PRIVACY POLICY (GDPR)
1. INTRODUCTION
1.1. This Privacy Policy governs the manner in which "BRUMI" EOOD ("Administrator") collects, processes, stores and protects the personal data of Customers when using the art-monkey.com Platform.
1.2. The policy has been prepared in accordance with:
• Regulation (EU) 2016/679 (GDPR)
• Personal Data Protection Act
• Electronic Commerce Act
• Consumer Protection Act
1.3. The Administrator guarantees that it processes personal data lawfully, fairly and transparently, only for specific and legitimate purposes.
2. ADMINISTRATOR DATA
"BRUMI" Ltd.
UIC: 114687801
Address: Pleven, 88 Georgi Kochev Blvd.
Email: info@art-monkey.com
Phone: 0888 040 996
The administrator is not obliged to appoint a Data Protection Officer (DPO), but all inquiries related to personal data are accepted at the specified email.
3. CATEGORIES OF PERSONAL DATA WE COLLECT
3.1. Data provided by the Customer when ordering:
• First name, last name, family name
• Telephone
• Email address
• Delivery address
• Invoice details (for legal entities)
3.2. Personalization data:
• Photos
• Lyrics
• Graphic files
• Designs provided by the Client
3.3. Automatically collected data:
• IP address
• Browser type
• Operating system
• Cookie data
• Security logs
3.4. Marketing data:
• Email address for newsletter subscription
• Order history (for personalized offers)
3.5. Payment details:
• Bank card details are NOT stored by the Administrator
• Payment operators process this data independently
4. PURPOSES OF PROCESSING
4.1. For the performance of a contract:
• accepting and processing orders
• manufacturing of personalized products
• delivery
• communication with the Client
4.2. For legal obligations:
• accounting
• tax reporting
• document archiving
4.3. For legitimate interest:
• improving services
• protection against abuse
• security support
4.4. On the basis of consent:
• marketing messages
• newsletters
• promotional offers
5. LEGAL GROUNDS FOR PROCESSING
The processing is carried out on the basis of:
• Art. 6, para. 1, b. GDPR – performance of a contract
• Art. 6, para. 1, b. "c" GDPR – legal obligation
• Art. 6, para. 1, b. "e" GDPR – legitimate interest
• art. 6, para. 1, b. "a" GDPR – consent
6. STORAGE PERIODS
6.1. Order data – 5 years (accounting requirements).
6.2. Personalization data – up to 30 days after execution, unless the Client requests deletion earlier.
6.3. Marketing data – until unsubscribed from the newsletter.
6.4. Security logs – up to 1 year.
7. SHARING DATA WITH THIRD PARTIES
The data is only provided to:
• courier companies (Econt, Speedy)
• payment operators
• banks
• accounting software
• IT support (if necessary)
The administrator does not sell, rent or provide personal data for marketing purposes to third parties.
8. DATA TRANSFER OUTSIDE THE EU
8.1. In principle, the Administrator does not transfer data outside the EU.
8.2. If this becomes necessary (for example when using cloud services), the transfer will only take place when:
• adequate level of protection;
• standard contractual clauses;
• additional guarantees.
9. TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
The administrator applies:
• SSL encryption
• limited access to data
• server protection
• antivirus systems
• security logs
• staff training
• incident procedures
10. SECURITY BREACH PROCEDURE
10.1. Upon detection of a breach, the Administrator:
• assesses risk
•takes immediate measures
• notify the CPDP within 72 hours
• notify affected individuals if necessary
11. RIGHTS OF DATA SUBJECTS
The client has the right to:
• access
• correction
• erasure ("right to be forgotten")
• restriction
• objection
• portability
• withdrawal of consent
All requests are processed within 30 days.
12. NEWSLETTER AND MARKETING
12.1. Marketing messages are sent only with explicit consent.
12.2. The customer can unsubscribe at any time via a link in the email.
13. COOKIES
13.1. The platform uses:
• functional cookies
• analytical cookies
• security cookies
13.2. Detailed information is included in the separate Cookie Policy.
14. CHANGE OF POLICY
The Administrator may update the Policy by publishing a new version of the Platform.
15. ENTRY INTO FORCE
This Policy enters into force on the date of its publication.