Privacy Policy

Privacy Policy

 

Mandatory Information on Data Protection Rights

 

 

 

Information about the company processing your data:

 

Company Name: MyMini Solutions Ltd.

Company Identification Number (EIK/BULSTAT): 208088029

Registered Address: Bulgaria Blvd. 50A, Sofia, Bulgaria

Correspondence Address: Bulgaria Blvd. 50A, Sofia, Bulgaria

Phone: +359 884 049 876

Email: support@myminilovebox.com

Website: myminilovebox.com

 

 

 

Information about the Competent Data Protection Supervisory Authority

 

Name: Commission for Personal Data Protection

Headquarters and Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria

Correspondence Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria

Phone: +359 2 915 3 518

Website: www.cpdp.bg

 

 

 

Compliance with Data Protection Regulations

 

MyMini Solutions Ltd. (hereinafter referred to as the “Administrator” or “Company”) operates in compliance with the Personal Data Protection Act and Regulation (EU) 2016/679 (GDPR) of the European Parliament and the Council, dated April 27, 2016, concerning the protection of individuals in relation to the processing of personal data and the free movement of such data.

 

This document aims to inform you about how we process your personal data and the rights you have regarding this processing.

 

 

 

Legal Basis for the Collection, Processing, and Storage of Your Personal Data

 

Article 1.

 

The Administrator collects and processes your personal data in relation to your use of the MyMiniLoveBox.com online store and the conclusion of contracts based on Article 6(1) of GDPR, specifically on the following grounds:

Your explicit consent as a customer

Fulfillment of contractual obligations by the Administrator

Compliance with legal obligations applicable to the Administrator

Legitimate interests of the Administrator or a third party

 

 

 

Purposes and Principles of Data Collection, Processing, and Storage

 

Article 2.

 

(1) We collect and process the personal data you provide us in connection with the use of our online store and the conclusion of a contract with the company, including for the following purposes:

Creating an account and providing full functionality of the online store

Entering and executing a distance contract

Identification of the contracting party

Accounting purposes

Statistical analysis

Information security protection

Ensuring the execution of the service contract

Sending newsletters, if you have expressed interest in receiving them

 

(2) We adhere to the following principles when processing your personal data:

Lawfulness, fairness, and transparency

Purpose limitation

Data minimization and relevance

Accuracy and up-to-date information

Storage limitation

Integrity, confidentiality, and security

 

(3) The Administrator may process and store data for the following legitimate interests:

Fulfilling obligations to the National Revenue Agency (NRA), Ministry of Interior, and other governmental institutions

 

 

 

Types of Personal Data Collected and Processed

 

Article 3.

 

(1) The company performs the following operations with your personal data:

User Registration & Online Purchase Contract – Used to create an account for purchasing goods and storing contact details for order processing and delivery.

Impact Assessment Conclusion: The operation “User Registration & Execution of a Distance Sales Contract” complies with GDPR and provides sufficient guarantees for protecting users’ rights and interests.

Commercial Transactions with Partners or Clients – Used to enter and manage contracts with business partners or customers.

Impact Assessment Conclusion: Since only minimal personal data is collected, no additional impact assessment is required.

Newsletter Subscription – Used to manage the process of sending newsletters to users who have opted in.

Impact Assessment Conclusion: No additional impact assessment is required.

Exercise of Withdrawal Rights or Complaints – Used for handling returns and complaints.

Impact Assessment Conclusion: No additional impact assessment is required.

 

(2) The Administrator processes the following categories of personal data:

 

Identification Data (email, name, etc.)

Purpose:

1.Communication with the user and sending updates

2.Registration of the user in the online store

3.Subscription to the newsletter

Legal Basis:

•By accepting the Terms & Conditions, registering in the online store, or placing an order, a contractual relationship is established between you and the Administrator, allowing data processing under Article 6(1)(b) GDPR.

•Newsletter subscription data is processed based on your explicit consent under Article 6(1)(a) GDPR.

 

Delivery Data (full name, phone, address)

Purpose: Fulfilling contractual obligations related to order processing and shipping

Legal Basis: Data processing is based on the contractual relationship established when you place an order, in accordance with Article 6(1)(b) GDPR.

 

Additional Data Provided by You (e.g., personal details in your profile)

Purpose: Completing the user profile with additional information

Legal Basis: Data processing occurs only if you have explicitly consented to providing additional details, under Article 6(1)(a) GDPR.

 

(3) The Administrator does NOT collect or process personal data related to:

Racial or ethnic origin

Political, religious, or philosophical beliefs

Membership in trade unions

Genetic and biometric data

Health-related data

Sexual life or sexual orientatio

 

Collection and Processing of Personal Data

 

Article 4. Processing of Personal Data for Business Transactions

 

(1) The company processes personal data provided by legal representatives or authorized persons of corporate business partners for the following purposes:

Entering into and executing a commercial transaction: The company processes only the full names of the legal representative or authorized person.

Impact Assessment Conclusion: Given the limited number of individuals affected and the minimal data collected, an impact assessment is not required for this operation.

 

(2) The Administrator collects personal data from the individuals to whom they relate and from the Commercial Register at the Registry Agency.

 

(3) The company does not perform automated decision-making with personal data.

 

 

 

Use of Cookies

 

Article 5.

 

The Administrator may use cookies to:

•Provide full website functionality

•Improve the user experience

•Conduct statistical analysis

•Facilitate easier website access

 

By using our website, you agree to the use of cookies. However, you can control or delete cookies at any time through your browser settings. Cookies do not contain personal data and are not used for identifying website visitors.

 

 

 

Data Retention Period

 

Article 6.

 

(1) The Administrator stores your personal data only for the duration of your account’s existence in the online store. Upon account deletion, the Administrator ensures that all related data is permanently erased or anonymized without unnecessary delay.

 

(2) If you place an order without registering an account, your personal data will be stored until the order is completed, unless you explicitly consent to data retention for:

Service improvements

Personalized recommendations

Special offers and promotions

Statistical analysis

 

(3) Personal data related to online purchases is retained for 5 years to protect the company’s legal interests in case of disputes.

 

(4) The Administrator will notify you if the retention period needs to be extended due to:

Legal obligations

Legitimate business interests

 

(5) Data retention may exceed the account’s existence if required by applicable laws.

 

Article 7.

 

Personal data of legal representatives of business partners is stored for the duration of the contract and beyond, if necessary, to fulfill legal obligations.

 

 

 

Data Sharing and Processing by Third Parties

 

Article 8.

 

(1) The Administrator may share part or all of your personal data with data processors for the purposes you have consented to, in compliance with GDPR regulations.

 

(2) If personal data is transferred to third countries or international organizations, you will be notified in advance.

 

 

 

Your Rights Regarding Data Collection, Processing, and Storage

 

Withdrawing Consent for Data Processing

 

Article 9.

 

(1) If you do not want your personal data to be processed for marketing purposes, you can withdraw your consent at any time by:

•Completing the Consent Withdrawal Form (Annex 1)

•Sending a free-text request via email

 

(2) After receiving your request, we will send an email confirmation with verification instructions to ensure the withdrawal is being made by the correct individual.

 

(3) Withdrawal of consent does not affect the legality of past data processing activities.

 

 

 

Right of Access

 

Article 10.

 

(1) You have the right to request confirmation from the Administrator regarding whether your personal data is being processed by submitting a free-text request via email.

 

(2) You also have the right to access:

•Your personal data

Information about how your data is collected, processed, and stored

 

(3) Upon receiving your request, we will send an email confirmation with instructions for verification.

 

(4) Once your identity is verified, the Administrator will provide a copy of your personal data in an electronic or other appropriate format.

 

(5) Access to your personal data is free of charge, but the Administrator reserves the right to impose an administrative fee in cases of repeated or excessive requests.

 

 

 

Right to Rectification

 

Article 11.

 

(1) You can correct or update inaccurate or incomplete personal data at any time using the “Edit Profile” option.

 

(2) Alternatively, you may request a correction by:

•Sending an email request

•Completing the Data Correction Request Form (Annex 4)

 

 

 

Right to Erasure (“Right to Be Forgotten”)

 

Article 12.

 

(1) You have the right to request partial or full deletion of your personal data, which the Administrator must fulfill without undue delay under the following conditions:

•Your data is no longer necessary for the original purpose it was collected for

•You withdraw your consent and there is no other legal basis for processing

•You object to data processing, including for direct marketing, and there are no overriding legitimate grounds for further processing

•Your data has been processed unlawfully

•Data deletion is required by law

•Data was collected for the provision of information society services

 

(2) The Administrator is not obligated to delete data if:

•Processing is necessary to exercise freedom of expression and information

•Processing is required by EU or national laws

•Data is needed for public health, research, or statistical purposes

•Data is needed for legal claims

 

(3) To exercise your “Right to Be Forgotten”, submit a request via:

Email

Data Deletion Request Form (Annex 2)

 

Upon receiving your request, we will send an email confirmation with verification instructions.

 

(4) Once your identity is confirmed, all personal data will be permanently erased.

 

(5) If you have an active order, you may request data deletion only after order fulfillment.

 

Right to Restrict Processing

 

Article 13.

 

You may request the restriction of data processing by submitting an email request if:

•You contest the accuracy of your personal data (restriction will apply while the data is being verified)

•Data processing is unlawful, but you prefer restriction over deletion

•The Administrator no longer needs your data, but you require it for legal claims

•You object to processing, pending verification of whether the Administrator’s legitimate interests override yours

 

Once we receive your request, we will send an email confirmation with verification instructions.

Right to Data Portability

 

Article 14.

 

(1) If you have given consent for the processing of your personal data, if processing is necessary for the performance of a contract, or if data is processed automatically, you have the right to:

•Request the transfer of your personal data in a structured, readable format and provide it to another data controller.

•Request the Administrator to directly transfer your personal data to another specified administrator, where technically feasible.

 

(2) To exercise your right to data portability, submit a request via:

Email

Data Portability Request Form (Annex 3)

 

Once the Administrator receives your request, an email verification process will be initiated.

 

(3) Upon successful verification, the Administrator will send your personal data in XML format to the email address specified in your request.

 

 

Right to Information About Data Recipients

 

Article 15.

 

You have the right to request information about all recipients to whom your personal data has been disclosed, including in cases where correction, deletion, or restriction of processing has been applied.

 

The Administrator may deny this request if:

•It is impossible to provide such information.

•It requires disproportionate effort.

 

 

Right to Object to Processing

 

Article 16.

 

You may object at any time to the processing of your personal data, including for:

Profiling

Direct marketing purposes

 

The Administrator will assess whether the processing should be discontinued, except in cases where there are legitimate grounds for continuing.

 

 

Your Rights in Case of a Data Security Breach

 

Article 17.

 

(1) If a data security breach occurs, which may pose a high risk to your rights and freedoms, the Administrator will notify you without undue delay, specifying:

•The nature of the breach

•The measures taken to address it

 

(2) The Administrator is not required to notify you if:

•Appropriate technical and organizational protection measures were already in place for the affected data.

•Measures have been taken to eliminate any risks to your rights.

•Notification would require disproportionate effort.

 

 

Sharing of Your Personal Data with Third Parties

 

Article 18.

 

(1) MyMini Solutions Ltd. does not share your personal data with unrelated third parties unless:

•It is necessary to fulfill a contractual obligation.

•You have explicitly consented to data sharing.

•There is a legal requirement to disclose data to government institutions.

 

Third-Party Service Providers:

MyMiniLoveBox.com collaborates with:

Courier Services: Econt Express AD, Speedy AD, BoxNow OOD

Hosting Services: SuperHosting.BG EOOD (EIK: 131449987)

•Privacy Policy: https://www.superhosting.bg/web-hosting-page-privacy-policy.php

 

Digital Data Processing:

Google Services: Google Analytics, Google Tag Manager

•Privacy Policy: https://privacy.google.com/

Facebook Tools: Facebook Tracking Pixel, Social Media Plugins

•Privacy Policy: https://www.facebook.com/privacy/explanation

MailChimp (for newsletters)

•Privacy Policy: https://mailchimp.com/legal/privacy/

 

(2) All data processors comply with GDPR security and legal standards.

 

 

International Data Transfers

 

Article 19.

 

The Administrator does not transfer your personal data to third countries outside the EU.

 

 

How to File a Complaint Regarding Data Protection

 

Article 20.

 

If you believe your data protection rights have been violated, you may file a complaint with the Commission for Personal Data Protection (CPDP):

 

Name: Commission for Personal Data Protection

Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria

Phone: +359 2 915 3 518

Website: www.cpdp.bg

 

 

Exercising Your Rights

 

Article 21.

 

To exercise any of your data protection rights, you may:

Use the attached forms

Submit a free-text request via email

 

Requests must include a clear statement identifying you as the data subject.

 

 

Data Transfers to Third Countries

 

Article 22.

 

If you consent to data transfers to third countries, the Administrator will inform you of any potential risks, including the absence of an adequate protection decision and appropriate safeguards.

 

Annex №1

 

Form for Withdrawal of Consent for Data Processing

 

Your Name:* …………………………….

Your Email (used in the online store)*: …………………………….

Contact Email:*: …………………………….

 

To:

 

Company Name: MyMini Solutions Ltd.

Company ID (EIK/BULSTAT): 208088029

Registered Address: 50A Bulgaria Blvd., Sofia, Bulgaria

Correspondence Address: 50A Bulgaria Blvd., Sofia, Bulgaria

Phone: +359 884 049 876

Email: support@myminilovebox.com

Website: myminilovebox.com

 

 

Subject: Withdrawal of Consent for Data Processing

 

I hereby withdraw my consent for the processing of my personal data for the purpose of receiving newsletters, promotional communications, or other marketing materials.

 

I acknowledge that I have read and understood the terms of withdrawing my consent, in accordance with the Mandatory Information on Data Protection Rights provided by the online store.

 

If you believe that your data protection rights have been violated, you have the right to file a complaint with the Commission for Personal Data Protection, as follows:

 

Commission for Personal Data Protection

Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria

Phone: +359 2 915 3 518

Website: www.cpdp.bg

 

 

Annex №2

 

Request to Be Forgotten – Deletion of My Personal Data

 

Your Name:* …………………………….

Your Email (used for registration or orders in the online store)*: …………………………….

Contact Email:*: …………………………….

 

To:

 

Company Name: MyMini Solutions Ltd.

Company ID (EIK/BULSTAT): 208088029

Registered Address: 50A Bulgaria Blvd., Sofia, Bulgaria

Correspondence Address: 50A Bulgaria Blvd., Sofia, Bulgaria

Phone: +359 884 049 876

Email: support@myminilovebox.com

Website: myminilovebox.com

 

 

Subject: Request for Deletion of Personal Data (“Right to Be Forgotten”)

 

I hereby formally request that all personal data collected, processed, and stored by you, which has been provided by me or third parties related to me, be deleted from your databases.

 

I understand that some or all of my personal data may continue to be processed and stored by the Administrator for the purpose of fulfilling legal obligations.

 

If I believe that my data protection rights have been violated, I have the right to file a complaint with the Commission for Personal Data Protection, as follows:

 

Commission for Personal Data Protection

Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria

Phone: +359 2 915 3 518

Website: www.cpdp.bg

 

Annex №3

 

Request for Data Portability

 

Your Name:* …………………………….

Your Email (used for registration or orders in the online store)*: …………………………….

Contact Email:* …………………………….

 

To:

 

Company Name: MyMini Solutions Ltd.

Company ID (EIK/BULSTAT): 208088029

Registered Address: 50A Bulgaria Blvd., Sofia, Bulgaria

Correspondence Address: 50A Bulgaria Blvd., Sofia, Bulgaria

Phone: +359 884 049 876

Email: support@myminilovebox.com

Website: myminilovebox.com

 

 

Subject: Request for Data Portability

 

I hereby formally request that all personal data related to me, which has been collected, processed, and stored in your databases, be transferred in XML format to the following email address:

 

Recipient’s Email: …………………………….

Receiving Data Controller: …………………………….

 

Company Name: …………………………….

Identification Number (EIK, BULSTAT, or other official registry ID): …………………………….

Email: …………………………….

 

If I believe that my data protection rights have been violated, I have the right to file a complaint with the Commission for Personal Data Protection, as follows:

 

Commission for Personal Data Protection

Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria

Phone: +359 2 915 3 518

Website: www.cpdp.bg

 

Annex №4

 

Request for Data Correction

 

Your Name:* …………………………….

Your Email (used for registration or orders in the online store)*: …………………………….

Contact Email:* …………………………….

 

To:

 

Company Name: MyMini Solutions Ltd.

Company ID (EIK/BULSTAT): 208088029

Registered Address: 50A Bulgaria Blvd., Sofia, Bulgaria

Correspondence Address: 50A Bulgaria Blvd., Sofia, Bulgaria

Phone: +359 884 049 876

Email: support@myminilovebox.com

Website: myminilovebox.com

 

 

Subject: Request for Data Correction

 

I hereby formally request that the following personal data, which has been collected, processed, and stored by you, be corrected as follows:

 

Data to be corrected:

………………………………………………………

 

Requested correction:

………………………………………………………

 

If I believe that my data protection rights have been violated, I have the right to file a complaint with the Commission for Personal Data Protection, as follows:

 

Commission for Personal Data Protection

Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria

Phone: +359 2 915 3 518

Website: www.cpdp.bg