Transparency in the processing of personal data
 
In its capacity as the Administrator of personal data, ” Grand Millennium ” EOOD has an obligation to inform you of what to expect when processing your personal data.
Types of personal data we process :
I. We process on a contractual and pre-contractual basis (Art. 6, Par. 1, b. “b” of the GDPR) the following categories of data:
1. Data about your profile in the jarvanitskincare.com e-store , which is created for you after entering into an informal contract with the Administrator, accepting the General Terms and Conditions for using the website and e-store www.jarvanitskincare.com (“General Terms”) as follows :
● Personal and surname;
● Email address;
● Password .
2. Data for an online order through the jarvantskincare.com e-store , made by you, concluding an informal contract at a distance with the Administrator in application of the General Terms and Conditions, as well as data for the preparation of orders (pre-contractual process of initiating/starting orders by phone according to the General Terms and Conditions ):
● Data on ordered products (including SKU number of the relevant product from the e-store) and quantity;
● First and last name of the delivery person;
● Delivery address – country, city, postal code, address;
● Delivery telephone;
● Email address;
● Invoice data – names, telephone, city, country, postal code, address ;
● Delivery method;
● Payment method;
● Order number;
● Payment amount;
● Payment status;
● Delivery status;
● Traffic data according to the Electronic Communications Act or metadata (if available and depending on communication) .
II. We process the following data on the basis of your consent (Article 6, Par. 1, b. “a” of the GDPR), expressed through a deliberate action – independent entry of optional data and/or free selection of specific options:
1. Data about your account in the e-shop jarvantskincare.com :
● Company of a legal entity and/or name of another personified or unpersonified entity/organization.
2. Contact data and sent message, voice communication or posted comment , provided when filling out a contact form on the jarvantskincare.com e-store or when sending us an email, conventional mail, telegram, fax, phone call, sending an SMS, posting of blog comment and other forms of communication and/or expression as follows:
● Personal and surname;
● Email address;
● Telephone number;
● Fax number;
● Address;
● Internet site;
● Content of the comment / message / voice communication;
● Traffic data according to the Electronic Communications Act or metadata (if available and depending on the communication) .
3. Data for online ordering through the jarvantskincare.com e-store :
● Order history.
4. Bank account details for refund purposes:
● You may withdraw any of the consents provided above through your account settings or according to the form and manner prescribed in this Policy. Upon withdrawal of consent, the processing of the relevant type of personal data for the specified purposes is suspended. Withdrawal of consent does not affect the lawfulness of processing based on consent given prior to its withdrawal.
III. We process on a legal basis (Art. 6, Par. 1, b. “c” of the GDPR), in accordance with local and federal legislation, the following data:
jarvantskincare.com e-store :
● Personal and surname;
● Email address;
● Company of a legal entity and/or name of another personified or impersonal entity / organization .
jarvantskincare.com e-store , as well as data for order preparation:
● Data on ordered food and products by type (incl. SKU number of the relevant product from the e-store) and quantity;
● First and last name of the delivery person;
● Delivery address – country, city, postal code, address;
● Delivery telephone number;
● Telephone number from which the pre-contractual process is initiated;
● Email address (in the pre-contractual process);
● Invoice data – names, social security number, phone, city, country, postal code, address;
● Delivery method;
● Payment method;
● Order number;
● Payment amount;
● Payment status and history;
● Status and history of supplies;
● History of orders;
● Content of messages / voice communication;
● Traffic data according to the Electronic Communications Act or metadata (if available and depending on the communication) .
3. Contact data and sent message, voice communication or posted comment provided when filling out a contact form on the jarvantskincare.com e-shop or when sending us an email, conventional mail, telegram, fax, phone call, sending an SMS , posting a blog comment and other forms of communication and/or expression as follows:
● Personal and surname;
● Email address;
● Telephone number;
● Fax number;
● Address;
● Internet site;
● Content of the comment / message/ voice communication;
● Traffic data according to the Electronic Communications Act or metadata (if available and depending on the communication) .
IV. We process the following data on the basis of legitimate interest (Article 6, Par. 1, b. “e” of the GDPR):
jarvantskincare.com e-store :
● Personal and surname;
● Email address;
● Company of a legal entity and/or name of another personified or impersonal entity / organization .
jarvantskincare.com e-store , as well as data for order preparation:
● Data on ordered food and products by type (incl. SKU number of the relevant product from the e-store) and quantity;
● First and last name of the delivery person;
● Delivery address – country, city, postal code, address;
● Delivery telephone number;
● Telephone number from which the pre-contractual process is initiated;
● Email address (in the pre-contractual process);
● Invoice data – names, social security number, phone, city, country, postal code, address;
● Delivery method;
● Payment method;
● Order number;
● Payment amount;
● Payment status and history;
● Status and history of deliveries;
● History of orders;
● Content of messages / voice communication;
● Traffic data according to the Electronic Communications Act or metadata (if available and depending on the communication) .
3. Contact data and sent message, voice communication or posted comment provided when filling out a contact form on the jarvantskincare.com e-shop or when sending us an email, conventional mail, telegram, fax, phone call, sending an SMS , posting a blog comment and other forms of communication and/or expression as follows:
● Personal and surname;
● Email address;
● Telephone number;
● Fax number;
● Address;
● Internet site;
● Content of the comment / message / voice communication;
● Traffic data according to the Electronic Communications Act or metadata (if available and depending on the communication) .
Purposes of personal data processing:
1. Your profile data in the jarvantskincare.com e-store is processed for the purposes of:
● Fulfillment of the Administrator’s accountability obligation by recording legally significant authentication data in electronic protocols – technical logs;
● Delivery of ordered products;
● Providing support in case of technical malfunctions, informing customers by operators in our contact (call) center or in connection with complaints, tracking deliveries, payments and others;
● Verification by sending an email to ensure the security of access to your account data and when changing your password;
● Authentication when logging into your account;
● Sending emails and/or push notifications for the purposes of direct marketing and advertising with your express consent;
● Compliance with the provisions of laws, court decisions, legal orders and decisions of authorities and supervisory bodies. This includes using your personal data to collect and verify accounting data and comply with accounting reporting rules.
2. Online order data through the jarvantskincare.com e-store is processed for the purposes of:
● Delivery of ordered products;
● Providing support in case of technical malfunctions, informing customers by operators in our contact (call) center or in connection with complaints, tracking deliveries, payments and others;
● Preventing and investigating abuses of online orders and related supplies, as well as losses and fraud;
● Compliance with the provisions of laws, court decisions, legal orders and decisions of authorities and supervisory bodies. This includes using your personal data to collect and verify accounting data and comply with accounting reporting rules;
● Analysis of statistical data obtained after anonymization of your data.
3. Contact data and sent message or published comment are processed for the purposes of:
● Your identification as the sender/author of a message and of a published comment;
● Communication with you.
Third parties with access to personal data, in connection with their activity and services provided, jointly with jarvantskincare.com:
1. We use the following providers of cloud services, hosting, reverse proxy, CDN, servers / clusters and colocation:
● SuperHosting.BG EOOD – provide hosting and cloud services for the needs of jarvantskincare.com . You can read their privacy policy as well as their data processing agreement at the following address: https://www.superhosting.bg/web-hosting-page-terms-and-agreements.php 
2. Consultants and suppliers in various fields for the purpose of protecting our legitimate interests in maintaining and improving the quality of the services we provide to you, to meet legal requirements, protection of legal rights and interests in judicial, pre-trial and administrative proceedings. The ones we regularly use are the following:
● Courier companies for delivery: Econt, euShipments .
3. State bodies and institutions in connection with inspections carried out by them in accordance with legal requirements and restrictions:
With respect to private entities, we require and monitor said third parties to implement all technical and organizational measures to protect this data.
The data is processed for the following periods:
1. Data provided on a contractual basis:
● Account data – until the expiration of 5 years from the date of the last online order or in the absence of an order, as well as until the deletion of the account through the functionalities of the e-store or until the expiration of 5 years from the date of your last login, whichever comes first is rather
The profile data is linked to and determines the data for online orders, which determines the application of the time set in relation to them.
In the absence of an order based on the informal contract, you as a user have a legal expectation to use the profile and therefore we have provided you with a functional possibility to delete your profile at any time before the expiry of the final five-year period.
● Online order data – until the expiration of 5 years from the date of the specific order. The term is determined based on the statute of limitations for repayment of receivables.
2. Data in connection with the collection and verification of accounting data and compliance with accounting reporting:
● Accounting registers and financial statements , including documents for tax control, audit and subsequent financial inspections are kept for 10 years, starting from January 1 of the accounting period following the accounting period to which they relate.
All other carriers of accounting information are stored for 3 years, starting from January 1 of the accounting period following the accounting period to which they relate.
3. Data provided on the basis of consent:
● Until its withdrawal, in the manner in which it was provided, including through the functionalities of the e-store or blog or by deletion, and with respect to the e-store – until the expiration of 5 years from the date of the latter.
Your rights in relation to your personal data:
5.1 Right of access, including the right to a copy of the data being processed:
● At any time, you have the right to request information about your personal data that we store. You can contact us and based on a written request and verification of your identity, the data will be provided to you.
5.2 Right to correct inaccurate personal data:
● You have the right to request correction of your personal data if it is incorrect, including completion of incomplete personal data. You can do this through your profile or by submitting a written request to jarvant@jarvantskincare.com , after proper authentication of your identity.
5.3 Right to deletion (“Right to be forgotten”) in the following cases:
● Eliminating the need for processing;
● Withdrawal of consent when processing is based on consent;
● Illegal data processing;
● Legal obligation to delete .
The right to be forgotten is not an absolute right and may not be respected in cases provided for by law or due to lack of proper authentication of your identity.
5.4 Right to restriction of processing when:
● The veracity of the data is disputed, for the period in which their veracity must be verified;
● The processing of the data is without legal basis, but instead of deleting them, you want their limited processing;
● If the data is necessary for the establishment, exercise or defense of your legal claims;
● An objection has been filed to the processing of the data, pending verification of whether the administrator’s grounds are legitimate.
In the event of correction, erasure or restriction of processing, we will notify each recipient to whom the personal data has been disclosed, unless this is impossible or requires a disproportionate effort.
5.5 Right to object to processing based on legitimate interest:
● You have the right to object to the processing of your personal data based on the legitimate interest of the Administrator or a third party. The administrator will not continue to process your personal data unless it is proven that there are compelling legal grounds for doing so that take precedence over your interests and rights or due to legal disputes and other procedural and non-procedural actions it is necessary.
5.6 Right to object to direct marketing:
● You have the right to object to receiving marketing communications, including profiling and analysis for direct marketing purposes.
The above-described rights are exercised through a written request in a form determined by the Administrator, which you can obtain at the Administrator’s headquarters or electronically after inquiring with the Data Protection Officer and filling in the electronic form received in response with the application of the necessary documents. You will receive an answer to your inquiry within one month of receiving your written request.
Use of cookies:
1. What are cookies?
Cookies are small text files that a website can save on your computer or mobile device when you visit a page or site. A cookie will help the site or other sites recognize your device the next time you visit it. Web beacons or other similar files can do the same. We use the term cookies in this policy to refer to all files that collect information in this way.
Cookies perform many different functions. For example, they help us remember your username or preferences, analyze how well our sites are performing, or even allow us to recommend content to you that we think will be of interest to you.
Some cookies contain personal information – for example, if you clicked “Remember me” when you signed in, the cookie will remember your username. Most cookies do not collect information that can identify you, but rather collect general information about how users reach and use our sites or what their location is.
2. How to turn off cookies?
All modern browsers allow you to change cookie settings. You can usually find these settings in your browser’s “options” or “preferences” menu. To be aware of these settings, the aforementioned links may help you, or you can use the “Help” button from your browser’s menus for more details.
Please remember that if you choose to stop cookies, some sections of our site may not work properly.
jarvantskincare.com use cookies that contain your personal data?
No, the cookies we use are anonymous and do not contain any personal data.
6.3 More information:
More information about how businesses use cookies is available at: www.allaboutcookies.org .
If you have any questions regarding this Cookie Policy , please contact us by email: jarvant @jarvantskincare.com