1. Objectives of the Privacy Policy

1.1. This Privacy Policy aims to define the principles and procedures related to the protection of personal data of the users of our SaaS product, ensuring that such data is processed in accordance with applicable data protection legislation.

1.2. The Privacy Policy covers the collection, use, and storage of personal data, as well as the rights of data subjects regarding the processing of their personal data by our organization.

1.3. The primary objective of this policy is to provide transparency and clarity regarding how users' personal data is processed, ensuring that processing is carried out lawfully, fairly, and in a transparent manner.

1.4. The Privacy Policy complies with the requirements of Regulation (EU) 2016/679 (GDPR) and the Personal Data Protection Act, providing the necessary technical and organizational measures to protect data from unauthorized access, alteration, or destruction.

1.5. This policy is intended to inform users about their rights regarding their personal data and to define the processes for exercising these rights, including the right of access, rectification, erasure, and restriction of processing.

2. Collected Personal Data

2.1. The Client (Principal) and the Provider (Contractor) agree that the collection of personal data by the Provider shall be conducted in accordance with applicable data protection legislation, including Regulation (EU) 2016/679 and the Personal Data Protection Act.

2.2. The Provider collects the following categories of personal data for the purposes of executing this Agreement: client data, which includes entity name, Unified Identification Code (UIC/EIK), VAT number, address, and the name of the managing director (Authorized Representative).

2.3. The Provider also collects recipient data, which includes first and last names, and user data, which includes first name, last name, and email address.

2.4. All collected personal data will be processed solely for the purposes of this Agreement and will be stored in accordance with the prescribed timeframes and data protection measures established by the Personal Data Protection Act and Regulation (EU) 2016/679.

3. Purposes of Data Processing

3.1. Personal data is processed with the primary objective of ensuring effective account management for users of our SaaS product, ensuring data accuracy and relevance.

3.2. Personal data is used for issuing invoices and other financial documents related to the services provided, complying with all requirements of tax and financial legislation.

3.3. Data processing is performed to ensure high-quality customer service, including support and resolution of questions or issues related to the use of the services.

3.4. Data may be used to fulfill legal obligations and requirements imposed by applicable legislation.

3.5. Personal data may be processed for internal analysis and improving the quality of the services offered, ensuring that such actions do not conflict with the fundamental principles of data protection.

4. Legal Basis for Processing

4.1. The processing of personal data by the Provider is carried out based on the Client's right as a legal entity to register and maintain a customer management system in accordance with applicable legislation.

4.2. Processing of personal data is necessary for the performance of this contract, ensuring the provision of account management services and the issuance of invoices according to the Provider's contractual obligations.

4.3. Processing is necessary for compliance with the Provider's legal obligations arising from the tax and financial legislation of the Republic of Bulgaria, including, but not limited to, requirements for the storage and provision of accounting information.

4.4. Any processing not directly related to the performance of the contract or legal obligations will only be carried out after obtaining explicit consent from the data subject, in accordance with Regulation (EU) 2016/679.

5. Data Storage and Protection

5.1. Users' personal data is stored in a secure database under constant supervision, accessible only to authorized persons to protect against unauthorized access, alteration, or destruction.

5.2. The Provider implements all necessary technical and organizational measures to protect personal data, according to the requirements of Regulation (EU) 2016/679 and applicable national legislation.

5.3. Access to stored data is restricted and provided only to the Provider's employees who have the necessary rights and obligations to process such data, ensuring traceability of all processing activities.

5.4. The Provider ensures regular assessment of data security risks and updates protection measures to ensure their effectiveness and compliance with legal requirements.

5.5. In the event of a personal data breach, the Provider shall immediately notify the competent authorities and take action to minimize potential harm to Users.

5.6. Personal data is stored for a period no longer than necessary to fulfill contractual obligations and in accordance with applicable legislation.

6. Sharing Data with Third Parties

6.1. The Provider undertakes not to share Users' personal data with third parties, except where necessary to fulfill obligations under this Agreement or as provided by law.

6.2. In cases where sharing personal data with third parties is necessary to perform contractual obligations, the Provider guarantees that these third parties will process the data in accordance with applicable data protection legislation.

6.3. The Principal and the Contractor agree that any disclosure of personal data to third parties will be carried out in compliance with the requirements of Regulation (EU) 2016/679 and the Personal Data Protection Act.

6.4. The Provider is obliged to inform the Principal about all third parties to whom personal data has been disclosed, as well as the purposes of such disclosure, prior to the disclosure taking place.

6.5. In case of violation of provisions regarding the disclosure of personal data to third parties, the Provider shall be held liable under the terms of this Agreement and applicable legislation.

7. User Rights

7.1. Users have the right to access their personal data stored and processed by the Provider, as well as to receive information regarding the purposes of processing, the categories of personal data, and the recipients of such data.

7.2. Users have the right to request the rectification of inaccurate or incomplete personal data concerning them without undue delay by the Provider.

7.3. Users have the right to request the erasure of their personal data when it is no longer necessary for the purposes for which it was collected, or if its processing is unlawful.

7.4. Users have the right to restrict the processing of their personal data in cases provided by law, such as when the accuracy of the data is contested by them.

7.5. Users have the right to data portability, allowing them to receive the personal data they have provided to the Provider in a structured, commonly used, and machine-readable format.

7.6. Users have the right to object to the processing of their personal data on grounds relating to their particular situation, unless the Provider demonstrates compelling legitimate grounds for processing which override the interests or rights and freedoms of the Users.

7.7. All requests related to User rights under this section should be submitted in writing to the Provider, who is obliged to respond within one month of receiving the request.

8. Data Retention

8.1. Personal data of users is stored for a period no longer than necessary to fulfill contractual obligations and in accordance with applicable legislation.

8.2. Personal data is stored for a period of up to 30 days after the date of user account deletion, after which it is deleted from all backup copies.

8.3. Data storage is carried out in accordance with security and data protection standards provided for in Regulation (EU) 2016/679 and the Personal Data Protection Act.

8.4. The Licensor ensures that data stored by it is protected from unauthorized access, alteration, or destruction through the application of appropriate technical and organizational measures.

8.5. In case of a requirement to extend the retention period due to legal obligations or other legitimate reasons, the Licensor shall notify the Licensee of the grounds and duration of such retention.

9. Data Transfer Outside the EU

9.1. Personal data collected and processed within the framework of this agreement is not transferred to third countries outside the European Union (EU) or international organizations, unless appropriate safeguards for personal data protection are in place according to Regulation (EU) 2016/679.

9.2. The Licensee undertakes to ensure that all transfers of personal data outside the EU related to the performance of this agreement will be carried out in accordance with the legitimate grounds and appropriate protection measures provided for in Regulation (EU) 2016/679.

9.3. When transfer of data outside the EU is necessary for the purposes of this agreement, the Licensor and the Licensee undertake to use standard contractual clauses or other instruments approved by the European Commission that ensure an adequate level of data protection.

10. Contact Information

10.1. For questions related to this Privacy Policy, as well as for requests to exercise user rights, interested parties should contact the Data Controller.

10.2. The Data Controller provides communication options through provided contact details, including an email address and a postal address.

10.3. All inquiries and requests will be considered promptly, and the controller undertakes to respond within the timeframes established by law.

10.4. To exercise their rights, users can contact the Data Controller via email address: support [at] invoico7.com.