Thank you for your interest in our company. Data protection is of a particularly high priority for the management of SMDL Simed EOOD. The website of SMDL Simed EOOD – simed.bg can be used without providing personal data. However, if the data subject wishes to use the special services of our company through our website, processing of personal data may be necessary. If the processing of personal data is necessary and there is no legal basis for such processing, we usually need to obtain the consent of the person concerned.
The processing of personal data, for example the name, address, email address or telephone number of an interested party, is always carried out in accordance with the General Data Protection Regulation and in accordance with the country-specific data protection regulations applicable to SMDL Simed EOOD. Through this data protection declaration, our company would like to inform the public about the type, scope and purpose of the personal data we collect, use and process. In addition, data subjects are informed of their rights through this data protection declaration.
As an administrator, SMDL Simed EOOD has implemented numerous technical and organizational measures to ensure the most complete protection of personal data processed through this website.
Depending on the case, we may transfer or give access to some of your personal data to the following categories of recipients:
IT service providers;
If we are required by law, or if this is necessary to protect our legitimate interests, we may also disclose certain personal data to public authorities.
We guarantee that access to your data by third-party private legal entities takes place in accordance with the legal provisions in the field of data protection and information confidentiality, based on contracts concluded with them.
1. Definitions
The data protection declaration of SMDL Simed EOOD is based on the terms used by the European legislation for directives and regulations when issuing the General Data Protection Regulation (GDPR). Our data protection statement should be easy to read and understand for both the public and our customers and business partners. To ensure this, we would like to explain the terminology used in advance.
In this data protection statement, we use the following terms, among others:
a) personal data
“Personal Data” means any information relating to an identified or identifiable living natural person. Individual data that, when taken together, can lead to the identification of a specific individual also constitutes personal data.
B) data subject
A data subject is any identified or identifiable natural person whose personal data is processed by the person responsible for the processing.
In progress
Processing is any process carried out with or without the aid of automated processes or any similar series of processes in relation to personal data, such as collecting, recording, organizing, ordering, storing, adapting or changing, reading, querying, using, disclosing by transmission, distribution or other form of provision, comparison or linking, restriction, deletion or destruction.
D) Restriction of processing
Restriction of processing is the marking of stored personal data in order to limit their future processing.
E) Profiling
Profiling is any type of automated processing of personal data, which consists in the use of these personal data to assess certain personal aspects related to a natural person, in particular aspects related to work, the economic situation. To analyze or predict the personal preferences, interests, behavior, location of this individual.
F) Pseudonymization
“Pseudonymization” means the processing of personal data in such a way that the personal data can no longer be associated with a specific data subject without the use of additional information, provided that it is stored separately and is subject to technical and organizational measures with in order to ensure that the personal data is not linked to an identified natural person or to an identifiable natural person.
G) Responsible person or administrator
“Administrator” means a natural or legal person, public body, agency or other structure that alone or jointly with others determines the purposes and means of processing personal data; where the purposes and means of this processing are determined by Union law or the law of a Member State, the controller or the special criteria for its determination may be established in Union law or in the law of a Member State;
H) Processor of personal data – The processor is a natural or legal person, public body, agency or other body that processes personal data on behalf of the responsible person;
I) Recipient
Means a natural or legal person, public body, agency or other structure to which the personal data is disclosed, whether or not it is a third party. At the same time, public authorities that may receive personal data within the framework of a specific investigation in accordance with Union law or the law of a Member State are not considered “recipients”; the processing of this data by the specified public authorities complies with the applicable data protection rules in accordance with the purposes of the processing;
J) Third party means a natural or legal person, public body, agency or other body other than the data subject, the administrator, the personal data processor and the persons who, under the direct supervision of the administrator or the personal data processor, have the right to process the personal data;
K) Consent of the subject – means any freely expressed, specific, informed and unequivocal indication of the will of the data subject, by means of a statement or a clear affirmative action, which expresses his consent to the personal data related to him being processed.
2. Name and address of the person responsible for the processing within the meaning of the General Data Protection Regulation, other data protection laws applicable in the member states of the European Union and other provisions of a data protection nature is:
SMDL Simed EOOD
1 Petar Angelov St
Svishtov, Bulgaria
Phone: +359886046402
E-Mail: simedlab@mail.bg
Website: www.simed.bg
3. Name and address of the Data Protection Officer The Data Protection Officer of the person responsible for the processing is:
Silvia Georgieva
Phone: +359886046402
E-Mail: simedlab@mail.bg
1 Petar Angelov St
Svishtov, Bulgaria
Any interested party may at any time contact our data protection officer directly with any questions or suggestions regarding data protection.
3. Cookies
The websites use cookies. Cookies are text files that are stored and managed on a computer system through an Internet browser.
Many websites and servers use cookies. Many cookies contain a so-called “cookie ID”. The cookie ID is a unique identifier for the cookie. It consists of a string of characters by which websites and servers can be assigned to the specific Internet browser in which the cookie was stored. This allows the visited websites and servers to distinguish the individual browser of the person concerned from other Internet browsers that contain other cookies. A particular internet browser can be recognized and identified by the unique identification number of the “cookie”.
Through the use of cookies, SMDL Simed EOOD can provide users of this website with more user-friendly services that would not be possible without the cookie setting.
By using a cookie, the information and offers on our website can be optimized in the user’s interest. As already mentioned, cookies allow us to recognize users of our website. The purpose of this recognition is to make it easier for users to use our website. For example, the user of a website that uses cookies does not have to re-select his preferred language every time he visits the website, because this is done by the website and by the cookie stored on the user’s computer system.
The person concerned can at any time prevent the setting of cookies from our website by means of a corresponding setting in the Internet browser used and thus permanently object to the setting of cookies. In addition, cookies that have already been set can be deleted at any time through an Internet browser or other software programs. This is possible in all common internet browsers. If the person concerned disables the cookie setting in the internet browser used, not all functions of our website may be fully usable.
4. Collection of General Data and Information
The website of SMDL Simed EOOD collects a series of general data and information each time the website is accessed by a data subject or an automated system. This aggregate data and information is stored in server log files. (1) the types and versions of the browser used, (2) the operating system used by the access system, (3) the website from which the access system reaches our website (the so-called Referrer), (4) the subsites that are accessible through our website access system, can be controlled, (5) the date and time of access to the website, (6) internet protocol address (IP address),
When using this general data and information, SMDL Simed EOOD does not draw any conclusions about the person concerned. Rather, this information is necessary to (1) properly deliver our website content, (2) optimize our website content and advertising, (3) ensure the long-term functionality of our information technology systems and our website technology and (4) provide law enforcement authorities with the information required by law enforcement authorities in the event of a cyber attack. Therefore, these anonymously collected data and information are evaluated statistically by SMDL Simed EOOD on the one hand and with the aim of increasing data protection and data security in our company, with the aim of ultimately ensuring an optimal level of protection of the personal data we process . Anonymous data in server log files is stored separately from any personal data provided by a data subject.
5. Contact options through the website
Due to legal regulations, the website of SMDL Simed EOOD contains information that allows quick electronic contact with our company and direct communication with us, which also includes a common address for the so-called electronic mail (e-mail address). If a data subject contacts the person responsible for the processing by email or contact form, the personal data transmitted by the data subject will be automatically saved. Such personal data transmitted on a voluntary basis by a data subject to the person responsible for the processing are stored for the purposes of the processing or for contacting the data subject.
6. Website Blog Comment Feature
SMDL Simed EOOD offers users the opportunity to leave individual comments on individual posts in a blog located on the website of the person responsible for the processing. A blog is a website that is usually open to the public and where one or more people, called bloggers or web bloggers, can post articles or record thoughts in so-called blog posts. Blog posts can usually be commented on by third parties.
If an interested person leaves a comment on a blog published on this website, in addition to the comments left by the person concerned, information about the time the comment was entered and the user name (pseudonym) chosen by the person concerned is stored and published. In addition, the IP address assigned by the Internet Service Provider (ISP) of the person concerned is also recorded. The IP address is stored for security reasons and in case the person concerned violates the rights of third parties or publishes illegal content by submitting a comment. Therefore, the storage of this personal data is in the own interest of the person responsible for the processing, so that it can be justified in the event of a violation of the law.
7. Routine deletion and blocking of personal data
The person responsible for the processing processes and stores personal data of the data subject only for the period necessary to achieve the purpose of storage, or if this is required by European directives and regulations or other legislator in the laws or regulations are provided to which the administrator submits.
If the storage purpose no longer applies or if the storage period prescribed by European directives and regulations or other responsible legislator expires, personal data will be routinely blocked or deleted in accordance with legal provisions.
8. Rights of the data subject
A) Right of Confirmation
Any data subject has the right, granted by the European legislator of directives and regulations, to request confirmation from the person responsible for processing whether personal data relating to them are being processed. If the data subject wishes to exercise this right of confirmation, he may at any time contact an employee of the person responsible for the processing.
B) Right to information
Any person affected by the processing of personal data has the right granted by the European Directive and the legislator to obtain free information about the personal data stored about him and a copy of this information from the person responsible for the processing at any time. In addition, European directives and regulations grant the data subject access to the following information:
the purposes of processing
the categories of personal data that are processed by the recipients or the categories of recipients to whom the personal data has been or is still being disclosed, especially for recipients in third countries or international organizations
if possible, the planned duration for which the personal data will be stored or, if this is not possible, the criteria for determining that duration
the existence of a right to rectification or deletion of personal data about you or to limit processing by the person responsible or a right to object to such processing
the availability of the right of appeal to a supervisory authority
if the personal data were not collected from the data subject: all available information about the origin of the data
the presence of automated decision-making, including profiling in accordance with Article 22 (1) and (4) GDPR and – at least in these cases – meaningful information about the logic and scope and purpose of the effects of this processing for the individual
The person has the right to information about whether the personal data have been transferred to a third country or an international organization. If this is the case, the data subject has the right to be informed of the appropriate safeguards in relation to the transfer.
If the data subject wishes to exercise this right to information, he may at any time contact the officer responsible for the processing.
C) Right to rectification
Any person affected by the processing of personal data has the right, granted by the European legislator of directives and regulations, to request the immediate correction of incorrect personal data concerning them. In addition, the data subject has the right, taking into account the purposes of the processing, to request the completion of incomplete personal data – including through a supplementary declaration.
If the data subject wishes to exercise this right of rectification, he may at any time contact an employee responsible for the processing.
D) Right to erasure (right to be forgotten)
Any person affected by the processing of personal data has the right, granted by the European legislator of directives and regulations, to require the person responsible to delete the personal data relating to them immediately, provided that the following reasons are applicable and insofar as the processing is not required:
Personal data is collected for such purposes or otherwise processed for which it is no longer necessary.
The data subject revokes the consent on which the processing is based in accordance with Article 6(1) letter GDPR or Article 9(2) letter GDPR and there is no other legal basis for the processing.
The data subject objects to the processing in accordance with Article 21(1) of the GDPR and there are no overriding legitimate reasons for the processing, or the data subject objects in accordance with Article 21(2) of the GDPR processing one.
Personal data has been processed illegally.
The erasure of personal data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the person responsible is subject.
The personal data is collected in connection with the information society services offered in accordance with Article 8(1) of the GDPR.
If one of the above-mentioned reasons is applicable and the person concerned wants to delete personal data at SMDL Simed EOOD, he can contact an employee at any time. The employee of SMDL Simed EOOD will immediately arrange the execution of the deletion request.
If the personal data is published by SMDL Simed EOOD, our company, as the responsible person, is obliged to delete the personal data in accordance with Article 17, paragraph 1 of the GDPR, SMDL Simed EOOD takes appropriate measures, taking into account the available technology and implementation costs . Measures, including technical measures, to inform other data processors who process published personal data that the data subject has requested the deletion of any links to that personal data or copies or replicas of those other data processors that he has requested, unless the processing it is not necessary. The employee of SMDL Simed EOOD will organize the necessary in individual cases.
E) Right to restriction of processing
Any person affected by the processing of personal data has the right, granted by the European legislator of directives and regulations, to request the controller to limit the processing if one of the following conditions is met:
The accuracy of the personal data is disputed by the data subject for a period of time that allows the person responsible to verify the accuracy of the personal data.
The processing is unlawful, the data subject refuses to delete the personal data and instead requests that the use of the personal data be restricted.
The person responsible no longer needs the personal data for the purposes of the processing, but the person concerned needs them to assert, exercise or defend legal claims.
The data subject has objected to the processing in accordance with Article 21(1) of the GDPR and it has not yet been determined whether the legitimate reasons of the controller outweigh those of the data subject.
If one of the above conditions is met and the interested party would like to request a limitation of the personal data stored in SMDL Simed EOOD, they can contact an employee of the IBD at any time. The employee of SMDL Simed EOOD will arrange the restriction of the processing.
F) Right to data portability
Any person affected by the processing of personal data has the right, granted by the European legislator of directives and regulations, to receive the personal data concerning them, which have been provided to a person responsible for the person concerned, in a structured, common and machine readable format. You also have the right to transfer this data to another responsible person without hindrance from the responsible person to whom the personal data was provided, provided that the processing is based on consent in accordance with Article 6(1) Letter GDPR or Art. 9 paragraph 2 letter a DS-GVO or of a contract according to Article 6 paragraph 1 letter b DS-GVO and the processing is carried out using automated procedures,
In addition, when exercising their right to data portability in accordance with Article 20(1) of the GDPR, the data subject has the right to have the personal data transferred directly from one controller to another, insofar as this is technically feasible and if this is the case does not affect the rights and freedoms of other persons.
In order to assert the right to data portability, the interested party can contact an employee of SMDL Simed EOOD at any time.
G) Right to object
Any person affected by the processing of personal data has the right, granted by the European legislator of directives and regulations, to object at any time to the processing of personal data relating to them. This also applies to profiling based on these provisions.
SMDL Simed EOOD will no longer process the personal data in the event of an objection, unless we can demonstrate compelling legitimate reasons for the processing that outweigh the interests, rights and freedoms of the data subject, or the processing serves to establish, exercise or defend legal claims .
If SMDL Simed EOOD processes personal data in order to manage direct mail, the data subject has the right at any time to object to the processing of personal data for the purposes of such advertising. This also applies to profiling insofar as it is related to such direct advertising. If the data subject objects to SMDL Simed EOOD processing for direct marketing purposes, SMDL Simed EOOD will no longer process the personal data for these purposes.
In addition, the data subject has the right, for reasons arising from his or her particular situation, to object to the processing of personal data concerning him or her, which is carried out by SMDL Simed EOOD for scientific or historical research purposes or for statistical data purposes, unless such processing is necessary for the performance of a task in the public interest.
In order to exercise the right to object, the interested party can directly contact any employee of SMDL Simed EOOD or another employee. The data subject is also free in connection with the use of information society services, regardless of Directive 2002/58 / EC, to exercise his right to object through automated procedures that use technical specifications.
H) Automated solutions in individual cases, including profiling
Any person affected by the processing of personal data has the right granted by the European legislator of directives and regulations not to be subject to a decision based solely on automated processing – including profiling – which has legal effects on them or similarly significantly affects them , if the decision (1) is not necessary for the conclusion or performance of a contract between the data subject and the responsible person, or (2) based on the legal provisions of the Union or of the Member States to which the person is responsible, these legal provisions contain appropriate measures to protect the rights and freedoms as well as the legitimate interests of the data subject or (3) with the express consent of the data subject.
If the decision (1) is necessary for the conclusion or performance of a contract between the data subject and the responsible person or (2) it is taken with the express consent of the data subject, SMDL Simed EOOD takes appropriate measures to protect rights and freedoms, as well as to protect the legitimate interests of the data subject, including at least the right to obtain intervention from the person responsible, to express his own point of view and to challenge the decision.
If the data subject wishes to assert rights in relation to automated decisions, he or she may at any time contact an employee of the person responsible for the processing.
I) Right to withdraw consent under data protection law
Any person affected by the processing of personal data has the right, granted by the European legislator of directives and regulations, to withdraw his consent to the processing of personal data at any time.
If the data subject wishes to assert his right to withdraw his consent, he may at any time contact an employee of the person responsible for the processing.
9. Data protection provisions regarding the application and use of Facebook
The person responsible for the processing has integrated components of the company Facebook on this website. Facebook is a social network.
A social network is an online community that typically allows users to communicate with each other and interact in virtual space. A social network can serve as a platform for the exchange of opinions and experiences or enable the Internet community to provide personal or company-related information. Among other things, Facebook allows users of the social network to create personal profiles, upload photos, and more.
Facebook’s operating company is Facebook, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA. If a data subject resides outside the USA or Canada, the person responsible for the processing of personal data is Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
Whenever one of the individual pages of this website is accessed, which is operated by the person responsible for processing and on which a Facebook component (Facebook plug-in) is integrated, the Internet browser in the information technology system of the person concerned is activated automatically by the corresponding Facebook component. A complete overview of all Facebook plugins can be found at https://developers.facebook.com/docs/plugins/?locale=de_DE.
As part of this technical process, Facebook receives information about which specific subpage of our website was visited by the person concerned.
If the person concerned is logged into Facebook in a certain period, Facebook recognizes each visit to our website by the person concerned and, for the entire period of the respective stay on our website, which specific subpage of our website the person concerned visits. This information is collected by the Facebook component and assigned to the respective Facebook account of the respective person by Facebook. If the data subject activates one of the Facebook buttons integrated into our website, for example the “Like” button, or if the data subject makes a comment, Facebook assigns this information to the personal Facebook user account of the data subject and saves this personal data.
Facebook always receives information via the Facebook component that the person concerned has visited our website if the person concerned is logged into Facebook at the same time as accessing our website; this happens regardless of whether the relevant person clicks on the Facebook component or not. If the data subject does not want this information to be transmitted to Facebook, he can prevent the transmission by logging out of his Facebook account before calling up our website.
The data guideline published by Facebook, which is available at
https://de-de.facebook.com/about/privacy/,
provides information about the collection, processing and use of personal data by Facebook. It also explains which setting options Facebook offers to protect the data subject’s privacy. In addition, various applications are available that make it possible to suppress the transmission of data to Facebook. Such applications can be used by the data subject to suppress data transmission to Facebook.
10. Data protection provisions regarding the implementation and use of Google Analytics (with anonymization function)
The person responsible for the processing has integrated the Google Analytics component (with anonymization function) on this website. Google Analytics is a web analysis service. Web analytics is the collection and evaluation of data about the behavior of visitors to Internet pages. The web analytics service collects, among other things, data on which website the relevant person visited (so-called Referrer), which sub-pages of the website were accessed or how often and for how long a sub-page was viewed. Web analytics is mainly used to optimize a website and to analyze the costs and benefits of internet advertising.
The operating company of the Google Analytics component is Google Inc., 1600 Amphitheater Pkwy, Mountain View, CA 94043-1351, USA.
The person responsible for the processing uses the plug-in “_gat._anonymizeIp” for web analysis via Google Analytics. Through this addendum, the IP address of the Internet connection of the person concerned is shortened and anonymized by Google, if our Internet pages are accessed from a member state of the European Union or from another signatory to the Agreement on the European Economic Area.
The purpose of the Google Analytics component is to analyze the flow of visitors to our website. Google uses the data and information obtained, among other things, to evaluate the use of our website, to compile online reports for us that show the activities on our website, and to provide other services related to the use of our website.
Google Analytics places a cookie in the information technology system of the person concerned. What cookies are has already been explained above. By setting the cookie, Google has the possibility to analyze the use of our website. Each time one of the individual pages of this website is accessed, which is managed by the person responsible for the processing and in which a Google Analytics component is integrated, the Internet browser in the information technology system of the person concerned is automatically triggered by the respective a component of Google Analytics.
The cookie is used to store personal information such as the time of access, the location from which the access was made and the frequency of visits to our website by the person concerned. Each time you visit our website, this personal data, including the IP address of the Internet connection used by the person concerned, is transmitted to Google in the United States of America. This personal data is stored by Google in the United States of America. Google may transmit this personal data collected through the technical process to third parties.
The person concerned can at any time prevent the setting of cookies by our website, as already shown above, by means of the corresponding setting of the Internet browser used and thus permanently object to the setting of cookies. Such a setting of the Internet browser used would also prevent Google from setting a cookie in the information technology system of the person concerned. In addition, a cookie already set by Google Analytics can be deleted at any time via the Internet browser or other software programs.
In addition, the data subject has the possibility to object to and prevent the collection of the data generated by Google Analytics related to the use of this website and the processing of this data by Google. To do this, the interested party must download and install a browser add-on under the link https://tools.google.com/dlpage/gaoptout. This browser add-on informs Google Analytics via JavaScript that no data or information about website visits can be transmitted to Google Analytics. Installing the browser add-on is considered an objection by Google. If the data subject’s IT system is deleted, formatted or reinstalled at a later time, the data subject must reinstall the browser add-on to disable Google Analytics. If the browser add-on is uninstalled or disabled by the interested party or another person due to their sphere of influence, there is an opportunity to reinstall or reactivate the browser add-on.
Further information and the applicable Google data protection regulations can be found at https://www.google.de/intl/de/policies/privacy/
and on
http://www.google.com/analytics/terms/de. html. Google Analytics is explained in more detail under this link https://www.google.com/intl/de_de/analytics/.
11. Legitimate interests in processing pursued by the controller or a third party
If the processing of personal data is based on Article 6 I letter f of the GDPR, our legitimate interest is the conduct of our business activities for the benefit of all our employees and our shareholders.
12. Duration for which personal data is stored
The criterion for the duration of the storage of personal data is the corresponding statutory storage period. After the expiry of the period, the relevant data is routinely deleted, provided that it is no longer necessary for the performance of the contract or for the conclusion of a contract.
13. Statutory or contractual provisions for the provision of personal data; Necessity to conclude the contract; Obligation of the data subject to provide the personal data; possible consequences of non-compliance
The provision of personal data is partly required by law (e.g. tax regulations) or may also result from contractual provisions (e.g. contractual partner information). In order to enter into a contract, it may sometimes be necessary for a data subject to provide us with personal data that we subsequently need to process. For example, the data subject is obliged to provide us with personal data when our company enters into a contract with them. Failure to provide personal data would mean that the contract cannot be concluded with the interested party. Before the data subject provides personal data, the data subject must contact one of our employees.
14. Availability of automated decision-making
As a responsible company, we do not use automated decision-making or profiling.