Currency
EUR
  • BGN
  • EUR
Language

GDPR Privacy Policy

Mandatory Information on Data Subjects' Rights under Personal Data Protection

Information about the company processing your data:

  • Name: Victoria 69 - MONT Ltd.
  • VAT/Company Registration Number: 101137371
  • Headquarters and Management Address: Blagoevgrad, 13 Vasil Levski Blvd
  • Correspondence Address: Blagoevgrad, 13 Vasil Levski Blvd
  • Phone: 0884073030
  • E-mail: office@victory69.com
  • Website: www.cosmeticstorebg.com

Information on the competent supervisory authority for personal data protection

  • Name: Commission for Personal Data Protection
  • Headquarters and Management Address: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd
  • Correspondence Address: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd
  • Phone: 02 915 3 518
  • Website: www.cpdp.bg

Victoria 69 - MONT Ltd. (hereinafter referred to as the "Administrator" or "Company") operates in compliance with the Personal Data Protection Act and Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, regarding the protection of individuals with regard to the processing of personal data and on the free movement of such data. This information aims to inform you about all aspects of the processing of your personal data by the Company and the rights you have in relation to this processing.

Basis for Collection, Processing, and Storage of Your Personal Data

Art. 1. The Administrator collects and processes your personal data in connection with the use of the online store www.cosmeticstorebg.com and entering into contracts with the company based on Art. 6, Para. 1 of Regulation (EU) 2016/679 (GDPR), specifically based on the following grounds:

  • Explicit consent obtained from you as a client;
  • Fulfillment of the Administrator's obligations under a contract with you;
  • Compliance with a legal obligation applicable to the Administrator;
  • For the purposes of legitimate interests of the Administrator or a third party;

Purposes and Principles of Collection, Processing, and Storage of Your Personal Data

Art. 2. (1) We collect and process the personal data you provide in connection with the use of the online store and entering into a contract with the company, including for the following purposes:

  • Creating a profile and providing full functionality when using the online store;
  • Entering into and fulfilling a distance contract;
  • Individualization of the contract party;
  • Accounting purposes;
  • Statistical purposes;
  • Protection of information security;
  • Ensuring the fulfillment of the contract for providing the respective service;
  • Sending a newsletter upon your expressed desire;

(2) We adhere to the following principles when processing your personal data:

  • Lawfulness, fairness, and transparency;
  • Limitation of processing purposes;
  • Data minimization and relevance to processing purposes;
  • Accuracy and up-to-date data;
  • Limitation of storage to achieve processing purposes;
  • Integrity and confidentiality of processing and ensuring appropriate security levels for personal data.

(3) In processing and storing personal data, the Administrator may process and store personal data for the protection of the following legitimate interests:

  • Fulfillment of obligations to the National Revenue Agency, the Ministry of Interior, and other state and municipal authorities.

Types of Personal Data Collected, Processed, and Stored by Our Company

Art. 3. (1) The company performs the following operations with the personal data provided by you for the following purposes:

  • User registration in the online store and execution of a distance sale contract – the purpose of this operation is to create a profile for using the online store to purchase goods and provide contact details for the delivery of purchased goods. Registration and profile creation for using the online store is not a mandatory step for providing the service and is available to a significant extent without creating a profile.
  • Conclusion of a commercial transaction with a client or partner – the purpose of this operation is to conclude and execute a contract with a commercial partner or client and its administration. Given the limited scope of collected personal data and the fact that some of it is collected from publicly available sources, a data impact assessment is not required for this operation.
  • Sending a newsletter (newsletter) – the purpose of this operation is to manage the process of sending newsletters to clients who have requested to receive them. Given the limited scope of collected personal data, a data impact assessment is not required for this operation.
  • Exercising the right of withdrawal or making a complaint – the purpose of this operation is to manage the process of exercising the right of withdrawal or complaint by the client. Given the limited scope of collected personal data, a data impact assessment is not required for this operation.

(2) The Administrator processes the following categories of personal data and information for the following purposes and on the following grounds:

  • Your identifying data (e-mail, name, etc.)

Purpose of data collection: 1) Establishing contact with the user and sending information to them, 2) For the purposes of user registration in the online store, and 3) For sending a newsletter. Basis for processing your personal data – By accepting the terms and conditions and registering in the online store or placing an order without registration, or by entering into a written contract, a contractual relationship is established between the Administrator and you, based on which we process your personal data – Art. 6, Para. 1, (b) GDPR. Your data for sending newsletters is processed based on your explicit consent – Art. 6, Para. 1, (a) GDPR.

  • Delivery data (names, phone, address, etc.)

Purpose of data collection: Fulfillment of the Administrator's obligations under the sales contract and delivery of purchased goods. Basis for processing your personal data – By accepting the terms and conditions and registering in the online store or placing an order without registration, or by entering into a written contract, a contractual relationship is established between the Administrator and you, based on which we process your personal data – Art. 6, Para. 1, (b) GDPR.

  • Additional data provided by you – If you wish to complete your profile, you can provide additional data such as name, surname, phone number.

Purpose of data collection: Completing information about the user in their user account. Basis for processing data: You have given explicit consent for processing your personal data for one or more specific purposes – Art. 6, Para. 1, (a) GDPR at the time of registration in the online store. Providing this data is not mandatory for registration in the online store.

(3) The Administrator does not collect or process personal data related to the following:

  • Revealing racial or ethnic origin;
  • Revealing political, religious, or philosophical beliefs, or membership in trade unions;
  • Genetic and biometric data, data about health status or sexual life or sexual orientation.

(4) Personal data is collected by the Administrator from the individuals to whom it relates.

(5) The company does not perform automated decision-making with data.

Art. 4. (1) The company performs the following operations with the personal data provided by you as legal representatives or authorized persons of legal entities-commercial partners for the following purposes:

  • Conclusion and execution of a commercial transaction: For concluding and executing a commercial transaction with a commercial company, we process only the full name of the legal representative or authorized person from the company. Based on the data impact assessment: Given the small number of individuals whose data is processed and the limited scope of collected personal data, a data impact assessment is not necessary for this operation.

(2) Personal data is collected by the Administrator from the individuals to whom it relates and from the Commercial Register at the Registration Agency.

(3) The company does not perform automated decision-making with data.

Art. 5. The Administrator may use so-called "cookies" for the purposes of providing full functionality of the website, improving user experience, statistical purposes, easier access, etc., with which you consent by using

the website. You can control and/or delete cookies at any time through your browser settings. Cookies do not constitute personal data and are not used to identify visitors and users of the online store.

Retention Period for Your Personal Data

Art. 6. (1) The Administrator retains your personal data for no longer than the existence of your profile in the online store. After the deletion of your profile, the Administrator takes necessary measures to delete and destroy all your data without undue delay or to anonymize it (i.e., render it in a form that does not reveal your identity).

(2) The Administrator processes your personal data provided during a non-registered order in the online store until the completion of the order, unless you have explicitly consented at the time of ordering for your data to be processed for purposes such as service improvement, providing recommended content, individual conditions, promotions, as well as for statistical purposes.

(3) The Administrator retains your personal data provided in connection with online orders for a period of 5 years for the purpose of protecting the Administrator's legal interests in case of judicial or administrative disputes with users of the online store.

(4) The Administrator will notify you if the retention period for the data needs to be extended for the fulfillment of a legal obligation or for legitimate interests of the Administrator or other reasons.

(5) The Administrator retains personal data that must be kept according to applicable legislation for the prescribed period, which may exceed the duration of your profile in the online store or until the completion of the order.

Art. 7. The Administrator retains the personal data of the legal representatives of its commercial partners for the duration of the contract execution, to comply with legitimate interests and legal obligations of the Administrator, which may exceed the duration of the concluded contract.

Transfer of Your Personal Data for Processing

Art. 8. (1) The Administrator may, at its discretion, transfer part or all of your personal data to data processors for the purposes of processing to which you have consented, in compliance with the requirements of Regulation (EU) 2016/679 (GDPR).

(2) The Administrator will notify you if it intends to transfer part or all of your personal data to third countries or international organizations.

Your Rights Regarding the Collection, Processing, and Storage of Your Personal Data

Withdrawal of Consent for Processing Your Personal Data

Art. 9. (1) If you do not wish your provided personal data to be processed for marketing purposes and receiving newsletters, you may withdraw your consent for processing at any time by completing the consent withdrawal form in Appendix No. 1 or by a free-form request and sending it to us via email.

(2) Upon receiving your request, we will send you an email to the address you provided for receiving newsletters and promotional messages with detailed instructions for verifying you as a newsletter recipient and data subject for whom consent withdrawal has been requested.

(3) The withdrawal of consent does not affect the lawfulness of the processing of personal data that the Administrator has carried out up to that point.

Right of Access

Article 10.

  1. You have the right to request and obtain from the Administrator confirmation of whether personal data related to you is being processed by sending a request in free text via email.

  2. You have the right to access data related to you as well as information regarding the collection, processing, and storage of your personal data.

  3. Upon receiving your request, we will send you an email, using the email address you used for registration or for making orders in the online store, with detailed instructions for verifying your identity as the data subject requesting access to the data.

  4. After verification, as per paragraph 3, the Administrator will provide you, upon request, with a copy of the personal data being processed, related to you, in electronic or other appropriate format.

  5. Access to the data is free of charge, but the Administrator reserves the right to impose an administrative fee in the case of repetitive or excessive requests.

Right to Rectification or Completion

Article 11.

  1. You can correct or complete inaccurate or incomplete personal data related to you at any time through the "Edit Profile" option.

  2. You can correct or complete inaccurate or incomplete personal data related to you directly through your profile on the website or by sending a request to the Administrator via email, using the form in Appendix No. 4 or by free text request.

Right to Erasure ("Right to be Forgotten")

Article 12.

  1. You have the right to request from the Administrator the deletion of some or all personal data related to you, and the Administrator is obliged to delete them without undue delay, when one of the following grounds applies:

    • The personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
    • You withdraw your consent on which the processing is based and there is no other legal ground for the processing;
    • You object to the processing of your personal data, including for the purposes of direct marketing, and there are no legal grounds for the processing which override your interests;
    • The personal data have been processed unlawfully;
    • The personal data must be erased to comply with a legal obligation under EU law or the law of a Member State applicable to the Administrator;
    • The personal data have been collected in relation to the offer of information society services.
  2. The Administrator is not obliged to erase personal data if they are retained and processed:

    • For the exercise of the right of freedom of expression and information;
    • To comply with a legal obligation which requires processing under EU law or the law of a Member State applicable to the Administrator, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Administrator;
    • For reasons of public interest in the area of public health;
    • For archiving purposes in the public interest, for scientific or historical research, or for statistical purposes;
    • For the establishment, exercise, or defense of legal claims.
  3. To exercise the right to be forgotten, you must send an email request for the deletion of your personal data processed by the Administrator, by completing the form in Appendix No. 2 or by free text request. Subsequently, the Administrator will send to the email address you used for registration or making orders in the online store, a letter with detailed instructions for verifying your identity as the data subject requesting erasure.

  4. Once we verify the identity of the person making the request and the person to whom the data relate according to the instructions sent to you, we will delete all the data we process about you in accordance with paragraph 3.

  5. If there is an order placed by you that is being processed, the earliest moment you can request to be "forgotten" is after the successful completion of the order.

Right to Restriction

Article 13.

  1. You have the right to request from the Administrator to restrict the processing of your data by sending a free text request via email when:

    • You contest the accuracy of the personal data, for a period enabling the Administrator to verify the accuracy of the personal data;
    • The processing is unlawful, but you do not want the personal data to be erased, just the processing to be restricted;
    • The Administrator no longer needs the personal data for the purposes of processing, but you need them for the establishment, exercise, or defense of legal claims;
    • You have objected to the processing pending verification whether the legitimate grounds of the Administrator override your interests.
  2. Upon receiving your request, we will send you an email, using the email address you used for registration or making orders in the online store, with detailed instructions for verifying your identity as the data subject requesting restriction of processing.

  3. After verification in accordance with paragraph 2, the company will cease processing your data, but will not remove any posts you have made in the online store, if any.

Right to Data Portability

Article 14.

  1. If you have given consent for the processing of your personal data or the processing is necessary for the performance of a contract with the Administrator, or if your data are processed in an automated manner, you may:

    • Request from the Administrator to provide your personal data in a readable format and transfer it to another Administrator;
    • Request from the Administrator to directly transfer your personal data to another Administrator of your choice, where technically feasible.
  2. You may exercise the right to data portability by sending an email request using the form in Appendix No. 3 or a free text request. Subsequently, the Administrator will send to the email address you used for registration or making orders in the online store, a letter with detailed instructions for verifying your identity as the data subject requesting data portability.

  3. After verification according to paragraph 2, the company will send to the specified email address the data it processes about you in XML format.

Right to Information

Article 15.

You may request from the Administrator information about all recipients to whom the personal data for which correction, erasure, or restriction of processing has been requested, have been disclosed. The Administrator may refuse to provide this information if it is impossible or requires disproportionate effort.

Right to Object

Article 16.

You may object at any time to the processing of personal data by the Administrator related to you, including if processed for the purposes of profiling or direct marketing.

Your Rights in Case of Personal Data Breach

Article 17.

  1. If the Administrator becomes aware of a personal data breach that may pose a high risk to your rights and freedoms, it will notify you without undue delay about the breach and the measures taken or to be taken.

  2. The Administrator is not obliged to notify you if:

    • It has implemented appropriate technical and organizational measures to protect the data affected by the breach;
    • It has taken subsequent measures to ensure that the breach no longer poses a high risk to your rights;
    • Notification would require disproportionate effort.

Entities to Whom Your Personal Data is Provided

Article 18.

  1. For the purpose of processing your personal data and providing the service in its full functionality and considering your interests, the Administrator may provide the data to the following data processors:

    Data ProcessorPurpose of Data Processing
    Econt Express Ltd.Delivery of ordered goods and services
    Speedy ADDelivery of ordered goods and services
  2. Data processors comply with all legal and security requirements for processing and storing your personal data.

Article 19.

The Administrator does not transfer your data to third countries.

Article 20.

In the event of a violation of your rights under the above or applicable data protection legislation, you have the right to lodge a complaint with the Commission for Protection of Personal Data as follows:

  • Name: Commission for Protection of Personal Data
  • Head Office and Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
  • Correspondence Address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2
  • Phone: 02 915 3 518
  • Website: www.cpdp.bg

Article 21.

You may exercise all your rights concerning the protection of your personal data using the forms attached to this information. Of course, these forms are not mandatory, and you may submit your requests in any form that includes a statement and identifies you as the data subject.

Article 22.

If consent relates to transfers, the Administrator describes the potential risks of transferring data to third countries in the absence of an adequacy decision and appropriate safeguards.


Appendix No. 1

Form for Withdrawal of Consent for Processing Purposes

Your Name*: .........................

Your Email Used in the Online Store*: .........................

Contact Email*: .........................

To

Name: Viktoria 69 - MONT Ltd.

UIC/BULSTAT: 101137371

Head Office and Address: Blagoevgrad, Vasil Levski Blvd. 13

Correspondence Address: Blagoevgrad, Vasil Levski Blvd. 13

Phone: 0884073030

Email: office@victory69.com

Website: www.cosmeticstorebg.com

I hereby withdraw my consent for the processing of the personal data provided by me for the purposes of receiving newsletters, advertising messages, or other marketing materials, being aware of the terms for withdrawing consent in accordance with the Mandatory Information on the Rights of Data Subjects under the data protection laws of the online store.

Here is the translation of the text into English:

---

**In the event of a violation of your rights under the above or applicable data protection legislation, you have the right to file a complaint with the Data Protection Commission as follows:**

Name: Data Protection Commission.

Headquarters and address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2

Correspondence address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2

Phone: 02 915 3 518

Website: [www.cpdp.bg](http://www.cpdp.bg)

---

**Appendix No. 2**

**Request for “right to be forgotten” - for the deletion of personal data related to me**

Your Name*: .........................

Your email used for registration or orders in the online store*: .........................

Contact email*: .........................

To

Name: Victoria 69 - MONT Ltd.

UIC/BULSTAT: 101137371

Headquarters and address: Blagoevgrad, Vasil Levski Blvd. 13

Correspondence address: Blagoevgrad, Vasil Levski Blvd. 13

Phone: 0884073030

Email: office@victory69.com

Website: [www.cosmeticstorebg.com](http://www.cosmeticstorebg.com)

Please delete all personal data you collect, process, and store that was provided by me or third parties related to me, according to the identified details, from your databases.

I declare that I am aware that part or all of my personal data may continue to be processed and stored by the administrator for the purpose of fulfilling its legal obligations.

In the event of a violation of your rights under the above or applicable data protection legislation, you have the right to file a complaint with the Data Protection Commission as follows:

Name: Data Protection Commission.

Headquarters and address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2

Correspondence address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2

Phone: 02 915 3 518

Website: [www.cpdp.bg](http://www.cpdp.bg)

---

**Appendix No. 3**

**Request for data portability**

Your Name*: .........................

Your email used for registration or orders in the online store*: .........................

Contact email*: .........................

To

Name: Victoria 69 - MONT Ltd.

UIC/BULSTAT: 101137371

Headquarters and address: Blagoevgrad, Vasil Levski Blvd. 13

Correspondence address: Blagoevgrad, Vasil Levski Blvd. 13

Phone: 0884073030

Email: office@victory69.com

Website: [www.cosmeticstorebg.com](http://www.cosmeticstorebg.com)

Please send all personal data related to me that is collected, processed, and stored in your databases in XML format to:

Email: .........................

Administrator – receiving the data: .........................

Name: .........................

Identification number (UIC, BULSTAT, registration number at CPDP): .........................

Email: .........................

In the event of a violation of your rights under the above or applicable data protection legislation, you have the right to file a complaint with the Data Protection Commission as follows:

Name: Data Protection Commission.

Headquarters and address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2

Correspondence address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2

Phone: 02 915 3 518

Website: [www.cpdp.bg](http://www.cpdp.bg)

---

**Appendix No. 4**

**Request for data correction**

Your Name*: .........................

Your email used for registration or orders in the online store*: .........................

Contact email*: .........................

To

Name: Victoria 69 - MONT Ltd.

UIC/BULSTAT: 101137371

Headquarters and address: Blagoevgrad, Vasil Levski Blvd. 13

Correspondence address: Blagoevgrad, Vasil Levski Blvd. 13

Phone: 0884073030

Email: office@victory69.com

Website: [www.cosmeticstorebg.com](http://www.cosmeticstorebg.com)

Please correct the following personal data that you collect, process, and store, provided by me or third parties related to me, as follows:

Data to be corrected:

..................................................

Please correct it as follows:

..................................................

In the event of a violation of your rights under the above or applicable data protection legislation, you have the right to file a complaint with the Data Protection Commission as follows:

Name: Data Protection Commission.

Headquarters and address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2

Correspondence address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. No. 2

Phone: 02 915 3 518

Website: [www.cpdp.bg](http://www.cpdp.bg)

---

**COOKIE USAGE INFORMATION**

A cookie (HTTP cookie) is a small text file sent from a website to an internet browser, and then returned by the browser each time it accesses that site. Cookies can contain various information; they are typically used to authenticate a registered user on the site as part of the login or initial registration process, and also to maintain a "shopping cart" for selected items during the session. Cookies may be used for site personalization (displaying different content to different users) or for tracking user actions on the site for marketing and advertising purposes. Cookies can be temporary (session cookies) or persistent (fixed cookies). Temporary cookies are deleted when the browser is closed, while persistent cookies are stored on the user's computer until they expire or are manually deleted. In 2011, the European Union introduced the requirement that all websites operating within its territory inform users about the use of cookies.

The online store [www.cosmeticstorebg.com](http://www.cosmeticstorebg.com) uses:

Strictly necessary cookies - these cookies are required for the site to function. They are set when a user performs actions such as choosing a language, currency, login session, or using a password. The browser can be set to block these cookies, but some functionalities of the site may not work.

Analytics and statistics cookies - these are used to analyze traffic from site visitors and gather statistical information about traffic sources, page visits, and user actions.

Third-party cookies - from our marketing and advertising partners: Google Adsense and Facebook. These may be used by them to measure the effectiveness of their ads and to personalize the advertising content displayed to users so that it matches their interests and searches.

Most modern internet browsers are set by default to accept cookies, but this can be changed in the browser settings. It can be set to block all cookies or only those from third parties. Restricting cookie usage may affect some of the site's functionalities. Users can delete stored cookie files through their browser settings.