Personal Data Protection Policy for Visitors of https://www.vazhod.bg/
VAZHOD JSC processes your personal data with the highest level of security in connection with your visit to and use of the Company’s website.
VAZHOD JSC collects and processes personal data only in compliance with applicable Bulgarian and European legislation. Personal data is processed only for specified purposes and within the limits established by law.
For the purposes and legal grounds described in this Privacy Policy, VAZHOD JSC acts as a Data Controller and applies appropriate technical and organizational measures to protect personal information.
This Privacy Policy provides information regarding the purposes, legal grounds, methods of processing, categories of personal data processed, categories of recipients to whom data may be disclosed, and your rights concerning the processing of your personal data.
Please read this Privacy Policy carefully.
Policy Updates
To ensure the implementation of the most up-to-date security measures and compliance with applicable legislation, VAZHOD JSC may periodically update this Privacy Policy.
We encourage you to review this Privacy Policy regularly to remain informed about how we protect your personal data.
This Privacy Policy was adopted on 01 April 2026.
Data Controller Information
VAZHOD JSC, UIC: 115018553, 7 Vladaya Street, Plovdiv, Bulgaria, e-mail: office@vazhod.bg
VAZHOD JSC provides information regarding the categories of personal data processed, the purposes and legal grounds for processing, and the manner in which personal data is collected, processed, stored and disclosed.
Information About the Competent Supervisory Authority
- Name: Commission for Personal Data Protection (CPDP)
- Registered Office and Management Address: 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria
- Correspondence Address: 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria
- Phone:02 915 3 518
- Email: kzld@government.bg, kzld@cpdp.bg
- Website: www.cpdp.bg
What Personal Data Do We Process?
When you visit and use the functionalities of the VAZHOD JSC website, we may process the following personal data:
- Name
- E-mail address;
- IP address
Други данни:
Cookies – detailed information about them can be found below.
Legal Basis for Processing Personal Data
The processing of personal data voluntarily provided by you is necessary for taking steps at the request of the data subject through the completion of the contact form available on our website, pursuant to Article 6(1)(b) of Regulation (EU) 2016/679 (GDPR).
Purposes of Processing Personal Data
The personal data provided by you will be used solely for the purpose of administering and responding to inquiries submitted through the website functionality, including:
- Contact forms
Requests and inquiries submitted through the website
VAZHOD JSC respects and protects the confidentiality of your personal data. Subject to applicable legal requirements, personal data may be disclosed to:
- System administrators, IT personnel and employees of the Company
- Law enforcement authorities and other competent public authorities
- The Commission for Personal Data Protection in connection with obligations arising under applicable personal data protection legislation, including the Personal Data Protection Act and Regulation (EU) 2016/679
Cookies Used on Our Website
In order to provide personalized and efficient services through our website, VAZHOD JSC uses technologies that store information about website usage. This is achieved through the use of cookies.
Cookies are small text files containing limited amounts of information which are stored on your computer or within your web browser. Upon subsequent visits, your browser sends these cookies back to our website, allowing the website to recognize your device and remember certain user preferences, including visits, clicks and browsing activity.
The information collected through cookies is used solely for technical purposes related to improving and personalizing the functionality of our website. Information collected through cookies cannot be linked to a specific individual.
Further information regarding cookies and their functionality can be found at: https://www.aboutcookies.org/.
By visiting our website, you consent to the use of cookies as described in this Notice. However, you may control and manage cookies in various ways. Please note that deleting or blocking cookies may affect your use of our website and may limit access to certain functionalities or sections of the website.
Types of Cookies We May Use
- Essential Cookies
These cookies are necessary for the proper functioning of our website. They enable you to browse the website and use its features. For example, they allow us to display information in the appropriate language.
- Functional Cookies
These cookies enable us to tailor the operation of the website according to visitors’ preferences and to provide full functionality, including access to video content. The information collected is anonymous, used for limited purposes, and retained for a limited period of time.
- Analytics Cookies
We use analytics tools to understand website traffic, user interaction, and visitor interests. Information collected through these cookies is used exclusively for statistical purposes and is not intended to personally identify users.
These cookies provide information about pages visited, whether the website was accessed via mobile or desktop devices, and other anonymous usage data.
Analytics services are provided by Google Analytics and Meta. Information relating to your IP address is not linked to any other information held by Google.
- Targeting and Advertising Cookies
These cookies do not store personal information. Instead, they contain information regarding your use of our website and may be used by advertising partners to display content that is more relevant to your interests.
Examples include cookies provided by Facebook, Google, LinkedIn and other advertising platforms.
Cookie Management
You may control and manage cookies through your browser settings.
Please note that deleting cookies may also remove saved preferences.
For more information on how to manage cookie settings, please visit:
https://www.aboutcookies.org
http://www.cookiecentral.com
The cookies used when visiting the VAZHOD JSC website are as follows:
Domain: https://vazhod.bg/
- sbjs_current – deleted automatically at the end of the session
- sbjs_current_add – deleted automatically at the end of the session
- sbjs_first – deleted automatically at the end of the session
- sbjs_first_add – deleted automatically at the end of the session
- sbjs_migrations – deleted automatically at the end of the session
- sbjs_session – deleted automatically after 30 minutes
- sbjs_udata – deleted automatically at the end of the session
To domain https://google.com/
- NID – deleted automatically after 6 months
- __Secure-3PAPISID – Automatically deleted after 1 month
- __Secure-3PSID – Automatically deleted after 1 month
- __Secure-3PSIDCC – Automatically deleted after 1 year
- __Secure-3PSIDTS – Automatically deleted after 1 year
We use the following service providers. Further information about their privacy policies and instructions on how to opt out of their cookies can be found on their respective websites:
- Google Analytics: https://support.google.com/analytics/answer/6004245
- Meta: https://www.facebook.com/privacy/policies/cookies/
VAZHOD JSC reserves the right, at its sole discretion, to modify and supplement the manner in which cookies are used and the types of cookies employed at any time. In the event of any changes to this Policy, we will indicate the date of the amendment. Such changes shall become effective with respect to you and your personal data from the date of the amendment or from another explicitly specified later date.
Additional information regarding cookie settings for your web browser can be found at the following links:
- Internet Explorer http://support.microsoft.com/gp/cookies/en
- Mozilla Firefox http://support.mozilla.com/en-US/kb/Cookies
- Google Chrome http://www.google.com/support/chrome/bin/answer.py?hl=bg&answer=95647
- Safari http://support.apple.com/kb/PH5042
- Opera http://www.opera.com/browser/tutorials/security/privacy/
How Long Do We Retain Your Personal Data?
As a general rule, VAZHOD JSC ceases the active processing of your personal data once the purposes described above have been fulfilled. However, personal data will not be deleted before the expiry of any statutory retention periods required by applicable law.
Personal data is retained for no longer than necessary and, in any event, for a period not exceeding five (5) years.
Please note that we will not delete or anonymize your personal data where such data is required for ongoing judicial, administrative, or complaint-handling proceedings.
- Right to Information and Access
You have the right to request:
- Information as to whether personal data relating to you is being processed, the purposes of such processing, the categories of data concerned, and the recipients or categories of recipients to whom the data is disclosed;
- Communication, in an intelligible form, of the personal data being processed and any available information concerning its source;
- Information regarding the logic involved in any automated processing of personal data relating to you, at least in cases involving automated decision-making.
- Right to Rectification
Where we process incomplete or inaccurate personal data, you have the right at any time to request that we:
- Erase, rectify, or block personal data whose processing does not comply with applicable legal requirements;
- Notify third parties to whom your personal data has been disclosed of any erasure, rectification, or blocking, unless this proves impossible or involves disproportionate effort.
- Right to Erasure (“Right to be Forgotten”)
You may request the deletion of your personal data where you no longer wish such data to be processed and there are no overriding legal grounds for its retention, including where:
- The personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
- You withdraw the consent on which the processing is based;
- You object to the processing and there are no overriding legitimate grounds for continuing the processing;
- The personal data has been processed unlawfully;
- The personal data must be erased in order to comply with a legal obligation.
The right to erasure is not absolute. VAZHOD JSC may refuse deletion where processing is necessary:
- For exercising the right of freedom of expression and information;
- For archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes;
- For the establishment, exercise, or defence of legal claims.
- Right to Object
You have the right to object at any time to the processing of your personal data where there are legal grounds for doing so. Where the objection is justified, the relevant personal data shall no longer be processed.
- Right to Restriction of Processing
You may request restriction of processing where:
- You contest the accuracy of the personal data, for a period enabling us to verify its accuracy;
- The processing is unlawful and you oppose the erasure of the data and request restriction instead;
- We no longer need the personal data for the stated purposes, but you require it for the establishment, exercise, or defence of legal claims;
- You have objected to the processing pending verification of whether our legitimate grounds override yours.
- Right to Data Portability
You may request that we provide the personal data you have entrusted to our care to another controller in an organized, orderly, structured, commonly used electronic format if:
- We process the data pursuant to a contract and based on a declaration of consent, which may be withdrawn, or on a contractual obligation; and
- The processing is carried out by automated means.
- Right to Withdraw Consent
You have the right, at any time, to withdraw your consent to the processing of personal data, provided that the respective processing is based on consent given by you. Such withdrawal shall not affect the lawfulness of processing based on consent before its withdrawal.
- Right to Lodge a Complaint
In the event that you believe we are violating the applicable regulatory framework, we kindly ask you to contact us to clarify the matter. Of course, you have the right to lodge a complaint with the Commission for Personal Data Protection or with the relevant court in accordance with the Administrative Procedure Code. Since May 25, 2018, you can also lodge a complaint with a supervisory authority within the EU.
- Right to Compensation
Pursuant to Art. 39, para. 2 of the LPDP (Law on Personal Data Protection) and Art. 82, para. 1 of Regulation (EU) 2016/679, any person who has suffered damage as a result of an infringement of the provisions of Regulation (EU) 2016/679 has the right to receive compensation through judicial proceedings before the competent judicial authority.
Exercising Your Rights
Applications for exercising your rights shall be submitted to the following e-mail address: office@vazhod.bg. They must be signed with a QES (Qualified Electronic Signature) or in another manner that undisputedly verifies the will of the person submitting the application. We shall issue a decision on your request within one month of its submission. When objectively necessary, a longer period may be required in order to collect all requested data, and if this seriously hinders our activity, this period may be extended up to 30 days. With our decision, we grant or refuse access and/or the information requested by the applicant, but we always substantiate our response.
The minimum information to be contained in the application (pursuant to Art. 37v of the LPDP) should be as follows: Name, address, Personal Identification Number (EGN) / Personal Number of a Foreigner (LNCh) / Passport No.;
Description of the request;
Signature and date of submission;
Correspondence address / email (depending on the preferred form for receiving information);
Power of attorney (if applicable).
Regarding the rights described above: right to information, right to rectification, “right to be forgotten”, right to object, right to restriction of processing, right not to be subject to a decision based solely on automated processing, right to withdraw consent, right to lodge a complaint, as well as with regard to the controller’s actions in connection with these rights, a special register will be established in which all actions taken will be recorded.
The initial provision of a response to a request is free of charge. In case of excessiveness (repetitiveness of more than 2 /two/ identical in substance applications within a period of 12 /twelve/ months) or manifest unfoundedness of the requests received from the same data subject, the Controller may request a reasonable fee for executing the request or refuse to act on the application.
Principles of Personal Data Processing Pursuant to Regulation (EU) 2016/679
- “Lawfulness, fairness and transparency” – Your data is processed in accordance with the applicable legislation, fairly and in a transparent manner in relation to the data subject;
- “Purpose limitation” – Your data is collected for specified, explicit and legitimate purposes and is not further processed in a manner that is incompatible with those purposes;
- “Data minimization” – The types of data we collect are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
- “Accuracy” – Accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;
- “Storage limitation” – Your data is kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed;
- “Integrity and confidentiality” – Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures.
Definitions
“Personal data” means any information relating to an identified or identifiable natural person;
“Data subject” means a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
“Restriction of processing” means the marking of stored personal data with the aim of limiting their processing in the future;
“Pseudonymisation” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person;
“Controller” means a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
“Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
“Personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed;
“Recipient” means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.
