Privacy Policy and Confidentiality

Date of last document update: 25-02-2025г.

We present you with information on the transparency of the personal data processed by us in accordance with Article 13 of Regulation (EU) 2016/679 (General Data Protection Regulation). Please familiarize yourself with its content. For your convenience, the information is structured in sections, in case you wish to immediately familiarize yourself with a specific part of it.

1. Administrator and contact details

The administrator of the personal data is "Stonehard Marketing" EOOD, UIC 131254299, with registered office and management address: Sofia, 51-G "Cherni Vrah" Blvd., floor 7 (Realtons Place office building).

You have the opportunity to contact the administrator, in addition to the specified address, also via the following e-mail address: [email protected] or by phone +359 2 404 97 34.

In this document “Privacy and Confidentiality Policy”, “Stonehard Marketing” EOOD will be referred to for brevity as “Stonehard Marketing” or the “Company”.

2. Purposes of processing, legal grounds, data categories, recipients and storage periods

The information, which may contain your personal data, is processed for one or more of the following purposes:

• Conclusion and execution of contracts in our field of activity;

• Providing services requested by the User;

• Functioning of our website;

• Direct marketing;

• Human resources.

For your convenience, we present all information regarding the categories of personal data processed, the legal grounds for the processing, the categories of recipients and the storage periods for each of the purposes of the processing.

2.1. Conclusion and execution of contracts

The personal data processed for the conclusion and performance of contracts to which the Company is a party relate to the natural persons with whom we conclude them or to the representatives of legal entities and contact persons with whom we have contractual relations. The legal basis for the processing of personal data is Art. 6, par. 1, b. "b" of Regulation (EU) 2016/679 - the performance of a contract or pre-contractual relations initiated by the data subject.

The personal data processed include the identification data of the parties to the contract, bank account data, if payment is made, and other data depending on the subject matter of the specific contract, strictly necessary for its performance.

Personal data may be provided to data subjects, other authorities and persons only in legally established cases (e.g. the National Revenue Agency, law enforcement agencies). The services of accounting firms may be used for their processing.

The period of storage of personal data is determined depending on the duration of the contract and the statute of limitations of possible claims under it.

2.2. Provision of services requested by a User

The personal data that are collected and processed in the performance of services requested by a User to the Company, where the signing of a contract is not mandatory, and/or payment of remuneration for services or consultations provided is also not required, are as follows: Usually, to provide such services and consultations, the Company collects and processes personal data such as name, surname, family name, contact details (telephone number, email address, place of residence), as well as sometimes data on professional activities and place of work of the User who requested consulting services.

Personal data may be provided to data subjects, other authorities and persons only in legally established cases (e.g. the National Revenue Agency, law enforcement agencies). The services of accounting firms may be used for their processing.

The period of storage of personal data is determined depending on the duration of the service requested by the User and the statute of limitations of possible claims under it.

2.3. Functioning of our website

Please note that individuals can also be identified by online identifiers such as Internet Protocol (IP) addresses and cookies. We use cookies to operate our site, for which we have provided the necessary information on our site.

The nature of the data collected through cookies is IP address, location, page viewed, type and parameters of the device. The basis for their processing is your consent – art. 6, par. 1, b. "a" of Regulation (EU) 2016/679. The exception is cookies for the provision of a service that is explicitly requested by you, according to art. 4a, par. 4 of the Electronic Commerce Act.

Categories of recipients may be law enforcement agencies in the exercise of their powers.

The data of registered visitors is deleted if the account is not used for 5 years or until the individuals withdraw their consent, or until they delete it by the individual themselves.

Information about the storage of other cookies and how they can be disabled can be obtained from the "Cookies Policy" page.

2.4. Direct marketing

With your consent, we use your personal data to directly or indirectly present the services, reputation and initiatives of our Company, as well as to survey customer satisfaction with the services used. The legal basis for processing is the consent of the data subject - art. 6, par. 1, b. "a" of Regulation (EU) 2016/679. You have the right to withdraw your consent to the processing of your personal data for this purpose at any time.

The categories of personal data we collect refer to a limited amount of personal information that identifies the person (name and surname, email address, telephone number) and the consent given by him, including the withdrawal of consent.

Recipients of this information may only be law enforcement agencies in the exercise of their powers. We do not transfer such data to third countries.

Personal data for direct marketing purposes is stored until consent to its processing is withdrawn. After that, we only store a limited amount of information to prove that there was consent to processing and it was withdrawn.

2.5. Human resources

For the purposes of human resources management, we process personal data of job applicants, current and former employees, representatives and shareholders of the controller. Depending on the nature of the personal data, the legal grounds on which they are processed are: Art. 6, par. 1, b. "c" and Art. 9, par. 2, b. "b" of Regulation (EU) 2016/679 - compliance with the controller's legal obligations. These obligations arise mainly from the Commercial Act and the Labor Code.

The categories of personal data processed include: data for the identification of individuals, data on education and qualifications, health data, contact data, as well as other data required under labor and social security legislation, the application of tax laws, accounting, safe and healthy working conditions. The collected data are used only for the specified activities and are provided to third parties only in cases where this is provided for by law. In such cases, data may be provided, for example, to the National Revenue Agency, the Executive Agency "General Labor Inspectorate", law enforcement and other public authorities, in view of their powers and competence. The information is not stored outside the EU and the European Economic Area.

The administrator provides appropriate technical and organizational measures to protect your personal data throughout the entire period of their storage, which is determined according to the requirements of labor legislation: 50 years for payroll, 3 years for sick leaves, 5 years after termination of the employment relationship for the employment file, 6 months for documents of job applicants with whom an employment contract has not been concluded.

The activities to ensure healthy and safe working conditions are regulated by a contract with an occupational health service in accordance with Regulation No. 3 of January 25, 2008 on the conditions and procedure for carrying out the activities of occupational health services.

3. Transfer of personal data to third countries

You should keep in mind that the member states of the European Union, the European Economic Area (Iceland, Liechtenstein and Norway) and the Swiss Confederation are NOT third countries. All other countries outside this circle are.

If it is necessary to transfer personal data to recipients in them, the guarantees pursuant to Art. 44 et seq. of Regulation (EU) 2016/679 shall apply. In the event that no decision of the European Commission on an adequate level of protection has been taken for the given country, your personal data may be transferred if this is necessary for the performance of the contract with you or for the implementation of pre-contractual measures taken at your request. In all cases, the principles of Regulation (EU) 2016/679 shall apply to the transfer of personal data in order to protect your rights and freedoms.

4. Your rights under Regulation (EU) 2016/679

The General Data Protection Regulation provides the following rights of individuals in relation to the processing of their personal data:

• Right of access to your personal data processed by the administrator;

• Right to correct inaccurate or incomplete personal data;

• Right to erasure ("right to be forgotten") of personal data that is processed unlawfully or on an invalid legal basis (expired storage period, withdrawn consent, fulfilled initial purpose for which it was collected, etc.);

• Right to restriction of processing in the event of a dispute between the controller and the individual regarding the lawfulness or accuracy of the processed personal data until its resolution and/or for the establishment, exercise or defense of legal claims;

• Right to data portability, where your personal data are processed by automated means on the basis of consent or a contract. For this purpose, the data is transmitted in a structured, commonly used and machine-readable format;
the right to object to the processing of your personal data at any time and on grounds relating to your particular situation, if your personal data is processed on the basis of legitimate interest, public interest or official authority;
the right to object to the processing of personal data for direct marketing purposes. You do not need to give reasons, we will in any case comply with your objection made on this basis;

• The right not to be subject to a fully automated decision, including profiling, which produces legal effects concerning the data subject or significantly affects him/her.
The automated processing we perform does not involve making fully automated decisions with significant legal or other consequences for you.

You may exercise your rights under Regulation (EU) 2016/679 by submitting a written or electronic application to the data controller. In the application, you should indicate your name, surname, family name, personal identification number, address and other data for your identification as a data subject, describe the nature of your request, your preferred form of communication and actions taken on your request. You must sign your request, indicate the date of submission and your address for correspondence. These requirements arise from Articles 37b and 37c of the Personal Data Protection Act. To send your application, you can use the contact details of the controller or our email address: [email protected]

Please note that even after you delete your account or request that your data be deleted, copies of certain information from your account may remain visible under certain circumstances, such as if you have shared information with social media or other services, or where retaining such copies is necessary to comply with legal obligations or legal protection. Due to the nature of information caching technology, your account may not become immediately inaccessible to others.

5. Right to complain to the Personal Data Protection Commission

If you believe that your rights under Regulation (EU) 2016/679 have been violated, you have the right to file a complaint with the Personal Data Protection Commission, Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd., fax +359 2 915 3525, [email protected]

6. Importance of providing your personal data

When we process your personal data for the purposes of entering into and performing contracts with you, the provision of personal data is a necessary condition for entering into a contract. Failure to provide it prevents the possibility of taking steps on requests that are anonymous.

With your consent, we process personal data when you voluntarily decide to subscribe to our offers, promotions, current news, market research or request a specific consultation from us that does not require signing a contract. If you do not consent to this, we will not be able to know what offers you are interested in and provide you with the services specifically requested and targeted to you.

7. How we process your personal data

Personal data is processed both by automated means and manually and is protected by appropriate security measures, taking into account the state of the art, the costs of implementation, as well as the nature, scope, context and purpose of the processing. The Company implements appropriate administrative, technical, personnel and physical measures to protect the personal data it holds against loss, theft and unauthorized use, disclosure or alteration.

8. From what sources do we receive your personal data?

We receive the processed personal data from you, as data subjects. If necessary, we may additionally have access to publicly available registers such as property or commercial registers, but we would not take such actions if we do not have a pre-contractual or contractual relationship with you.

9. Links to other websites

This privacy policy does not cover any links on our site to other websites. We recommend that you read the transparency/privacy policies/statements of the other websites you visit.

10. Updating this personal data processing policy

The Company has the right to amend or update this Privacy Policy. Any changes to this Privacy Policy will be announced in advance by posting on the Company's website.

This field will help you select properties in countries that you do not know well as settlements. You can choose in which general area the property you are looking for is located, selecting base areas according to your interests - for example, in seaside resorts, in mountain/ski resorts, in the capital of the country, urban properties, rural areas in the country, etc. This way you will be able to see properties in all settlements belonging to a specific base and general area. For example, properties in all seaside resorts in the country or properties in all mountain resorts in the country.