as to tax authorities.
  • In order to fully execute our contractual obligations, we collaborate with other entities that provide logistics services for timely delivery of the products we purchase from us.
  • We also collaborate with marketing and advertising providers to pursue our business endeavors.

The legal basis for the transfer of data to third parties may be Art. 6 (1) point a GDPR when we rely on your consent, especially for transfers aiming at advertising purposes, Art. 6 (1) point b GDPR when the transfer is made for contractual purposes, Art. 6 (1) point c GDPR when the transfer is mandated by law, or Art. 6 (1) point f GDPR when we have a legitimate interest to proceed with the transfer (e.g. profiling). 

With the exception of public or judicial authorities, we enter into Data Processing Agreements with our partners who act as data processors. DPAs are legally binding contracts that regulate our relations with our partners and define obligations and liability for both sides. If our partners are established outside the EU we may transfer your data internationally and especially in the USA, as long as an adequate level of protection of your data is guaranteed. For that purpose, our partners may have adopted the Standard Contractual Clauses issued by the EU Commission.

  1. For how long do we store your personal data?

We have adopted a storage limitation policy, in order to ensure that we do not keep your personal data for longer than necessary according to the purpose for which they are being processed. However, the duration of storage of your data may differ, depending on the categories of personal data, the purpose of the processing, the legal basis of the processing and possible legal obligations we abide by to retain your data. 

Purpose

Period of storage

Quality of browsing

We keep your browsing data only for the duration of the session or at most for (6) months after your session. Your browsing data are automatically deleted after the above period. See more on our cookies policy

Contractual performance

Your data will be stored for the time necessary to execute our contractual obligations. Further storage may be required by taxation law.

You can cancel your customer account at any time, unless otherwise needed until the execution of your order, by contacting customercare@unders.eu

Newsletter and registration forms

Your data is stored for as long as you wish to keep your subscription to our newsletter and you customer account activated.

Customer services

Your data is stored for as long as necessary to fully respond to your request.

Analytical and behavioral cookies

We keep your browsing data at most for six (6) months after your last session. After that, your data are automatically deleted. See more on our cookies policy

 

After the aforementioned period, your data will be automatically deleted unless otherwise dictated by judicial or other public authorities or in case we need to establish, support or defend against legal claims.

  1. How we secure your data

We are committed to safeguarding your personal data. For this purpose, we implement technical and organizational measures which include: i)  SSL or TLS encryption (see https://), ii) application of cyber security policy, regular cyber security monitoring, etc. We are committed to safeguarding your personal data. For this purpose, we implement technical and organizational measures which include, among others, encryption of your data and close cyber security monitoring.

  1. Your rights regarding the processing of your personal data

Chapter III of GDPR provides you with the following rights:

  • Right of access (art. 15)

You have the right to obtain confirmation on whether we process your personal data as well as to ask information about the purposes of the processing, the legal standing of the processing, the categories of personal data being processed, the recipients of your data, the period for which your data will be stored and if your data is being transferred to third countries. You have also the right to request a copy of your personal data undergoing processing as long as rights or freedoms of others are not adversely affected.

  • Right of rectification (art. 16)

You have the right to ask for corrections of your personal data that we process in case of false entries, inaccuracies or out of date information.

  • Right of erasure (art. 17)

When provided by law, you can request that we erase your personal data as long as they are no longer necessary, or you have withdrawn your consent which has been the legal basis for a certain processing, or the personal data have been unlawfully processed. We reserve the right to retain your data in case the processing is required by law or for the establishment or exercise of legal claims. 

  • Right of restriction of processing (art. 18)

 

This right can be exercised in the circumstances provided by law, but especially when your data may be inaccurate, when the processing is unlawful, or when the data is no longer needed. If you exercise your right, we shall refrain from any further processing of your data, with the exception of storage, unless you give us your consent to resume processing or processing is necessary for the exercise of legal claims.

 

  • Right to data portability (art. 20)

In certain cases, set out by law, you have the right to receive your data in a structured, commonly used and machine-readable format as well as the right to request that we transmit your data to another entity.

  • Right to object (art. 21)

 

You have the right to oppose to the processing of your personal data when based on the grounds of legitimate interest, including profiling and direct marketing purposes. In that case, we shall refrain from processing your personal data for those purposes. If the processing of your data is based on your prior consent, you have the right to withdraw it at any time. However, doing so does not affect the lawfulness of the use of your date processed before the withdrawal (art. 7).

 

You may exercise your rights, by contacting us using the contact information mentioned above. (Link to point 1 here)

You also have the right to lodge a complaint or alert before the Bulgarian Commission for Personal Data Protection, by following the instructions mentioned here:

https://www.cpdp.bg/en/?p=pages&aid=56

 

  1. Policy Updates

We reserve the right to revise our privacy policy and we work on always keeping it up to date. When we do so, we may notify you (e.g., banner notification, e-mail). In any case, you may consult our Privacy and Cookie Policy at any time, using the links at the footer of our website.